Re: Auditor fun
Posted in 2007
On Sep 18, 3:51 pm, Superboer <superbo...@t-online.de> wrote:
> Do not underestimate that....!!!!!!!
> one could create tables consuming all the space is the easiest thing
> which comes
> to mind....
>
> that is why V93 and higher if i recall correctly have a onconfig
> param:
>
> DBCREATE_PERMISSION informix
> this will give
> 330: Cannot create or rename database.
> 388: No resource permission.> when you try to create a database as other user then informix.
>
> Superboer.
>
> On 18 sep, 16:24, mal...@btinternet.com wrote:
>
>
>
> > We had the Auditors round today, usual stuff, how do we control
> > database access, password expiry policy etc etc (set bullshit
> > generator to 'Stun'), but he also showed me this article by some bloke
> > called David Litchfiled from a chapter in the "Database Hackers
> > Handbook" called "Informix - discovery, attack and defense".
> > Anyway, apart from the obvious bits about stack overflow exploits and
> > how easy it is to breach a windows box (old news is no news....) and
> > some stuff about parsing shmem dumps to get user passwords out (I
> > don't think so), it has the following gem
> > <quote>
> > If you can connect to the server then you can issue the
> > CREATE DATABASE command - regardless of your privileges; what's more,> > the database is created and you are given DBA privileges on it. Once
> > you're
> > DBA on a database you own the whole server. Whilst this doesn't seem
> > to be public knowledge yet, IBM have known about it for a while and
> > there is an undocumented
> > workaround available to prevent this. See the section on securing
> > Informix for more details. At this stage it seems like "game over" but
> > on the off
> > chance that someone has protected their server using the workaround,
> > let's examine
> > other ways to gain control of the server.
> > </quote>
> > What utter crap - create a database and suddenly you're God on the
> > server - errmm hello, error 388 "No Resource Permission" on any other
> > db on the server (unless you have resource permission granted by the
> > DBA!). Where did he get this rubbish? And who is David Litchfield?
> > Reads like disinformation to me........- Hide quoted text -
>
> - Show quoted text -
Its also in later versions of DS 7.31