Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Mailing Lists -> Oracle-L -> Database security

Database security

From: <Jared.Still_at_radisys.com>
Date: Tue, 16 Mar 2004 14:36:31 -0800
Message-ID: <OFDE70491C.BF913BA8-ON88256E59.007A38C4-88256E59.007C1B20@radisys.com>


List,

Here in the midst of Sarbanes Oxley, I've been pondering methods that might be used to prevent a system administrator from connecting to any databases running on that box.

I know that it is possible to setup Oracle on Windows so that without a password, you cannot logon to the database as sysdba.

eg. sqlplus "/ as sysdba" will require a password.

The caveat to this is that the SA can simply:

That won't get you SYSDBA, but it will get you DBA, which is probably enough
for any nefarious activities.

On *nix it is a bit different of course. Anyone with root can simply su to oracle.

I have been perusing Pete Finnigan's "Oracle Security Step-by-Step" but have
not yet found information pertaining to this particular topic, other than revoking
privs from the DBA account. That action is not applicable here, as the team of
DBA's consists of me by myself.

And TIA Mladen, but I already know how it works on unix, and that MS is the
dark side of the force, but is unfortunately what I have to live with.

Jared



Please see the official ORACLE-L FAQ: http://www.orafaq.com

To unsubscribe send email to: oracle-l-request_at_freelists.org put 'unsubscribe' in the subject line.
--
Archives are at http://www.freelists.org/archives/oracle-l/
FAQ is at http://www.freelists.org/help/fom-serve/cache/1.html
-----------------------------------------------------------------
Received on Tue Mar 16 2004 - 16:33:06 CST

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US