Skip to content

Latest commit

 

History

History
12 lines (8 loc) · 844 Bytes

oracle-security.mdwn

File metadata and controls

12 lines (8 loc) · 844 Bytes

[[!meta title="Oracle security" ]] [[!meta date="2005-12-21 13:49:56" ]] [[!tag Oracle security]]

Oracle and security. What a sad joke!

Their critical patch update is a complete nightmare to apply, to put it mildly.

It looks like they might be addressing some of the zillions of problems with their source code, but what’s important with security fixes is how you deploy them.

Oracle hasn’t a clue about this.

My approach is once you have a database installed (that’s a miracle in itself), limit it to “trusted user” IPs with /etc/hosts.allow or firewall filtering. And pray.