12
返回列表 发新帖
楼主: losingb

[讨论] 急求!在linux下的oracle如何防止蛮力攻击?有什么好的方法或防护手段吗?

[复制链接]
论坛徽章:
47
蒙奇·D·路飞
日期:2017-03-27 08:04:23马上有车
日期:2014-02-18 16:41:112014年新春福章
日期:2014-02-18 16:41:11一汽
日期:2013-09-01 20:46:27复活蛋
日期:2013-03-13 07:55:232013年新春福章
日期:2013-02-25 14:51:24ITPUB 11周年纪念徽章
日期:2012-10-09 18:03:322012新春纪念徽章
日期:2012-02-13 15:13:202012新春纪念徽章
日期:2012-02-13 15:13:202012新春纪念徽章
日期:2012-02-13 15:13:20
11#
发表于 2013-8-21 00:21 | 只看该作者
> still can't understand SEC_MAX_FAILED_LOGIN_ATTEMPTS how to "drop connections after the specified number of authentication attempts fail"

I have a feeling that we have to write a sophisticated maybe an OCI client program to test this. The program would initiate a connection so the server side process is started and a TCP connection is established. The program sends username and a wrong password. The server process rejects the logon but stays running because the client doesn't tell it to exit. The program tries another time with a wrong password, another time, another time, ... never telling the server process to exit. With SEC_MAX_FAILED_LOGIN_ATTEMPTS set, I imagine the server process will exit even if the client never tells it to. The problem with trying to simulate with Sqlplus is that I think Sqlplus quietly requests to the server process to exit after a failed logon. The OCI program we write should avoid doing that.

BTW, any such test should make sure your profile has failed_login_attempts set to unlimited to avoid its irrelevant interference.

使用道具 举报

回复

您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

TOP技术积分榜 社区积分榜 徽章 团队 统计 知识索引树 积分竞拍 文本模式 帮助
  ITPUB首页 | ITPUB论坛 | 数据库技术 | 企业信息化 | 开发技术 | 微软技术 | 软件工程与项目管理 | IBM技术园地 | 行业纵向讨论 | IT招聘 | IT文档
  ChinaUnix | ChinaUnix博客 | ChinaUnix论坛
CopyRight 1999-2011 itpub.net All Right Reserved. 北京盛拓优讯信息技术有限公司版权所有 联系我们 未成年人举报专区 
京ICP备16024965号-8  北京市公安局海淀分局网监中心备案编号:11010802021510 广播电视节目制作经营许可证:编号(京)字第1149号
  
快速回复 返回顶部 返回列表