RE: SQL SA password

From: Damon Sisola (dsisola@osius.com)
Date: 02/15/02


From: "Damon Sisola" <dsisola@osius.com>
To: "'RICH ROHRICH'" <Rich_Rohrich@pgn.com>, <focus-ms@securityfocus.com>
Date: Thu, 14 Feb 2002 15:23:37 -0800

If the SQL Server security is not locked down well, and the default server
roles exist, you can login as an admin on the box and use the Administrators
groups trusted connection (Use Windows Authentication) to get in with the SA
privilege. Then change the SA password as you wish.

-----Original Message-----
From: RICH ROHRICH [mailto:Rich_Rohrich@pgn.com]
Sent: Thursday, February 14, 2002 1:25 PM
To: focus-ms@securityfocus.com
Subject: SQL SA password

Anyone know of a way to retrieve or break the SA password for a SQL database
on a Windows2000 server. We accidently locked ourselves out of a box. If I
should post this elsewhere please let me know.

Rich