• opc.three (4/8/2013)


    If nuclear blasts were the only reason to leave xp_cmdshell disabled then you would have a great point. Unfortunately, that is simply too narrow a view.

    The circle continues so you've compelled me to say it again. If someone has SA privs, they can get to the command line whether xp_CmdShell is enabled or not. If someone doesn't have SA privs, they can't get to the command line whether xp_CmdShell is enabled or not. I believe it's a narrow view to think otherwise.

    You're turn. 😉

    --Jeff Moden


    RBAR is pronounced "ree-bar" and is a "Modenism" for Row-By-Agonizing-Row.
    First step towards the paradigm shift of writing Set Based code:
    ________Stop thinking about what you want to do to a ROW... think, instead, of what you want to do to a COLUMN.

    Change is inevitable... Change for the better is not.


    Helpful Links:
    How to post code problems
    How to Post Performance Problems
    Create a Tally Function (fnTally)