Security
Attacks on Oracle Databases Get Even Simpler
Friday, July 24th, 2009According to this article, an open source tool, Metasploit, is getting new functionality specifically created to infiltrate an Oracle DBMS environment. True, the database version being attacked in the upcoming demo is antiquated (10g rather than 10gR2 or even 11g) but this goes to show that it is critical for Oracle databases to be patched [...]
Can I Apply an Oracle Security Patch to a RAC Database Without Taking Downtime?
Friday, September 5th, 2008In short, it depends. The first step involved with applying an Oracle CPU is using the OPatch tool to apply the patch to the required Oracle Homes. This requires that no processes are running out of the home at the time of patching. This requirement does mean that the instances running on one instance on [...]
Only 10% of Oracle Databases are Secure!
Tuesday, April 29th, 2008A recent article in eWEEK revealed alarming statistics surrounding patch and CPU application. The survey was conducted by a company that appears to benefit from the patch application process being as painful as possible (they sell a solution that attempts to mitigate security risks surrounding non-patched databases). Back to the survey, here are a few [...]
Action Profile: Mass User Updates
Wednesday, March 26th, 2008Goal
Make a change whereby a database user is changed in some way across the enterprise. Properties that might be changed include the user’s password, if the user is locked out, or a change to the privileges of the user.
Use Case
A user’s password has been compromised after it was accidentally posted to a public message board. [...]
Securing Your Databases
Wednesday, October 24th, 2007Is it any wonder that database security is practically last on the “To Do” list of DBAs? Their chaotic day is filled with “installing, upgrading, capacity planning, tuning, fixing application performances, and recovering documents” as well as “firefighting their way through their day-to-day activities.”
Free time? What’s that?
In a recent article in eWEEK entitled, “The Job [...]
Here We Go Again - The First Release Blues
Tuesday, September 4th, 2007Well just in case anyone was rushing out to implement Oracle 11g databases, there is new research which finds flaws in the 11g release, opening up new holes for malicious actors to circumvent the security intentions of database owners. Even the highly touted new releases of Oracle Database Vault and Oracle Audit Vault are [...]
