Make it secure

I have created a Oracle Form.
I transfered this form onto Oracle Apps Server.
Its working fine.
This is a simple FORM.
Functionality of the user_unlock FORM is as follows:
Its allows user to unlock account.
This FORM base on all_users table.
when user run this form.
First user need to serach the name on
enter the name in the text field.
when user clicks on the button its unlock the user account.
I have wrote a procedure in my database.
execute this procedure on when_button_pressed trigger.
For this process make little secure.
I have created a user abc with create session privileges.
I have granted above procedure to the new user.
I add one database logon FORM in this process as below:
Now our non-oracle help desk user browse the url.
database logon FORM popup,
all username/password/strings values are already there.
They need to click on logon button will bring unlock FORM.
And helpdesk user will unlock the account.
Here are my worries:
What is to prevent someone from unlocking the privileged accounts that have
well known default passwords that are now shipped as locked?
The search facility makes it possible for a hacker to l
earn all the usernames on the database with a wildcard search.
How can I make it secure?
DN

DN, you asked this before I answered it.
Re: How to give limited privileges to the user to  perform required duties?
If you don't like that answer, please say so and why. Another alternative you might consider if you don't have an application user table and must use ALL_USERS is to create a role for your application and grant that role (without admin) to your application users. You can then join ALL_USERS with USER_ROLE_PRIVS in your block and eliminate all but the users of your application.

Similar Messages

  • How do you make a secure pdf form editable?

    How do you make a secure pdf file editable?

    The best way is to apply a digital signature to the file. Any other way can
    be manipulated quite easily.

  • Why can I not make a secure connection using safari?

    why can I not make a secure connection using safari?

    I have the exact same problem.  I just updated to 4.3.3 and now my inline controls on my earphones don't work.  The earphones work, but the controls don't.  It doesn't even recognize that there is a mic attached.  Even with the earphones in it still uses the built in mic. Why did my controls stop working?!

  • How to make adf security?

    Dear all
    How to make adf security?
    I am new adf security.
    I'm facing security issue. Now i need to secure me application (User, Group, Role etc...)
    Oracle recommend me use WebLogic internal LDAP or OID. How to manage User, Group, Role deploy after?
    Thanks Lhagva

    Hi,
    once you deployed an application, users and roles are no longer in the domain of ADF Security. So the administration is
    WLS console - if users and groups are in the WLS LDAP
    Identity Management - if users and roles are in OID, RDBMA, Active Directory etc.
    Enterprise Managers - to manage application roles and granting permissions or application roles to enterprise groups
    Frank

  • Make a secure pdf unsecure

    Is it possible to make a secure pdf unsecure using Adobe Acrobat Pro?
    Basically, I am trying to add text using the Edit Document Text tool, but I cannot and I believe it is because it is secure.

    Everything Dave Merchant has said is reasonable and I have nothing against protecting intellectual property or copyright. But I am not talking about unsecuring a pdf in order to
    copy content. I am talking about adding an image filee to a pdf so that it can
    contain my signature.
    I do not doubt that the ingenuity of Adobe engineers cannot find a way to protect the contents of a document, prevent them from being copied, altered, etc., while still allowing a third party user to add a signature to that document. I cannot see how anybody is harmed by allowing a
    signature on a document, and surely there can be a nuanced approach to
    protecting intellectual property without banning all modifications to a document.
    I am also discouraged in having discovered that Bluebeam Revu is also taking an approach similar to Adobe. With Revu v7, I was able to add my signature to secured documents. Now, with v11, which I just spent a lot of money on, I can do nothing but view a secured document. That’s another pdf company that is not taking a nuanced approach to pdf protection …

  • ITunes is extremely slow and I cannot make a secure connection

    When I connect to iTunes my computer is extremely slow, and when I try to connect to the iTunes store I get the error message cannot make a secure connection.  I have internet access and I have ran the iTunes diagnostics test and all the tests passed except making a secure connection.  I have disabled all of my security systems including my firewall and Norton.  I am not running any proxy settings.  This has been an ongoing problem for over a month and I am at a loss. 

    Check out this Apple article -> iTunes: Advanced iTunes Store troubleshooting
    Blocked by configuration: (Mac OS X/Windows)
    Configure Internet Options (for Windows computers only):
    Run iTunes Diagnostics. If the "Secure link to iTunes Store" section does not pass, do the following.
    Open Internet Explorer.
    From the Tools menu, choose Internet Options.
    Click Connections.
    Under "Dial-up and Virtual Private Networking," choose "Never dial  a connection." It may not be possible to choose this if you’ve never used  dial-up Internet; if this is the case, skip to the next step.
    Click LAN Settings.
    In the window that opens, enable the option to "Automatically detect  settings" if it is not enabled.
    iTunes uses Internet Options proxy settings. Apple recommends  removing proxy settings that interfere with access to the iTunes Store  if needed.
    Click OK.
    Click the Advanced tab.
    Scroll down to the Security section and look for the option to "Check for server certificate revocation." If it is enabled, disable it.
    Look for Use SSL 3.0 and Use TLS 1.0. Make sure at least one of  those two checkboxes is selected and click OK (You can select both checkboxes).
    Apply any changes, and restart your computer if you modified the option to "Check for server certificate revocation" (step #11).

  • Safari cannot make a secure connection to Google or Youtube--but only on my home network

    Recently, when I am on my home network, I cannot connect to Google or Youtube.  When I try to, I get an error message that says that Safari can't make a secure connection to the site.  (I can connect to these sites with Firefox at home though)  However, when I am at work, both Google and Youtube load just fine on Safari.  Any idea what could be causing this?  I suspect that it's the repeater that my landlord installed in my apartment, but I really have no idea.
    I am running Mavericks (10.9.4) on a 15-inch, late 2011 MacBook Pro.

    Hello Punxsutawney Phyllis,
    Thanks for using Apple Support Communities.
    See the article below to troubleshoot this error message you are receiving.
    Mac OS: "Unable to establish a secure connection" or "can't verify identity" messages in Web browsers
    http://support.apple.com/kb/TA20405
    Take care,
    Alex H.

  • Can I make iPad Security Copies on Time Capsule?

    Can I make iPad Security Copies on Time Capsule?

    Sorry, I am not sure what a Security Copy might be, but if you are asking about backups, the iPad and other iOS devices back up to iTunes on your computer.
    Then, if you have the computer setup to backup to the Time Capsule, the backups of the iPad are copied over from the computer.
    So, the iPad backs up indirectly to the Time Capsule.
    The iPad can also back up directly to iCloud if you prefer.
    See this Apple support document for more details abut iOS backups.
    http://support.apple.com/kb/ht1766

  • Upgrade of Business Objects v3.0 to v3.1 makes folder security disappear

    Hi All,
    re: Upgrade of Business Objects v3.0 to v3.1 makes folder security disappear
    We just upgraded to v3.1 and the security I put in place in v3.0 did not carry over for the folders. Our company wanted to secure the folders per SAP security role, so I did that by breaking the inheritence relationship from the Root Folder on child folders that they should not have access to (see SAP note#1281763 for explaination on this type of procedure). It worked fine in v3.0, but after the upgrade, all of those changes had disappeared and every SAP role was able to see every folder. This was a major effort to secure those folders and I do not want to do it again. Also, we did import the roles into the upgrade BO v3.1 before we imported the BO structure, which as told to us by SAP, would work and not cause this issue.
    Thanks for your help!

    Hello Gary,
    I recommend to post this query to the [BusinessObjects Enterprise Administration|BI Platform; forum.
    This forum is dedicated to topics related to administration and configuration of BusinessObjects Enterprise, BusinessObjects Edge, and Crystal Reports Server.
    It is monitored by qualified technicians and you will get a faster response there.
    Also, all BOE Administration queries remain in one place and thus can be easily searched in one place.
    Best regards,
    Falk

  • TS1470 My itunes is unable to make a secure connection.

    My itunes is unable to make a secure connection
    I tried the methods given in the support but they haven"t working. I have two security systems running on my computer CA (only parental controls)and Microsoft security essentials.

    Close your iTunes,
    Go to command Prompt -
    (Win 7/Vista) - START>PROGRAMS>ACCESSORIES, right mouse click "Command Prompt", choose "Run as Administrator".
    (Win XP SP2 n above) - START>PROGRAMS>ACCESSORIES>Command Prompt
    In the "Command Prompt" screen, type in
    netsh winsock reset
    Hit "ENTER" key
    Restart your computer.
    If you do get a prompt after restart windows to remap LSP, just click NO.
    Now launch your iTunes and see if it is working now.
    If you are still having these type of problems after trying the winsock reset, refer to this article to identify which software in your system is inserting LSP:
    Apple software on Windows: May see performance issues and blank iTunes Store
    http://support.apple.com/kb/TS4123?viewlocale=en_US
    p.s.  Most security software parental controls are known to have caused secured connection issue.  If the above does not work, try disable or uninstall parantal controls.

  • HT5312 How do I first make a security email?

    I don't have one right now, but I need to make one in order to recover my security answers to the questions. But since I don't know those, I can't make the security email. It doesn't make a lot of sense to me, so I need to know how to do this. It would be great if I got some answers ^^

    You need to ask Apple to reset your security questions; ways of contacting them include clicking here and picking a method for your country, phoning AppleCare and asking for the Account Security team, and filling out and submitting this form.
    (97385)

  • How do I remove a wifi network account from iMac? Or how do I encrpyt an open wifi network account to make it secure?

    Somehow a wifi network connection  has been created either on my airport router or iMac or iPad which is non secured, I.e. Open. I cannot workout how to delete it or make it a secure connection. My concern is that other users may able to access my computers via this open wifi connection.
    What can I do to correct this?

    click on the wifi icon and go all the way down to network preference click and open it once you on network window on the bottom right there is a advance icon click that then you should be able to delete all the network that your mac is remember.
    hope this is help.

  • After having replaced the iMac hard drive I no longer can make iTunes security backups from my iPhone 4S?

    After having had my iMac's hard drive replaced (had a defect 1 TB Seagate) and the 10.8.2 reinstalled, I no longer can make security backups from my iPhone 4S. iTunes simply tells me that the backup cannot be saved on my computer (which it has done numerous times prior the replacement of the hard drive). Any suggestions on how to fix this?

    Click the green jelly button at top left of iTunes window to resize the screen to fit.

  • How to make a Secure User Authentication !!!!!!!!

    Hello to all the experts out there,
    I am making a website, in which user has to logs in by entering his userid and password. after login, he can make a transaction of money from his account. u can think of it as an online banking site. so this must be secure login i.e password should not be stolen by any third party or proxies, so it must be encrypted; same account should not be accessed by two pc's at the same time etc. i have implemented it by using sessions only.
    checking userid and password from database if valid then store it to session and forward to welcome page page
    <%
    rs1 = stmt.executeQuery("select userid, password from users where userid = '" + vuserid + "' AND password = '" + vpassword + "'");
    if(rs1.next() )
    {   userExist = true;
         //user exists, now make session object
         UserInfo ui = new UserInfo();
         ui.setUserid(vuserid);
         ui.setPassword(vpassword);
         session.setMaxInactiveInterval(1800);
         session.setAttribute("UserInfo", ui);
    rs1.close();
    stmt.close();
    con.close();
    %>
    <jsp:forward page="Lwelcome.jsp" />
    <%
    then at each page i check the attribute UserInfo
    <%
    UserInfo ui = (UserInfo) session.getAttribute("UserInfo");
    if(ui != null && ui.getUserid().length() !=0 && ui.getPassword().length() !=0)
    %>
    // HTML code
    <%
    %>
    It works fine.
    plz tell me how to encript the password before sending it to server and should i also save the password in encripted form in the database?
    how to achieve single login? and also as i have created an instance of UserInfo class at the time of setting attributes in session(code given above), what is the scope of this object?
    Thanks in advance!!!

    Use HTTPS. Start the HTTPS session when they first access the login page and continue using HTTPS until they log out. This way the password will be encoded. Check the documentation for you application server as to how to set up HTTPS for you system.

  • Re: Unable to make a secure connection to Weblogic 9 with Jconsole

    Hi,
    I'm after some help configuring my jconsole 5 (or 6) command line and service URL to create a secure connection to a Weblogic 9.2 server (1.5 JVM). The weblogic runtime mbeans server is being used to host my custom mbeans. Here are the settings I'm currently using:-
    "D:\jdk1.6.0_13\bin\jconsole.exe" -J-Djmx.remote.protocol.provider.pkgs=weblogic.management.remote -J-Djava.class.path="D:\jdk1.6.0_13\lib\jconsole.jar;D:\jdk1.6.0_13\lib\tools.jar;D:\gmac\weblogic_client_jars\wljmxclient.jar" -J-Djavax.net.ssl.keyStore=d:\keystores\????????.jks -J-Djavax.net.ssl.keyStorePassword=??????? -debug service:jmx:<strong>t3s</strong>:///jndi/<strong>t3s</strong>://w.x.y.z:ppppppp/weblogic.management.mbeanservers.runtime
    This fails with the following error:-
    09-Apr-2009 11:40:18 com.sun.corba.se.impl.legacy.connection.SocketFactoryConnectionImpl <init><br />
    WARNING: "IOP00410201: (COMM_FAILURE) Connection failure: socketType: IIOP_SSL_WLS; hostname: 1.2@; port: 2089"<br />
    org.omg.CORBA.COMM_FAILURE: vmcid: SUN minor code: 201 completed: No<br />
    at com.sun.corba.se.impl.logging.ORBUtilSystemException.connectFailure(ORBUtilSystemException.java:2172)<br />
    at com.sun.corba.se.impl.logging.ORBUtilSystemException.connectFailure(ORBUtilSystemException.java:2193)<br />
    at com.sun.corba.se.impl.legacy.connection.SocketFactoryConnectionImpl.<init>(SocketFactoryConnectionImpl.java:73)<br />
    at com.sun.corba.se.impl.legacy.connection.SocketFactoryContactInfoImpl.createConnection(SocketFactoryContactInfoImpl.java:70)<br />
    at com.sun.corba.se.impl.protocol.CorbaClientRequestDispatcherImpl.beginRequest(CorbaClientRequestDispatcherImpl.java:152)<br />
    at com.sun.corba.se.impl.protocol.CorbaClientDelegateImpl.request(CorbaClientDelegateImpl.java:118)<br />
    at com.sun.corba.se.impl.protocol.CorbaClientDelegateImpl.is_a(CorbaClientDelegateImpl.java:211)<br />
    at org.omg.CORBA.portable.ObjectImpl._is_a(ObjectImpl.java:112)<br />
    at weblogic.corba.j2ee.naming.Utils.narrowContext(Utils.java:126)<br />
    at weblogic.corba.j2ee.naming.InitialContextFactoryImpl.getInitialContext(InitialContextFactoryImpl.java:94)<br />
    at weblogic.corba.j2ee.naming.InitialContextFactoryImpl.getInitialContext(InitialContextFactoryImpl.java:31)<br />
    at weblogic.jndi.WLInitialContextFactory.getInitialContext(WLInitialContextFactory.java:41)<br />
    at javax.naming.spi.NamingManager.getInitialContext(NamingManager.java:667)<br />
    at javax.naming.InitialContext.getDefaultInitCtx(InitialContext.java:288)<br />
    at javax.naming.InitialContext.init(InitialContext.java:223)<br />
    at javax.naming.InitialContext.<init>(InitialContext.java:197)<br />
    at weblogic.management.remote.common.ClientProviderBase.makeConnection(ClientProviderBase.java:138)<br />
    at weblogic.management.remote.common.ClientProviderBase.newJMXConnector(ClientProviderBase.java:79)<br />
    at javax.management.remote.JMXConnectorFactory.newJMXConnector(JMXConnectorFactory.java:338)<br />
    at javax.management.remote.JMXConnectorFactory.connect(JMXConnectorFactory.java:247)<br />
    at javax.management.remote.JMXConnectorFactory.connect(JMXConnectorFactory.java:207)<br />
    at sun.tools.jconsole.ProxyClient.tryConnect(ProxyClient.java:336)<br />
    at sun.tools.jconsole.ProxyClient.connect(ProxyClient.java:296)<br />
    at sun.tools.jconsole.VMPanel$2.run(VMPanel.java:280)<br />
    Caused by: java.net.UnknownHostException: 1.2@<br />
    at java.net.PlainSocketImpl.connect(PlainSocketImpl.java:177)<br />
    at java.net.SocksSocketImpl.connect(SocksSocketImpl.java:366)<br />
    at java.net.Socket.connect(Socket.java:519)<br />
    at com.sun.net.ssl.internal.ssl.SSLSocketImpl.connect(SSLSocketImpl.java:550)<br />
    at com.sun.net.ssl.internal.ssl.SSLSocketImpl.<init>(SSLSocketImpl.java:353)<br />
    at com.sun.net.ssl.internal.ssl.SSLSocketFactoryImpl.createSocket(SSLSocketFactoryImpl.java:71)<br />
    at weblogic.corba.client.security.SSLORBSocketFactory.createSocket(SSLORBSocketFactory.java:275)<br />
    at weblogic.corba.client.iiop.BiDirSSLORBSocketFactory.createSocket(BiDirSSLORBSocketFactory.java:61)<br />
    at com.sun.corba.se.impl.legacy.connection.SocketFactoryConnectionImpl.<init>(SocketFactoryConnectionImpl.java:55)<br />
    ......I've tried all secure protocols (IIOPS, T3S, and HTTPS) with the same result. Until I added the following to the command line I got an "unknown protocol error".
    -J-Djmx.remote.protocol.provider.pkgs=weblogic.management.remote
    I know the service URL works as I have a standalone java client which can make the connection using the same JVM arguments and service URL from my development machine, using any of the mentioned protocols. I can also access the server using IIOP from jconsole unencrypted, but this will need to be turned off eventually.
    Any help would be appreciated.
    Regards
    Andrew
    </p>
    Edit : 15-Apr-2009 :
    I've Also tried using weblogic.jar in the jconsole classpath rather than wljmxclient.jar and get the following error:-
    java.io.IOException
    at weblogic.management.remote.common.ClientProviderBase.makeConnection(ClientProviderBase.java:151)
    at weblogic.management.remote.common.ClientProviderBase.newJMXConnector(ClientProviderBase.java:79)
    at javax.management.remote.JMXConnectorFactory.newJMXConnector(JMXConnectorFactory.java:338)
    Caused by: javax.naming.ConfigurationException Root exception is java.net.MalformedURLException: no host: t3s://:0
    at weblogic.jndi.internal.ExceptionTranslator.toNamingException(ExceptionTranslator.java:45)
    at weblogic.jndi.WLInitialContextFactoryDelegate.toNamingException(WLInitialContextFactoryDelegate.java:773)
    at weblogic.jndi.WLInitialContextFactoryDelegate.getInitialContext(WLInitialContextFactoryDelegate.java:365)
    at weblogic.jndi.Environment.getContext(Environment.java:307)
    I did find one sun forum posting relating to problems connecting JConsole to SSL/TLS. In that case the poster ended up creating a new connector provider for jconsole to use. I don't know if this is relevant to my situation, and no code examples were made available for me to try. If anyone can offer some advice on things to check it would be a great help, or free alternatives to JConsole which are proven to work with secure protocols.
    Edited by: APD on Apr 15, 2009 2:55 AM

    Solution *Part 1"
    Well I've managed to get JConsole and Weblogic 9.2 working over a secure connection. Getting to the solution has involved a
    lot of searching on the web, and some help from Oracle support, but the biggest credit goes to a team from Xebia (France)
    for their blogsite with an informative article on the subject.
    Here are the links to the article
    Original in French:-
    http://blog.xebia.fr/2007/06/28/jconsole-et-weblogic-9
    Put through Google's translation toolset into English:-
    http://translate.google.com/translate?hl=en&sl=fr&u=http://blog.xebia.fr/2007/06/28/jconsole-et-weblogic-9
    Originally I reviewed this without translation, but not being a French speaker/reader I just skipped the text and looked at
    the code / setup examples. This lead me to my first breakthrough which was to add the following to the JConsole startup
    command:-
    -J-Djmx.remote.protocol.provider.pkgs=weblogic.management.remote
    and
    -J-Djava.class.path="D:\jdk1.5.0_16\lib\jconsole.jar;D:\jdk1.5.0_16\lib\tools.jar;D:\weblogic_client_jars\wljmxclient.jar"
    This forces JConsole to use the weblogic classes for the various protocols, rather than its own classes, and cured the problem
    of JConsole throwing an "Unknown protocol" exception when I tried to use T3, T3S, IIOPS or HTTPS. However it didn't cure the
    next problem, which depending on the version of JConsole, was either "Unknown host" or "Malformed URL".
    I experimented with using "Weblogic.jar" in place of "wljmxclient.jar" (both taken from my Weblogic installation), and got a
    different set of errors.
    After further searching on the web, with no success, I had the inspiration to put the Xebia article through Google
    translate to see if anything else popped out, and it did. It turns out that there is a mismatch in the way the userid and
    password typed into JConsole's GUI is passed to the underlying protocol "client provider", and then the server (this may
    just be a weblogic issue), so it becomes necessary to extend the weblogic classes with a version that puts the
    userid/password in the correct place before calling the original weblogic methods. Once done the classpath needs updating
    to include the jar for the new client provider classes, and the jmx.remote.protocol.provider.pkgs needs to point at those
    classes instead of the weblogic ones.
    Here's one of the client providers I created, derived from the sample code in the Xebia article:-
    package myproviders.jmx.remote.t3;
    import java.io.IOException;
    import java.util.HashMap;
    import java.util.Map;
    import javax.management.remote.JMXConnector;
    import javax.management.remote.JMXServiceURL;
    * Extended from the original Weblogic provider to correct the userid/password location problem.
    * Credit to the team from Xebia Business Intelligence Architects for the solution.
    public class ClientProvider extends weblogic.management.remote.t3.ClientProvider {
         private static final String local_protocol = "t3"; // just a debug constant
         public JMXConnector newJMXConnector(JMXServiceURL serviceURL,
                   Map environment) throws IOException {
              System.out.println("inside myproviders clientProvider.newJMXConnector()");
              System.out.println("Protocol is " + local_protocol);
              Map newMap = checkCredentials (environment);
              System.out.println("continuing with super.newJMXConnector()");
              return super.newJMXConnector(serviceURL, newMap);
         @SuppressWarnings ("unchecked")
         private Map checkCredentials (Map map)
              System.out.println("...inside myproviders clientProvider.checkCredentials()");
              // if the old map doesn't contain the new security properties
              if (!map.containsKey("java.naming.security.principal") && ! map.containsKey("java.naming.security.credentials"))
                   System.out.println("......Missing new format credentials");
                   // but it does contain the old one
                   if (map.containsKey("jmx.remote.credentials"))
                        System.out.println("......found old format credentials - transforming old to new.");
                        // build a new map containing the correct properties, as well as the old ones, so whichever
                        // version the server is expecting, it will get the values.
                        Map newMap = new HashMap();                    
                        newMap.putAll(map);
                        String[] cred = (String[])map.get("jmx.remote.credentials");
                        newMap.put("java.naming.security.principal", cred[0]);
                        newMap.put("java.naming.security.credentials",cred[1]);
                        return newMap;
              return map;
    ---------------------------------------------------------------------------------------------------------------

Maybe you are looking for

  • How to get the full result of a google search?

    How to get the full results of a google search? Nov 23, 2006 2:28 AM Hi, Friends, I want to build a URL collector as a seamless and integrated part of my desktop application in java language which can access the full search results of google, but i a

  • I just installed Maverick on my Mac, now I can't open Final Cut Pro!

    I just installed Maverick on my Mac. When I started Final Cut Pro, I got the message that probably it doesn't work with Maverick. Before that moment it was also impossible to update Final Cut Pro.  App Store directed me to Apple Menu looking for upda

  • Is there any way to find out the serial number to an old ipod that i cannot find?

    theres a recall on the od ipod nanos the 1st generation ones and i purchased one and im not sure when and currently i am unaware of the whereabouts of the ipod. is there any way to find out the serial number without actually finding the ipod to confi

  • Aleaud idoc in status 56

    hi i work in production support and new to idocs this is the problem given to me i have to solve it asap. when i check the idocs in we02 transaction it shows idocs in status 56 with a message ipartner profile inbound not available. DETAILED DESCRIPTI

  • Submit bug report

    I'd like to submit a possible bug. Bug: App Store doesn't close and the screen doesn't turn off after updating apps I used App Store to update my apps remotely before bedtime.  This morning, all the apps have been updated, but my iPad's screen was st