home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!saimiri.primate.wisc.edu!ames!sun-barr!cs.utexas.edu!newsfeed.rice.edu!hsdndev!news.cs.umb.edu!pytlik
- From: pytlik@ra.cs.umb.edu (Marek Pytlik)
- Newsgroups: comp.databases.oracle
- Subject: Re: OPS$LOGIN : security hole?
- Message-ID: <1992Dec18.022352.3477@cs.umb.edu>
- Date: 18 Dec 92 02:23:52 GMT
- References: <1992Dec15.144220.25349@relay.nswc.navy.mil> <8aT=R#A@engin.umich.edu> <1go861INN4hv@rave.larc.nasa.gov>
- Sender: news@cs.umb.edu (USENET News System)
- Organization: University of Massachusetts at Boston, Dept of Math and CS
- Lines: 14
- Nntp-Posting-Host: ra.cs.umb.edu
-
- In article <1go861INN4hv@rave.larc.nasa.gov> p228@uni05.larc.nasa.gov (Bailey Bob) writes:
- >In article <8aT=R#A@engin.umich.edu> lwk@engin.umich.edu (Lewis W Kellum) writes:
- >>
- >>Here's another question: If I know Mr.Schow's unix login id, and the internet
- >>hostname of his Oracle server, what keeps me from creating his login id
- >>on my host and connecting to his ops$ oracle account? - Woody Kellum
- >
- >The only way the ops$ account works without a password is when you are
- >directly logged into the host server at the OS level. If you connect to
- >the host via SQL*Net, the RDBMS will require entry of the password.
- >
- >Bob Bailey
- that is not true in case of unix (clinent) to unix (server). smith on client
- can access smith's database account on server.
-