Security

Technical Article

SQL Server 2005 Security - Part 2 Authorization

  • Article

Following the discussion of new or enhanced authentication-related functionality in SQL Server 2005 Beta 2 in our previous article, we are shifting our focus to authorization features, which determine the level of access rights once the user's logon process is successfully completed. Among topics that will be covered here, are separation of user and schema, modifiable context of module execution, increased permission granularity, and improved catalog security.

(1)

You rated this post out of 5. Change rating

2005-03-08

3,832 reads

Technical Article

The Case of the Stolen Laptop: Mitigating the Threats of Equipment The

  • Article

The fear of having laptops stolen is a huge worry for all organizations. Maybe it’s even happened to you (I hope not!). The solution is simple, really -- don’t let your laptop get stolen. (I can hear you laughing now.) Keep the thing with you at all times, or leave it in your hotel room when you don’t want to carry it around. Yes, everyone has heard the warnings about hotel room theft, but I’ve never had something stolen from a hotel room and I spend well over 200 nights a year in hotels. (If you travel to a location where the general population has kleptomaniac tendencies, stay in hotels that offer safes in the room.) You’re far more likely to leave your laptop or PDA or smart phone or USB drive lying on the seat in a taxi or on the counter at a bar.

You rated this post out of 5. Change rating

2005-02-28

1,325 reads

Technical Article

SQL Server 2005 Part 1 - Security (Authentication)

  • Article

In this installment of our series covering new and improved functionality of SQL Server 2005 Beta 2, we will focus on the topic of security, which has been becoming increasingly prominent among the issues on every database and system administrator's agenda. A new approach to software development started with the Trustworthy Computing initiative launched in early 2002, necessitated by the growing number of exploits directed at the Microsoft operating system and applications, resulted in a "secure by default" product with highly customizable security features further increasing the degree of protection. We will start with the features related to authentication (the process of identifying logins connecting to the SQL Server and users accessing databases), and continue with authorization (determining the level of permissions granted once the initial connection is established) and encryption in the future articles. In particular, we will cover here, password policy implementation and management as

(1)

You rated this post out of 5. Change rating

2005-02-01

5,709 reads

SQLServerCentral Article

Removing the Builtin Administrators - Some Pitfalls to Avoid

  • Article

The SQL Server 2000 security model is not the best one of all the RDBMS platforms and requires some work to secure properly. One of the practices that is recommended is removing the builtin/administrators group from accessing the SQL Server. New author Kathi Kellenberger shows us some of the pitfalls she encountered when removing this group from her servers.

(4)

You rated this post out of 5. Change rating

2007-08-10 (first published: )

30,153 reads

Technical Article

Manipulating Microsoft SQL Server Using SQL Injection

  • Article

Focuses on advanced techniques that can be used in an attack on an application utilizing Microsoft SQL Server as a backend. These techniques demonstrate how an attacker could use a SQL Injection vulnerability to retrieve the database content from behind a firewall and penetrate the internal network. Also provided are recommendations on how to prevent such attacks.

You rated this post out of 5. Change rating

2005-01-05

2,626 reads

Blogs

Creating a Local Model Chatbot on Windows

By

After my session at VSLive last week, I had a few questions from the...

To refer and to be referred

By

Referrals have never been more important in the job market. They’re no longer nice...

A New Word: Dorgone

By

dorgone– adj. wondering if you could slip away from an event or group conversation...

Read the latest Blogs

Forums

Querying Multiple Tables for the Same Information

By RedSoxRay

I have about 100 Tables that are all suffixed with _Modify. These tables record...

Make It Routine

By Steve Jones - SSC Editor

Comments posted to this topic are about the item Make It Routine

Finding Gaps in Sequential Data Using SQL Server

By Imran2629

Comments posted to this topic are about the item Finding Gaps in Sequential Data...

Visit the forum

Question of the Day

Negative and Positive Numbers

If I want to know whether a number of negative, positive, or zero, what is the easiest way to get this in T-SQL?

See possible answers