Free Newsletters

   All InfoWorld Newsletters
Security Adviser | Roger A. Grimes » Oracle security vs. MS-SQL

November 21, 2006 | Comments: (0)

Oracle security vs. MS-SQL

David Litchfield presents a compelling paper.

Microsoft SQL appears many times more secure than Oracle based upon the numbers of announced exploits alone. The numbers are so startling, it's hard to say that the numbers don't mean something this time around.

Click here for David's report.

Posted by Roger Grimes on November 21, 2006 02:16 PM


RATE THIS ARTICLE:





 

  •  
  • COMMENTS




Some of this paper's info will surely be cherry-picked by RedHat in the months ahead...

Posted by: Code Guy at November 22, 2006 10:27 AM

Here's an interesting reply from David Litchfield responding to his critics
----------------
-------- Original Message --------
Subject: Re: "Which is more secure? Oracle vs. Microsoft" (is it a fair comparison?)
Date: Wed, 22 Nov 2006 10:57:27 -0000
From: David Litchfield
To: Matthew Conover , ,
References:


Hi Matt,

>Given that NGS Software participated in Microsoft's Security
>Development Lifecycle [1] and your paper is already being referenced by
>Microsoft employees [2], the following question should be addressed to
>ensure the comparison is fair:
>Did NGS Software find any bugs in a version of SQL Server mentioned in
>the paper (7, 2005, and 2005) during a private security audit which
>were disclosed to Microsoft and fixed without being mentioned in a
>Microsoft security bulletin?

No. Additionally, if I was to find a bug in released code today Microsoft would fix it as usual and a public announcement would be made. It is imperative for both Microsoft and NGSSoftware that NGSSoftware is seen to be independent and not "in the pocket" of Microsoft. Since working with Microsoft we have been publicly credited in many Microsoft Bulletins - here's the list for 2006 alone:

http://www.microsoft.com/technet/security/bulletin/ms06-nov.mspx
http://www.microsoft.com/technet/security/bulletin/ms06-aug.mspx
http://www.microsoft.com/technet/security/bulletin/ms06-jun.mspx
http://www.microsoft.com/technet/security/bulletin/ms06-mar.mspx
http://www.microsoft.com/technet/security/bulletin/ms06-jan.mspx

The bottom line is that Oracle really is just more buggy.
Cheers,
David

Posted by: Roger A. Grimes at November 26, 2006 09:16 AM

Technology White Papers

 

InfoWorld Technology Marketplace

  • Need simple, low cost server virtualization? - Do more with less. Support fewer servers. Simplify disaster recovery. Implement proven, easy-to-use server virtualization...
  • Virtually Limitless Virtual Storage - Do you need virtualization space savings of 50% or more with virtually no performance impact? You might be able to get storage...
  • Invisible IT? - The goal of IT is to become an invisible entity within a larger organization. Eliminating visibility and road blocks IT ...
  • It Really Is Easy to be Green - "Green IT" is a popular concept. And IT organizations are learning the influence that IT purchase decisions have on data...
  • Key Strategies For SOA Testing - SOA requires a unique approach to testing. Unless you're willing to reorient your testing procedures and technology now,...
  • Eliminate Botnet Security Risks - Botnets are widely regarded as the top threat to network security. This Whitepaper explains how botnets have traditionally...

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
» BUY A LINK NOW

Sponsored Technology Links