• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

Intriguing OleDB problem

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    #21
    Originally posted by suityou01 View Post
    It is not running in the context of IUSER, rather the context of the application pool. .Net has supported impersonation for years.

    I'd read up on it if I were you.

    HTH
    I agree someone needs to do some reading up on security. Unfortunately its not me.
    merely at clientco for the entertainment

    Comment


      #22
      Originally posted by suityou01 View Post
      I love you all equally Doogie, no need to seek attention.
      It was a serious question. CUK is the last place I'd ask a programming question simply due to the very small number of people here... on SO you get answers from the people who designed the technologies in the first place sometimes!

      And could you keep the spats for General... there's special thread for it and everything!
      Originally posted by MaryPoppins
      I'd still not breastfeed a nazi
      Originally posted by vetran
      Urine is quite nourishing

      Comment


        #23
        Originally posted by d000hg View Post
        It was a serious question. CUK is the last place I'd ask a programming question simply due to the very small number of people here... on SO you get answers from the people who designed the technologies in the first place sometimes!

        And could you keep the spats for General... there's special thread for it and everything!
        Sound advice.

        I did not want a spat. I think Eek has rather let himself down with his childish rants. If he had simply said

        "Fair enough, if it works it works, however be aware that you have potentially caused the following issues ....."

        This would have been a level headed and mature response, worthy of a time seasoned contractor. Instead, well, the least said the better.

        Oh, and for the record, he has a history of splurging my requests for help in technical all over General. Newcomers to the forum may see this and decide to refrain from posting in technical on the strength of this. Just saying like
        Knock first as I might be balancing my chakras.

        Comment


          #24
          Originally posted by suityou01 View Post
          Oh, and for the record, he has a history of splurging my requests for help in technical all over General. Newcomers to the forum may see this and decide to refrain from posting in technical on the strength of this. Just saying like
          Personally I think his attempt to post proper answers here and then mock you about it in General is better than complaining the answers aren't good enough
          Originally posted by MaryPoppins
          I'd still not breastfeed a nazi
          Originally posted by vetran
          Urine is quite nourishing

          Comment


            #25
            Originally posted by eek
            Examples please as I don't believe I'm the prime culprit for taking your crap from technical and posting it in general.

            i'll admit to other examples but that was firstly to give you a laugh, to ensure that MF and others replied and because that was the most appropriate place for it to be. From memory the advice you got in general was better than the advice in Business and Contracts anyway.

            As for ranting I'm trying to work out how many others have agreed with you so far.
            I love it when you back pedal
            Knock first as I might be balancing my chakras.

            Comment


              #26
              I had deleted that.

              If you want to attack me do it in general. If you are brave enough.
              merely at clientco for the entertainment

              Comment


                #27
                Originally posted by eek View Post
                I had deleted that.

                If you want to attack me do it in general. If you are brave enough.
                Really don't as I am a grown up with better things to do.

                HTH
                Knock first as I might be balancing my chakras.

                Comment


                  #28
                  Originally posted by eek
                  There is a reason why the IUSR user has very minimal access rights
                  Originally posted by suityou01 View Post
                  It is not running in the context of IUSER, rather the context of the application pool. .Net has supported impersonation for years.
                  That's the point he's trying to make. Good security practice is to give the app the least privileges required to do what it needs to do i.e. give it permission to the oracle home directory. By choosing to impersonate another user you have, as a side effect, given it access to everything that user can access which probably includes lots and lots of other things that it doesn't need and probably shouldn't have access to. If the web app were to be exploited and an attacker able to run arbitrary code the range of things they could do is now significantly wider.
                  While you're waiting, read the free novel we sent you. It's a Spanish story about a guy named 'Manual.'

                  Comment


                    #29
                    Originally posted by suityou01 View Post
                    Really don't as I am a grown up with better things to do.
                    Like writing your passive-aggressive signature? Did you have to consult SQL for Dummies?
                    Originally posted by MaryPoppins
                    I'd still not breastfeed a nazi
                    Originally posted by vetran
                    Urine is quite nourishing

                    Comment


                      #30
                      Originally posted by d000hg View Post
                      Like writing your passive-aggressive signature? Did you have to consult SQL for Dummies?
                      SELECT User_Id IgnoresList FROM CUK_USERS WHERE USER_NAME = 'EEK' OR USER_CAN_SPELL = FALSE;
                      ignoreList

                      Oh, the irony

                      (And since user_name is case sensitive, the query would return no rows anyway)
                      Best Forum Advisor 2014
                      Work in the public sector? You can read my FAQ here
                      Click here to get 15% off your first year's IPSE membership

                      Comment

                      Working...
                      X