Priviliged access through ODBC
Posted in 2000
Topics: Connectivity: ODBC / JDBC / .NET, Connectivity: ESQL/C, 4GL & Embedded SQL
Hi, We are deploying an information system where we use 4GL application programs that access an Informix database. What we have done so far is that we defined all table priviliges for all users. As far as a user accesses the database through the application program there is no risk of having unwanted manipulation of the data. But when it comes to usage of ODBC, eg through use of MS-Access, then things change. Now the same user can do anything with the data that he/she wants. So this is a big risk. This situation gives a lot of tension. We can't define more table priviliges, because then the application programs don't work anymore. So what we are looking for is a possibility to define the required table priviliges for the case that a person access the database through ODBC. Does anybody know of the possibilities that are available. Any advice/help/tip will be appreciated. regards, Henk
Hi henk, Lets say I told the user his password is "smart" To all users U give an extantion they do not know, Like the user abowe, his real password is "smart123" Now add "123" to all the other users' password, and plant this extantion in your login script. If any will try to login with any odbc enabled s/w, typing "smart" as password will cause login error.....
>Subject: Priviliged access through ODBC >From: Henk van der Geld henk.van.der.geld@centric.nl >Date: 08.06.00 17:22 W. Europe Daylight Time >Message-id: <393FBA3A.E09CD42F@centric.nl> > >Hi, > >We are deploying an information system where we use 4GL application >programs that access an Informix database. What we have done so far is >that we defined all table priviliges for all users. As far as a user >accesses the database through the application program there is no risk >of having unwanted manipulation of the data. But when it comes to usage >of ODBC, eg through use of MS-Access, then things change. Now the same >user can do anything with the data that he/she wants. So this is a big >risk. This situation gives a lot of tension. We can't define more table >priviliges, because then the application programs don't work anymore. So >what we are looking for is a possibility to define the required table >priviliges for the case that a person access the database through ODBC. >Does anybody know of the possibilities that are available. Any >advice/help/tip will be appreciated. > >regards, >Henk > > > > ensure that your table owners are lower case and match a real account unix account. Require your pc users to use an account on the back end with the appropriate privileges. That way your table privileges will be honored. Don't get fooled by snapshots - require your pc users to link and not snap. Nona