Re: Security Question

  • From: Jared Still <jkstill@xxxxxxxxx>
  • To: cjnewman@xxxxxxxxxxxxx
  • Date: Thu, 5 Feb 2009 09:16:47 -0800

The following google search...
http://www.google.com/search?hl=en&rlz=1B3GGGL_enUS218US224&q=%22alter+session%22+dump+data+blocks&btnG=Search

... found several methods for dumping blocks with 'alter sesssion';

http://www.ixora.com.au/scripts/sql/dump.sql
http://bbs.erp100.com/archiver/tid-10972.html
...

Jared Still
Certifiable Oracle DBA and Part Time Perl Evangelist



On Thu, Feb 5, 2009 at 8:55 AM, Newman, Christopher
<cjnewman@xxxxxxxxxxxxx>wrote:

> Pete Finnigan recently (yesterday) wrote a blog entry regarding
> instrumentation and security
> (http://www.petefinnigan.com/weblog/entries/index.html) .  In one
> section it states "...Imagine that most users have the ALTER SESSION
> system privilege and therefore they can dump data blocks; imagine that
> we have secure some data in the table using VPD; this same method allows
> bypass of VPD."
>
> It was my understanding that ALTER SYSTEM was needed to dump blocks,
> *not* ALTER SESSION.  Can anyone clarify?
>
> Thanks - Chris
>
> --
> //www.freelists.org/webpage/oracle-l
>
>
>

Other related posts: