views:

336

answers:

1

I noticed its possible to run SQL scripts with Oracle's SQLPlus by providing only a username and no password. Isn't this like a horrible breach of any form of security for Oracle?

Or am I missing something?

+6  A: 

Most likely, your oracle server has OS Authentication enabled, this basically tells oracle to trust users already logged into the OS.

Matthew Watson
That makes sense, thanks. Hadn't realized that was a feature
Robert Gould