Security review your database for default accounts with known passwords

Hi,
I have just added a new free tool to my web site that will test your
database for known default users and more importantly for known default
passwords. The tool is a set of PL/SQL scripts that loads a list of 474
known default users to a table. A package procedure is then used to loop
through all of the databases users to test if they are default and have
known passwords.
The list of passwords and users is supplied in a spreadsheet that
includes details of what most of the users are used for as well as a
severity rating for them. This is probably the biggest list of default
users available on the net.
The scripts were written by Marcel-Jan Krijgsman and are available from
http://www.petefinnigan.com/default/default_password_checker.htm
Kind regards
Pete
Pete Finnigan (email:[email protected])
Web site: http://www.petefinnigan.com - Oracle security audit specialists
Oracle security blog: http://www.petefinnigan.com/weblog/entries/index.html
Book:Oracle security step-by-step Guide - see http://store.sans.org for details.

Thanks, now I understand why the wifi keeps dropping. On my personal wireless network, it also seems the distance from the access point is not good compared to my laptop. At work our network & exchange teams don't seem to have the desire to struggle with this "toy" until customers start forcing its adoption. I am using OWA and it works fine over EDGE. I will share your posting with them.
Thank you again.
Dell   Windows XP Pro

Similar Messages

  • HT5576 Email sent Check your inbox for an email with instructions on how to reset your security information but i haven't got anytthng in my email

    Email sent
    Check your inbox for an email with instructions on how to reset your security information
      but  i haven't get anything in my email

    I never got mine either. I ended up scheduling for them to call me to reset my security questions.

  • Yahoo Email and Calendar will sync to my iPhone, but Contacts will not.  Selection for "Default Account" doesn't even show in the Contacts section within Settings on the iPhone.

    I have always had my Yahoo Email, Calendar and Contacts synched to my iPhone.  However, I noticed some Contacts weren't synching from the Yahoo account to my iPhone, so I thought if I just deleted the Yahoo account and added it back, I'd be fine.  That worked fine for my Email and Calendar, but now I have NO Contacts from Yahoo on my iPhone.  When I go to Settings, under Contacts, it doesn't even have the option for 'Default Account.'  Help!

    Hello Marsha,
    Thanks for using Apple Support Communities.
    It's not clear exactly what you're trying to accomplish here.  If you're wanting to set up SMS forwarding introduced in iOS 8, then please follow the directions below.  Also, your Apple ID should be an email address.
    To use Continuity for SMS and MMS with your iPhone and your Mac, iPad or iPod touch
    Your iPhone, iPad, and iPod touch need to use iOS 8.1, and your Mac needs to use OS X Yosemite.
    Sign in to iMessage on your iPhone, your other iOS devices, and your Mac using the same Apple ID.
    On your iPhone:
    Go to Settings > Messages > Send & Receive > You Can Be Reached By, and add a check to both your phone number and email address.
    Go to Messages > Text Message Forwarding, and enable the device(s) you would like to forward messages to.
    Your Mac, iPad, or iPod touch will display a code. Enter this code on your iPhone to verify the SMS feature.
    Connect your iPhone, iPad, iPod touch, and Mac using Continuity - Apple Support
    Take care,
    Alex H.

  • Sap FICO Certification for Financial Accounting with mySAP ERP 2005

    Hi,
    I would like to write SAP-FICO Certification for Financial Accounting with mySAP ERP 2005
    Topic areas:
    SAP overview, Financial Accounting Master Data, Document and Posting Control,Special General Ledger Transactions, Document Parking, Substitution and Validation ,Payment Program, Dunning Program, Correspondence, Interest Calculation,Evaluation Options in Reporting ,Closing Operations in Financial Accounting ,Asset Accounting,The New General Ledger,SAP Solution Manager.
    If anyone have the Material for above topics, please send me my mail Id: [email protected]
    if anyone appeared recently for certification for the same code, please send model questions and answers.
    i will be very thankfull to you.
    Regards,
    Satyaprakash

    Hi
    I am also writing SAP-FICO Certification for Financial Accounting with mySAP ERP 2005.
    Request you to send me whatever the material you have in this regard.
    thanking you in advance
    Suri

  • I have set up two users, one for myself and one for children.  The computer automatically logs in for the children with no password required.  When the children go to spotlight and type in a search criteria all of my files show up.  How do I prevent this?

    I have set up two users, one for myself and one for children.  The computer automatically logs in for the children with no password required.  When the children go to spotlight and type in a search criteria all of my files show and open up.  How do I prevent this?

    Log in to your account, and move all your files to your home folder. No other users should be able to access them there and they won't show up with a Spotlight search.
    Make sure your kids' account(s) do not have admin privileges.

  • How can i delete an icloud account with out password or access to old email

    how can i delete an icloud account with out password or access to old email

    If the old ID ("email address) is yours, and is an ealier version of your current iCloud ID, go to https://appleid.apple.com, click Manage my Apple ID and sign in with your current iCloud ID.  Click edit next to the primary email account, change it back to your old email address and save the change.  Then edit the name of the account to change it back to your old email address.  You can now use your current password to turn off Find My iDevice, even though it prompts you for the password for your old account ID. Then save any photo stream photos that you wish to keep to your camera roll.  When finished go to Settings>iCloud, tap Delete Account and choose Delete from My iDevice when prompted (your iCloud data will still be in iCloud).  Next, go back to https://appleid.apple.com and change your primary email address and iCloud ID name back to the way it was.  Now you can go to Settings>iCloud and sign in with your current iCloud ID and password.

  • Need MBAM 2.5 Helpdesk and selfservice sites to open for authenticated users with no password prompt

    I Need MBAM 2.5 Helpdesk and self service sites to open for authenticated users with no password prompt. I just cant seem to get this to work. The account used in the application pool has its SPN registered and delegation set. I can use that account to login
    to the sites but am prompted for a password. That said anyone I add into the helpdesk users group cannot negotiate the sites. Only the account I have set in the application pool can. I want domain authenticated users that have been added to the MBAM Help Desk
    Users group to negotiate the site with NO password challenge at all.
    tconners

    This generally means that your SPN is not set up correctly.  Let's say the web server you installed the SSP on is lance.contoso.com and your app pool creds are corp\lance.  You should set an SPN similar to setspn -s http/lance.contoso.com
    corp\lance.  In your browser, you should now be able to access the SSP without prompts.  However, if you still get prompted, generally that means that your local intranet zone in IE does not have an entry for *.contoso.com.  Since you are entering
    an FQDN in your browser, IE interprets the "." to mean "on the internet" which breaks Kerberos authentication.  By adding *.contoso.com to your local intranet zone, you are telling it that lance.contoso.com is on the intranet, so use
    Kerberos.
    I can confirm, that I have exact configuration and I always get the password promt for the very first time. We have 2 server (1xIIS and 1xSQL) infrastructure in production with SPN set like it should and I get the password prompt.

  • Mail account with 2 passwords

    I have this requirement. Client uses exchange server. Two people will have the same email account with different passwords.
    To open the mail account, both of them together have to provide the password in 2 steps. Can 2 static passwords can be supported in this scenario or it has to be like 2 step validation with one static password and one dynamic code received through a phone.
    How can the 2 static passwords can be implemented.
    Thanks
    ramakrishna

    Hi Ramakrishna,
    You seem to be interested in something like 2-factor or
    Multi-factor authentication (MFA), however 2 passwords for single
    AD account is not supported by Active Directory.
    Additional Info:
    Manage Risk with Conditional Access Control
    Under the hood tour on Multi-Factor Authentication in ADFS
    Using Multi-Factor Authentication with Active Directory Federation Services
    How to enable password + user certificate authentication in ADFS 3.0
    Regards,
    Satyajit
    Please “Vote As Helpful”
    if you find my contribution useful or “Mark As Answer” if it does answer your question. That will encourage me - and others - to take time out to help you.

  • HT5624 Restore back up of my iPhone-password not recognised. After restore, itunes can not restore because it says the password is incorrect. But I can sign into my apple account with the password.

    Restore back up of my iPhone-password not recognised. After restore, itunes can not restore because it says the password is incorrect. But I can sign into my apple account with the password.  My iPhone is now set to factory settings as a new phone, what can i do to access the back up from my phone before I reset it. 

    That does happen.  It depends on how hard the server is being hit, as well as the connection speed of your system.  If you are on a windows system, you will want to disable any antivirus or firewall software during the download.

  • I have backed up my old phone to itunes, however, when I try to restore data to new phone it is saying the password is incorrect but I can get into my itunes account with my password so I am doing something wrong?

    I have backed up my old phone to itunes, however, when I try to restore data to my new phone it is saying the password is incorrect but I can get into my itunes account with my password so I am doing something wrong?

    I'm having this EXACT same problem with my iPhone 4, and I have the same computer stats (I have a Samsung Series 7)

  • How do I create a default account with an ACS Server

    Has anyone seen this. I have an ACS Solution engine appliance with Several devices using it for authentication and accounting. It all seems to work great.
    When I add a new device (router or switch) i noticed that it will let me login via the acs based authentication even before i even setup the aaa-client account for this device in the acs appliance. I do have the tacacs key and all the appropriate information on the router or switch but i dont have an entry for it in the acs appliance yet. This has puzzled me Where is this default account setup. I have another ACS server (Windows Based) It seems to have a completely different behavior when it encounters an unconfigured AAA-client compared to the ACS Appliance. Can anyone tell me how to configure the ACS server to do the same and where these configuration options exist?
    This really concerns me from a security perspective.

    Hmm, ACS should not (by default) accept traffic from any old device.
    Could it be you have a wild-card IP Addr in your ACS network config somewhere that accidentally includes the new device?
    Or possibly a DNS name (instead of an IP Addr) that resolves to the address of the new device?
    Try changing the shared secret in the device - you should find you get errors in the Failed Attempts Log.
    Also check the Passed Authenications report as this included the ACS network config device name in the Access-Device column.

  • Clean up user certificate in Lync Database for Deleted Account

    Hi all,
    I have a case in which several user accounts have been deleted from AD. And not like Exchange, deleted user from AD does not remove Lync data (i dont get it why they design it differently).
    From lync server, get-csusercertificate and get-csuser for those deleted account has no result as expected.
    But when i use dbanalyze /report:user for those deleted account, the user certificate is still there.
    I run Update-CsUserDatabase -Force -FQDn xyz.domain.local still the user certificates are there.
    How can i clean up those certificates instead of waiting them to be expired?
    Thanks!

    Thanks for the feedback.
    Surely because of this issue, we need remove certificate on clients, and do the "proper" way for further account deletion. 
    If anyone curious about this case, I suggest everyone using Lync Server spend some time to try this scenario:
    1. Create user on your AD (ie: [email protected] wait for replication or force it)
    2. Enable Lync account for that user 
    3. Logon to a PC with Lync Client (i used Lync Client 2013), logon using the
    [email protected] , DONT FORGET To Save Password - that's what user usually do. You may do chat, add contacts, etc.
    4. From Lync server, with command prompt, go to Lync ResKit directory, run the following command dbanalyze.exe /report:user /user:[email protected] /sqlserver:<FQDN of Lync Server>\RTCLocal.
    At the bottom of the report, there will be information about the invoked certificate with Device ID, Publication Time, and Expiration Time, and the certificate itself. There will be more than 1 certificate for test.user if you logon to another PC and save
    the password too.
    5. Now, from user PC, logoff from Lync Client. Logon to your AD, delete [email protected], wait for some time for replication. 
    6. Now go back to user PC, sign in with Lync Client. Amazingly you're still be able to sign in to Lync, do the chat, and everything, as long as you haven't delete the sign in info.
    7. For admin perspective, you may use Get-CsUser for the [email protected], or Get-CsUserCertificate or any Get-CS command, there will be no [email protected] on your Lync Server, but if you use
    dbanalyze, there will be a quite information about that user along with their certificate. <= This is the one i haven't figure any way to clean it up.
    8. Funny thing is, if you ever notice on your Lync Server, the normal user account who logon and logoff using IM client app, will be logged on Lync Server eventviewer (Windows Log - Security). But the
    [email protected] will not be logged on the eventviewer, therefore you won't know where they are login from (what PC), like a ghost account.
    I am expecting at least there is some kind of other ResKit to clean up this junk data from server database.

  • Duplicate target database for standby failing with below error

    Hello All, Need your assistance
    We are creating a physical standby database (standalone) from 2 node RAC database, OS =RHEL5 and DB =11gR2
    What we did: We took RMAN backup of primary DB along with archives and copied to standby server in same location. We have modified necessory prameters on primary as well as standby too.
    The command we used :
    RMAN>connect target sys/pwd@primary auxiliary sys/pwd@stdby
    RMAN> run {
    allocate auxiliary channel ch1 type disk;
    duplicate target database for standby dorecover nofilenamecheck;
    release channel ch1;
    Note we tried : duplicate target database for standby as well as duplicate target database for standby nofilenamecheck methods too....But no luck..we are getting following error.
    channel ch1: reading from backup piece /u01/BDB/BWFCCPRD_5fmpdvce_1_1
    channel ch1: ORA-19870: error while restoring backup piece /u01/BDB/BWFCCPRD_5fmpdvce_1_1
    ORA-19501: read error on file "/u01/BDB/BWFCCPRD_5fmpdvce_1_1", block number 121856 (block size=8192)
    ORA-27072: File I/O error
    Additional information: 4
    Additional information: 121856
    Additional information: 1036288
    failover to previous backup
    released channel: ch1
    RMAN-00571: ===========================================================
    RMAN-00569: =============== ERROR MESSAGE STACK FOLLOWS ===============
    RMAN-00571: ===========================================================
    RMAN-03002: failure of Duplicate Db command at 10/20/2011 09:16:11
    RMAN-05501: aborting duplication of target database
    RMAN-05556: not all datafiles have backups that can be recovered to SCN 41855007833
    RMAN-03015: error occurred in stored script Memory Script
    RMAN-06026: some targets not found - aborting restore
    RMAN-06023: no backup or copy of datafile 4 found to restore
    RMAN-06023: no backup or copy of datafile 2 found to restore
    RMAN-06023: no backup or copy of datafile 1 found to restore
    could you pease help to resolve this ....?
    Note : Creating standby using RMAN 11g new feature : duplicate target database for standby from active database is not possible in our environment since the network bandwith is tooooo low, We have tried and not able to succeed because of n/w issue, So we are doing this alternate method...!!!
    Looking for your valuable advises...
    Thanks in Advance....

    Take the fresh backup and also check the space crunch. The below clink may help you
    ORA-27072: File I/O error Additional information: 2
    --neeraj
    Edited by: Vishen on Oct 20, 2011 2:14 PM

  • How do register for an account with firefox?

    I thought I had registered for Firefox - but it was Mozilla add-nos. No where do I see where I can set up an account with my info for auto-fill and my cell number so I can download Firefox Aurora onto my cell.
    You have a lot of info but it all seems to revert to Mozilla. I get that but I am trying to use you as primary web browser for my pc and cell, but just can't find where to start a Firefox account.
    I thought I was crazy, but I asked around and there are many that can't figure it out either and have told me you all just want to keep your community as is and not let anyone else in? That sound very odd. But it is an odd world.
    Thanks.

    hello, you don't need an account at mozilla to download firefox for your mobile - just get it from the google play store: https://play.google.com/store/apps/details?id=org.mozilla.firefox

  • I created a second email account with a password but when I try to get mail for it and I put in password it says login failed. Why? and how do I fix it.

    I created second email account ([email protected]) with a Password but when I try to get mail and enter password, it says "Sending of Password did not succeed. Mail server mail.comcast.net responded: login failed". What am I doing wrong?

    Have you logged on to the webmail account using a browser and enabled either Pop or Imap forwarding for that email address?
    Have you created a mail account in Thunderbird that uses the chosen webmail forwarding option?
    Password - make sure caps lock is not switched - it must be the same password you use to access the webmail account.
    check:
    Tools > account Settings > Server Settings
    username = full email address
    Please post info:
    In Thunderbird
    Help > Troubleshooting information
    click on 'copy text to clipboard'
    paste info in this question
    edit /remove all info on fonts and printers.

Maybe you are looking for

  • ParserException: XMLParser: Prefix 'c' is not mapped to a namespace

    Hello and thanks in advance for any help. I am trying to deploy a war (that worked with Tomcat 4.1) on SAP Web Application Server. In this war I have a JSP that says <?xml version="1.0" encoding="UTF-8"?> <jsp:root version="1.2" xmlns:jsp="http://jav

  • I received a strange text message - please help??

    Last night I received a text message on the iPhone but it appeared differently on screen - it took up the whole of the screen and had the telephone number at the top in large numbers - then the text message across the screen - and then a large 'DISCA

  • Capture START and END installation date on order line item

    Requirement: capture both start and finish dates for an installation program. Will likely require 2 new fields at order line item level. USEREXIT_MOVE_FIELD_TO_VBAP??? Any suggestion for this enhancement???

  • Adobe Elements 11 does not open

    I just bought the Full Version of Elemts 11 and installed it on  my PC. There was no Prblem during the installtion and I could enter the serial number. The icon for Elemtens 11 is on my desktop, but when I click it ther comes a message, that tells my

  • Compensating for tabs and leader dots when converting to HTML

    A FrameMaker document contains a series of "tables" which are actually very long lists. They have the appearance of a TOC: a text phrase, a long line of leader dots, a tab, and a numeral at the end of the dots. Since the tabs and leader dots vanish w