extproc.exe from an Audit
Hi all,
We have audited and the auditors noted this finding:
External Procedure executable (extproc) is found
• \app\test\product\11.2.0\dbhome_1\bin\extproc.exe
External Procedure executable (extproc) is found
• Configuration file for:
o ExtProc=tnsnames.ora
o ExtProc SID=CLREXTPROC
Extproc is intended only to accept requests from the Oracle database server but local users can still execute commands bypassing this restriction. No authentication takes place when extproc is asked to load a library and execute a function. This allows local users to run commands as the Oracle user.
They recommend the following actions:
ALERT57-128898.pdf" name="contextTextUrl_1386076118728" title="Click (or CTRL+Click if using Firefox) to view" id="contextTextUrl_1386076118728">http://www.oracle.com/technetwork/topics/security/2003