Errors in Oracle password protection system
Security experts have warned about the risk of hackers recovering Oracle database passwords due to weaknesses in the security mechanism of this package.
The flaw could put many Oracle customers in jeopardy of the threat of hackers. According to the SANS Institute of Technology, Oracle should " restore " the password protection engine to database users because they have discovered Oracle's even better encrypted password recovery.
SANS experts have informed Oracle of this security flaw since July 2005, but so far no response has been received from this company. About 1 month ago, the news website CNet also posted news about the vulnerability and notified Oracle but did not receive a reply.
SANS recommends administering Oracle database should use more complex passwords than normal and assign limited permissions to users to protect safety while waiting for Oracle's fixes.
VH - ( ZDNet )
- 65 Oracle product security errors have been fixed
- Utilities to help protect data
- First training Oracle Database 10G in Vietnam
- New deep variant exploits Oracle errors
- Network security - How to set a password with high security
- The more complex the password, the safer? Not sure!
- Vietnam is free to use Oracle Database XE
- Password protection before a thief
- Reset account password in Vista
- Oracle purchased 2 Thor Technologies and OctetString
- Oracle can release its own version of Linux
- Set file protection password not open and save content edit