Translating with DrWatson… this can take a few seconds the first time.
This is a genuine, complex translation. DrWatson protects commands, error codes, and log output while naturally translating the surrounding text. It’s translated once and saved.
On IDS 10.00.FC9 (AIX 5.3), a wrong password made dbaccess/CSDK clients report error -951 ("incorrect password or user not known") while the online.log recorded the true error -952 ("password is not correct"). Respondents explained this is intentional: since 10.00.UX7/XC7 (bug132837 in the release notes) the server masks the client-side error so attackers can't distinguish an invalid user from a valid user with a bad password. The poster confirmed older builds (10.00.FC4) still show -952, so no fix is needed — it's expected behaviour.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
LYNKZ MIKE — — source: IIUG Forums & Mailing Lists
Hi everyone, im facing a problem with ids 10.00.FC9 on aix 5.3. When a users
inputs wrong password dbaccess or csdk or any applications shows -951 errors
but in the online.log shows error -952 which is the real error number.
For example:
DBACCESS:
951: Incorrect password or user informix@neit is not known on the dat
ONLINE.LOG:
15:17:07 listener-thread: err = -952: oserr = 0: errstr = informix@drp_test:
User (informix@drp_test)'s password is not correct for the database server.
Anyone knows why this could be happening??
Thanks in advanced.
This is was done intentionally.. so that malicious client could not
determine what was the reason of failure.
In server log we were reporting the error correctly.
regards,
Manoj
=
"LYNKZ MIKE" =
<yellr@telecom.co =
m.co> =
To
Sent by: ids@iiug.org =
ids-bounces@iiug. =
cc
org =
Subj=
ect
dbaccess reports different error=
03/11/2009 03:17 than online.log [15094] =
PM =
=
=
Please respond to =
ids@iiug.org =
=
=
Hi everyone, im facing a problem with ids 10.00.FC9 on aix 5.3. When a
users
inputs wrong password dbaccess or csdk or any applications shows -951
errors
but in the online.log shows error -952 which is the real error number.
For example:
DBACCESS:
951: Incorrect password or user informix@neit is not known on the dat
ONLINE.LOG:
15:17:07 listener-thread: err =3D -952: oserr =3D 0: errstr =3D
informix@drp_test:
User (informix@drp_test)'s password is not correct for the database ser=
ver.
Anyone knows why this could be happening??
Thanks in advanced.
***********************************************************************=
********
Forum Note: Use "Reply" to post a response in the discussion forum.
=
↪ replying to Manoj Mohan
LYNKZ MIKE — — source: IIUG Forums & Mailing Lists
Hi Manoj, thanks for your answer, i just made a test on a ids installed on
suse on my vmware, and the error showed when i input wrong password on
dbaccess is 952 same like on online.log.
It could be a problem with fix level? or any enviroment variable?
Thanks for help
Hi Lynkz
This is expected behavior which was introduced since 10.00.UX7. It prevents an
attacker to distinguish between an invalid login name (and hence also an
invalid password) and a valid login name and invalid password.
Regards,
-Ping
--- On Wed, 3/11/09, LYNKZ MIKE <yellr@telecom.com.co> wrote:
> From: LYNKZ MIKE <yellr@telecom.com.co>
> Subject: dbaccess reports different error than online.log [15094]
> To: ids@iiug.org
> Date: Wednesday, March 11, 2009, 3:17 PM
> Hi everyone, im facing a problem with
> ids 10.00.FC9 on aix 5.3. When a users
> inputs wrong password dbaccess or csdk or any applications
> shows -951 errors
> but in the online.log shows error -952 which is the real
> error number.
>
> For example:
> DBACCESS:
> 951: Incorrect password or user informix@neit is not known> on the dat
>
> ONLINE.LOG:
> 15:17:07 listener-thread: err = -952: oserr = 0: errstr =
> informix@drp_test:
> User (informix@drp_test)'s password is not correct for the
> database server.
>
> Anyone knows why this could be happening??
>
> Thanks in advanced.
>
>
>
*******************************************************************************
>
> Forum Note: Use "Reply" to post a response in the
> discussion forum.
>
>
↪ replying to PING TANG
LYNKZ MIKE — — source: IIUG Forums & Mailing Lists
awesome Ping!!! that sounds reasonable, do you have any source documentation
for this??
Thanks a lot in advanced
Probably you have an older version IDS on your VMware. Would you please
provide your IDS version?
Regards,
-Ping
--- On Wed, 3/11/09, LYNKZ MIKE <yellr@telecom.com.co> wrote:
> From: LYNKZ MIKE <yellr@telecom.com.co>
> Subject: Re: dbaccess reports different error than online.l [15096]
> To: ids@iiug.org
> Date: Wednesday, March 11, 2009, 3:54 PM
> Hi Manoj, thanks for your answer, i
> just made a test on a ids installed on
> suse on my vmware, and the error showed when i input wrong
> password on
> dbaccess is 952 same like on online.log.
>
> It could be a problem with fix level? or any enviroment
> variable?
> Thanks for help
>
>
>
*******************************************************************************
>
> Forum Note: Use "Reply" to post a response in the
> discussion forum.
>
>
Hi Lynkz
Please refer to bug132837 in 10.00XC7's release notes.
Regards,
-Ping
--- On Wed, 3/11/09, LYNKZ MIKE <yellr@telecom.com.co> wrote:
> From: LYNKZ MIKE <yellr@telecom.com.co>
> Subject: Re: dbaccess reports different error than online.l [15098]
> To: ids@iiug.org
> Date: Wednesday, March 11, 2009, 4:05 PM
> awesome Ping!!! that sounds
> reasonable, do you have any source documentation
> for this??
>
> Thanks a lot in advanced
>
>
>
*******************************************************************************
>
> Forum Note: Use "Reply" to post a response in the
> discussion forum.
>
>
↪ replying to PING TANG
LYNKZ MIKE — — source: IIUG Forums & Mailing Lists
Yeah Ping, you are really rigth!!
Just i reinstalled ids from 10.00.FC4 on same S.O (AIX 5.3) and tried to use a
wrong password and dbaccess showed me 952: User (informix@drp_test)'s password
is not correct for the datab
Thanks a lot again, your help was really helpful
We use strictly necessary cookies to make this site work. With your
consent we’d also use optional cookies for analytics and marketing. You can accept all,
reject all, or choose. Read our Cookie Policy.