RE: How to prevent ODBC connection
Posted in 1999
Topics: Connectivity: ODBC / JDBC / .NET, Server Administration, Security, Permissions & Auditing
But how do you set up an audit trail when only one user actually modifies the database? CEO "WHO THE HELL DELETED OUR BEST CUSTOMER!!!" DBA "Well, it seems that dummy_user did..." -----Original Message----- From: Art S. Kagel [SMTP:kagel@bloomberg.net] Posted At: Friday, May 28, 1999 11:13 AM Posted To: Informix Conversation: How to prevent ODBC connection Subject: Re: How to prevent ODBC connection Gabor Heppes wrote: > > Hi All, > > My problem with ODBC is not how to make it work, rather how to prevent * smart users accessing the database via ODBC. [clipped] OK I'm going to throw my hat into the ring on this one. I see three problems each feeding on the next so we eliminate them one at a time: o I need to prevent smart dummies from loading an ODBC driver on their PC and accessing the database without authorization. Solution: Remove permissions from ALL users and PUBLIC and only grant dangerous (your definition) permissions to a single dummy user (ie a user with a valid login but no password). o BUT users need permissions so they can run apps that access the database and modify data! Solution: Make all legal apps SUID the dummy user. Only these apps will be able to do anything you want to restrict. [clipped] Art S. Kagel
Scott Black wrote: > > But how do you set up an audit trail when only one user actually > modifies the database? > > CEO "WHO THE HELL DELETED OUR BEST CUSTOMER!!!" > > DBA "Well, it seems that dummy_user did..." I think I answered this but my news server has presented it so.... That SUID APP captures the REAL userid or name and sends it as part of the update/insert/delete. I used to have a partner who insisted, rather strongly, before triggers, that every table carry a last-update-date and a last-modified-by column. Even with triggers I often have to agree with her that this is the best way to maintain a trail. Art S. Kagel > -----Original Message----- > From: Art S. Kagel [SMTP:kagel@bloomberg.net] > Posted At: Friday, May 28, 1999 11:13 AM > Posted To: Informix > Conversation: How to prevent ODBC connection > Subject: Re: How to prevent ODBC connection > > Gabor Heppes wrote: > > > > Hi All, > > > > My problem with ODBC is not how to make it work, rather how to > prevent > * smart users accessing the database via ODBC. > [clipped] > > OK I'm going to throw my hat into the ring on this one. I see > three > problems each feeding on the next so we eliminate them one at a > time: > > o I need to prevent smart dummies from loading an ODBC driver on > their > PC and accessing the database without authorization. > > Solution: Remove permissions from ALL users and PUBLIC and only > grant > dangerous (your definition) permissions to a single dummy user > (ie a > user with a valid login but no password). > > o BUT users need permissions so they can run apps that access > the > database and modify data! > > Solution: Make all legal apps SUID the dummy user. Only these > apps > will be able to do anything you want to restrict. > > [clipped] > > Art S. Kagel