OK so this story aint new and these guys have some how got some publicity thanks to the e-week and are basking in the 25 sec fame about the Oracle worm issue.
You'd be nuts to have your DBA role to public and thereby with the *vulnerable* version of CTXSYS schema as well (so you've been pretty slack in not complying with the Oracle security patches!) but anyways. See here what it does.
Anyways like I said, you just don't keep all accounts unlocked and lot's of things which Oracle also recommends (in it's Nov letter to customers) is a good advice.
Comments
Post a Comment