Re: securing a database deployment

From: Zach Wells (zwells_at_remove_ain1.com)
Date: 10/13/04


Date: Wed, 13 Oct 2004 15:00:39 -0500

Essam Salah wrote:
> Hi All
>
> I want to deploy a SQL server database on my client windows 2003 server ; I
> will have admin access on the server through Terminal services
>
> The client server will have SQL server 2000 installed ; and I will use a
> backup copy of my db and install it using Restor Database command in the
> Enterprise manager
>
> How can prevent my client from viewing/modifing my Database while he has
> admin access to the server ?

Charge him 5xyour normal rate to fix anything he breaks.

>
> The database will host information relative to an ASP.net website that is
> hosted on IIS on the same server ; a username/password for this DB should be
> available also on the web.config file of the ASP.net website .. what is the
> minimum security setting that should be given to this username/password to
> allow the website manipulate the database ?
>
> Please advice about that ; the reason I want to do this is to prevent my
> client from reverse engineering my system analysis and databse design; but
> at the same time being able to use my ASP.net web application .
>

You can create contracts that make it illegal for them to reverse
engineer your application, assuming you're selling him a complete
application and that you weren't hired to create the specific
application for the client.

Zach



Relevant Pages

  • RE: database server audit tools
    ... * Oracle Application Server ... please send me also some links to harden my database server from attacks.. ... Audit your website security with Acunetix Web Vulnerability Scanner: ...
    (Pen-Test)
  • Re: Brainwave: A Complete Web Platform With Database Out of the Box
    ... Its application server is built on CherryPy. ... And its database is its true gem. ... large form to fill out; huge license agreement; very little documentation outside of PDF; online demo links to a local IP address; NOTHING I can find on the website actually runs on Brainwave etc. etc. ... Spend all your time making your website look good with content that is available online easily. ...
    (comp.lang.python)
  • Re: Databse Results
    ... Therefore as the webmaster I can grant access to the other website via the control panel. ... database in another website, unless the sites are under a single user account and on the same server.". ... > Thomas A. Rowe (Microsoft MVP - FrontPage) ...
    (microsoft.public.frontpage.client)
  • Re: Publishing data from WinForms application to the web
    ... But this client app should have access to WebSite DB. ... I am using SQL Server 2005. ... I am creating a WinForms application for a client. ... Server database up to a database on a website also SQL Server 2005). ...
    (microsoft.public.vsnet.general)
  • Re: Databse Results
    ... If any host allows one website to see or access another website's database ... Thomas A. Rowe (Microsoft MVP - FrontPage) ... > A web server can also be a file server, ...
    (microsoft.public.frontpage.client)

Quantcast