Database Networking (MOSC)

MOSC Banner

TNS Listener Poison Attack using VNCR

edited Nov 19, 2015 5:40PM in Database Networking (MOSC) 22 commentsAnswered ✓

For TNS Poisoning (Oracle Security Alert for CVE-2012-1675), Oracle first recommended implementing "Class of Secure Transport" (COST) to handle the instance registrations, but now "Starting with Oracle Database Version 11.2.0.4 and Oracle Database 12c (12.1.0.1), the screening of service registration requests from database instances is performed using the Oracle Listener inherent "Valid Node Checking for Registration" (VNCR) feature. Oracle recommends using the "VNCR" feature in 11.2.0.4 and 12c as an alternative to COST if the implementation is only to regulate database service registration requests with Listeners."

For 12c: OraAgent is automatically handling the setup.  For 11.2.0.4, this is not being done and I cannot find a document detailing the listener.ora changes (and possibly any init parameter changes) to prevent TNS Listener Poison Attack using VNCR for Standalone/Restart and for RAC.

Tagged:

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center