Oracle FAQ | Your Portal to the Oracle Knowledge Grid |
![]() |
![]() |
Home -> Community -> Usenet -> c.d.o.server -> Re: Project lockdown - opinion solicitation
"EdStevens" <quetico_man_at_yahoo.com> wrote in message
news:1187976674.337926.228510_at_r23g2000prd.googlegroups.com...
> On advice last week, I have downloaded the "Project Lockdown" document
> and begun reviewing it. I get a very uneasy feeling about his
> suggestion to remove the SUID bit from the Oracle executables.
> Searching through this ng I find a lot of issues stemming from not
> leaving the file permissions just as they are created when following
> installation instructions to the letter.
>
> It seems to me this could cause a lot of nagging problems. It also
> seems that if your ORACLE_HOME is on a box where issuance of os user
> accounts is limited to DBAs and SAs the ability to exploit the SUID
> would be extremely limited.
>
> Am I missing something?
>
Seems that in general if the DBA/SA wants to steal data the SU bit is not really going to stop them as they already pretty much have the keys to the kingdom. Received on Sun Aug 26 2007 - 03:04:47 CDT
![]() |
![]() |