Re: Audit Logins - Preformance Issue??

From: Sue Hoegemeier (Sue_H@nomail.please)
Date: 05/28/02


From: Sue Hoegemeier <Sue_H@nomail.please>
Date: Mon, 27 May 2002 22:24:40 -0600


Yes...at the minimum failed logins but failed and successful
to track sa logins would be best. The impact on the server
is negligible.
Don't forget to check your MSDE installations on your
network. Make sure you have the current service packs and
security updates - watch for line wrap on the links:
Make Your SQL Servers Less Vulnerable
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/tools/chklist/sqlsec.asp
Microsoft Baseline Security Analyzer
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/tools/Tools/mbsahome.asp

-Sue

On Sat, 25 May 2002 05:35:48 -0700, "Scott H."
<schenderson2@rogers.com> wrote:

>Folks,
>
>As the result of the most recent virus alert, I've been
>informed that it may be a good idea to have login auditing
>turned on for both successful, and unsuccessful logins. My
>question has 2 parts, a) Is this so, and b) does this
>impact performance whatsoever?
>On a similar note, we have ensured that our sa login does
>not have a null password and we're also blocking ports
>1433, and 1434. Is there anything else I should do to
>properly secure my SQL Server environment?
>
>Thanks in advance,
>
>Scott H.



Relevant Pages

  • Re: Compromised Server? Anyone recognize the suspect Services?
    ... I finally discovered that there was a whole folder structure under ... Event viewer shows normal logins, but I did not have it set to record ... there are a bunch of logins for Website Accounts created by the ... order to find those files on the Web Server I had to make sure that System ...
    (microsoft.public.windows.server.networking)
  • Re: Sql Server 2005 Dev. Ed. on Windows Server 2003
    ... Check out this KB which is about transferring Logins: http://support.microsoft.com/kb/246133 ... Also, since this is running on a newly installed Windows Server 2003, is ... them from your older SQL Server instance to the newer one. ...
    (microsoft.public.sqlserver.setup)
  • Re: Enabling STARTTLS in Exchange 2003 IMAP service?
    ... For the first, if you simply want to enable encrypted logins, then once you ... I guess I don't understand the need to have that command listed. ... > This section describes a means for "upgrading" an ordinary cleartext IMAP ... In order to use it, however, the server must advertise support for ...
    (microsoft.public.exchange2000.protocols)
  • Re: Enabling STARTTLS in Exchange 2003 IMAP service?
    ... For the first, if you simply want to enable encrypted logins, then once you ... I guess I don't understand the need to have that command listed. ... > This section describes a means for "upgrading" an ordinary cleartext IMAP ... In order to use it, however, the server must advertise support for ...
    (microsoft.public.exchange2000.admin)
  • Re: Transferring logins form 6.5 to 2000, anyone?!
    ... > server is case-insenstive, and the 2000 server is case-sensitive, then you ... > end up with all your passwords in upper case when they're copied. ... > /* Get 6.5 login information into the worktable, excluding system logins. ... >> Microsoft Online Support Engineer ...
    (microsoft.public.sqlserver.security)