Re: Database security
Posted in 1991
Path: emory!samsung!uunet!boulder!agate!linus!alliant!merk!spdcc!das.harvard.edu!bochner From: bochner@das.harvard.edu (Harry Bochner) Newsgroups: comp.databases.informix Message-ID: <2120@endor.das.harvard.edu.harvard.edu> Date: 10 Oct 91 20:05:03 GMT References: <503@rand.mel.cocam.oz.au> Sender: usenet@das.harvard.edu.harvard.edu Organization: Aiken Computation Lab, Harvard University Nntp-Posting-Host: flare In article <503@rand.mel.cocam.oz.au>, shaneb@auzodt3.mel.cocam.oz.au (Shane Booth) writes: |> Does anyone know a way to allow users to run a 4GL application that inserts |> and deletes from a database, but to disallow the users from altering the data |> by running isql? Here we run Informix-4GL version 4.00.UC1 for Sco Unix. One ugly approach that might sometimes help (if you trust unix security ;-) is to keep these users from running isql by changing the unix file permissions on it. On my system, ls -lg isql reports -rwxr-xr-x 5 informix informix 688128 Dec 3 1990 isql if you did chmod o-rx isql then only users who belong to group informix would be able to run isql; then you just have to put the users who _should_ be able to run it into the informix group. But beware, this also prevents the users who can't run isql from running sperform and sacego, because the latter are just links to isql. I learned this the hard way :-(, and as a result gave up on this scheme; now I just rely on the fact that the relevant users aren't adventurous enough to try running a program other than the ones I write for them ... For completeness, the above holds for version 4.00 under SunOS 4.1; other versions may be different. -- Harry Bochner bochner@das.harvard.edu