Re: Identifying ODBC Connections?
Posted in 2007
On Jun 2, 3:15 am, "DGPretzel" <d...@gci.net> wrote:
> "scottishpoet" <drybur...@yahoo.com> wrote in message
>
> news:1180707376.310893.278720@u30g2000hsc.googlegroups.com...
>
> > Do you suspect these are exisiting users that are now also using ODBC
> > or new users that are using ODBC?
>
> Existing users.
>
>
>
> > onstat -u>
> > This would get the user IDs and every session they had connected to
> > the server. their ODBC connection so do some users have more
> > connections that you believe they should have?
>
> All the ordinary (non IT staff) users have at most one session at a time.
> We just want to know if each session is an ODBC connection or not.
>
>
>
> > is it exisiting users using their own password or has someones
> > password been "cloned" and they all use the same user id and password?
>
> The former.
>
> > If you feel someones password has been compromised you can revoke that
> > ID and password anbd theyn see how many people moan they can;t connect
> > anymore. You would see a lengthy list of a particluar user ID if it
> > was being abused.
>
> We do not suspect any compromised passwords. People are using their own
> accounts.
>
> > Do your "Normal" applications use shared memory connections or TCP
> > connections? If its normally shared memeory connections then change
> > the port that the TCP connections are using and configure this on the
> > "authorised" odbc users machines and then see who moans they can't
> > connect anymore
>
> All users use TCP connections. So, we can't distinguish ODBC that way.
> We just would like to determine which sessions are ODBC, if any, because
> that would indicate a user to be investigated for MS Access or Excel use.
>
> I contacted Informix Tech Support, and they told us it can't be done.
>
> I guess that's the end of this line of inquiry.
>
> It sure would be useful to us, and possibly others, to be able to discern
> this. Excel and Access are just ubiquitous.
>
> Thank you, anyway, for your thoughts.
>
> DG
We use ODBC connections and I noticed that the TTY column on onstat -u
shows the machine name of the Windows PC instead of the TTY session.
Our Solaris app server they know their passwords, but the password on
the Informix server differs. Anyone who needs ODBC access gets a
special login and password. Not great but it works and keeps the
rookies away from the database. I wish the ODBC drivers could be read
only.