Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Mailing Lists -> Oracle-L -> Re: auditing is my friend

Re: auditing is my friend

From: Pete Finnigan <oracle_list_at_peterfinnigan.demon.co.uk>
Date: Wed, 08 Oct 2003 07:49:25 -0800
Message-ID: <F001.005D2672.20031008074925@fatcity.com>


Hi Paul,

Have a look at the paper i wrote for security focus a few months ago, called "An Introduction to simple Oracle auditing" - there is a link to it on my site - http://www.petefinnigan.com/orasec.htm - its the second paper on there. It is not in-depth but concentrates on the benefits of just turning audit on and gives examples of SQL to find a few abuses, such as logins out of hours, users sharing accounts, attempts to use accounts that do not exist etc - as i say just basic ideas. I agree its well worth just turning audit on and seeing what can be learned from just audit session for instance!.

Kind regards

Pete
--

Pete Finnigan
email:pete_at_petefinnigan.com
Web site: http://www.petefinnigan.com - Oracle security audit specialists Book:Oracle security step-by-step Guide - see http://store.sans.org for details.

--

Please see the official ORACLE-L FAQ: http://www.orafaq.net
--

Author: Pete Finnigan
  INET: oracle_list_at_peterfinnigan.demon.co.uk

Fat City Network Services    -- 858-538-5051 http://www.fatcity.com
San Diego, California        -- Mailing list and web hosting services
---------------------------------------------------------------------
To REMOVE yourself from this mailing list, send an E-Mail message to: ListGuru_at_fatcity.com (note EXACT spelling of 'ListGuru') and in the message BODY, include a line containing: UNSUB ORACLE-L (or the name of mailing list you want to be removed from). You may also send the HELP command for other information (like subscribing). Received on Wed Oct 08 2003 - 10:49:25 CDT

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US