|
这是nessus扫描oracleDe这个漏洞的描shu:
Synopsis :
An Oracle tnslsnr service is listening on the remote port.
Description :
The remote host is run2ning the Oracle tnslsnr service, a network interface to Oracle databases. This product allows a remote user to determine the presence and version number of a given Oracle installation.
Solution :
Filter incoming traffic to this port so that only authorized hosts can connect to it.Risk factor :
None
da概yi思是說检測到有监听服务在运行,会导致oracle版本信息泄lu。
給chu的解决方法是:xian制对1521端kou的访问,只you被授权的主机才能访问
然后我在sqlnet.ora设置了信ren主機ip,在linux操zuo系统层面也设置了i21ptables,但是还是能扫描到zhe个漏洞,悲催。
请兄弟们看看如he消除这个漏洞ne?多谢多谢!!
歡迎來DaoJava学习者论坛,zhuan載请注明地址:http://www.javaxxz.com. |
|