Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Mailing Lists -> Oracle-L -> Re: "Can't Break In" and Securing iAS on NT

Re: "Can't Break In" and Securing iAS on NT

From: Rodd Holman <roddholman_at_HotPOP.com>
Date: Thu, 25 Apr 2002 07:23:28 -0800
Message-ID: <F001.0044F56E.20020425072328@fatcity.com>


Sounds like the only way to secure iAS on NT is not to put it on NT. You might try LINUX. It would at least let you use your existing hardware. And, it's free or relatively cheap depending on distro.

Rodd

On Thu, 2002-04-25 at 07:53, Boivin, Patrice J wrote:

    I am reading through O'Reilly's Apache: The Definitive Guide, 1999.     

    On page 42 it says:
    "In plain English, this means, once again, that Win32 is not an adequate     platform for running a Web server that has any need for security."     

    Has anyone been able to get info out of MetaLink on how to secure iAS on NT?          

    Do you have any info on how to secure iAS on NT? I was told last year to     install iAS on NT and this year I have been told to "secure the Oracle     servers".     

    If you have any info, SANS would probably like to see it too, they are     putting together an Oracle security guide.     

    I like Oracle, in my opinion it's better than anything else out there right     now. But I have been told to secure the Oracle servers and so far I appear     to have hit a brick wall with the MetaLink helpdesk people, they keep asking     me if I have specific concerns.     

    I asked them to tell me if the local administrator account is the right one     to use for installing Oracle software on NT, one technical analyst quoted     installation notes saying that a new account should be created and placed in     the local administrators group; another told me that the local administrator     account is fine; the third one hard closed my TAR without answering my     question. He figured that since I had asked the same question for iAS, OEM     and the rdbms, he didn't need to answer my question.     

    Regards,
    Patrice Boivin
    Systems Analyst (Oracle Certified DBA)     

    Systems Admin & Operations | Admin. et Exploit. des systèmes
    Technology Services        | Services technologiques
    Informatics Branch         | Direction de l'informatique 
    Maritimes Region, DFO      | Région des Maritimes, MPO
    

    E-Mail: boivinp_at_mar.dfo-mpo.gc.ca
    --
    Please see the official ORACLE-L FAQ: http://www.orafaq.com     --
    Author: Boivin, Patrice J
      INET: BoivinP_at_mar.dfo-mpo.gc.ca     

    Fat City Network Services    -- (858) 538-5051  FAX: (858) 538-5051
    San Diego, California        -- Public Internet access / Mailing Lists
    --------------------------------------------------------------------
    To REMOVE yourself from this mailing list, send an E-Mail message     to: ListGuru_at_fatcity.com (note EXACT spelling of 'ListGuru') and in     the message BODY, include a line containing: UNSUB ORACLE-L     (or the name of mailing list you want to be removed from). You may     also send the HELP command for other information (like subscribing).

--

Please see the official ORACLE-L FAQ: http://www.orafaq.com
--

Author: Rodd Holman
  INET: roddholman_at_HotPOP.com

Fat City Network Services    -- (858) 538-5051  FAX: (858) 538-5051
San Diego, California        -- Public Internet access / Mailing Lists
--------------------------------------------------------------------
To REMOVE yourself from this mailing list, send an E-Mail message to: ListGuru_at_fatcity.com (note EXACT spelling of 'ListGuru') and in the message BODY, include a line containing: UNSUB ORACLE-L (or the name of mailing list you want to be removed from). You may also send the HELP command for other information (like subscribing). Received on Thu Apr 25 2002 - 10:23:28 CDT

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US