ALTER USER username IDENTIFIED BY VALUES ‘password_hash’ is an undocumented SQL statement. It is used internally by import utilities to store a password hash, which was previously saved with an export utility, in the data dictionary base table SYS.USER$. In situations where a DBA needs to connect as a certain user, but does not or must not know the password of that user, the capability to restore a saved password hash saves time and spares the DBA from annoyance asking around for passwords.
KeywordsBrute Force Data Dictionary Brute Force Attack Versus ALUE Login Attempt
Unable to display preview. Download preview PDF.