Anyone can access my Sql Server!

From: ian (anonymous_at_discussions.microsoft.com)
Date: 09/16/04


Date: Thu, 16 Sep 2004 12:44:28 -0700

I have Sql Server running an a SBS2003 box. I want to
provide access to a couple of users via the internet.

At first they couldn't connect because the Authentication
was set to Windows Only. I have changed it to Sql Server
and Windows, and now they can successfully create a DSN
using their credentials.

What I also have found to my horror is that using NT
authentication, a DSN can be created from anywhere
regardless of the Login ID. When a DSN has been created in
this manner, data can be changed.

My database is wide open - Help!



Relevant Pages

  • Re: Windows Authentication in asp.net 2005 to SQL Server?
    ... If the domains do not trust each other, Windows authentication is not going ... Basic authentication sometimes makes the need for Kerberos delegation go ... generic account to do the backend data stuff on our SQL Server. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Remote connection failed
    ... If you are going over a remote connection or are not logging ... into the domain where SQL Server is then no, Windows ... authentication won't work. ...
    (microsoft.public.sqlserver.connect)
  • RE: RefreshLink error - 3078
    ... this was tested on Windows XP w/ SP2 installed. ... because the DSN is incorrectly configured/installed. ... and it sure enough had showed the data I had in my SQL server ... Microsoft Online Partner Support ...
    (microsoft.public.access.conversion)
  • Re: Changing passwords / Blocking SA login attempts
    ... I went into the Server Config properties and changed to Windows ... My login for Start and Run SQL server was in this format. ... I am supposing this was an SQL authentication, ...
    (microsoft.public.sqlserver.security)
  • Windows Authentication with IIS on separate machines
    ... Yes, setting Basic Authentication in IIS works, but the ... >in SQL server but doesn't work if user account was ... >imported from a Windows account. ...
    (microsoft.public.sqlserver.security)