Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Firebird server vulnerability ?

Posted on 2013-12-13
6
Medium Priority
?
398 Views
Last Modified: 2013-12-24
I have at home a Firebird server installed on my PC
It is accessible from the internet.
I developped a simple application for friends.
I didn't change the default admin and password account of the DB that can be accessed.
Is there some vulnerability involved ?
I mean, if somebody connects to it with for example SQL Manager Lite, can he do something else than "play" with the data inside that database ?
0
Comment
Question by:LeTay
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
6 Comments
 
LVL 43

Expert Comment

by:pcelba
ID: 39717519
If wiping the database is just a game then why do you care about the rest of computer? :-)

OK, possible computer data damage depends on the user under which is Firebird running on the server (your computer). If the PC user has sufficient rights and the person attacking the computer is experienced enough then your computer is not safe. Firebird supports external UDFs which can do almost anything...

OTOH, are your friends experienced enough in computer hacking? Probably not. Do you know their friends? Probably not... etc.

So assign the Firebird to a dedicated user which can access just the Firebird data and the rest of computer is moreless safe.
0
 

Author Comment

by:LeTay
ID: 39717700
Understood.
Now how do I dedicate a specific user to access it ?
0
 
LVL 43

Expert Comment

by:pcelba
ID: 39717775
Simply create a new user in your Windows (Control Panel - User Accounts) and assign this user to the Firebird service. This user must not be an administrator and it must have full access to the data folder and all parts of your system used by Firebird. More about installation and security is here: http://www.firebirdsql.org/manual/qsg2-config.html

Also your friends should use newly created Firebird user names and their own passwords not the SYSDBA with masterkey.
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 
LVL 19

Accepted Solution

by:
NickUpson earned 2000 total points
ID: 39717979
and change the password on the default account, sysdba can do anything with a database including remove all data & tables
0
 

Author Comment

by:LeTay
ID: 39718853
Can you refresh my mind about the way to setup an account and password in a firebird database ?
Thanks
0
 
LVL 19

Assisted Solution

by:NickUpson
NickUpson earned 2000 total points
ID: 39719005
you can use a 3rd party tool or the gsec command line that comes with the install

"gsec -- "will tell you all the options
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
Recently I was talking with Tim Sharp, one of my colleagues from our Technical Account Manager team about MongoDB’s scalability. While doing some quick training with some of the Percona team, Tim brought something to my attention...
Video by: Steve
Using examples as well as descriptions, step through each of the common simple join types, explaining differences in syntax, differences in expected outputs and showing how the queries run along with the actual outputs based upon a simple set of dem…
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question