Oracle Training Oracle Support Development Oracle Apps

 
 Home
 E-mail Us
 Oracle Articles
New Oracle Articles


 Oracle Training
 Oracle Tips

 Oracle Forum
 Class Catalog


 Remote DBA
 Oracle Tuning
 Emergency 911
 RAC Support
 Apps Support
 Analysis
 Design
 Implementation
 Oracle Support


 SQL Tuning
 Security

 Oracle UNIX
 Oracle Linux
 Monitoring
 Remote s
upport
 Remote plans
 Remote
services
 Application Server

 Applications
 Oracle Forms
 Oracle Portal
 App Upgrades
 SQL Server
 Oracle Concepts
 Software Support

 Remote S
upport  
 Development  

 Implementation


 Consulting Staff
 Consulting Prices
 Help Wanted!

 


 Oracle Posters
 Oracle Books

 Oracle Scripts
 Ion
 Excel-DB  

Don Burleson Blog 


 

 

 


 

 

 

 

DBA charged with data theft

Lewis Cunningham alerts us to this press release about a DBA named William Sullivan who is charged with charged stealing for profit, taking sensitive data and selling it to criminals:

“About 2.3 million records are believed to be at issue, including about 2.2 million [records] containing bank account information and 99,000 containing credit card information, Certegy said in a release.”

A web search suggests that Fidelity National is an Oracle shop, although this “inside job” could have happened on any database product.

This “inside job” theft by a trusted DBA is a serious area of Oracle security and many products how audit the DBA:

  • Oracle Data Vault  – Cunningham notes: “Oracle Data Vault uses Virtual Private Database/ASO to prevent DBA access to application data. The DBA can still manage and maintain the database but cannot view or change application data.”
     

  • Lumigent Integra – Lumigent has a product (Integra) that does not allow the DBA to bypass Oracle auditing and detects data theft.

Oracle DBA’s threats include the following: 

·         Root kit attacks – In a root kit attack, the operating system is compromised.  I once fixed a client site with a root kit that had installed a daemon process that was constantly accessing confidential information and e-mailing Oracle to a competitor.  This attack went undiscovered for more than a year and virtually all of the company’s proprietary information was lost.

·         Fire-me attacks – Internal Oracle personnel have been know to write routines that trigger a Oracle data extraction on the day when their user ID is removed from the computer system.  Because most Oracle procedures required pulling the user ID before notifying the employee, these hackers will return home to find all of the confidential information waiting for them in their in-box.
 

·         Trojan horse – Once an employee gets the internal IP address of another employee, they can map-out phony sign-on screens to their boss and get a privileged password.  These attacks are usually easy using tools such as X-Windows that allow screen images to be redirected onto other screens.

 

·         PC Privacy tools – Common tools such as PC Anywhere can be used to look-over the shoulder of a co-employee, snooping into their activities and passwords.

For more examples of inside jobs by DBA’s, read my article on database horror stories.



 

 
 
��  
 
 
Oracle Training at Sea
 
 
 
 
oracle dba poster
 

 
Follow us on Twitter 
 
Oracle performance tuning software 
 
Oracle Linux poster
 
 
 

 

Burleson is the American Team

Note: This Oracle documentation was created as a support and Oracle training reference for use by our DBA performance tuning consulting professionals.  Feel free to ask questions on our Oracle forum.

Verify experience! Anyone considering using the services of an Oracle support expert should independently investigate their credentials and experience, and not rely on advertisements and self-proclaimed expertise. All legitimate Oracle experts publish their Oracle qualifications.

Errata?  Oracle technology is changing and we strive to update our BC Oracle support information.  If you find an error or have a suggestion for improving our content, we would appreciate your feedback.  Just  e-mail:  

and include the URL for the page.


                    









Burleson Consulting

The Oracle of Database Support

Oracle Performance Tuning

Remote DBA Services


 

Copyright © 1996 -  2017

All rights reserved by Burleson

Oracle ® is the registered trademark of Oracle Corporation.

Remote Emergency Support provided by Conversational