Re: Informix Warehouse Accelerator Prerequisites
Posted in 2011
As expectable, this is now completely off-topic. But just a few remarks: - Te requisites mention "telnet", the client. - As someone else already pointed out, this is used by a script to talk to one "listener" inside IWA - Whn I mentioned root for packet sniffing, my idea was that since you don't see other machine's packets, you can only see yours. And even for that you'd need root. And yes, if you're already root than you have other things to worry about - You talke about "external machines", but it obvious that if you're concern about security, you know it starts "inside your home" - Not sure about what "guidelines" you're talking about when you mention .rhosts and /etc/hosts.equiv. But this is another usual/useless discussion (which me and you already had). When I ask i is this insecure, people answer me "because of the r* services". When I ask why do you have r* services running, people don't answer. The only new factor in this old discussion is that since 11.70.FC2 you can use your own "hosts.equiv". But I wouldn't expect you to know this. Regards. On Sun, Aug 21, 2011 at 4:00 PM, Ian Michael Gumby <im_gumby@hotmail.com>wrote: > Fernando, > > If you have questions about security, talk to Errol Back-Cunningham. Last I > heard he was an IT Specialist out of Philly. > (If you knew his CV and history, you'll understand why... ;-) > > With respect to IWA... > > 1) I think if you replace 'telnet' with 'ssh', you're going to be fine. > 2) Network security: > Most IT shops used managed switches which can do layer 2 along with layer > 3. Depending on your switch manufacturer, you can see packets. > To your comment about becoming root on a machine and then do packet > sniffing... why? You've already compromised the box which means you already > have access. > If you are not setting up a VPN (layer 2) the odds are your IWA and IDS > machines will be in the same rack and on the same physical switch. You're > right that the most likely vector of attack will not be via the network but > by gaining access to your chain of machines starting with the machines > connecting to the outside world. (Assuming of course your apps already stop > the ability to do SQL injection attacks.) If you follow IBM/Informix's > guidelines of using .rhosts or /etc/hosts.equiv, you're already too late. Of > course if you set up port filtering on your machines, you have less risk by > limiting ssh to the machines only from certain machines inside your > firewall. > > Now if you really want to be paranoid... > > Assuming you're using the following: > a) ToR switch capable of doing Layer 2 > b) servers that have at least 2 NIC ports. > c) your IWA server doesn't need any outside connection except to your IDS > server... > > Do the following: > On your switch, set up a VPN consisting of the two ports and a separate > 10.x.x.x network > Set up the NIC ports on the machine and do IP port filtering to limit what > types of traffic you're going to allow between the two machines. > > Then it doesn't matter if you allow telnet or not. > In order to get to the IWA machine you will need to hack your IDS machine, > or hack your ToR switch. Either way its pretty difficult and most likely > you're not dealing with data that sensitive that someone outside of the > company is going to make the effort. Most likely the admins who know enough > about your machines will already have the root password so you're fscked > already if they want to steal your information. > > Again, I agree that telent is bogus, but you should be ok using SSH. > > HTH > > -G > > > ------------------------------ > Date: Fri, 19 Aug 2011 20:06:33 +0100 > Subject: Re: Informix Warehouse Accelerator Prerequisites > From: domusonline@gmail.com > To: red_valsen@yahoo.com > CC: informix-list@iiug.org > > > I suppose you can create an encrypted tunnel to overcome this difficulty. > Nevertheless I never understand (and please don't get me wrong) what is the > real problem on having clear text inside an organization. > We all use switches, and AFAIK it creates an exclusive channel between two > points. The options I know to overcome this are root access so that you can > eavesdrop all the network traffic on your server NICs or some sorts of ARP > poisoning that obviously can cause greater problems (and that require proper > security measures to prevent it). > > So, what am I missing? > Regards. > > > On Fri, Aug 19, 2011 at 7:46 PM, red_valsen <red_valsen@yahoo.com> wrote: > > IBM lists on its website (http://publib.boulder.ibm.com/infocenter/ > idshelp/v117/index.jsp?topic=%2Fcom.ibm.acc.doc%2Fids_acc_prereqs.htm<http://publib.boulder.ibm.com/infocenter/%0Aidshelp/v117/index.jsp?topic=/com.ibm.acc.doc/ids_acc_prereqs.htm> > ) > the presence of the woefully insecure Unix utility telnet as a > prerequisite for use of the Informix Warehouse Accelerator. It's been > nearly 10 years since I've worked in an IT environment that would > allow telnet since it transmits passwords in clear text. The > screaming security hole that telnet use implies becomes a showstopper > to even broaching IWA to management -- even for test and evaluation. > What in the world is the need for using telnet with IWA? Can a more > palatable utility be substituted? > _______________________________________________ > Informix-list mailing list > Informix-list@iiug.org > http://www.iiug.org/mailman/listinfo/informix-list > > > > > -- > Fernando Nunes > Portugal > > http://informix-technology.blogspot.com > My email works... but I don't check it frequently... > > _______________________________________________ Informix-list mailing list > Informix-list@iiug.org http://www.iiug.org/mailman/listinfo/informix-list > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...