2.2.4 Ensure 'LOCAL_LISTENER' Is Set Appropriately

Information

The TNS poisoning attack allows to redirect TNS network traffic to another system by registering a listener to the TNS listener. This attack can be performed by unauthorized users with network access. By specifying the IPC protocol it is no longer possible to register listeners via TCP/IP.

Solution

To remediate this setting execute the following SQL statement. ALTER SYSTEM SET LOCAL_LISTENER='(DESCRIPTION=(ADDRESS=(PROTOCOL=IPC)(KEY=REGISTER)))' SCOPE = BOTH;

See Also

https://workbench.cisecurity.org/files/601