« OTN Visitor Browsers & OSs | Main | New Oracle Q&A Site »

Default Passwords are Evil

EWeek, as usual, is doing its best to raise alarm bells re: Oracle security, this time in regard to a published worm that is designed to take advantage of the use of default usernames and passwords. The article does at least correctly point out that this work exploits DBA-created password schemes, not Oracle technology per se.


DBAs, remember to always, always change all default passwords after installation!


We are working with Oracle ACE and security expert Arup Nanda to publish a rather comprehensive guide to locking-down production databases when tight deadlines (a day, a week, a month, etc,) are involved (and when aren't they, really?). In fact, Arup's very first recommendation is to identify and remove default passwords from production databases!


Look for this multi-part guide to publish sometime this quarter.

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About This Entry

This page contains a single entry from the blog posted on January 9, 2006 10:53 AM.

The previous post in this blog was OTN Visitor Browsers & OSs.

The next post in this blog is New Oracle Q&A Site.

Many more can be found on the main index page or by looking through the archives.

Powered by
Movable Type and Oracle