Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 48 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » August 2005 » Some good tips on Dougs blog?

[Previous entry: "Oracle simplifies SOAs"] [Next entry: "A good page describing Oradebug"]

Some good tips on Dougs blog?

August 11th, 2005 by Pete

Post to del.icio.us   Post to Furl   Digg!

I saw this evening a good post on Doug Burns blog titled "A shortcut for ORACLE_HOME" - Doug shows us how to use the "?" as a substitute for the ORACLE_HOME environment variable saving the need to type complete paths in when running scripts from the Oracle installation. Jeff Hunter piped in with a comment that you need to be careful to not run scripts from a local Oracle Home if you are accessing the database remotely.

This is an interesting point from Doug and Jeff. Short cuts are great for saving time but can also cause heartache if errors like those indicated here occur. This, you might say is not a security issue but it becomes one if the database is trashed by running the wrong scripts. Security should also include the possibilities of errors occurring, either on purpose or maliciously or carelessly. It can become a security issue because it was possible to cause damage whether on purpose or not. This is an issue of privilege level and least privilege principles. The fact still stands though that it is a good time saving tip!

August 2005
SMTWTFS
 123456
78910111213
14151617181920
21222324252627
28293031   

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Weblog Home
Weblog Archives

Oracle Security Step-by-Step (Version 2.0)

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Web Development
SQL Server Security

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0




View Pete Finnigan's profile on LinkedIn

Pete Finnigan

Create Your Badge



Valid XHTML 1.0!