chunk access
Posted in 2005
Topics: Storage & Space Management
Hi,
The chunks are created with user and group informix. Theoritically only users
in this this group should be able to access the chunks. But i have created a
user "dummy" which is not in informix group. THis user is still able to access
the data in the database. How is this possible.
I will list the steps here.
All the chunks in the instance have the following permissions.
crw-rw---- 1 informix informix 64 0x040004 Mar 1 16:29 /dev/vg04/rcalms2_dbs1
And they are linked through links as
lrwxrwxrwx 1 root sys 22 Mar 1 16:48 /dev/calms2/calms2_dbs1 ->
/dev/vg04/rcalms2_dbs1
created user dummy.
created a database caldw and gave connect permission to dummy user on this data
base.
And i tried to access the data in the database by giving
select * from exp_cost.I was able to retrieve the data.
My doubt is the "dummy" users does not have rw permision on this character
devices but still it is able to access. How is this?
Bye.
Hi,
this is one of the reasons you are using a database
and not accessing the data directly in files. Afterall
you have to get some kind of "service" from an expensive
database product - and this is one of them.
The database server processes are running as user informx,
therefore they have access to all the data, and that is correct,
because otherwise the whole thing would not work. And that's
why the chunks need to have "*rw-rw---- informix informix"
access rights and owner/group.
Which users can access the data via SQL is controlled by the
database server. There are SQL statements like GRANT, REVOKE
and even role-based privileges for all kinds of access levels (connect,
read, write, ...). And this is how you allow or restrict data access
when using a database server product.
The UNIX file "access rights - owner/group" concept with access
only for "informix" is to ensure that nobody else can access
the data by by-passing the database server, e.g. steal the data without
having data access permissions in/from the database server.
Hmm. If this explanation doesn't lift the fog, then I recommend one
of the more basic training classes for relational databases (preferrably
for IBM Informix Dynamic Server, e.g. "Database Administration", but
something more general might do just as well), or get yourself a text
book explaining the concepts of relational databases and SQL.
After that I guess you should then be fine with IBM Informix manuals
like "Guide to SQL: Tutorial", "Database Design and Implementation
Guide" and "Administrator's Guide". You can of course start with these
manuals right away (they are available for free download), but it may
not give you a structured approach to the fundamentals and hence not
necessarily a steep learning curve.
Regards,
Martin
--
Martin Fuerderer
IBM Informix Development Munich, Germany
Information Management
forum.subscriber@iiug.org wrote on 24.03.2005 06:05:50:
> Hi,
> The chunks are created with user and group informix. Theoritically only
users
> in this this group should be able to access the chunks. But i have
created a
> user "dummy" which is not in informix group. THis user is still able to
access the data in the database. How is this possible.
>
> I will list the steps here.
>
> All the chunks in the instance have the following permissions.
>
> crw-rw---- 1 informix informix 64 0x040004 Mar 1 16:29
/dev/vg04/rcalms2_dbs1
>
> And they are linked through links as
>
> lrwxrwxrwx 1 root sys 22 Mar 1 16:48
/dev/calms2/calms2_dbs1 -> /dev/vg04/rcalms2_dbs1
>
> created user dummy.
> created a database caldw and gave connect permission to dummy user on
this data
> base.
>
> And i tried to access the data in the database by giving
> select * from exp_cost.> I was able to retrieve the data.
>
>
>
> My doubt is the "dummy" users does not have rw permision on this
character devices but still it is able to access. How is this?
>
>
>
> Bye.
>
>
>
>
>
PARAMESHWAR.... said:
> Hi,
> The chunks are created with user and group informix. Theoritically only
> users
> in this this group should be able to access the chunks. But i have created
> a
> user "dummy" which is not in informix group. THis user is still able to
> access the data in the database. How is this possible.
Errr... oninit process has setuid and ssetgid permissions.
> I will list the steps here.
>
> All the chunks in the instance have the following permissions.
>
> crw-rw---- 1 informix informix 64 0x040004 Mar 1 16:29
> /dev/vg04/rcalms2_dbs1
>
> And they are linked through links as
>
> lrwxrwxrwx 1 root sys 22 Mar 1 16:48
> /dev/calms2/calms2_dbs1 -> /dev/vg04/rcalms2_dbs1
>
> created user dummy.
> created a database caldw and gave connect permission to dummy user on this
> data
> base.
>
> And i tried to access the data in the database by giving
> select * from exp_cost.> I was able to retrieve the data.
>
>
>
> My doubt is the "dummy" users does not have rw permision on this character
> devices but still it is able to access. How is this?
>
>
>
> Bye.
>
>
>
>
>
--
Bye now,
Obnoxio
"C'est pas parce qu'on n'a rien à dire qu'il faut fermer sa gueule"
- Coluche
"I'm trying to see things your way, but I can't get my head up my ass"
- JCH
"Ogni uomo mi guarda come se fossi una testa di cazzo"
- Marco
Travel broadens a person. You look as if you have been all over the world.
I went to the airport to check in and they asked what I did because I
looked like a terrorist. I said I was a comedian. They said, "Say
something funny then." I told them I had just graduated from flying
school.
-- Ahmed Ahmed
http://i2.photobucket.com/albums/y41/Obnoxio/thinkIfoundtheproblem.jpg
Informix by default grants select, insert, update, and delete
privileges to a table once its created originally, at least with the versions
I have worked with so far. I don't know if 10g has changed that.
So, keep in mind that unless you revoke all from the <table name> just any
body can access that table.
Hope this helps.
Ravi.
"Martin Fuer...." <MARTINFU@de.ibm.com> wrote:
Hi,
this is one of the reasons you are using a database
and not accessing the data directly in files. Afterall
you have to get some kind of "service" from an expensive
database product - and this is one of them.
The database server processes are running as user informx,
therefore they have access to all the data, and that is correct,
because otherwise the whole thing would not work. And that's
why the chunks need to have "*rw-rw---- informix informix"
access rights and owner/group.
Which users can access the data via SQL is controlled by the
database server. There are SQL statements like GRANT, REVOKE
and even role-based privileges for all kinds of access levels (connect,
read, write, ...). And this is how you allow or restrict data access
when using a database server product.
The UNIX file "access rights - owner/group" concept with access
only for "informix" is to ensure that nobody else can access
the data by by-passing the database server, e.g. steal the data without
having data access permissions in/from the database server.
Hmm. If this explanation doesn't lift the fog, then I recommend one
of the more basic training classes for relational databases (preferrably
for IBM Informix Dynamic Server, e.g. "Database Administration", but
something more general might do just as well), or get yourself a text
book explaining the concepts of relational databases and SQL.
After that I guess you should then be fine with IBM Informix manuals
like "Guide to SQL: Tutorial", "Database Design and Implementation
Guide" and "Administrator's Guide". You can of course start with these
manuals right away (they are available for free download), but it may
not give you a structured approach to the fundamentals and hence not
necessarily a steep learning curve.
Regards,
Martin
--
Martin Fuerderer
IBM Informix Development Munich, Germany
Information Management
forum.subscriber@iiug.org wrote on 24.03.2005 06:05:50:
> Hi,
> The chunks are created with user and group informix. Theoritically only
users
> in this this group should be able to access the chunks. But i have
created a
> user "dummy" which is not in informix group. THis user is still able to
access the data in the database. How is this possible.
>
> I will list the steps here.
>
> All the chunks in the instance have the following permissions.
>
> crw-rw---- 1 informix informix 64 0x040004 Mar 1 16:29
/dev/vg04/rcalms2_dbs1
>
> And they are linked through links as
>
> lrwxrwxrwx 1 root sys 22 Mar 1 16:48
/dev/calms2/calms2_dbs1 -> /dev/vg04/rcalms2_dbs1
>
> created user dummy.
> created a database caldw and gave connect permission to dummy user on
this data
> base.
>
> And i tried to access the data in the database by giving
> select * from exp_cost.> I was able to retrieve the data.
>
>
>
> My doubt is the "dummy" users does not have rw permision on this
character devices but still it is able to access. How is this?
>
>
>
> Bye.
>
>
>
>
>
__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com