 




<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WRKQRY Security Flaw / Users can Alter/ Replace Data in Production Files</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/wrkqry-security-flaw-users-can-alter-replace-data-in-production-files/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/wrkqry-security-flaw-users-can-alter-replace-data-in-production-files/</link>
	<description></description>
	<lastBuildDate>Tue, 21 May 2013 17:44:06 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: tomliotta</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/wrkqry-security-flaw-users-can-alter-replace-data-in-production-files/#comment-69279</link>
		<dc:creator>tomliotta</dc:creator>
		<pubDate>Wed, 21 Oct 2009 00:40:13 +0000</pubDate>
		<guid isPermaLink="false">#comment-69279</guid>
		<description><![CDATA[If you&#039;ve given authority to change the file data to the user, they can change it with WRKQRY or UPDDTA or ODBC or RPG or COBOL or CL or REXX or remote commands or... well, just about any tool they can get hold of that&#039;s capable of issuing file updates. The security flaw is not in the tools; it&#039;s in the authority that&#039;s been granted to the users.

If you don&#039;t want a user to change file data, revoke the authority to change the data.

Tom]]></description>
		<content:encoded><![CDATA[<p>If you&#8217;ve given authority to change the file data to the user, they can change it with WRKQRY or UPDDTA or ODBC or RPG or COBOL or CL or REXX or remote commands or&#8230; well, just about any tool they can get hold of that&#8217;s capable of issuing file updates. The security flaw is not in the tools; it&#8217;s in the authority that&#8217;s been granted to the users.</p>
<p>If you don&#8217;t want a user to change file data, revoke the authority to change the data.</p>
<p>Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gilly400</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/wrkqry-security-flaw-users-can-alter-replace-data-in-production-files/#comment-55074</link>
		<dc:creator>gilly400</dc:creator>
		<pubDate>Fri, 25 Jul 2008 09:10:23 +0000</pubDate>
		<guid isPermaLink="false">#comment-55074</guid>
		<description><![CDATA[Hi,

Unless the output format is the same as the existing file (which is unlikely from a query), then the only thing they can possibly do is replace the file.  If this happens then your application programs are likely to start crashing with level checks, so you&#039;ll know straight away that someone&#039;s done this.

If you have your security set up correctly with authorisations to files ,etc then you shouldn&#039;t get this happening.  If you don&#039;t have your security set up right, then your users can probably use all sorts of other ways to modify data they shouldn&#039;t be modifying.

You can always set up a test file and user and show this to your auditor - just to prove the point.

Regards,

Martin Gilbert.]]></description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Unless the output format is the same as the existing file (which is unlikely from a query), then the only thing they can possibly do is replace the file.  If this happens then your application programs are likely to start crashing with level checks, so you&#8217;ll know straight away that someone&#8217;s done this.</p>
<p>If you have your security set up correctly with authorisations to files ,etc then you shouldn&#8217;t get this happening.  If you don&#8217;t have your security set up right, then your users can probably use all sorts of other ways to modify data they shouldn&#8217;t be modifying.</p>
<p>You can always set up a test file and user and show this to your auditor &#8211; just to prove the point.</p>
<p>Regards,</p>
<p>Martin Gilbert.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 3/10 queries in 0.037 seconds using memcached
Object Caching 281/287 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-05-21 17:52:21 -->