Showing posts with label library. Show all posts
Showing posts with label library. Show all posts

Monday, March 19, 2012

Database security on a Local Network

This is regarding general protection of a database hosted on a network. I am developing a database application for my college library using VB.NET, that will reside on a network.
For some reasons, I did not want to hardcode the Database location in the application. Instead, when a user logs in, he can choose the database location using a folder browser control, if the location has changed.

Now, I realize that for this, I have to put the database in a shared folder, which makes it quite vulnerable. Having pondered over the problem for sometime, a solution that comes to my mind is to place a Text file in the same shared folder that always contains the correct path of the database. When a user chooses that folder, I will read the actual path of the database from the text file, and move the database to a non-shared folder.
I haven't yet implemented this approach, but felt it better to consult someone before. So, would this approach work, and is it a good idea.
For information purposes, I consider it important to mention that the database is in MS Access. I know this is not a place for discussing it, but this is a general security concern. So, I thought
people would not mind answering it....


Hi,

how aout securing the MDB file using the appropiate NTFS permissions and eventually additional Access password security or using an ldb file ? I don′t know if there can be concurrent users on the database, but coyping the database file to a shared folder will allow other users also to copy the file to another folder and working on it, for you having the trouble to bring the data together afterwards.

HTH, Jens K. Suessmeyer.


http://www.sqlserver2005.de

|||More than the problem of bringing it together afterwards, I am worried about someone manipulating it mischievously. That's why I thought of putting the database in a non-shared folder on the server and a text file in a shared folder, which will always

contain the correct path of the DB on the server.

So, when a user logs in, he will select the path of the text file. As he

will do so with a folder chooser, he will not know that the folder contains a

text file & not the actual DB. Internally, I will read the database path from

that file in my application, & use that path to construct the connection

string...

I think this approach will shield the database from direct access on the network, using an explorer etc.

I already have Access password security, but still I dont want the database to be directly accessible on the network.
Can you elaborate a bit more on securing the Database on the server with NTFS permissions, in a way that my application can still access & manipulate it?|||

One thing, you cannot perform such move/copy with a SQL Server database as that will be in exclusive use of SQLengine.

Refer to KBA http://support.microsoft.com/kb/295234, http://support.microsoft.com/kb/307901 and link http://vb123.com/toolshed/links/map/opr.htm for more information.

|||There are two things I will mention again here...
1) My database is in Access
2) And, I am not moving the Database at run-time. The database will remain in its non-shared folder. And there will be a text file, that will act as a sort of pointer to the database location for my application, as I will read the DB path from the text file.|||

I suggest posting this question on a Microsoft Access or Microsoft Visual Basic forum instead of this one. This forum is used for posting questions related to Microsoft SQL Server security features, as you observed, and your question is Access specific.

Thanks
Laurentiu

|||

Hi,

You can do this well with NTFS permission with Read right for everyone in Group so that everyone can read the database files (this will not make user to able to copy files/folder too) , and give write/modify permission to specific users who need to insert/update/delete records in your access database. Refer www.windowsecurity.com/articles/Understanding-Windows-NTFS-Permissions.html to understand NTFS permission properly and with Advance you may restrict Take Ownership/traversing etc.

HTH

Hemantgiri S. Goswami

Friday, February 17, 2012

database performance

Hi All

In Oracle i can get Performance varables like Library Cache Hits, Dictionary Cache Hits, Database Buffers Read ,Redolog Buffers Read etc from the system dynamic tables.

I want to know how to get the same / related performance details in sql server 2000 and 2005. ( which are the parameters , Optimal value and which table/dynamic view to query).

Thanks in Advance

You can use dynamic management views, new to 2005.

http://msdn2.microsoft.com/en-us/library/ms188754.aspx|||

Hi,

In SQL 2000 (and 2005), you can query master.dbo.sysperfinfo to find most of what your looking for.

Additionally, sp_monitor and some DBCC commands have additional information, see http://www.sql-server-performance.com/dbcc_commands.asp and http://www.sqldev.net/articles/dbcc_sqlperf.htm for more details.

Hope that helps.

Jamie

|||

In addition to the other references already provided, you might find the examples and information in this white paper useful: http://www.microsoft.com/technet/prodtechnol/sql/2005/tsprfprb.mspx

Regards,

Gail

|||

Hi .... Thanks for your reply........

I need a query/queries to find the following in MS sql server.

1) To find most frequently accessed/executed tables/procedures

Please help me

Thanks in advance

|||

You might find that exploring the dynamic system views to be useful.

For example:

SELECT * FROM sys.dm_os_performance_counters

And there are quite a few additional dynamic system views to choose from. In Object Explorer, click on your database, VIEWS, and then System Views.

Often, the quality of the responses received is related to our ability to ‘bounce’ ideas off of each other. In the future, to make it easier for us to offer you assistance, and to prevent folks from wasting time on already answered questions, please don't post to multiple newsgroups. Choose the one that best fits your question and post there. Only post to another newsgroup if you get no answer in a day or two (or if you accidentally posted to the wrong newsgroup –and you indicate that you've already posted elsewhere).

|||

Check the response in your duplicate post in the Transact-SQL forum.

Often, the quality of the responses received is related to our ability to ‘bounce’ ideas off of each other. In the future, to make it easier for us to offer you assistance, and to prevent folks from wasting time on already answered questions, please:

Don't post to multiple newsgroups. Choose the one that best fits your question and post there. Only post to another newsgroup if you get no answer in a day or two (or if you accidentally posted to the wrong newsgroup –and you indicate that you've already posted elsewhere).

|||

Hi Arnie...

I made the post in the other forum by mistake ......

thanks for the reminder

|||

can u send me the reply link for ur question

I need a query/queries to find the following in MS sql server.

1) To find most frequently accessed/executed tables/procedures

database performance

Hi All

In Oracle i can get Performance varables like Library Cache Hits, Dictionary Cache Hits, Database Buffers Read ,Redolog Buffers Read etc from the system dynamic tables.

I want to know how to get the same / related performance details in sql server 2000 and 2005. ( which are the parameters , Optimal value and which table/dynamic view to query).

Thanks in Advance

You can use dynamic management views, new to 2005.

http://msdn2.microsoft.com/en-us/library/ms188754.aspx|||

Hi,

In SQL 2000 (and 2005), you can query master.dbo.sysperfinfo to find most of what your looking for.

Additionally, sp_monitor and some DBCC commands have additional information, see http://www.sql-server-performance.com/dbcc_commands.asp and http://www.sqldev.net/articles/dbcc_sqlperf.htm for more details.

Hope that helps.

Jamie

|||

In addition to the other references already provided, you might find the examples and information in this white paper useful: http://www.microsoft.com/technet/prodtechnol/sql/2005/tsprfprb.mspx

Regards,

Gail

|||

Hi .... Thanks for your reply........

I need a query/queries to find the following in MS sql server.

1) To find most frequently accessed/executed tables/procedures

Please help me

Thanks in advance

|||

You might find that exploring the dynamic system views to be useful.

For example:

SELECT * FROM sys.dm_os_performance_counters

And there are quite a few additional dynamic system views to choose from. In Object Explorer, click on your database, VIEWS, and then System Views.

Often, the quality of the responses received is related to our ability to ‘bounce’ ideas off of each other. In the future, to make it easier for us to offer you assistance, and to prevent folks from wasting time on already answered questions, please don't post to multiple newsgroups. Choose the one that best fits your question and post there. Only post to another newsgroup if you get no answer in a day or two (or if you accidentally posted to the wrong newsgroup –and you indicate that you've already posted elsewhere).

|||

Check the response in your duplicate post in the Transact-SQL forum.

Often, the quality of the responses received is related to our ability to ‘bounce’ ideas off of each other. In the future, to make it easier for us to offer you assistance, and to prevent folks from wasting time on already answered questions, please:

Don't post to multiple newsgroups. Choose the one that best fits your question and post there. Only post to another newsgroup if you get no answer in a day or two (or if you accidentally posted to the wrong newsgroup –and you indicate that you've already posted elsewhere).

|||

Hi Arnie...

I made the post in the other forum by mistake ......

thanks for the reminder

|||

can u send me the reply link for ur question

I need a query/queries to find the following in MS sql server.

1) To find most frequently accessed/executed tables/procedures