SP_EXECUTESQL Security in 2005



Hi,

Recently moved a few DBs from '00 to '05. At that time our DBA changed the
security to all SP's so that the impersonating user only has access to
Execute the SP's. This seemed all fine and dandy, except that some of our
SP's had dynamic SQL using SP_EXECUTESQL, which fail on security when
executed.

She would like me to change all the SP's to not be dynamic (which, in these
cases, would not make sense).

I understand what she is trying to do, but it seems silly, to me, to not be
able to use SP_EXECUTESQL when "necessary".

Is there a way, security wise (or something else outside the range of my
question) to meet in the middle or is there a way to change my SP to be able
to accomplish the same functionality?

Thank you
t
.



Relevant Pages

  • Re: SP_EXECUTESQL Security in 2005
    ... the Impersonating User only has access to run a SP, ... occasions) create Dynamic SQL ... security to all SP's so that the impersonating user only has access to ... Execute the SP's. ...
    (microsoft.public.sqlserver.security)
  • Re: SP_EXECUTESQL Security in 2005
    ... the Impersonating User only has access to run a SP, ... occasions) create Dynamic SQL ... security to all SP's so that the impersonating user only has access to ... Execute the SP's. ...
    (microsoft.public.sqlserver.security)
  • [NEWS] DB2 on iSeries Stored Procedures Vulnerability
    ... Beyond Security would like to welcome Tiscali World Online ... This vulnerability lets an otherwise limited user execute iSeries ... This vulnerability lets a user execute REXX scripts. ... CL programs sources are kept in Source files. ...
    (Securiteam)
  • [Full-Disclosure] Flaws security feature of SP2
    ... Author: Jürgen Schmidt, heise Security ... Windows Explorer does not update zone information ... When a user tries to execute a file downloaded from the ... files from archives with a ZoneID greater than or equal ...
    (Full-Disclosure)
  • RE: [Full-Disclosure] Flaws security feature of SP2
    ... Flaws security feature of SP2 ... Windows Explorer does not update zone information ... When a user tries to execute a file downloaded from the ... files from archives with a ZoneID greater than or equal ...
    (Full-Disclosure)