MSAMM
Back to course

Oracle Apps DBA: Keeping E-Business Suite Alive · Module 15 · Security, credentials and audit

What breaks: four security findings

Lesson 160 of 184 · 2 min

A DEFAULT ACCOUNT STILL ENABLED, a PASSWORD IN A WORLD-READABLE SCRIPT, an AUDIT TRAIL NOBODY READ, and a TEST ENVIRONMENT REACHABLE FROM OUTSIDE. THE DEFAULT ACCOUNT IS THE ONE AN AUDITOR FINDS IN TEN MINUTES AND NOBODY ELSE EVER WOULD. Open, unused, and on a password published in Oracle's documentation — and nothing in normal operation would ever surface it, because nobody uses it. Lesson 2, and the check takes ten minutes on an inherited estate. THE PASSWORD IN A WORLD-READABLE SCRIPT IS THE ONE WHERE THE EXPOSURE IS LARGER THAN IT LOOKS. Anybody with a shell on that host can read it — and so can anybody with a copy of a backup, a clone, or a file somebody took to a laptop. Lesson 3, and the remedy is rotation rather than a permissions change, because the copies already exist. THE AUDIT TRAIL NOBODY READ IS THE ONE THAT

The full lesson is part of the course

The video, the complete written lesson and the module quiz are included in Oracle Apps DBA: Keeping E-Business Suite Alive, with a certificate on completion and a fourteen-day refund window.

Get the free lessons by email

We will email you a link to every free lesson in this course. No account needed, and one message only.

In this module: Module 15 · Security, credentials and audit

  1. 1What you are actually holding
  2. 2The default accounts
  3. 3The credential in the context fileFree preview
  4. 4Changing the passwords that matter
  5. 5Least privilege for a DBA team
  6. 6Auditing: what to record and what it costs
  7. 7Encryption, in transit and at rest
  8. 8Network exposure
  9. 9What breaks: four security findings
  10. 10Lab briefing · Audit an estate you did not build