Re: Internet password attacks

From: Hal Berenson (hberenson_at_predictableit.com)
Date: 08/31/05

  • Next message: Hal Berenson: "Re: Internet password attacks"
    Date: Wed, 31 Aug 2005 15:07:01 -0600
    
    

    I'm not currently an MVP, but I was the General Manager of the SQL Server
    group. And I made the decisions on what security enhancements went into SQL
    Server 2000. So while I can't speak for Microsoft, and I can provide both
    historical perspective and decent analysis of why Microsoft does things.

    -- 
    Hal Berenson, President
    PredictableIT, LLC
    "FloMister" <FloMister@discussions.microsoft.com> wrote in message 
    news:72AA5F92-5276-4B97-A3F1-2827338DA22F@microsoft.com...
    > I've been programming for 20+ years and to me there are a number of
    > inexpensive solutions to this problem that Microsoft could deploy, but 
    > they
    > have delibertly choosen not to for whatever motive.  The fact that no
    > Micrsoft MVP has responded to this post as I have seen in most other 
    > posts,
    > further backs this opinion.
    >
    > Is there a Microsft MVP out there willing to touch this issue?
    >
    > "Ross Presser" wrote:
    >
    >> On Mon, 29 Aug 2005 08:22:51 -0400, Russell Stevens wrote:
    >>
    >> > <<Allow the SA account to be renamed in a service pack?  You are mad>>
    >> >
    >> > No - the SP doesn't rename it, it gives the SQL admin the ability to 
    >> > change
    >> > it. If he has apps that use it, then he can fix them first or leave as 
    >> > is.
    >>
    >> There are many many parts *internal* to SQL server that depend on the sa
    >> account being named sa.  A service pack that changes them all to tolerate 
    >> a
    >> renamed sa account is a dangerous thing to do.
    >> 
    

  • Next message: Hal Berenson: "Re: Internet password attacks"

    Relevant Pages

    • RE: Sp_xp_cmdshell_proxy_account & SQL 2005
      ... I Iunderstand that you are unable to create the proxy account on SQL Server ... Microsoft Online Community Support ...
      (microsoft.public.sqlserver.security)
    • Re: logon failure
      ... MSSQLServer service after you change the username of administrator account. ... username for the SQL Server startup service account or the SQL Server Agent ... Microsoft SQL Server service account on the SQL Server host computer. ...
      (microsoft.public.windows.server.sbs)
    • RE: Problem: Changing the SQL Server services password
      ... Are the passwords of SQL Server service account and Microsoft Cluster ... By default the error logs are located in the folder ...
      (microsoft.public.sqlserver.clustering)
    • Re: Problem: Changing the SQL Server services password
      ... Are the passwords of SQL Server service account and Microsoft Cluster ... By default the error logs are located in the folder ...
      (microsoft.public.sqlserver.clustering)
    • Re: Can SQL Server 2000 and 2005 Coexist???
      ... Microsoft itself declared that they've seen people with Beta2 in production. ... But SQL Server 2005 is still in beta, so don't put it on a production ... > Mike Epprecht, Microsoft SQL Server MVP ...
      (microsoft.public.sqlserver.setup)