Re: Relation of OS user to Informix database user
Posted in 2005
Colin Dawson — — source: Usenet: comp.databases.informix
Just to add to the discussion
<SNIP>
>
> > It however allowed me to do a
> > GRANT SELECT ON TABLE T TO B.>
>Possibly - but did it actually add anything to the systabauth table? If
>you read the GRANT manual pages carefully, there appears to be a
>loophole such that a GRANT statement might execute 'OK' without granting
>the permissions.
<SNIP>
Is this a loophole or a security measure? I had been led to believe it works
this way deliberately.
By telling a user(hacker) that his command has failed is giving him
information/knowledge about your systems you may not want
Regards
Colin
There are 10 types of people in the world, those that understand binary and
those that don't
sending to informix-list