# Vantage security and ODBC **Category:** [Yahoo Archive](https://www.epiusers.help/c/yahoo-archive/9) **Created:** 2001-02-23 12:38 UTC **Views:** 804 **Replies:** 27 **URL:** https://www.epiusers.help/t/vantage-security-and-odbc/2285 --- ## Post #1 by @system
> That's a good point, Troy. One outcome of the issue being raised here has[Non-text portions of this message have been removed]
> been my recognition of the security holes I've created by installing Report
> Builder for various users. I plan to remove Report Builder where necessary.
>
> How would you prevent a user from installing or re-installing Report
> Builder?
>
> Regards,
> Scott
>
> -----Original Message-----
> From: Troy Funte [mailto:tfunte@...]
> Sent: Thursday, February 22, 2001 12:22 PM
> To: vantage@yahoogroups.com
> Subject: Re: [Vantage] Vantage security and ODBC
>
> Incidently, any user who knows how to create a shortcut could, in theory,
> install report builder on their machine and run it too.
>
> So using Access, although a potential time-bomb, relies on the ignorance of
> the general user. It is the rogue programmer-in-disguise-as-an-engineer
> that will might you headaches.
>
> Troy
> ----- Original Message -----
> From: Lepley, Scott A.
> To: 'vantage@yahoogroups.com'
> Sent: Thursday, February 22, 2001 5:46 AM
> Subject: RE: [Vantage] Vantage security and ODBC
>
> Thanks for the reply, Troy. I understand that allowing data input via
> ODBC
> would or could bypass validation routines and thereby corrupt the
> database.
> That type of access is already ruled out in my opinion. However, even if
> the ODBC link were limited to read-only, that doesn't alleviate my
> concern.
> My concern is regarding just that ability, that of the Access application
> users being able to read the data. It appears that ODBC would allow them
> to
> see virtually any data, whether they needed to see it or not. If it were
> acceptable for these users to see all data, I would simply install Report
> Builder on their machines to let them access the data that way.
>
>
> [Non-text portions of this message have been removed]
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
>
>
> Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
----- Original Message -----
From: Lepley, Scott A.
To: Vantage YahooGroup (E-mail)
Cc: O'Rourke, Kevin P.
Sent: Wednesday, February 21, 2001 4:45 PM
Subject: [Vantage] Vantage security and ODBC
I'm sure this has been discussed previously, but I sure would appreciate it
if some users would be willing to respond again regarding this issue.
The situation here at this company is the following. The Customer Service
Supervisor here is knowledgeable about databases. He is currently
developing a customer service application in Microsoft Access and wishes to
establish connections between Access and Vantage using ODBC functionality.
I am the person responsible for coordinating the company's use of Vantage.
I have no control over the application development. I am uncomfortable
providing this functionality because of security concerns. As far as I
know, if I implement ODBC, it will allow access to all of the Progress
tables, except payroll, and thereby circumvent the access controls
established in Vantage. Everything that I have been able to learn so far
about this issue seems to confirm my concern. If my concern is legitimate,
are there any ways to mitigate this security risk?
Regards,
Scott A. Lepley
Systems Administrator
Mauell Corporation
31 Old Cabin Hollow Road
Dillsburg PA 17019-8815
Phone: 717-432-8686, ext. 14
Fax: 717-432-8688
Email: sal@...
[Non-text portions of this message have been removed]
Yahoo! Groups Sponsor
Click here for Classmates.com
To unsubscribe from this group, send an email to:
vantage-unsubscribe@egroups.com
Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service.
[Non-text portions of this message have been removed]
>
> What I've heard on the list before, is that you want Access to have Read only links. Otherwise there is the risk of Access changing Vantage data in a compromising way - meaning there are no checks and balances and data could be corrupted. The SAFEST way to use Access is to import it from an exported file. By linking directly through ODBC, it would be hard, in my opinion to maintain any kind of security on the database. A user could corrupt the database, or have access to confidential information such as payroll stuff.
>
> I'm no expert, but these are some of the things I've heard. There are probably others on the list who could give you more detail.
>
> Troy Funte
> Liberty Electronics
> ----- Original Message -----
> From: Lepley, Scott A.
> To: Vantage YahooGroup (E-mail)
> Cc: O'Rourke, Kevin P.
> Sent: Wednesday, February 21, 2001 4:45 PM
> Subject: [Vantage] Vantage security and ODBC
>
> I'm sure this has been discussed previously, but I sure would appreciate it
> if some users would be willing to respond again regarding this issue.
>
> The situation here at this company is the following. The Customer Service
> Supervisor here is knowledgeable about databases. He is currently
> developing a customer service application in Microsoft Access and wishes to
> establish connections between Access and Vantage using ODBC functionality.
> I am the person responsible for coordinating the company's use of Vantage.
> I have no control over the application development. I am uncomfortable
> providing this functionality because of security concerns. As far as I
> know, if I implement ODBC, it will allow access to all of the Progress
> tables, except payroll, and thereby circumvent the access controls
> established in Vantage. Everything that I have been able to learn so far
> about this issue seems to confirm my concern. If my concern is legitimate,
> are there any ways to mitigate this security risk?
>
> Regards,
> Scott A. Lepley
> Systems Administrator
> Mauell Corporation
> 31 Old Cabin Hollow Road
> Dillsburg PA 17019-8815
> Phone: 717-432-8686, ext. 14
> Fax: 717-432-8688
> Email: sal@...
>
> [Non-text portions of this message have been removed]
>
> Yahoo! Groups Sponsor
>
> Click here for Classmates.com
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
> Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service.
>
> [Non-text portions of this message have been removed]
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
>
>
> Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
----- Original Message -----
From: Lepley, Scott A.
To: Vantage YahooGroup (E-mail)
Cc: O'Rourke, Kevin P.
Sent: Wednesday, February 21, 2001 4:45 PM
Subject: [Vantage] Vantage security and ODBC
I'm sure this has been discussed previously, but I sure would appreciate
it
if some users would be willing to respond again regarding this issue.
The situation here at this company is the following. The Customer Service
Supervisor here is knowledgeable about databases. He is currently
developing a customer service application in Microsoft Access and wishes
to
establish connections between Access and Vantage using ODBC functionality.
I am the person responsible for coordinating the company's use of Vantage.
I have no control over the application development. I am uncomfortable
providing this functionality because of security concerns. As far as I
know, if I implement ODBC, it will allow access to all of the Progress
tables, except payroll, and thereby circumvent the access controls
established in Vantage. Everything that I have been able to learn so far
about this issue seems to confirm my concern. If my concern is
legitimate,
are there any ways to mitigate this security risk?
[Non-text portions of this message have been removed]
>only links. Otherwise there is the risk of Access changing Vantage data in a
> What I've heard on the list before, is that you want Access to have Read
>probably others on the list who could give you more detail.
> I'm no expert, but these are some of the things I've heard. There are
>it
> Troy Funte
> Liberty Electronics
> ----- Original Message -----
> From: Lepley, Scott A.
> To: Vantage YahooGroup (E-mail)
> Cc: O'Rourke, Kevin P.
> Sent: Wednesday, February 21, 2001 4:45 PM
> Subject: [Vantage] Vantage security and ODBC
>
> I'm sure this has been discussed previously, but I sure would appreciate
> if some users would be willing to respond again regarding this issue.Service
>
> The situation here at this company is the following. The Customer
> Supervisor here is knowledgeable about databases. He is currentlyto
> developing a customer service application in Microsoft Access and wishes
> establish connections between Access and Vantage using ODBCfunctionality.
> I am the person responsible for coordinating the company's use ofVantage.
> I have no control over the application development. I am uncomfortablefar
> providing this functionality because of security concerns. As far as I
> know, if I implement ODBC, it will allow access to all of the Progress
> tables, except payroll, and thereby circumvent the access controls
> established in Vantage. Everything that I have been able to learn so
> about this issue seems to confirm my concern. If my concern islegitimate,
> are there any ways to mitigate this security risk?<http://docs.yahoo.com/info/terms/>
>
> Regards,
> Scott A. Lepley
> Systems Administrator
> Mauell Corporation
> 31 Old Cabin Hollow Road
> Dillsburg PA 17019-8815
> Phone: 717-432-8686, ext. 14
> Fax: 717-432-8688
> Email: sal@...
>
> [Non-text portions of this message have been removed]
>
> Yahoo! Groups Sponsor
>
> Click here for Classmates.com
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
> Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service.
>
> [Non-text portions of this message have been removed]
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
>
>
> Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
>only links. Otherwise there is the risk of Access changing Vantage data in a
> What I've heard on the list before, is that you want Access to have Read
>probably others on the list who could give you more detail.
> I'm no expert, but these are some of the things I've heard. There are
>it
> Troy Funte
> Liberty Electronics
> ----- Original Message -----
> From: Lepley, Scott A.
> To: Vantage YahooGroup (E-mail)
> Cc: O'Rourke, Kevin P.
> Sent: Wednesday, February 21, 2001 4:45 PM
> Subject: [Vantage] Vantage security and ODBC
>
> I'm sure this has been discussed previously, but I sure would appreciate
> if some users would be willing to respond again regarding this issue.Service
>
> The situation here at this company is the following. The Customer
> Supervisor here is knowledgeable about databases. He is currentlyto
> developing a customer service application in Microsoft Access and wishes
> establish connections between Access and Vantage using ODBCfunctionality.
> I am the person responsible for coordinating the company's use ofVantage.
> I have no control over the application development. I am uncomfortablefar
> providing this functionality because of security concerns. As far as I
> know, if I implement ODBC, it will allow access to all of the Progress
> tables, except payroll, and thereby circumvent the access controls
> established in Vantage. Everything that I have been able to learn so
> about this issue seems to confirm my concern. If my concern islegitimate,
> are there any ways to mitigate this security risk?<http://docs.yahoo.com/info/terms/>
>
> Regards,
> Scott A. Lepley
> Systems Administrator
> Mauell Corporation
> 31 Old Cabin Hollow Road
> Dillsburg PA 17019-8815
> Phone: 717-432-8686, ext. 14
> Fax: 717-432-8688
> Email: sal@...
>
> [Non-text portions of this message have been removed]
>
> Yahoo! Groups Sponsor
>
> Click here for Classmates.com
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
> Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service.
>
> [Non-text portions of this message have been removed]
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
>
>
> Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
>
> Ignorance is not normally considered a valid security policy, especially
> when the natives are becoming more and more computer literate. ( Whether we
> like it or not ... )
>
> -----Original Message-----
> From: Joe Konecny [mailto:jkonecn@...]
> Sent: Thursday, February 22, 2001 7:19 AM
> To: vantage@yahoogroups.com
> Subject: Re: [Vantage] Vantage security and ODBC
>
> The whole database is wide open with ODBC including payroll. Also
> consider that v5 installs odbc by default on each workstation
> like it or not. All they need is the host name, database name
> and the port number. That info is easy to get. So really any user
> anywhere can use ODBC and get at payroll or any other table.
>
> That said... I'm very glad ODBC access is there and fortunately
> none of our users know anything about ODBC.
>
> Troy Funte wrote:
> >
> > What I've heard on the list before, is that you want Access to have Read
> only links. Otherwise there is the risk of Access changing Vantage data in a
> compromising way - meaning there are no checks and balances and data could
> be corrupted. The SAFEST way to use Access is to import it from an exported
> file. By linking directly through ODBC, it would be hard, in my opinion to
> maintain any kind of security on the database. A user could corrupt the
> database, or have access to confidential information such as payroll stuff.
> >
> > I'm no expert, but these are some of the things I've heard. There are
> probably others on the list who could give you more detail.
> >
> > Troy Funte
> > Liberty Electronics
> > ----- Original Message -----
> > From: Lepley, Scott A.
> > To: Vantage YahooGroup (E-mail)
> > Cc: O'Rourke, Kevin P.
> > Sent: Wednesday, February 21, 2001 4:45 PM
> > Subject: [Vantage] Vantage security and ODBC
> >
> > I'm sure this has been discussed previously, but I sure would appreciate
> it
> > if some users would be willing to respond again regarding this issue.
> >
> > The situation here at this company is the following. The Customer
> Service
> > Supervisor here is knowledgeable about databases. He is currently
> > developing a customer service application in Microsoft Access and wishes
> to
> > establish connections between Access and Vantage using ODBC
> functionality.
> > I am the person responsible for coordinating the company's use of
> Vantage.
> > I have no control over the application development. I am uncomfortable
> > providing this functionality because of security concerns. As far as I
> > know, if I implement ODBC, it will allow access to all of the Progress
> > tables, except payroll, and thereby circumvent the access controls
> > established in Vantage. Everything that I have been able to learn so
> far
> > about this issue seems to confirm my concern. If my concern is
> legitimate,
> > are there any ways to mitigate this security risk?
> >
> > Regards,
> > Scott A. Lepley
> > Systems Administrator
> > Mauell Corporation
> > 31 Old Cabin Hollow Road
> > Dillsburg PA 17019-8815
> > Phone: 717-432-8686, ext. 14
> > Fax: 717-432-8688
> > Email: sal@...
> >
> > [Non-text portions of this message have been removed]
> >
> > Yahoo! Groups Sponsor
> >
> > Click here for Classmates.com
> >
> >
> > To unsubscribe from this group, send an email to:
> > vantage-unsubscribe@egroups.com
> >
> > Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service.
> >
> > [Non-text portions of this message have been removed]
> >
> >
> > To unsubscribe from this group, send an email to:
> > vantage-unsubscribe@egroups.com
> >
> >
> >
> > Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
> <http://docs.yahoo.com/info/terms/>
>
> Yahoo! Groups Sponsor
>
> <http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=1700007183:N/
> A=524804/*http://www.classmates.com/index.tf?s=2629> Classmates.com
> Click here for Classmates.com
>
> <http://us.adserver.yahoo.com/l?M=163100.1330039.2920210.2/D=egroupmail/S=17
> 00007183:N/A=524804/rand=582186115>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
> Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service
> <http://docs.yahoo.com/info/terms/> .
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
>
>
> Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
> I'm sure this has been discussed previously, but I sure would appreciate it[Non-text portions of this message have been removed]
> if some users would be willing to respond again regarding this issue.
>
> The situation here at this company is the following. The Customer Service
> Supervisor here is knowledgeable about databases. He is currently
> developing a customer service application in Microsoft Access and wishes to
> establish connections between Access and Vantage using ODBC functionality.
> I am the person responsible for coordinating the company's use of Vantage.
> I have no control over the application development. I am uncomfortable
> providing this functionality because of security concerns. As far as I
> know, if I implement ODBC, it will allow access to all of the Progress
> tables, except payroll, and thereby circumvent the access controls
> established in Vantage. Everything that I have been able to learn so far
> about this issue seems to confirm my concern. If my concern is legitimate,
> are there any ways to mitigate this security risk?
>
> Regards,
> Scott A. Lepley
> Systems Administrator
> Mauell Corporation
> 31 Old Cabin Hollow Road
> Dillsburg PA 17019-8815
> Phone: 717-432-8686, ext. 14
> Fax: 717-432-8688
> Email: sal@...
>
>
> [Non-text portions of this message have been removed]
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
>
>
> Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
----- Original Message -----
From: Lepley, Scott A.
To: 'vantage@yahoogroups.com'
Sent: Thursday, February 22, 2001 5:46 AM
Subject: RE: [Vantage] Vantage security and ODBC
Thanks for the reply, Troy. I understand that allowing data input via ODBC
would or could bypass validation routines and thereby corrupt the database.
That type of access is already ruled out in my opinion. However, even if
the ODBC link were limited to read-only, that doesn't alleviate my concern.
My concern is regarding just that ability, that of the Access application
users being able to read the data. It appears that ODBC would allow them to
see virtually any data, whether they needed to see it or not. If it were
acceptable for these users to see all data, I would simply install Report
Builder on their machines to let them access the data that way.
I welcome any further comments.
Regards,
Scott
-----Original Message-----
From: Troy Funte [mailto:tfunte@...]
Sent: Thursday, February 22, 2001 2:56 AM
To: vantage@yahoogroups.com
Subject: Re: [Vantage] Vantage security and ODBC
What I've heard on the list before, is that you want Access to have Read
only links. Otherwise there is the risk of Access changing Vantage data in a
compromising way - meaning there are no checks and balances and data could
be corrupted. The SAFEST way to use Access is to import it from an exported
file. By linking directly through ODBC, it would be hard, in my opinion to
maintain any kind of security on the database. A user could corrupt the
database, or have access to confidential information such as payroll stuff.
I'm no expert, but these are some of the things I've heard. There are
probably others on the list who could give you more detail.
Troy Funte
Liberty Electronics
----- Original Message -----
From: Lepley, Scott A.
To: Vantage YahooGroup (E-mail)
Cc: O'Rourke, Kevin P.
Sent: Wednesday, February 21, 2001 4:45 PM
Subject: [Vantage] Vantage security and ODBC
I'm sure this has been discussed previously, but I sure would appreciate
it
if some users would be willing to respond again regarding this issue.
The situation here at this company is the following. The Customer Service
Supervisor here is knowledgeable about databases. He is currently
developing a customer service application in Microsoft Access and wishes
to
establish connections between Access and Vantage using ODBC functionality.
I am the person responsible for coordinating the company's use of Vantage.
I have no control over the application development. I am uncomfortable
providing this functionality because of security concerns. As far as I
know, if I implement ODBC, it will allow access to all of the Progress
tables, except payroll, and thereby circumvent the access controls
established in Vantage. Everything that I have been able to learn so far
about this issue seems to confirm my concern. If my concern is
legitimate,
are there any ways to mitigate this security risk?
[Non-text portions of this message have been removed]
Yahoo! Groups Sponsor
Click here for Classmates.com
To unsubscribe from this group, send an email to:
vantage-unsubscribe@egroups.com
Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service.
[Non-text portions of this message have been removed]
>
> Thanks for the reply, Joe. I should have mentioned that we are using
> version 3.00.632. Regarding payroll, I understood that the payroll table
> was encrypted and therefore could be read only through Vantage. Was this
> true in ver. 3 and now isn't in ver. 5? Additionally, I understand that,
> even if the payroll table is encrypted, this does nothing to protect labor
> rate information that may be stored in tables related to job management.
>
> I welcome additional comments.
>
> Regards,
> Scott
>
> -----Original Message-----
> From: Joe Konecny [mailto:jkonecn@...]
> Sent: Thursday, February 22, 2001 8:19 AM
> To: vantage@yahoogroups.com
> Subject: Re: [Vantage] Vantage security and ODBC
>
> The whole database is wide open with ODBC including payroll. Also
> consider that v5 installs odbc by default on each workstation
> like it or not. All they need is the host name, database name
> and the port number. That info is easy to get. So really any user
> anywhere can use ODBC and get at payroll or any other table.
>
> That said... I'm very glad ODBC access is there and fortunately
> none of our users know anything about ODBC.
>
> Troy Funte wrote:
> >
> > What I've heard on the list before, is that you want Access to have Read
> only links. Otherwise there is the risk of Access changing Vantage data in a
> compromising way - meaning there are no checks and balances and data could
> be corrupted. The SAFEST way to use Access is to import it from an exported
> file. By linking directly through ODBC, it would be hard, in my opinion to
> maintain any kind of security on the database. A user could corrupt the
> database, or have access to confidential information such as payroll stuff.
> >
> > I'm no expert, but these are some of the things I've heard. There are
> probably others on the list who could give you more detail.
> >
> > Troy Funte
> > Liberty Electronics
> > ----- Original Message -----
> > From: Lepley, Scott A.
> > To: Vantage YahooGroup (E-mail)
> > Cc: O'Rourke, Kevin P.
> > Sent: Wednesday, February 21, 2001 4:45 PM
> > Subject: [Vantage] Vantage security and ODBC
> >
> > I'm sure this has been discussed previously, but I sure would appreciate
> it
> > if some users would be willing to respond again regarding this issue.
> >
> > The situation here at this company is the following. The Customer
> Service
> > Supervisor here is knowledgeable about databases. He is currently
> > developing a customer service application in Microsoft Access and wishes
> to
> > establish connections between Access and Vantage using ODBC
> functionality.
> > I am the person responsible for coordinating the company's use of
> Vantage.
> > I have no control over the application development. I am uncomfortable
> > providing this functionality because of security concerns. As far as I
> > know, if I implement ODBC, it will allow access to all of the Progress
> > tables, except payroll, and thereby circumvent the access controls
> > established in Vantage. Everything that I have been able to learn so
> far
> > about this issue seems to confirm my concern. If my concern is
> legitimate,
> > are there any ways to mitigate this security risk?
> >
> > Regards,
> > Scott A. Lepley
> > Systems Administrator
> > Mauell Corporation
> > 31 Old Cabin Hollow Road
> > Dillsburg PA 17019-8815
> > Phone: 717-432-8686, ext. 14
> > Fax: 717-432-8688
> > Email: sal@...
> >
> > [Non-text portions of this message have been removed]
> >
> > Yahoo! Groups Sponsor
> >
> > Click here for Classmates.com
> >
> >
> > To unsubscribe from this group, send an email to:
> > vantage-unsubscribe@egroups.com
> >
> > Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service.
> >
> > [Non-text portions of this message have been removed]
> >
> >
> > To unsubscribe from this group, send an email to:
> > vantage-unsubscribe@egroups.com
> >
> >
> >
> > Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
> <http://docs.yahoo.com/info/terms/>
>
> Yahoo! Groups Sponsor
>
>
> <http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=1700007183:N/
> A=524804/*http://www.classmates.com/index.tf?s=2629> Classmates.com
> Click here for Classmates.com
>
>
> <http://us.adserver.yahoo.com/l?M=163100.1330039.2920210.2/D=egroupmail/S=17
> 00007183:N/A=524804/rand=582186115>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
> Your use of Yahoo! Groups is subject to the Yahoo!
> <http://docs.yahoo.com/info/terms/> Terms of Service.
>
> [Non-text portions of this message have been removed]
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
>
>
> Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
>only links. Otherwise there is the risk of Access changing Vantage data in a
> What I've heard on the list before, is that you want Access to have Read
>probably others on the list who could give you more detail.
> I'm no expert, but these are some of the things I've heard. There are
>it
> Troy Funte
> Liberty Electronics
> ----- Original Message -----
> From: Lepley, Scott A.
> To: Vantage YahooGroup (E-mail)
> Cc: O'Rourke, Kevin P.
> Sent: Wednesday, February 21, 2001 4:45 PM
> Subject: [Vantage] Vantage security and ODBC
>
> I'm sure this has been discussed previously, but I sure would appreciate
> if some users would be willing to respond again regarding this issue.Service
>
> The situation here at this company is the following. The Customer
> Supervisor here is knowledgeable about databases. He is currentlyto
> developing a customer service application in Microsoft Access and wishes
> establish connections between Access and Vantage using ODBCfunctionality.
> I am the person responsible for coordinating the company's use ofVantage.
> I have no control over the application development. I am uncomfortablefar
> providing this functionality because of security concerns. As far as I
> know, if I implement ODBC, it will allow access to all of the Progress
> tables, except payroll, and thereby circumvent the access controls
> established in Vantage. Everything that I have been able to learn so
> about this issue seems to confirm my concern. If my concern islegitimate,
> are there any ways to mitigate this security risk?<http://docs.yahoo.com/info/terms/>
>
> Regards,
> Scott A. Lepley
> Systems Administrator
> Mauell Corporation
> 31 Old Cabin Hollow Road
> Dillsburg PA 17019-8815
> Phone: 717-432-8686, ext. 14
> Fax: 717-432-8688
> Email: sal@...
>
> [Non-text portions of this message have been removed]
>
> Yahoo! Groups Sponsor
>
> Click here for Classmates.com
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
> Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service.
>
> [Non-text portions of this message have been removed]
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
>
>
> Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
>A=524804/* http://www.classmates.com/index.tf?s=2629
>00007183:N/A=524804/rand=582186115>
> The payroll tables are not accessible via ODBC in v4. I haven't tried this
> with v5 yet. I view it just a little irresponsible, on Epicor's part, to
> leave a corporate wide system wide open like this. Nothing gets the blood
> boiling like everyone in the company finding out where the money goes and
> who gets how much of it.
>
> Ted Kitch
> ted@...
>
> -----Original Message-----
> From: Lepley, Scott A. [mailto:sal@...]
> Sent: Thursday, February 22, 2001 7:59 AM
> To: 'vantage@yahoogroups.com'
> Subject: RE: [Vantage] Vantage security and ODBC
>
> Thanks for the reply, Joe. I should have mentioned that we are using
> version 3.00.632. Regarding payroll, I understood that the payroll table
> was encrypted and therefore could be read only through Vantage. Was this
> true in ver. 3 and now isn't in ver. 5? Additionally, I understand that,
> even if the payroll table is encrypted, this does nothing to protect labor
> rate information that may be stored in tables related to job management.
>
> I welcome additional comments.
>
> Regards,
> Scott
>
> -----Original Message-----
> From: Joe Konecny [mailto:jkonecn@...]
> Sent: Thursday, February 22, 2001 8:19 AM
> To: vantage@yahoogroups.com
> Subject: Re: [Vantage] Vantage security and ODBC
>
> The whole database is wide open with ODBC including payroll. Also
> consider that v5 installs odbc by default on each workstation
> like it or not. All they need is the host name, database name
> and the port number. That info is easy to get. So really any user
> anywhere can use ODBC and get at payroll or any other table.
>
> That said... I'm very glad ODBC access is there and fortunately
> none of our users know anything about ODBC.
>
> Troy Funte wrote:
> >
> > What I've heard on the list before, is that you want Access to have Read
> only links. Otherwise there is the risk of Access changing Vantage data in a
> compromising way - meaning there are no checks and balances and data could
> be corrupted. The SAFEST way to use Access is to import it from an exported
> file. By linking directly through ODBC, it would be hard, in my opinion to
> maintain any kind of security on the database. A user could corrupt the
> database, or have access to confidential information such as payroll stuff.
> >
> > I'm no expert, but these are some of the things I've heard. There are
> probably others on the list who could give you more detail.
> >
> > Troy Funte
> > Liberty Electronics
> > ----- Original Message -----
> > From: Lepley, Scott A.
> > To: Vantage YahooGroup (E-mail)
> > Cc: O'Rourke, Kevin P.
> > Sent: Wednesday, February 21, 2001 4:45 PM
> > Subject: [Vantage] Vantage security and ODBC
> >
> > I'm sure this has been discussed previously, but I sure would appreciate
> it
> > if some users would be willing to respond again regarding this issue.
> >
> > The situation here at this company is the following. The Customer
> Service
> > Supervisor here is knowledgeable about databases. He is currently
> > developing a customer service application in Microsoft Access and wishes
> to
> > establish connections between Access and Vantage using ODBC
> functionality.
> > I am the person responsible for coordinating the company's use of
> Vantage.
> > I have no control over the application development. I am uncomfortable
> > providing this functionality because of security concerns. As far as I
> > know, if I implement ODBC, it will allow access to all of the Progress
> > tables, except payroll, and thereby circumvent the access controls
> > established in Vantage. Everything that I have been able to learn so
> far
> > about this issue seems to confirm my concern. If my concern is
> legitimate,
> > are there any ways to mitigate this security risk?
> >
> > Regards,
> > Scott A. Lepley
> > Systems Administrator
> > Mauell Corporation
> > 31 Old Cabin Hollow Road
> > Dillsburg PA 17019-8815
> > Phone: 717-432-8686, ext. 14
> > Fax: 717-432-8688
> > Email: sal@...
> >
> > [Non-text portions of this message have been removed]
> >
> > Yahoo! Groups Sponsor
> >
> > Click here for Classmates.com
> >
> >
> > To unsubscribe from this group, send an email to:
> > vantage-unsubscribe@egroups.com
> >
> > Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service.
> >
> > [Non-text portions of this message have been removed]
> >
> >
> > To unsubscribe from this group, send an email to:
> > vantage-unsubscribe@egroups.com
> >
> >
> >
> > Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
> <http://docs.yahoo.com/info/terms/>
> < http://docs.yahoo.com/info/terms/ <http://docs.yahoo.com/info/terms/> >
>
> Yahoo! Groups Sponsor
>
> <
> http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=1700007183:N/
> <http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=1700007183:N/
> >
> A=524804/* http://www.classmates.com/index.tf?s=2629
> <http://www.classmates.com/index.tf?s=2629> > Classmates.com
> Click here for Classmates.com
>
> <
> http://us.adserver.yahoo.com/l?M=163100.1330039.2920210.2/D=egroupmail/S=17
> <http://us.adserver.yahoo.com/l?M=163100.1330039.2920210.2/D=egroupmail/S=17
> >
> 00007183:N/A=524804/rand=582186115>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
> Your use of Yahoo! Groups is subject to the Yahoo!
> < http://docs.yahoo.com/info/terms/ <http://docs.yahoo.com/info/terms/> >
> Terms of Service.
>
> [Non-text portions of this message have been removed]
>
> Yahoo! Groups Sponsor
>
>
> <http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=1700007183:N/
> A=524804/*http://www.classmates.com/index.tf?s=2629> Classmates.com
> Click here for Classmates.com
>
>
> <http://us.adserver.yahoo.com/l?M=163100.1330039.2920210.2/D=egroupmail/S=17
> 00007183:N/A=524804/rand=801979269>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
> Your use of Yahoo! Groups is subject to the Yahoo!
> <http://docs.yahoo.com/info/terms/> Terms of Service.
>
> [Non-text portions of this message have been removed]
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
>
>
> Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
>only links. Otherwise there is the risk of Access changing Vantage data in a
> What I've heard on the list before, is that you want Access to have Read
>probably others on the list who could give you more detail.
> I'm no expert, but these are some of the things I've heard. There are
>it
> Troy Funte
> Liberty Electronics
> ----- Original Message -----
> From: Lepley, Scott A.
> To: Vantage YahooGroup (E-mail)
> Cc: O'Rourke, Kevin P.
> Sent: Wednesday, February 21, 2001 4:45 PM
> Subject: [Vantage] Vantage security and ODBC
>
> I'm sure this has been discussed previously, but I sure would appreciate
> if some users would be willing to respond again regarding this issue.Service
>
> The situation here at this company is the following. The Customer
> Supervisor here is knowledgeable about databases. He is currentlyto
> developing a customer service application in Microsoft Access and wishes
> establish connections between Access and Vantage using ODBCfunctionality.
> I am the person responsible for coordinating the company's use ofVantage.
> I have no control over the application development. I am uncomfortablefar
> providing this functionality because of security concerns. As far as I
> know, if I implement ODBC, it will allow access to all of the Progress
> tables, except payroll, and thereby circumvent the access controls
> established in Vantage. Everything that I have been able to learn so
> about this issue seems to confirm my concern. If my concern islegitimate,
> are there any ways to mitigate this security risk?<http://docs.yahoo.com/info/terms/>
>
> Regards,
> Scott A. Lepley
> Systems Administrator
> Mauell Corporation
> 31 Old Cabin Hollow Road
> Dillsburg PA 17019-8815
> Phone: 717-432-8686, ext. 14
> Fax: 717-432-8688
> Email: sal@...
>
> [Non-text portions of this message have been removed]
>
> Yahoo! Groups Sponsor
>
> Click here for Classmates.com
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
> Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service.
>
> [Non-text portions of this message have been removed]
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
>
>
> Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
>A=524804/* http://www.classmates.com/index.tf?s=2629
>00007183:N/A=524804/rand=582186115>
>ml?kbid=14081> Epicor uses their own security in Vantage. I believe that
>only links. Otherwise there is the risk of Access changing Vantage data in a
> What I've heard on the list before, is that you want Access to have Read
>probably others on the list who could give you more detail.
> I'm no expert, but these are some of the things I've heard. There are
>it
> Troy Funte
> Liberty Electronics
> ----- Original Message -----
> From: Lepley, Scott A.
> To: Vantage YahooGroup (E-mail)
> Cc: O'Rourke, Kevin P.
> Sent: Wednesday, February 21, 2001 4:45 PM
> Subject: [Vantage] Vantage security and ODBC
>
> I'm sure this has been discussed previously, but I sure would appreciate
> if some users would be willing to respond again regarding this issue.Service
>
> The situation here at this company is the following. The Customer
> Supervisor here is knowledgeable about databases. He is currentlyto
> developing a customer service application in Microsoft Access and wishes
> establish connections between Access and Vantage using ODBCfunctionality.
> I am the person responsible for coordinating the company's use ofVantage.
> I have no control over the application development. I am uncomfortablefar
> providing this functionality because of security concerns. As far as I
> know, if I implement ODBC, it will allow access to all of the Progress
> tables, except payroll, and thereby circumvent the access controls
> established in Vantage. Everything that I have been able to learn so
> about this issue seems to confirm my concern. If my concern islegitimate,
> are there any ways to mitigate this security risk?<http://docs.yahoo.com/info/terms/>
>
> Regards,
> Scott A. Lepley
> Systems Administrator
> Mauell Corporation
> 31 Old Cabin Hollow Road
> Dillsburg PA 17019-8815
> Phone: 717-432-8686, ext. 14
> Fax: 717-432-8688
> Email: sal@...
>
> [Non-text portions of this message have been removed]
>
> Yahoo! Groups Sponsor
>
> Click here for Classmates.com
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
> Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service.
>
> [Non-text portions of this message have been removed]
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
>
>
> Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
><
>A=524804/* http://www.classmates.com/index.tf?s=2629
>
><
>00007183:N/A=524804/rand=582186115>
>
>A=524804/* http://www.classmates.com/index.tf?s=2629
>00007183:N/A=524804/rand=801979269>
> In my estimation, it's my responsibility (not Epicor's) to make sure the
> system is not wide open to the users. They have implemented their own
> security in their own application, and provided the necessary tools to
> administer it from and IS/IT admin. We (their customers) have demanded the
> ability to access the data via ODBC. Maybe we should be careful what we ask
> for. After all, it's up to us to either install or not install the drivers
> on the workstations. In Scott's case, I understand that the company is
> pushing it on him. But isn't this a management responsibility within his
> company, and not really reflective of Epicor?
>
> -----Original Message-----
> From: Ted Kitch [mailto:ted@...]
> Sent: Thursday, February 22, 2001 7:32 AM
> To: 'vantage@yahoogroups.com'
> Subject: RE: [Vantage] Vantage security and ODBC
>
> There really isn't a lot that can be done regarding security using ODBC.
> ODBC was setup to use the database security of the DBMS itself. Here is a
> KB article from Progress regarding security -
> http://www.progress.com/services/support/cgi-bin/techweb-kbase.cgi/webkb.htm
> l?kbid=14081
> <http://www.progress.com/services/support/cgi-bin/techweb-kbase.cgi/webkb.ht
> ml?kbid=14081> Epicor uses their own security in Vantage. I believe that
> you could implement Progress database security, but then everyone would have
> to log on twice to access Vantage, once into Progress and once into Vantage.
>
>
> The payroll tables are not accessible via ODBC in v4. I haven't tried this
> with v5 yet. I view it just a little irresponsible, on Epicor's part, to
> leave a corporate wide system wide open like this. Nothing gets the blood
> boiling like everyone in the company finding out where the money goes and
> who gets how much of it.
>
> Ted Kitch
> ted@...
>
> -----Original Message-----
> From: Lepley, Scott A. [mailto:sal@...]
> Sent: Thursday, February 22, 2001 7:59 AM
> To: 'vantage@yahoogroups.com'
> Subject: RE: [Vantage] Vantage security and ODBC
>
> Thanks for the reply, Joe. I should have mentioned that we are using
> version 3.00.632. Regarding payroll, I understood that the payroll table
> was encrypted and therefore could be read only through Vantage. Was this
> true in ver. 3 and now isn't in ver. 5? Additionally, I understand that,
> even if the payroll table is encrypted, this does nothing to protect labor
> rate information that may be stored in tables related to job management.
>
> I welcome additional comments.
>
> Regards,
> Scott
>
> -----Original Message-----
> From: Joe Konecny [mailto:jkonecn@...]
> Sent: Thursday, February 22, 2001 8:19 AM
> To: vantage@yahoogroups.com
> Subject: Re: [Vantage] Vantage security and ODBC
>
> The whole database is wide open with ODBC including payroll. Also
> consider that v5 installs odbc by default on each workstation
> like it or not. All they need is the host name, database name
> and the port number. That info is easy to get. So really any user
> anywhere can use ODBC and get at payroll or any other table.
>
> That said... I'm very glad ODBC access is there and fortunately
> none of our users know anything about ODBC.
>
> Troy Funte wrote:
> >
> > What I've heard on the list before, is that you want Access to have Read
> only links. Otherwise there is the risk of Access changing Vantage data in a
> compromising way - meaning there are no checks and balances and data could
> be corrupted. The SAFEST way to use Access is to import it from an exported
> file. By linking directly through ODBC, it would be hard, in my opinion to
> maintain any kind of security on the database. A user could corrupt the
> database, or have access to confidential information such as payroll stuff.
> >
> > I'm no expert, but these are some of the things I've heard. There are
> probably others on the list who could give you more detail.
> >
> > Troy Funte
> > Liberty Electronics
> > ----- Original Message -----
> > From: Lepley, Scott A.
> > To: Vantage YahooGroup (E-mail)
> > Cc: O'Rourke, Kevin P.
> > Sent: Wednesday, February 21, 2001 4:45 PM
> > Subject: [Vantage] Vantage security and ODBC
> >
> > I'm sure this has been discussed previously, but I sure would appreciate
> it
> > if some users would be willing to respond again regarding this issue.
> >
> > The situation here at this company is the following. The Customer
> Service
> > Supervisor here is knowledgeable about databases. He is currently
> > developing a customer service application in Microsoft Access and wishes
> to
> > establish connections between Access and Vantage using ODBC
> functionality.
> > I am the person responsible for coordinating the company's use of
> Vantage.
> > I have no control over the application development. I am uncomfortable
> > providing this functionality because of security concerns. As far as I
> > know, if I implement ODBC, it will allow access to all of the Progress
> > tables, except payroll, and thereby circumvent the access controls
> > established in Vantage. Everything that I have been able to learn so
> far
> > about this issue seems to confirm my concern. If my concern is
> legitimate,
> > are there any ways to mitigate this security risk?
> >
> > Regards,
> > Scott A. Lepley
> > Systems Administrator
> > Mauell Corporation
> > 31 Old Cabin Hollow Road
> > Dillsburg PA 17019-8815
> > Phone: 717-432-8686, ext. 14
> > Fax: 717-432-8688
> > Email: sal@...
> >
> > [Non-text portions of this message have been removed]
> >
> > Yahoo! Groups Sponsor
> >
> > Click here for Classmates.com
> >
> >
> > To unsubscribe from this group, send an email to:
> > vantage-unsubscribe@egroups.com
> >
> > Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service.
> >
> > [Non-text portions of this message have been removed]
> >
> >
> > To unsubscribe from this group, send an email to:
> > vantage-unsubscribe@egroups.com
> >
> >
> >
> > Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
> <http://docs.yahoo.com/info/terms/>
> < http://docs.yahoo.com/info/terms/ <http://docs.yahoo.com/info/terms/> >
>
> Yahoo! Groups Sponsor
>
> <
> http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=1700007183:N/
> <http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=1700007183:N/
> >
> A=524804/* http://www.classmates.com/index.tf?s=2629
> <http://www.classmates.com/index.tf?s=2629> > Classmates.com
> Click here for Classmates.com
>
> <
> http://us.adserver.yahoo.com/l?M=163100.1330039.2920210.2/D=egroupmail/S=17
> <http://us.adserver.yahoo.com/l?M=163100.1330039.2920210.2/D=egroupmail/S=17
> >
> 00007183:N/A=524804/rand=582186115>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
> Your use of Yahoo! Groups is subject to the Yahoo!
> < http://docs.yahoo.com/info/terms/ <http://docs.yahoo.com/info/terms/> >
> Terms of Service.
>
> [Non-text portions of this message have been removed]
>
> Yahoo! Groups Sponsor
>
>
> <http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=1700007183:N/
> A=524804/*http://www.classmates.com/index.tf?s=2629> Classmates.com
> Click here for Classmates.com
>
>
> <http://us.adserver.yahoo.com/l?M=163100.1330039.2920210.2/D=egroupmail/S=17
> 00007183:N/A=524804/rand=801979269>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
> Your use of Yahoo! Groups is subject to the Yahoo!
> <http://docs.yahoo.com/info/terms/> Terms of Service.
>
> [Non-text portions of this message have been removed]
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
>
>
> Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
>
>
> Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
>
> Brian,
>
> If I read correctly, the ODBC in emanufacturing version 5.0 is automatically
> installed on your client. You do not have a choice. I have not verified this.
> But can someone running 5.0 verify? - If this is the case I will think twice
> about going live with 5.0 until there is better security.
>
> Best Regards,
> Dina
>
> Brian Davis wrote:
>
> > In my estimation, it's my responsibility (not Epicor's) to make sure the
> > system is not wide open to the users. They have implemented their own
> > security in their own application, and provided the necessary tools to
> > administer it from and IS/IT admin. We (their customers) have demanded the
> > ability to access the data via ODBC. Maybe we should be careful what we ask
> > for. After all, it's up to us to either install or not install the drivers
> > on the workstations. In Scott's case, I understand that the company is
> > pushing it on him. But isn't this a management responsibility within his
> > company, and not really reflective of Epicor?
> >
> > -----Original Message-----
> > From: Ted Kitch [mailto:ted@...]
> > Sent: Thursday, February 22, 2001 7:32 AM
> > To: 'vantage@yahoogroups.com'
> > Subject: RE: [Vantage] Vantage security and ODBC
> >
> > There really isn't a lot that can be done regarding security using ODBC.
> > ODBC was setup to use the database security of the DBMS itself. Here is a
> > KB article from Progress regarding security -
> > http://www.progress.com/services/support/cgi-bin/techweb-kbase.cgi/webkb.htm
> > l?kbid=14081
> > <http://www.progress.com/services/support/cgi-bin/techweb-kbase.cgi/webkb.ht
> > ml?kbid=14081> Epicor uses their own security in Vantage. I believe that
> > you could implement Progress database security, but then everyone would have
> > to log on twice to access Vantage, once into Progress and once into Vantage.
> >
> >
> > The payroll tables are not accessible via ODBC in v4. I haven't tried this
> > with v5 yet. I view it just a little irresponsible, on Epicor's part, to
> > leave a corporate wide system wide open like this. Nothing gets the blood
> > boiling like everyone in the company finding out where the money goes and
> > who gets how much of it.
> >
> > Ted Kitch
> > ted@...
> >
> > -----Original Message-----
> > From: Lepley, Scott A. [mailto:sal@...]
> > Sent: Thursday, February 22, 2001 7:59 AM
> > To: 'vantage@yahoogroups.com'
> > Subject: RE: [Vantage] Vantage security and ODBC
> >
> > Thanks for the reply, Joe. I should have mentioned that we are using
> > version 3.00.632. Regarding payroll, I understood that the payroll table
> > was encrypted and therefore could be read only through Vantage. Was this
> > true in ver. 3 and now isn't in ver. 5? Additionally, I understand that,
> > even if the payroll table is encrypted, this does nothing to protect labor
> > rate information that may be stored in tables related to job management.
> >
> > I welcome additional comments.
> >
> > Regards,
> > Scott
> >
> > -----Original Message-----
> > From: Joe Konecny [mailto:jkonecn@...]
> > Sent: Thursday, February 22, 2001 8:19 AM
> > To: vantage@yahoogroups.com
> > Subject: Re: [Vantage] Vantage security and ODBC
> >
> > The whole database is wide open with ODBC including payroll. Also
> > consider that v5 installs odbc by default on each workstation
> > like it or not. All they need is the host name, database name
> > and the port number. That info is easy to get. So really any user
> > anywhere can use ODBC and get at payroll or any other table.
> >
> > That said... I'm very glad ODBC access is there and fortunately
> > none of our users know anything about ODBC.
> >
> > Troy Funte wrote:
> > >
> > > What I've heard on the list before, is that you want Access to have Read
> > only links. Otherwise there is the risk of Access changing Vantage data in a
> > compromising way - meaning there are no checks and balances and data could
> > be corrupted. The SAFEST way to use Access is to import it from an exported
> > file. By linking directly through ODBC, it would be hard, in my opinion to
> > maintain any kind of security on the database. A user could corrupt the
> > database, or have access to confidential information such as payroll stuff.
> > >
> > > I'm no expert, but these are some of the things I've heard. There are
> > probably others on the list who could give you more detail.
> > >
> > > Troy Funte
> > > Liberty Electronics
> > > ----- Original Message -----
> > > From: Lepley, Scott A.
> > > To: Vantage YahooGroup (E-mail)
> > > Cc: O'Rourke, Kevin P.
> > > Sent: Wednesday, February 21, 2001 4:45 PM
> > > Subject: [Vantage] Vantage security and ODBC
> > >
> > > I'm sure this has been discussed previously, but I sure would appreciate
> > it
> > > if some users would be willing to respond again regarding this issue.
> > >
> > > The situation here at this company is the following. The Customer
> > Service
> > > Supervisor here is knowledgeable about databases. He is currently
> > > developing a customer service application in Microsoft Access and wishes
> > to
> > > establish connections between Access and Vantage using ODBC
> > functionality.
> > > I am the person responsible for coordinating the company's use of
> > Vantage.
> > > I have no control over the application development. I am uncomfortable
> > > providing this functionality because of security concerns. As far as I
> > > know, if I implement ODBC, it will allow access to all of the Progress
> > > tables, except payroll, and thereby circumvent the access controls
> > > established in Vantage. Everything that I have been able to learn so
> > far
> > > about this issue seems to confirm my concern. If my concern is
> > legitimate,
> > > are there any ways to mitigate this security risk?
> > >
> > > Regards,
> > > Scott A. Lepley
> > > Systems Administrator
> > > Mauell Corporation
> > > 31 Old Cabin Hollow Road
> > > Dillsburg PA 17019-8815
> > > Phone: 717-432-8686, ext. 14
> > > Fax: 717-432-8688
> > > Email: sal@...
> > >
> > > [Non-text portions of this message have been removed]
> > >
> > > Yahoo! Groups Sponsor
> > >
> > > Click here for Classmates.com
> > >
> > >
> > > To unsubscribe from this group, send an email to:
> > > vantage-unsubscribe@egroups.com
> > >
> > > Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service.
> > >
> > > [Non-text portions of this message have been removed]
> > >
> > >
> > > To unsubscribe from this group, send an email to:
> > > vantage-unsubscribe@egroups.com
> > >
> > >
> > >
> > > Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
> > <http://docs.yahoo.com/info/terms/>
> > < http://docs.yahoo.com/info/terms/ <http://docs.yahoo.com/info/terms/> >
> >
> > Yahoo! Groups Sponsor
> >
> > <
> > http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=1700007183:N/
> > <http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=1700007183:N/
> > >
> > A=524804/* http://www.classmates.com/index.tf?s=2629
> > <http://www.classmates.com/index.tf?s=2629> > Classmates.com
> > Click here for Classmates.com
> >
> > <
> > http://us.adserver.yahoo.com/l?M=163100.1330039.2920210.2/D=egroupmail/S=17
> > <http://us.adserver.yahoo.com/l?M=163100.1330039.2920210.2/D=egroupmail/S=17
> > >
> > 00007183:N/A=524804/rand=582186115>
> >
> > To unsubscribe from this group, send an email to:
> > vantage-unsubscribe@egroups.com
> >
> > Your use of Yahoo! Groups is subject to the Yahoo!
> > < http://docs.yahoo.com/info/terms/ <http://docs.yahoo.com/info/terms/> >
> > Terms of Service.
> >
> > [Non-text portions of this message have been removed]
> >
> > Yahoo! Groups Sponsor
> >
> >
> > <http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=1700007183:N/
> > A=524804/*http://www.classmates.com/index.tf?s=2629> Classmates.com
> > Click here for Classmates.com
> >
> >
> > <http://us.adserver.yahoo.com/l?M=163100.1330039.2920210.2/D=egroupmail/S=17
> > 00007183:N/A=524804/rand=801979269>
> >
> > To unsubscribe from this group, send an email to:
> > vantage-unsubscribe@egroups.com
> >
> > Your use of Yahoo! Groups is subject to the Yahoo!
> > <http://docs.yahoo.com/info/terms/> Terms of Service.
> >
> > [Non-text portions of this message have been removed]
> >
> > To unsubscribe from this group, send an email to:
> > vantage-unsubscribe@egroups.com
> >
> >
> >
> > Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
> >
> >
> > To unsubscribe from this group, send an email to:
> > vantage-unsubscribe@egroups.com
> >
> >
> >
> > Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
>
>
> Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
>
> It's installed by default. Don't expect much to change in
> security though.
>
> Dina Hieber wrote:
> >
> > Brian,
> >
> > If I read correctly, the ODBC in emanufacturing version 5.0 is automatically
> > installed on your client. You do not have a choice. I have not verified this.
> > But can someone running 5.0 verify? - If this is the case I will think twice
> > about going live with 5.0 until there is better security.
> >
> > Best Regards,
> > Dina
> >
> > Brian Davis wrote:
> >
> > > In my estimation, it's my responsibility (not Epicor's) to make sure the
> > > system is not wide open to the users. They have implemented their own
> > > security in their own application, and provided the necessary tools to
> > > administer it from and IS/IT admin. We (their customers) have demanded the
> > > ability to access the data via ODBC. Maybe we should be careful what we ask
> > > for. After all, it's up to us to either install or not install the drivers
> > > on the workstations. In Scott's case, I understand that the company is
> > > pushing it on him. But isn't this a management responsibility within his
> > > company, and not really reflective of Epicor?
> > >
> > > -----Original Message-----
> > > From: Ted Kitch [mailto:ted@...]
> > > Sent: Thursday, February 22, 2001 7:32 AM
> > > To: 'vantage@yahoogroups.com'
> > > Subject: RE: [Vantage] Vantage security and ODBC
> > >
> > > There really isn't a lot that can be done regarding security using ODBC.
> > > ODBC was setup to use the database security of the DBMS itself. Here is a
> > > KB article from Progress regarding security -
> > > http://www.progress.com/services/support/cgi-bin/techweb-kbase.cgi/webkb.htm
> > > l?kbid=14081
> > > <http://www.progress.com/services/support/cgi-bin/techweb-kbase.cgi/webkb.ht
> > > ml?kbid=14081> Epicor uses their own security in Vantage. I believe that
> > > you could implement Progress database security, but then everyone would have
> > > to log on twice to access Vantage, once into Progress and once into Vantage.
> > >
> > >
> > > The payroll tables are not accessible via ODBC in v4. I haven't tried this
> > > with v5 yet. I view it just a little irresponsible, on Epicor's part, to
> > > leave a corporate wide system wide open like this. Nothing gets the blood
> > > boiling like everyone in the company finding out where the money goes and
> > > who gets how much of it.
> > >
> > > Ted Kitch
> > > ted@...
> > >
> > > -----Original Message-----
> > > From: Lepley, Scott A. [mailto:sal@...]
> > > Sent: Thursday, February 22, 2001 7:59 AM
> > > To: 'vantage@yahoogroups.com'
> > > Subject: RE: [Vantage] Vantage security and ODBC
> > >
> > > Thanks for the reply, Joe. I should have mentioned that we are using
> > > version 3.00.632. Regarding payroll, I understood that the payroll table
> > > was encrypted and therefore could be read only through Vantage. Was this
> > > true in ver. 3 and now isn't in ver. 5? Additionally, I understand that,
> > > even if the payroll table is encrypted, this does nothing to protect labor
> > > rate information that may be stored in tables related to job management.
> > >
> > > I welcome additional comments.
> > >
> > > Regards,
> > > Scott
> > >
> > > -----Original Message-----
> > > From: Joe Konecny [mailto:jkonecn@...]
> > > Sent: Thursday, February 22, 2001 8:19 AM
> > > To: vantage@yahoogroups.com
> > > Subject: Re: [Vantage] Vantage security and ODBC
> > >
> > > The whole database is wide open with ODBC including payroll. Also
> > > consider that v5 installs odbc by default on each workstation
> > > like it or not. All they need is the host name, database name
> > > and the port number. That info is easy to get. So really any user
> > > anywhere can use ODBC and get at payroll or any other table.
> > >
> > > That said... I'm very glad ODBC access is there and fortunately
> > > none of our users know anything about ODBC.
> > >
> > > Troy Funte wrote:
> > > >
> > > > What I've heard on the list before, is that you want Access to have Read
> > > only links. Otherwise there is the risk of Access changing Vantage data in a
> > > compromising way - meaning there are no checks and balances and data could
> > > be corrupted. The SAFEST way to use Access is to import it from an exported
> > > file. By linking directly through ODBC, it would be hard, in my opinion to
> > > maintain any kind of security on the database. A user could corrupt the
> > > database, or have access to confidential information such as payroll stuff.
> > > >
> > > > I'm no expert, but these are some of the things I've heard. There are
> > > probably others on the list who could give you more detail.
> > > >
> > > > Troy Funte
> > > > Liberty Electronics
> > > > ----- Original Message -----
> > > > From: Lepley, Scott A.
> > > > To: Vantage YahooGroup (E-mail)
> > > > Cc: O'Rourke, Kevin P.
> > > > Sent: Wednesday, February 21, 2001 4:45 PM
> > > > Subject: [Vantage] Vantage security and ODBC
> > > >
> > > > I'm sure this has been discussed previously, but I sure would appreciate
> > > it
> > > > if some users would be willing to respond again regarding this issue.
> > > >
> > > > The situation here at this company is the following. The Customer
> > > Service
> > > > Supervisor here is knowledgeable about databases. He is currently
> > > > developing a customer service application in Microsoft Access and wishes
> > > to
> > > > establish connections between Access and Vantage using ODBC
> > > functionality.
> > > > I am the person responsible for coordinating the company's use of
> > > Vantage.
> > > > I have no control over the application development. I am uncomfortable
> > > > providing this functionality because of security concerns. As far as I
> > > > know, if I implement ODBC, it will allow access to all of the Progress
> > > > tables, except payroll, and thereby circumvent the access controls
> > > > established in Vantage. Everything that I have been able to learn so
> > > far
> > > > about this issue seems to confirm my concern. If my concern is
> > > legitimate,
> > > > are there any ways to mitigate this security risk?
> > > >
> > > > Regards,
> > > > Scott A. Lepley
> > > > Systems Administrator
> > > > Mauell Corporation
> > > > 31 Old Cabin Hollow Road
> > > > Dillsburg PA 17019-8815
> > > > Phone: 717-432-8686, ext. 14
> > > > Fax: 717-432-8688
> > > > Email: sal@...
> > > >
> > > > [Non-text portions of this message have been removed]
> > > >
> > > > Yahoo! Groups Sponsor
> > > >
> > > > Click here for Classmates.com
> > > >
> > > >
> > > > To unsubscribe from this group, send an email to:
> > > > vantage-unsubscribe@egroups.com
> > > >
> > > > Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service.
> > > >
> > > > [Non-text portions of this message have been removed]
> > > >
> > > >
> > > > To unsubscribe from this group, send an email to:
> > > > vantage-unsubscribe@egroups.com
> > > >
> > > >
> > > >
> > > > Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
> > > <http://docs.yahoo.com/info/terms/>
> > > < http://docs.yahoo.com/info/terms/ <http://docs.yahoo.com/info/terms/> >
> > >
> > > Yahoo! Groups Sponsor
> > >
> > > <
> > > http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=1700007183:N/
> > > <http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=1700007183:N/
> > > >
> > > A=524804/* http://www.classmates.com/index.tf?s=2629
> > > <http://www.classmates.com/index.tf?s=2629> > Classmates.com
> > > Click here for Classmates.com
> > >
> > > <
> > > http://us.adserver.yahoo.com/l?M=163100.1330039.2920210.2/D=egroupmail/S=17
> > > <http://us.adserver.yahoo.com/l?M=163100.1330039.2920210.2/D=egroupmail/S=17
> > > >
> > > 00007183:N/A=524804/rand=582186115>
> > >
> > > To unsubscribe from this group, send an email to:
> > > vantage-unsubscribe@egroups.com
> > >
> > > Your use of Yahoo! Groups is subject to the Yahoo!
> > > < http://docs.yahoo.com/info/terms/ <http://docs.yahoo.com/info/terms/> >
> > > Terms of Service.
> > >
> > > [Non-text portions of this message have been removed]
> > >
> > > Yahoo! Groups Sponsor
> > >
> > >
> > > <http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=1700007183:N/
> > > A=524804/*http://www.classmates.com/index.tf?s=2629> Classmates.com
> > > Click here for Classmates.com
> > >
> > >
> > > <http://us.adserver.yahoo.com/l?M=163100.1330039.2920210.2/D=egroupmail/S=17
> > > 00007183:N/A=524804/rand=801979269>
> > >
> > > To unsubscribe from this group, send an email to:
> > > vantage-unsubscribe@egroups.com
> > >
> > > Your use of Yahoo! Groups is subject to the Yahoo!
> > > <http://docs.yahoo.com/info/terms/> Terms of Service.
> > >
> > > [Non-text portions of this message have been removed]
> > >
> > > To unsubscribe from this group, send an email to:
> > > vantage-unsubscribe@egroups.com
> > >
> > >
> > >
> > > Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
> > >
> > >
> > > To unsubscribe from this group, send an email to:
> > > vantage-unsubscribe@egroups.com
> > >
> > >
> > >
> > > Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
> >
> >
> > To unsubscribe from this group, send an email to:
> > vantage-unsubscribe@egroups.com
> >
> >
> >
> > Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
>
>
> Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
--- In vantage@y..., Dina Hieber <dhieber@v...> wrote:
> Brian,
>
> If I read correctly, the ODBC in emanufacturing version 5.0 is
automatically
> installed on your client. You do not have a choice. I have not
verified this.
> But can someone running 5.0 verify? - If this is the case I will
think twice
> about going live with 5.0 until there is better security.
>
> Best Regards,
> Dina
>
> Brian Davis wrote:
>
> > In my estimation, it's my responsibility (not Epicor's) to make
sure the
> > system is not wide open to the users. They have implemented
their own
> > security in their own application, and provided the necessary
tools to
> > administer it from and IS/IT admin. We (their customers) have
demanded the
> > ability to access the data via ODBC. Maybe we should be careful
what we ask
> > for. After all, it's up to us to either install or not install
the drivers
> > on the workstations. In Scott's case, I understand that the
company is
> > pushing it on him. But isn't this a management responsibility
within his
> > company, and not really reflective of Epicor?
> >
> > -----Original Message-----
> > From: Ted Kitch [mailto:ted@m...]
> > Sent: Thursday, February 22, 2001 7:32 AM
> > To: 'vantage@y...'
> > Subject: RE: [Vantage] Vantage security and ODBC
> >
> > There really isn't a lot that can be done regarding security
using ODBC.
> > ODBC was setup to use the database security of the DBMS itself.
Here is a
> > KB article from Progress regarding security -
> > http://www.progress.com/services/support/cgi-bin/techweb-
kbase.cgi/webkb.htm
> > l?kbid=14081
> > <http://www.progress.com/services/support/cgi-bin/techweb-
kbase.cgi/webkb.ht
> > ml?kbid=14081> Epicor uses their own security in Vantage. I
believe that
> > you could implement Progress database security, but then everyone
would have
> > to log on twice to access Vantage, once into Progress and once
into Vantage.
> >
> >
> > The payroll tables are not accessible via ODBC in v4. I haven't
tried this
> > with v5 yet. I view it just a little irresponsible, on Epicor's
part, to
> > leave a corporate wide system wide open like this. Nothing gets
the blood
> > boiling like everyone in the company finding out where the money
goes and
> > who gets how much of it.
> >
> > Ted Kitch
> > ted@m...
> >
> > -----Original Message-----
> > From: Lepley, Scott A. [mailto:sal@m...]
> > Sent: Thursday, February 22, 2001 7:59 AM
> > To: 'vantage@y...'
> > Subject: RE: [Vantage] Vantage security and ODBC
> >
> > Thanks for the reply, Joe. I should have mentioned that we are
using
> > version 3.00.632. Regarding payroll, I understood that the
payroll table
> > was encrypted and therefore could be read only through Vantage.
Was this
> > true in ver. 3 and now isn't in ver. 5? Additionally, I
understand that,
> > even if the payroll table is encrypted, this does nothing to
protect labor
> > rate information that may be stored in tables related to job
management.
> >
> > I welcome additional comments.
> >
> > Regards,
> > Scott
> >
> > -----Original Message-----
> > From: Joe Konecny [mailto:jkonecn@g...]
> > Sent: Thursday, February 22, 2001 8:19 AM
> > To: vantage@y...
> > Subject: Re: [Vantage] Vantage security and ODBC
> >
> > The whole database is wide open with ODBC including payroll. Also
> > consider that v5 installs odbc by default on each workstation
> > like it or not. All they need is the host name, database name
> > and the port number. That info is easy to get. So really any
user
> > anywhere can use ODBC and get at payroll or any other table.
> >
> > That said... I'm very glad ODBC access is there and fortunately
> > none of our users know anything about ODBC.
> >
> > Troy Funte wrote:
> > >
> > > What I've heard on the list before, is that you want Access to
have Read
> > only links. Otherwise there is the risk of Access changing
Vantage data in a
> > compromising way - meaning there are no checks and balances and
data could
> > be corrupted. The SAFEST way to use Access is to import it from
an exported
> > file. By linking directly through ODBC, it would be hard, in my
opinion to
> > maintain any kind of security on the database. A user could
corrupt the
> > database, or have access to confidential information such as
payroll stuff.
> > >
> > > I'm no expert, but these are some of the things I've heard.
There are
> > probably others on the list who could give you more detail.
> > >
> > > Troy Funte
> > > Liberty Electronics
> > > ----- Original Message -----
> > > From: Lepley, Scott A.
> > > To: Vantage YahooGroup (E-mail)
> > > Cc: O'Rourke, Kevin P.
> > > Sent: Wednesday, February 21, 2001 4:45 PM
> > > Subject: [Vantage] Vantage security and ODBC
> > >
> > > I'm sure this has been discussed previously, but I sure would
appreciate
> > it
> > > if some users would be willing to respond again regarding
this issue.
> > >
> > > The situation here at this company is the following. The
Customer
> > Service
> > > Supervisor here is knowledgeable about databases. He is
currently
> > > developing a customer service application in Microsoft Access
and wishes
> > to
> > > establish connections between Access and Vantage using ODBC
> > functionality.
> > > I am the person responsible for coordinating the company's
use of
> > Vantage.
> > > I have no control over the application development. I am
uncomfortable
> > > providing this functionality because of security concerns.
As far as I
> > > know, if I implement ODBC, it will allow access to all of the
Progress
> > > tables, except payroll, and thereby circumvent the access
controls
> > > established in Vantage. Everything that I have been able to
learn so
> > far
> > > about this issue seems to confirm my concern. If my concern
is
> > legitimate,
> > > are there any ways to mitigate this security risk?
> > >
> > > Regards,
> > > Scott A. Lepley
> > > Systems Administrator
> > > Mauell Corporation
> > > 31 Old Cabin Hollow Road
> > > Dillsburg PA 17019-8815
> > > Phone: 717-432-8686, ext. 14
> > > Fax: 717-432-8688
> > > Email: sal@m...
> > >
> > > [Non-text portions of this message have been removed]
> > >
> > > Yahoo! Groups Sponsor
> > >
> > > Click here for Classmates.com
> > >
> > >
> > > To unsubscribe from this group, send an email to:
> > > vantage-unsubscribe@egroups.com
> > >
> > > Your use of Yahoo! Groups is subject to the Yahoo! Terms of
Service.
> > >
> > > [Non-text portions of this message have been removed]
> > >
> > >
> > > To unsubscribe from this group, send an email to:
> > > vantage-unsubscribe@egroups.com
> > >
> > >
> > >
> > > Your use of Yahoo! Groups is subject to
http://docs.yahoo.com/info/terms/
> > <http://docs.yahoo.com/info/terms/>
> > < http://docs.yahoo.com/info/terms/
<http://docs.yahoo.com/info/terms/> >
> >
> > Yahoo! Groups Sponsor
> >
> > <
> >
http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=17000071
83:N/
> >
<http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=1700007
183:N/
> > >
> > A=524804/* http://www.classmates.com/index.tf?s=2629
> > <http://www.classmates.com/index.tf?s=2629> > Classmates.com
> > Click here for Classmates.com
> >
> > <
> > http://us.adserver.yahoo.com/l?
M=163100.1330039.2920210.2/D=egroupmail/S=17
> > <http://us.adserver.yahoo.com/l?
M=163100.1330039.2920210.2/D=egroupmail/S=17
> > >
> > 00007183:N/A=524804/rand=582186115>
> >
> > To unsubscribe from this group, send an email to:
> > vantage-unsubscribe@egroups.com
> >
> > Your use of Yahoo! Groups is subject to the Yahoo!
> > < http://docs.yahoo.com/info/terms/
<http://docs.yahoo.com/info/terms/> >
> > Terms of Service.
> >
> > [Non-text portions of this message have been removed]
> >
> > Yahoo! Groups Sponsor
> >
> >
> >
<http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=1700007
183:N/
> > A=524804/*http://www.classmates.com/index.tf?s=2629>
Classmates.com
> > Click here for Classmates.com
> >
> >
> > <http://us.adserver.yahoo.com/l?
M=163100.1330039.2920210.2/D=egroupmail/S=17
> > 00007183:N/A=524804/rand=801979269>
> >
> > To unsubscribe from this group, send an email to:
> > vantage-unsubscribe@egroups.com
> >
> > Your use of Yahoo! Groups is subject to the Yahoo!
> > <http://docs.yahoo.com/info/terms/> Terms of Service.
> >
> > [Non-text portions of this message have been removed]
> >
> > To unsubscribe from this group, send an email to:
> > vantage-unsubscribe@egroups.com
> >
> >
> >
> > Your use of Yahoo! Groups is subject to
http://docs.yahoo.com/info/terms/
> >
> >
> > To unsubscribe from this group, send an email to:
> > vantage-unsubscribe@egroups.com
> >
> >
> >
> > Your use of Yahoo! Groups is subject to
http://docs.yahoo.com/info/terms/
> In my estimation, it's my responsibility (not Epicor's) to make sure thethe
> system is not wide open to the users. They have implemented their own
> security in their own application, and provided the necessary tools to
> administer it from and IS/IT admin. We (their customers) have demanded
> ability to access the data via ODBC. Maybe we should be careful what weask
> for. After all, it's up to us to either install or not install thedrivers
> on the workstations. In Scott's case, I understand that the company ishttp://www.progress.com/services/support/cgi-bin/techweb-kbase.cgi/webkb.htm
> pushing it on him. But isn't this a management responsibility within his
> company, and not really reflective of Epicor?
>
> -----Original Message-----
> From: Ted Kitch [mailto:ted@...]
> Sent: Thursday, February 22, 2001 7:32 AM
> To: 'vantage@yahoogroups.com'
> Subject: RE: [Vantage] Vantage security and ODBC
>
> There really isn't a lot that can be done regarding security using ODBC.
> ODBC was setup to use the database security of the DBMS itself. Here is a
> KB article from Progress regarding security -
>
> l?kbid=14081<http://www.progress.com/services/support/cgi-bin/techweb-kbase.cgi/webkb.ht
>
> ml?kbid=14081> Epicor uses their own security in Vantage. I believe thathave
> you could implement Progress database security, but then everyone would
> to log on twice to access Vantage, once into Progress and once intoVantage.
>this
>
> The payroll tables are not accessible via ODBC in v4. I haven't tried
> with v5 yet. I view it just a little irresponsible, on Epicor's part, toa
> leave a corporate wide system wide open like this. Nothing gets the blood
> boiling like everyone in the company finding out where the money goes and
> who gets how much of it.
>
> Ted Kitch
> ted@...
>
> -----Original Message-----
> From: Lepley, Scott A. [mailto:sal@...]
> Sent: Thursday, February 22, 2001 7:59 AM
> To: 'vantage@yahoogroups.com'
> Subject: RE: [Vantage] Vantage security and ODBC
>
> Thanks for the reply, Joe. I should have mentioned that we are using
> version 3.00.632. Regarding payroll, I understood that the payroll table
> was encrypted and therefore could be read only through Vantage. Was this
> true in ver. 3 and now isn't in ver. 5? Additionally, I understand that,
> even if the payroll table is encrypted, this does nothing to protect labor
> rate information that may be stored in tables related to job management.
>
> I welcome additional comments.
>
> Regards,
> Scott
>
> -----Original Message-----
> From: Joe Konecny [mailto:jkonecn@...]
> Sent: Thursday, February 22, 2001 8:19 AM
> To: vantage@yahoogroups.com
> Subject: Re: [Vantage] Vantage security and ODBC
>
> The whole database is wide open with ODBC including payroll. Also
> consider that v5 installs odbc by default on each workstation
> like it or not. All they need is the host name, database name
> and the port number. That info is easy to get. So really any user
> anywhere can use ODBC and get at payroll or any other table.
>
> That said... I'm very glad ODBC access is there and fortunately
> none of our users know anything about ODBC.
>
> Troy Funte wrote:
> >
> > What I've heard on the list before, is that you want Access to have Read
> only links. Otherwise there is the risk of Access changing Vantage data in
> compromising way - meaning there are no checks and balances and data couldexported
> be corrupted. The SAFEST way to use Access is to import it from an
> file. By linking directly through ODBC, it would be hard, in my opinionto
> maintain any kind of security on the database. A user could corrupt thestuff.
> database, or have access to confidential information such as payroll
> >appreciate
> > I'm no expert, but these are some of the things I've heard. There are
> probably others on the list who could give you more detail.
> >
> > Troy Funte
> > Liberty Electronics
> > ----- Original Message -----
> > From: Lepley, Scott A.
> > To: Vantage YahooGroup (E-mail)
> > Cc: O'Rourke, Kevin P.
> > Sent: Wednesday, February 21, 2001 4:45 PM
> > Subject: [Vantage] Vantage security and ODBC
> >
> > I'm sure this has been discussed previously, but I sure would
> itwishes
> > if some users would be willing to respond again regarding this issue.
> >
> > The situation here at this company is the following. The Customer
> Service
> > Supervisor here is knowledgeable about databases. He is currently
> > developing a customer service application in Microsoft Access and
> touncomfortable
> > establish connections between Access and Vantage using ODBC
> functionality.
> > I am the person responsible for coordinating the company's use of
> Vantage.
> > I have no control over the application development. I am
> > providing this functionality because of security concerns. As far asI
> > know, if I implement ODBC, it will allow access to all of the Progresshttp://docs.yahoo.com/info/terms/
> > tables, except payroll, and thereby circumvent the access controls
> > established in Vantage. Everything that I have been able to learn so
> far
> > about this issue seems to confirm my concern. If my concern is
> legitimate,
> > are there any ways to mitigate this security risk?
> >
> > Regards,
> > Scott A. Lepley
> > Systems Administrator
> > Mauell Corporation
> > 31 Old Cabin Hollow Road
> > Dillsburg PA 17019-8815
> > Phone: 717-432-8686, ext. 14
> > Fax: 717-432-8688
> > Email: sal@...
> >
> > [Non-text portions of this message have been removed]
> >
> > Yahoo! Groups Sponsor
> >
> > Click here for Classmates.com
> >
> >
> > To unsubscribe from this group, send an email to:
> > vantage-unsubscribe@egroups.com
> >
> > Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service.
> >
> > [Non-text portions of this message have been removed]
> >
> >
> > To unsubscribe from this group, send an email to:
> > vantage-unsubscribe@egroups.com
> >
> >
> >
> > Your use of Yahoo! Groups is subject to
> <http://docs.yahoo.com/info/terms/>http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=1700007183:N/
> < http://docs.yahoo.com/info/terms/ <http://docs.yahoo.com/info/terms/> >
>
> Yahoo! Groups Sponsor
>
> <
>
><http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=1700007183:N/
> >http://us.adserver.yahoo.com/l?M=163100.1330039.2920210.2/D=egroupmail/S=17
> A=524804/* http://www.classmates.com/index.tf?s=2629
> <http://www.classmates.com/index.tf?s=2629> > Classmates.com
> Click here for Classmates.com
>
> <
>
><http://us.adserver.yahoo.com/l?M=163100.1330039.2920210.2/D=egroupmail/S=17
> ><http://rd.yahoo.com/M=163100.1330039.2920210.2/D=egroupmail/S=1700007183:N/
> 00007183:N/A=524804/rand=582186115>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
> Your use of Yahoo! Groups is subject to the Yahoo!
> < http://docs.yahoo.com/info/terms/ <http://docs.yahoo.com/info/terms/> >
> Terms of Service.
>
> [Non-text portions of this message have been removed]
>
> Yahoo! Groups Sponsor
>
>
>
> A=524804/*http://www.classmates.com/index.tf?s=2629> Classmates.com<http://us.adserver.yahoo.com/l?M=163100.1330039.2920210.2/D=egroupmail/S=17
> Click here for Classmates.com
>
>
>
> 00007183:N/A=524804/rand=801979269>To unsubscribe from this group, send an email to:
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
> Your use of Yahoo! Groups is subject to the Yahoo!
> <http://docs.yahoo.com/info/terms/> Terms of Service.
>
> [Non-text portions of this message have been removed]
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
>
>
> Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
>
>
> Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
>As Scott says below, labor rates are available from the EMPBASICThis is one of the most aggravating parts of the whole ODBC security
>table using ODBC. I have not tried to update tables via Microsoft
>Access, but I have tried to update them via Visual Basic, and the
>call fails. According to Epicor tech support, there are triggers
>which prevent table updates unless certain conditions are met, but
>
> At 03:02 PM 2/22/2001 , you wrote:
> >As Scott says below, labor rates are available from the EMPBASIC
> >table using ODBC. I have not tried to update tables via Microsoft
> >Access, but I have tried to update them via Visual Basic, and the
> >call fails. According to Epicor tech support, there are triggers
> >which prevent table updates unless certain conditions are met, but
>
> This is one of the most aggravating parts of the whole ODBC security
> hole! Before purchasing it, I wanted to use it to directly update a few
> tables. In order to clean up some garbage data that was stuck in a few
> places. No can do... Access protested the I/O failed because there was a
> write trigger on that particular table.
>
> BUT... no trigger, and you can use Access, VB or whatever and easily
> update the data. Also easily corrupt it in lot of places!
>
> Great example: in Access, link the Vantage UserFile into a blank
> database. Double click on it; it opens in a nice spreadsheet-like
> format. Find your userid, then go to the SecurityMgr column and enter 1
> (or maybe it wants -1) Tada! You now have full priv's in Vantage.
>
> I you look in \Vantage\DB\Trg\{table_name} you can see which tables have
> triggers for the various actions.
>
> -Wayne
>
>
> To unsubscribe from this group, send an email to:
> vantage-unsubscribe@egroups.com
>
>
>
> Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
--- In vantage@y..., Wayne Cox <wmc@u...> wrote:
> At 03:02 PM 2/22/2001 , you wrote:
> >As Scott says below, labor rates are available from the EMPBASIC
> >table using ODBC. I have not tried to update tables via Microsoft
> >Access, but I have tried to update them via Visual Basic, and the
> >call fails. According to Epicor tech support, there are triggers
> >which prevent table updates unless certain conditions are met, but
>
> This is one of the most aggravating parts of the whole ODBC
security
> hole! Before purchasing it, I wanted to use it to directly update
a few
> tables. In order to clean up some garbage data that was stuck in a
few
> places. No can do... Access protested the I/O failed because
there was a
> write trigger on that particular table.
>
> BUT... no trigger, and you can use Access, VB or whatever and
easily
> update the data. Also easily corrupt it in lot of places!
>
> Great example: in Access, link the Vantage UserFile into a blank
> database. Double click on it; it opens in a nice spreadsheet-like
> format. Find your userid, then go to the SecurityMgr column and
enter 1
> (or maybe it wants -1) Tada! You now have full priv's in Vantage.
>
> I you look in \Vantage\DB\Trg\{table_name} you can see which tables
have
> triggers for the various actions.
>
> -Wayne
> I'm sure this has been discussed previously, but I sure would appreciateit
> if some users would be willing to respond again regarding this issue.to
>
> The situation here at this company is the following. The Customer Service
> Supervisor here is knowledgeable about databases. He is currently
> developing a customer service application in Microsoft Access and wishes
> establish connections between Access and Vantage using ODBC functionality.legitimate,
> I am the person responsible for coordinating the company's use of Vantage.
> I have no control over the application development. I am uncomfortable
> providing this functionality because of security concerns. As far as I
> know, if I implement ODBC, it will allow access to all of the Progress
> tables, except payroll, and thereby circumvent the access controls
> established in Vantage. Everything that I have been able to learn so far
> about this issue seems to confirm my concern. If my concern is
> are there any ways to mitigate this security risk?[Non-text portions of this message have been removed]
----- Original Message -----
From: Lepley, Scott A.
To: 'vantage@yahoogroups.com'
Sent: Thursday, February 22, 2001 5:46 AM
Subject: RE: [Vantage] Vantage security and ODBC
Thanks for the reply, Troy. I understand that allowing data input via
ODBC
would or could bypass validation routines and thereby corrupt the
database.
That type of access is already ruled out in my opinion. However, even if
the ODBC link were limited to read-only, that doesn't alleviate my
concern.
My concern is regarding just that ability, that of the Access application
users being able to read the data. It appears that ODBC would allow them
to
see virtually any data, whether they needed to see it or not. If it were
acceptable for these users to see all data, I would simply install Report
Builder on their machines to let them access the data that way.
[Non-text portions of this message have been removed]
----- Original Message -----
From: Lepley, Scott A.
To: 'vantage@yahoogroups.com'
Sent: Thursday, February 22, 2001 3:49 PM
Subject: RE: [Vantage] Vantage security and ODBC
That's a good point, Troy. One outcome of the issue being raised here has
been my recognition of the security holes I've created by installing Report
Builder for various users. I plan to remove Report Builder where necessary.
How would you prevent a user from installing or re-installing Report
Builder?
Regards,
Scott
-----Original Message-----
From: Troy Funte [mailto:tfunte@...]
Sent: Thursday, February 22, 2001 12:22 PM
To: vantage@yahoogroups.com
Subject: Re: [Vantage] Vantage security and ODBC
Incidently, any user who knows how to create a shortcut could, in theory,
install report builder on their machine and run it too.
So using Access, although a potential time-bomb, relies on the ignorance of
the general user. It is the rogue programmer-in-disguise-as-an-engineer
that will might you headaches.
Troy
----- Original Message -----
From: Lepley, Scott A.
To: 'vantage@yahoogroups.com'
Sent: Thursday, February 22, 2001 5:46 AM
Subject: RE: [Vantage] Vantage security and ODBC
Thanks for the reply, Troy. I understand that allowing data input via
ODBC
would or could bypass validation routines and thereby corrupt the
database.
That type of access is already ruled out in my opinion. However, even if
the ODBC link were limited to read-only, that doesn't alleviate my
concern.
My concern is regarding just that ability, that of the Access application
users being able to read the data. It appears that ODBC would allow them
to
see virtually any data, whether they needed to see it or not. If it were
acceptable for these users to see all data, I would simply install Report
Builder on their machines to let them access the data that way.
[Non-text portions of this message have been removed]
Yahoo! Groups Sponsor
Click here for Classmates.com
To unsubscribe from this group, send an email to:
vantage-unsubscribe@egroups.com
Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service.
[Non-text portions of this message have been removed]
>"Lepley, Scott A." wrote:
> I'm sure this has been discussed previously, but I sure would appreciateit
> if some users would be willing to respond again regarding this issue.Service
>
> The situation here at this company is the following. The Customer
> Supervisor here is knowledgeable about databases. He is currentlyto
> developing a customer service application in Microsoft Access and wishes
> establish connections between Access and Vantage using ODBCfunctionality.
> I am the person responsible for coordinating the company's use ofVantage.
> I have no control over the application development. I am uncomfortablelegitimate,
> providing this functionality because of security concerns. As far as I
> know, if I implement ODBC, it will allow access to all of the Progress
> tables, except payroll, and thereby circumvent the access controls
> established in Vantage. Everything that I have been able to learn so far
> about this issue seems to confirm my concern. If my concern is
> are there any ways to mitigate this security risk?<
>
> Regards,
> Scott A. Lepley
> Systems Administrator
> Mauell Corporation
> 31 Old Cabin Hollow Road
> Dillsburg PA 17019-8815
> Phone: 717-432-8686, ext. 14
> Fax: 717-432-8688
> Email: sal@...