Monday, 24 August 2020

Self-signed TLS/SSL certificate Vulnerability - Weblogic 12.2.1.4

Vulnerability Title: Self-signed TLS/SSL certificate

Service Port:4443

Service Name: HTTPS

Service Protocol: tcp

Vulnerability Description: 

The server's TLS/SSL certificate is self-signed. Self-signed certificates cannot be trusted by default, especially because TLS/SSL man-in-the-middle attacks typically use self-signed certificates to eavesdrop on TLS/SSL connections.


Solution:

Obtain a new TLS/SSL server certificate that is NOT self-signed and install it on the server or remove the demo certificates.

remove these demo.cert and DemoTrust.jks certificates and check:


$MWH/wlserver/server/lib/DemoTrust.jks

$MWH/wlserver/server/lib/demo.cert



Click Jacking Vulnerability - Weblogic 12.2.1.4

Vulnerability Title: Click Jacking

Service Port:4443

Service Name: HTTPS

Service Protocol: tcp

Vulnerability Description: 

Clickjacking, also known as a UI redress attack, is a method in which an attacker uses multiple transparent or opaque layers to trick a user into clicking a button or link on a page other than the one they believe they are clicking. Thus, the attacker is "hijacking" clicks meant for one page and routing the user to an illegitimate page.


Vulnerability Solution:Use HTTP X-Frame-Options. Send the HTTP response headers with X-Frame-Options that instruct the browser to restrict framing where it is not allowed.

 

1. Apply the Patch 30418565

 Patch 30418565 FORMS LISTENER SERVLET NOT GENERATING X-FRAME-OPTIONS HTTP HEADER

 

Add SAMEORIGIN option with X-Frame-Options optin in Run-time and Staging httpd.conf

--  X-Frame-Options is available at line 1033


Header always append X-Frame-Options SAMEORIGIN


2.Run-time directory:


$DOMAIN_HOME/config/fmwconfig/components/OHS/instances/<componentName>/httpd.conf


3.Staging directory:


$DOMAIN_HOME/config/fmwconfig/components/OHS/<componentName>/httpd.conf


Restart the service and check.

Sunday, 23 August 2020

Browsable Web Directory Vulnerability - Weblogic 12.2.1.4

Vulnerability Title:Browsable web directory 

Service Port:4443

Service Name:HTTPS

Service Protocol:tcp

Vulnerability Description: A web directory was found to be browsable, which means that anyone can see the contents of the directory. These directories can be found: 

 * via page spidering (following hyperlinks), or

 * as part of a parent path (checking each directory along the path and searching for ""Directory Listing"" or similar strings), or

 * by brute forcing a list of common directories.

 Browsable directories could allow an attacker to perform a directory traversal attack by viewing ""hidden"" files in the web root, including CGI scripts, data files, or backup pages."

Vulnerability Proof: https://<*.*,*.*>:4443/OracleHTTPServer12c_files/ 


Solution:

Remove the "Indexs" option from Run-time & Staging httpd.conf 

--check @ line # 241


From: Options Indexes FollowSymLinks

To: Options FollowSymLinks


1.Run-time directory:

$DOMAIN_HOME/config/fmwconfig/components/OHS/instances/<componentName>/httpd.conf


2.Staging directory:

$DOMAIN_HOME/config/fmwconfig/components/OHS/<componentName>/httpd.conf


You should add the following value in [default] section of the formsweb.cfg


3.$DOMAIN_HOME/config/fmwconfig/servers/WLS_FORMS/applications/formsapp_12.2.1/config/formsweb.cfg


#

#X-Frame-Options to Resolve Click-Jacking

#

Set_X_Frame_Options=true


If you are not planing for https then comment out these lines in both Run-time and Staging httpd.conf files:


# Include the SSL definitions and Virtual Host container

include "ssl.conf"------------------------------->Comment out this.


....

IncludeOptional "moduleconf/*.conf" ------------------------------->Comment out this.



Restart the services and then test.


Weblogic 12.2.1.4 Admin Server Default Port Change

 

Please make the below changes to update the port in FMW 12.2.1.4:


Step 1: Take the backup of the below files:


$DOMAIN_HOME/config/fmwconfig/servers/AdminServer/applications/em/META-INF/emoms.properties

$DOMAIN_HOME/sysman/state/targets.xml

$DOMAIN_HOME/bin/stopManagedWebLogic.sh

$DOMAIN_HOME/bin/startManagedWebLogic.sh

$DOMAIN_HOME/bin/stopWebLogic.sh


Step 2: Navigate to the Weblogic Admin Console > Environments > Servers > AdminServer > Configuration Tab > General Sub Tab > now change the listen port from 7001 to 7010 and save the changes


Step3: Update the Admin Port(7001 to 7010) in the below files:


$DOMAIN_HOME/config/fmwconfig/servers/AdminServer/applications/em/META-INF/emoms.properties

$DOMAIN_HOME/sysman/state/targets.xml

$DOMAIN_HOME/bin/stopManagedWebLogic.sh

$DOMAIN_HOME/bin/startManagedWebLogic.sh

$DOMAIN_HOME/bin/stopWebLogic.sh


Step 4: Run $DOMAIN_HOME/bin/setDomainEnv.sh


Step 5: Restart your Admin Server and test the Weblogic Console URL and EM Console URL.


Admin Server Failure To Start With Error BEA-000362 Server failed

There are 1 nested errors:

weblogic.management.DeploymentException: java.io.IOException: Error from fcntl() for file locking, Resource temporarily unavailable, errno=11


Solution: 

Remove these *.lok file and then try to start

$DOMAIN_HOME/edit.lok
$DOMAIN_HOME/config/lifecycle-config.xml.lok
$DOMAIN_HOME/config/ovd/default/ovd.lok
$DOMAIN_HOME/servers/AdminServer/tmp/AdminServer.lok
$DOMAIN_HOME/servers/WLS_FORMS/tmp/WLS_FORMS.lok
$DOMAIN_HOME/servers/WLS_REPORTS/tmp/WLS_REPORTS.lok
$DOMAIN_HOME/tmp/<filename>.lok

find . -name "*.lok" -exec rm -f {} \;


$DOMAIN_HOME/servers/AdminServer/data/store/default/_WLS_ADMINSERVER000000.DAT
$DOMAIN_HOME/servers/AdminServer/data/store/diagnostics/WLS_DIAGNOSTICS000000.DAT
$DOMAIN_HOME/servers/WLS_FORMS/data/store/default/_WLS_WLS_FORMS000000.DAT
$DOMAIN_HOME/servers/WLS_FORMS/data/store/diagnostics/WLS_DIAGNOSTICS000000.DAT
$DOMAIN_HOME/servers/WLS_REPORTS/data/store/default/_WLS_WLS_REPORTS000000.DAT
$DOMAIN_HOME/servers/WLS_REPORTS/data/store/diagnostics/WLS_DIAGNOSTICS000000.DAT



find . -name "*.DAT" -exec rename '.DAT' '.DAT_OLD' {} \;

Saturday, 20 June 2020

Rolling Upgrade Error in Script

Few months back we were upgrading our AIX based database from 11gR2 [11.2.0.4] to 12c [12.2.0.1] by rolling upgrade. When we run physru_v3.sh script it is giving error:


WARN: The last execution of this script either exited in error or at the
-e user's request. At this point, there are three available options:

-e 1) resume the rolling upgrade where the last execution left off
-e 2) restart the script from scratch
-e 3) exit the script
-e
Option (2) assumes the user has restored the primary and physical
-e standby back to the original configuration as required by this script.

-e Enter your selection (1/2/3):
-e Sep 24 11:17:59 2019 [0-1] not a valid option - ''

-e Enter your selection (1/2/3):
-e Sep 24 11:17:59 2019 [0-1] not a valid option - ''

-e Enter your selection (1/2/3):
-e Sep 24 11:17:59 2019 [0-1] not a valid option - ''


Solution:

The issue is caused by the following setup:
in physru_v3.sh script change first line from below and then rerun the script

#!/bin/sh

to

#!/bin/bash  <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<

Reports Server Component Status in REPORTS 12C

How to check report server component status as we previously check by opmnctl?


Due to decommissioning of opmn from 12c, that option is not available. There are two ways to check, unfortunately none of them as simple as opmn:

1. Run the command $DOMAIN_HOME/reports/bin/rwdiag.sh -findall 

If the reports server appears in the output, then it is up and running. If it does not appear, it is down
or

2. Check the REPORT Server components logs.