"mlazarus-sSJ1ceXosh9vBvnq28/[email protected]" <mlazarus-sSJ1ceXosh9vBvnq28/[email protected]> wrote:
> The original poster (Shalom) was suggesting that ...
<snip>
>there is a possible security hole.
I agree that this isn't a "hole". I think it comes down to the definition.
I.e., is the existence of *ALLOBJ a hole? Of course it isn't. However, if there was no way to prevent access to *ALLOBJ, then a hole would exist.
In this case, there is a set of actions that can take place that cause inaccurate info to be recorded. It is possible to cause a journal to record that one user created a value, when in fact the value was created by a different user.
But because it's possible to prevent that by proper application of known security principles, it isn't a "hole".
Nevertheless, this is fairly a novel idea and is well worth being made known to everyone. It clearly demonstrates that proper precautions must be taken. It provides a textbook example of why, for example, debug access to production tasks is a serious issue. The discussion illustrates for everyone who is learning from this list why the related precautionary guidelines exist.
Tom Liotta
--
Tom Liotta
The PowerTech Group, Inc.
19426 68th Avenue South
Kent, WA 98032
Phone 253-872-7788 x313
Fax 253-872-7904
http://www.powertech.com
__________________________________________________________________
Switch to Netscape Internet Service.
As low as $9.95 a month -- Sign up today at http://isp.netscape.com/register
Netscape. Just the Net You Need.
New! Netscape Toolbar for Internet Explorer
Search from anywhere on the Web and block those annoying pop-ups.
Download now at http://channels.netscape.com/ns/search/install.jsp
_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.