1. 修復Oracle TNS 監聽器遠程中毒漏洞
1.1 修改監聽文件
vi $ORACLE_HOME/network/admin/listener.ora
# listener.ora Network Configuration File: /u01/app/oracle/product/11.2.0/db_1/network/admin/listener.ora
# Generated by Oracle configuration tools.
SID_LIST_LISTENER =
(SID_LIST =
(SID_DESC =
(GLOBAL_DBNAME = ods)
(ORACLE_HOME = /u01/app/oracle/product/11.2.0/db_1)
(SID_NAME = ods)
)
)
LISTENER =
(DESCRIPTION_LIST =
(DESCRIPTION =
(ADDRESS = (PROTOCOL = TCP)(HOST = IP或主機名)(PORT = 1521))
# (ADDRESS = (PROTOCOL = IPC)(KEY = EXTPROC1521)) --注釋掉,一般不會使用ipc,絕大部分應用使用tcp連接數據庫
)
)
ADR_BASE_LISTENER = /u01/app/oracle
# 單實例只需要新增下面這一行就OK
VALID_NODE_CHECKING_REGISTRATION_LISTENER=1
# RAC需要新增下面三行,有多少個LISTENER_SCAN監聽就添加幾個
VALID_NODE_CHECKING_REGISTRATION_LISTENER=ON
VALID_NODE_CHECKING_REGISTRATION_LISTENER_SCAN1=ON
REGISTRATION_INVITED_NODES_LISTENER_SCAN1=(添加rac節點的所有public IP,包括主機IP,VIP,SCANIP)
1.2 重新加載監聽
lsnrctl reload
lsnrctl reload listener_scan1 # RAC實例還需要執行該命令