Re: Auditor fun
Posted in 2007
On Sep 18, 3:24 pm, mal...@btinternet.com wrote:
> We had the Auditors round today, usual stuff, how do we control
> database access, password expiry policy etc etc (set bullshit
> generator to 'Stun'), but he also showed me this article by some bloke
> called David Litchfiled from a chapter in the "Database Hackers
> Handbook" called "Informix - discovery, attack and defense".
> Anyway, apart from the obvious bits about stack overflow exploits and
> how easy it is to breach a windows box (old news is no news....) and
> some stuff about parsing shmem dumps to get user passwords out (I
> don't think so), it has the following gem
> <quote>
> If you can connect to the server then you can issue the
> CREATE DATABASE command - regardless of your privileges; what's more,> the database is created and you are given DBA privileges on it. Once
> you're
> DBA on a database you own the whole server. Whilst this doesn't seem
> to be public knowledge yet, IBM have known about it for a while and
> there is an undocumented
> workaround available to prevent this. See the section on securing
> Informix for more details. At this stage it seems like "game over" but
> on the off
> chance that someone has protected their server using the workaround,
> let's examine
> other ways to gain control of the server.
> </quote>
> What utter crap - create a database and suddenly you're God on the
> server - errmm hello, error 388 "No Resource Permission" on any other
> db on the server (unless you have resource permission granted by the
> DBA!). Where did he get this rubbish? And who is David Litchfield?
> Reads like disinformation to me........
Can be interesting what happens when you start playing with synonyms
for the database you are administrator for onto databases you have no
connect permission on, particularly on very old products such as
72.3 / 7.24