Oracle Apps DBA: Keeping E-Business Suite Alive · Module 15 · Security, credentials and audit
Network exposure
Lesson 159 of 184 · 2 min
What should NEVER be reachable from the internet, how to check what is, and THE LISTENER THAT WAS. The list of things that should be reachable from outside is short, and everything else being reachable is an accident rather than a decision. WHAT USERS NEED IS THE WEB TIER, OVER HTTPS. That is the whole list for most estates. WHAT SHOULD NEVER BE REACHABLE IS THE DATABASE LISTENER, THE WEBLOGIC ADMIN CONSOLE, AND ADMINISTRATIVE ACCESS TO THE HOSTS. A listener exposed to the internet is the database itself offered to anybody who can reach it — every default account from Lesson 2 becomes remotely testable, by anybody, continuously. AND IT HAPPENS BY ACCIDENT RATHER THAN BY DECISION, WHICH IS WHY IT IS WORTH CHECKING RATHER THAN ASSUMING. A firewall rule written broadly to fix an outage. A cloud instance created with an open security group — Module 14 Lesson 8's…
The full lesson is part of the course
The video, the complete written lesson and the module quiz are included in Oracle Apps DBA: Keeping E-Business Suite Alive, with a certificate on completion and a fourteen-day refund window.
In this module: Module 15 · Security, credentials and audit
- 1What you are actually holding
- 2The default accounts
- 3The credential in the context fileFree preview
- 4Changing the passwords that matter
- 5Least privilege for a DBA team
- 6Auditing: what to record and what it costs
- 7Encryption, in transit and at rest
- 8Network exposure
- 9What breaks: four security findings
- 10Lab briefing · Audit an estate you did not build
