Knowledge Base

backimg
 
 
FAQ
 

3734: Security concern with v6.3.1 and v6.3.2 Log Server and Reporter
Back  Print  Email  Bookmark  Download  Subscribe  Copy Article Link 
Article Viewed 1
Reviewed 4/16/2009
Security concern with v6.3.1 and v6.3.2 Log Server and Reporter
Text Size + -
Article Information
Updated:
17 October 2008
Applies To:
Websense Enterprise 6.3.1, 6.3.2
Websense Web Security Suite 6.3.1, 6.3.2

Article
Important Information
Notes and Warnings:


This problem does not occur in organizations that use a trusted connection (Windows Authentication) for database communications.

Websense Web Security and Websense Web Filter v7 users do not experience this problem.


Feedback

Did this solve your problem?
Yes No
How helpful was this article?
(0% incomplete - 100% best)
How can the article be improved?
Problem Description:

Installing the Log Server and Reporter components launches a program called createdbu which creates or upgrades the Websense Log Database in SQL Server or MSDE. In Websense Web Security Suite and Websense Enterprise versions 6.3.1 and 6.3.2, this program saves a log file called CreateDbInstall.log, which contains information that is useful to Technical Support personnel if a problem is encountered during the process.

This log file contains the complete osql command executed to create or upgrade the database, which includes the user name and password for the SQL account that has permission to manage the Websense Log Database. Since this information appears in clear text, it is possible that employees who have access to the installation machine could view the password and thereby gain unapproved access to SQL Server or MSDE operations.

Websense, Inc., thanks Eric Beaulieu for reporting this issue.


Error Messages: (Detailed)


Resolution:

Until a correction is implemented, you can prevent unauthorized access to SQL Server or MSDE by deleting the following file after successful installation or upgrade of either the Log Server or Websense Reporter component:

<installation path>\SQL\CreateDbInstall.log

The default installation path is C:\Program Files\Websense.

Be sure to delete this file from each machine where either Log Server or Websense Reporter is installed or upgraded. Additionally, if you run the createdbu program manually to create a new catalog database, be sure to delete the CreateDbInstall.log file afterward.

If there are any problems during the installation, copy the file to a secure location before deleting it from the local machine. You may need the file as you work with Websense Technical Support to resolve the problem.

This problem will be fixed in v6.3.3, which is scheduled for release in the first quarter of 2009.


Documentation References


3rd Party Documentation:


Websense Product Data
Product Components Affected:
Log Server, Websense Reporter
Integration Component:
N/A
Platform:
Windows
Client OS:
N/A


Visit our Forums > Didn't find what you're looking for? Try our forums where you can share questions and suggestions in discussion groups with experienced Websense customers.

NOTICE In the course of providing technical support for our own products, we find that we are sometimes asked to provide information with respect to the operation of third-party products and the interoperability of those products with Websense products. We may elect to provide information regarding third-party products as a courtesy to our customers, but because the information relates to non-Websense products, the information may not be complete or accurate and cannot be warranted or guaranteed in any way. Websense does not represent that it has any expertise with respect to non-Websense products and will not be responsible in any way for claims arising from our customers' use of third-party products, regardless of whether Websense has provided any information or support relating to those products.
 Highlight  
backimg