Re: Please correct me: Informix security sucks
Posted in 2000
Topics: Performance & Tuning, Platform-Specific Issues
On Fri, 28 Apr 2000, Daniel Wood wrote: > So exactly how does database permissions prevent a user with root access > from directly reading the catalog information from the disk bypassing the > database engine. Unless encrypted this would be trivial. I believe Oracle > does document the layout of their disk structures. All database information is stored in binary format and isn't easily (or feasibly) readable. Also, root doesn't have any special privileges; he/she is just like any user and needs to be granted access. But, as with Oracle, root can *become* any user - there's no database that can get around that. > > It would be easy to write a utility to dump the system catalog information. Nope. See above. > > I don't want to argue which product is superior but I will say that having > a feature that provides a false sense of security does not make any product > superior. Any user that can access the data needs a valid login ID. If the database administrator takes proper care, you should be safe. - Ron F. ________________________________________________________________________ Ron Flannery <mailto:rflanner@informixhandbook.com>, 248-887-8470x40 Lead author, Informix Handbook President, One Point Solutions "Your Complete Reference" "Informix & Web/Database solutions" http://www.informixhandbook.com http://www.one-point.com ________________________________________________________________________ > > Greg Starnes wrote: > > > My problem is that were using Informix for the back-end of a software > > package we are selling. Most of the value of this product is in the schema > > of the tables. If we set up this package on our clients computer (who will > > have root privelidges on the OS), they can go in and steal the layout of the > > tables. > > > > With Oracle, there is security at the DB level, so we can preset the > > privelidges on the tables, so that they cant get into them and rip them off > > (ie. take the schema and use it to set up thier own accounting dept (we are > > building an accounting package)). > > > > Am I going to have to tell my boss that Oracle is in fact superior... This > > could be a deal breaker for Informix, and I'd love to NOT see that happen. > > > > Thanks for your comments, it raises some interesting questions for our web > > server. > > > > "David Stes" <stes@pandora.be> wrote in message > > news:3908A205.93B8D4D7@pandora.be... > > > Greg Starnes wrote: > > > > > > > > Oracle has security at the OS and Database level. All I can find from > > > > Informix is that they only have security at the OS level. SO, if you > > have > > > > root privileges for the OS, you can get into the tables of our product > > > > (which, obviously we dont want to happen). > > > > > > Having security at both os and database level seems complex. > > > > > > I like the Informix simplicity of having only OS level security. > > > > > > There's also a risk of duplication, where the database would implement > > > services that can/are better provided by the OS. > > > > > > Maybe there exists for example a "crypto-filesystem" where the > > > read/write's to files would be encrypted so you could have a layer of > > > security (provided by the OS) like that. > > > > > > But I also sometimes worry about Informix security. > > > > > > Wouldn't informix SE security for Linux (I use SE, I don't know about > > > Dynamic) be improved, by implementing communication IPC through simple > > > pipes ? > > > > > > I don't need the remote capabilities of "sesoctcp" and I think both > > > security and performance could be better if communication through pipes > > > (seipcpip?) were supported. > > > > > > This is something that I worry about, that the informix daemon is > > > listening on a socket and would accept connections; I'd rather have it > > > listen only on a domain socket or pipe, but I don't think there's a way > > > to do it right now. >
"Ron M. Flannery" wrote: > All database information is stored in binary format and isn't easily (or > feasibly) readable. Also, root doesn't have any special > privileges; he/she is just like any user and needs to be granted access. > But, as with Oracle, root can *become* any user - there's no database > that can get around that. I believe Oracle has "database users" which are NOT system users. These db users connect with a user name and password which are not in /etc/passwd hence you can NOT su to them. The database maintains the list of valid db users and passwd's who can connect. If they used canned applications which connected to the database you wouldn't see the passwd they used. This was the point being made. However, hard coded passwords in executables are easy to find even if scrambled. > > It would be easy to write a utility to dump the system catalog information. > > Nope. See above. Once I was at a company where the Altos Unix OS panicked whenever an Informix archive was done. I had no access to and had never seen Unix source code but I hand patched in a stack backtrace routine, in machine code, into the routine which prints kernal messages. From this I disassembled the routine which invoked the panic and reverse engineered it into pseudo C code. I studied the function and discovered the bug which I was then able to convince Altos that they had in their kernal. Previous attempts at dealing with Altos tech. support were useless. If this is a 10 then figuring out the structure of rows which hold the column names, types, etc. is about a 2. I assume Oracle's documenation is decent. Long before I came to Informix the information in the 5X Informix DBA manual gave me enough info. to write code to read and interpret the raw database instance. If Oracle's documentation is poor then maybe it's a 3 on the scale of 1 to 10 in difficultly. and, Heck!, I just work in tech. support.
See below.... "Ron M. Flannery" wrote: > On Fri, 28 Apr 2000, Daniel Wood wrote: > > > So exactly how does database permissions prevent a user with root access > > from directly reading the catalog information from the disk bypassing the > > database engine. Unless encrypted this would be trivial. I believe Oracle > > does document the layout of their disk structures. > > All database information is stored in binary format and isn't easily (or > feasibly) readable. Also, root doesn't have any special > privileges; he/she is just like any user and needs to be granted access. > But, as with Oracle, root can *become* any user - there's no database > that can get around that. > > > > > It would be easy to write a utility to dump the system catalog information. > > Nope. See above. Wanna bet?.... ;-) I've debugged stuff without source code before. I've found bugs in other vendor's compilers based on the generated binary. Also, I've written utilities to format and intreprete stuff in binary format without any documentation. I'm not all that smart either - just stubborn. Also don't forget how Compact Computer got started. They reverse engineered the IBM PC and in order to legally do that, they had to use engineers that knew absolutly nothing about the IBM PC. Now just imagine how few really good engineers there were at the time that had absolutly no knowledge about the IBM PC, including having never even seen one. Remember at the time it was the neatest 'hot stuff'. > > > > > I don't want to argue which product is superior but I will say that having > > a feature that provides a false sense of security does not make any product > > superior. > > Any user that can access the data needs a valid login ID. If the database > administrator takes proper care, you should be safe. > > - Ron F. > > ________________________________________________________________________ > Ron Flannery <mailto:rflanner@informixhandbook.com>, 248-887-8470x40 > > Lead author, Informix Handbook President, One Point Solutions > "Your Complete Reference" "Informix & Web/Database solutions" > http://www.informixhandbook.com http://www.one-point.com > ________________________________________________________________________ > > > > Greg Starnes wrote: > > > > > My problem is that were using Informix for the back-end of a software > > > package we are selling. Most of the value of this product is in the schema > > > of the tables. If we set up this package on our clients computer (who will > > > have root privelidges on the OS), they can go in and steal the layout of the > > > tables. > > > > > > With Oracle, there is security at the DB level, so we can preset the > > > privelidges on the tables, so that they cant get into them and rip them off > > > (ie. take the schema and use it to set up thier own accounting dept (we are > > > building an accounting package)). > > > > > > Am I going to have to tell my boss that Oracle is in fact superior... This > > > could be a deal breaker for Informix, and I'd love to NOT see that happen. > > > > > > Thanks for your comments, it raises some interesting questions for our web > > > server. > > > > > > "David Stes" <stes@pandora.be> wrote in message > > > news:3908A205.93B8D4D7@pandora.be... > > > > Greg Starnes wrote: > > > > > > > > > > Oracle has security at the OS and Database level. All I can find from > > > > > Informix is that they only have security at the OS level. SO, if you > > > have > > > > > root privileges for the OS, you can get into the tables of our product > > > > > (which, obviously we dont want to happen). > > > > > > > > Having security at both os and database level seems complex. > > > > > > > > I like the Informix simplicity of having only OS level security. > > > > > > > > There's also a risk of duplication, where the database would implement > > > > services that can/are better provided by the OS. > > > > > > > > Maybe there exists for example a "crypto-filesystem" where the > > > > read/write's to files would be encrypted so you could have a layer of > > > > security (provided by the OS) like that. > > > > > > > > But I also sometimes worry about Informix security. > > > > > > > > Wouldn't informix SE security for Linux (I use SE, I don't know about > > > > Dynamic) be improved, by implementing communication IPC through simple > > > > pipes ? > > > > > > > > I don't need the remote capabilities of "sesoctcp" and I think both > > > > security and performance could be better if communication through pipes > > > > (seipcpip?) were supported. > > > > > > > > This is something that I worry about, that the informix daemon is > > > > listening on a socket and would accept connections; I'd rather have it > > > > listen only on a domain socket or pipe, but I don't think there's a way > > > > to do it right now. > > -- Madison Pruet =========================================== Enterprise Replication Product Developement Dallas, Texas Informix Software ===========================================
Madison Pruet wrote: > See below.... > > "Ron M. Flannery" wrote: > > > On Fri, 28 Apr 2000, Daniel Wood wrote: > > > It would be easy to write a utility to dump the system catalog information. > > > > Nope. See above. > > Wanna bet?.... ;-) > > I've debugged stuff without source code before. I've found bugs in other vendor's > compilers based on the generated binary. Also, I've written utilities to format and > intreprete stuff in binary format without any documentation. I'm not all that smart > either - just stubborn. Arrrrr! You guys are pussies! I once debugged a database by hooking wires up between the memory bus and my nipples with alligator clips! Then the "patch" required that I pee on the mother board to burn a new shunt. (Had to drink a whole case of Mountain Dew to get the acidity right!)
In article <390B1A7D.2ED67D54@informix.com>, Paul Brown <paul.No.brown@informix.com> writes > > > Arrrrr! You guys are pussies! > > I once debugged a database by hooking wires up between the > memory bus and my nipples with alligator clips! Then the "patch" required > that I pee on the mother board to burn a new shunt. (Had to drink a whole > case of Mountain Dew to get the acidity right!) > Don't worry, help is on the way...I'll just need to mount the extra large dart gun on top of the truck first... -- David Williams