Re: Port 1433 is open to internet, how can I secure db?

From: John Bell (jbellnewsposts_at_hotmail.com)
Date: 07/03/05

  • Next message: John Bell: "Re: Preventing ALL text SQL Injection by removing single-quotes ?"
    Date: Sun, 3 Jul 2005 10:20:06 +0100
    
    

    Hi

    Security is not only what is in-built into the product, your whole
    organisation needs to be taken into account when considering how secure your
    systems are. Although IDS systems and strong passwords may stop or hold off
    recognised brute force attacks, they will not guard against social
    engineering, mis-configuration or unknown security issues. This is not only
    applies to SQL Server, but the OS and other software that is running on your
    exposed server.

    In this country your can by a wall safe that looks like and electical
    socket. That does not stop a burgular kicking in all the electrical sockets
    in the house. But if you put that safe on your outside wall, how long before
    it was kicked in?

    John

    "Hoof Hearted" <HoofHearted@discussions.microsoft.com> wrote in message
    news:3EF88705-53A2-43D9-8B58-5E375DDF7804@microsoft.com...
    > Pardon me for jumping in...
    >
    > I administer a few networks, all with Sql Server exposed to the outside
    > world on port 1433. I have never had any problems. If strong passwords
    > are
    > in place, isn't sql server secure?
    >


  • Next message: John Bell: "Re: Preventing ALL text SQL Injection by removing single-quotes ?"

    Relevant Pages

    • Re: Protecting database from administrators
      ... there is no encryption while at rest it must still be secure. ... All the security MS has offered is weak. ... If it is attached to SQL Server on ...
      (microsoft.public.sqlserver.security)
    • Re: Is there any way to prevent hacker trying to guess sa password?
      ... My point is that Microsoft should know by ... Having a SQL Server or several should NOT need a "security team", ... because MS can't provide a simple secure solution. ...
      (microsoft.public.sqlserver.security)
    • Re: How secure is MS SQL Server 2000?
      ... While you do need to lock down SQL Server your ... It uses the full Windows security features. ... > impression is one of frustration when it comes to trying to secure a SQL ... >>>So I can have port TCP 1433 and UPD 1434 open and still retain a secure ...
      (microsoft.public.sqlserver.security)
    • Re: hide contents of a table
      ... You can go a long way at obscuring things with Access security (including ... keep the honest and idle curious out, however if you need strong security ... you should consider a server based system - SQL Server. ... > What is the best way to secure the data in the table? ...
      (microsoft.public.access.security)
    • Re: Ten least secure programs
      ... it's probably better you leave the topic alone ... I said I do not have security issues with the programs I code. ... I didn't realize you were a Linux user, ... > the most widely used and secure UNIX flavors? ...
      (Security-Basics)

    Loading