You are now on my old blog. Please update your bookmarks to my new blog
http://laurentschneider.com




21 April 2006

dbms_sheduler jobs

I read in blog from Pete Finnigan about the potential security hole in DBMS_SCHEDULER package.

DBMS_SCHEDULER as a new alternative for DBMS_JOB by Patrick Sinke

Note that on some OS, like AIX5L / oracle 10.2.0.2, the job runs as ORACLE, not as NOBODY

1 Comments:

Blogger Laurent Schneider said...

but it does not run binaries, just interpreted shell scripts, so if you do not access to the system, you probably will not find a script to harm... you cannot run something like rm or mkdir

21/4/06 14:09  

Post a Comment

<< Home