Privileges
Posted in 2008
Topics: Stored Procedures & SPL, Security, Permissions & Auditing
I found a very strange case, in which an unprivileged user on the objects in
the DB, you can make all kinds of activities on them:
NOTE: There is no privilege assigned to "public"
**************************************
1) Verify that the user can connect to the DB, and are not allowed on any
objects it.
dbschema -d produc_320 -p mrombola
DBSCHEMA Schema Utility INFORMIX-SQL Version 10.00.FC6
Copyright IBM Corporation 1996, 2006 All rights reserved
Software Serial Number AAA#B000000
grant connect to "mrombola";
revoke usage on language SPL from public ;
grant usage on language SPL to public ;No permissions for user mrombola.
2) Even if you have verified that the user does not have privileges on any
subject of the BD, I can perform queries and updates without any problems.
user_connect
mrombola
num_proceso_dw cla_fac descripcion (select and insert)
1 PPP Prueba
Someone can help determine what might be happening?
Thank you! Greetings.
Paola Rombolá
Cordoba-Argentina
You've given public access - this is everyone. Public overrides individuals
-----Original Message-----
From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of PAOLA
ROMBOLá
Sent: 04 February 2008 16:40
To: ids@iiug.org
Subject: Privileges [11135]
I found a very strange case, in which an unprivileged user on the objects in
the DB, you can make all kinds of activities on them:
NOTE: There is no privilege assigned to "public"
**************************************
1) Verify that the user can connect to the DB, and are not allowed on any
objects it.
dbschema -d produc_320 -p mrombola
DBSCHEMA Schema Utility INFORMIX-SQL Version 10.00.FC6
Copyright IBM Corporation 1996, 2006 All rights reserved
Software Serial Number AAA#B000000
grant connect to "mrombola";
revoke usage on language SPL from public ;
grant usage on language SPL to public ;No permissions for user mrombola.
2) Even if you have verified that the user does not have privileges on any
subject of the BD, I can perform queries and updates without any problems.
user_connect
mrombola
num_proceso_dw cla_fac descripcion (select and insert)
1 PPP Prueba
Someone can help determine what might be happening?
Thank you! Greetings.
Paola Rombola
Cordoba-Argentina
****************************************************************************
***
Forum Note: Use "Reply" to post a response in the discussion forum.
No virus found in this incoming message.
Checked by AVG Free Edition.
Version: 7.5.516 / Virus Database: 269.19.19/1257 - Release Date: 03/02/2008
17:49
No virus found in this outgoing message.
Checked by AVG Free Edition.
Version: 7.5.516 / Virus Database: 269.19.19/1257 - Release Date: 03/02/2008
17:49
PAOLA ROMBOLá wrote:
If your have tables that have granted priveleges to user PUBLIC, then
any user with CONNECT privelege will inherit the public privs on those
tables.
Art S. Kagel
Oninit
> I found a very strange case, in which an unprivileged user on the objects in
> the DB, you can make all kinds of activities on them:
>
> NOTE: There is no privilege assigned to "public"
> **************************************
>
> 1) Verify that the user can connect to the DB, and are not allowed on any
> objects it.
>
> dbschema -d produc_320 -p mrombola>
> DBSCHEMA Schema Utility INFORMIX-SQL Version 10.00.FC6
> Copyright IBM Corporation 1996, 2006 All rights reserved
> Software Serial Number AAA#B000000
>
> grant connect to "mrombola";
> revoke usage on language SPL from public ;
> grant usage on language SPL to public ;> No permissions for user mrombola.
>
> 2) Even if you have verified that the user does not have privileges on any
> subject of the BD, I can perform queries and updates without any problems.
>
> user_connect
> mrombola
>
> num_proceso_dw cla_fac descripcion (select and insert)
>
> 1 PPP Prueba
>
> Someone can help determine what might be happening?
>
> Thank you! Greetings.
>
> Paola Rombolá
> Cordoba-Argentina
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
> ------------------------------------------------------------------------
>
> See you at the IIUG Informix 2008 Conference
> The Power Conference for Informix Professionals
> April 27 - 30, 2008 Marriott Overland Park (Kansas City), Kansas
> http://www.iiug.org/conf
> Registration Now Open!!
================================================================================
===========
Please access the attached hyperlink for an important electronic
communications disclaimer:
http://www.oninit.com/home/disclaimer.php
================================================================================
===========
OK bad reading (next time put glasses on first!) According to the email
content below, youve given connect privilege to mrombola explicitly. This
will allow you to select and insert, but not create tables etc. (Im
assuming that youve previously revoked connect from public on that database
as stated.)
_____
From: Paola Rombolá [mailto:mprombola@hotmail.com]
Sent: 04 February 2008 18:41
To: simon@coynes.eclipse.co.uk
Subject: RE: Privileges [11136]
No Simon, all privileges were revoked from public
> ***********************************
> NOTE: There is no privilege assigned to "public"
> ***********************************
Thank you!
_____
> To: mprombola@hotmail.com
> From: simon@coynes.eclipse.co.uk
> Subject: RE: Privileges [11136]
> Date: Mon, 4 Feb 2008 13:28:25 -0500
>
> You've given public access - this is everyone. Public overrides
individuals
>
> -----Original Message-----
> From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of
PAOLA
> ROMBOLá
> Sent: 04 February 2008 16:40
> To: ids@iiug.org
> Subject: Privileges [11135]
>
> I found a very strange case, in which an unprivileged user on the objects
in
>
> the DB, you can make all kinds of activities on them:
>
> NOTE: There is no privilege assigned to "public"
> **************************************
>
> 1) Verify that the user can connect to the DB, and are not allowed on any
> objects it.
>
> dbschema -d produc_320 -p mrombola>
> DBSCHEMA Schema Utility INFORMIX-SQL Version 10.00.FC6
> Copyright IBM Corporation 1996, 2006 All rights reserved
> Software Serial Number AAA#B000000
>
> grant connect to "mrombola";
> revoke usage on language SPL from public ;
> grant usage on language SPL to public ;> No permissions for user mrombola.
>
> 2) Even if you have verified that the user does not have privileges on any
> subject of the BD, I can perform queries and updates without any problems.
>
> user_connect
> mrombola
>
> num_proceso_dw cla_fac descripcion (select and insert)
>
> 1 PPP Prueba
>
> Someone can help determine what might be happening?
>
> Thank you! Greetings.
>
> Paola Rombola
> Cordoba-Argentina
>
>
****************************************************************************
> ***
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
> No virus found in this incoming message.
> Checked by AVG Free Edition.
> Version: 7.5.516 / Virus Database: 269.19.19/1257 - Release Date:
03/02/2008
> 17:49
>
> No virus found in this outgoing message.
> Checked by AVG Free Edition.
> Version: 7.5.516 / Virus Database: 269.19.19/1257 - Release Date:
03/02/2008
> 17:49
>
>
>
****************************************************************************
***
> Forum Note: Use "Reply" to post a response in the discussion forum.
_____
Express yourself instantly with MSN Messenger! HYPERLINK
"http://clk.atdmt.com/AVE/go/onm00200471ave/direct/01/"MSN Messenger
No virus found in this incoming message.
Checked by AVG Free Edition.
Version: 7.5.516 / Virus Database: 269.19.19/1257 - Release Date: 03/02/2008
17:49
No virus found in this outgoing message.
Checked by AVG Free Edition.
Version: 7.5.516 / Virus Database: 269.19.19/1257 - Release Date: 03/02/2008
17:49
No virus found in this outgoing message.
Checked by AVG Free Edition.
Version: 7.5.516 / Virus Database: 269.19.19/1257 - Release Date: 03/02/2008
17:49