adewale4favour
Registered User.
- Local time
- Today, 02:45
- Joined
- Aug 9, 2019
- Messages
- 58
Hi Guys,
I probably would't be the first person to notice this, it actually calls my curiosity, so I tried it and it worked. I developed Access Database with all the required security settings, both for the Front End (FE) and the Back End (BE). The users are all required to Login, before any access is given and based on their user level authorization.
I tried to use the Power Query resources in Excel to access the backend of the database, this is to fetch all users password, but the system returned an error, that the Database is password protected, which is fine. I now tried using the same query to access the Front End to fetch the Users Credentials and surprisingly, it worked. All user details, Name and Password, together with User Level Authorization was fetched.
Now my area of concern is this, if an intruder, wants to get user credentials to get information from the system, if the fellow adopt same means, then he/she will have access to the whole system, even the Administrative right.
Please guys, is there a way around protecting this from happening?
Regards
Michael
I probably would't be the first person to notice this, it actually calls my curiosity, so I tried it and it worked. I developed Access Database with all the required security settings, both for the Front End (FE) and the Back End (BE). The users are all required to Login, before any access is given and based on their user level authorization.
I tried to use the Power Query resources in Excel to access the backend of the database, this is to fetch all users password, but the system returned an error, that the Database is password protected, which is fine. I now tried using the same query to access the Front End to fetch the Users Credentials and surprisingly, it worked. All user details, Name and Password, together with User Level Authorization was fetched.
Now my area of concern is this, if an intruder, wants to get user credentials to get information from the system, if the fellow adopt same means, then he/she will have access to the whole system, even the Administrative right.
Please guys, is there a way around protecting this from happening?
Regards
Michael
Last edited: