RE: oracle account suddenly change to lock???

From: Mark W. Farnham <mwf_at_rsiz.com>
Date: Sat, 21 Nov 2009 11:15:51 -0500
Message-ID: <624D9E7BBB9B4A4EA4CCE6E4BF2EBD18_at_rsiz.com>



do you lock accounts after a certain number of connection attempts that are bad?

If so, this can be a symptom of a variety of denial of service attack where if they can see your server and happen upon some real user ids (possibly common id, for example for some off the shelf suite), and then they just make login attempts with any old wrong password enough times to lock the account.

The world is sometimes a nasty place.

Of course this a complete guess from my viewpoint, but something you can look into.

Regards,

mwf

-----Original Message-----

From: oracle-l-bounce_at_freelists.org [mailto:oracle-l-bounce_at_freelists.org] On Behalf Of dba1 mcc
Sent: Saturday, November 21, 2009 10:48 AM To: oracle-l_at_freelists.org
Subject: oracle account suddenly change to lock???

we have ORACLE 10GR2 on Linux server. More of account on our database will sudden change to "lock".

I check DB parameter "resource_limit" and it set to "false".

any ideal?

Thanks.       

--

http://www.freelists.org/webpage/oracle-l

--

http://www.freelists.org/webpage/oracle-l Received on Sat Nov 21 2009 - 10:15:51 CST

Original text of this message