Security Hole in Informix
Posted in 2000
Topics: Triggers, Constraints & Referential Integrity, Versions, Editions & End-of-Life
Currently I am implementing internet system on the IDS 7.3 for Linux. I have found strange security hole in the IDS. User with the only connect privilege has the ability to generate database schema, view database structure etc.. Is there any way to prevent users from doing that ? It looks really weird if user can view tables security info, triggers and procedures. I would really appreciate help. Sincerely, Ben Zbigniew Bebas zbebas@esklep.com
I do not understand. How do you expect users to actually use the database if they cannot inquire as to the database structure etc? Art S. Kagel Zbigniew Ben Bebas wrote: > > Currently I am implementing internet system on the IDS 7.3 for Linux. > I have found strange security hole in the IDS. > User with the only connect privilege has the ability to > generate database schema, view database structure etc.. > Is there any way to prevent users from doing that ? > It looks really weird if user can view tables > security info, triggers and procedures. > > I would really appreciate help. > > Sincerely, > > Ben Zbigniew Bebas > > zbebas@esklep.com
I think that the problem may be the permissions set (or not set) on the tables. My guess from the brief description of the problem is that the user can connect somehow (via ODBC?) and see all of the database tables? The tables are most likely open to public for select, insert, update and delete. So if a user is granted connect privileges the client tool (?) can see the tables and schema? This is a guess at what might be happening...... (been there done that) Some more details about the environment would be helpful. Zbigniew Ben Bebas <zbebas@esklep.com> wrote in message news:39643382.7E40F51D@esklep.com... > Currently I am implementing internet system on the IDS 7.3 for Linux. > I have found strange security hole in the IDS. > User with the only connect privilege has the ability to > generate database schema, view database structure etc.. > Is there any way to prevent users from doing that ? > It looks really weird if user can view tables > security info, triggers and procedures. > > I would really appreciate help. > > Sincerely, > > Ben Zbigniew Bebas > > zbebas@esklep.com > >
due to Codds 13 rules the database info must be kept in database tables, those database must be readable by anyone with select permissions (OK maybe not MUST but in Informix they must) in order to access the underlying structure of the database and therefore the database itself. There is no mechanism to protect the "source code" for the DDL. Mike South The BEST in adult Video www.mikesouth.com