Restricting login to conect Informix thru ICONNECT
Posted in 2008
Topics: Connectivity: ESQL/C, 4GL & Embedded SQL, Security, Permissions & Auditing, Platform-Specific Issues, Versions, Editions & End-of-Life
We have IDS 10.0 UC4 and SUSE Linux 9 Let me clear my problem by example : Say loggin "X" Loggin "X" with password is available to user having the permission OF UPDATE/DELETE at Informix Login "X" can log on to Linux server and perform there menu based work that is controlled by the I4GL program. ICONNECT is available at PC with MS-Windows O/S. Now some smart user can go to the MS-EXCEL etc. and connect to the INFORMIX with Loggin "X" using ICONNECT and can give the query for UPDATE/DELETE. Now we want to control loggin 'X' to execute any query from MS-EXCEL etc. using ICONNECT. Is there any way to control Loggin 'X'.
Create Login "Y" with "select" permission on IDS, and "nologin" shell on Linux and set up your ODBC with Login "Y". HTH 2008/8/9 LOKESH GUPTA <lokeshgupta2@gmail.com> > We have IDS 10.0 UC4 and SUSE Linux 9 > > Let me clear my problem by example : > > Say loggin "X" > > Loggin "X" with password is available to user having the permission OF > UPDATE/DELETE at Informix > > Login "X" can log on to Linux server and perform there menu based work that > is > controlled by the I4GL program. > > ICONNECT is available at PC with MS-Windows O/S. > > Now some smart user can go to the MS-EXCEL etc. and connect to the INFORMIX > with Loggin "X" using ICONNECT and can give the query for UPDATE/DELETE. > > Now we want to control loggin 'X' to execute any query from MS-EXCEL etc. > using ICONNECT. > > Is there any way to control Loggin 'X'. > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Skip +264-81-124-2345
One way is to NOT give update/insert/delete permissions to login "X" for update/delete, but to a different login, call it "updater", whose password is not generally known. Then within the 4GL application login to the database as user "updater" being careful when coding that the password cannot be discovered by extracting plaintext strings from the executable file (one method is to build the password in pieces over mulitple concatenate or append statements). Then destroy the copy of the password in memory so that a power user cannot peek into memory to find it either. Art On Fri, Aug 8, 2008 at 10:51 PM, LOKESH GUPTA <lokeshgupta2@gmail.com>wrote: > We have IDS 10.0 UC4 and SUSE Linux 9 > > Let me clear my problem by example : > > Say loggin "X" > > Loggin "X" with password is available to user having the permission OF > UPDATE/DELETE at Informix > > Login "X" can log on to Linux server and perform there menu based work that > is > controlled by the I4GL program. > > ICONNECT is available at PC with MS-Windows O/S. > > Now some smart user can go to the MS-EXCEL etc. and connect to the INFORMIX > with Loggin "X" using ICONNECT and can give the query for UPDATE/DELETE. > > Now we want to control loggin 'X' to execute any query from MS-EXCEL etc. > using ICONNECT. > > Is there any way to control Loggin 'X'. > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Art S. Kagel Oninit (www.oninit.com) IIUG Board of Directors (art@iiug.org) Disclaimer: Please keep in mind that my own opinions are my own opinions and do not reflect on my employer, Oninit, the IIUG, nor any other organization with which I am associated either explicitly or implicitly. Neither do those opinions reflect those of other individuals affiliated with any entity with which I am affiliated nor those of the entities themselves.
The easiest way to handle this it to put some kind of firewall in the database server or in the network between it and the rest of the network. Then, allow only connection to the INFORMIXSERVER port from the server where the 4GL is running. In version 11, you can use sysdbopen procedure and check the hostname of the user session. Assuming it's not the application (4GL) server, then raise and error and/or disconnect. You could also use roles, but since they cannot (yet at least) be password protected, a power and smart user could discover it and set it while using ODBC. I think other RDBMS can limit the connections to a known application name, but I think this is a bit risky... Maybe I'm wrong... Regards. On Sat, Aug 9, 2008 at 3:51 AM, LOKESH GUPTA <lokeshgupta2@gmail.com> wrote: > We have IDS 10.0 UC4 and SUSE Linux 9 > > Let me clear my problem by example : > > Say loggin "X" > > Loggin "X" with password is available to user having the permission OF > UPDATE/DELETE at Informix > > Login "X" can log on to Linux server and perform there menu based work that > is > controlled by the I4GL program. > > ICONNECT is available at PC with MS-Windows O/S. > > Now some smart user can go to the MS-EXCEL etc. and connect to the INFORMIX > with Loggin "X" using ICONNECT and can give the query for UPDATE/DELETE. > > Now we want to control loggin 'X' to execute any query from MS-EXCEL etc. > using ICONNECT. > > Is there any way to control Loggin 'X'. > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...