Persist Security Info 参数的作用
来源:互联网 发布:淘宝商品地址怎么复制 编辑:程序博客网 时间:2024/06/05 09:16
Persist Security Info属性的意思是表示是否保存安全信息,其实可以简单的理解为"ADO在数据库连接成功后是否保存密码信息",
True表示保存,False表示不保存
ADO缺省为True
(ADO.net缺省为False,未测试,根据参考资料上说的)
具体可以通过ADO的Connect对象的ConnectString属性进行验证,如下所示(以下在Delphi7中测试通过):
----------------------------------------------------------------------------------------------------------
数据库连接前
ConnectString="Provider=MSDAORA.1;Password=mypassword;User ID=yzs;Data Source=ydgl22;Persist Security Info=false"
数据库连接成功后
ConnectString="Provider=MSDAORA.1;User ID=yzs;Data Source=ydgl22"
----------------------------------------------------------------------------------------------------------
数据库连接前
ConnectString="Provider=MSDAORA.1;Password=mypassword;User ID=yzs;Data Source=ydgl22;Persist Security Info=true"
数据库连接成功后
ConnectString="Provider=MSDAORA.1;Password=mypassword;User ID=dlyx;Data Source=ydgl22"
----------------------------------------------------------------------------------------------------------
总体来说,如果数据库连接成功后不再需要连接的密码,出于安全性考虑,还是建议将Persist Security Info设为false,以防止后门程序取得数据库连接的密码(windows2003在sp1前就发生过这个问题)。
以下是摘自微软的ADO.net资料
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/cpguide/html/cpconsecureadonetconnections.asp
Keep Persist Security Info as False
Setting Persist Security Info to true or yes will allow security-sensitive information, including the userid and password, to be obtained from the connection after the connection has been opened. If you are supplying a userid and password when making a connection, you are most protected if that information is used to open the connection, and then discarded. As a result, your option that helps to provide greater security is to set Persist Security Info to false or no.
This is especially important if you are supplying an open connection to an untrusted source or persisting connection information to disk. Keeping Persist Security Info as false helps ensure that the untrusted source does not have access to the security-sensitive information for your connection and also helps ensure that no security-sensitive information is persisted to disk with your connection string information.
Persist Security Info is false by default.
- Persist Security Info 参数的作用
- Persist Security Info 参数的作用
- Persist Security Info 参数的作用
- ADO数据库连接中的Persist Security Info参数的作用
- ADO数据库连接中的Persist Security Info参数的作用
- 数据库连接的Persist Security Info参数说明
- 终于搞清楚了ADO数据库连接中的Persist Security Info参数的作用
- Persist Security Info
- Persist Security Info 是什么意思
- Persist Security Info
- Persist Security Info意义(转)
- Persist Security Info=False是干什么的
- .NET连接数据库字符串密码丢失的解决方法(persist security info=true;)
- NET连接数据库字符串密码丢失的解决方法(persist security info=true;)
- .NET连接数据库字符串密码丢失的解决方法(persist security info=true;)
- iOS编程info.list文件参数作用
- IOS编程info.list文件参数作用
- "Provider=SQLOLEDB.1;Persist Security Info=False;User ID=;PassWord=;Initial Catalog=;Data Source="
- Oracle执行计划详解
- Quaterion小结
- winform 分页控件
- Item 6-7 重用标准库
- Ubuntu10.10中安装sun-java6-jdk
- Persist Security Info 参数的作用
- 【转】18条背下来没人敢和你忽悠CPU
- Item 8 异常安全的ctor和dtor
- oracle系统视图作用大全
- C 语言宏高级应用
- virtualbox + debian + kde + compiz体验
- 怎样成为明星DBA
- GetUserName问题
- 调整事件递交