Web and SQL Security

From: David (Dante_at_community.nospam)
Date: 03/23/05


Date: Wed, 23 Mar 2005 06:13:05 -0800

Hi

I know that a couple of years ago I read a Microsoft recommendation that SQL
server shoudl not run on the same machine as IIS.

We are looking at taking a managed hosted server for an app. and I wondered
if the same reccomendation applies. Does it depend on the way the hosting
company sets up the server or is it always less secure when the two are on
one machine?
We can have two less powerful machines or one more powerful machine to do
the job and security is the thing that will determine which way to go. We wil
use Windows Server 2003, SQL Server 200 and .Net Framework.

Any thoughts appreciated.

David



Relevant Pages

  • FW: Microsoft Security Advisory MS 03-007
    ... am trying to find a vulnerability tester/script and I could test it out ... Department of the Army server that had been compromised and that this ... announcement covers IIS 5.1 but not IIS 6, ... How a Hacker Uses SQL Injection to Steal Your SQL Data! ...
    (Focus-Microsoft)
  • RE: Confusion on standard security methodologies.
    ... Application will talk to a back-end SQL ... By "back-end," I assume you mean on a different box from IIS? ... If SQL is on a separate box, you won't be able to use NT authentication ... impersonations (meaning that once passed to the IIS server, ...
    (microsoft.public.inetserver.iis.security)
  • RE: MS patch-scanner for Win-NT, 2K, IIS, SQL
    ... MS patch-scanner for Win-NT, 2K, IIS, SQL ... XML file from the following location - mssecure.xml Possible ... and on a NT 4 Server, but the scanner works fine on a W2K Server ...
    (Focus-Microsoft)
  • Re: SQL CE Synching Problems
    ... install location of SQL CE instead of under Inetpub like I had done before. ... > so the issue has to be between the server tools and the publisher. ... >>I ran the wizard again to check all the permissions and this is what it ... >> A request to send data to the computer running IIS has failed. ...
    (microsoft.public.sqlserver.ce)
  • Re: IIS6 hang
    ... > sql 2000 ... > about 800 sessions to IIS at any given time from onsite ... > crash and hang agent or iisstate to help me out. ... > information from another server. ...
    (microsoft.public.inetserver.iis)