Re: Web and SQL Security

From: Dennis Redfield (dennis_redfield_at_newsgroup.nospam)
Date: 03/23/05


Date: Wed, 23 Mar 2005 09:48:12 -0500

Usually the issue is concerned with SQL Server housed on the same box as a
web server running OUTSIDE the firewall. Typically (!) DB servers are not
placed outside the firewall. There is nothing inhirently insecure about IIS
and SQL Server on the same box, although you will want to review the
recommendations on hardening both your IIS and SQL Server installations.

hope this helps.

dlr

"David" <Dante@community.nospam> wrote in message
news:E3F758FD-A178-4DC9-8CB1-2567F9DA9468@microsoft.com...
> Hi
>
> I know that a couple of years ago I read a Microsoft recommendation that
SQL
> server shoudl not run on the same machine as IIS.
>
> We are looking at taking a managed hosted server for an app. and I
wondered
> if the same reccomendation applies. Does it depend on the way the hosting
> company sets up the server or is it always less secure when the two are on
> one machine?
> We can have two less powerful machines or one more powerful machine to do
> the job and security is the thing that will determine which way to go. We
wil
> use Windows Server 2003, SQL Server 200 and .Net Framework.
>
> Any thoughts appreciated.
>
> David



Relevant Pages

  • Re: IS IT SAFE TO HOST SQL SERVER AND IIS SERVER ON THE SAME MACHINE
    ... > safe to host a web application on a mchine outside of our firewall ... and the sql server would reside on this one machine. ... The vulnerabilities of Windows, IIS and SQL are well known, so you ...
    (microsoft.public.inetserver.iis.security)
  • Re: Clickonce and license question question
    ... would prefer to change the way we license / register the application. ... updates the SQL server at our ISP that the license key is now in use. ... What about just meaking the company open their firewall for the server? ...
    (microsoft.public.dotnet.framework.windowsforms)
  • Re: Connection error from VBScript
    ... The only firewall we use is Windows Firewall and that is disabled by default ... -2147467259 from MS OLE DB Provider, Specified SQL Server not found. ... you only need TCP/IP connectivity and TCP port 1433 to ...
    (microsoft.public.data.ado)
  • RE: SBS 2003 Unable to connect to database STS_Config
    ... Uninstall the SQL server from the SBS 2k3 server from add/remove programs ... Uninstall Microsoft SQL Server Desktop Engine (SHAREPOINT) ... If AV software install any extra IIS virtual directory, ...
    (microsoft.public.windows.server.sbs)
  • Re: Memory issues with 64-bit SQL Server 2005 on 64-bit Win 2003 C
    ... I also checked the individual patch levels for the .NET drivers, SQL Server ... The SQL Server is fully patched, however Windows Update reported that the OS ... Lock pages in memory -- I guess you might have taken care of it as well. ...
    (microsoft.public.sqlserver.clustering)