/usr/share/doc/firebird
Issue: ====== If the LocalSystem user is allowed to install the Firebird Service, it could make the whole system accessible to a malicious attacker. Scope: ====== Affects Windows NT platforms. Document author: ================= Alex Peshkov (peshkoff@mail.ru) Document date: 2003/06/22 ============== Firebird installation kits for Windows NT systems, i.e. those that support services, currently provide a route into the host system for any hacker who finds a new security hole in Firebird. All of the current kits install the Firebird service to run under the LocalSystem account. Through Firebird, the attacker can get LocalSystem access to the system. The steps to fix things manually are simple: 1) add the user 'firebird' as a member of the Domain users group, with default rights 2) grant this user write access to all databases, including security2.fdb (isc4.gdb in pre-1.5 versions), and the firebird.log file 3) grant the user 'firebird' rights to "Login as service" 4) make the Firebird services (FirebirdServer and FirebirdGuardian, if used, log in with username 'firebird' Solution: ========= Alex Peshkov People writing installers should note that Firebird's standard routine to install and manage the Firebird Service on WinNT/2000/XP platforms (instsvc.exe) was upgraded in version 1.5 by the addition of an optional L[ogin] switch to the {install} command. It is strongly recommended that you employ this switch in the Windows kits, to make the 'firebird' user, not LocalSystem, the default account under which the Firebird Service logs in. For more details, see the document README.instsvc switch to (see instsvc.exe).
.
Edit
..
Edit
CHANGELOG.md
Edit
Firebird-3-QuickStart.pdf
Edit
Firebird-4.0.6-ReleaseNotes.pdf
Edit
IDPLicense.txt
Edit
IPLicense.txt
Edit
README.DiskSpaceAllocation
Edit
README.Fedora
Edit
README.IPv6
Edit
README.NTSecurity
Edit
README.Optimizer.txt
Edit
README.SecureRemotePassword.html
Edit
README.Win32LibraryInstallation.txt
Edit
README.Win9X_NT_embedding
Edit
README.build.macosx.md
Edit
README.build.mingw.html
Edit
README.build.msvc.html
Edit
README.build.posix.html
Edit
README.coding.style
Edit
README.connection_string_charset.txt
Edit
README.connection_strings
Edit
README.external_routines.txt
Edit
README.fb_cancel_operation
Edit
README.fb_shutdown
Edit
README.fbsvcmgr
Edit
README.garbage_collector
Edit
README.gbak
Edit
README.incompatibilities.3to4.txt
Edit
README.incompatibilities.txt
Edit
README.instsvc
Edit
README.intl
Edit
README.isql_enhancements.txt
Edit
README.makefiles
Edit
README.md
Edit
README.modern_cpp.md
Edit
README.monitoring_tables
Edit
README.online_validation
Edit
README.performance_monitoring
Edit
README.plugins.html
Edit
README.providers.html
Edit
README.raw_devices
Edit
README.read_consistency.md
Edit
README.read_password_from_file
Edit
README.replication.md
Edit
README.security_database.txt
Edit
README.services_extension
Edit
README.session_idle_timeouts
Edit
README.sha1
Edit
README.statement_timeouts
Edit
README.superclassic
Edit
README.trace_services
Edit
README.transaction_at_snapshot.md
Edit
README.trusted_authentication
Edit
README.user.embedded
Edit
README.user.troubleshooting
Edit
README.wire.compression.html
Edit
README.xnet
Edit
sample
Edit
sql.extensions
Edit
udf_replace.sql
Edit
udf_replace.txt
Edit