SQL authenticated push subscriber's password appears in profiler

From: Nayan Raval (nr@anon.com)
Date: 03/28/03


From: "Nayan Raval" <nr@anon.com>
Date: Fri, 28 Mar 2003 02:39:34 -0800


Set up:

SQL Server 2000 SP3. Transactional replication with
separate publication and distribution servers. Set up a
push subscriber specifying sql authenticated login and
password.

Security problem:

Run profiler. On publication server visit
Tools...Replication...Configure Publishing, Subscribers
and Distribution. Select the Subscribers tab and change
the sql authenticated login's password.

You'll see sp_MSupdate_subscriber_info appearing in
Profiler with the password in clear text.

If the publication server and distribution server are on
the same sql server then instead of
sp_MSupdate_subscriber_info you see sp_changesubscriber in
profiler. The latter doesn't show parameters.

Please could MS fix this for separate publisher and
distributor.

Thanks,

--
Nayan Raval


Relevant Pages

  • Reenable current subscriptions
    ... SQL Server on our main server. ... After that move we can not attach our old subscribers to either new or old ... The initial snapshot for publication 'databaseName' is not yet available. ...
    (microsoft.public.sqlserver.ce)
  • Re: Upgrade scenario
    ... > (only other updateable option in SQL Server 7.0). ... Recreate any SQL Agent jobs that should be setup on the 2005 server ... You have moved all of your subscribers over ... Applications congtinue to run during the upgrade ...
    (microsoft.public.sqlserver.replication)
  • Re: Merge Replication between sites - Keeping hot backu servers ready
    ... Initially I thought about same keeping A as publisher and rest all ... But the connectivity between SERVER A and SERVER B may ... > subscribers to A if your network speeds can cope with it. ... > Paul Ibison SQL Server MVP, ...
    (microsoft.public.sqlserver.replication)
  • RE: SBS 2003 Unable to connect to database STS_Config
    ... Uninstall the SQL server from the SBS 2k3 server from add/remove programs ... Uninstall Microsoft SQL Server Desktop Engine (SHAREPOINT) ... If AV software install any extra IIS virtual directory, ...
    (microsoft.public.windows.server.sbs)
  • RE: migrating from wmsde to sql server
    ... Click Start, point to All Programs\Microsoft SQL Server, and then click ... then click New SQL Server Registration. ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)