Click here to monitor SSC
SQLServerCentral is supported by Red Gate Software Ltd.
 
Log in  ::  Register  ::  Not logged in
 
 
 
        
Home       Members    Calendar    Who's On


Add to briefcase

Is accessing MDF and LDF file enough to steal data? Expand / Collapse
Author
Message
Posted Tuesday, November 29, 2011 4:57 PM
Grasshopper

GrasshopperGrasshopperGrasshopperGrasshopperGrasshopperGrasshopperGrasshopperGrasshopper

Group: General Forum Members
Last Login: Wednesday, April 23, 2014 12:39 AM
Points: 18, Visits: 98
Hi all,

My question is if someone have access to mdf and ldf file of a DB, is it enough for him to access everything? for example can he then create a SQL or Access database and access the data??

Regards,
Amir
Post #1213614
Posted Tuesday, November 29, 2011 5:02 PM


SSCertifiable

SSCertifiableSSCertifiableSSCertifiableSSCertifiableSSCertifiableSSCertifiableSSCertifiableSSCertifiableSSCertifiable

Group: General Forum Members
Last Login: Today @ 10:14 PM
Points: 6,171, Visits: 7,237
Yes, with exceptions. Under standard circumstances (no TDE, san encryption, etc) then yes, a non-corrupt mdf can be completely restored elsewhere. You may get slight data loss or corruption if the file was copied during usage, but not severe enough that you'd consider it safe.


- Craig Farrell

Never stop learning, even if it hurts. Ego bruises are practically mandatory as you learn unless you've never risked enough to make a mistake.

For better assistance in answering your questions | Forum Netiquette
For index/tuning help, follow these directions. |Tally Tables

Twitter: @AnyWayDBA
Post #1213616
Posted Tuesday, November 29, 2011 5:11 PM


Keeper of the Duck

Keeper of the Duck

Group: Moderators
Last Login: Thursday, July 10, 2014 1:34 PM
Points: 6,623, Visits: 1,855
Without encryption, if I can get your .mdf and .ldf (and any .ndf files) for a given database, then I can attach the database as long as I have the same version or newer of SQL Server. I don't even have to go through a restore process (just for clarification).

This is a known issue with administrators over the system where SQL Server is installed. Even if you remove their access from within SQL Server, if they are able to stop SQL Server (which they can as administrators), they can then get the files at rest. This is why TDE is so attractive: minimum performance hit and the files at rest are encrypted.


K. Brian Kelley, CISA, MCSE, Security+, MVP - SQL Server
Regular Columnist (Security), SQLServerCentral.com
Author of Introduction to SQL Server: Basic Skills for Any SQL Server User
| Professional Development blog | Technical Blog | LinkedIn | Twitter
Post #1213618
Posted Tuesday, November 29, 2011 5:19 PM
Grasshopper

GrasshopperGrasshopperGrasshopperGrasshopperGrasshopperGrasshopperGrasshopperGrasshopper

Group: General Forum Members
Last Login: Wednesday, April 23, 2014 12:39 AM
Points: 18, Visits: 98
Thanks for your precise answers ...
Post #1213622
« Prev Topic | Next Topic »

Add to briefcase

Permissions Expand / Collapse