10 Quotes by David Litchfield

  • Author David Litchfield
  • Quote

    On November 7 NGS alerted NISCC to the problem. It was hoped that due to the severity of the problem that Oracle would release a fix or a workaround for this in the January 2006 Critical Patch Update. They failed to do so.

  • Tags
  • Share

  • Author David Litchfield
  • Quote

    Oracle still has not released an official patch, so it is still leaving its customers at risk. It is a trivial thing to fix. If the company is still working on it, I do not understand why.

  • Tags
  • Share

  • Author David Litchfield
  • Quote

    SQL injection is probably today's biggest security issue. This problem has been known about for years, but seven out of ten Web applications are still vulnerable. I find it extremely frustrating.

  • Tags
  • Share

  • Author David Litchfield
  • Quote

    Someone can come in off the Internet over the Web without a user ID or password and interact with the back-end database server, so it goes through all the firewalls. This is critical.

  • Tags
  • Share

  • Author David Litchfield
  • Quote

    We disclosed this to Oracle on Oct. 25 last year. Around the same time, they were alerted to another high-risk flaw that is not as serious as this one. They fixed that one in the January CPU but neglected to fix this. It's not a case of not having enough time, because the fix is trivial and the risks are severe.

  • Tags
  • Share


  • Author David Litchfield
  • Quote

    The whole point of a regular patch cycle is that people can plan ahead and install once. But if you are having to install it nine times, where's the benefit of that?

  • Tags
  • Share