Quantcast
Channel: SCN: Message List - SAP SQL Anywhere
Viewing all articles
Browse latest Browse all 2182

Re: How to disallow read/write client files from the client?

$
0
0

Not really because the hypothetical exploit would come from the IQ/SQL Anywhere server (think data stream injection).

 

The call back DB_CALLBACK_VALIDATE_FILE_TRANSFER supplied by Jason allows the developer to close this hole by denying file transfers.  It would be nice if the default behavior was to disallow file transfers and require the developers to enable it. 

 

Of course, this is just one potential hole.  It would be easier to infect the (assuming) windows client boxes IMO - see metasploit for the numerous methods of doing that.


Viewing all articles
Browse latest Browse all 2182

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>