K. Brian Kelley - Databases, Infrastructure, and Security
Archives: March 2009
SQL Server Authentication Modes and Surface Area Test
One of the videos I did for JumpStart TV is up on the front page:
It is an introductory video to help understand the two types of authentication SQL Server can perform: Windows authentication only and Mixed Mode. It's primary purpose was to cover the two… Read more
0 comments, 357 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 16 March 2009
Microsoft March Security Bulletin Release
This month there were 3 security bulletins released and 1 re-released:
First, let's tackle the bulletin which was re-released. MS08-052, which was issued for a remote code execution vulnerabilities in GDI+ (graphics rendering). The bulletin was re-released to cover situations where Windows… Read more
0 comments, 248 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 10 March 2009
[Off-Topic] Eleven Year-Old Making a Difference
Those who know me personally know that I grow my hair out to donate for kids. I have donated a couple of times to Locks of Love. This past Saturday I participated in a hair collection drive led by 11 year-old Sarah Brotman:
3 comments, 174 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 9 March 2009
CONTROL SERVER vs. sysadmin membership
In a previous blog post on Detecting When a Login Has Implicit Access to a Database, I mentioned that having CONTROL SERVER rights means having implicit rights into the databases. Robert Davis posted a comment asking if there was a difference with respect to explicit permissions between being a… Read more
2 comments, 1,859 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 6 March 2009
Adobe Flash Player Update Available
There is an Adobe Flash Player available to address a security issue. The bulletin shows as being released February 24, 2008, however, my system didn't show an alert for it until this week. Details here:
The reason I flag… Read more
2 comments, 239 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 6 March 2009
Three Operating System (Windows) patches due on Tuesday
Microsoft's advance security bulletin has come out and it looks like they are planning on releasing 3 security bulletins on Tuesday, March 10, 2009. However, none are for the Excel malformed file issue that is currently being exploited. Of the patches, one is a critical rated remote code execution vulnerability.… Read more
0 comments, 144 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 6 March 2009
Owning an Object in SQL Server 2005/2008
One of the things that we have to re-learn when going from SQL Server 2000 to 2005/2008 is that objects no longer have owners. Rather, objects are contained in schema and schema have owners. And if you query sys.objects, you will see that this seems to hold true. While there… Read more
0 comments, 2,427 reads
Posted in K. Brian Kelley - Databases, Infrastructure, and Security on 4 March 2009



Subscribe to this blog