Re: Auditor fun
Posted in 2007
malc_p@btinternet.com wrote:
> We had the Auditors round today, usual stuff, how do we control
> database access, password expiry policy etc etc (set bullshit
> generator to 'Stun'), but he also showed me this article by some bloke
> called David Litchfiled from a chapter in the "Database Hackers
> Handbook" called "Informix - discovery, attack and defense".
> Anyway, apart from the obvious bits about stack overflow exploits and
> how easy it is to breach a windows box (old news is no news....) and
> some stuff about parsing shmem dumps to get user passwords out (I
> don't think so), it has the following gem
> <quote>
> If you can connect to the server then you can issue the
> CREATE DATABASE command - regardless of your privileges; what's more,> the database is created and you are given DBA privileges on it. Once
> you're
> DBA on a database you own the whole server. Whilst this doesn't seem
> to be public knowledge yet, IBM have known about it for a while and
> there is an undocumented
> workaround available to prevent this. See the section on securing
> Informix for more details. At this stage it seems like "game over" but
> on the off
> chance that someone has protected their server using the workaround,
> let's examine
> other ways to gain control of the server.
> </quote>
> What utter crap - create a database and suddenly you're God on the
> server - errmm hello, error 388 "No Resource Permission" on any other
> db on the server (unless you have resource permission granted by the
> DBA!). Where did he get this rubbish? And who is David Litchfield?
> Reads like disinformation to me........
>
That was a very well know issue... Informix (before IBM) introduced the
mentioned parameter in 9.30. You can easily find references to this at least in
2004. Bugtraq and securifyfocus announced it in 2006...
It was a serious flaw since you could consume space and create load problems
within an instance but you could not gain privilege access to other databases
AFAIK.
Besides the obvious design flaw what we can blame Informix/IBM was not to
document it properly as soon as it created the fix...
I personally hate this kind of undocumented features, although I understand
some of them may need some field testing before broad use...
Regards.
---------------------------------------
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...