Re: Restricting ISQL access to Administrators only
Posted in 1996
The 'obvious' way to do this is to move the real isql executable into a directory with permissions which prevent ordinary users from accessing it -- maybe create a directory /usr/informix/secure with owner informix, group set to some new group (eg secure), and directory permissions 750. Move the distributed ISQL program into that directory. Create a C program and use it as /usr/informix/bin/isql; it is installed with SGID 'secure' permissions set. It should check the real UID of the person running the program, and will execute /usr/informix/secure/isql if the user is entitled to run it, and will object if they are not. This solves the immediate problem -- there are some implementation issues to be resolved (like does the program pay any attention to $INFORMIXDIR, which it shouldn't if it is to be secure), and so on. The residual issue is 'what other ways are there to gain uncontrolled access to the database', and the answer is many. At least you have to worry about DB-Access too, though the same trick can be used for that. Do you have ESQL/C on the system. You can do an awful lot of damage with a trivial ESQL/C program which simply uses 'EXEC SQL CREATE PROCEDURE FROM "file";' because that file does not have to contain a create procedure statement. Unless you can also shut up all (most of?) the back doors, your security is more virtual than real. Yours, Jonathan Leffler (johnl@informix.com) #include <disclaimer.h> >From: DMurray370@aol.com >Date: Wed, 19 Jun 1996 18:49:09 -0400 >X-Informix-List-Id: <list.10379> > >I'd like to be able to restrict ISQL INFORMIX 7.12 access to SYSADMINs only. >All the users currently have UPDATE rights on most of the database tables, so >if they find their way into ISQL they can do alot of damage. I'd like to set >something up in their shell profiles that will "take away" the ISQL command. >We're currently running the HPUX9.? Unix version. I believe I might be able >to reassign the ISQL command to executing something else, but I'm not quite >sure how to do it. > >Any help would be greatly appreciated? > >Thanks, >David Murray