RE: Onstat -g ses only for DBSA?
Posted in 2005
Topics: General Discussion
In 9.40 IBM added more information about the session and decided to hide it from all users other than DBSA. IDS 10 also has it hidden. MW > -----Original Message----- > From: owner-informix-list@iiug.org > [mailto:owner-informix-list@iiug.org] On Behalf Of Paul Watson > Sent: Friday, 8 April 2005 9:57 a.m. > To: informix-list@iiug.org > Subject: Re: Onstat -g ses only for DBSA? > > Raise a support call and get it a feature request sent to IBM > > > Lucho wrote: > > > Hi, I have got a doubt. > > > > There are two servers. > > > > One of them with an informix server version: IBM Informix Dynamic > > Server Version 9.30.UC6W4 > > > > and the other > > IBM Informix Dynamic Server Version 9.40.FC5 > > > > When I execute the command Onstat -g ses on the first one (version > > 9.30), it's all good > > > > but when I execute the command on the second one (version > 9.40), I've > > got the following error: > > Must be a DBSA to run this program. > > > > I am not DBSA in any of these servers. > > > > What's the problem? THANKS! > > > -- > Paul Watson # > Oninit Ltd # Growing old is mandatory > Tel: +44 1436 672201 # Growing up is optional > Fax: +44 1436 678693 # > Mob: +44 7818 003457 # > www.oninit.com # > > sending to informix-list
Murray Wood (IList) wrote:
> In 9.40 IBM added more information about the session and decided to
> hide it from all users other than DBSA. IDS 10 also has it hidden.
>
>>From: Paul Watson
>>
>>Raise a support call and get it a feature request sent to IBM
>>
>>Lucho wrote:
>>>There are two servers.
>>>
>>>One of them with an informix server version: IBM Informix Dynamic
>>>Server Version 9.30.UC6W4
>>>
>>>and the other
>>>IBM Informix Dynamic Server Version 9.40.FC5
>>>
>>> When I execute the command Onstat -g ses on the first one
>>> (version 9.30), it's all good but when I execute the command on
>>> the second one (version 9.40), I've got the following error:
>>> Must be a DBSA to run this program.
>>>
>>>I am not DBSA in any of these servers.
>>>
>>>What's the problem? THANKS!
The problem is that you can see the SQL, and the SQL can include
confidential information. If anyone can run onstat -g ses, anyone can
see the confidential data in the SQL - and if you're using encryption,
that could include passwords. It is not remotely clear that it is (or
ever was) a good idea for the general public (including intruders logged
in as an unprivileged user) to be able to see the SQL of other users.
That said, it may be necessary to provide a mechanism that the DBSA can
configure to permit 'onstat -g ses' and related queries to be used by
unprivileged users. I don't like it in the slightest, but if you really
don't care who can see what in your database, maybe you should be
allowed to say "Yes - the intruders can see anything in my database".
With this one, unusually, I don't think there is already a get-out
mechanism; for all the other changes in security, I believe there is an
override that can be used if you really insist on running an insecure
system.
There are a number of other places where the server currently defaults
to insecure and modern requirements mean that the default will be
secure. That means there will be vaguely similar changes in the future.
There'll be an override mechanism, but out of the box, the server will
run (more) securely.
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2005.01 -- http://dbi.perl.org/
Jonathan Leffler schrieb:
> Murray Wood (IList) wrote:
>
>> In 9.40 IBM added more information about the session and decided to
>> hide it from all users other than DBSA. IDS 10 also has it hidden.
>>
>>> From: Paul Watson
>>>
>>> Raise a support call and get it a feature request sent to IBM
>>>
>>> Lucho wrote:
>>>
>>>> There are two servers.
>>>> One of them with an informix server version: IBM Informix Dynamic
>>>> Server Version 9.30.UC6W4
>>>>
>>>> and the other
>>>> IBM Informix Dynamic Server Version 9.40.FC5
>>>>
>>>> When I execute the command Onstat -g ses on the first one
>>>> (version 9.30), it's all good but when I execute the command on
>>>> the second one (version 9.40), I've got the following error:
>>>> Must be a DBSA to run this program.
>>>>
>>>> I am not DBSA in any of these servers.
>>>>
>>>> What's the problem? THANKS!
>
>
> The problem is that you can see the SQL, and the SQL can include
> confidential information. If anyone can run onstat -g ses, anyone can
> see the confidential data in the SQL - and if you're using encryption,
> that could include passwords. It is not remotely clear that it is (or
> ever was) a good idea for the general public (including intruders logged
> in as an unprivileged user) to be able to see the SQL of other users.
>
> That said, it may be necessary to provide a mechanism that the DBSA can
> configure to permit 'onstat -g ses' and related queries to be used by
> unprivileged users. I don't like it in the slightest, but if you really
> don't care who can see what in your database, maybe you should be
> allowed to say "Yes - the intruders can see anything in my database".
> With this one, unusually, I don't think there is already a get-out
> mechanism; for all the other changes in security, I believe there is an
> override that can be used if you really insist on running an insecure
> system.
>
> There are a number of other places where the server currently defaults
> to insecure and modern requirements mean that the default will be
> secure. That means there will be vaguely similar changes in the future.
> There'll be an override mechanism, but out of the box, the server will
> run (more) securely.
>
we use sudo on several sites to overcome the new feature, although
I personally like them. Several customers wanted to keep everything
'as it always was' , though.
dic_k
--
Richard Kofler
SOLID STATE EDV
Dienstleistungen GmbH
Vienna/Austria/Europe
Related threads
- Posting from the Informix-list
- Migrating from IDS 9.40.UC6 to 11.50.UC3
- Ip for a network session
- questions onstat -g