Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Mailing Lists -> Oracle-L -> RE: [oracle-l] Re: Oracle HTTP Server Cross Site Scripting Vulner abil lity

RE: [oracle-l] Re: Oracle HTTP Server Cross Site Scripting Vulner abil lity

From: Jesse, Rich <Rich.Jesse_at_qtiworld.com>
Date: Wed, 28 Jan 2004 09:07:45 -0600
Message-ID: <FBE1FCA40ECAD41180400050DA2BC54004E9364F@qtiexch2.qgraph.com>


Or, just comment out the startup of "isqlplus" from $ORACLE_HOME/Apache/Apache/conf/oracle_apache.conf (on Unixish servers). For example, I'd just like to use the UltraSearch functionality, so iSQL isn't needed.

Rich

Rich Jesse                        System/Database Administrator
rich.jesse_at_qtiworld.com           Quad/Tech International, Sussex, WI USA



-----Original Message-----

From: MacGregor, Ian A. [mailto:ian_at_SLAC.Stanford.EDU] Sent: Tuesday, January 27, 2004 7:34 PM
To: 'oracle-l_at_freelists.org'
Subject: [oracle-l] Re: Oracle HTTP Server Cross Site Scripting Vulnerabil lity

How many people actually run the HTTP server which comes with the database? Isn't that pleading for someone to commit mischief. It was too long ago that an SSL problem was announced also dealing with the HTTP server. The attack vector employs iSQL is that only available through the "database" HTTP server or can it be run via iAS.

Ian MacGregor
Stanford Linear Accelerator Center
ian_at_slac.stanford.edu



Please see the official ORACLE-L FAQ: http://www.orafaq.com

To unsubscribe send email to: oracle-l-request_at_freelists.org put 'unsubscribe' in the subject line.
--
Archives are at http://www.freelists.org/archives/oracle-l/
FAQ is at http://www.freelists.org/help/fom-serve/cache/1.html

-----------------------------------------------------------------
Received on Wed Jan 28 2004 - 09:07:45 CST

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US