Re: Security bug?
From: R. van Noorloos (renennospam@syfact.com)
Date: 01/23/03
- Next message: Mary Chipman: "Re: Secure a SQL-Server 2000 database."
- Previous message: John Jost: "SQL Conenction Error"
- In reply to: John Alderson: "Re: Security bug?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "R. van Noorloos" <renennospam@syfact.com> Date: Thu, 23 Jan 2003 16:01:53 +0100
John,
Are you sure that it is promted when installing with NT authentication.
Beacuase I have done a numerous installation. But I cannot remember ever
seen an prompt when instaling with NT authentication. I know I'm prompted
when installing with Mixed Mode
Kind regards
Rene
"John Alderson" <jalderson.spamnot@adelphia.net> wrote in message
news:u$G9BbtwCHA.2492@TK2MSFTNGP10...
> SQL Server 2000 Setup has been prompting for a password for sa since RTM,
> IIRC. This is nothing new with SP3. However, it's only a prompt and the
> ignorant administrator can still bypass it. I think it would serve
> Microsoft well to retool the prompt to be such that a password is a
> requirement to continue setup.
>
> Further, folks pleading security ignorance just doesn't fly when a 3
second
> Google search on sql security brings up www.sqlsecurity.com as the first 2
> hits and Chip Andrews Blackhat presentation as the third.
>
> John Alderson
>
>
> "R. van Noorloos" <renennospam@syfact.com> wrote in message
> news:#1UntkrwCHA.2636@TK2MSFTNGP12...
> > Kevin
> >
> > Thanks, I know there is more, but a blank password is easely overseen if
> you
> > standard install with NT security and not aware of this. And also
> > administrators could be denied access to a database/sql server,depending
> on
> > the confidentiallity of the stored information.
> >
> > But it is good to know SP3 is forcing it anyway.
> >
> > Kind regards
> >
> > René van Noorloos
> >
> > Syfact int'l
> >
> > "Kevin McDonnell [MS]" <kevmc@online.microsoft.com> wrote in message
> > news:Y5oyS$XwCHA.3048@cpmsftngxa06...
> > > Also, installing sp3 will prompt the user to change a blank 'sa'
> password.
> > > Only Administrators should be allowed to modify the servers registry
> key.
> > > There's more to securing a server than supplying a good 'sa'
password...
> > >
> > >
> > > Kevin McDonnell
> > > Microsoft SQL Server Support
> > >
> >
> >
>
- Next message: Mary Chipman: "Re: Secure a SQL-Server 2000 database."
- Previous message: John Jost: "SQL Conenction Error"
- In reply to: John Alderson: "Re: Security bug?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|