Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Usenet -> c.d.o.server -> Re: How to secure Personal Oracle in the Network ?

Re: How to secure Personal Oracle in the Network ?

From: Billy Verreynne <vslabs_at_onwe.co.za>
Date: Mon, 11 Mar 2002 07:15:37 GMT
Message-ID: <3c8c56db.253692654@news.saix.net>


xtanto_at_hotmail.com (Krist) wrote:

>I want to install Personal Oracle (PO) in win98 PC which is connected
>in a windows 2000 network. I don't want any other user access my data
>in PO except myself.
>
>Can / How can I prevent the Domain Administrator and others from
>accessing my data ?

Do not run an Oracle listener.

Delete the file LMSCRIPT.EXE (? - think it is called that) from the Windows directory. This will prevent the domain admin from running automated domain login scripts on your machine (which could be used to access whatever files you have on your system).

Do not share any folders or drives.

Do not run the Windows Admin client software (SMS) on your system (it can even allow the domain admin to take control of the GUI on your machine).

When leaving for home, powerdown your machine, unplug the the network cable, lock the office.

Even so.. I'm sure that I can still hack into your machine easily via any of the Outlook Express, IE and other holes you have on that Win98 machine of yours (the wonders of ActiveScripting). So unless you go and harden your Win98 machine, it is pretty much an open target for a real hack attempt, especially on a LAN (which gives most users a sense of false security which they usually will not have on the net).

You need to decide how sensitive that data is.. and then question not only the choice of your operating system, but also look at physical access control and many other security aspects. Social engineering is one of the prime methods used to gain access. No amount of software security can prevent a "mental" security lapse.

--
Billy


--
Billy
Received on Mon Mar 11 2002 - 01:15:37 CST

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US