From: sybrandb@my-deja.com
Newsgroups: comp.databases.oracle.server
Subject: Re: DBA Studio--Don't need password ?
Date: Sat, 11 Nov 2000 09:10:51 GMT
Organization: Deja.com - Before you buy.
Lines: 44
Message-ID: <8uj2eq$lap$1@nnrp1.deja.com>
References: <8uiql3$fbp$1@nnrp1.deja.com>
NNTP-Posting-Host: 213.116.132.191
X-Article-Creation-Date: Sat Nov 11 09:10:51 2000 GMT
X-Http-User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows 98; Parool INTERNET)
X-Http-Proxy: 1.1 x70.deja.com:80 (Squid/1.1.22) for client 213.116.132.191
X-MyDeja-Info: XMYDJUIDsybrandb


In article <8uiql3$fbp$1@nnrp1.deja.com>,
  xiaoyangw@my-deja.com wrote:
> Hi
>
> I installed a 8.1.6 for NT in a Win2000 server and
> find I can connect to a database via any username&password.
> what I do is as following:
> 1. start DBA Studio from start menu
> 2. check start DBA studio stand alone radio button
> 3. input any string as username & pass, such as 12345/56789
> 4. select role as SYSDBA
> 5 then I can conenct to my database and do everything
>
> if I connect to a database from OMS, I can not login as above.
> Can anyone tell me is this a bug? if not( I think it should not)
> How can I close this door ?
>  regards
>
> simon
>
> Sent via Deja.com http://www.deja.com/
> Before you buy.
>
This is not a door, or it is a door you left open. You are probably
logged in as administrator on that server. Which means you can
connect / as sysdba *by design*. The only thing you could do is check
whether you have OS_<SID>_DBA or OS_DBA groups on that NT box.
As the special privileges apply to the administrator only, I'm not sure
why that is a problem. Don't you trust people logging in as
administrator? You can create extra hurdles by removing those groups.
However, if an intruder wants to crack that database, he will do so
anyway.

Regards,

--
Sybrand Bakker, Oracle DBA

All standard disclaimers apply
------------------------------------------------------------------------


Sent via Deja.com http://www.deja.com/
Before you buy.

