fosterjr
27th October 2004, 18:12
Does you install still have the default Baan passwords?

robertvg
7th November 2006, 12:31
and if not, please post your new password ?

patvdv
8th November 2006, 19:12
Somewhat of a weird poll I would agree. Fosterjr, what are your intentions with this poll? Care to elaborate?

bamnsour
24th November 2006, 14:21
The results of this poll show it all.

Until now, some 33% of Baan installations still use the same user/password that everybody in the Baan business would know. This is a big hole in the security of the company - where people with accesses to the network can easily go into the Baan system and....delete the Baan database, or take sensetive information they are not authorized to take. The amazing thing is that this security threat is not addressed by a lot of companies, according to this poll.

Companies that are required to comply with SOX regulations - must change the system passwords once in a while, so the system will not be compromised.

Maybe fosterjr had other reasons for doing this poll, but this is my "take home" from it. A great poll by the way.

Arthas
9th January 2007, 10:41
Please Don't forget!

The installation manual says (or at least it used to say) that there were five compulsory users to set up:
bsp
tools
applic
tbase
admin

These were religiously created at the o/s and baan/triton level, but the last four were often never used again. They were typically set up with the pw the same as the uid. A huge flaw in security.

Also, review the inf_users or ora_users or whateverdb_users file - a lot of them are set up to connect to the database as user "Baan" for all users, this is also a potential weakness.