Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Usenet -> c.d.o.server -> Re: Looking for Security book

Re: Looking for Security book

From: Paul Drake <drak0nian_at_yahoo.com>
Date: 5 Feb 2003 17:16:12 -0800
Message-ID: <1ac7c7b3.0302051716.7fff98ff@posting.google.com>


Natalka Rosalia Maria Roshak <nroshak_at_fas.harvard.edu> wrote in message news:<b1rp0o$mt7$1_at_news.fas.harvard.edu>...
> Hi,
>
> I'm looking for a good book on Oracle security. Anyone have any
> recommendations?
>
> TIA,
> Natalka

Oracle Security Handbook by Aaron Newman, Marlene Theiault ISBN 0-07-2113325
Oracle Press - Osborne

Oracle Security: Step-by-Step by Pete Finnigan ISBN 0-9724273-4-1 SANS - http://store.sans.com - which does use SSL. This is more of a practical checklist, not really reading material. Lots of good links.

Pentest paper, "Exploting and Protecting Oracle" by Pete Finnigan Pentest-limited -
http://www.pentest-limited.com/oracle-security.htm www.pentest-limited.com/oracle-security.pdf

mailing lists.

Secure the operating system first - before you install the oracle software.
So whatever os you're running on - get a good system administration.security text for it.

SANS has guides for Solaris, Windows, etc.

Good luck finding a way of determining when your system and database is secure.

Gaja described a symptom of "Compulsive Tuning Disorder" in the Performance Tuning 101 book. The only thing that is "too paranoid" to me is not letting users log into the database. Everything else is negotiable.

Paul Received on Wed Feb 05 2003 - 19:16:12 CST

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US