RE: onstat: Shared memory: permission denied???
Posted in 2000
Topics: Security, Permissions & Auditing, Platform-Specific Issues
I've heard this for the past few years on this list, and I have yet to
find a reason why. We do it, and have NEVER had ANY problems
whatsoever. There is however a slight advantage in having a readymade
group that MIS can use. Whatever the security reasons are, they are
still there. If I were unable to do something due to not being in group
Informix, I would just su to root (or informix) and do it anyway. This
way is less typing.
Why all the paranoia?
-----Original Message-----
From: Obnoxio The Clown [mailto:obnoxio@hotmail.com]
Sent: Wednesday, June 07, 2000 6:23 AM
Posted To: informix
Conversation: onstat: Shared memory: permission denied???
Subject: Re: onstat: Shared memory: permission denied???
Nononononononononononononononononononononononononononononononononono!!
From: dmoeller@geocities.com
>
>You might try adding that 'other' user to the informix group.
Nooooooooooooooooooooooooooooooo!!! Major security violation.
>Here's what 'ipcs' outputs on my system:
>IPC status from <running system> as of Tue Jun 6 10:38:3
>Message Queue facility not in system.
>T ID KEY MODE OWNER GROUP
>Shared Memory:
>m 800 0x52574801 --rw-rw---- root informix
>m 801 0x52574802 --rw-rw---- root informix
>m 802 0x52574803 --rw-rw---- root informix
>
>So if a user isn't root, informix or in the informix group they won't
>have permissions to read the shared memory segments..
>
>The groups on my solaris 2.6 are in /etc/group.
>
>Dave
>
>
>In article <960306588.533683@curry>,
> "Marc Thompson" <MarcT@bops.com> wrote:
> > Greetings,
> >
> > I'm receiving the following error message when I run onstat - as any
>user
> > other than root and informix:
> >
> > #onstat -
> > onstat: Shared memory: permission denied
> >
> > I've searched through Answers Online and found nothing.
> >
> > I am running Informix Dynamic Server.2000 on a RedHat Linux 6.2
>system.
> >
> > Any help is appreciated,
> > Marc Thompson
> >
> > --
> > ---------------------------------------
> > Marc Thompson
> > BOPS, Inc.
> > Austin, TX
> >
> >
>
>
>Sent via Deja.com http://www.deja.com/
>Before you buy.
________________________________________________________________________
Get Your Private, Free E-mail from MSN Hotmail at http://www.hotmail.com
My thoughts exactly Scott.
Well said.
"playing devil's advocate is second nature for everyone, we don't need
any experts. what we do need is people who can fix problems...."
Said by Dave in response to the stupid, moronic "well, being the
devil's advocate"
Dave
> Scott Black
>
> I've heard this for the past few years on this list, and I have yet to
> find a reason why. We do it, and have NEVER had ANY problems
> whatsoever. There is however a slight advantage in having a readymade
> group that MIS can use. Whatever the security reasons are, they are
> still there. If I were unable to do something due to not being in
group
> Informix, I would just su to root (or informix) and do it anyway.
This
> way is less typing.
>
> Why all the paranoia?
>
> -----Original Message-----
> From: Obnoxio The Clown [mailto:obnoxio@hotmail.com]
> Nononononononononononononononononononononononononononononononononono!!
>
> From: dmoeller@geocities.com
> >
> >You might try adding that 'other' user to the informix group.
>
> Nooooooooooooooooooooooooooooooo!!! Major security violation.
>
> >Here's what 'ipcs' outputs on my system:
> >IPC status from <running system> as of Tue Jun 6 10:38:3
> >Message Queue facility not in system.
> >T ID KEY MODE OWNER GROUP
> >Shared Memory:
> >m 800 0x52574801 --rw-rw---- root informix
> >m 801 0x52574802 --rw-rw---- root informix
> >m 802 0x52574803 --rw-rw---- root informix
> >
> >So if a user isn't root, informix or in the informix group they won't
> >have permissions to read the shared memory segments..
> >
> >The groups on my solaris 2.6 are in /etc/group.
> >
> >Dave
> >
> >
> >In article <960306588.533683@curry>,
> > "Marc Thompson" <MarcT@bops.com> wrote:
> > > Greetings,
> > >
> > > I'm receiving the following error message when I run onstat - as
any
> >user
> > > other than root and informix:
> > >
> > > #onstat -
> > > onstat: Shared memory: permission denied
> > >
> > > I've searched through Answers Online and found nothing.
> > >
> > > I am running Informix Dynamic Server.2000 on a RedHat Linux 6.2
> >system.
> > >
> > > Any help is appreciated,
> > > Marc Thompson
> > >
> > > --
> > > ---------------------------------------
> > > Marc Thompson
> > > BOPS, Inc.
> > > Austin, TX
Sent via Deja.com http://www.deja.com/
Before you buy.
Scott Black wrote:
> I've heard this for the past few years on this list, and I have yet to
> find a reason why. We do it, and have NEVER had ANY problems
> whatsoever. There is however a slight advantage in having a readymade
> group that MIS can use. Whatever the security reasons are, they are
> still there. If I were unable to do something due to not being in group
> Informix, I would just su to root (or informix) and do it anyway. This
> way is less typing.
>
> Why all the paranoia?
You seem to be implying that all DBAs belong to the group "informix".
That's OK.
But if you have all and sundry belonging to the group, you could get into
trouble. The most dramatic example is that such users get the ability to
bring down the instance (onmode -ky). Other examples abound.
Rudy
>
>
> -----Original Message-----
> From: Obnoxio The Clown [mailto:obnoxio@hotmail.com]
> Sent: Wednesday, June 07, 2000 6:23 AM
> Posted To: informix
> Conversation: onstat: Shared memory: permission denied???
> Subject: Re: onstat: Shared memory: permission denied???
>
> Nononononononononononononononononononononononononononononononononono!!
>
> Get Your Private, Free E-mail from MSN Hotmail at http://www.hotmail.com
Members of group informix can shutdown the engine, OK if only DBAs are
included. My biggest objection is that group members can write to database
RAW disk directly. I just want anyone writing to those disks to have to
think about what they are doing enough that they realize they will be
gaining some power by su'ing to user informix to perform whatever engine
maintenance is needed. Our own logins are for our own work, the informix
login for server work. Helps me and mine put on the right 'head' and get
into the correct frame of mind, read: CAREFUL!
Art S. Kagel
Scott Black wrote:
>
> I've heard this for the past few years on this list, and I have yet to
> find a reason why. We do it, and have NEVER had ANY problems
> whatsoever. There is however a slight advantage in having a readymade
> group that MIS can use. Whatever the security reasons are, they are
> still there. If I were unable to do something due to not being in group
> Informix, I would just su to root (or informix) and do it anyway. This
> way is less typing.
>
> Why all the paranoia?
>
> -----Original Message-----
> From: Obnoxio The Clown [mailto:obnoxio@hotmail.com]
> Sent: Wednesday, June 07, 2000 6:23 AM
> Posted To: informix
> Conversation: onstat: Shared memory: permission denied???
> Subject: Re: onstat: Shared memory: permission denied???
>
> Nononononononononononononononononononononononononononononononononono!!
>
> From: dmoeller@geocities.com
> >
> >You might try adding that 'other' user to the informix group.
>
> Nooooooooooooooooooooooooooooooo!!! Major security violation.
>
> >Here's what 'ipcs' outputs on my system:
> >IPC status from <running system> as of Tue Jun 6 10:38:3
> >Message Queue facility not in system.
> >T ID KEY MODE OWNER GROUP
> >Shared Memory:
> >m 800 0x52574801 --rw-rw---- root informix
> >m 801 0x52574802 --rw-rw---- root informix
> >m 802 0x52574803 --rw-rw---- root informix
> >
> >So if a user isn't root, informix or in the informix group they won't
> >have permissions to read the shared memory segments..
> >
> >The groups on my solaris 2.6 are in /etc/group.
> >
> >Dave
> >
> >
> >In article <960306588.533683@curry>,
> > "Marc Thompson" <MarcT@bops.com> wrote:
> > > Greetings,
> > >
> > > I'm receiving the following error message when I run onstat - as any
> >user
> > > other than root and informix:
> > >
> > > #onstat -
> > > onstat: Shared memory: permission denied
> > >
> > > I've searched through Answers Online and found nothing.
> > >
> > > I am running Informix Dynamic Server.2000 on a RedHat Linux 6.2
> >system.
> > >
> > > Any help is appreciated,
> > > Marc Thompson
> > >
> > > --
> > > ---------------------------------------
> > > Marc Thompson
> > > BOPS, Inc.
> > > Austin, TX
> > >
> > >
> >
> >
> >Sent via Deja.com http://www.deja.com/
> >Before you buy.
>
> ________________________________________________________________________
> Get Your Private, Free E-mail from MSN Hotmail at http://www.hotmail.com