Subject Re: [IBDI] Path on win NT 4.0 => INTERBASE SECURITY HOLE
Author Fabrice Vendé - INFOCOB
> You need to create a database in a physical location (i.e. not a mapped
> location; and not using UNC notation) and you need the full server path
as
> seen from the client. For TCP/ip that is
> servername:c:\something\something\thedatabase.gdb.
>
> You should make certain that all clients have the same physical path, i.e.
> it is Bad Karma to omit the backslash following the drive designator.
>
> You can change the location of the Temp files, though. Use the server
> manager program to do this.

Isn't it a security hole ?
On my interbase client I can create a database on the NT server with :
severname:c:\test.dll

It is easy to create a database with these names:
servername:c:\winnt\system32\kernel32.dll !!!!!!!!
or servername:c:\winnt\profiles\administrator\ntuser.dat !!!

With the administrator password (just the right to create a database) of
interbase it's easy to crash a NT server ?!

Fabrice Vende
fabrice@...

-
SARL I N F O C O B
Developpement, formation, matériel, logiciel
http://www.infocob.com