Explore top 10 tips to secure your open-source projects now. Read More
×The phpMyAdmin developers have announced the release of version 3.3.9.1 and 2.11.11.2 of their database administration tool, security updates that fix a path disclosure vulnerability. According to the developers, when the README, ChangeLog or LICENSE files are removed from their original location, the scripts used to display these files can show their full path, possibly leading to further attacks.. All versions previous to 3.3.9.1 and 2.11.11.2 are said to be affected. While the developers consider the vulnerability to be non-critical, they still advise all users to upgrade as soon as possible. Alternatively, users can apply the provided patches. The link for this article located at H Security is no longer available. . The maintainers of phpMyAdmin have released new versions 3.3.9.1 and 2.11.11.2 to address a critical path disclosure vulnerability. Users are advised to upgrade promptly!. phpMyAdmin Security, Database Tool Fix, Path Exposure Issue. . LinuxSecurity.com Team
As Oracle prepares to dump a passel of 81 security fixes on its user base -- including seven critical patch updates (CPUs) for its database product -- many database administrators are preparing to patch their Oracle database platforms accordingly. . But if recent numbers from the Independent Oracle Users Group annual security survey are an accurate barometer, there are still plenty of others who will sit on the CPUs due out next week for a year or longer. Security experts believe organizations first need to improve these numbers by instituting patching best practices for databases. "I find it funny that there are patches everywhere else that are applied on a regular basis to machines like desktops and so on, but it is still not a general practice for the databases," says Michelle Malcher, director of education for IOUG and a DBA and team lead at a Chicago-based financial firm. According to a recent survey of its members, only 37 percent of organizations patch their systems within the same three-month cycle that CPUs are released. Approximately 28 percent either take a year or more to patch, have never applied a CPU, or don't know how long it takes them to patch their databases. The link for this article located at Dark Reading is no longer available. . Streamlining your Oracle database patching is vital for security and compliance. Follow best practices for updates, assessments, and user training for success. Oracle Database Patching, Database Protection, Patch Management Strategies. . LinuxSecurity.com Team
If you're using MySQL, there are some easy things you can do to secure your systems and significantly reduce the risk of unauthorised access to your sensitive data. The most valuable asset for technology-based organisations is usually the customer or product information in their databases. And so, a critical part of database administration in such organisations consists of securing these databases against outside attack and hardware/software failures. In most cases, hardware and software failures are handled through a data backup regimen. Most databases come with built-in tools to automate the entire process, making this aspect of the job relatively painless and error-free. What's not so simple, however, is the second half of the puzzle: making sure that outside hackers can't get into the system and either steal or damage the information contained therein. And unfortunately, there usually isn't an automated way to solve this problem; rather, it requires you, the administrator, to manually put in place roadblocks and obstacles to trip up would-be hackers and to ensure that your company's data stays secure. . The link for this article located at BuilderAU is no longer available. . Enhance MySQL data security by implementing strong authentication, encryption, user privilege limitation, regular backups, firewall setup, and more. MySQL Security, Database Protection, Data Security Steps. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.