RE: Creating a checklist for SQL Server 2000



Yes, you are on the right track, where possible use Windows and not SQL
security for access control. MS is expecting everyone to authenticate via
the OS and is not updating these functions in SQL. In addition, for good
segregation of duties you want the SQL logs directed to the OS logs.
However the audit function is SQL and Windows related and the removal of
unnecessary services are SQL specific.


Warren V. Camp, CPA, CISA, MS, MBA
Warren V. Camp, CPA, LLC
Better Ideas for IT Risk & Security Mgt. and Compliance
SOX, HIPAA, NIST, GCC

-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx] On
Behalf Of Pranav Lal
Sent: Thursday, February 22, 2007 5:51 AM
To: security-basics@xxxxxxxxxxxxxxxxx
Subject: Creating a checklist for SQL Server 2000

Hi all,

I have been asked to get a checklist for SQL server 2000. I have found
material at the following locations; http://www.nsa.gov/snac/db/mssql_2k.pdf
http://msdn2.microsoft.com/en-us/library/aa302337.aspx
http://www.sans.org/reading_room/whitepapers/application/1273.php?portal=332
3855d672e12e0e1e53f32fb3f15af

I find that SQL server security is highly integrated with the operating
system so a separate SQL server 2000 only checklist is almost meaningless.
Am I on the right track? The problem is that the client wants to see a
"checklist" and consequently so does my boss.
So, are there any checklists out there or do I have to carry out some kind
of rephrasing exercise on material from the above links?

Pranav

---------------------------------------------------------------------------
This list is sponsored by: BigFix

If your IT fails, you're out of business - or worse. Arm your enterprise
with BigFix, the single converged IT security and operations engine. BigFix
enables continuous discovery, assessment, remediation, and enforcement for
complex and distributed IT environments in real-time from a single console.
Think what's next. Think BigFix.

http://ad.doubleclick.net/clk;82309979;15562032;o?http://www.bigfix.com/ITNe
xt/
---------------------------------------------------------------------------


---------------------------------------------------------------------------
This list is sponsored by: BigFix

If your IT fails, you're out of business - or worse. Arm your
enterprise with BigFix, the single converged IT security and operations
engine. BigFix enables continuous discovery, assessment, remediation,
and enforcement for complex and distributed IT environments in real-time
from a single console.
Think what's next. Think BigFix.

http://ad.doubleclick.net/clk;82309979;15562032;o?http://www.bigfix.com/ITNext/
---------------------------------------------------------------------------



Relevant Pages

  • RE: SQL Slammer doing the rounds again?
    ... SQL Slammer doing the rounds again? ... "I used to hate writing assignments, ... > Security Business Unit ... > at the largest, most highly-anticipated industry ...
    (Incidents)
  • Re: sql injection query
    ... escapes the values so this alone greatly enhances security. ... there was a post here a while ago about Validating SQL ... these regex's were very good] so he had no worries about Injection. ... wanted to know if I call a storedprocedure like this I would be similarly ...
    (microsoft.public.dotnet.framework.adonet)
  • [NEWS] IBM Informix Web DataBlade Vulnerable to Auto-decoding of HTML Entities
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... HTML encoded strings are automatically being decoded when used in SQL ... When a string has been ... $'ed it should thus be safe to use it in an SQL query, ...
    (Securiteam)
  • Re: sql injection - missed it at bh/defcon + follow on query.
    ... sql injection - missed it at bh/defcon + follow on query. ... >I got thro' a login by putting ... >This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • Re: Microsoft Informational Alert
    ... > PSS Security Response Team Alert - SQL Security Recommendations ... > PRODUCTS AFFECTED: SQL Server ... Secure your SA login account with a non-NULL password. ...
    (microsoft.public.security)