Security hole allows a remote job to run.



Hello everyone,

I discovered a security hole that I would like to close. There is a SQL
Account with only read permissions. However, from a remote computer a
DTS package can be scheduled by using this account by creating a job to
run from this remote computer to our production database. How can I
prevent a job outside of the production database from making a
connection using a SQL account.

Thank you for your time!

p.s. I did denywrite but it still allows the connection.


*** Sent via Developersdex http://www.developersdex.com ***
.



Relevant Pages

  • Re: W2K/WMI service (WinMgmt.exe) accessing an ODBC connection
    ... If a SQL account is used then the only thing needed on the ... machine running SQL is SQL login and database grants. ... If integrated, then in addition, I have seen the account need ... then changing this to use trusted connection ...
    (microsoft.public.win32.programmer.wmi)
  • Re: W2K/WMI service (WinMgmt.exe) accessing an ODBC connection
    ... If a SQL account is used then the only thing needed on the ... machine running SQL is SQL login and database grants. ... If integrated, then in addition, I have seen the account need ... then changing this to use trusted connection ...
    (microsoft.public.windows.server.security)
  • Re: Unable to use System DSN
    ... secure method to use ODBC connection information without ... >your app, and NOT with an NT Account, i think you should ... >a simple sql account with ONLY the privileges set that ... >> We are trying to use a System DSN to connect to a SQL ...
    (microsoft.public.dotnet.framework.adonet)
  • Re: Utter madness!
    ... If it's going to be "tricky" to get a trusted connection to my SQL box ... certain authentication scenarios are harder in that set ... To do the service account approach, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Unable to establish connection to sql database using trusted account
    ... > We were unable to establish a connection to a database on ... > a sql server using a trusted account. ...
    (microsoft.public.sharepoint.windowsservices)