Re: Database security
Posted in 1991
Path: emory!swrinde!cs.utexas.edu!usc!rutgers!pyrnj!pyramid!infmx!seashore!randall From: randall@informix.com (Randall Rhea) Newsgroups: comp.databases.informix Message-ID: <randall.687142279@seashore> Date: 11 Oct 91 00:51:19 GMT References: <503@rand.mel.cocam.oz.au> <13683@sbsvax.cs.uni-sb.de> Sender: news@informix.com (Usenet News) Organization: Informix Software, Inc. becker@ukh840.med-in.uni-sb.de writes: >shaneb@auzodt3.mel.cocam.oz.au (Shane Booth) writes: >> >> Does anyone know a way to allow users to run a 4GL application that inserts >> and deletes from a database, but to disallow the users from altering the data >> by running isql? Here we run Informix-4GL version 4.00.UC1 for Sco Unix. >I asked this question to a representant of INFORMIX at the exposition of the >German Unix User Group. The answer was no. There is no Informix-tool to >decide which front-end is speaking with sqlexec/sqlturbo. Perhaps You can >use the setuid in Your 4gl-program for changing the owner. But this may be >difficult. We do this here, and it is not difficult. Our 4GL applications call a C function that calls setuid(). The user ID is changed to a user that has been GRANTED permission to update, insert, and delete. All other users on the system are GRANTed SELECT permission only. This way, users will not be able to UPDATE the data when they run isql. The 4GL executable must be owned by root, and the UNIX permissions must be set to set the user ID. (e.g. chmod 4755 exec.4ge) -- =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= Randall Rhea Informix Software, Inc. Project Manager, MIS Sales/Marketing Systems uunet!pyramid!infmx!randall