473,399 Members | 2,159 Online
Bytes | Software Development & Data Engineering Community
Post Job

Home Posts Topics Members FAQ

Join Bytes to post your question to a community of 473,399 software developers and data experts.

Security Challenge

Hello there nice folks,

OS: NT
Office: XP
Assumption 01: Already read MS's Security FAQ
Assumption 02: Good knowledge of how to secure a database
Scenario:

1) Tables in a "secured"mdb backend
2) Forms, Code, Queries and linked tables in a "secured" .mde front
end
3) "Users" group given no access at all
4) By pass key permanently disabled in the mde file by passing the ddl
parameter (checked and works like a charm)
5) People accessing the database through the mde file have an intense
logic behind the forms where Form 1 has to have information Before
Entering/viewing Information in Form 2 and so on and so forth
6) Based on the status of a record, user's are permitted/ not
permitted to view record

Challenge:
As you can see, everything looks hunky dory from the scenario above.
However, let's say user JOEBLOE has read access on Table 1 and Table 2
but is not suppose to see Table 2 until data has been entered in Table
1.

JOEBLOE is a curious user, who has nothing else to do at work except
for exploring Access databases lying around. Also, JOEBLOE knows quite
a bit of Access and thinks he is a programmer. To hack into the
system, JOEBLOE makes a new Access database but opens it using the MDW
file located on his system. Because JOEBLOE has read ….and also write
access to these tables, he can import them and view Table 1 and Table
2 without following the enforced system implemented through forms in
the MDE.

How do I prevent JOEBLOE from doing this?

All help is really appreciated

Thanks
JOEBLOES despiser
Farooq
Nov 13 '05 #1
1 1131
Item #25 in the security FAQ deals with this issue:
25. How can I help prevent users from updating any tables by any means
other than through forms?

Haven't done it personally, but sounds like it should work in your
situation.
On 18 Jun 2004 05:12:30 -0700, kf*****@yahoo.com (Farooq) wrote:
Hello there nice folks,

OS: NT
Office: XP
Assumption 01: Already read MS's Security FAQ
Assumption 02: Good knowledge of how to secure a database
Scenario:

1) Tables in a "secured"mdb backend
2) Forms, Code, Queries and linked tables in a "secured" .mde front
end
3) "Users" group given no access at all
4) By pass key permanently disabled in the mde file by passing the ddl
parameter (checked and works like a charm)
5) People accessing the database through the mde file have an intense
logic behind the forms where Form 1 has to have information Before
Entering/viewing Information in Form 2 and so on and so forth
6) Based on the status of a record, user's are permitted/ not
permitted to view record

Challenge:
As you can see, everything looks hunky dory from the scenario above.
However, let's say user JOEBLOE has read access on Table 1 and Table 2
but is not suppose to see Table 2 until data has been entered in Table
1.

JOEBLOE is a curious user, who has nothing else to do at work except
for exploring Access databases lying around. Also, JOEBLOE knows quite
a bit of Access and thinks he is a programmer. To hack into the
system, JOEBLOE makes a new Access database but opens it using the MDW
file located on his system. Because JOEBLOE has read ….and also write
access to these tables, he can import them and view Table 1 and Table
2 without following the enforced system implemented through forms in
the MDE.

How do I prevent JOEBLOE from doing this?

All help is really appreciated

Thanks
JOEBLOES despiser
Farooq

**********************
ja**************@telusTELUS.net
remove uppercase letters for true email
http://www.geocities.com/jacksonmacd/ for info on MS Access security
Nov 13 '05 #2

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

2
by: Graeme Coutts | last post by:
Developed a web application which adopts a custom security model which displays a login page and requests a username/password combination. The username works in a mixed-mode of usernames matched with...
1
by: Rob Barnes | last post by:
When I try to create a machine-level security policy based on an assembly's strong name, I get the following error: "ERROR: Invalid label or name" The caspol command is: "caspol -machine...
3
by: Glen Scott | last post by:
Hi, I'm writing an ASP app that administers an ISA server remotely. The fact that it's an ISA server isn't my problem I believe. My question? What is the security difference between disabling...
11
by: Will | last post by:
I am looking at using a table with user names, passwords and user rights, which I would administer. I have read a lot about the shortfalls of this and the lack of security but the customer does...
26
by: Stav | last post by:
Hi there. I'm working on an application that currently uses DAO to connect to an Access 97 database. The database is created by and used exclusively by the product to store search results and...
6
by: David++ | last post by:
Hi folks, So I have implemented a Web service which provides several Web Methods. Before the client can use the WebMethods they must first be authenticated and authorized i.e. they login, obtain...
2
by: piter | last post by:
Hi. My goal is to achive security similiar to the HTTPS. The data visible for the port sniffer must be ciphered. Is this possible with WS-Security or WS-Security only enables mi to secure...
9
by: David T. Ashley | last post by:
Thanks for the helpful replies on the other thread. Essentially it was pointed out that a process with the same UID as the ones writing/reading the pipes would be able to examine the memory of the...
0
BarryA
by: BarryA | last post by:
What are the essential steps and strategies outlined in the Data Structures and Algorithms (DSA) roadmap for aspiring data scientists? How can individuals effectively utilize this roadmap to progress...
1
by: nemocccc | last post by:
hello, everyone, I want to develop a software for my android phone for daily needs, any suggestions?
0
by: Hystou | last post by:
There are some requirements for setting up RAID: 1. The motherboard and BIOS support RAID configuration. 2. The motherboard has 2 or more available SATA protocol SSD/HDD slots (including MSATA, M.2...
0
marktang
by: marktang | last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However,...
0
by: Hystou | last post by:
Most computers default to English, but sometimes we require a different language, especially when relocating. Forgot to request a specific language before your computer shipped? No problem! You can...
0
jinu1996
by: jinu1996 | last post by:
In today's digital age, having a compelling online presence is paramount for businesses aiming to thrive in a competitive landscape. At the heart of this digital strategy lies an intricately woven...
0
tracyyun
by: tracyyun | last post by:
Dear forum friends, With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each...
0
agi2029
by: agi2029 | last post by:
Let's talk about the concept of autonomous AI software engineers and no-code agents. These AIs are designed to manage the entire lifecycle of a software development project—planning, coding, testing,...
0
isladogs
by: isladogs | last post by:
The next Access Europe User Group meeting will be on Wednesday 1 May 2024 starting at 18:00 UK time (6PM UTC+1) and finishing by 19:30 (7.30PM). In this session, we are pleased to welcome a new...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.