SqlServerKudos - Stories tagged with Security
1
kudos
spam Kudos Remove

I am a forum spammer! Delete my account immediately!!

published 928 days, 18 hours, 47 minutes ago posted by sasa 938 days, 8 hours, 25 minutes ago
Thursday, November 05, 2009 5:36:44 PM GMT Tuesday, October 27, 2009 3:58:00 AM GMT
The subject may look confusing that 1 part of it confirms its a forum spammer and another part to delete that account!!! Here is the email text that I have received highlighting valueable advice on security: *********** This email address was created solely to register automatically at thousands of forums for the purposes of spamming forums like yours. Remove my account and any other account registered with my email address, and strongly consider strengthening your forum's password requirements....(read ... (more)
category: News | clicked: 1 | comment | | source: sqlserver-qa.net
tags: email, forum, foundation, password, Security, spam, team
1
kudos
spam Kudos Remove

Alert - Critical Product Vulnerability - October 2009 Microsoft Security Bulletin Release

published 937 days, 20 hours, 25 minutes ago posted by sasa 947 days, 9 hours, 6 minutes ago
Tuesday, October 27, 2009 3:57:57 PM GMT Sunday, October 18, 2009 3:17:46 AM GMT
This alert is to provide you with an overview of the new security bulletin(s) being released on October 13, 2009. Security bulletins are released monthly to resolve critical problem vulnerabilities. New Security Bulletins Microsoft is releasing the following 13 new security bulletins for newly discovered vulnerabilities: Bulletin ID Bulletin Title Maximum Severity Vulnerability Impact Restart Requirement Affected Software* MS09-050 Vulnerabilities in SMBv2 Could Allow Remote Code Execution (975517)...(re... (more)
category: News | clicked: 0 | comment | | source: sqlserver-qa.net
tags: alert, Best Practices, bulletin, microsoft, operating system, search, Security, vulnerability, windows
1
kudos
spam Kudos Remove

Fifth pillar - Secure

published 951 days, 21 hours, 21 minutes ago posted by sasa 957 days, 15 hours, 41 minutes ago
Tuesday, October 13, 2009 3:01:48 PM GMT Wednesday, October 07, 2009 8:42:28 PM GMT
As I have mentioned in all of the previous posts, basic functionality is the foundation of any system. So it goes without saying that if you have just implemented a payroll system, everyone is getting paid.  To meet the basic bar that EVERYONE agrees upon, to be useful things have to work. Frankly, this is generally the only criteria which needs to be met for most systems to be considered complete, and since I don’t want get off on a rant, that is all that I will say (for now at least, it will be in the ... (more)
category: Security | clicked: 0 | comment | | source: sqlblog.com
tags: Database Design, Pillars, Security
1
kudos
spam Kudos Remove

Microsoft Security Bulletin major revisions - August 2009

published 965 days, 22 hours, 21 minutes ago posted by sasa 969 days, 1 hour, 51 minutes ago
Tuesday, September 29, 2009 2:02:28 PM GMT Saturday, September 26, 2009 10:32:41 AM GMT
******************************************************************** Title: Microsoft Security Bulletin Major Revisions Issued: August 25, 2009 ******************************************************************** Summary ======= The following bulletins have undergone a major revision increment. Please see the appropriate bulletin for more details. * MS09-044 - Critical * MS09-029 - Critical Bulletin Information: ===================== * MS09-044 - Critical - http://www.microsoft.com/technet/security/bulle... (more)
category: News | clicked: 2 | comment | | source: sqlserver-qa.net
tags: bulletin, critical, microsoft, Security
1
kudos
spam Kudos Remove

MSG 10314 An error occurred in the Microsoft .NET Framework while trying to load assembly id 65536. The server may be running out of resources, or the assembly may not be trusted with PERMISSION_SET = EXTERNAL_ACCESS or UNSAFE.

published 966 days, 22 hours, 26 minutes ago posted by sasa 969 days, 10 hours, 11 minutes ago
Monday, September 28, 2009 1:57:32 PM GMT Saturday, September 26, 2009 2:12:43 AM GMT
As it states on the subject line this is an error that would cause when the system is trying to load assembly due to the permissions, the second part of the subject also needs consideration that server may be running out of resources & security issue. Msg 10314, Level 16, State 11, Line 2 An error occurred in the Microsoft .NET Framework while trying to load assembly id 65536. The server may be running out of resources, or the assembly may not be trusted with PERMISSION_SET = EXTERNAL_ACCESS...(read more) (more)
category: News | clicked: 0 | comment | | source: sqlserver-qa.net
tags: .NET, access, Assemblies, BOL, CLR, error, Login, login mapping, privileges, Security, sid, SQL Server, versioncontrol
1
kudos
spam Kudos Remove

Are You Really Protected from Injection?

published 995 days, 12 hours, 4 minutes ago posted by sasa 1000 days, 17 hours, 2 minutes ago
Monday, August 31, 2009 12:19:40 AM GMT Tuesday, August 25, 2009 7:21:37 PM GMT
In my last post, Top 10 T-SQL Code Smells, I caught some flack got some feedback for including one (#3) about the use of Stored Procedures for Select statements. Several people expressed objections over the risk of SQL Injection, and how Stored Procs would prevent it, but some of the correspondence I've gotten made me worry that, perhaps, some of those folks might have a false sense of security around this issue. Disclaimer: the whole Stored Procs or not Stored Procs debate has already happened; I am no... (more)
category: Security | clicked: 1 | comment | | source: sqlblog.com
tags: injection, Security, Stored Procedures
1
kudos
spam Kudos Remove

How to secure a new SQL Server Reporting Services farm

published 999 days, 22 hours, 55 minutes ago posted by sasa 1005 days, 14 hours, 29 minutes ago
Wednesday, August 26, 2009 1:28:42 PM GMT Thursday, August 20, 2009 9:54:17 PM GMT
Last month, I talked about the licensing model for the "Scale Out" Reporting Services model. It is expensive. Well, this month I am building a proof-of-concept for a customer. Luckily, we can use the Developer edition until we go into production. I feel much more comfortable dealing with technical issues versus licensing issues. Let's take a look... (more)
category: Security | clicked: 1 | comment | | source: www.networkworld.com
tags: Scale Out, Security, SSRS, Web Farm
1
kudos
spam Kudos Remove

How to specify a Windows Authentication user in T-SQL

published 1000 days, 23 hours, 4 minutes ago posted by sasa 1006 days, 17 hours, 15 minutes ago
Tuesday, August 25, 2009 1:19:45 PM GMT Wednesday, August 19, 2009 7:07:55 PM GMT
This may only be a SQL Server 2005 problem. Comments either way please. Only one of these works: grant execute on storedproc to [domain1\ismom] grant execute on storedproc to 'domain1\ismom' grant execute on stored_proc to '[domain1\ismom]' (more)
category: Management | clicked: 1 | comment | | source: weblogs.sqlteam.com
tags: Authentication, Security
1
kudos
spam Kudos Remove

Tools to enhance SQL Server security, analyze that!

published 1006 days, 22 hours, 56 minutes ago posted by sasa 1011 days, 21 hours, 15 minutes ago
Wednesday, August 19, 2009 1:27:36 PM GMT Friday, August 14, 2009 3:07:55 PM GMT
There are various methods you could apply to secure SQL Server platform, that includes the areas of physical hardware and networking systems connecting clients to the database servers, and the binary files that are used to process database requests! It is not that easy to implement the strict measures of security when the databases are spread out in an enterprise-wide network. There are tons of information about best practices for physical security stric... (more)
category: Management | clicked: 3 | comment | | source: sqlserver-qa.net
tags: audit, feature, lock down, Security, sql injection, Tools, verison, vulnerability
1
kudos
spam Kudos Remove

SQL Logins For Windows Domain Accounts Limited To Pre-Windows 2000 Format

published 1026 days, 12 minutes ago posted by sasa 1028 days, 22 hours, 31 minutes ago
Friday, July 31, 2009 12:11:33 PM GMT Tuesday, July 28, 2009 1:51:51 PM GMT
You may have noticed that when you create a login on a SQL server that's mapped to a Windows domain account you have to use the pre-Windows 2000 format [domain\login]. Did you also notice that there's a limitation of 20 characters on the login portion of this format? Let's pretend that you use nice descriptive names for application accounts, for example:Sales.ReportUtil.ProdServiceSales.ReportUtil.ProdWebuser When you try to add these logins the 20 character limit cuts them both off at "Sales.ReportUt... (more)
category: Security | clicked: 1 | comment | | source: kendalvandyke.blogspot.com
tags: Login, Security
2
kudos
spam Kudos Remove

Looking for security vulnerabilities in database code

published 1029 days, 18 minutes ago posted by sasa 1031 days, 5 hours, 46 minutes ago
Tuesday, July 28, 2009 12:05:09 PM GMT Sunday, July 26, 2009 6:37:29 AM GMT
I've always been concerned with security and I've always stressed the importance of auditing the REAL user context not just the current user (see this post on EXECUTE AS and auditing). So, I generally try to avoid using dynamic string execution and if necessary create well tested/protected parameters (fyi - using QUOTENAME can be a fantasic solution to protectng identifiers as input paramet... (more)
category: Security | clicked: 1 | comment | | source: www.sqlskills.com
tags: Security, SQL Server 2005, SQL Server 2008
1
kudos
spam Kudos Remove

View Permissions for Reporting Services in SharePoint Integrated Mode

published 1030 days, 10 minutes ago posted by sasa 1031 days, 5 hours, 50 minutes ago
Monday, July 27, 2009 12:13:38 PM GMT Sunday, July 26, 2009 6:32:55 AM GMT
Setting up security for SSRS in SharePoint integrated mode can be a bit tricky, particularly if you want to set up some of your users to only be able to run reports, but not to be able to modify or change them. If you give the users the standard Contribute permission level in SharePoint, they have the ability to view and execute reports, but they can also delete existing reports or add new ones. If you assign only the Read permission level to the users, they won't even be able to see the reports in the d... (more)
category: Security | clicked: 5 | comment | | source: agilebi.com
tags: Security, SharePoint, SSRS
3
kudos
spam Kudos Remove

For shared SQL Server providers : hiding your list of databases from customers

published 1029 days, 18 minutes ago posted by sasa 1031 days, 6 hours, 50 minutes ago
Tuesday, July 28, 2009 12:05:09 PM GMT Sunday, July 26, 2009 5:33:37 AM GMT
In a shared SQL Server hosting environment, there are several problems that can arise when you let your customers use Management Studio to connect and administer their databases.  In the typical case, you give them a single SQL Authentication username and password, and they are supposed to be able to connect only to their database.  By default, however, Object Explorer and Object Explorer Details will gladly present the entire list of databases on the server.  In this case, not only are you exposing all ... (more)
category: Security | clicked: 8 | comment | | source: sqlblog.com
tags: Database List, Management Studio, Security, Shared Hosting, SSMS
Previous 1 2 3 Next