Kevin,
 
That has been my point in the past.  It is really not feasible to establish connection policy this way.
 
For example:  anybody can change the name of the sqlplus.exe executable on their desktop, run it, and connect to the database.  v$session.program now reports the new executable name - not sqlplus.
 
The same goes for any tool on the desktop - including odbc connections.
 
Security policy has to start at the account/password level.
 
Tom Mercadante
Oracle Certified Professional
-----Original Message-----
From: Kevin Lange [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, September 10, 2002 1:54 PM
To: Multiple recipients of list ORACLE-L
Subject: RE: methodology to keep only certain programs to connect to

With a setup like this, how do you stop a user from simply renaming the program they are using to match what you expect to see and, therefore, getting past your security ??
-----Original Message-----
From: Shaw John-P55297 [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, September 10, 2002 11:59 AM
To: Multiple recipients of list ORACLE-L
Subject: RE: methodology to keep only certain programs to connect to

use v_$mystat - it has the sid - then do your join with v$session
-----Original Message-----
From: JOE TESTA [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, September 10, 2002 10:58 AM
To: Multiple recipients of list ORACLE-L
Subject: methodology to keep only certain programs to connect to

I've been tasked to ensure only certain app programs access the database.
 
I'm thinking on-logon trigger, check the program field from v$session.  unfortunately v$session is for all sessions, i can't seem to find the view that tells me only MY info during login.  I only want the sid, serial#, username and program for my just now connection to the database.
 
Does this exist or am I going about this the wrong way?
 
We're thinking of checking those fields to make sure sql*plus, toad, etc can't connect as a particular user(even though the password is known out in the community).
 
any ideas would be greatly appreciated.
 
joe
 

Reply via email to