Little security issue in password box on connections

I'm on 1.2.0.29.98 on OSX. I have a password with an @ symbol in it. I was making a new connection in the connection dialog box and typed in the password wrong. I noticed when I double clicked the obfuscated password it only highlighted part of it to the right of the @ symbol instead of the whole password. For other symbols ($, % for example) it will only highlight from where you double clicked up to (and including) that symbol or between two of those symbols.
It could help people to figure out the passwords, it should highlight all the password when you double click it.

Thank you for bringing this to our attention. As you mentioned, it isn't a glaring hole in password security, but even a little hole is undesirable.
- John McGinnis
SQL Developer Team

Similar Messages

  • Security Issues - No password required for unsleeping and screensaver

    I checked the box under security to 'require password when waking from sleep/screensaver' or whatever its called. It worked fine for like 2 weeks...i activate screensaver or sleep the laptop and have to put in a password to get out of it. Now when I wake or unsleep it, no password is required...what can I do? I cannot find any pattern or installation/change I made to cause this at all.
    MacBook Pro 1.83 with OS 10.4.6 (all latest updates and firmware)

    I deleted 3 plist preference files, the checkbox still remained for the require password option. I did a reboot and the checkbox was still there, and didnt work properly. I did the uncheck/check deal and blam...started to work properly again. Thanks for your help!

  • Security issue: Wakeup password glitch in Mavericks

    Here is what I'm seeing:
    My Macbook Air goes to sleep.
    I press a key and see the password box.
    Press ESC to cancel the login.
    Press a key again.
    The Mac wakes up without a password.
    I don't know if this is just Mavericks, but I never saw this before I upgrade.

    If I had it set for "Wait 5 minutes" it shouldn't prompt for a password the first time.
    The original situation was that it would prompt me for a password (even though I was set to Wait 5 minutes). Then I would press ESC, wake-up again, and it wouldn't prompt for a password.
    Less of a security flaw than a glitch, prompting for a password when it shouldn't.
    Now that I have it set for immediate, it's supposed to prompt me for the password every time and it does.

  • Configtool Secure Store JDBC password - Error while connecting to DB

    Hi All
    I was following the note 701654 which asked to update the config tool secure store pssword. I changed the JDBC password too instead admin password alone. Now the problem is the config tool is not able to connect to the database and this lead to the jcontrol.exe to be stopped. We tried to give back the DB password we remembered unfortunately none of them worked. Please guide me to get around this.
    Should I need to change the DB password if so please let me know the procedure and the places I need to do the change.
    Thanks, Raj

    The problem was fixed. I changed the DB password directly in the SQL server and updated it in the secure store and it worked.
    Note 997510 gave a good idea on the error and the solutions.
    Thanks, Raj

  • Security issues with password retrieval

    Anyone who comes in physical contact with a mac can open and edit as desired, theadmin users that already exist on the machine. I wonder if there is someone who hasa proposed security measures around this problem?
    For example, if a company wants to use mac, but want to give users limited access sothey can not mess around in the operating system or delete the programs that are required by the company to have on your machine. What measures could be used toachieve this? How can you prevent that other than the designated administrator can add users with admin privileges?

    tedthemechanic wrote:
    But once the employees take the computer home and starts googling they will soon realize that they can stop the startup process and create their own admin account:
    mount -uw /
    rm /var/db/.AppleSetupDone
    How to prevent this?
    My above reply prevents them from doing this 100% as the startup key combination to enter those commands is ignored.
    I forgot to add that you should set the root password as well. Easiest to do with the utility on the OS install disk. Just make it different from the other admin passwords on the machine.

  • IOMEGA home media network hard drive security issue - admin password bypass

    Some time ago I analysed the http traffic between the above and firefox so that I could automate the restart process because I wanted to restart the drive about once a week overnight.  This I achieved by writing a simple python program and it seemed to work ok but I stopped doing it after a short while.  Many months later I have returned to this and found that the conversation has changed.  The redirection that used to occur has gone and I can now restart my drive without the need for a valid administrator password and I have done this both from a computer on my lan and also via an external  no-ip free dns domain name.  Note that any attempt to access the drive via a browser still requires a valid password.  My original drive was at firmware level 2.063 and this one (a replacement under warranty) is at 2.064.
    Has anyone come across this problem and has anyone any idea how to fix it?
    Happy to post my python code if required.

    Thank you for the reply.  I followed your advice.  I guess the upgrade worked ok because the device now says its at the right level, it removed the admin password (which I then re-instated) and a robots.txt file has appeared in the FTP folder.  However, a couple of things didn't work as advertised:
    1. When I tried to turn on remote access it just hung and I had to reboot the device.  It subsequently resolved itself after a couple of reboots and when I wasn't looking.
    2. When I tried to access the folders through a browser I was presented with a greyed-out 'public' user, for which I did not have a password, and this only resolved itself when I added a new user, which led to another problem ...
    3. I cleared the passwords on a couple of users because I wanted to change them.  No way could I get a prompt for a new password - followed the instructions in the manual - so I ended up deleting them and recreating them from scratch.
    Now then, has this fixed my original problem?  Not really.  The situation is that when remote access is enabled then my program in its current form doesn't work (but I would need to see if I could make it work).  If remote access is disabled and I get my router to port-forward, say 8000, as 80 to the iomega then my program still works fine and I can do a restart or shutdown without the admin password.
    Obviously now that I have this program worked out I can go on to do other admin tasks remotely.
    I'd appreciate any further ideas you might have.

  • I'm trying to connect to my home wifi with my imac gh5. After I enter the password it says connection timeout or password incorrect. I know there's no issue with the connection but I don't know what else to do. Does anyone know how to fix this problem?

    I'm trying to connect to my home wifi with my imac gh5. After I enter the password it says connection timeout or password incorrect. I know there's no issue with the connection but I don't know what else to do. Does anyone know how to fix this problem?

    What is the make & model of your home Wi-Fi router that you are attempting to connect your G5 iMac to? Which exact model of iMac do you have?
    What wireless security type is your router using: WEP, WPA, or WPA2? If you temporarily disable wireless security, can the iMac connect to it now?

  • HT201210 you are running the latest version of iTunes, have no other USB devices attached, have no security software installed, and are directly connected to your ISP source, simply restarting the computer and the iOS device can clear up certain issues th

    you are running the latest version of iTunes, have no other USB devices attached, have no security software installed, and are directly connected to your ISP source, simply restarting the computer and the iOS device can clear up certain issues that could prevent you from restoring. After restarting the computer and iOS device, attempt to restore again.

    How big is your library?  I would recommend the following troubleshooting steps:
    - Backup your library.  Always a good idea before messing with things.  
    - Create a new library.   Refer to this article for details:  http://support.apple.com/kb/HT1589.  This won't delete your old library, you're just creating a new empty one.  Also refer to this article to get back to your old library later.
    - Add a few albums into this new library.  Not everything, just a small sampling, as a test.
    - Activate Match on this new library.  You shouldn't have to re-pay, it should just say "Add Computer" or similar.
    - At this point, Match should run again. With just a few albums it should complete in just a few minutes.
    If iTunes doesn't crash at this point, then likely there's something about your original library that Match doesn't like - what that is I don't know, but at least you'll know it's not your PC.   If iTunes still crashes, then if could be a number of other things, but probably not your library.   My next suggestion (if you haven't already done this) is to uninstall / reinstall iTunes.   If that doesn't work, then my next ideas you won't like.   

  • Spoof dialog Boxes security issue

    Hi all
    Any one out there aware of this security issue with Safari
    "Secunia Research has discovered a vulnerability in various browser's, which can be exploited by malicious web sites to spoof dialog boxes.
    The problem is that JavaScript dialog boxes do not display or include their origin, which allows a new window to open e.g. a prompt dialog box, which appears to be from a trusted site."
    I found the above by accident as i was looking up something else.
    If you go to Secunia site and try the test you may find that you are also vulnerable.
    http://secunia.com/multiple_browser'sdialog_origin_vulnerabilitytest/
    The only way i found to stop the spoof dialog box was to turn off enable plug-ins in preferences. However i don't have any plug-ins in my Safari plug-in folder.
    I'am running safari 1.3(v312) however it would appear that it also effects version 2.2 of Safari too. Also i have installed the latest update but to no effect. Other browser effect are:-
    _ Internet Explorer for Mac
    - Internet Explorer
    - Opera
    - iCab
    - Mozilla / FireFox / Camino
    My question is, is this vulnerability true, or just a setup
    Any comments welcome.
    ~Tim

    Hi,
    The issue is resolved, but I don't know what caused this error.
    I uninstalled the java components and BO then I deleted the BO folder under program files, then I deleted all BO entries in the registry.
    Finally I reinstalled everything except the service pack and that finally worked. I don't know the cause of this error.
    Regards,
    Marcela

  • Secure enough to write the db connection username password in form?

    Secure enough to write the db connection username password in form?
    Can anyone read the pdf form, extract the content or scripts from it?
    Thanks
    Asiye

    >Can anyone read the pdf form, extract the content or scripts from it?
    Always assume that.
    Aandi Inston

  • Powerview Cannot connect to the server due to a security issue. The server may not have been able to match the host for silverlight

    Hello,
    I have a sharepoint 2010 sp1 CU Dec 2011 server with a SQL Server 2012 SP1 CU4 reporting services instance.  I am able to open Power View and use it normally when bypassing the ISA Reverse Proxy server.  However when going thru ISA I receive the
    following Error.
    Power View  Cannot connect to the server due to a security issue.  The server may not have been able to match the host for Silverlight.  This error appears after I click yes on an Internet Explorer Display Mixed Mode prompt.
    I've seen a couple references to this issue but not much.  This one mentions a clientaccesspolicy.xml file but I haven't had any luck with that.  http://connect.microsoft.com/SQLServer/feedback/details/716433/cannot-connect-to-the-server-due-to-a-security-issue-the-server-may-not-have-been-able-to-match-the-host-for-silverlight
    Any Ideas?  Thanks.
    Ryan

    Hi Ryan,
    Based on my research, the issue should occur due to a by design behavior in Threat Management Gateway (TMG). To work around this issue, you can use SSL between the TMG and the SharePoint Web Server.
    Hope this helps.
    Regards,
    Mike Yin
    TechNet Community Support

  • Security issue with connecting to Microsoft Live

    I currently use StudioCloud for my studio management software. However, I'm unable to use the email features of the software as they state "**Adobe Air has a security issue connecting to Windows Live and, as such, StudioCloud can not work with Windows Live/Hotmail at this time.**" (http://app1.studiocloud.com/support/index.php?/article/AA-00265/0).
    Are there any plans on resolving this issue?
    As a small business owner, I need to streamline my processes.  If there is a possibilty of this being fixed in the near future, then I won't look at other options, but if it isn't, then I need to determine if I will be moving my email to another host, or using a different studio managment software, or finding a different method of handing my email communications with my clients which is efficient and meets my needs. 
    Thank you.
    Catherine Bowser

    Reported via a live chat.  I must say that the guy was very helpful and said he'd reported the issue together with the tracert data I had provided.
    Afraid I lose the will when trying to speak to BT by phone!

  • Scripting 'Save PSD as PDF with password security' and 'Open PDF with password security' issue.

    Hi!
    I'm now building an extension for Photoshop. The script (jsx) should save the active document as Photoshop PDF secured with a password. The PW is the same all the time and is set in the script. Then the script is to open the PDF with that same password. I need all this to protect the PDF from opening by a user, so that only the script has access to the file.
    I've googled a lot. I've seen a similar topic on this community dated as 2012. It's not answered. With an only comment saying that saving with a password seems to be possible via GUI and not via a script.
    Has anything changed since 2012?
    P.S. Illustrator .documentPassword and .requireDocumentPassword don't work in PS and ScriptListener still gives nothing :-/

    ScriptListener still gives nothing
    Which probably means the task is (still) not possible to achieve with Photoshop Scripting.
    Both Photoshop DOM and AM seem to have weaknesses/omissions that I would consider more relevant but if you regard the issue as crucial you may want to post a Feature Request over at
    Photoshop Family Customer Community

  • HT1725 Message says Apple ID is Disable how do I fix this. I changed my password 4 times already. It's not a security issue  Please help me. Thank you

    Please help me ever since the update every time I try to order an App I get a message saying "Apple ID I'd Disable" I've changed my password 4 times And changed my credit card also I don't think it's a security issue. Thank you

    Hi Melivan!
    I have an article here that can guide you through some steps for dealing with your disabled Apple ID:
    Apple ID: 'This Apple ID has been disabled for security reasons' alert appears
    http://support.apple.com/kb/ts2446
    Thanks for coming to the Apple Support Communities!
    Cheers,
    Braden

  • Security issues with connecting pdf to database

    I have a pdf form that is being called from a webform as part
    of a web application. The PDF has two dropdown lists that I was
    populating from a SQL Server Database. I had created a special user
    that had select access only to the tables for the dropdowns.
    My question is are there any known security issues with
    regard to allowing a pdf to connect to a database this way. The PDF
    is being called from a secure connection but I don't know if
    opening this database connection to populate these dropdowns
    exposes a security hole of any sort. If it does, do you have a
    solution to make this secure? I am asking because another developer
    on the project brought up the issue of this design creating a
    security risk and I haven't been able to find anything online
    discussing it either way.
    Thanks!
    Maureen

    Hello Maureen,
    Thanks for posting, but I'm not sure I see if your question
    relates to Acrobat.com
    Are you using any of the Acrobat.com Services as any part of
    your workflow?
    Thanks!
    Pete

Maybe you are looking for

  • AiO Remote iOS app -scanning A4

    I have a Photosmart 5515 All in One printer and have been using the iOS app AiO Remote app to scan in some A4 pages. I set the app to scan to a document and also the page size to A4. Looking at the resultant document it has scaled the the document do

  • Dual display mavericks

    Hello, I bought a wire in the apple store last week, DVI to HDMI in order to conect two monitors. Now with mavericks os we can show a diferent desktops in each monitor but I can't with the wire. I just can do the same as in mountain lion (mirror). Do

  • How to store output data in JCOP scripts?

    Hello! I want to create JCOP script files that can use the output data from one call as input data to the next. Is this possible? If yes, how do I do it? like: /send command ->outputdata 9000 /send command+outputdata Thanks in advance!

  • I can't download iPhoto from App Store

    Everytime I try to install iPhoto from the App Store it tells me, "These apps cannot be accepted on this computer." Can someone help figure out whar is it that I need to do?

  • How to use DBSequence ?

    Hello everybody ... I'm using JDeveloper 11.1, JDK 1.6 , ADF Fusion web application. I have two projects for that application, Model and View projects. At Model I have entity object base on Oracle XE database table, there is sequences at that table a