Plateforme Level Extreme
Abonnement
Profil corporatif
Produits & Services
Support
Légal
English
Blatant attack on VFP database/tables at DevTeach
Message
De
16/05/2003 15:39:23
 
 
À
15/05/2003 22:33:55
Information générale
Forum:
Visual FoxPro
Catégorie:
Conférences & événements
Divers
Thread ID:
00788302
Message ID:
00789435
Vues:
26
Hi Bob,

While many responsible solutions to solving security issues with VFP have been mentioned in this thread already, lets not forget that any network security manager in a medium to large network worth his/her salt will not allow any access to their servers without them being virtually locked down. They will try to get into the data themselves the smart way and the dumb user way to test the system and if an enduser can access files outside his/her own directory or corrupt them outside the app, it is not even allowed on their server.

>>Stephane,
>>
>>There are questions that I have regarding the interactive access to SQL Server. Many people have MS Access installed on their computer. If a user has access to the SQL Server database, what prevents him/her from just opening an Access Data Project, connecting to the database and editing it interactively? If security hasn't been properly configured, what prevents the user from altering or dropping tables?
>>
>>John
>
>This is why the application we ship uses an applicatin role, which allows a very low security level user access when they connect outside the ap, but when the log into the ap it uses the application role to upgrade the connection with rights needed to run the ap.
>
>The other way is to have data access 100% via SP's which could do some type of authentication to determine whether the user is in the ap or not.
>
>BOb
.·*´¨)
.·`TCH
(..·*

010000110101001101101000011000010111001001110000010011110111001001000010011101010111001101110100
"When the debate is lost, slander becomes the tool of the loser." - Socrates
Vita contingit, Vive cum eo. (Life Happens, Live With it.)
"Life is not measured by the number of breaths we take, but by the moments that take our breath away." -- author unknown
"De omnibus dubitandum"
Précédent
Suivant
Répondre
Fil
Voir

Click here to load this message in the networking platform