RE: dba_audit_session

From: Powell, Mark <mark.powell2_at_hp.com>
Date: Fri, 8 May 2015 15:46:36 +0000
Message-ID: <1E24812FBE5611419EFAFC488D7CCDD128175554_at_G4W3290.americas.hpqcorp.net>



Someone else may recognize what causes these messages but until someone else posts you should be able to pull the IP address from the audit information for the failed connections and verify that the failed attempts are all coming from within your environment or from outside. If inside you can look more closely at what the server in question is running?

From: oracle-l-bounce_at_freelists.org [mailto:oracle-l-bounce_at_freelists.org] On Behalf Of Chris King Sent: Thursday, May 07, 2015 11:47 AM
To: Oracle-l Digest Users
Subject: Fw: dba_audit_session

dbconsole has reported that "There have been 1068 failed login attempts in the last 30 minutes." So I did a select on dba_audit_sessions where returncode !=0 and found that in every case, the os_username is oracle, the returncode is 1017 (invalid username/password).. but.. and here's my question.. the username field of dba_audit_session varies and does not contain database username. Some of the 70 different values are "MSGBOX(" "HTTPS:" ".EXAMPLE.COM" "AND1=1".

How can I further track down what is happening?

Note that this has only begun happening since I applied COST to restrict instance registration in Oracle RAC (Doc ID 1340831.1), so could be related, but it's not clear how the change would cause this.

Thanks in advance all!

--
http://www.freelists.org/webpage/oracle-l
Received on Fri May 08 2015 - 17:46:36 CEST

Original text of this message