[12762] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Oracle 8i questions

daemon@ATHENA.MIT.EDU (Martin.Wunderli@JUNGLE.CH)
Mon Nov 29 15:39:35 1999

Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Message-Id:  <199911290413.FAA05491@sherekhan.jungle.ch>
Date:         Mon, 29 Nov 1999 05:13:23 +0100
Reply-To: Martin.Wunderli@JUNGLE.CH
From: Martin.Wunderli@JUNGLE.CH
X-To:         Brock Tellier <btellier@USA.NET>, bugtraq@securityfocus.com
To: BUGTRAQ@SECURITYFOCUS.COM

Hi,

>EXECS_NOT_TO_UNSET="oracle dbsnmp"
>From what I've read on the Oracle support page, the "oracle" program MUST be
>setuid-oracle if it is in a multi-user environment

No, it does not need to. If you connect through sqlnet (that is: a listener
running as oracle which starts the oracle
binary), no sgid/suid needs to be set. But if you then try to connect directly
by issueing sqlplus username/password, it will fail with 'Oracle not
available'. The latter is mostly not really a problem.

Cheers
Martin

--
Martin Wunderli, Grundstrasse 11, 8048 Zuerich, Tel:   +41  1 400 21 71

home help back first fref pref prev next nref lref last post