Pete Finnigan's Oracle Security Forum (http://www.petefinnigan.com/forum/yabb/YaBB.cgi)
Oracle Security >> Oracle Security >> Newbie question on Oracle 9i ORA_DBA
(Message started by: Pete Finnigan on Nov 17th, 2005, 4:19am)

Title: Newbie question on Oracle 9i ORA_DBA
Post by Pete Finnigan on Nov 17th, 2005, 4:19am
Being new to Oracle, I apologize for a question, that I pose, while it probably is hidden somewhere in the standard Oracle-docs.
We are talking Oracle 9i version 9.2.0.2 here.
Database setup on a XP-home machine.
User on another machine (in the same network) with XP-pro creates a local group 'ORA_DBA' , makes himself a member of it, and then he can connect as DBA to the database on the other machine, no passwords asked.
Question: Is there a way to stop this idiosyncracy? Help please, point me in the direction where to look. Straight answers are also welcome of course ;)

Title: Re: Newbie question on Oracle 9i ORA_DBA
Post by Pete Finnigan on Nov 17th, 2005, 7:39pm
Yes - disable Simple File Sharing. See "Database Servers on Windows XP and the Unintended Consequences of Simple File Sharing" at www.databasesecurity.com/dbsec-papers.htm - (broken link)
,
David Litchfield

Title: Re: Newbie question on Oracle 9i ORA_DBA
Post by Pete Finnigan on Nov 18th, 2005, 3:41am
Thanx a lot, worked like a charm!
Nice paper also btw!

FYI I am just visiting Indonesia for some IT volunteer work, and they jumped upon me with this question. I knew there would be some 'simple' answer, I'm just not on speaking terms with version 9 of Oracle...

Thanx again!



Powered by YaBB 1 Gold - SP 1.4!
Forum software copyright © 2000-2004 Yet another Bulletin Board