Re: ODBC and Security
Posted in 1996
Alex Fiore wrote:
>
> Billy Wheeler wrote:
> >
> > My understanding is that client/server architecture is *extremely*
> > vulnerable to basically any app (Lotus/Access/MS-Word :) with an ODBC driver
> > coming in and either acquiring or altering your data. I'd be very interested
> > to hear what experienced C/S developers do to minimise this risk.
> > --
>
> Using an ODBC driver to an Informix database does not give
> you any greater access than with ESQL/C. The same user-level security
> is in place. The ODBC driver will still have to go through the
> connectivity software (ESQL/C and INET). They will still have to
> provide a username and password to login to the database. Whatever
> security you have implemented in the design of your database (user
> access to tables, permissions, views, etc.) are still in effect.
>
Yes, but is that security enough? Like the original postings were getting at,
much of security is implemented in a central application, which may even be a
third party application. Although permissions are easy enough to apply for read
or select access to the database, permissions to modify data (update, insert or
delete) can be more difficult. This is because in complex databases, modifying
data has to adhere to certain rules which can be totally impractical to implement
using just SQL with views, constraints, triggers and stored procedures.
A simple enough example, just to demonstrate, would be a bookkeeping system that
requires a debet sum for every kredit sum recorded, and v.s. A central
application would just require the user to make every set of records have a net
sum of zero (debet=kredit). When using an ODBC client, however, like ms-access or
Lotus notes, there are no restrictions if they are not programmed in the SQL
database. Progamming the above example with triggers and stored procedures is not
straightforward even though the concept of the problem is simple.
> If your database is designed with no security precautions (everyone
> logs in with the same user ID, all permissions are available to
> public, etc.) than that is what you get. Anyone accessing the
> database using any tool (whether via ODBC or not) will have
> full access to your tables.
Yes, the problem doesn't really have anything to do with ODBC. The user can of
course make his own program on the server machine and run that. If dbaccess is
open to all users, then that's an easy way for the user to bypass security. But,
it is the ease of use of the PC environment that makes the danger all the more
apparent; not to speak of possibilities like viruses that, instead of erasing
your local hard disk, quietly delete all the database information that the user
had access to delete, or secretly alters the ODBC driver so that all select
statements are changed to delete statements. My destructive imagination is only
warming up. :)
I stand on my opinion that ODBC clients should not have access to alter data,
only read.
----------------------------------------------------------------------
John H. Frantz Power-4gl: Extending Informix-4gl
frantz@centrum.is http://www.strengur.is/~frantz/pow4gl.html