Subject Re: [IB-Architect] Test Program
Author Craig Stuntz
Jim Starkey wrote:
>
> Sean Leyne has been arguing for a test program to check vulnerability
> to back door.
> [...]
> But it occurred to me that we could put a test on the firebird
> site: enter a node name and an optional database name string it
> it says yes, no, or can't tell....
>
> Thoughts?

It should probably also check for SYSDBA and masterkey, in addition to
the recently released issue. The former are perhaps a bigger
vulnerability!

Also, you might want to limit the number of times the tool can be run
from a particular IP address, lest somebody write another program to use
your tool as a port scanner.

-Craig

--
Craig Stuntz Vertex Systems Corporation
Senior Developer http://www.vertexsoftware.com

Delphi/InterBase weblog: http://delphi.weblogs.com
_______________________________________________
Ib-architect mailing list
Ib-architect@...
http://mers.com/mailman/listinfo/ib-architect