Re: Onstat -g ses only for DBSA?
Posted in 2005
Jonathan Leffler schrieb:
> Murray Wood (IList) wrote:
>
>> In 9.40 IBM added more information about the session and decided to
>> hide it from all users other than DBSA. IDS 10 also has it hidden.
>>
>>> From: Paul Watson
>>>
>>> Raise a support call and get it a feature request sent to IBM
>>>
>>> Lucho wrote:
>>>
>>>> There are two servers.
>>>> One of them with an informix server version: IBM Informix Dynamic
>>>> Server Version 9.30.UC6W4
>>>>
>>>> and the other
>>>> IBM Informix Dynamic Server Version 9.40.FC5
>>>>
>>>> When I execute the command Onstat -g ses on the first one
>>>> (version 9.30), it's all good but when I execute the command on
>>>> the second one (version 9.40), I've got the following error:
>>>> Must be a DBSA to run this program.
>>>>
>>>> I am not DBSA in any of these servers.
>>>>
>>>> What's the problem? THANKS!
>
>
> The problem is that you can see the SQL, and the SQL can include
> confidential information. If anyone can run onstat -g ses, anyone can
> see the confidential data in the SQL - and if you're using encryption,
> that could include passwords. It is not remotely clear that it is (or
> ever was) a good idea for the general public (including intruders logged
> in as an unprivileged user) to be able to see the SQL of other users.
>
> That said, it may be necessary to provide a mechanism that the DBSA can
> configure to permit 'onstat -g ses' and related queries to be used by
> unprivileged users. I don't like it in the slightest, but if you really
> don't care who can see what in your database, maybe you should be
> allowed to say "Yes - the intruders can see anything in my database".
> With this one, unusually, I don't think there is already a get-out
> mechanism; for all the other changes in security, I believe there is an
> override that can be used if you really insist on running an insecure
> system.
>
> There are a number of other places where the server currently defaults
> to insecure and modern requirements mean that the default will be
> secure. That means there will be vaguely similar changes in the future.
> There'll be an override mechanism, but out of the box, the server will
> run (more) securely.
>
we use sudo on several sites to overcome the new feature, although
I personally like them. Several customers wanted to keep everything
'as it always was' , though.
dic_k
--
Richard Kofler
SOLID STATE EDV
Dienstleistungen GmbH
Vienna/Austria/Europe