Passwords retrievable via SQLDMO

From: Harlan Messinger (h.messinger_at_comcast.net)
Date: 01/10/05

  • Next message: Reddi: "Permissions question"
    Date: Mon, 10 Jan 2005 17:21:43 -0500
    
    

    I was startled, while experimenting with the SQLDMO library, to find out
    that it allows you to see the passwords that were used to register SQL
    Servers in Enterprise Manager. Is it me, or is this an astonishing security
    breach?

    -- 
    Harlan Messinger
    Remove the first dot from my e-mail address.
    Veuillez ๔ter le premier point de mon adresse de courriel.
    

  • Next message: Reddi: "Permissions question"

    Relevant Pages

    • Re: nessus scan
      ... Null sessions do NOT allow unauthenticated access to data on ... > when XP Pro users try to change their domain passwords at logon. ... > downlevel clients to access those servers. ... > auditing for account logons events and account management on domain ...
      (microsoft.public.win2000.security)
    • Re: Outlook express
      ... I recently purchased a Dell and still want to use Outlook ... no matter what computer you use to access your account. ... still go through all of your accounts with passwords and change them. ... Email goes to your ISP's servers, ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: How do you have OWA configured????
      ... How to Change OWA Passwords Through IIS ... The exchange servers are stand alone AD units that ...
      (microsoft.public.inetserver.iis.security)
    • Re: Lock out Internet logon attempts?
      ... > How long are your passwords? ... >> willing to take the minimum precautions of safety on the internet, ... >> Safety and Security starts with the servers that I own. ...
      (microsoft.public.security)
    • Re: [Linux]: password sync in 2 or more linux boxes
      ... >> how could I acheive passwd sync in 2 or more linux servers. ... So NIS and NFS is out of question. ... > Passwords are stored encrypted on your system anyway. ...
      (comp.os.linux.security)

  • Quantcast