From JTESTA@longaberger.com Mon, 27 Aug 2001 12:23:57 -0700 From: "JOE TESTA" Date: Mon, 27 Aug 2001 12:23:57 -0700 Subject: Re: FW: database upgrade policy? Message-ID: MIME-Version: 1.0 Content-Type: text/plain I couldnt get it to work for anyone other than someone in the dba group already on linux.  if you're in the dba group you can connect / as sysdba anyways, so i guess i'm missing where the security hole is.   joe >>> Rajendra.Jamadagni@espn.com 08/23/01 04:41PM >>>Okay have a look at bug 1919536, it allows a user to log in as sysdba whenusing sqlplus in 9i.Initial testing on our system proves that this is true, luckily the db islocked down except for sys admin and dba group.Raj______________________________________________________Rajendra Jamadagni        MIS, ESPN Inc.Rajendra dot Jamadagni at ESPN dot comAny opinion expressed here is personal and doesn't reflect that of ESPN Inc.QOTD: Any clod can have facts, but having an opinion is an art !*********************************************************************2This e-mail message is confidential, intended only for the named recipient(s) above and may contain information that is privileged, attorney work product or exempt from disclosure under applicable law. If you have received this message in error, or are not the named recipient(s), please immediately notify corporate MIS at (860) 766-2000 and delete this e-mail message from your computer, Thank you.*********************************************************************2-- Please see the official ORACLE-L FAQ: http://www.orafaq.com-- Author: Jamadagni, Rajendra  INET: Rajendra.Jamadagni@espn.comFat City Network Services    -- (858) 538-5051  FAX: (858) 538-5051San Diego, California        -- Public Internet access / Mailing Lists--------------------------------------------------------------------To REMOVE yourself from this mailing list, send an E-Mail messageto: ListGuru@fatcity.com (note EXACT spelling of 'ListGuru') and inthe message BODY, include a line containing: UNSUB ORACLE-L(or the name of mailing list you want to be removed from).  You mayalso send the HELP command for other information (like subscribing).