SQLServerCentral is supported by Red Gate Software Ltd.
 
Log in  ::  Register  ::  Not logged in
 
 
 

K. Brian Kelley - Databases, Infrastructure, and Security

Add to Technorati Favorites Add to Google
Author Bio
Brian is a SQL Server author, columnist, and Microsoft MVP focusing primarily on SQL Server security. He is a contributing author for How to Cheat at Securing SQL Server 2005 (Syngress) and Professional SQL Server 2008 Administration (Wrox). Brian currently serves as a database administrator / architect for AgFirst Farm Credit Bank where he can concentrate on his passion: SQL Server. He previously was a systems and security architect for AgFirst Farm Credit Bank where he worked on Active Directory, Windows security, VMware, and Citrix. In the technical community, Brian is president of the Midlands PASS Chapter, an official chapter of PASS. Brian is also a junior high youth minister at Spears Creek Baptist Church in Elgin, SC.
August 2008 - Posts

August Charlotte SQL Server User Group Meeting Announcement

Rating: (not yet rated) Rate this |  Discuss | 4,648 Reads | 33 Reads in Last 30 Days |no comments

The Charlotte SQL Server User Group meeting will be held online on August 20th at 12 Noon (EDT). They'll have as the speaker SQL Server MVP Brad McGehee. From the front page:

Don't miss our August 20th online meeting with renowned SQL Server MVP, Brad McGehee. Brad is an experienced DBA and noted founder of SQL-Server-Performance.com. His topic will be "Introducing the SQL Server 2008 Performance Data Collector."

If you are interested in attending, please confirm your attendance with Peter Shire, president of the Charlotte SQL Server User Group.

 


[OFF-TOPIC] "Geek" Comics I Follow

By K. Brian Kelley in K. Brian Kelley - Databases, Infrastructure, and Security 08-14-2008 4:08 PM | Categories: Filed under:
Rating: (not yet rated) Rate this |  Discuss | 2,981 Reads | 39 Reads in Last 30 Days |no comments

Like a lot of folks my age (in their 30s), I grew up on comics, both comic strips in the newspaper and comic book magazines. Here are the "geek" comics I follow nowadays on-line:

I used to follow the Heroes Happen Here {Comic Series}, but that one is done. If you're reading this and follow a different one that is a good stress reliever for you, post it in the comics. I'm looking for others. As far as non-geek, I also get Snoopy, Dilbert, and B.C.

 


Microsoft Events in August for Columbia, SC

Rating: (not yet rated) Rate this |  Discuss | 2,357 Reads | 32 Reads in Last 30 Days |no comments

The following events are for August 21, 2008, in downtown Columbia, SC.

 



Check Authentication Scheme (Kerberos) on SQL Server 2005

Rating: (not yet rated) Rate this |  Discuss | 5,548 Reads | 90 Reads in Last 30 Days |no comments

I had to redo SPNs today because we swapped out service accounts on some of our non-production SQL Servers. I wanted to verify that connections in bound were being made with Kerberos. If you've ever dealt with this, if the SPNs are wrong you usually get an SSPI error, but just to be safe, I wanted positive confirmation that the connection was Kerberos. Here's the quick and dirty query to show the connections and the mode by which they are connecting:

SELECT
       s.session_id
    ,  c.connect_time
    ,  s.login_time
    ,  c.protocol_type
    ,  c.auth_scheme
    ,  s.host_name
    ,  s.program_name
FROM sys.dm_exec_sessions s
  JOIN sys.dm_exec_connections c
    ON s.session_id = c.session_id

If you have a lot of connections you'll probably want to filter by host_name or by the login, but I didn't have a need to for what I was doing.


Free SQL Sticker from Paul Nielsen

By K. Brian Kelley in K. Brian Kelley - Databases, Infrastructure, and Security 08-04-2008 10:49 PM | Categories: Filed under:
Rating: (not yet rated) Rate this |  Discuss | 2,425 Reads | 34 Reads in Last 30 Days |no comments

A little while ago Paul Nielsen tweeted about having free Euro-style SQL stickers. All one had to do was email him with your snail mail address and he'd send him your way. He's still offering to send out free stickers. If you are interested, you can see what one looks like at his web site:

SQL Server Bible

He announced in the latest SQL Server Bible eNewsletter (you can sign up for it at his web site) that you can get your very own sticker by emailing him at pauln {at} sqlserverbible {dot} com. He sent me two stickers which came in last week. One went on the back of my wife's van. Put it on right before church this past Sunday. There's probably two in our church that would get it, but still. Speaking of which, this is what he's written on his home page about the sticker:

cool, vinyl sticker, suitable for a notebook lid. want one? 

The other one did fit perfectly on the cover of my Dell XPS laptop, which I happened to get in white. So now instead of a Dell logo, you see SQL. Looks great! Get your sticker before he runs out!

EDIT: As a follow-up, Paul has written a blog post about it. He asks that you put "Euro SQL Sticker" as the subject of the email.

 


Great Read on the Difficulty of Computer Security

By K. Brian Kelley in K. Brian Kelley - Databases, Infrastructure, and Security 08-04-2008 12:05 PM | Categories: Filed under:
Rating: (not yet rated) Rate this |  Discuss | 1,881 Reads | 32 Reads in Last 30 Days |no comments

The SANS Internet Storm Center has a great handler post about working at the Abuse department for an ISP:

Securing a Network - Lessons Learned

The handler, Deborah Hale goes into detail about some of the issues faced. Things like end users not having up-to-date antivirus, mail servers getting blacklisted and then it be a tedious process to get them unblocked, to the insecurity of small business customers without full-time IT staff and the risks they pose. Loved the point about reviewing logs (point #1). Often in security your logs are your best friend.

 

 


You Hired Good People, Right?

By K. Brian Kelley in K. Brian Kelley - Databases, Infrastructure, and Security 08-02-2008 12:33 PM | Categories: Filed under:
Rating: (not yet rated) Rate this |  Discuss | 2,275 Reads | 37 Reads in Last 30 Days |no comments

In the current issue of Redmond magazine there's an interesting story in the Never Again column. It's titled:

Listen to the People You Hire

The situation is one that's familiar to a lot of IT folks, there's a problem, they've got a reasonable solution, but management feels that an outside opinion needs to be brought in to bring light to the situation. The third party comes in, offers the same opinion that the in-place  IT folks have been stating all along, and then proceeds to offer their own services to fix the problem. They then come in, the solution delivered isn't right, and the existing IT staff is left to pick up the pieces. Meanwhile, the consultants have exited with a sizable chunk of money... more than if the IT personnel had been allowed to solve the solution in the first place.

I'm not against consultants or consulting. When needed expertise is lacking within an organization, such as when a company is gearing up on a new technology, bringing in knowledgable consultants to help implement the solution and provide training and education makes a lot of sense. Another case is when there's a particularly challenging problem that for a regular IT staff that simply requires a domain expert, a good consultant can mean success. And finally there are cases where consultants can be brought in to augment staff, if the situation permits it and would actually benefit from such a move (see Brook's Law), to provide additional workers to complete a project.

The article naturally heaps the blame on the consulting solution and in the situation described with the facts presented, I would have to agree. However, the concluding shot was this:

The bottom line is that if you don't trust your network administrators and heed what they're telling you, you need to hire new ones. 

Based on how the article read out, this doesn't make a whole lot of sense. The problem wasn't that the network folks were untrustworthy. They were. The problem was that management didn't trust them. Hiring new network administrators wouldn't have solved the issue. Management had to learn to trust the people it had employed. Given that, I would amend the final line to read something like this:

The bottom line is that you should trust your network administrators and heed what they're telling you unless they've given you reason not to. If they have, you need to hire new ones. 

If you've hired good people, trust them and invest in them. This gives them a reason to care about the organization and about the job they do. Often they can save the organization money and pain if they are worth their salt. If they aren't trustworthy, they're going to cost everyone in the long run, so you need to replace them. And by the way, trustworthy people are going to know when they need help. And they won't be disagreeable to bringing folks in. After all, they care about the organization they work for and understand that they are valued and respected.

 


Nmap 4.68 Available

Rating: (not yet rated) Rate this |  Discuss | 3,329 Reads | 39 Reads in Last 30 Days |no comments

The network scanner Nmap has a new version out, 4.68. The GUI interface (Zenmap) which comes with the Windows installer version is pretty sharp. A lot of changes in this version.

 I just did a test run and it correctly identified OS and services on the boxes I just hit against. Used Zenmap and while it is a simple and straight-forward interface, it works.