Oracle Apps DBA: Keeping E-Business Suite Alive · Module 15 · Security, credentials and audit
Lab briefing · Audit an estate you did not build
Lesson 161 of 184 · 3 min
Find EVERY PLACE A CREDENTIAL IS STORED, EVERY ACCOUNT THAT SHOULD NOT EXIST, and WRITE THE FINDINGS AS SOMEBODY WOULD HAVE TO ACT ON THEM. The writing is the deliverable, because a security finding that cannot be acted on is an observation, and observations do not get fixed. FOR CREDENTIALS, WORK LESSON 3'S LIST EXHAUSTIVELY. Configuration files and their permissions. Every script on the estate — grep for the obvious patterns, and read the ones that connect to anything. Shell history in every home directory somebody administers from. Scheduled jobs, monitoring configuration, and anything a clone would carry — Module 6 Lesson 5. FOR ACCOUNTS, RUN LESSON 2'S CHECK AND THEN GO FURTHER. Default passwords, accounts open that nothing connects as, and — the one people omit — database accounts belonging to people who have left, which is Module 9 Lesson 8's first failure at the database layer. AND CHECK…
The full lesson is part of the course
The video, the complete written lesson and the module quiz are included in Oracle Apps DBA: Keeping E-Business Suite Alive, with a certificate on completion and a fourteen-day refund window.
In this module: Module 15 · Security, credentials and audit
- 1What you are actually holding
- 2The default accounts
- 3The credential in the context fileFree preview
- 4Changing the passwords that matter
- 5Least privilege for a DBA team
- 6Auditing: what to record and what it costs
- 7Encryption, in transit and at rest
- 8Network exposure
- 9What breaks: four security findings
- 10Lab briefing · Audit an estate you did not build
