RE: Informix Warehouse Accelerator Prerequisites
Posted in 2011
Fernando, If you have questions about security, talk to Errol Back-Cunningham. Last I heard he was an IT Specialist out of Philly. (If you knew his CV and history, you'll understand why... ;-) With respect to IWA... 1) I think if you replace 'telnet' with 'ssh', you're going to be fine. 2) Network security: Most IT shops used managed switches which can do layer 2 along with layer 3. Depending on your switch manufacturer, you can see packets. To your comment about becoming root on a machine and then do packet sniffing... why? You've already compromised the box which means you already have access. If you are not setting up a VPN (layer 2) the odds are your IWA and IDS machines will be in the same rack and on the same physical switch. You're right that the most likely vector of attack will not be via the network but by gaining access to your chain of machines starting with the machines connecting to the outside world. (Assuming of course your apps already stop the ability to do SQL injection attacks.) If you follow IBM/Informix's guidelines of using .rhosts or /etc/hosts.equiv, you're already too late. Of course if you set up port filtering on your machines, you have less risk by limiting ssh to the machines only from certain machines inside your firewall. Now if you really want to be paranoid... Assuming you're using the following: a) ToR switch capable of doing Layer 2 b) servers that have at least 2 NIC ports. c) your IWA server doesn't need any outside connection except to your IDS server... Do the following: On your switch, set up a VPN consisting of the two ports and a separate 10.x.x.x network Set up the NIC ports on the machine and do IP port filtering to limit what types of traffic you're going to allow between the two machines. Then it doesn't matter if you allow telnet or not. In order to get to the IWA machine you will need to hack your IDS machine, or hack your ToR switch. Either way its pretty difficult and most likely you're not dealing with data that sensitive that someone outside of the company is going to make the effort. Most likely the admins who know enough about your machines will already have the root password so you're fscked already if they want to steal your information. Again, I agree that telent is bogus, but you should be ok using SSH. HTH -G Date: Fri, 19 Aug 2011 20:06:33 +0100 Subject: Re: Informix Warehouse Accelerator Prerequisites From: domusonline@gmail.com To: red_valsen@yahoo.com CC: informix-list@iiug.org I suppose you can create an encrypted tunnel to overcome this difficulty. Nevertheless I never understand (and please don't get me wrong) what is the real problem on having clear text inside an organization. We all use switches, and AFAIK it creates an exclusive channel between two points. The options I know to overcome this are root access so that you can eavesdrop all the network traffic on your server NICs or some sorts of ARP poisoning that obviously can cause greater problems (and that require proper security measures to prevent it). So, what am I missing? Regards. On Fri, Aug 19, 2011 at 7:46 PM, red_valsen <red_valsen@yahoo.com> wrote: IBM lists on its website (http://publib.boulder.ibm.com/infocenter/ idshelp/v117/index.jsp?topic=%2Fcom.ibm.acc.doc%2Fids_acc_prereqs.htm) the presence of the woefully insecure Unix utility telnet as a prerequisite for use of the Informix Warehouse Accelerator. It's been nearly 10 years since I've worked in an IT environment that would allow telnet since it transmits passwords in clear text. The screaming security hole that telnet use implies becomes a showstopper to even broaching IWA to management -- even for test and evaluation. What in the world is the need for using telnet with IWA? Can a more palatable utility be substituted? _______________________________________________ Informix-list mailing list Informix-list@iiug.org http://www.iiug.org/mailman/listinfo/informix-list -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... _______________________________________________ Informix-list mailing list Informix-list@iiug.org http://www.iiug.org/mailman/listinfo/informix-list