Solved

OS admin access on an oracle system

Posted on 2014-03-03
3
451 Views
Last Modified: 2014-03-10
can anyone give some examples on what kind of risks to an oracle database would arise were a hacker to gain admin (on windows) or root (on linux) access to the server hosting the oracle software and database files? what could they do with such access to affect the usual confidentiality/availability/integrity of such a database? Just trying to get my head around how OS and server apps can affect one another..
0
Comment
Question by:pma111
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 74

Accepted Solution

by:
sdstuber earned 167 total points
ID: 39901421
they could do anything they wanted to the database.

including dropping it or altering the data anyway they wanted.
they could also corrupt the binaries that run the database too or corrupt the files.

If the hacker has access to the storage holding the backups then they could steal and/or corrupt the data completely so it could never be recovered.

Please address previous question that was closed inappropriately
0
 
LVL 38

Assisted Solution

by:Geert Gruwez
Geert Gruwez earned 167 total points
ID: 39901964
if they got to that point, then basically it's game over

mind you, if they knew a little about the system, they could probably order tons of articles and have you paying for it

there are companies out there, which do "attack and penetration testing"
those are the ones who will tell you what holes you have in the system

it usually costs less than a few hackers ...
0
 
LVL 23

Assisted Solution

by:David
David earned 166 total points
ID: 39902174
Consider having a jump or satellite server, with secure shell tunneling required to reach the actual database servers.
0

Featured Post

Want Experts Exchange at your fingertips?

With Experts Exchange’s latest app release, you can now experience our most recent features, updates, and the same community interface while on-the-go. Download our latest app release at the Android or Apple stores today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Shell script to create broker configuration file using current broker Configuration, solely for purpose of backup on Linux. Script may need to be modified depending on OS-installation. Please deploy and verify the script in a test environment.
Your data is at risk. Probably more today that at any other time in history. There are simply more people with more access to the Web with bad intentions.
This video explains at a high level about the four available data types in Oracle and how dates can be manipulated by the user to get data into and out of the database.
This videos aims to give the viewer a basic demonstration of how a user can query current session information by using the SYS_CONTEXT function

624 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question