Solved

Pass through query encrypt password

Posted on 2008-11-03
6
911 Views
Last Modified: 2012-06-22
I have an application with many pass-through queries with the password saved in the odbc connection.  

How do i prevent the user from being able to see the password.  

thanks

dave
0
Comment
Question by:david_88
  • 3
  • 3
6 Comments
 
LVL 34

Expert Comment

by:jefftwilley
ID: 22868267
Hi dave,
The connection string is kept in the mSysObjects table which is a system table. Just make sure you disable shift keys in your database and hide the mSysObjects table. A savy user may still be able to query the table to see the data. In that case, you can create the connection strings in code when you link the tables and either code in the credentials or mask them in a data table using Access's Password masking feature.
J
0
 

Author Comment

by:david_88
ID: 22868439
sounds good i have found a link to dsable the shift key

how do i hide the msSysobjects table i cant see this table anyaway ?

thanks

dave
0
 
LVL 34

Expert Comment

by:jefftwilley
ID: 22869438
Its a setting option under Tools/Options. Hide System Objects.

Remember, anything stored in a table in access is available via query. So the only real security you can have when it comes to passwords is either to store them in a Password formatted field, or code them.

Access wasn't' built to be bulletproof...so there is some risk in just hiding objects.

If you code the credentials, you can create a mde out of the DB and your users won't be able to get to the code.

Hope this helps.
J
0
Backup Your Microsoft Windows Server®

Backup all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

 

Author Comment

by:david_88
ID: 22874430
well it needs to be relativley secure as it has access to important tables which i dont want people running any query they want on the orders table.

i have 2 apps with about 20 pass-through query's in total what would be the best method to make this secure.  I dont mind either of the 2 options you have mentiond

dave
0
 
LVL 34

Accepted Solution

by:
jefftwilley earned 500 total points
ID: 22878279
When you set up your connection string, you use code correct?

example:

        sConn = "ODBC;"
        sConn = sConn & "DSN=" & rsDatabaseInfo!DSN & ";"
        sConn = sConn & "APP=Microsoft Access;"
        sConn = sConn & "DATABASE=" & rsDatabaseInfo!DBName & ";"
        sConn = sConn & "UID=" & rsDatabaseInfo!UID & ";"
        sConn = sConn & "PWD=" & rsDatabaseInfo!PWD & ";"

Any/all of the fields above can be stored in your table as encrypted data.

When you disable the Shift keys and the Tools Menu when your app opens, a user wouldn't be able to make the System objects visible to modify them. When you create a .mde out of your databases, the user is not able to get to the actual code. That's about as secure as you can get with Access.
J
0
 

Author Closing Comment

by:david_88
ID: 31512747
yeah have gone with this idea as i can see alot of benefits

cheers
dave
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

Introduction When developing Access applications, often we need to know whether an object exists.  This article presents a quick and reliable routine to determine if an object exists without that object being opened. If you wanted to inspect/ite…
Introduction The Visual Basic for Applications (VBA) language is at the heart of every application that you write. It is your key to taking Access beyond the world of wizards into a world where anything is possible. This article introduces you to…
Using Microsoft Access, learn some simple rules for how to construct tables in a relational database. Split up all multi-value fields into single values: Split up fields that belong to other things into separate tables: Make sure that all record…
In Microsoft Access, learn how to use Dlookup and other domain aggregate functions and one method of specifying a string value within a string. Specify the first argument, which is the expression to be returned: Specify the second argument, which …

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now