Solved

Firebird server vulnerability ?

Posted on 2013-12-13
6
385 Views
Last Modified: 2013-12-24
I have at home a Firebird server installed on my PC
It is accessible from the internet.
I developped a simple application for friends.
I didn't change the default admin and password account of the DB that can be accessed.
Is there some vulnerability involved ?
I mean, if somebody connects to it with for example SQL Manager Lite, can he do something else than "play" with the data inside that database ?
0
Comment
Question by:LeTay
  • 2
  • 2
  • 2
6 Comments
 
LVL 41

Expert Comment

by:pcelba
Comment Utility
If wiping the database is just a game then why do you care about the rest of computer? :-)

OK, possible computer data damage depends on the user under which is Firebird running on the server (your computer). If the PC user has sufficient rights and the person attacking the computer is experienced enough then your computer is not safe. Firebird supports external UDFs which can do almost anything...

OTOH, are your friends experienced enough in computer hacking? Probably not. Do you know their friends? Probably not... etc.

So assign the Firebird to a dedicated user which can access just the Firebird data and the rest of computer is moreless safe.
0
 

Author Comment

by:LeTay
Comment Utility
Understood.
Now how do I dedicate a specific user to access it ?
0
 
LVL 41

Expert Comment

by:pcelba
Comment Utility
Simply create a new user in your Windows (Control Panel - User Accounts) and assign this user to the Firebird service. This user must not be an administrator and it must have full access to the data folder and all parts of your system used by Firebird. More about installation and security is here: http://www.firebirdsql.org/manual/qsg2-config.html

Also your friends should use newly created Firebird user names and their own passwords not the SYSDBA with masterkey.
0
Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

 
LVL 19

Accepted Solution

by:
NickUpson earned 500 total points
Comment Utility
and change the password on the default account, sysdba can do anything with a database including remove all data & tables
0
 

Author Comment

by:LeTay
Comment Utility
Can you refresh my mind about the way to setup an account and password in a firebird database ?
Thanks
0
 
LVL 19

Assisted Solution

by:NickUpson
NickUpson earned 500 total points
Comment Utility
you can use a 3rd party tool or the gsec command line that comes with the install

"gsec -- "will tell you all the options
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

Introduction: I have seen many questions on EE and elsewhere, asking about how to find either gaps in lists of numbers (id field, usually) ranges of values or dates overlapping date ranges combined date ranges I thought it would be a good …
I guess that all of us know that caching the data usually increase the performance, but I worried if all of us are aware about the risk that caching the data provides and how to minimize this.  That’s the reason why I decided to write this short art…
Video by: Steve
Using examples as well as descriptions, step through each of the common simple join types, explaining differences in syntax, differences in expected outputs and showing how the queries run along with the actual outputs based upon a simple set of dem…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

6 Experts available now in Live!

Get 1:1 Help Now