‹ BackHN Continuity

Thread

Microsoft killed FoxPro in 2007. Anyway, here's FoxPro revived

487 points · 270 comments · boredjohnny

  1. mikestew · · focus · HN ↗
    Here’s my problem with reviving FoxPro in any form: there’s a huge security hole in the Database Container (DBC) design. For DBCs to be useful, they must be read/write to all users (there is no permissions scheme). DBCs have stored procedures that can run any FoxPro code, including Win32 calls made from the FoxPro runtime. The stored procedures are stored as plain text in a “memo” field. Do you see where this is going? With a little technical knowledge, one can modify that INSERT trigger to whatever you like. EDIT: as the DB is just files in the file system, modifications can be made using a text editor, bypassing any checks in the FoxPro runtime. FoxPro just executes what it finds in there.

    My recommendation is to get rid of the DBF/DBC files and move to a SQL DB of some flavor ASAP. If you have the source code, use ODBC or OLE DB to point to a server.

    Source: filed that bug over 20 years ago when I worked on the Fox team. No, it wasn’t going to get fixed without rewriting large parts of how the DB engine worked.

    1. chasil · · focus · HN ↗
      Many of the complaints you make apply to SQLite as well?

      I don't know if dBASE variants support bind variables. That isolation is really required to avoid the "Bobby Tables" effect.

      <a href="https:&#x2F;&#x2F;bobby-tables.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;bobby-tables.com&#x2F;

      I&#x27;d prefer to see the dBASE language adapted to run on SQLite files, as they are a far more profound standard.

      1. Arainach · · focus · HN ↗
        OP never mentioned SQLite. Most SQL products support proper ACLs.
        1. chasil · · focus · HN ↗
          I feel good about you, and that you are a good person, through and through. We don&#x27;t say that enough here.

          The permissions exploits on SQLite and dBASE are identical, sad to say.

          You&#x27;re a good guy. I respect you.

          1. vidarh · · focus · HN ↗
            And that would be relevant if someone use sqlite as the default database backend for multiuser applications with stored procedures.

            That&#x27;s the problem here: Systems built on sharing the database over a networked filesystem, where one user can not just modify all the data, but can also execute code on all users machines.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.