Re: Security bug?

From: R. van Noorloos (renennospam@syfact.com)
Date: 01/23/03


From: "R. van Noorloos" <renennospam@syfact.com>
Date: Thu, 23 Jan 2003 09:27:11 +0100


Kevin

Thanks, I know there is more, but a blank password is easely overseen if you
standard install with NT security and not aware of this. And also
administrators could be denied access to a database/sql server,depending on
the confidentiallity of the stored information.

But it is good to know SP3 is forcing it anyway.

Kind regards

René van Noorloos

Syfact int'l

"Kevin McDonnell [MS]" <kevmc@online.microsoft.com> wrote in message
news:Y5oyS$XwCHA.3048@cpmsftngxa06...
> Also, installing sp3 will prompt the user to change a blank 'sa' password.
> Only Administrators should be allowed to modify the servers registry key.
> There's more to securing a server than supplying a good 'sa' password...
>
>
> Kevin McDonnell
> Microsoft SQL Server Support
>



Relevant Pages

  • Re: Having ASPNET member of Administrators
    ... I would tend to agree with Kevin, but will also stand by my point of fixing ... granting elevated privileges to the ASPNET account. ... >>> So much for the principle of least privilege... ... In general, where security is the issue, the ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: [Full-disclosure] [SCADASEC] 11. Re: SCADA Security - Software fees
    ... vendors offer half assed services that sell for half assed prices. ... quality service because of how the crap service is marketed. ... Quality vendors in the security industry are a dime a dozen. ... So as I asked your friend Kevin, ...
    (Full-Disclosure)
  • Re: How do you lock you computer?
    ... | If you want others off the computer, you must physically lock it up | out of their reach. ... | There is no security without physical security. ... | "kevin" wrote in message ...
    (microsoft.public.windowsxp.newusers)
  • Re: Early Report from LAs Hollywood Park pin show (STARTED TODAY!)
    ... in LA County. ... Nice to meet you Kevin! ... The security guys even stopped by and played a few games - I ... With more attendance this show could easily support itself in future ...
    (rec.games.pinball)