From: Duret, Kathy <>
Date: Fri, 3 Dec 2004 13:18:31 -0600
Amen to that! We have that all over here.

Then when you try to change your password all these rogue reports/macros/excel things break and they all blame you......

I am going through a migration now and am going through this right now.

You should be aware that program such as MS Access and such frequently store the user name/passwords in the connect strings in plain text. Programs such as Access can be very valuable in the hands of the right user for reporting, moving data etc...however, all too often it ends up in the hands of very evil users who write really weird macros which do things like put your entire 20GB database in an Excel file every night.=20

IMHO the real security issue is with the oracle client install. Sorry if the
following is too obvious... You need to be certain that the DBA utilities are=20
never installed and that the sqlnet config can't be changed so as to avoid=20
system probing. And everyone has changed all default passwords, right? ;-)
Then the remaining issue would be account administration...what your password=20
controls are...(length, content, expiration, sharing of accounts...).


|Hi All,

|Can anybody share what are database security issues when using ODBC
(set up
|on client PCs).




