|
Blue Forest http://www.lslnet.com at 11:08 on July 8, 2006
Sa be removed or locked treatment Read two articles that in the past have, but we will not say, appears to raise the level a bit, hee hee
Http://www.lslnet.com/linux/#viewthread.php?tid=724589&extra=&page=1
I wonder if good brother? No results of the
Http://www.lslnet.com/linux/#viewthread.php?tid=728310&extra=page%3D2
Wrote the following on the Eastern
Sa be removed or locked treatment
Basic knowledge :
Sysloginroles reservoir system and the master table syslogins
Syslogins record Login information, but no information competence. Several major field name, status (locked state 2 0 normal), suid, the Login can operate this table sa_role
Login authority sysloginroles recorded message suid counterparts Login, srid corresponding authority (0 sa_role;1 sso_role specific syssrvroles see Table 1) This table is only sso_role the Login to operate nor to have sa_role
Sa_role with the operation of the database system administrator privileges, but some will be completed only sso_role (authorized, add Login, change password, etc.)
First talk about being locked :
Sso_role final is not a normal lock, if sa locked, and the Login ssa_role sp_locklogin sa, 'unlock' can be.
Table sa_role syslogins irregular because the Login can be amended and as long as syslogins set status=2 update on the inside, unlocking update syslogins set status=0
Sa_role not have the Login, down Behold, bars directly alter the master document
Sa say that was deleted : (The reference here is to be deleted from syslogins that there sysloginroles table content. I did not succeed sp_droplogin sa)
1 of the sa_role and sso_role Login
No problems, plus sa will, sp_addlogin sa, passwd, but attention must put sa syslogins the suid to 1 (not the new one), and this can sysloginroles counterparts, we should not mandate. Of course, you can do manual authorization.
Sso_role sa_role but no two are the Login (sa End continuously cut their link is the case, no one seems to have sso_role)
I used to think no, because sa_role authorized users and can not build, operate syslogins suddenly thought, could insert a sa syslogins : insert values (1,0, '2004-01-01', 0,0,0,0,0. 'master' and 'sa', null, null, null, null, null, null, null, null), the main this is null sa password inserted into the sa password ultimately what you do not know (there may be a corresponding value of fixed passwords) sa can change the password (no sso_role) is a good way to increase -psa Sybase System to allow the resumption of this system, leaving no need for me to say the hour.
Only three general competence Login
I would like to talk about the fact this is the same principle, by the authority sysloginrols table is sa information, select * from sysloginroles (ase12.5)
Suid status srid
----------- ----------- ------
1 0 1
1 1 1
1 2 1
1 3 1
Srid 0 and 1 which shows sa_role and sso_role to be done is to suid 13 (sa) to 3 (the ordinary Login suid, assuming Login to testlogin)
See page dbcc
Offset 32-row ID=0 row length=12 # varlen cols=0
21571020 ( 0): 00000100 01000000 00000000
Row-Offset table for variable-length columns :
Offset 44-row ID=1 row length=12 # varlen cols=0
2157102C (0) : 00010100 01000000 01000000
In front of the state, in the middle is suid back srid.
If Windows is under sybase12.5
Direct open master documents, the search 00000100 01000000 00000000 00010100 01000000 01000000
If your Login is the id 3
Directly into 0c000000 01000000 00000000 00010100 00000100 0c000000
Sybase System reopening, it is your Login sa_role and ssa_role this, and then address the sa
If not, "00000100 01000000 00000000 00010100 01000000 01000000" separate finding, it should be in the vicinity.
4 If not Login or no record sysloginroles
I have no way to know who brothers, this soon. But for the Login mon_user plaques have available, but there seems to probe the Login can download to sybsystemdb, in the end to know what to do with the stickers, not bother to ask the Sybase System
This problem should not frequently encountered, yet they do not seem to change master what good way (if not the master backup), plus do some important operational matters, a re-examination of the submission, the more hastily written, some tests are not comprehensive, please Paizhuan wrong places. Sysloginroles ase12.0 the structure seems a bit different, without careful examination, it can be, I used to see the law changed Unix stickers should also be. |
Thanks, man, good practices! |
Lz now it is easier to amend the master equipment ah. |
Upstairs flattering |
Admirable!
BTW,
If it is on UNIX, it is not part of the reform on the Arab red?
See page dbcc
Offset 32-row ID=0 row length=12 # varlen cols=0
21571020 (0) : 00000100 01000000 [color=Red]00000000[/color]
Row-Offset table for variable-length columns :
Offset 44-row ID=1 row length=12 # varlen cols=0
2157102C (0) : 00010100 01000000 [color=Red]01000000[/color]
Od can be changed using incorrect? Or other use of any special tools? |
Srid red is the value of the policy should be changed in the middle suid value of the above article says very clearly,
Unix, we should see my previous articles that directly alter the master equipment change master database : the state (win and UNIX)
Http://www.lslnet.com/linux/#viewthread.php?tid=721224&fpage=1&highlight= |
The article is well understood are the target for the system!
But the hope that the people! Ha ha |
Lz master is a master bin, 1976. Admire ah |
Angels are showing great! |
Strongman, should increase quality and useful for future generations! |
| |