Re: Password security [where is the password] - Mailing list pgsql-odbc

From Ludek Finstrle
Subject Re: Password security [where is the password]
Date
Msg-id 20070122062612.GB22535@soptik.pzkagis.cz
Whole thread Raw
In response to Password security [where is the password]  ("Ezequias Rodrigues da Rocha" <ezequias.rocha@gmail.com>)
List pgsql-odbc
> I would like to know where is the password setted on the connection Dialog.
> If it remains after the client shutdown it must be in some place in the hard
> disk. I am afread about it. Can anyone tell me if someone can catch it
> (hacker) ?

It's stored in registry:
System DSN:
HKLM\Software\ODBC\ODBC.INI\<DSN name> in string value Password.
All the users with access to the computer can read it (don't forgot
the network registry access).

User DSN:
HKCU\Software\ODBC\ODBC.INI\<DSN name> in string value Password.
If everything is properly only the user and Admin can read it.

File DSN:
in file
All the users with access to the file can read it.

Regards,

Luf

P.S. The admin could change the default ACL on registry tree.

pgsql-odbc by date:

Previous
From: "Ezequias Rodrigues da Rocha"
Date:
Subject: Password security [where is the password]
Next
From: Ludek Finstrle
Date:
Subject: Re: Password security [where is the password]