Re: How to prevent 'sa' from 'hacking' Windows Server ?

From: Jacco Schalkwijk (jacco.please.reply_at_to.newsgroups.mvps.org.invalid)
Date: 07/21/04


Date: Wed, 21 Jul 2004 11:02:21 +0100

Yes, run SQL Server under an Windows account that isn't a member of the
Windows administrators group and doesn't have permissions to create Windows
users. sa inherits the permissions of the Windows account that SQL Server is
running under.

-- 
Jacco Schalkwijk
SQL Server MVP
"tristant" <krislioe@cbn.net.id> wrote in message
news:Om7pwQwbEHA.3636@TK2MSFTNGP10.phx.gbl...
> Hi All,
>
> We are running SQL Server 2000 at Windows 2000 Server.
> I Just realize that with 'sa' login from query analyzer from client
computer
> , it can execute sp_cmdshell and some 'Net bla bla comannd' create new
> Windows user , assign administrator to it and then become 'god' with that
> user account.
>
> Is there aniway to overcome this security hole ?
>
> Thanks in advance,
> Krist
>
>


Relevant Pages

  • Re: Slow booting xp home.
    ... Changing the boot order to boot first from your hard disk might save you a half second, but you won't be able to boot from a CD until you change it back - and the time spent to do that will erase any previous time saved. ... 2- Consider what software you really want to start with Windows and also how you've configured your applications at startup ... Installing and Registering Visual Studio Express Editions Smart Device ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: Setting perm. on stored procedures using windows auth.
    ... windows account and are in the local windows administrators group, ... I support the Professional Association of SQL Server and it community ... I added that 1 user to a database role and I set execute ... > permissions for some stored procedures in my database. ...
    (microsoft.public.sqlserver.security)
  • Re: Login with no Fixed Server Role and DB Role can stop SQL Agent Service?
    ... Yup - somehow the user has windows security rights to control services - we ... This posting is provided "AS IS" with no warranties, and confers no rights. ... >> a Window 2000 Login with Domain User default permissions, ... Forget about SQL Server for the moment. ...
    (microsoft.public.sqlserver.security)
  • Re: Slow booting xp home.
    ... Thirty seconds to boot Windows? ... I read somewhere that Microsoft suggest 30s boot up on xp home, I have seen videos on youtube of 8s boot up on xp, I'd be delighted with 30s and happy just to get below a minute. ... Installing and Registering Visual Studio Express Editions Smart Device ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: Setting perm. on stored procedures using windows auth.
    ... Thank you Wayne. ... > windows account and are in the local windows administrators group, ... > Wayne Snyder, MCDBA, SQL Server MVP ... >> permissions for some stored procedures in my database. ...
    (microsoft.public.sqlserver.security)

Quantcast