Re: network security
Posted in 1993
> > We have a system set up with two RS/6000s, one as our database > server and one as a "software server". Our users rexec a command from > their PCs to run our application on the latter machine. We run I-Net > and I-Star for the communications between the machines. The users > have to have IDs on both machines to allow them to perform transactions > in the INFORMIX database, and the "software server" has an entry in the > database server's hosts.equiv file for the same reason. This > setup currently allows the users, if they know the correct commands, > to log directly into the software server and then rlogin into the > database server without a password. Does anyone have any suggestions on > how to tighten up security within AIX to prevent the users from doing > this kind of thing, but still allow the INFORMIX functions to work? We have exactly the same issues here. We solve these by using a front end menuing system written in shell. This system generates a menu based on the contents of an authorisation file. There is however a much easier method based on the difference between Informix's access method and those of rlogin remsh/rsh/ rcp etc. All of the rexec utilities open the password file on the remote machine and read the shell entry to determine the command interpreter to use to exec the command. Informix however open a socket to the remote machine. If you create a shell script called logout (or similar) with just 1 line containing exit and you make that the shell for all the users you wish to block then you have effectively prevented then from using rlogin, rsh etc. (At least you have on my 5.4 system) The other approach is to place the command exit at the top of each users .profile. If you adopt this approach then you also have to make a decison with ftp. You can either lock out the users password entry preventing them from using FTP at all. or you have to tighten up the users home directory so they cannot remove / modify their .profile/.cshrc. > > Ideally we would like them to only be able to run the applications > we give them access to and to not be able to get to the database server > at all (except with the database queries in the applications). > > Thanks. > > Cathy J. Senft Internet: cjsenft@lexmark.com > Lexmark International, Inc. Phone: (606) 232-7194 > 740 New Circle Rd. NW Fax: (606) 232-2177 > Lexington, KY 40511-1876 > Regards Steve ----------------------------------------------------------------------------- Steve Weet - European Mis - Motorola Cellular Subscriber Group Beechgreen Court, Chineham, Basingstoke, HANTS England. Phone : +44 (0)256 790154 E-Mail stevew@chineham.euro.csg.mot.com Fax : +44 (0)256 817481 Mobile : +44 (0)850 335105 Post : w10075