Thursday, April 18, 2013

APPLSYSPUB security

Recently I was asked to post the output from running "Generate concurrent processing environment information" to an Oracle SR, but before I did I scrolled through it before posting just to make sure there wasn't anything sensitive that was being transmitted.  I was quite shocked at what I found!  The password to the APPLSYSPUB account was right there in plain text for the whole world to see!

Listing of all Environment Variables:
.
.
.
.
GWYUID=APPLSYSPUB/<plain text password>
.
.
.
.

No comments:

Post a Comment