Solved

Pass through query encrypt password

Posted on 2008-11-03
6
918 Views
Last Modified: 2012-06-22
I have an application with many pass-through queries with the password saved in the odbc connection.  

How do i prevent the user from being able to see the password.  

thanks

dave
0
Comment
Question by:david_88
  • 3
  • 3
6 Comments
 
LVL 34

Expert Comment

by:jefftwilley
ID: 22868267
Hi dave,
The connection string is kept in the mSysObjects table which is a system table. Just make sure you disable shift keys in your database and hide the mSysObjects table. A savy user may still be able to query the table to see the data. In that case, you can create the connection strings in code when you link the tables and either code in the credentials or mask them in a data table using Access's Password masking feature.
J
0
 

Author Comment

by:david_88
ID: 22868439
sounds good i have found a link to dsable the shift key

how do i hide the msSysobjects table i cant see this table anyaway ?

thanks

dave
0
 
LVL 34

Expert Comment

by:jefftwilley
ID: 22869438
Its a setting option under Tools/Options. Hide System Objects.

Remember, anything stored in a table in access is available via query. So the only real security you can have when it comes to passwords is either to store them in a Password formatted field, or code them.

Access wasn't' built to be bulletproof...so there is some risk in just hiding objects.

If you code the credentials, you can create a mde out of the DB and your users won't be able to get to the code.

Hope this helps.
J
0
U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

 

Author Comment

by:david_88
ID: 22874430
well it needs to be relativley secure as it has access to important tables which i dont want people running any query they want on the orders table.

i have 2 apps with about 20 pass-through query's in total what would be the best method to make this secure.  I dont mind either of the 2 options you have mentiond

dave
0
 
LVL 34

Accepted Solution

by:
jefftwilley earned 500 total points
ID: 22878279
When you set up your connection string, you use code correct?

example:

        sConn = "ODBC;"
        sConn = sConn & "DSN=" & rsDatabaseInfo!DSN & ";"
        sConn = sConn & "APP=Microsoft Access;"
        sConn = sConn & "DATABASE=" & rsDatabaseInfo!DBName & ";"
        sConn = sConn & "UID=" & rsDatabaseInfo!UID & ";"
        sConn = sConn & "PWD=" & rsDatabaseInfo!PWD & ";"

Any/all of the fields above can be stored in your table as encrypted data.

When you disable the Shift keys and the Tools Menu when your app opens, a user wouldn't be able to make the System objects visible to modify them. When you create a .mde out of your databases, the user is not able to get to the actual code. That's about as secure as you can get with Access.
J
0
 

Author Closing Comment

by:david_88
ID: 31512747
yeah have gone with this idea as i can see alot of benefits

cheers
dave
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Most if not all databases provide tools to filter data; even simple mail-merge programs might offer basic filtering capabilities. This is so important that, although Access has many built-in features to help the user in this task, developers often n…
I originally created this report in Crystal Reports 2008 where there is an option to underlay sections. I initially came across the problem in Access Reports where I was unable to run my border lines down through the entire page as I was using the P…
Familiarize people with the process of retrieving data from SQL Server using an Access pass-thru query. Microsoft Access is a very powerful client/server development tool. One of the ways that you can retrieve data from a SQL Server is by using a pa…
In Microsoft Access, learn how to use Dlookup and other domain aggregate functions and one method of specifying a string value within a string. Specify the first argument, which is the expression to be returned: Specify the second argument, which …

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

25 Experts available now in Live!

Get 1:1 Help Now