K. Brian Kelley - Databases, Infrastructure, and Security
New article: Identifying What Runs at Startup on SQL Server
Another article has published over at MSSQLTips.com. This one covers how to identify what stored procedures are set to run when SQL Server starts up as well as what jobs are set to run when SQL Server Agent comes online. An attacker could use both of these places to embed code to regain… Read more
0 comments, 96 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 30 January 2012
You require WHAT for a license?
I was trying to acquire a license for a product I was trying to look at using a free program. Now, because the organization is providing the license for free, I expect some strings to be attached. Want me email? Yup, how else would you send me the license? You… Read more
3 comments, 132 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 26 January 2012
About those backups...
So I went to present at Charleston PASS on Thursday night and of course I had my standard contact information on my slides. This included the web site I have (had) as my brochure site: truthsolutions.com (it's not up, so no link). I hadn't checked it in a while because… Read more
0 comments, 686 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 25 January 2012
Clicking on Links in Email
Every security awareness presentation makes the warning about opening attachments or clicking on links in emails when you don't know the sender or aren't 100% positive that the sender intended to send the email. Yet, despite this general warning, we all typically do it. For instance, if you're on Twitter and… Read more
0 comments, 151 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 24 January 2012
New Article: How to audit sysadmin members on multiple servers using PowerShell
My first article of 2012 has published over at MSSQLTips.com. This one covers the basic technique for using PowerShell to audit for a server role across multiple SQL Servers. It is assumed you have appropriate rights on those servers. You can read the article here:
0 comments, 113 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 23 January 2012
Speaking at Charleston PASS on January 19th
I will be presenting on SQL Server security on January 19th in Charleston, SC. You can find the details at the Charleston PASS website. I'm looking forward to it.
Both my wife and I graduated from colleges in Charleston. I'm a graduate of The Citadel and my wife graduated… Read more
0 comments, 165 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 4 January 2012
Renewed as MVP for SQL Server
I have been renewed as an MVP for SQL Server. This is my 4th award. It's humbling to receive the award each time, as many other MVPs have expressed. If you're wondering how to become an MVP, then Paul Randal's post (blog | twitter) from 2009 is probably the… Read more
3 comments, 309 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 2 January 2012
January Midlands PASS meeting - Hosting Ed Wilson, the "Scripting Guy"
On January 10, 2012, Midlands PASS is pleased to welcome back PowerShell expert and teacher, Ed Wilson (blog | twitter), and his lovely wife Teresa.
Whether you haven't learned what PowerShell is yet or you're an expert yourself, you're sure to learn something from Ed as he… Read more
0 comments, 149 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 30 December 2011
What is SQL Saturday?
I saw the following post from Andy Warren (blog | twitter), one of the creators of SQL Saturday. He was trying to explain what SQL Saturday was to a non-SQL person and found that while saying it's a free day of training is accurate but not complete. I… Read more
0 comments, 442 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 29 December 2011
SQLRally 2012 - Dallas Registration Is Open!
Want 2 days of Microsoft SQL Server training where you can hand-pick what you're learning about for the low price of $299?
That's what you get with SQLRally, which next year will be held in Dallas, Texas. Registration just opened for this event and the early bird $299 pricing… Read more
0 comments, 181 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 30 November 2011
No SQL Saturday - Columbia, SC in 2012
Last week my partner in crime, Bobby Dimmick (blog | twitter) and I sat down for lunch and caught up and asked the question, "What's next?" Bobby and I discussed plans and goals for next year and what became pretty apparent very quickly is that neither of us… Read more
2 comments, 156 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 14 November 2011
SQL Server security webinar now available on-demand
Last week I was able to give a SQL Server security webinar with Quest Software and SQL Server MVP Kevin E. Kline (blog | twitter). The webinar is available for viewing and the slides for download now:
Experts' Perspective Webcast: Building a Bulletproof Security Strategy for SQL Server Read more
0 comments, 144 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 8 November 2011
Meme Monday: #SQLFamily
Tom asks what #SQLFamily means to me. This is a hard one, not because of what #SQLFamily does for me, but rather, trying to limit it to a blog post.
#SQLFamily Provides Knowledge Growth Opportunities:
There is always something being talked about, whether SQL Server related or not, that I… Read more
1 comments, 144 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 7 November 2011
Presenting Tomorrow (Thursday) via Webinar - SQL Server Security
I have the privilege of being able to give a webinar tomorrow, November 3, at 11 AM EDT. It will be through Quest's Experts' Perspective series. You can register here:
In this webinar I'll be discussing how to design… Read more
0 comments, 141 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 2 November 2011
Webinar on SQL Server Security on November 3, 2011
I have the privilege of being able to give a webinar next Thursday, November 3, at 11 AM EDT. It will be through Quest's Experts' Perspective series. You can register here:
Experts' Perspective Webcast: Building a Bulletproof Security Strategy for SQL Server
In this webinar I'll be discussing how to… Read more
1 comments, 145 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 28 October 2011
Understanding Kerberos, Part III
Welcome back to both our Kerberos coverage and to another topic for SQL University's Security and Auditing Week. In today's lesson we're going to cast some light on what is likely the most used tool in managing Service Principal Names (SPNs) for Kerberos: SETSPN. If you're not familiar with… Read more
0 comments, 240 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 28 October 2011
SQL University: SQL Agent Jobs That Run at SQL Agent Start
Welcome to Security week at SQL University. I apologize for the late start. However, if you want to do some related reading from last week, take a look at the Kerberos series I started:
The reason I point out the Kerberos… Read more
0 comments, 172 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 27 October 2011
Understanding Kerberos, Part II
The majority of the time, the problems I see with Kerberos are due to a bad SPN (Service Principal Name) configuration. So in this post we'll talk about what an SPN contains and how it should look. An SPN contains several pieces of information:
- The service identifier (this is MSSQLSvc…
0 comments, 194 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 18 October 2011
Understanding Kerberos, Part I
A get a lot of questions where I work about Kerberos and how it works for SQL Server, whether we're talking about the database engine or Reporting Services. I also see it quite a bit on Twitter. This is a series of posts that looks to explain Kerberos in more… Read more
6 comments, 251 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 17 October 2011
Speaking at the 2011 Carolina Technology Conference
On Tuesday, October 18, 2011, I will be speaking at the Carolina Technology Conference in Columbia, SC. I'm scheduled for the 3:30-4:20 PM slot, meaning about a 40-45 minute presentation on database security. While I will focus primarily on Microsoft SQL Server security, I will approach database and data security… Read more
2 comments, 136 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 14 October 2011




Subscribe to this blog