sysdbopen
Posted in 2011
User asked how to prevent the sysdbopen procedure from being displayed via dbschema command to users with limited permissions. Suggested solutions included removing dbschema from user paths, using a modified dbschema replacement utility, and restricting direct access. However, responders noted users could still access procedure source via direct sysprocbody queries, and LBAC restrictions might be needed as a proper solution.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Stored Procedures & SPL, Platform-Specific Issues
Redhat Enterprise Linux 5
Informix 11.50 FC8W2
Is there a way to protect the <user>.sysdbopen procedure from being
displayed using the dbschema command?
Example.
User X has CONNECT permissions to a database and only SELECT permissions
on tables.
If the user does dbschema -d <dbname> -f all, the sysdbopen procedure
schema will be dumped for that user.
I'm looking for a way to protect that code from being seen by users.
Thanks for you help.
Jamie
restrict the dbschema command.
j.
On Sep 22, 2011, at 3:10 PM, jgedyedba@teleformix.com wrote:
> Redhat Enterprise Linux 5=20
> Informix 11.50 FC8W2=20
>=20
> Is there a way to protect the <user>.sysdbopen procedure from being=20
> displayed using the dbschema command?=20
>=20
> Example.=20
>=20
> User X has CONNECT permissions to a database and only SELECT =
permissions=20
> on tables.=20
>=20
> If the user does dbschema -d <dbname> -f all, the sysdbopen procedure=20=
> schema will be dumped for that user.=20
>=20
> I'm looking for a way to protect that code from being seen by users.=20=
>=20
> Thanks for you help.=20
>=20
> Jamie=20
>=20
>=20
> =
**************************************************************************=
*****=20
> Forum Note: Use "Reply" to post a response in the discussion forum.=20=
>=20
Remove dbschema from that users' paths?
Replace dbschema with a version of my dbschema replacement utility
(myschema) that's been modified to not print out the sysdbopen function?
Art
Art S. Kagel
Advanced DataTools (www.advancedatatools.com)
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions and
do not reflect on my employer, Advanced DataTools, the IIUG, nor any other
organization with which I am associated either explicitly, implicitly, or by
inference. Neither do those opinions reflect those of other individuals
affiliated with any entity with which I am affiliated nor those of the
entities themselves.
On Thu, Sep 22, 2011 at 3:10 PM, jgedyedba@teleformix.com <
jgedyedba@teleformix.com> wrote:
> Redhat Enterprise Linux 5
> Informix 11.50 FC8W2
>
> Is there a way to protect the <user>.sysdbopen procedure from being
> displayed using the dbschema command?
>
> Example.
>
> User X has CONNECT permissions to a database and only SELECT permissions
> on tables.
>
> If the user does dbschema -d <dbname> -f all, the sysdbopen procedure
> schema will be dumped for that user.
>
> I'm looking for a way to protect that code from being seen by users.
>
> Thanks for you help.
>
> Jamie
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--20cf303bfbc4c7322f04ad8ced32
Just a note, there is no way to guarantee the user will not directly
access sysprocbody :
select p.owner, p.procname, p.mode , b.*
from sysmaster:sysprocedures p, sysmaster:sysprocbody b
where b.procid = p.procid
and p.procname = 'sysdbopen'
and b.datakey = 'T'
On 22/9/2011 16:45, Art Kagel wrote:
> Remove dbschema from that users' paths?
> Replace dbschema with a version of my dbschema replacement utility
> (myschema) that's been modified to not print out the sysdbopen function?
>
> Art
>
> Art S. Kagel
> Advanced DataTools (www.advancedatatools.com)
> Blog: http://informix-myview.blogspot.com/
>
> Disclaimer: Please keep in mind that my own opinions are my own opinions and
> do not reflect on my employer, Advanced DataTools, the IIUG, nor any other
> organization with which I am associated either explicitly, implicitly, or by
> inference. Neither do those opinions reflect those of other individuals
> affiliated with any entity with which I am affiliated nor those of the
> entities themselves.
>
> On Thu, Sep 22, 2011 at 3:10 PM, jgedyedba@teleformix.com<
> jgedyedba@teleformix.com> wrote:
>
>> Redhat Enterprise Linux 5
>> Informix 11.50 FC8W2
>>
>> Is there a way to protect the<user>.sysdbopen procedure from being
>> displayed using the dbschema command?
>>
>> Example.
>>
>> User X has CONNECT permissions to a database and only SELECT permissions
>> on tables.
>>
>> If the user does dbschema -d<dbname> -f all, the sysdbopen procedure
>> schema will be dumped for that user.
>>
>> I'm looking for a way to protect that code from being seen by users.
>>
>> Thanks for you help.
>>
>> Jamie
>>
>>
>>
>>
>
*******************************************************************************
>> Forum Note: Use "Reply" to post a response in the discussion forum.
>>
>>
> --20cf303bfbc4c7322f04ad8ced32
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
True. LBAC restriction on the source records there? Maybe?
Art
On Sep 23, 2011 1:09 PM, "Cesar Inacio Martins" <
cesar_inacio_martins@yahoo.com.br> wrote:
> Just a note, there is no way to guarantee the user will not directly
> access sysprocbody :
>
> select p.owner, p.procname, p.mode , b.*
> from sysmaster:sysprocedures p, sysmaster:sysprocbody b
> where b.procid = p.procid>
> and p.procname = 'sysdbopen'
>
> and b.datakey = 'T'
>
> On 22/9/2011 16:45, Art Kagel wrote:
>> Remove dbschema from that users' paths?
>> Replace dbschema with a version of my dbschema replacement utility
>> (myschema) that's been modified to not print out the sysdbopen function?
>>
>> Art
>>
>> Art S. Kagel
>> Advanced DataTools (www.advancedatatools.com)
>> Blog: http://informix-myview.blogspot.com/
>>
>> Disclaimer: Please keep in mind that my own opinions are my own opinions
and
>> do not reflect on my employer, Advanced DataTools, the IIUG, nor any
other
>> organization with which I am associated either explicitly, implicitly, or
by
>> inference. Neither do those opinions reflect those of other individuals
>> affiliated with any entity with which I am affiliated nor those of the
>> entities themselves.
>>
>> On Thu, Sep 22, 2011 at 3:10 PM, jgedyedba@teleformix.com<
>> jgedyedba@teleformix.com> wrote:
>>
>>> Redhat Enterprise Linux 5
>>> Informix 11.50 FC8W2
>>>
>>> Is there a way to protect the<user>.sysdbopen procedure from being
>>> displayed using the dbschema command?
>>>
>>> Example.
>>>
>>> User X has CONNECT permissions to a database and only SELECT permissions
>>> on tables.
>>>
>>> If the user does dbschema -d<dbname> -f all, the sysdbopen procedure
>>> schema will be dumped for that user.
>>>
>>> I'm looking for a way to protect that code from being seen by users.
>>>
>>> Thanks for you help.
>>>
>>> Jamie
>>>
>>>
>>>
>>>
>>
>
*******************************************************************************
>>> Forum Note: Use "Reply" to post a response in the discussion forum.
>>>
>>>
>> --20cf303bfbc4c7322f04ad8ced32
>>
>>
>>
>
*******************************************************************************
>> Forum Note: Use "Reply" to post a response in the discussion forum.
>>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
--90e6ba3fcd554b171d04ad9ee878
Just a quick note, sysdbopen can be a C UDR or Java UDR.
John F. Miller III
STSM, Embedability Architect
miller3@us.ibm.com
503-578-5645
IBM Informix Dynamic Server (IDS)
ids-bounces@iiug.org wrote on 09/23/2011 10:08:44 AM:
> From: "Cesar Inacio Martins" <cesar_inacio_martins@yahoo.com.br>
> To: ids@iiug.org
> Date: 09/23/2011 10:09 AM
> Subject: Re: sysdbopen [25021]
> Sent by: ids-bounces@iiug.org
>
> Just a note, there is no way to guarantee the user will not directly
> access sysprocbody :
>
> select p.owner, p.procname, p.mode , b.*
> from sysmaster:sysprocedures p, sysmaster:sysprocbody b
> where b.procid = p.procid>
> and p.procname = 'sysdbopen'
>
> and b.datakey = 'T'
>
> On 22/9/2011 16:45, Art Kagel wrote:
> > Remove dbschema from that users' paths?
> > Replace dbschema with a version of my dbschema replacement utility
> > (myschema) that's been modified to not print out the sysdbopen
function?
> >
> > Art
> >
> > Art S. Kagel
> > Advanced DataTools (www.advancedatatools.com)
> > Blog: http://informix-myview.blogspot.com/
> >
> > Disclaimer: Please keep in mind that my own opinions are my own
> opinions and
> > do not reflect on my employer, Advanced DataTools, the IIUG, nor any
other
> > organization with which I am associated either explicitly,
> implicitly, or by
> > inference. Neither do those opinions reflect those of other individuals
> > affiliated with any entity with which I am affiliated nor those of the
> > entities themselves.
> >
> > On Thu, Sep 22, 2011 at 3:10 PM, jgedyedba@teleformix.com<
> > jgedyedba@teleformix.com> wrote:
> >
> >> Redhat Enterprise Linux 5
> >> Informix 11.50 FC8W2
> >>
> >> Is there a way to protect the<user>.sysdbopen procedure from being
> >> displayed using the dbschema command?
> >>
> >> Example.
> >>
> >> User X has CONNECT permissions to a database and only SELECT
permissions
> >> on tables.
> >>
> >> If the user does dbschema -d<dbname> -f all, the sysdbopen procedure
> >> schema will be dumped for that user.
> >>
> >> I'm looking for a way to protect that code from being seen by users.
> >>
> >> Thanks for you help.
> >>
> >> Jamie
> >>
> >>
> >>
> >>
> >
>
*******************************************************************************
> >> Forum Note: Use "Reply" to post a response in the discussion forum.
> >>
> >>
> > --20cf303bfbc4c7322f04ad8ced32
> >
> >
> >
>
*******************************************************************************
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>