- It's the applications, stupid
- Will a whitelist save personal computing?
- Thousands of Web sites under attack
- To solve the unsolvable problem
- Re-thinking the security of virtual machines
- Security Development Lifecycle trumps code complexity
- Is your Web site FIPS compliant?
- Computer security: Why have least privilege?
- Strategic security: Get a handle on authentication
- Control user installs of software
November 21, 2006 | Comments: (0)
Oracle security vs. MS-SQL
David Litchfield presents a compelling paper.
Microsoft SQL appears many times more secure than Oracle based upon the numbers of announced exploits alone. The numbers are so startling, it's hard to say that the numbers don't mean something this time around.
Click here for David's report.
Posted by Roger Grimes on November 21, 2006 02:16 PM
RATE THIS ARTICLE:
-

- COMMENTS
Some of this paper's info will surely be cherry-picked by RedHat in the months ahead...
Here's an interesting reply from David Litchfield responding to his critics
----------------
-------- Original Message --------
Subject: Re: "Which is more secure? Oracle vs. Microsoft" (is it a fair comparison?)
Date: Wed, 22 Nov 2006 10:57:27 -0000
From: David Litchfield
To: Matthew Conover , ,
References:
Hi Matt,
>Given that NGS Software participated in Microsoft's Security
>Development Lifecycle [1] and your paper is already being referenced by
>Microsoft employees [2], the following question should be addressed to
>ensure the comparison is fair:
>Did NGS Software find any bugs in a version of SQL Server mentioned in
>the paper (7, 2005, and 2005) during a private security audit which
>were disclosed to Microsoft and fixed without being mentioned in a
>Microsoft security bulletin?
No. Additionally, if I was to find a bug in released code today Microsoft would fix it as usual and a public announcement would be made. It is imperative for both Microsoft and NGSSoftware that NGSSoftware is seen to be independent and not "in the pocket" of Microsoft. Since working with Microsoft we have been publicly credited in many Microsoft Bulletins - here's the list for 2006 alone:
http://www.microsoft.com/technet/security/bulletin/ms06-nov.mspx
http://www.microsoft.com/technet/security/bulletin/ms06-aug.mspx
http://www.microsoft.com/technet/security/bulletin/ms06-jun.mspx
http://www.microsoft.com/technet/security/bulletin/ms06-mar.mspx
http://www.microsoft.com/technet/security/bulletin/ms06-jan.mspx
The bottom line is that Oracle really is just more buggy.
Cheers,
David
TOP STORIES
HP buys EDS for $13.9 billionCorporate software spending slows
MS targets smartphone market
SOA Software buys LogicLibrary
Phishers scamming IRS rebates
Sun to clarify JavaFX plan
MS' dev tool service packs
Developers' role shifting
MS: SP3 reboots OEMs' fault
Apple: iPhone out of stock
ADDITIONAL RESOURCES

- Application Security: Threats and How to Counter Them
- Why Linux Threats Mean Business
- Minding the Machines: PC Disaster Recovery for the Enterprise

- Protect Your Data with SSL
- Prevent Your Next Microsoft Exchange Outage
- 11 Myths About Microsoft Exchange Backup & Recovery





