Home » RDBMS Server » Security » Oracle exposed on a Webserver
|
|
|
Re: Oracle exposed on a Webserver [message #148345 is a reply to message #148215] |
Wed, 23 November 2005 14:16  |
stry_cat
Messages: 3 Registered: November 2005
|
Junior Member |
|
|
Frank Naude wrote on Wed, 23 November 2005 02:55 | Hi,
The best would be to put your webservers within a secure zone (DMZ) and config the firewalls so that only the secure zone can connect to your database servers.
|
Well as long as we can access the db servers from anywhere within our network, this sounds like a possible solution.
Quote: |
If you don't, the consequences could be severe. For example, a hacker gets into the webserver, see your Oracle userid/password in one of those PHP/Perl scripts, connect to it and sell the data to your companies competitors.
|
I don't see how the DMZ proposal will help in this case. If the hacker gets into the webserver and sees the Oracle userid/password won't he be able to access the data b/c he's in the secure zone? Don't you need to prevent him from hacking the webserver in this case? Does this DMZ secure zone idea stop that?
|
|
|
Goto Forum:
Current Time: Thu May 01 19:49:14 CDT 2025
|