[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference utrop1::linkworks_v3

Title:LinkWorks V3.0 Notes Conference
Notice:LNX_APO = APO issues, LINKWORKS_V3 = V3.0 issues
Moderator:tacklr.apd.dec.com::TACK_Lm::TACK_L
Created:Tue Jun 28 1994
Last Modified:Fri Jun 06 1997
Last Successful Update:Fri Jun 06 1997
Number of topics:2269
Total number of notes:8338

2167.0. "Security issue..." by KERNEL::SIMPSONR (fred) Mon Mar 24 1997 13:44

VMS V6.2 LinkWorks V3.07

The customer has a user who has a folder and two documents within it, which is
accessible from their desktop. The user claims that he created them himself in
June/July of last year. He went to delete them and found that the creator/owner
was someone different. The user that owns them, did not have an account when
these documents were created. This is a potential security risk, he wonders if
his database is corrupt. He has been unable as yet to find any other users with
the same problem. The problem is also that the user happens to be in the
security department of their company so is taking this quite seriously! Any
ideas?

Cheers,
Richard.
T.RTitleUserPersonal
Name
DateLines
2167.1TAV02::YAKIRYakir Lavie, ISRAEL DTN 882-3327Thu Mar 27 1997 10:3017
FWIW

I have seen this phenomenon also on LNX 307 on Alpha Dunix. 
I am not sure if this has recurred at the customer site since they have
upgraded to LNX 308.
The owner was changed to X, where user X had left the company several months
previously.

Needless to say, as Mr. Murphy would have it, this customer customer is 
our most "security oriented".

They feel there is a bug here, although they realise it may be hard to track
down with such scant data.

Yakir

2167.2KERNEL::SIMPSONRfredThu Mar 27 1997 16:335
Thanks Yakir for the feedback. Does anyone in LinkWorks engineering know if
this was a problem in V3.07, and that it has been cured in V3.08,

Cheers,
Richard.
2167.3problem not known. AccessRight?UTROP1::16.197.208.129::VISSER_JJoop Visser @ UTOTue Apr 01 1997 12:068
Enginering has no awareness of such a problem.
The only remark made was "Should it be possible for the new owner
to do this? In other words what is the accessright of the document?"

Enginering will keep it in mind to see if there are situations
possible which could result in such situations.

Joop Visser