Looking for SQL security details (Version 2)

From: Sarbjit Singh Gill (ssgill_at_gilltechnologies.com)
Date: 02/10/04

  • Next message: Marc Fossi: "SecurityFocus Microsoft Newsletter #175"
    To: <focus-ms@securityfocus.com>
    Date: Tue, 10 Feb 2004 22:47:08 +0800
    
    

     
    Greetings,

    As I prepare for SQL Security presentation, I realized when I logged into
    SQL using Query Analyzer, the password I typed was not case sensitive. I
    know changing the character set to case sensitive would have solve that
    issue but it would have effected other databases and my application as well.

    What technique is used by SQL to retrieve and used the stored encrypted in
    the system tables(syslogins)

    /Gill

    -----Original Message-----
    From: Sarbjit Singh Gill [mailto:ssgill@gilltechnologies.com]
    Sent: Sunday, February 08, 2004 11:25 PM
    To: 'focus-ms@securityfocus.com'
    Subject: Looking for SQL security details

    Greetings

    I am preparing for a "10 Steps To Help Secure SQL Server 2000" presentation.
    I would have to carry out demos of vulnerabilities, hacks, break-in. All I
    have are microsoft Security Guides. They aren't efficient enough for a
    full-blown demos.

    Please advice how do I begin.

    Regards
    Gill

    ---------------------------------------------------------------------------
    Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

    Protect your network with the comprehensive security solution that
    integrates six applications for ease of use and lower TCO.

    Firewall - Virus protection - Spam protection - URL blocking - VPN
    - Wireless security.

    Download 30-day evaluation at:
    http://www.astaro.com/php/contact/securityfocus.php
    ---------------------------------------------------------------------------


  • Next message: Marc Fossi: "SecurityFocus Microsoft Newsletter #175"

    Relevant Pages

    • RE: SQL Slammer doing the rounds again?
      ... SQL Slammer doing the rounds again? ... "I used to hate writing assignments, ... > Security Business Unit ... > at the largest, most highly-anticipated industry ...
      (Incidents)
    • Re: sql injection query
      ... escapes the values so this alone greatly enhances security. ... there was a post here a while ago about Validating SQL ... these regex's were very good] so he had no worries about Injection. ... wanted to know if I call a storedprocedure like this I would be similarly ...
      (microsoft.public.dotnet.framework.adonet)
    • [NEWS] IBM Informix Web DataBlade Vulnerable to Auto-decoding of HTML Entities
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... HTML encoded strings are automatically being decoded when used in SQL ... When a string has been ... $'ed it should thus be safe to use it in an SQL query, ...
      (Securiteam)
    • Re: sql injection - missed it at bh/defcon + follow on query.
      ... sql injection - missed it at bh/defcon + follow on query. ... >I got thro' a login by putting ... >This list is provided by the SecurityFocus Security Intelligence Alert ...
      (Pen-Test)
    • Re: Microsoft Informational Alert
      ... > PSS Security Response Team Alert - SQL Security Recommendations ... > PRODUCTS AFFECTED: SQL Server ... Secure your SA login account with a non-NULL password. ...
      (microsoft.public.security)