Problems with permissions in SE
Posted in 1999
Topics: Installation, Setup & Upgrades
Hello! In Installation Guide version 6.0 (Unix products) we can read . "... if you make an actual user on an Informix product a member of group informix, you can cause unintended and uncontrolled database access". We are working with SE 5.10, RDS-4.00. In some programs we use the following sequence: ... whenever error continue drop table "whatever..." whenever error call glo_error create table "whaever ( ... )" ... instead of delete from "whatever..." or using a temp table If user that executes the program does not belong to group "informix" we have an error when you try to create the table, if he belongs to group "informix" we do not have any problem. What kind of "unintended and uncontrolled database access" could we find ?? thanks in advance -- Evelio Martínez Office: +34 96 374-47-02 +34 96 374-47-03 programacionaf@sinix.net
Evelio Martínez wrote: > In Installation Guide version 6.0 (Unix products) we can read. > "... if you make an actual user on an Informix product a member of > group informix, you can cause unintended and uncontrolled database > access". > > We are working with SE 5.10, RDS-4.00. > In some programs we use the following sequence: > ... > whenever error continue > drop table "whatever..." > whenever error call glo_error > create table "whaever ( ... )" > ... > > instead of > > delete from "whatever..." > > or using a temp table > > If user that executes the program does not belong to group > "informix" we have an error when you try to create the table, > if he belongs to group "informix" we do not have any problem. Then I suspect you have not got the software installed properly. This normally indicates that the engine, sqlexec, is not installed with owner root, group informix, permissions 6511 (SUID, SGID, execute for owner, group, others; you can decide to use 6755 and that's probably what $INFORMIXDIR/etc/sefiles says is correct). Alternatively, the permissions on one or more of the directories leading to the database directory is not set correctly. > What kind of "unintended and uncontrolled database access" could > we find ?? cp /dev/null /where/your/database/is/stores.dbs/systables.idx cp /dev/null /where/your/database/is/stores.dbs/bigtabl192.dat Oops - bye, bye database! Or, Mr Snoopy from outside the firewall can copy the data to his own area, then download to his machine, filching all your secrets. Or ... It doesn't have to be malicious, but basically, anybody who is in group informix can access (read or modify or destroy) the data in the database without using the database to make the changes. This is generally regarded as insecure, unintended, uncontrolled and undesirable. -- Jonathan Leffler (jleffler@informix.com, jleffler@earthlink.net) Guardian of DBD::Informix v0.60 -- see http://www.perl.com/CPAN #include <disclaimer.h>
Jonathan Leffler wrote: > > > > We are working with SE 5.10, RDS-4.00. > > In some programs we use the following sequence: > > ... > > whenever error continue > > drop table "whatever..." > > whenever error call glo_error > > create table "whaever ( ... )" > > ... > > > > instead of > > > > delete from "whatever..." > > > > or using a temp table > > > as a consequence of this, I am having -710 error. Is there any way to avoid this error without using the "delete option"? -- Evelio Martínez Office: +34 96 374-47-02 +34 96 374-47-03 programacionaf@sinix.net