Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Mailing Lists -> Oracle-L -> Re: Java Permissions Oracle 10 : updated

Re: Java Permissions Oracle 10 : updated

From: Stefan Knecht <knecht.stefan_at_gmail.com>
Date: Tue, 22 Aug 2006 12:50:07 +0200
Message-ID: <486b2b610608220350l3d9b642btd402098f1b87722a@mail.gmail.com>


Actually it's not that bad... JVM is very specific about what it allows - it implements a default policy of "deny everything unless specifically allowed".
If you grant execute (or write, for that matter) to specific application executables only, there's not much that can go wrong, as no shell is spawned, and therefore no shell processing (like "/my/good/bin && /my/bad/bin") can be done.

the one thing you never want to do is grant execute on a shell, though :-)

Stefan

On 8/22/06, Niall Litchfield <niall.litchfield_at_gmail.com> wrote:
>
> You might want to think rather carefully about the security implications
> of this particular function
>
> select function_run_os_command('rm -rf *') from dual;
>
> might be somewhat interesting....
>
> On 8/22/06, John Dunn <jdunn_at_sefas.com> wrote:
>
> >
> > > Can anyone please assist me with java permissions when running a java
> > > function in Oracle 10 on linux?
> > >
>
>
>
>
> --
> Niall Litchfield
> Oracle DBA
> http://www.orawin.info
>

--
http://www.freelists.org/webpage/oracle-l
Received on Tue Aug 22 2006 - 05:50:07 CDT

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US