Auditor fun
Posted in 2007
Topics: Server Administration, Security, Permissions & Auditing
We had the Auditors round today, usual stuff, how do we control
database access, password expiry policy etc etc (set bullshit
generator to 'Stun'), but he also showed me this article by some bloke
called David Litchfiled from a chapter in the "Database Hackers
Handbook" called "Informix - discovery, attack and defense".
Anyway, apart from the obvious bits about stack overflow exploits and
how easy it is to breach a windows box (old news is no news....) and
some stuff about parsing shmem dumps to get user passwords out (I
don't think so), it has the following gem
<quote>
If you can connect to the server then you can issue the
CREATE DATABASE command - regardless of your privileges; what's more,the database is created and you are given DBA privileges on it. Once
you're
DBA on a database you own the whole server. Whilst this doesn't seem
to be public knowledge yet, IBM have known about it for a while and
there is an undocumented
workaround available to prevent this. See the section on securing
Informix for more details. At this stage it seems like "game over" but
on the off
chance that someone has protected their server using the workaround,
let's examine
other ways to gain control of the server.
</quote>
What utter crap - create a database and suddenly you're God on the
server - errmm hello, error 388 "No Resource Permission" on any other
db on the server (unless you have resource permission granted by the
DBA!). Where did he get this rubbish? And who is David Litchfield?
Reads like disinformation to me........
Do not underestimate that....!!!!!!!
one could create tables consuming all the space is the easiest thing
which comes
to mind....
that is why V93 and higher if i recall correctly have a onconfig
param:
DBCREATE_PERMISSION informix
this will give
330: Cannot create or rename database.
388: No resource permission.when you try to create a database as other user then informix.
Superboer.
On 18 sep, 16:24, mal...@btinternet.com wrote:
> We had the Auditors round today, usual stuff, how do we control
> database access, password expiry policy etc etc (set bullshit
> generator to 'Stun'), but he also showed me this article by some bloke
> called David Litchfiled from a chapter in the "Database Hackers
> Handbook" called "Informix - discovery, attack and defense".
> Anyway, apart from the obvious bits about stack overflow exploits and
> how easy it is to breach a windows box (old news is no news....) and
> some stuff about parsing shmem dumps to get user passwords out (I
> don't think so), it has the following gem
> <quote>
> If you can connect to the server then you can issue the
> CREATE DATABASE command - regardless of your privileges; what's more,> the database is created and you are given DBA privileges on it. Once
> you're
> DBA on a database you own the whole server. Whilst this doesn't seem
> to be public knowledge yet, IBM have known about it for a while and
> there is an undocumented
> workaround available to prevent this. See the section on securing
> Informix for more details. At this stage it seems like "game over" but
> on the off
> chance that someone has protected their server using the workaround,
> let's examine
> other ways to gain control of the server.
> </quote>
> What utter crap - create a database and suddenly you're God on the
> server - errmm hello, error 388 "No Resource Permission" on any other
> db on the server (unless you have resource permission granted by the
> DBA!). Where did he get this rubbish? And who is David Litchfield?
> Reads like disinformation to me........
On 18 Sep, 15:51, Superboer <superbo...@t-online.de> wrote:
> Do not underestimate that....!!!!!!!
> one could create tables consuming all the space is the easiest thing
> which comes
> to mind....
>
> that is why V93 and higher if i recall correctly have a onconfig
> param:
>
> DBCREATE_PERMISSION informix
> this will give
> 330: Cannot create or rename database.
> 388: No resource permission.> when you try to create a database as other user then informix.
>
> Superboer.
>
Yes but that would just be a DOS attack, Litchfield's implication is
that you become DBA or similar on all databases and hence can be
*really* malicious.
Malc