Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Usenet -> c.d.o.server -> Oracle Default Users and Security

Oracle Default Users and Security

From: Pete Finnigan <pete_at_peterfinnigan.demon.co.uk>
Date: Fri, 2 Nov 2001 23:36:50 +0000
Message-ID: <jlZpvqAS4y47Ewym@peterfinnigan.demon.co.uk>


Hi all

If anyone is interested i have put together a list of the all default Oracle users i can find and their default passwords and hashes 109 so far and i still have some areas to look at.

I have found in my recent work on Oracle security audits that a major area of concern is the amount of databases where there still exists at least one default account where the password is still a default one.

So i have created a table at http://www.pentest-limited.com/defaultuser. htm ( or you can go to the site and its in the technical and white papers section ) that has the users and passwords and hashes and a simple SQL script generated from this list that can be run as a DBA to check if any defaults are still set easily.

regards,
Pete

-- 
Pete Finnigan
IT Security Consultant
PenTest Limited

Office  01565 830 990
Fax     01565 830 889
Mobile  07974 087 885

pete.finnigan_at_pentest-limited.com

www.pentest-limited.com
Received on Fri Nov 02 2001 - 17:36:50 CST

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US