Re: ps shows user/password under Unix - SU

From: B C Zygmunt <bzy_at_ornl.gov>
Date: Thu, 10 Feb 1994 12:53:09 GMT
Message-ID: <1994Feb10.125309.22422_at_ornl.gov>


I agree with Lee Parsons whose reply to this question included:

	If you have oracle userid/passwords normally sitting unencrypted 
	someplace then you have a problem designed into your system. By taking
	out ps your not removing the problem only covering it up. The only way
	to fix the problem is to change the design of the system/application.


At our installation, front-end programs are going to be written for all Oracle tools (such as SQL*Plus) so that if a password is entered on the command line an error occurs. When this happens, the history file (which would reveal the password) will also be deleted.

Beverly  

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 

+ + +
+ Beverly Cather Zygmunt + Phone: (615) 574-1007 +
+ Oak Ridge National Laboratory + email: zygmuntbc_at_ornl.gov +
+ Building 4500N, MS 6274 + bzy_at_ornl.gov +
+ Oak Ridge, TN 37831-6274 + +
+ + +
+ + +
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+ +
+ "If you torture your data long enough, they will tell you what +
+ you want to hear." -- James L. Mills +
+ +
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Received on Thu Feb 10 1994 - 13:53:09 CET

Original text of this message