Re: Fw: OT - Getting fired for database oops
- From: Stephen Booth <stephenbooth.uk@xxxxxxxxx>
- To: dbvision@xxxxxxxxxxxx
- Date: Wed, 27 May 2009 14:23:24 +0100
2009/5/27 Nuno Souto <dbvision@xxxxxxxxxxxx>: > > > Which is a tricky proposition > at best: how often should one check and for how long? Daily (or more/less often depending on your level of paranoia), as long as the server is in operation. The last place where I was doing direct support of the databases all key settings files were checked every day (using diff). Basically we'd have a 'clean' copy and each day a script would be run by cron that would compare the live file with a 'clean' copy. If there were any differences an email was sent to the root mailbox and thence forwarded to the ops mailbox. If the changes were authorised the changed file would be copied over to the 'clean' copy, otherwise the changed file would be quarantined and the file refreshed with a known safe version (most of our settings files were version controlled in SCCS so we'd just revert to an earlier version, then manually run the check script for that file, if not then we'd copy back the 'clean' copy). Additionally any legitimate changes had to go through the change control system and the change would have the change control number above it in a comment line so we could quickly confirm if a change was legitimate. It's not perfect, it could take up to a day to identify a change, but it did the job. No system is perfectly secure, no piece of software is guaranteed bug free. You just have to do your best and be resigned to the fact that your users are probably your biggest security hole. Stephen -- It's better to ask a silly question than to make a silly assumption. http://stephensorablog.blogspot.com/ | http://www.linkedin.com/in/stephenboothuk | Skype: stephenbooth_uk Apparently I'm a "Eierlegende Woll-Milch-Sau", I think it was meant as a compliment. -- http://www.freelists.org/webpage/oracle-l
- References:
- Re: Fw: OT - Getting fired for database oops
- From: Jared Still
- Re: Fw: OT - Getting fired for database oops
- From: Jack van Zanen
- RE: Fw: OT - Getting fired for database oops
- From: Andre van Winssen
- Re: Fw: OT - Getting fired for database oops
- From: Jared Still
- RE: Fw: OT - Getting fired for database oops
- From: Andre van Winssen
- Re: Fw: OT - Getting fired for database oops
- From: Nuno Souto
- Re: Fw: OT - Getting fired for database oops
- From: Andre van Winssen
- Re: Fw: OT - Getting fired for database oops
- From: Nuno Souto
- RE: Fw: OT - Getting fired for database oops
- From: Tanel Poder
- Re: Fw: OT - Getting fired for database oops
- From: Nuno Souto
- Re: Fw: OT - Getting fired for database oops
Other related posts:
- » Fw: OT - Getting fired for database oops - Guang Mei
- » Re: Fw: OT - Getting fired for database oops - Andrew Kerber
- » Re: Fw: OT - Getting fired for database oops - Jared Still
- » Re: Fw: OT - Getting fired for database oops - Rich Jesse
- » Re: Fw: OT - Getting fired for database oops - S. Anthony Sequeira
- » Re: Fw: OT - Getting fired for database oops - Yong Huang
- » Re: Fw: OT - Getting fired for database oops - Adric Norris
- » Re: Fw: OT - Getting fired for database oops - Jared Still
- » Re: Fw: OT - Getting fired for database oops - Rich Jesse
- » Re: Fw: OT - Getting fired for database oops - Jared Still
- » Re: Fw: OT - Getting fired for database oops - Tony van Lingen
- » RE: Fw: OT - Getting fired for database oops - Joel.Patterson
- » Re: Fw: OT - Getting fired for database oops - Thomas Day
- » Re: Fw: OT - Getting fired for database oops - Jared Still
- » Re: Fw: OT - Getting fired for database oops - Ravi Gaur
- » RE: Fw: OT - Getting fired for database oops - SHEEHAN, JEREMY
- » RE: Fw: OT - Getting fired for database oops - Bobak, Mark
- » Re: Fw: OT - Getting fired for database oops - Jared Still
- » Re: Fw: OT - Getting fired for database oops - Thomas Day
- » Re: Fw: OT - Getting fired for database oops - Jack van Zanen
- » Re: Fw: OT - Getting fired for database oops - Howard Latham
- » RE: Fw: OT - Getting fired for database oops - Andre van Winssen
- » Re: Fw: OT - Getting fired for database oops - Jared Still
- » RE: Fw: OT - Getting fired for database oops - Andre van Winssen
- » RE: Fw: OT - Getting fired for database oops - Tanel Poder
- » Re: Fw: OT - Getting fired for database oops - Nuno Souto
- » Re: Fw: OT - Getting fired for database oops - Niall Litchfield
- » Re: Fw: OT - Getting fired for database oops - Jared Still
- » Re: Fw: OT - Getting fired for database oops - Andre van Winssen
- » Re: Fw: OT - Getting fired for database oops - Nuno Souto
- » RE: Fw: OT - Getting fired for database oops - Tanel Poder
- » RE: Fw: OT - Getting fired for database oops - Bobak, Mark
- » Re: Fw: OT - Getting fired for database oops - Nuno Souto
- » Re: Fw: OT - Getting fired for database oops - Stephen Booth
- » Re: Fw: OT - Getting fired for database oops - Andre van Winssen
- » Re: Fw: OT - Getting fired for database oops - Connor McDonald
- » RE: Fw: OT - Getting fired for database oops - Tanel Poder
- » RE: Fw: OT - Getting fired for database oops - Andre van Winssen
- » Re: Fw: OT - Getting fired for database oops - Frits Hoogland
- » Re: Fw: OT - Getting fired for database oops - Nuno Souto