Solved

How to insert decoded password into command line?

Posted on 2012-03-29
9
1,384 Views
Last Modified: 2012-05-27
Hi.

Is a Windows Server OS 2003/2008.
The problem - a shell scripts (*.BAT/*.CMD files) sometimes contains a string like this:

db2 connect MyDbName user MyDbUsername using MyDbPassword

Open in new window


We need to hide any such "security-sensitive" information from scripts.
Is not allowed to store password in a clear-text in scripts.

Please note: we already have a TXMON.INI file which contains encrypted password. And I can program a simple tool which can decode that password but...

... the question is - how exactly to feed the "DB2 connect ..." command line with a decrypted password?

On UNIX/Linix I know - there is an ability to substitute a part of command line with StdOut from some application (using apostrophe char). So, on Linux it could sounds like this (this example command is not related to db2, is just to show an approach - instead of command enclosed in `` Linux shell inserts StdOut of a command inside a ``):

tar cvf - `find ./ -name ?akefile 2>/dev/null` | gzip -9c > backup.tar.gz

Open in new window


But I do not know - how to do it on Windows? Is it possible at all?
If yes - how exactly? If not - what other options we may have to solve this?

Note: is not ok to use PowerShell. Is only ok to use standard Windows CMD. Or even better to say - is only ok to use DB2CMD (which is a kind of wrapper over Windows CMD).

Note: is not ok to enforce user to enter password anytime script is running. Because in most cases scripts should run automatically without human assistance.

Note: is not ok to use ""db2 connect ..." command without credentials(!). Because a logged user credentials are not always match a correct database account. But however scripts should still works fine in such cases.

Regards,
Dmitry.
0
Comment
Question by:Dmitry_Bond
  • 5
  • 2
  • 2
9 Comments
 
LVL 6

Expert Comment

by:Tomislavj
ID: 37781307
try with this tool to encode batch file
0
 

Author Comment

by:Dmitry_Bond
ID: 37782104
I have looked on CPAU tool. Do not like it. It is not convenient for me.

Imagine - what would happen if customer will change password?! It would means that we have to re-encode all the jobs with CPAU tool. That is bad scenario for us.

I would prefer to read & decode password from existing INI file rather than encoding/encrypting lot of jobs with CPAU tool. Read&decode - I can do this with my tool (is just a couple of API calls) but question - how to submit password from a running program into a command line of "DB2 connect ..."?

Another problem with CPAU - it seems does not work. I can create a job file but it fail on job execution. So, I typed commands (as described in CPAU examples):

cpau -u DOMX\myusername -p myDomainPassword -ex "ConnectDb.bat" -enc -file connect.job

cpau -dec -file connect.job -lwp

Open in new window


1st command works fine, 2nd command always do not work. :-\

So, tool is not suitable and is not working.

Please suggest other options.
0
 
LVL 27

Expert Comment

by:tliotta
ID: 37783745
Simple answer "Don't use scripts. Compile a program."

If plain-text scripts are a problem, then they simply should not be used.

Tom
0
Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

 
LVL 6

Expert Comment

by:Tomislavj
ID: 37784277
When you call a batch file, you can enter parameters after the command that the batch file refers to as %1, %2, etc.

For example, in the batch file hi.bat, you have following code

@echo Hi %1 and welcome!

Open in new window


if you called it as

hi Tom

Open in new window


you will get

Hi Tom and welcome!

Open in new window


so, maybe you can make program to decrypt password and call db.bat with password as parameter

then, in db.bat there will be

db2 connect MyDbName user MyDbUsername using %1

Open in new window

0
 

Author Comment

by:Dmitry_Bond
ID: 37785761
1) The "do not use scripts" is bad option for us. We need it exactly in a form of scripts.
 
2)
... so, maybe you can make program to decrypt password and call db.bat with password as parameter ...

Show the script code please. I want to look on it.

The big problem with your answer is that you did not answered my question - HOW EXACTLY TO RETURN SOMETHING FROM EXE TO USE IN BAT FILE?

I had posted an example from Linux shell script which is showing an approach. I want something similar in Windows.
0
 
LVL 27

Expert Comment

by:tliotta
ID: 37789455
The problem is that a script can be modified at any time to ECHO a decoded password parameter or any other sensitive information. Unless the script itself is protected from every user that can be a risk, there will not be anything that is hidden.

As long as it is understood that nothing is protected in the script, then a script is fine.

Tom
0
 

Author Comment

by:Dmitry_Bond
ID: 37794863
Ya... but script is the easiest (and cheapest) way to do maintenance.
If not use a script then we have to invest a lot of resources into development of special maintenance application. We could not do it now...

Personnel on site is not so experienced to do ECHO for a password. Also, script file itself could be protected by security settings to disable write access to it. So, in this particular case is ok to still use a script in some places. Only need to hide a clear-text password somehow.
0
 

Accepted Solution

by:
Dmitry_Bond earned 0 total points
ID: 38001146
Finally I did solved it in a following way:

@echo off

set SW_DbName=$(DbName)
set SW_DbUser=$(DbUser)
set SW_DbPwd=$(DbPasswEncrypted)
set SW_DbPwdId=%TIME:~-2%
rundll32 %~dp0\..\Maintain\InstUtil.dll,SecTxt_DecodePwd
call "%temp%\SWPw%SW_DbPwdId%.bat"
del /f /q "%temp%\SWPw%SW_DbPwdId%.bat"

db2 connect to %SW_DbName% user %SW_DbUser% using %SW_DbPwd%

echo Connected at %DATE%, %TIME%
set SW_DbPwd=

Open in new window


Write-access to script is denied by installer. Also it script itself is not in a "public" directory. So, I assume that should be enough for my case.

Note: the $(...) parameters are replaced by installed with actual values.
Here is example of encoded password: 2!cf1a8b63~MGBsqB7yZgvagDPpnfMq6Xh/RLP4ASyQx7LZdkdedxV+aRbWoZsA+Rsf7b0qt30rURz/v9fPXuW6jCPRkVJ3EB.
So, it has CRC-value and some random data.
The InstUtil.dll is a my dll with password decoding function.
0
 

Author Closing Comment

by:Dmitry_Bond
ID: 38016257
Solution is not perfect but is match our needs and conditions.
Also match standard Windows functionality.
0

Featured Post

Networking for the Cloud Era

Join Microsoft and Riverbed for a discussion and demonstration of enhancements to SteelConnect:
-One-click orchestration and cloud connectivity in Azure environments
-Tight integration of SD-WAN and WAN optimization capabilities
-Scalability and resiliency equal to a data center

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
dbcc checkdb datawarehouse 2 61
Exchange 2016 Databse move 5 65
Need a starter for ETL protocol? 4 65
free version of MSSQL for over 10GB DB 19 69
This article describes some very basic things about SQL Server filegroups.
Many companies are looking to get out of the datacenter business and to services like Microsoft Azure to provide Infrastructure as a Service (IaaS) solutions for legacy client server workloads, rather than continuing to make capital investments in h…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
Video by: Steve
Using examples as well as descriptions, step through each of the common simple join types, explaining differences in syntax, differences in expected outputs and showing how the queries run along with the actual outputs based upon a simple set of dem…

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question