use of connect statement
Posted in 2012
User on Informix 11.5 FC8W2 sought ways to prevent CONNECT statements from switching database users in dbaccess despite menu restrictions. Suggested solutions included enforcing unique passwords (long-term) and using sysdbopen() procedures (11.10+) with dbinfo('sessionid') to validate sessions by host origin. STSN auditing was also recommended for tracking session starts.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Server Administration, Versions, Editions & End-of-Life
Version 11.5 FC8W2 on Linux
Does anyone know of a way to prevent a user from using the CONNECT statement
to connect to the database as another user?
The users are connecting using dbaccess. I've limited the menu options on
dbaccess so they can't use that to change users, but they've figured out a
way around that.
Thanks
Make the 'other users' change their passwords and not share them! Change
or eliminate any "shared" user ids that have access to the database and
replace them with private ones.
Art
Art S. Kagel
Advanced DataTools (www.advancedatatools.com)
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions
and do not reflect on my employer, Advanced DataTools, the IIUG, nor any
other organization with which I am associated either explicitly,
implicitly, or by inference. Neither do those opinions reflect those of
other individuals affiliated with any entity with which I am affiliated nor
those of the entities themselves.
On Thu, May 31, 2012 at 12:05 PM, Jamie Gedye <jgedyedba@teleformix.com>wrote:
> Version 11.5 FC8W2 on Linux
>
> Does anyone know of a way to prevent a user from using the CONNECT
> statement
> to connect to the database as another user?
>
> The users are connecting using dbaccess. I've limited the menu options on
> dbaccess so they can't use that to change users, but they've figured out a
> way around that.
>
> Thanks
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--14dae9340cadebec7104c15778e0
Thanks Art. That's a long term solution that's being worked on. Right now
the problem is our connections come from JDBC strings that have the
passwords included in it. We're working on a plan to change that, but I was
hoping for something in the short term.
We do run auditing but there doesn't seem to be an audit on a "connect",
just the dbopen and close.
Is there an easy way to get the current session id once connected? If so, I
could be something in the sysdbopen procedure to check what host the session
is coming from and disconnect if necessary.
-----Original Message-----
From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Art
Kagel
Sent: Thursday, May 31, 2012 11:22 AM
To: ids@iiug.org
Subject: Re: use of connect statement [27270]
Make the 'other users' change their passwords and not share them! Change or
eliminate any "shared" user ids that have access to the database and replace
them with private ones.
Art
Art S. Kagel
Advanced DataTools (www.advancedatatools.com)
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions and
do not reflect on my employer, Advanced DataTools, the IIUG, nor any other
organization with which I am associated either explicitly, implicitly, or by
inference. Neither do those opinions reflect those of other individuals
affiliated with any entity with which I am affiliated nor those of the
entities themselves.
On Thu, May 31, 2012 at 12:05 PM, Jamie Gedye
<jgedyedba@teleformix.com>wrote:
> Version 11.5 FC8W2 on Linux
>
> Does anyone know of a way to prevent a user from using the CONNECT
> statement to connect to the database as another user?
>
> The users are connecting using dbaccess. I've limited the menu options
> on dbaccess so they can't use that to change users, but they've
> figured out a way around that.
>
> Thanks
>
>
>
>
****************************************************************************
***
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--14dae9340cadebec7104c15778e0
****************************************************************************
***
Forum Note: Use "Reply" to post a response in the discussion forum.
Hmmm... in terms of auditing, you could look into STSN (STart SessioN)
And you can use the sysdbopen() procedure to make some validations,
provided that you're using 11.10+
Regards.
On Thu, May 31, 2012 at 5:32 PM, Jamie Gedye <jgedyedba@teleformix.com>wrote:
> Thanks Art. That's a long term solution that's being worked on. Right now
> the problem is our connections come from JDBC strings that have the
> passwords included in it. We're working on a plan to change that, but I was
> hoping for something in the short term.
>
> We do run auditing but there doesn't seem to be an audit on a "connect",
> just the dbopen and close.
>
> Is there an easy way to get the current session id once connected? If so, I
> could be something in the sysdbopen procedure to check what host the
> session
> is coming from and disconnect if necessary.
>
> -----Original Message-----
> From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Art
> Kagel
> Sent: Thursday, May 31, 2012 11:22 AM
> To: ids@iiug.org
> Subject: Re: use of connect statement [27270]
>
> Make the 'other users' change their passwords and not share them! Change or
> eliminate any "shared" user ids that have access to the database and
> replace
> them with private ones.
>
> Art
>
> Art S. Kagel
> Advanced DataTools (www.advancedatatools.com)
> Blog: http://informix-myview.blogspot.com/
>
> Disclaimer: Please keep in mind that my own opinions are my own opinions
> and
> do not reflect on my employer, Advanced DataTools, the IIUG, nor any other
> organization with which I am associated either explicitly, implicitly, or
> by
> inference. Neither do those opinions reflect those of other individuals
> affiliated with any entity with which I am affiliated nor those of the
> entities themselves.
>
> On Thu, May 31, 2012 at 12:05 PM, Jamie Gedye
> <jgedyedba@teleformix.com>wrote:
>
> > Version 11.5 FC8W2 on Linux
> >
> > Does anyone know of a way to prevent a user from using the CONNECT
> > statement to connect to the database as another user?
> >
> > The users are connecting using dbaccess. I've limited the menu options
> > on dbaccess so they can't use that to change users, but they've
> > figured out a way around that.
> >
> > Thanks
> >
> >
> >
> >
>
> ****************************************************************************
> ***
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
> >
>
> --14dae9340cadebec7104c15778e0
>
>
> ****************************************************************************
> ***
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--00248c6a6736a10efa04c157c3ba
dbinfo('sessionid'):
> select dbinfo('sessionid') from sysmaster:sysdual;
(expression)
1233
1 row(s) retrieved.
Art
Art S. Kagel
Advanced DataTools (www.advancedatatools.com)
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions
and do not reflect on my employer, Advanced DataTools, the IIUG, nor any
other organization with which I am associated either explicitly,
implicitly, or by inference. Neither do those opinions reflect those of
other individuals affiliated with any entity with which I am affiliated nor
those of the entities themselves.
On Thu, May 31, 2012 at 12:32 PM, Jamie Gedye <jgedyedba@teleformix.com>wrote:
> Thanks Art. That's a long term solution that's being worked on. Right now
> the problem is our connections come from JDBC strings that have the
> passwords included in it. We're working on a plan to change that, but I was
> hoping for something in the short term.
>
> We do run auditing but there doesn't seem to be an audit on a "connect",
> just the dbopen and close.
>
> Is there an easy way to get the current session id once connected? If so, I
> could be something in the sysdbopen procedure to check what host the
> session
> is coming from and disconnect if necessary.
>
> -----Original Message-----
> From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Art
> Kagel
> Sent: Thursday, May 31, 2012 11:22 AM
> To: ids@iiug.org
> Subject: Re: use of connect statement [27270]
>
> Make the 'other users' change their passwords and not share them! Change or
> eliminate any "shared" user ids that have access to the database and
> replace
> them with private ones.
>
> Art
>
> Art S. Kagel
> Advanced DataTools (www.advancedatatools.com)
> Blog: http://informix-myview.blogspot.com/
>
> Disclaimer: Please keep in mind that my own opinions are my own opinions
> and
> do not reflect on my employer, Advanced DataTools, the IIUG, nor any other
> organization with which I am associated either explicitly, implicitly, or
> by
> inference. Neither do those opinions reflect those of other individuals
> affiliated with any entity with which I am affiliated nor those of the
> entities themselves.
>
> On Thu, May 31, 2012 at 12:05 PM, Jamie Gedye
> <jgedyedba@teleformix.com>wrote:
>
> > Version 11.5 FC8W2 on Linux
> >
> > Does anyone know of a way to prevent a user from using the CONNECT
> > statement to connect to the database as another user?
> >
> > The users are connecting using dbaccess. I've limited the menu options
> > on dbaccess so they can't use that to change users, but they've
> > figured out a way around that.
> >
> > Thanks
> >
> >
> >
> >
>
> ****************************************************************************
> ***
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
> >
>
> --14dae9340cadebec7104c15778e0
>
>
> ****************************************************************************
> ***
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--14dae9340cad9d6fad04c15935c0
Thanks Art. That's exactly what I need!
-----Original Message-----
From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Art
Kagel
Sent: Thursday, May 31, 2012 1:27 PM
To: ids@iiug.org
Subject: Re: use of connect statement [27273]
dbinfo('sessionid'):
> select dbinfo('sessionid') from sysmaster:sysdual;
(expression)
1233
1 row(s) retrieved.
Art
Art S. Kagel
Advanced DataTools (www.advancedatatools.com)
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions and
do not reflect on my employer, Advanced DataTools, the IIUG, nor any other
organization with which I am associated either explicitly, implicitly, or by
inference. Neither do those opinions reflect those of other individuals
affiliated with any entity with which I am affiliated nor those of the
entities themselves.
On Thu, May 31, 2012 at 12:32 PM, Jamie Gedye
<jgedyedba@teleformix.com>wrote:
> Thanks Art. That's a long term solution that's being worked on. Right
> now the problem is our connections come from JDBC strings that have
> the passwords included in it. We're working on a plan to change that,
> but I was hoping for something in the short term.
>
> We do run auditing but there doesn't seem to be an audit on a
> "connect", just the dbopen and close.
>
> Is there an easy way to get the current session id once connected? If
> so, I could be something in the sysdbopen procedure to check what host
> the session is coming from and disconnect if necessary.
>
> -----Original Message-----
> From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of
> Art Kagel
> Sent: Thursday, May 31, 2012 11:22 AM
> To: ids@iiug.org
> Subject: Re: use of connect statement [27270]
>
> Make the 'other users' change their passwords and not share them!
> Change or eliminate any "shared" user ids that have access to the
> database and replace them with private ones.
>
> Art
>
> Art S. Kagel
> Advanced DataTools (www.advancedatatools.com)
> Blog: http://informix-myview.blogspot.com/
>
> Disclaimer: Please keep in mind that my own opinions are my own
> opinions and do not reflect on my employer, Advanced DataTools, the
> IIUG, nor any other organization with which I am associated either
> explicitly, implicitly, or by inference. Neither do those opinions
> reflect those of other individuals affiliated with any entity with
> which I am affiliated nor those of the entities themselves.
>
> On Thu, May 31, 2012 at 12:05 PM, Jamie Gedye
> <jgedyedba@teleformix.com>wrote:
>
> > Version 11.5 FC8W2 on Linux
> >
> > Does anyone know of a way to prevent a user from using the CONNECT
> > statement to connect to the database as another user?
> >
> > The users are connecting using dbaccess. I've limited the menu
> > options on dbaccess so they can't use that to change users, but
> > they've figured out a way around that.
> >
> > Thanks
> >
> >
> >
> >
>
> **********************************************************************
> ******
> ***
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
> >
>
> --14dae9340cadebec7104c15778e0
>
>
> **********************************************************************
> ******
> ***
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
>
>
****************************************************************************
***
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--14dae9340cad9d6fad04c15935c0
****************************************************************************
***
Forum Note: Use "Reply" to post a response in the discussion forum.