1. 检查使用默认用户密码的账号
--11g 通过数据字典SYS.DEFAULT_PWD$或视图DBA_USERS_WITH_DEFPWD select u.username, u.account_status, u.created, u.lock_date, u.expiry_date from dba_users u, (select username from DBA_USERS_WITH_DEFPWD) tt where u.username = tt.username ; -- 11g以前版本 @pwcheck.sql
附:
-- pwcheck.sql -- Minimal password security check, see note 160861.1 on WebIV, -- Since collisions are virtually impossible, only check passwords. -- (C) 2003 Oracle Corporation, written by Harm ten Napel select username "User(s) with Default Password!", account_status "Status" from dba_users where password in (\'E066D214D5421CCC\', -- dbsnmp \'24ABAB8B06281B4C\', -- ctxsys \'72979A94BAD2AF80\', -- mdsys \'9AAEB2214DCC9A31\', -- mdsys \'C252E8FA117AF049\', -- odm \'A7A32CD03D3CE8D5\', -- odm_mtr \'88A2B2C183431F00\', -- ordplugins \'7EFA02EC7EA6B86F\', -- ordsys \'9B616F5489F90AD7\', -- ordcommon \'4A3BA55E08595C81\', -- outln \'F894844C34402B67\', -- scott \'3F9FBD883D787341\', -- wk_proxy \'79DF7A1BD138CF11\', -- wk_sys \'7C9BA362F8314299\', -- wmsys \'88D8364765FCE6AF\', -- xdb \'F9DA8977092B7B81\', -- tracesvr \'9300C0977D7DC75E\', -- oas_public \'A97282CE3D94E29E\', -- websys \'AC9700FD3F1410EB\', -- lbacsys \'E7B5D92911C831E1\', -- rman \'AC98877DE1297365\', -- perfstat \'66F4EF5650C20355\', -- exfsys \'84B8CBCA4D477FA3\', -- si_informtn_schema \'D4C5016086B2DC6A\', -- sys \'5638228DAF52805F\', -- sys \'D4DF7931AB130E37\') -- system /