Re: Microsoft Access 97 Stores Database Password as Plaintext

From: Nick Lamb (njl98rat_private)
Date: Mon Feb 08 1999 - 15:13:34 PST

  • Next message: GANG WANG: "Re: Buffer overflow in Solaris 2.6/2.7 /usr/bin/lpstat"

    On Mon, 8 Feb 1999 sozniat_private wrote:
    
    [Added line breaks]
    > This other issue you have brought up is indeed a very serious security risk
    > In fact I always open up Access databases in a hex editor just to see what
    
    > The problem is that Access allocates the the space it needs for its tables
    > but until used, that space will contain whatever used to be on those
    > sectors on the hard drive.
    
    This shouldn't be a problem in a well-behaved system. There's no reason for
    the OS to hand people the contents of old (deleted?) files when they try
    to read data which they've never written. Presumably this wouldn't happen
    on NT Workstation/Server running Access?
    
    I suspect that Access would really like to create a file with holes (to
    save allocating unnecessary disk) but of course, this only works for NTFS
    and thus can't be required without losing a lot of potential users.
    
    Nick.
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:33:11 PDT