hacking into RMS database

something for the programmers to wrap their heads around...

how hard would it be to accurately crack open an RMS database and pull out sales and other information if a random hard drive with a Store database just landed in your lap and you had access to plenty of tech heads? could 1 guy do it alone in a few hours? would it take a cia level hacker 3 days? anyone know at all? i'm really just curious...not trying to test out the software or anything...so far it's been effectively safe for us.

thanks, kamal

Reply to
Kamal Hood
Loading thread data ...

why hacking RMS db ? to export sales and other??

This database is easy, and unprotected

antonio

Reply to
Antonio Mazzeo

aaaarrgh!!

yes. hacking to get sales information, like total sales, total cost of product, or inventory. but a hacker wouldn't have to understand a lot about how the rms database was structured? i guess they could just figure it out by looking at the transactions table... so it's that easy, huh? even without the password (i know i'm setting myself up for this one)?

thanks ant> > how hard would it be to accurately crack open an RMS database and pull out

Reply to
Kamal Hood

One guy, less than one hour. Make sure you mask your credit card numbers!

Reply to
Glenn Adams [MVP - Retail Mgmt]

Kamal... in my old company we wrote a new POS without documentation that work with RMS database (transactions, customers, batch, department.. item.. ALL!!) .. or SQL Profiler for hacking :)

antonio

Reply to
Antonio Mazzeo

Uh, man if you have a secure password on the database then your pretty safe. A brute force exe would take forever to find the right password. Don't password it and you might as well not have it. I think the level of person to hack into it with a password would not be a hacker. mt

"Glenn Adams [MVP - Retail Mgmt]" wrote in message news:% snipped-for-privacy@TK2MSFTNGP09.phx.gbl...

Reply to
Masta T

I have always been concerned about the backup files myself. I mean... if I am not mistaken... the password is on the SQL server... not the database itself?

I mean... if you search for *.bck on a PC running RMS and a backup file was created and saved on it localy...

Could one not simply instal RMS on another computer and restore any backup file? If so... with odbc or sql you could then get at the database content pretty quick?

what do you and your clients do with your .bck files?

Marc Wagner

formatting link

Reply to
Marc Wagner

in SQL Server you can password protect your backup files as well.

Reply to
root

Hi Root :-) it's great to see you again.

Can this also be done this with MSDE?

Marc Wagner

formatting link

Reply to
Marc Wagner

I'm sure it can. command prompt.

formatting link

Reply to
root

BeanSmart website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.