DB security and patch alerts
Posted in 2007
Question: why do Oracle and Microsoft generate constant security alerts/patches while Informix rarely does — is Informix really that secure? Responses: yes, largely; IDS is usually deployed behind a firewall rather than directly exposed to the internet, and SQL Server's tight OS coupling plus Oracle's huge codebase create more vulnerabilities. Jonathan Leffler (IBM) confirmed Informix does have security issues, but they are fixed quickly and publication is deliberately delayed so fixes ship in fix packs/PIDs before disclosure (e.g. the 2006 NGSS reports were already patched), and he invited private reports of security concerns. Discussion, not a bug fix — no patch action required.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: General Discussion
Ladies and Gentlemen: I've got a serious question on security and patch alerts. It seems almost every day I get an Oracle or Microsoft security alert and patch requirement, but almost NEVER see an alert for INFORMIX. Am I missing something here? Is the security that tight in INFORMIX? Rob
Yes. ----- Original Message ----- From: Rob Konikoff <ids@iiug.org> At: 2/20 9:22:09 Ladies and Gentlemen: I've got a serious question on security and patch alerts. It seems almost every day I get an Oracle or Microsoft security alert and patch requirement, but almost NEVER see an alert for INFORMIX. Am I missing something here? Is the security that tight in INFORMIX? Rob ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.
Generally it's that tight Paul Watson Tel: +44 1414161772 Mob: +44 7818003457 Web: www.oninit.com Failure is not as frightening as regret. Attend IDUG 2007 San Jose, North America May 6-10, 2007 Visit http://www.iiug.org/conf for more information. > -----Original Message----- > From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On > Behalf Of Rob Konikoff > Sent: 20 February 2007 08:22 > To: ids@iiug.org > Subject: DB security and patch alerts [8434] > > Ladies and Gentlemen: > > I've got a serious question on security and patch alerts. It > seems almost every day I get an Oracle or Microsoft security > alert and patch requirement, but almost NEVER see an alert > for INFORMIX. > > Am I missing something here? Is the security that tight in INFORMIX? > > Rob > > > ************************************************************** > ***************** > Forum Note: Use "Reply" to post a response in the > discussion forum.
Hi, The point is that IDS is normaly not exposed in the internet, as oracle propagates to do. In this case, when a DB server is safely behind a firewall, not accessible from outside, only via applications, you should not have a real problem. (the problem is more to prevent access on your OS). You should also have no real problem with Oracle or SQL Server in this case. If you set it up with e.g. exposed IP Ports open to the internet, somebody could kill the instance with a DOS attack. I haven't tried that, but IDS is very stable and might be able to stand such an attack. That happens to every application which is exposed to the internet directly. That's what web-servers are build for ... Microsoft and Oracle have applications which are directly connected to the internet, so they are vulnerable and have to take care of such things. There is a way to address Informix directly via http (e.g. from an applet), but I dont know how many people are using this setup. Mostly, the setup would be that the instance is somewhere in your intranet and is addressed via an application server or by an ODBC/ADO/JDBC application. If something is exposed to the internet, it will most likely be via a web-server/application server. There you should bother about vulnerability in the first place. Marcus -----Original Message----- From: Rob Konikoff [mailto:rob.konikoff@us.army.mil] Sent: Tuesday, February 20, 2007 3:22 PM To: ids@iiug.org Subject: DB security and patch alerts [8434] Ladies and Gentlemen: I've got a serious question on security and patch alerts. It seems almost every day I get an Oracle or Microsoft security alert and patch requirement, but almost NEVER see an alert for INFORMIX. Am I missing something here? Is the security that tight in INFORMIX? Rob ************************************************************************ ******* Forum Note: Use "Reply" to post a response in the discussion forum.
Totally different architectures between the three. Since SQL Server is so incestuous with their OS, the security errors in Windoze propagate into their db engine. Oracle probably has a billion lines of code for all the components of their db; plenty of opportunity for everyone's favorite "buffer overflow". Bob Roussey Unix / Informix Administration Spirit Airlines Robert.Roussey@SpiritAir.com -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of ART KAGEL, BLOOMBERG/ 731 LEXIN Sent: Tuesday, February 20, 2007 9:23 AM To: ids@iiug.org Subject: Re: DB security and patch alerts [8435] Yes. ----- Original Message ----- From: Rob Konikoff <ids@iiug.org> At: 2/20 9:22:09 Ladies and Gentlemen: I've got a serious question on security and patch alerts. It seems almost every day I get an Oracle or Microsoft security alert and patch requirement, but almost NEVER see an alert for INFORMIX. Am I missing something here? Is the security that tight in INFORMIX? Rob ************************************************************************ ******* Forum Note: Use "Reply" to post a response in the discussion forum. ************************************************************************ ******* Forum Note: Use "Reply" to post a response in the discussion forum.
On 2/20/07, Rob Konikoff <rob.konikoff@us.army.mil> wrote: > Ladies and Gentlemen: > > I've got a serious question on security and patch alerts. It seems almost > every day I get an Oracle or Microsoft security alert and patch requirement, > but almost NEVER see an alert for INFORMIX. > > Am I missing something here? Is the security that tight in INFORMIX? I'd like to think the security in Informix is better than in the other two, though it would be foolish to make such a claim too emphatically. We certainly do have security issues; we fix those issues as quickly as we can. We try to delay the publication of the issues for as long as possible so that as many people will have automatically upgraded and have the fix in place before the risk is publicized. We work with the people who find the problems whenever they will let us - the majority do. For example, we had a set of security issues reported last August - by David Litchfield at NGSS. However, those bugs had been reported considerably earlier to us, and we had them fixed in all versions, including the 7.31 annual fix pack, so if you had upgraded during the year prior to the announcement, you would already have the fixes in place. I periodically get other reports; I've got two in progress at the moment, one of which doesn't reproduce in the current versions of IDS 10 (but did in an earlier version). The other will be fixed in the next available PID (post-interim drops). If anybody wants to report a security concern, you can report to me at my IBM email address (not this one, please) - see my signature. -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2005.02 -- http://dbi.perl.org/ NB: Please do not use this email for correspondence - I don't read it every week, even.