Changing Linux password with IDS 10
Posted in 2007
Topics: Stored Procedures & SPL, Security, Permissions & Auditing, Platform-Specific Issues
Hello group, I need to change user passwords on a linux system through a VB application = and an informix oledb connection. Unfortanatly, the it-policy in this compa= ny does not allow any ssh or telnet clients for this job.=20 So, is there any way to open a shell (passwd) on the linux side through exe= cution of a sql command or a spl function?=20 From a security view, i think there is no way. Any answer, even a "no way" is helpful. tia Joerg Volz=
On 7/13/07, Joerg Volz <joerg@it-volz.de> wrote: > I need to change user passwords on a linux system through a VB application > and an informix oledb connection. Unfortanatly, the it-policy in this company > does not allow any ssh or telnet clients for this job. > So, is there any way to open a shell (passwd) on the linux side through > execution of a sql command or a spl function? > From a security view, i think there is no way. > > Any answer, even a "no way" is helpful. Your as near to 'no way' as is possible without actually being definitive about it. Put it like this, there isn't a way to make an interactive connection to the password program via the regular connection to the database server from the client code. So, all the normal routes are out of the question. Yes, you probably could run something in the way of a stored procedure that uses SYSTEM to run a program that divines the PC from which the VB code connected to the server, and which somehow creates a window on the PC into which the user can type their old password and the new password (twice), but you're into the realms of the ridiculous - I don't know of anyone who has considered it worthwhile to attempt it. Since telnet and ssh are out, I guess you'll have to use rlogin instead. -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2007.0226 -- http://dbi.perl.org/ NB: Please do not use this email for correspondence. I don't necessarily read it every week, even.
I did this on HP-UX in 1992 since Informix 5 - have appl store password in table, then update password table with batch problem which runs often or use stored procedure to trigger change pawword. In a message dated 7/15/2007 12:44:10h s AM Eastern Daylight Time, jleffler.iiug@gmail.com writes: > does not allow any ssh or telnet clients for this job. > So, is there any way to open a shell (passwd) on the linux side through > execution of a sql command or a spl function? ************************************** Get a sneak peak of the all-new AOL at http://discover.aol.com/memed/aolcom30tour