Subject | Re: [firebird-support] gbak 1.5 + server 1.0 = crash |
---|---|
Author | Marco Parmeggiani |
Post date | 2004-04-22T11:17:50Z |
In data Tue, 20 Apr 2004 13:12:51 +0200, hai scritto:
1.0.x servers crash only in conjuntion with the use of the -se switch in
gbak 1.5
backups made without the -se switch are made correctly.
I know that exposing a database to the world is a thing to avoid so no one
does it and the above problem is not so important, but i think that at
least at a local level it could become a security issue as it could lead
easly to a denial of service.
To kill the server you need only to know a username and a password for that
server, no matter if that username is SYSDBA or the owner of the database
or "someone". So, normal users could easly kill the server with a 1.5 gbak
at hand.
HTH
ciao
> What i've found is that when i use gbak in conjunction with a 1.0 server,more info:
> the server crashes. Maybe it's "normal" but having found nothing on the 1.5
> release note, i'm asking here.
1.0.x servers crash only in conjuntion with the use of the -se switch in
gbak 1.5
backups made without the -se switch are made correctly.
I know that exposing a database to the world is a thing to avoid so no one
does it and the above problem is not so important, but i think that at
least at a local level it could become a security issue as it could lead
easly to a denial of service.
To kill the server you need only to know a username and a password for that
server, no matter if that username is SYSDBA or the owner of the database
or "someone". So, normal users could easly kill the server with a 1.5 gbak
at hand.
HTH
ciao