﻿<?xml version="1.0" encoding="utf-8"?><rss xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" version="2.0"><channel><title>SQLServerCentral.com Content tagged Security</title><link>http://www.sqlservercentral.com/</link><description>Content tagged Security posted on SQLServerCentral.com</description><language>en-us</language><ttl>360</ttl><managingEditor>sjones@sqlservercentral.com (Steve Jones)</managingEditor><item><title>Loginless In Seattle</title><description><![CDATA[<p>Identify orphaned Database Users and differentiate them from &quot;Loginless&quot; Database Users.</p>]]></description><guid>http://www.sqlservercentral.com/articles/Security/98202/</guid><pubDate>Mon, 13 May 2013 06:00:00 UT</pubDate><link>http://www.sqlservercentral.com/articles/Security/98202/</link></item><item><title>The Security of You</title><description><![CDATA[<p>There is a lot of data out there that is specific to an individual, none more important perhaps than biometric data. Steve Jones writes a bit about the security implications involved in working with this data. (This editorial was originally published on Nov 10, 2008. It is being re-run as Steve is at SQL Bits.)</p>]]></description><guid>http://www.sqlservercentral.com/articles/Editorial/64873/</guid><pubDate>Fri, 03 May 2013 06:00:00 UT</pubDate><link>http://www.sqlservercentral.com/articles/Editorial/64873/</link></item><item><title>Getting the lowdown on 18456 errors</title><description><![CDATA[<p>If you can establish a connection to a SQL Server, but are having problems logging in to it, you will...</p>]]></description><guid>http://www.sqlservercentral.com/blogs/discussionofsqlserver/2013/04/18/getting-the-lowdown-on-18456-errors/</guid><pubDate>Tue, 30 Apr 2013 06:00:00 UT</pubDate><link>http://www.sqlservercentral.com/blogs/discussionofsqlserver/2013/04/18/getting-the-lowdown-on-18456-errors/</link></item><item><title>Script to find username and corresponding loginname for all user DB</title><description><![CDATA[<p>Script to find username and corresponding loginname for all user database in SQL Server</p>]]></description><guid>http://www.sqlservercentral.com/scripts/Security/98347/</guid><pubDate>Mon, 29 Apr 2013 06:00:00 UT</pubDate><link>http://www.sqlservercentral.com/scripts/Security/98347/</link></item><item><title>Change DB Owner to sa for multiple DB's</title><description><![CDATA[<p>Changes DB owner to sa for Online DB's where owner is not sa</p>]]></description><guid>http://www.sqlservercentral.com/scripts/Security/98338/</guid><pubDate>Fri, 26 Apr 2013 06:00:00 UT</pubDate><link>http://www.sqlservercentral.com/scripts/Security/98338/</link></item><item><title>The Patch Wild, Wild West </title><description><![CDATA[<p>Microsoft might be changing their patching process for applications. This has Steve Jones worried they may move towards an Apple/iOS like model, which would not be good for server systems.
</p>]]></description><guid>http://www.sqlservercentral.com/articles/Editorial/98404/</guid><pubDate>Wed, 17 Apr 2013 06:00:00 UT</pubDate><link>http://www.sqlservercentral.com/articles/Editorial/98404/</link></item><item><title>Security: People Are the Weakest Link</title><description><![CDATA[<p>There was an interesting conversation on Twitter today about security awareness and why the training&#160;so often fails. From my perspective,&#160;here's...</p>]]></description><guid>http://www.sqlservercentral.com/blogs/brian_kelley/2013/03/28/security-people-are-the-weakest-link/</guid><pubDate>Fri, 05 Apr 2013 06:00:00 UT</pubDate><link>http://www.sqlservercentral.com/blogs/brian_kelley/2013/03/28/security-people-are-the-weakest-link/</link></item><item><title>How do I move a SQL login from one server to another without the password?</title><description><![CDATA[<p>This is an uncommon task but one that does turn up every once in awhile.  A SQL login has to...</p>]]></description><guid>http://www.sqlservercentral.com/blogs/sqlstudies/2013/03/25/how-do-i-move-a-sql-login-from-one-server-to-another-without-the-password/</guid><pubDate>Wed, 03 Apr 2013 06:00:00 UT</pubDate><link>http://www.sqlservercentral.com/blogs/sqlstudies/2013/03/25/how-do-i-move-a-sql-login-from-one-server-to-another-without-the-password/</link></item><item><title>The Command Shell</title><description><![CDATA[<p>This Friday Steve Jones talks about xp_cmdshell and the security regarding its use. Do you have any holes that might exist if administrators are allowed to use this tool on their instances?</p>]]></description><guid>http://www.sqlservercentral.com/articles/Editorial/98034/</guid><pubDate>Fri, 29 Mar 2013 06:00:00 UT</pubDate><link>http://www.sqlservercentral.com/articles/Editorial/98034/</link></item><item><title>A Good Security Response</title><description><![CDATA[<p>Evernote recently had a security incident and forced all users to reset their passwords. Many people thought this was a good response to a security incident. Would your company act in a similar manner?</p><!-- 12 Tools (SQL Dev Bundle)-->
<table border="0" cellpadding="0" cellspacing="10" style="width: 100%;"> <colgroup>  <col width="68" />  <col width="1266" /> </colgroup> <tbody>  <tr align="left" valign="top">   <td>    <a href="http://www.red-gate.com/products/sql-development/sql-developer-bundle/?utm_source=ssc&utm_medium=pubad&utm_content=12_tools&utm_campaign=sqldeveloperbundle&utm_term=rss-20013"><img src="http://assets.red-gate.com/external/SSC/devbundle_68x68.gif" alt="sqldeveloperbundle"></td>   <td><strong>12 essential tools for database professionals</strong><br />The SQL Developer Bundle contains 12 tools designed with the SQL Server developer and DBA in mind.  <a href="http://www.red-gate.com/products/sql-development/sql-developer-bundle/?utm_source=ssc&utm_medium=pubad&utm_content=12_tools&utm_campaign=sqldeveloperbundle&utm_term=rss-20013">Try it now.</a></td>  </tr> </tbody></table>


]]></description><guid>http://www.sqlservercentral.com/articles/Editorial/97943/</guid><pubDate>Tue, 26 Mar 2013 06:00:00 UT</pubDate><link>http://www.sqlservercentral.com/articles/Editorial/97943/</link></item><item><title>Algorithm Secrecy is not Security</title><description><![CDATA[<p>This week Steve Jones talks encryption and why you shouldn't be implementing anything you've invented.</p>]]></description><guid>http://www.sqlservercentral.com/articles/Security/97714/</guid><pubDate>Mon, 18 Mar 2013 06:00:00 UT</pubDate><link>http://www.sqlservercentral.com/articles/Security/97714/</link></item><item><title>Script to clean up “Windows” logins no longer in AD</title><description><![CDATA[<p>I was scanning http://dba.stackexchange.com and ran across the following question:
http://dba.stackexchange.com/questions/31478/sql-server-script-to-delete-accounts-no-longer-in-active-directory
Basically the OP wanted to know how to get rid of...</p>]]></description><guid>http://www.sqlservercentral.com/blogs/sqlstudies/2013/03/01/script-to-clean-up-windows-logins-no-longer-in-ad/</guid><pubDate>Tue, 12 Mar 2013 06:00:00 UT</pubDate><link>http://www.sqlservercentral.com/blogs/sqlstudies/2013/03/01/script-to-clean-up-windows-logins-no-longer-in-ad/</link></item><item><title>Securing SQL Server: Vulnerabilities You Might Not Have Considered</title><description><![CDATA[<p>A short look at the vulnerabilities your data may be susceptible to outside of the database tables. </p>]]></description><guid>http://www.sqlservercentral.com/articles/Encryption/97271/</guid><pubDate>Thu, 07 Mar 2013 07:00:00 UT</pubDate><link>http://www.sqlservercentral.com/articles/Encryption/97271/</link></item><item><title>Data We Don't Want</title><description><![CDATA[<p>There's potentially an exploit that can download lots of data to a machine. This shouldn't be a concern for servers, but you never know.</p>]]></description><guid>http://www.sqlservercentral.com/articles/Editorial/97460/</guid><pubDate>Tue, 05 Mar 2013 07:00:00 UT</pubDate><link>http://www.sqlservercentral.com/articles/Editorial/97460/</link></item><item><title>How to recover a SQL Server login password.</title><description><![CDATA[<p>I will describe a simple method anyone can use to obtain lost password information for a SQL Server login.</p>]]></description><guid>http://www.sqlservercentral.com/articles/password+cracking/96540/</guid><pubDate>Mon, 04 Mar 2013 07:00:00 UT</pubDate><link>http://www.sqlservercentral.com/articles/password+cracking/96540/</link></item><item><title>Security Change Snapshot</title><description><![CDATA[<p>This script gives a server level snapshot of recent security changes</p>]]></description><guid>http://www.sqlservercentral.com/scripts/Security/96976/</guid><pubDate>Thu, 28 Feb 2013 07:00:00 UT</pubDate><link>http://www.sqlservercentral.com/scripts/Security/96976/</link></item><item><title>Alter User</title><description><![CDATA[<p></p>]]></description><guid>http://www.sqlservercentral.com/questions/User/96359/</guid><pubDate>Mon, 18 Feb 2013 07:00:00 UT</pubDate><link>http://www.sqlservercentral.com/questions/User/96359/</link></item><item><title>Stored Procedures and SQL Injection</title><description><![CDATA[<p>Why do stored procedures help with security? In this piece, MVP Brian Kelley explains why SQL Injection and information gathering are hampered with stored procedures.</p><!-- 12 Tools (SQL Dev Bundle)-->
<table border="0" cellpadding="0" cellspacing="10" style="width: 100%;"> <colgroup>  <col width="68" />  <col width="1266" /> </colgroup> <tbody>  <tr align="left" valign="top">   <td>    <a href="http://www.red-gate.com/products/sql-development/sql-developer-bundle/?utm_source=ssc&utm_medium=pubad&utm_content=12_tools&utm_campaign=sqldeveloperbundle&utm_term=rss-20013"><img src="http://assets.red-gate.com/external/SSC/devbundle_68x68.gif" alt="sqldeveloperbundle"></td>   <td><strong>12 essential tools for database professionals</strong><br />The SQL Developer Bundle contains 12 tools designed with the SQL Server developer and DBA in mind.  <a href="http://www.red-gate.com/products/sql-development/sql-developer-bundle/?utm_source=ssc&utm_medium=pubad&utm_content=12_tools&utm_campaign=sqldeveloperbundle&utm_term=rss-20013">Try it now.</a></td>  </tr> </tbody></table>


]]></description><guid>http://www.sqlservercentral.com/articles/Security/96328/</guid><pubDate>Mon, 18 Feb 2013 07:00:00 UT</pubDate><link>http://www.sqlservercentral.com/articles/Security/96328/</link></item><item><title>Granting Permission to Grant Permissions</title><description><![CDATA[<p>I’ve never felt the need to allow this, but I saw someone ask the questions recently. Suppose you had a...</p>]]></description><guid>http://www.sqlservercentral.com/blogs/steve_jones/2013/01/28/granting-permission-to-grant-permissions/</guid><pubDate>Fri, 08 Feb 2013 07:00:00 UT</pubDate><link>http://www.sqlservercentral.com/blogs/steve_jones/2013/01/28/granting-permission-to-grant-permissions/</link></item><item><title>Serious Security</title><description><![CDATA[<p>The password issue has Steve Jones concerned. So many of us that use computing devices don't do a good job of securing our information.</p>]]></description><guid>http://www.sqlservercentral.com/articles/Editorial/95959/</guid><pubDate>Thu, 17 Jan 2013 07:00:00 UT</pubDate><link>http://www.sqlservercentral.com/articles/Editorial/95959/</link></item><item><title>Statistical Protection</title><description><![CDATA[<p>Statistical databases contain lots of information that can be used in a variety of ways, but it can also be abused. Steve Jones talks about some of the problems and potential solutions.</p>]]></description><guid>http://www.sqlservercentral.com/articles/Editorial/95957/</guid><pubDate>Tue, 08 Jan 2013 07:00:00 UT</pubDate><link>http://www.sqlservercentral.com/articles/Editorial/95957/</link></item><item><title>The $50,000 Laptop</title><description><![CDATA[<p>The average value of a lost laptop has been found to be much more than you might expect. Steve Jones talks about a recent study.</p>]]></description><guid>http://www.sqlservercentral.com/articles/Editorial/95956/</guid><pubDate>Mon, 07 Jan 2013 07:00:00 UT</pubDate><link>http://www.sqlservercentral.com/articles/Editorial/95956/</link></item><item><title>List all Usernames, Roles for all the databases.</title><description><![CDATA[<p>Generates a list of ALL Users and their database Roles for all Databases (Or for a specific user).</p>]]></description><guid>http://www.sqlservercentral.com/scripts/Administration/63841/</guid><pubDate>Mon, 31 Dec 2012 07:00:00 UT</pubDate><link>http://www.sqlservercentral.com/scripts/Administration/63841/</link></item><item><title>The Principle of Least Privilege</title><description><![CDATA[<p>One of the tenets of good security is that no person or process is granted more rights than it needs...</p>]]></description><guid>http://www.sqlservercentral.com/blogs/steve_jones/2012/12/17/the-principle-of-least-privilege/</guid><pubDate>Fri, 21 Dec 2012 07:00:00 UT</pubDate><link>http://www.sqlservercentral.com/blogs/steve_jones/2012/12/17/the-principle-of-least-privilege/</link></item><item><title>You Need to Manage Passwords</title><description><![CDATA[<p>I saw a note this week from CNet about a system built to crack passwords (also on ArsTechnica). It reminded...</p>]]></description><guid>http://www.sqlservercentral.com/blogs/steve_jones/2012/12/12/you-need-to-manage-passwords/</guid><pubDate>Tue, 18 Dec 2012 07:00:00 UT</pubDate><link>http://www.sqlservercentral.com/blogs/steve_jones/2012/12/12/you-need-to-manage-passwords/</link></item><item><title>Logins vs Users</title><description><![CDATA[<p>Logins are not Users. It’s a pretty easy concept but one that seems to give a lot of people problems....</p>]]></description><guid>http://www.sqlservercentral.com/blogs/sqlstudies/2012/12/03/logins-vs-users/</guid><pubDate>Wed, 12 Dec 2012 07:00:00 UT</pubDate><link>http://www.sqlservercentral.com/blogs/sqlstudies/2012/12/03/logins-vs-users/</link></item><item><title>Regulators, Mount Up</title><description><![CDATA[<p>If you are bound by HIPAA regulations, you may have more auditing in your future. If you're not, perhaps you should still pay attention to the criteria being used for auditing.</p>]]></description><guid>http://www.sqlservercentral.com/articles/Editorial/95262/</guid><pubDate>Wed, 28 Nov 2012 07:00:00 UT</pubDate><link>http://www.sqlservercentral.com/articles/Editorial/95262/</link></item><item><title>Password Insecurities</title><description><![CDATA[<p>Tony Davis argues that the Standards and best practices exist to avoid being hacked, but implementing them requires time and investment and often there simply doesn't seem to be the will to do it.</p>]]></description><guid>http://www.sqlservercentral.com/articles/Editorial/95224/</guid><pubDate>Mon, 26 Nov 2012 07:00:00 UT</pubDate><link>http://www.sqlservercentral.com/articles/Editorial/95224/</link></item><item><title>Unprotected Queries</title><description><![CDATA[<p>There are over half a million database servers out on the Internet without protection. How can this happen?</p>]]></description><guid>http://www.sqlservercentral.com/articles/Editorial/61655/</guid><pubDate>Tue, 06 Nov 2012 07:00:00 UT</pubDate><link>http://www.sqlservercentral.com/articles/Editorial/61655/</link></item><item><title>SQL Server Reporting Services 2012 Permissions </title><description><![CDATA[<p>As you begin developing reports for deployment to a Report Server, what security considerations need to be taken into account in order to grant users access to run a report.</p>]]></description><guid>http://www.sqlservercentral.com/redirect/articles/94589/</guid><pubDate>Wed, 31 Oct 2012 06:00:00 UT</pubDate><link>http://www.sqlservercentral.com/redirect/articles/94589/</link></item></channel></rss>