473,788 Members | 3,053 Online
Bytes | Software Development & Data Engineering Community
+ Post

Home Posts Topics Members FAQ

Make Access EVEN MORE SECURE than SQL Server!!

Yes, deliberately untrue and provocative subject line. Sorry. Just that I
posted earlier and nobody, apart from Tom, seemed interested.

I'm not talking Jet Users & Groups, I may or may not implement that. Even if
I do file/folder rights still need to be managed.

I've searched the archives and read the many postings. The basic problem
seems to be this:

Access is a 'file server' based system. So if you want your users to use the
db they've got to have access to the file. And can do stuff to it you might
not want.

David Fenton had a good idea, ShareName$ hides the Share. But you need admin
privileges to name shares, and in this case I won't ever have them. But if
you do have admin rights this seems pretty good too.

So this is what I came up with. The app is FE/BE split. FE on whichever
workstations, BE on a network share. MIS have set the share up for me, and I
have full control permissions over that. I just tried this on my network,
which is the same config as the one at work (roughly speaking!) - XP Pro
clients, Win2K Server.

On the folder containing the backend I give users write privileges, but
nothing else, specifically denying them List Folder/Read Data. But letting
them delete subfolders/files (to get rid of the ldb.)

On the backend mdb (which is in that folder) I give them Read, Read &
Execute rights, and don't allow inherited rights. This is for a user I
intend to only be read only. This seemed to work. Logging on as my
'ReadOnly' user I could read the data, but couldn't update it, insert or
whatever. The ldb file was created and deleted fine, but I couldn't examine
the contents of the folder. Am I missing something?

Often I've heard it said that you can't stop people simply copying the file,
whatever you do with NT permissions. That doesn't seem to be the case here.
Or am I right in thinking that they could just copy the whole folder?

I'll try it now, and see what happens with my read/write user too......

Nope, neither user could copy the whole folder (to get at the file). Both
users could connect to the data in the way I intend (read only or read
write). The ldb gets created and deleted as the last user logs off.

This seems like a fairly robust setup, as far as the back end data file is
concerned. So what huge hole have I missed?

Yours, Mike MacSween
Nov 12 '05 #1
0 1501

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

9
2286
by: Rich May | last post by:
Afternoon all, Apologies for cross-posting but as my query covers both Access and SQL Server I thought I'd send it both! I have inherited a project to migrate a fairly complex series of Access databases into a single proper SQL database with a web front end. Its quite a nasty job as people are working on a variety of data sets
2
1050
by: Jeremy S. | last post by:
What does it take to make a Web server a "secure server"? I need to serve some images from my IIS6 server and they must be accessible via https. I have never set up a server to work with https. How can I accomplish this? Where do I start? Thanks
5
1612
by: COHENMARVIN | last post by:
I have a sql server database hosted by an ISP. It has credit card fields. I want to make the database secure. My asp.net pages refer to the database as follows: strConnection = ConfigurationSettings.AppSettings; Which means they get the connectionstring for the database from a web.config file. The web.config file has the following tags: <appSettings> <add key="ConnectionInformation"
7
1458
by: analyst | last post by:
I need to migrate an Excel app I developed ten years ago, that has evolved into something with a life of it's own. But I know little to nothing about database platforms and development. The Excel file stores info in 60 cells on each line of the spreadsheet, a new line for every sample that is received. This spreadsheet grows to 10,000 lines in a couple months and I have to archive and purge it back down to a more stable size. The...
7
1716
by: runner7 | last post by:
Can anyone tell me the easiest or best way to do secure server-to-server transmissions using PHP? Does SSL work for server-to-server? Thanks for any replies.
15
2887
by: Wes Groleau | last post by:
When I try to import from Access, the DTS wizard only allows me to import tables and queries. OK, I'm not surprised the "macros" and reports don't come over. But it executes each query, and created a _table_ to hold the results. The sensible thing would be that SELECT queries become views and the others become stored procedures. But I find no way controls I can select to do that.
2
3989
by: Flo 'Irian' Schaetz | last post by:
Hello, just a quick question: Does anyone have an idea if NuSoap allows to secure server? Of course I could include a username/password field into each request, but that would be gravely unelegant (and not very secure). If not, are there any alternative libraries for Webservices with PHP? Flo
3
2755
by: zr | last post by:
Hi, Does usage of checked iterators and checked containers make code more secure? If so, can that code considered to be reasonably secure?
0
9655
marktang
by: marktang | last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However, people are often confused as to whether an ONU can Work As a Router. In this blog post, we’ll explore What is ONU, What Is Router, ONU & Router’s main usage, and What is the difference between ONU and Router. Let’s take a closer look ! Part I. Meaning of...
0
9498
by: Hystou | last post by:
Most computers default to English, but sometimes we require a different language, especially when relocating. Forgot to request a specific language before your computer shipped? No problem! You can effortlessly switch the default language on Windows 10 without reinstalling. I'll walk you through it. First, let's disable language synchronization. With a Microsoft account, language settings sync across devices. To prevent any complications,...
0
10363
Oralloy
by: Oralloy | last post by:
Hello folks, I am unable to find appropriate documentation on the type promotion of bit-fields when using the generalised comparison operator "<=>". The problem is that using the GNU compilers, it seems that the internal comparison operator "<=>" tries to promote arguments from unsigned to signed. This is as boiled down as I can make it. Here is my compilation command: g++-12 -std=c++20 -Wnarrowing bit_field.cpp Here is the code in...
1
10110
by: Hystou | last post by:
Overview: Windows 11 and 10 have less user interface control over operating system update behaviour than previous versions of Windows. In Windows 11 and 10, there is no way to turn off the Windows Update option using the Control Panel or Settings app; it automatically checks for updates and installs any it finds, whether you like it or not. For most users, this new feature is actually very convenient. If you want to control the update process,...
0
8993
agi2029
by: agi2029 | last post by:
Let's talk about the concept of autonomous AI software engineers and no-code agents. These AIs are designed to manage the entire lifecycle of a software development project—planning, coding, testing, and deployment—without human intervention. Imagine an AI that can take a project description, break it down, write the code, debug it, and then launch it, all on its own.... Now, this would greatly impact the work of software developers. The idea...
1
7517
isladogs
by: isladogs | last post by:
The next Access Europe User Group meeting will be on Wednesday 1 May 2024 starting at 18:00 UK time (6PM UTC+1) and finishing by 19:30 (7.30PM). In this session, we are pleased to welcome a new presenter, Adolph Dupré who will be discussing some powerful techniques for using class modules. He will explain when you may want to use classes instead of User Defined Types (UDT). For example, to manage the data in unbound forms. Adolph will...
0
6749
by: conductexam | last post by:
I have .net C# application in which I am extracting data from word file and save it in database particularly. To store word all data as it is I am converting the whole word file firstly in HTML and then checking html paragraph one by one. At the time of converting from word file to html my equations which are in the word document file was convert into image. Globals.ThisAddIn.Application.ActiveDocument.Select();...
1
4069
by: 6302768590 | last post by:
Hai team i want code for transfer the data from one system to another through IP address by using C# our system has to for every 5mins then we have to update the data what the data is updated we have to send another system
3
2894
bsmnconsultancy
by: bsmnconsultancy | last post by:
In today's digital era, a well-designed website is crucial for businesses looking to succeed. Whether you're a small business owner or a large corporation in Toronto, having a strong online presence can significantly impact your brand's success. BSMN Consultancy, a leader in Website Development in Toronto offers valuable insights into creating effective websites that not only look great but also perform exceptionally well. In this comprehensive...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.