Security question - restricting access to a specific application

Hello,
Looking for suggestions on how I could limit connections to a database to a specific application. Here is the scenario.
I have an application running from a desktop that has oracle accounts for each user. The user has a read only role by default that I cannot alter. This means that the user can use excel (for example) and bypass the application to look at sensitive data.
I know I can lock down the desktop, remove excel, etc, etc. However, I'm looking for other options that could be used, be it process, additional Oracle software (the database is 10R2 enterprise edition), etc.
Problems: The app doesn't identify itself internally. I can see the program, but that is easily faked so thus unreliable.
Any suggestions at all?

I'll look at VPD again, but don't think the vendor will support us if we do.
We are unable to modify the app - third party supported
exactly - dont want toad, excel, sql*plus, whatever accessing the db from the same host.
thought above secure app roles as well, but need something concrete that I could validate agianst. If the app could call it and supply that, great but I cannot alter the application. I'm using secured app roles in an in house app and it does work well.
looking with our ti staff about encapsulating the application communication through a secure vpn tunnel into the data zone. may be an option as all other connections would not make it through the firewall into the data zone. (everything is internal, just to be segmented).
Edited by: GPC on Aug 26, 2010 12:18 PM
Edited by: GPC on Aug 26, 2010 12:22 PM

Similar Messages

  • Restrict access to a specific method in JSE

    Hello all,
    I'd like to know if there is a way to restrict access to a specific method in JSE. Basically, my intention is to do this:
    Subject.doAs(subject, new ProtectedMethod());
    // only users with a specific role can access this method
    // (permission specified in my policy file?)
    public class ProtectedMethod implements PrivilegedAction<String> {
       public String run() {
    }I believe that is not possible to specify a method name in policy file via java.lang.RuntimePermission "accessDeclaredMembers", so is there another way to do this?
    Thanks in advance,
    Andre

    I am not an expert of this media hub, but what I would like to know is that are you referring to the security you have setup with the original folders? So after you have created a backup, whatever type of access you have setup was removed? Can you please elaborate?
    Check the FAQ's for NMH305 from here: http://support.linksys.com/en-us/support/storage/NMH305

  • HT204266 How can I change my security questions to access I tunes store?

    I just got a new I pad and I am trying to purchase from the I tunes store but I cannot remember the answers to my security questions and now I can't access it. What can I do?

    Welcome to the Apple Community.
    You might try to see if you can change your security questions. Start here, change your country if necessary and go to manage your account > Password and Security.
    I'm able to do this, others say they need to input answers to their current security questions in order to make changes, I'm inclined to think its worth a try, you don't have anything to lose.
    If that doesn't help you might try contacting Apple through Express Lane (select your country, navigate to iCloud help and enter the serial number of one of your devices)

  • HT1491 How do I change my security questions in order to purchase new applications?

    How do I change my secuirty questions? The ones that pop up when I am trying to purchase a new application. I don't
    know the answers or remember setting them up.

    From a Kappy  post
    The Best Alternatives for Security Questions and Rescue Mail
    1.  Send Apple an email request at: Apple - Support - iTunes Store - Contact Us.
    2.  Call Apple Support in your country: Customer Service: Contact Apple support.
    3.  Rescue email address and how to reset Apple ID security questions.
    An alternative to using the security questions is to use 2-step verification:
    Two-step verification FAQ Get answers to frequently asked questions about two-step verification for Apple ID.

  • I forgot my security questions to access my account on another devise

    I forgot my security question answers. How can I reset them or find them

    http://support.apple.com/kb/HT5312
    -If you established a rescue email address, there will be a link on the "Passwords & Security" page of id.apple.com.  Clicking the link will send the reset to your rescue email address (NOTE:  This is not the same address as your Apple ID email)
    -If there is no link on the page, then you didn't establish a rescue email address.  Contact AppleCare at 800.694.7466 (If you are in the US), and ask for account security.  You will need to answer some questions to verify your identity, AND you will need access to a computer to generate a temporary support pin.
    -If you are not in the US, click http://support.apple.com/kb/HT5699 - Apple ID: Contacting Apple for help with Apple ID account security
    HTH

  • Disable Java Security Warning: Allow access to the following application from this web site?

    Dear all,
    When I open web intelligence with BI launchpad, this warning has been shown:
    "The web site is requesting access and control of the Java application shown above. Allow access only if you trust the web site and know that the application is intended to run on this site.
    Allow access to the following application from this web site?"
    and it has just three button of "Yes", "No" and "Help".
    I go to Java Control Panel and Security tab, then set security level on the "Medium" and add my site in the Exception Site List but this warning is shown each time I open web intelligence.
    I have searched the internet very much but I haven't found any solutions for disabling of it. How can I disable this security warning?
    Java version 7 update 67
    windows XP
    SAP BusinessObject BI Platform 4.1 Support Pack 4 Patch 2
    best regards,

    Hello,
    We have the same issue with BI4.1 SP3 FP3.
    Can anyone help us ?
    Nawale.

  • Need to restrict access to multiple servlet applications on same box

    Hi!
    I have deployed two separate servlet applications to the same IAS. I need
    to restrict access to each application - that is requests from one source
    should only have access to one application and not the other. The web
    server we are using is IIS.
    Should I create a separate IAS to deploy the second application to? Can I
    restrict based on IP - that is port 80 is reserved to application 1 while
    port 81 is restricted to application 2? If so, how do I go about this? It
    appears that the web connector only receives on one port (default 80).
    Any help would be greatly appreciated.
    Sheila

    I see. So do you mean that I can override the port number in the proxy startup script itself? I can try doing that and see if it works fine.
    About Coherence 3.7, yes. I did see that it has some cool features about proxy discovery. But at this point I am stuck at using 3.6 and 3.6.1.
    Edited by: online19 on Jun 29, 2011 5:41 PM

  • I forgot my security question to accessing itunes purchases

    how do i reset my security question for itunes access?

    You need to ask Apple to reset your security questions; this can be done by phoning AppleCare and asking for the Account Security team, or clicking here and picking a method, or if your country isn't listed in either article, filling out and submitting this form.
    They wouldn't be security questions if they could be bypassed without Apple verifying your identity.
    (106162)

  • How do i delete a icould email from my iphone when i no longer have access to the email address and my security questions dont match to get in to the account?

    I am trying to delete my icloud account from my iphone as i no longer have access to this email and when i try to challenge the security question to access the account apparently i dont know my own date of birth. I cant delete the account as i dont remeber the passwrod and i have a new icloud account that i would like to link the phone to. Any help would be appreciated
    thanks

    If the old ID (iCloud account) is yours, and if it is an earlier version of your current ID, go to https://appleid.apple.com, click Manage my Apple ID and sign in with your current iCloud ID.  Click edit next to the primary email account, change it back to your old email address and save the change.  Then edit the name of the account to change it back to your old email address.  You can now use your current password to turn off Find My iDevice, even though it prompts you for the password for your old account ID. Then save any photo stream photos that you wish to keep to your camera roll.  When finished go to Settings>iCloud, tap Delete Account and choose Delete from My iDevice when prompted (your iCloud data will still be in iCloud).  Next, go back to https://appleid.apple.com and change your primary email address and iCloud ID name back to the way it was.  Now you can go to Settings>iCloud and sign in with your current iCloud ID and password.
    This will not work if your current ID is an entirely new ID and is not a newer version of the old ID.

  • Security questions are different than questions I originally answered can't access iTunes for new ipad

    Need to answer security questions to access new iPad, security questions are different than what I originally answered.

    Doubtful.

  • How to change AppleID password without access to security questions or rescue email?

    Hi,
    I am curious how a friend managed to change his AppleID password via his iPhone without knowing the answers to the security questions or access to the rescue email. As someone else helped him with the process (not an Apple employee), he hasn't been able to explain it. I still haven't been able to figure how it was done. Wonder if anyone out here could shed some light, thanks!

    Hi there mokcl,
    You may find the troubleshooting steps in the article below helpful.
    If you forgot the answers to your Apple ID security questions
    http://support.apple.com/kb/HT6170
    If you can't reset your security questions
    Contact Apple Support in either of these circumstances:
    You don't see the link to send a reset email, which means you don't have a rescue address.
    You see the link to send a reset email, but you don't have access to email at the rescue address.
    A temporary support PIN isn't usually required, but Apple may ask you to generate a PIN if your identity needs to be verified.
    -Griff W.

  • SSH login- how do I restrict access to a shared folder?

    I have created Shares in WGM for SMB and AFP access on my OS X 10.4.8 Server. However when I connect via SSH it's not restricting access to the folder based on the User Name I login with- I see the entire volume! How do I restrict access to a specific folder based on a user name setup in WGM? ACL's?

    Hey George,
    It sounds like you are trying to limit ssh/sftp users to a specific area, aka jails. The FTP server lets you 'chroot' users to a certain area making it appear as the root thus preventing them from navigating up the hierarchy, which is what I think you, and me and many others are trying to accomplish.
    The ssh compiled into OS X is missing this very needed feature. There have been a few documented workarounds, but they've either been too insecure or too clunky for me.
    I've dealt with the fact that my users can get to the root of the hard drive, and have just been very careful about my privileges (by using ACLs), thus preventing them from getting inside areas they shouldn't.
    There's a good write up here: http://www.schwie.com/brad/macosxsftpchroot/ and if you include the term 'chroot' in your searches, you should find a bit about it here too.
    And Roger, I think George meant the file sharing protocol used by ssh. man sftp.

  • TS3297 itunes 10.6.1 now asking for 3 security questions. After input I get "error in the itunes store -1202". I cannot purchase from the store.

    Running Vista Ultimate. Itunes 10.6.1 is now asking to answer 3 security questions before accessing the store. After entry I get "error in the itunes store -1202" I cannot purchase music at this point. Any help is appreciated.

    This problem is resolved. I deleted the old iTunes (with write permissions turned on for my account) and reinstalled successfully. Removing the deleted iTunes from Trash was troublesome even with root but after playing around with permissions and flags, I was able to remove it.

  • HT5312 i forgot the answer to my security question which was required by apple to purches an app.. i would appricate any advice on what i should do.   thank you

    i forgot the answer to my security question which was required by apple to purches an app.. i would appricate any advice on what i should do.
    thank you.
    Mosab azdein

    Hi Mva,
    If you set up a Rescue email address:
    Go into Manage Your AppleID, https://appleid.apple.com/cgi-bin/WebObjects/MyAppleId.woa/, select Password and Security, and click the first option (see below), and you will be able to proceed from there..... (I HOPE the first button is showing for you!)
    Reset your password
    You can change or reset the password for your Apple ID account by providing some information.
    Select your authentication method.
    Email authentication: To access your information, we will send an email to the rescue email address on file for you.
      Answer security questions: To access your information, you will need to answer the security question(s) provided when you originally created your Apple ID.
    If you did not set up a Rescue email address:
    1. Go to Express Lane  and select 'iTunes' from the list of 'products' in the middle of the screen.
       Then select 'iTunes Store', and on the next screen select 'Account Management'
       Next choose 'Apple ID Account Security' and fill in that you'd like your security   
       questions/answers reset.
    You should get an email reply within about 24 hours (and check your Spam folder as well as your Inbox)
    2. Once your questions have been reset, and you set up new ones, also set up a RESCUE EMAIL ADDRESS, so if you forget them again, you won't have to go through all of this.....
    Hope this helps!
    Cheers,
    GB

  • Ability to restrict access to different Plan Types in Planning 11.1.2 ?

    Hi, we're running Planning/EPM version 11.1.2, with DRM and EPMA.
    We're creating a new Plan Type (Plan 2) within the Planning app, and if possible I'd like to restrict access to this 2nd plan type to only a small group of users. This 2nd plan type would be for additional what-if testing and we don't want their work to interfere with the main cube in Plan 1. Is it possible to use security provisioning or another technique so I can restrict who can have access to Plan 2?
    Also if I can do this, is it also possible to have Planning data forms that are only visible to Plan 2 and it's users?
    Thanks in advance.

    You can restrict forms easily using groups and/or direct provisioning.
    Typically you will always have security on your scenario dimension; I suggest using scenario or version security to restrict access to your data.
    Regards,
    John A. Booth
    http://www.metavero.com

Maybe you are looking for

  • How can I check DATA in BSEG for PO date corresponding (time period)

    PO date (BSTDK) but in bseg I only can find BLDAT AUGDT and it is also can not find in bkpf only can find it in VBAK

  • Firefox not displaying fonts and sizes properly

    In firefox the fonts are not displaying properly they are either bold or small and bold some text is displayed normally but most is not most is either really small or bold. This is also the case for IE, im on windows 7 running latest versions. Howeve

  • Memorex 52 max CDRW  burns but does not playback after installing 7.0

    I have a Memorex 52 MAx CDRW which worked fine with version 6.0, but after installing 7.0 and all recent upgrades it will burn the playlist ok but when attempting to playback recorded or regular cd music, it will skip from one song to the next on the

  • Can't active iPhone 5

    I have Iphone5. I use it very well in 2 months. But this morning I found require activation on the screen.I tried all the way but could not be activated.Can you help me. DN*******8GH <Edited By Host>

  • Forms 9i Debug

    Hello, I try to debug my Form remotly. The Application Server runs on an Unix machine and my Forms Builder on Windows XP. I entered the port and host information in the attach debug dialog. After run form I get the error message FRM-40010: Cannot rea