Click here to monitor SSC
SQLServerCentral is supported by Redgate
 
Log in  ::  Register  ::  Not logged in
 
 
 

Databases – Infrastructure – Security

Brian Kelley is an author, columnist, and Microsoft SQL Server MVP focusing primarily on SQL Server security. He is a contributing author for How to Cheat at Securing SQL Server 2005 (Syngress), Professional SQL Server 2008 Administration (Wrox), and Introduction to SQL Server (Texas Publishing). Brian currently serves as an infrastructure and security architect. He has also served as a senior Microsoft SQL Server DBA, database architect, developer, and incident response team lead.

Grateful to have been a Microsoft MVP

A couple of weeks ago I received the disappointing but expected news that I wasn’t renewed as a Microsoft Data Platform MVP. I say expected because I knew my ability to give back to the community had been greatly diminished over the later part of 2015 and into 2016. Between… Read more

0 comments, 171 reads

Posted in Databases – Infrastructure – Security on 2 January 2017

Reminder – Geek Sync Today!

Today (December 14, 2016) at 12 PM Eastern I’m giving a webinar on preparing for your SQL Server farm for the holidays.

Registration: Geek Sync – Surviving the Holidays with SQL Server

Here’s what I will be covering:

It’s the end of the year and you want to have a… Read more

0 comments, 115 reads

Posted in Databases – Infrastructure – Security on 14 December 2016

Geek Sync Tomorrow: Surviving the Holidays with SQL Server

Tomorrow (December 14, 2016) at 12 PM Eastern I’m giving a webinar on preparing for your SQL Server farm for the holidays.

Registration: Geek Sync – Surviving the Holidays with SQL Server

Here’s what I will be covering:

It’s the end of the year and you want to have a… Read more

0 comments, 95 reads

Posted in Databases – Infrastructure – Security on 13 December 2016

Happy Thanksgiving

It’s Thanksgiving again here in the United States. Throughout the years, the IT community has been awesome. I have been blessed by you all. I can certainly point to milestones in my career and list the folks who have helped me get to each one. 

But outside of work and… Read more

0 comments, 158 reads

Posted in Databases – Infrastructure – Security on 24 November 2016

Webinar Available On Demand – Building an Auditing Framework for SQL Server

Recently I gave an introductory webinar on how to build an auditing framework for SQL Server. The focus was for those tasked with auditing SQL Server on a regular basis and needing some ideas of how to get started. I talk through some of the challenges as well as what… Read more

0 comments, 218 reads

Posted in Databases – Infrastructure – Security on 19 October 2016

Webcast Tomorrow: Building an Auditing Framework for SQL Server

Faced with auditing SQL Server on a regular basis with no 3rd party tools? Where do you start? That’s what this webcast is on. Come watch on October 13, 3 PM Eastern time. 

Webcast: Building an Auditing Framework for SQL Server
There will be some code samples, but this is… Read more

0 comments, 181 reads

Posted in Databases – Infrastructure – Security on 12 October 2016

Reminder: Webinar today

This is a reminder that I’ll be giving a webinar today on managing SQL Server Agents jobs in a SQL Server Farm. Here are the details:

Webinar: Managing SQL Server Agent Jobs Across Your SQL Server Farm

On Thursday, September 8, at 3 PM EDT, I’ll be doing a webinar… Read more

0 comments, 143 reads

Posted in Databases – Infrastructure – Security on 8 September 2016

Reminder: #SQLChat at lunch today

This is a reminder that we’ll having a #SQLChat this afternoon at 12 PM EDT. Here are the details:

SQLChat: Do You Manage Multiple Servers?

On Wednesday, September 7, at 12 PM EDT (11AM CDT), we’ll be doing a #SQLChat covering managing multiple SQL Servers and how people handle dealing… Read more

0 comments, 220 reads

Posted in Databases – Infrastructure – Security on 7 September 2016

SQLChat on Wednesday, Webinar on Thursday!

I’m participating in two community activities this week. One is a #SQLCchat on Twitter and the other is a webinar through MSSQLTips.

SQLChat: Do You Manage Multiple Servers?

On Wednesday, September 7, at 12 PM EDT (11AM CDT), we’ll be doing a #SQLChat covering managing multiple SQL Servers and how… Read more

0 comments, 153 reads

Posted in Databases – Infrastructure – Security on 6 September 2016

I wrote a SQL Server auditing whitepaper!

I recently collaborated with Idera to produce a short whitepaper on the top 5 things to audit in SQL Server (database engine). You can grab it for free here (registration required):

Whitepaper: Top 5 Items to Audit in SQL Server

None of this is earth shattering. The whitepaper contains the… Read more

0 comments, 316 reads

Posted in Databases – Infrastructure – Security on 27 July 2016

Not More Than 16 Characters?!?

Microsoft, you’re killing me. This is the warning I received when typing in a password for Office 365:

I blinked when I saw the warning, “Your password can’t be longer than 16 characters.” I couldn’t believe that I had gotten that warning, so I erased what I had typed for… Read more

7 comments, 2,533 reads

Posted in Databases – Infrastructure – Security on 10 June 2016

Protecting Against Delete without Where

If I’m doing any manual work with T-SQL, I always begin every set of data change operations with BEGIN TRAN and I have the COMMIT TRAN commented out at the end of my script. Why?

Quite simply, because I’m wary of having a DELETE clause without a proper WHERE clause.… Read more

7 comments, 3,375 reads

Posted in Databases – Infrastructure – Security on 9 June 2016

A Different Type of Currency

Recently, a member of the community lamented that folks weren’t willing to provide an email address for free training. This reminds me of an old saying popularized by Heinlein, but one that was used a lot in the Perl community: TANSTAAFL (There Ain’t No Such Thing As A Free Lunch).… Read more

1 comments, 243 reads

Posted in Databases – Infrastructure – Security on 9 June 2016

Slides from 2016 Techno Security & Mobile Forensics Conference

I’ve completed both of my presentations at the 2016 Techno Security and Forensics Investigation Conference (#technosecurity). If you were able to make it to one of my talks, thank you for choosing to spend your time with me. While my slides will be available from the conference site,… Read more

0 comments, 268 reads

Posted in Databases – Infrastructure – Security on 7 June 2016

Sights that just scream, “No!”

I’m at a conference, specifically a security conference. So I looked at the available WiFi connections. Among the conference and hotel specific connections and the MiFi and cellphone uplinks I spotted this one:

That just screams, “No!” TANSTAAFL.


Read more

0 comments, 255 reads

Posted in Databases – Infrastructure – Security on 7 June 2016

Congrats to MSSQLTips on 10 Years!

MSSQLTips has posted about their 10 years as a resource to the SQL Server community. It’s where I do the bulk of my writing these days, mainly because I like the problem/solution format. However, the folks at MSSQLTips didn’t just write to acknowledge their 10th birthday. 

They also posted… Read more

0 comments, 262 reads

Posted in Databases – Infrastructure – Security on 6 June 2016

On Software and OS Lifecycle Management

An Important Rule: 

If you’re trying to convince someone to your viewpoint, insulting them generally doesn’t work. If it does anything, it will be more likely to entrench them against your position. Therefore, this is something that IT professionals should avoid. 

If You Write Your Own Software

or work… Read more

0 comments, 4,879 reads

Posted in Databases – Infrastructure – Security on 17 April 2015

On Software and OS Lifecycle Management

An Important Rule: 

If you’re trying to convince someone to your viewpoint, insulting them generally doesn’t work. If it does anything, it will be more likely to entrench them against your position. Therefore, this is something that IT professionals should avoid. 

If You Write Your Own Software

or work… Read more

0 comments, 141 reads

Posted in Databases – Infrastructure – Security on 17 April 2015

On PowerShell

I use PowerShell a lot and I write about using it to solve problems quite frequently. The fact that I can extending Powershell by interfacing with the .NET Framework or making a COM/COM+ object call means I can do just about anything I need to do in order to… Read more

0 comments, 216 reads

Posted in Databases – Infrastructure – Security on 10 April 2015

On PowerShell

I use PowerShell a lot and I write about using it to solve problems quite frequently. The fact that I can extending Powershell by interfacing with the .NET Framework or making a COM/COM+ object call means I can do just about anything I need to do in order to… Read more

0 comments, 461 reads

Posted in Databases – Infrastructure – Security on 10 April 2015

Older posts