DB links and Security

DB Version:10gR2
To connect to a remote DB, we create only one DB link for that DB. We create a public DB Link like
create public database link wmat
connect to SYSTEM identified by jklf
using '(DESCRIPTION =
     (ADDRESS_LIST =
          (ADDRESS = (PROTOCOL = TCP)(HOST = 10.80.16.314)(PORT = 1521))
     (CONNECT_DATA =
          (SID = wmat)
)';Since we are connecting as SYSTEM user of the remote DB, we only have to prefix the remote schema name and access the DB object over there.
But, isn't this a security threat for that remote DB since we are connecting as SYSTEM over there?
Question1.
If you did a security Audit in these two DBs, what would you say?
Question2.
Is creating a DB Link for every schema or one DB link connected to the SYSTEM (as mentioned above) of the remote DB the standard practice?

Insignificant wrote:
But, isn't this a security threat for that remote DB since we are connecting as SYSTEM over there?Most definitely yes.
Question1.
If you did a security Audit in these two DBs, what would you say? Be very concerned. As DBA I would refuse to implement such a link as it exposes the entire database to the whims of developers and end-users.
Question2.
Is creating a DB Link for every schema or one DB link connected to the SYSTEM (as mentioned above) of the remote DB the standard practice?Each Oracle schema represents a logical container for data and code objects - think of it as a logical database. Each schema should have its own privs. Own resource profiles. Etc.
This ensures a lot of things. Better security. Increase robusteness. Better isolation. Better transportability. Etc. (and in all aspects, from development to deployment to operation)
By the same token, if that logical container needs a database object called a db link to communicate with a remote database container - than that must be a secure and private link for that container (schema) only.
One should only use the public "shared" container for common data and code objects. For example, for PL/SQL exception management PL/SQL libraries. Message log PL/SQL libraries. Etc. (this is similar to the shared object/dynamic link library concept of Linux/Windows applications - where common code resides in a sharable format)

Similar Messages

  • DB Link working method and security issue.

    Hi All,
    I need some clarification how db link works.
    If I am having DB link and done some DML operations. After that I have done some DML opearation on the local database. I haven't commited the data yet. Then DB Link goes down. What will happen?
    In my case from local database if i am issuing
    select * from emp@iasdb
    then it shows updated data.
    If i am connecting to target database then it shows non updated data. How it is possible?
    What happen when DB Link goes down? Which database (taget / local) will keep lock of tables / rows I am updating?
    Tom can you please help me.
    Regards,
    Pritesh.

    If i am connecting to target database then it shows non updated data. How it is possible?Changes are visible only to the session doing the changes (until saved). Works even if the changes are across databases.
    If remote DB goes down, this is what you get on local DB:
    commit
    ERROR at line 1:
    ORA-02054: transaction 6.34.41922 in-doubt
    ORA-02068: following severe error from REMOTE_DB
    ORA-12152: TNS:unable to send break messageand if you now try to access the objects that were updated by above in-doubt transaction, you get this:
    select * from t
    ERROR at line 1:
    ORA-01591: lock held by in-doubt distributed transaction 6.34.41922ORA-01591 lock held by in-doubt distributed transaction string
    Cause: An attempt was made to access resource that is locked by a dead two-phase commit transaction that is in prepared state.
    Action: The database administrator should query the PENDING_TRANS$ and related tables, and attempt to repair network connection(s) to coordinator and commit point. If timely repair is not possible, the database administrator should contact the database administrator at the commit point if known or the end user for correct outcome, or use heuristic default if given to issue a heuristic COMMIT or ABORT command to finalize the local portion of the distributed transaction.

  • How do I reset my security questions? I do not have a reset questions link and have not received a response from Apple!

    Apple has been no help. Emailed me to call and ask them to reset my questions, tried to call and got told that I did not have apple support registered to my phone. Even though it is nothing to do with the actual phone. All I want to do is buy some apps but because I havent purchased on my iphone 5 before it makes me answer my security questions which I know the answers but must of written them a different way because it keeps telling me they are wrong. Please help!

    You will need to contact iTunes Support, http://apple.com/emea/support/itunes/contact.html (select Account Security as your help topic).
    After you reset your security questions, it is highly recommended you add a rescue email address. To do so, log in at appleid.apple.com and click on Password and Security. Answer the questions and then click on "Add Rescue Email Address:"

  • Crystal Reports Export to PDF and Security

    I am writing a PC application in VB.Net (using Visual Studio 2005 and which ever Crystal Reports package comes with it) which utilizes Crystal Reports and exports the reports to PDF files.  My company creates other PDFs through other programs and is able to set different security options on those PDFs to prevent users from being able to edit them in Adobe Acrobat.  I believe this involves setting a password and a few other options.  Is there a way to do this when creating a PDF by exporting to PDF a Crystal Report?
    Any help or advice on this matter would be greatly appreciated.

    Could you provide me a link and/or more informationa bout this Crystal Reports Scheduler?  I have another issue I'm trying to take care of and I'm wondering if this could help me.  I use the Crystal Reports that comes with Visual Studio 2008 to build my reports and then turn them into PDFs.  However these PDFs are not [section 508|http://www.section508.gov/|Section508.gov] compliant.  I need to add [tagging|http://www.acrobatusers.com/tutorials/what-are-pdf-tags-and-why-should-i-care|What are PDF tags and why should I care] to the PDFs.  Do you know if the component you mentioned can do this?  Or of any other product that can?
    [This|Export to PDF - Section 508 Accessibility Compliance; is the thread my other question is on.
    I'd appreciate any information you could give me.

  • Hai i am using firefox 3.6.When right clicking on a link and a window opens up, i want it to ask me "Open Link in New tab" first, not second.

    hai i am using firefox 3.6.When right clicking on a link and a window opens up, i want it to ask me "Open Link in New tab" first, not second.

    First, you are using a version of Firefox that is very old and outdated. Please update to at least Firefox 3.6.27, or more preferably, update to Firefox 10.0.2. There are lots of bug fixes, security improvements, and much improved performance in Firefox 10.
    After you do that, try seeing if you are still having a problem. If you are, is this that when you try to select "Open in a new tab" it opens in a new window instead? Or something else?

  • PHP/MySQL updates within OS X S and Security updates?

    Hey All,
    Does anyone know of a link that will provide any info about PHP, PHP plug-in, or MySQL updates that are included in the Server OS or security updates, or any other software updates? This way I won't have to read through all of Apple's support articles for all OS and security updates.
    Updating a bunch of web servers from OS X S 10.6.3 to OS X 10.6.6
    Thank you in advance!

    Great news thanks!

  • Email hacked, password reset and security details ...

    Hi All, just need some advice really.
    My primary email was hacked last week, and my password changed. I have taken all measures to try and regain control but have been unsuccesful. I have spoken to four different people today on the phone. First of all i was moved to a different department twice, thn I was told I had to speak with the security department as the security questions had the wrong answers! When I eventually got through,and after 30 minutes of being on the phone, I was told that I cannot be helped. I explained 5 times what the issue was and that I had been referred to this department becuas eof security question isssues, but that was not registered!!!
    i was then told to use the forgotten password option! As I had already said three times, I had tried this, but the answers had been changed! Thats why I was on the phone to sort this out. I was then told that my answers had been reste and to wait a little while. Five hours later I have come back to try and sort this out and I STIILL HAVE THE SAME ISSUE! I don't know what to do now, as the first time round took over an hour to try and get somewhere!!!!
    Can someone please refer me to someone who is actually going to LISTEN and help, rather than telling me that 'I can't help you madam'

    i am sorry to see that someone else is having this sort of problem
    the security and customer help in India cannot be trusted,
    they actually allowed somebody to have access to my e-mail and account details
    then despite my objections allowed someone to stop my phone calls and
    send them to a mycander mobile phone (ending238)
    then all sorts of pain followed.
    THE ONLY SOLUTIONS IS TO WRITE TO THE DIRECTORS OF BT AND SEEK HELP FROM THE CHAIRMANS
    SUPPORT TEAM. TRY SUE HALPIN. I THREATENED LEGAL ACTION AND WOULD/MAY CARRY OUT THAT THREAT.
    even she was confused and disturbed by the trouble she had getting things put right, is it to simple,
    get a new primary e-mail and anew logon to bt.com (your account)
    change your passwords and security questions, do not use the same for both
    all that fus about including a number or a capital is rubbish but you are t a degree stuck wth a number
    use something like 25sausagecaravanaxe. at least 14 letters no linking of the words like carrotsaladwatercress1
    just pure rubbish
    if you want the names and personal postboxes of the directors at newgate st london let me know
    i have had 2 months of pure pain and distress, keep in mind when speeking to some call centres
    you cannot educate pork, never give them admin rights and remote access.
    or beleive the latest from India   its all caused by Iphones and Ipads
    best of

  • Following an amazon link and then accessing the page makes firefox open another amazon page in a new tab. How do I stop this

    I have this bizarre problem with firefox and Amazon (com and co.uk)
    If I click a link (open in new tab) to an amazon page the page opens in a new tab. Fine.
    If I then select that page (click its tab) the page is displayed and then a new amazon page opens in a new tab with the url http://www.amazon.com/?ie=UTF8&*Version*=1&*entries*=0&link_code=hom&tag=skipthemalls-20
    If I close the new amazon page and return to the original amazon page the phenomenon does not repeat - not new window opens.
    This does not happen in any other browser (IE or Chrome)
    This does not happen on any other website.
    I've scanned my PC (Malwarebytes and security essentials) and found nothing sinister
    All forefox add ons are disabled. To be sure, I've started 'restarted firefox with add ons disabled' and the problem still occurs. I've even reset Firefox to its original state and still the problem occurs.
    So now what?
    Windows 7 Ultimate
    Thinkpad R60 4GB

    That page is coded to a particular "affiliate" (skipthemalls) and may have the purpose of setting a cookie to earn a cut of revenue from your purchase. If that is not caused by the site you visited that brought you to Amazon, it's hard to think of a reason for it to open. (Even then, you would think it would be processed transparently in the background.)
    More generally, when you have a problem with one particular site, a good "first thing to try" is clearing your Firefox cache and deleting your saved cookies for the site.
    (1) Bypass Firefox's Cache
    Use Ctrl+Shift+r to reload the page fresh from the server.
    Alternately, you also can clear Firefox's cache completely using:
    orange Firefox button (or Tools menu) > Options > Advanced
    On the Network mini-tab > Cached Web Content : "Clear Now"
    If you have a large hard drive, this might take a few minutes.
    (2) Remove the site's cookies (save any pending work first). While viewing a page on the site, try either:
    * right-click and choose View Page Info > Security > "View Cookies"
    * Alt+t (open the classic Tools menu) > Page Info > Security > "View Cookies"
    In the dialog that opens, you can remove the site's cookies individually.
    Then try reloading the page. Does that help?

  • How to hide links and tab

    Hi All,
    I am working on SAP Sourcing 7.0. There are few changes I am trying to do in my system. They are:-
    1>I am trying to hide Xpress tab from the top navigation. I went to the Setup->Workbench page. I have seen XPress is Default Buy-Side Template for XPrress Tab and Enable to hide check box is disabled. I tried to edit the page but no success.
    I am able to add new page and able to hide. Pl let me know we can hide Xpress tab or not.
    2>I am trying to hide Reference guide, setup, about and help links. I am able to hide Reference guide link via making changes in the security profile. But rest of the link I am not able to do. Pl let me know if itu2019s possible or not.
    Deepak!!!

    Hi Mudit,
    Thanks for reply.I was able to hide XPress via hit and trail, once again thanks for input.But this changes are reflecting globally. Is there any way for hiding these links for specific user..?
    1>I have observered in the security profile's Access right dropdown System option is available, Once i select, i can see different permission options and setup is among the one of them. What I am thinking I can restrict the user permission at this lavel, if I am not able to hide setup link.
    2>One thing i want to share and need you input. I have found below option inside the System Navigation Tabset (Buyside)
    Toolbar Container: System Navigation Tabset (Buyside) for  help, RG, about, help link under Gray Navigation Group.
    ToolbarID I have created are:-
    Help:-eso.system.toolbar.navigation.grayBarGroup.help
    Setup:-eso.system.toolbar.navigation.grayBarGroup.srm_toplink_setup
    Reference Guide:-eso.system.toolbar.navigation.grayBarGroup.refguide
    About:-eso.system.toolbar.navigation.grayBarGroup.srm_toplink_about......please confirm above toolbarIds.
    The mazor issue I faced was if I use wrong toolbar id, system starts throwing Oracle error after clicking setup link and all tabs are not visible.
    I faced such error yesterday when i was trying for hiding XPress. At this situation how to solve error. I know via giving correct toolID value system will start working fine and i have done the same...:), but is there any other way of resume the system to original state.
    Deepak!!!

  • I have a iPad mini, I recently acquired a $15 iTunes card to get apps and music. I have forgotten my security questions and I cannot buy anything HELP (I tried to reset them in the Password and Security tab but the text under the questions does not show)

    I recently acquired a $15 iTunes card to get apps and music. I have forgotten my security questions and I cannot buy anything HELP (I tried to reset them in the Password and Security tab but the text under the questions does not show)

    Apple ID: Contacting Apple for help with Apple ID account security
    http://support.apple.com/kb/HT5699?viewlocale=en_US&locale=en_US
    Try the link above. Try to find a phone number for your country, call and ask for account security.

  • HT201363 When I sign in to my Apple ID in "My Apple ID" and go to "Passwod and Security" I should answer the security questions but I don't remeber them and the bar that says "send to rescue email" doesn't show !! How could I recover the questions??

    When I sign in to my Apple ID in "My Apple ID" and go to "Passwod and Security" I should answer the security questions but I don't remeber them and the bar that says "send to rescue email" doesn't show !! How could I recover the questions??

    You will have to contact iTunes Support and tell them you have forgotten your Security Questions and need them reset. They will respond to you by email, usually within 24 hours. Here are two links to contact iTunes Support:
    http://www.apple.com/support/itunes/ww/
    or by email:
    http://www.apple.com/emea/support/itunes/contact.html
    Cheers,
    GB

  • Iso5 download error, network timed out, how do i stop this, all of my firewalls and security on my pc are currently swiched off but this still didnt help

    iso5 download error, network timed out, how do i stop this, all of my firewalls and security on my pc are currently swiched off but this still didnt help>
    trid multiple times over the last few weeks, after waiting 45 minutes for the download to comlete the network times out whilst processing the download

    The router is in your house.
    In a nutshell, a modem communicates with the Internet and brings a single communications link to your house,  The router takes that single link and divides it up among many links, both wired and wireless, to support many devices in your house.  The router and the modem may be separate physical boxes or, more commonly, they're in the same enclosure.
    Unfortunately, if there is a firewall in the router, you will need help.  I don't think that it's a good idea to try to walk you through it via the forum.  You should contact the router supplier and have them walk you through the investigation.

  • Hi please help me I'm appleid disable 7.0.4 iPhone 5s by email and security questions forgot not active now please please help me

    Hi please help me I'm appleid disable 7.0.4 iPhone 5s by email and security questions forgot not active now please please help me

    You might be able to re-enable your account via this page : http://appleid.apple.com, then 'reset your password'
    You might then need to log out of your account on your phone by tapping on your id in Settings > iTunes & App Store and then log back in so as to 'refresh' the account on it
    For your security questions, if you don't have a rescue email address, or you don't have access to the email account, then you will need to contact iTunes Support / Apple to get the questions reset.
    Contacting Apple about account security : http://support.apple.com/kb/HT5699 - you can also try this link to get your account re-enabled if the above doesn't work.
    When they've been reset you can then use the steps half-way down this page to update/add a rescue email address for potential future use : http://support.apple.com/kb/HT5312

  • HT5622 When I sign in with my apple ID and password then goto password and security, i do not get the option to reset my security information. Why not?

    I do not have the option to change my security information when I sign in to my Apple ID and goto Password and security. Why not?

    Just to be clear - what are you signing into?  You could be talking about connecting or setting a computer or device to your icloud or itunes account.  You could be talking about logging into your icloud account using a browser to icloud.com.  Or you may have followed a link to an Apple page that lets you edit your account.
    If you can't remember your security questions/answers then go to Express Lane  and select 'iTunes' from the list of 'products' in the middle of the screen.
    Then select 'iTunes Store', and on the next screen select 'Account Management'
    Next choose 'iTunes Store Account Security' and fill in that you'd like your security questions/answers reset.
    You should get an email reply within about 24 hours (and check your Spam folder as well as your Inbox) - but some recent posts are saying that Apple have temporarily suspended the reseting of security question/answers whilst account security processes are improved, so it may take longer.

  • I am increasingly having issues with clicking on links and not going anywhere with Firefox. When I paste the path into Internet Explorer it often works. Why?

    I have always preferred Firefox, but am getting quite annoyed when I click on Google links and don't get to the site. I thought maybe the sites were down, but then started pasting into IE and actually getting something. For example, today I clicked on a link from Harry and David to redeem a free magazine subscription to Food & Wine. I tried it multiple times, then tried it with IE and it worked right away. I don't know if it is just the latest version of Firefox, this seems to have been happening more and more for a while.

    Clear the cache and the cookies from sites that cause problems.
    "Clear the Cache":
    *Tools > Options > Advanced > Network > Cached Web Content: "Clear Now"
    "Remove Cookies" from sites causing problems:
    *Tools > Options > Privacy > Cookies: "Show Cookies"
    Start Firefox in <u>[[Safe Mode|Safe Mode]]</u> to check if one of the extensions (Firefox/Tools > Add-ons > Extensions) or if hardware acceleration is causing the problem (switch to the DEFAULT theme: Firefox/Tools > Add-ons > Appearance).
    *Do not click the Reset button on the Safe mode start window or otherwise make changes.
    *https://support.mozilla.org/kb/Safe+Mode
    *https://support.mozilla.org/kb/Troubleshooting+extensions+and+themes
    Do a malware check with some malware scanning programs on the Windows computer.<br />
    You need to scan with all programs because each program detects different malware.<br />
    Make sure that you update each program to get the latest version of their databases before doing a scan.
    *http://www.malwarebytes.org/mbam.php - Malwarebytes' Anti-Malware
    *http://www.superantispyware.com/ - SuperAntispyware
    *http://www.microsoft.com/security/scanner/en-us/default.aspx - Microsoft Safety Scanner
    *http://www.microsoft.com/windows/products/winfamily/defender/default.mspx - Windows Defender: Home Page
    *http://www.safer-networking.org/en/index.html - Spybot Search & Destroy
    You can also do a check for a rootkit infection with TDSSKiller.
    *http://support.kaspersky.com/viruses/solutions?qid=208280684
    See also:
    *"Spyware on Windows": http://kb.mozillazine.org/Popups_not_blocked

Maybe you are looking for

  • Compiling Java program from other java program

    Hi, How can I compile and capture the compilation result from another java program? Thanks

  • Configuration of Application servers for PROD system in BW3.5

    Hi, We are getting new app servers for our production system (not yet live). Could you tell me or post links to the configuration/settings to be used when setting up these servers? Any thing from recommended parameters to no. of work processes will b

  • Adobe Flash Player 10 Installed but?

    Hello I am using xp SP3 with Adobe Flash Player 10! Once in awhile I get this, like I am now>>> Hello, you either have JavaScript turned off or an old version of Adobe's Flash Player. Get the latest Flash player. But I have it installed and Video sti

  • Changing Multiple Smart Playlists View Options

    Hello I have lots of smart playlists in different folders in my iTunes Library. Is there any way to change the view options for multiple smart playlists in iTunes 10? Many Thanks Shaun

  • Windows media file in itunes

    Can i play my windows media player file directly on itunes. if yes How? Can i transfer/copy the media file using a pendrive on to the macbook air?