Re: Onstat -g ses only for DBSA?
Posted in 2005
Murray Wood (IList) wrote:
> In 9.40 IBM added more information about the session and decided to
> hide it from all users other than DBSA. IDS 10 also has it hidden.
>
>>From: Paul Watson
>>
>>Raise a support call and get it a feature request sent to IBM
>>
>>Lucho wrote:
>>>There are two servers.
>>>
>>>One of them with an informix server version: IBM Informix Dynamic
>>>Server Version 9.30.UC6W4
>>>
>>>and the other
>>>IBM Informix Dynamic Server Version 9.40.FC5
>>>
>>> When I execute the command Onstat -g ses on the first one
>>> (version 9.30), it's all good but when I execute the command on
>>> the second one (version 9.40), I've got the following error:
>>> Must be a DBSA to run this program.
>>>
>>>I am not DBSA in any of these servers.
>>>
>>>What's the problem? THANKS!
The problem is that you can see the SQL, and the SQL can include
confidential information. If anyone can run onstat -g ses, anyone can
see the confidential data in the SQL - and if you're using encryption,
that could include passwords. It is not remotely clear that it is (or
ever was) a good idea for the general public (including intruders logged
in as an unprivileged user) to be able to see the SQL of other users.
That said, it may be necessary to provide a mechanism that the DBSA can
configure to permit 'onstat -g ses' and related queries to be used by
unprivileged users. I don't like it in the slightest, but if you really
don't care who can see what in your database, maybe you should be
allowed to say "Yes - the intruders can see anything in my database".
With this one, unusually, I don't think there is already a get-out
mechanism; for all the other changes in security, I believe there is an
override that can be used if you really insist on running an insecure
system.
There are a number of other places where the server currently defaults
to insecure and modern requirements mean that the default will be
secure. That means there will be vaguely similar changes in the future.
There'll be an override mechanism, but out of the box, the server will
run (more) securely.
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2005.01 -- http://dbi.perl.org/