public execute permissions
Posted in 2016
Topics: Security, Permissions & Auditing
Informix 11.7FC8W2 Our auditors just ran the NCCSquirel tool on our database. The tool identified that public can execute a number of functions in the sysmaster database and suggest that execute permissions should be revoked from public on these functions. Is this the correct thing to do ? I am very very hesitend to make any changes in sysmaster. Any advice would be very much appreciated. I wonder wat IBM's response would be on doing something like this. Where can I find more info on Informix vulnerabilities ?
Id give that a miss, thanks. But I will defer to Jonathan Leffler, if he has any thoughts. > On 20 Jun 2016, at 13:27, FLIP VAN WYNGAARDT <flipv@raf.co.za> wrote: > > Informix 11.7FC8W2 > > Our auditors just ran the NCCSquirel tool on our database. > The tool identified that public can execute a number of functions in the > sysmaster database and suggest that execute permissions should be revoked from > public on these functions. > > Is this the correct thing to do ? I am very very hesitend to make any changes > in sysmaster. Any advice would be very much appreciated. > I wonder wat IBM's response would be on doing something like this. > Where can I find more info on Informix vulnerabilities ? > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. >
Hi, I would certainly avoid messing with sysmaster, certainly on a production system. I am not familiar with the tool but are they just running it blindly against sysmaster without an understanding of the special nature of this database and that it is not fully under your control. To connect as public you first have to authenticate to the database. Could you put in controls there? Some suggestions: - raise a PMR with IBM support. - try the suggested on a throw-away test system; it would be best if this system was as production-like as possible. IBM releases vulnerability information via a mailing list called "Informix Servers: Security bulletin" you can subscribe to at: https://www.ibm.com/support/mynotifications Ben.