Showing posts with label password. Show all posts
Showing posts with label password. Show all posts

Monday, March 19, 2012

DataBase security problems

Hello every one

We have made a application which cancreate and restoredata base for MS SQLwe also set the password. we want to make it secure. problem is thatif data base files are copy from one system to other system and try to open then . they are openedwith out asking data basePass word can any told me solution so that our data base become secure

Thank

Hello!

I developed database driven VC++ application. I faced a problem, which is "how to protect my database against direct access". E.g. .when i copy data files from one server to another and then using to attach the database to the new server the data base files are openedwith out asking password .

I use MS SQL Server 2000 enterprise Edition as a DBMS and appropriate database.

I want to make possible to manipulate with data in my database only through my client application.

1. How do I define SA password and instance name in silent mode of MS SQL 2000 EE installation with Mixed type of Authentication?

2. If my database be attached to my new instance. Is it possible to copy my database, attach it to another instance and get a direct access to its objects?

|||Hi,

actually you can′t secure it. The magic word in this case is prevention. Secure the directory that noone can connect to the server directory except the SQL Server Service user and administrator.

HTH, Jens Suessmeyer.

http://www.sqlserver2005.de
|||

This topic has been discussed already here: http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=52094&SiteID=1.

Thanks
Laurentiu

Sunday, February 19, 2012

database protection?

I know SQL Server has a good security system for the enterprise manager.
But are SQL server 2005 databases password protected?
In other words, suppose I make a database, named DATA1, with all its tables
and data on SQL Server 2005 I.
Can any one who download SQL Server Express 2005 open DATA1 on such a server
?
Are databases password protected like MS Access databases?
Thank you.newbie in hell (newbieinhell@.discussions.microsoft.com) writes:
> I know SQL Server has a good security system for the enterprise manager.
> But are SQL server 2005 databases password protected?
> In other words, suppose I make a database, named DATA1, with all its
> tables and data on SQL Server 2005 I.
> Can any one who download SQL Server Express 2005 open DATA1 on such a
> server?
> Are databases password protected like MS Access databases?
No. If you have been able to get hold of database file for SQL Server,
you can attach it to a server do whatever you like with it. What you can
do is to use encryption, and protect the encryption keys with the service
master key. In that case, it's difficult to get hold of everything, if
you attach it a different server.
I don't know Access, but from what I've heard passwords for Access databases
are not much of a protection either. It stops the stray wanderer, but
anyone who is decided to get in, will do so.
Erland Sommarskog, SQL Server MVP, esquel@.sommarskog.se
Books Online for SQL Server 2005 at
http://www.microsoft.com/technet/pr...oads/books.mspx
Books Online for SQL Server 2000 at
http://www.microsoft.com/sql/prodin...ions/books.mspx

Database protection

Is there a way to prevent users from logging into an MSDE database instance?
I created an MSDE instance using a strong SA password but I was still able
to logging to the database using Windows Authentication.
The reason I don't want the user to see the database is because the database
structure that I am distributing (MSDE) is exactly the same as the one I
have online. If I let the user peek into my MSDE database they might find a
way to mess-up the database that is online. I just don't want to take the
risk.
Also, is stored procedure encryption easily bypassed if I logon as a
database administrator?
Thanks.
If you don=B4t want Windows Authentication, disable it:
http://support.microsoft.com/default...;EN-US;q285097
INF: How to Change the Default Login Authentication Mode to SQL While
Installing SQL Server 2000 Desktop Engine by Using Windows Installer
<snip>
Another way to change the security mode after installation is to stop
SQL Server and set the appropriate registry key for your installation:
Default instance:
HKLM\Software\Microsoft\MSSqlserver\MSSqlServer\Lo ginMode
Named instance:
HKLM\Software\Microsoft\Microsoft SQL Server\Instance
Name\MSSQLServer\LoginMode
to 2 for mixed-mode or 1 for integrated. (Integrated is the default
setup for the SQL Server 2000 Data Engine.)
</snip>
-URL---
HTH, Jens Suessmeyer.
|||Hello,
I notice you have posted the same question in our SQLServer newsgroup,
which I have already responded. So please check my answer there and if you
need any further assistance on this particular issue, please reply to me in
that thread so I can follow up with you in time. Thanks.
Sophie Guo
Microsoft Online Partner Support
Get Secure! - www.microsoft.com/security
================================================== ===
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
================================================== ===
This posting is provided "AS IS" with no warranties, and confers no rights.
|||hi Jens,
Jens wrote:
> If you dont want Windows Authentication, disable it:
actually you cant disable Windows Authentication... you can disable standard
SQL Server authentication as you described, but not the contrary...
Andrea Montanari (Microsoft MVP - SQL Server)
http://www.asql.biz/DbaMgr.shtmhttp://italy.mvps.org
DbaMgr2k ver 0.15.0 - DbaMgr ver 0.60.0
(my vb6+sql-dmo little try to provide MS MSDE 1.0 and MSDE 2000 a visual
interface)
-- remove DMO to reply
|||You sure right, I misunderstood the op.
Thanks.
|||In message <3ot19pF794d7U1@.individual.net>, Andrea Montanari
<andrea.sqlDMO@.virgilio.it> writes
>hi Jens,
>Jens wrote:
>actually you cant disable Windows Authentication... you can disable standard
>SQL Server authentication as you described, but not the contrary...
Correct, however ... you can remove the "BUILTIN\..." Windows users
from the allowed Logins under Security tab to effectively disable the
Windows Users from logging into that instance.
Andrew D. Newbould E-Mail: newsgroups@.NOSPAMzadsoft.com
ZAD Software Systems Web : www.zadsoft.com
|||hi Andrew,
Andrew D. Newbould wrote:
> ...
> Correct, however ... you can remove the "BUILTIN\..." Windows users
> from the allowed Logins under Security tab to effectively disable the
> Windows Users from logging into that instance.
yes, of course, but this has a nasty side effect on MSDE instance, where the
Agent will no longer be able to start up, where you can not use Enterprise
Manager to set up the Win login(s) running the SQL Server and SQL Server
Agent..
until sp4, you could use the http://support.microsoft.com/kb/283811/en-us to
provide the appropriate permissions for that account, but sp4 chaged
something I'm still trying to figure out...
I'm still trying troubleshooting it..
I tryed "propagating" file permissions to all sub folders as described, as
long as assigning registry permissions as
HKLM\Software\Microsoft\MSSQLServer\Setup (READ)
HKLM\Software\Microsoft\MSSQLServer\MSSQLServer (FULL CONTROL)
for the account running SQL Server and
HKLM\Software\Microsoft\MSSQLServer\SQLSERVERAGENT (FULL CONTROL)
HKLM\SOFTWARE\Microsoft\MSSQLServer\Client\SuperSo cketNetLib\LastConnect
(FULL CONTROL)
HKLM\Software\Description\Microsoft\Rpc\UuidTempor aryData (FULL CONTROL)
HKLM\Software\Microsoft\MSSQLServer\Setup (READ)
HKLM\Software\ODBC\ODBC.INI (FULL CONTROL)
for the account running the Agent...
making those accounts member of the local sysadmins WinNT role
it seems to work, but I'm not completely confident about that...
feedback is welcome :D:D
but I definitevely hope kb article 283811 gets updated..
Andrea Montanari
http://www.asql.biz/DbaMgr.shtm
DbaMgr2k ver 0.15.0 - DbaMgr ver 0.60.0
(my vb6+sql-dmo little try to provide MS MSDE 1.0 and MSDE 2000 a visual
interface)
-- remove DMO to reply

Database protection

Is there a way to prevent users from logging into an MSDE database instance?
I created an MSDE instance using a strong SA password but I was still able
to logging to the database using Windows Authentication.
The reason I don't want the user to see the database is because the database
structure that I am distributing (MSDE) is exactly the same as the one I
have online. If I let the user peek into my MSDE database they might find a
way to mess-up the database that is online. I just don't want to take the
risk.
Also, is stored procedure encryption easily bypassed if I logon as a
database administrator?
Thanks.Rene
Create a new Login (DD) in SQL Server and and don't CRANT permission it to
the database. Now, when the user login with as DD he/she will not be able
access to the database
"Rene" <nospam@.nospam.com> wrote in message
news:uwzGIpbuFHA.2072@.TK2MSFTNGP14.phx.gbl...
> Is there a way to prevent users from logging into an MSDE database
> instance? I created an MSDE instance using a strong SA password but I was
> still able to logging to the database using Windows Authentication.
> The reason I don't want the user to see the database is because the
> database structure that I am distributing (MSDE) is exactly the same as
> the one I have online. If I let the user peek into my MSDE database they
> might find a way to mess-up the database that is online. I just don't want
> to take the risk.
> Also, is stored procedure encryption easily bypassed if I logon as a
> database administrator?
> Thanks.
>|||Thanks Uri
But if the user is logged on to Windows as an Administrator, doesn't this
user also has Admin right to the database by default? If this is the case,
even if I create a new database user it won't help because the person logged
into Windows as an administrator can automatically logging as "SA". Is this
the right?
"Uri Dimant" <urid@.iscar.co.il> wrote in message
news:eCCe1OcuFHA.3452@.TK2MSFTNGP14.phx.gbl...
> Rene
> Create a new Login (DD) in SQL Server and and don't CRANT permission it
> to the database. Now, when the user login with as DD he/she will not be
> able access to the database
>
>
> "Rene" <nospam@.nospam.com> wrote in message
> news:uwzGIpbuFHA.2072@.TK2MSFTNGP14.phx.gbl...
>|||Hello,
You can use sp_grantlogin to allow a Microsoft Windows NT user or group
account to connect to Microsoft SQL Server using Windows Authentication.
Use sp_denylogin to prevent a Microsoft Windows NT user or group from
connecting to Microsoft SQL Server. For example, you can run
sp_denylogin 'builtin\administrators'
to prevent from administrator to connect to SQL Server. However, make sure
you have the SA password and the authentication mode is mixed-mode before
you do so.
For more information, refer to the following articles:
http://msdn.microsoft.com/library/d...-us/tsqlref/ts_
sp_ga-gz_8dri.asp
http://msdn.microsoft.com/library/d...-us/tsqlref/ts_
sp_da-di_9jji.asp
I hope the information is helpful.
Sophie Guo
Microsoft Online Partner Support
Get Secure! - www.microsoft.com/security
========================================
=============
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
========================================
=============
This posting is provided "AS IS" with no warranties, and confers no rights.|||Well, don't permit them to connect as Administrators if you want to
implement the policy.
Remove them from 'Windows Administrators' and add to the newly created Group
only for access to the specific database
"Rene" <nospam@.nospam.com> wrote in message
news:uKoLoucuFHA.3720@.TK2MSFTNGP14.phx.gbl...
> Thanks Uri
> But if the user is logged on to Windows as an Administrator, doesn't this
> user also has Admin right to the database by default? If this is the case,
> even if I create a new database user it won't help because the person
> logged into Windows as an administrator can automatically logging as "SA".
> Is this the right?
>
> "Uri Dimant" <urid@.iscar.co.il> wrote in message
> news:eCCe1OcuFHA.3452@.TK2MSFTNGP14.phx.gbl...
>|||Hi
Have you looked at sp_revokedbaccess?
John
"Rene" <nospam@.nospam.com> wrote in message
news:uwzGIpbuFHA.2072@.TK2MSFTNGP14.phx.gbl...
> Is there a way to prevent users from logging into an MSDE database
> instance? I created an MSDE instance using a strong SA password but I was
> still able to logging to the database using Windows Authentication.
> The reason I don't want the user to see the database is because the
> database structure that I am distributing (MSDE) is exactly the same as
> the one I have online. If I let the user peek into my MSDE database they
> might find a way to mess-up the database that is online. I just don't want
> to take the risk.
> Also, is stored procedure encryption easily bypassed if I logon as a
> database administrator?
> Thanks.
>|||Hi
If they are administrators and you are worried that they can damage your
system, then access to your new database is not your only problem!
John
"Rene" <nospam@.nospam.com> wrote in message
news:uKoLoucuFHA.3720@.TK2MSFTNGP14.phx.gbl...
> Thanks Uri
> But if the user is logged on to Windows as an Administrator, doesn't this
> user also has Admin right to the database by default? If this is the case,
> even if I create a new database user it won't help because the person
> logged into Windows as an administrator can automatically logging as "SA".
> Is this the right?
>
> "Uri Dimant" <urid@.iscar.co.il> wrote in message
> news:eCCe1OcuFHA.3452@.TK2MSFTNGP14.phx.gbl...
>

Friday, February 17, 2012

Database password

Hi,
I use SQL server 2000.
I would like to know if there is any way to lock my database (set my own
password) so that someone who don't know the password won't be able to steal
the data. For example copy mdf/ldf or create a export of the database and
attach it to another sql server, or even browse the database contents from
Enterprise Manager or any other utility.
Thanks in advance and happy new year!
hi,
Penny wrote:
> Hi,
> I use SQL server 2000.
> I would like to know if there is any way to lock my database (set my
> own password) so that someone who don't know the password won't be
> able to steal the data. For example copy mdf/ldf or create a export
> of the database and attach it to another sql server, or even browse
> the database contents from Enterprise Manager or any other utility.
it is not possible to password protect single databases..
as you already probably know, the security architecture of SQL Server is not
implemented that way... you have a 2 phases authentication mechanism of
logging to SQL Server, where it is evaluated wheter or not the specified
login (both WinNT and SQL Server) can access the server instance, and then
whether or not a valid database user is available in your db for the
corresponding login.. if the database user "Guest" is available and no other
db user is mapped to the corresponding login, that "Guest" db user will be
used and applied, while no db access is permitted otherway...
but the method is instance centric and not database centric...

> Thanks in advance and happy new year!
you too..
Andrea Montanari (Microsoft MVP - SQL Server)
http://www.asql.biz/DbaMgr.shtmhttp://italy.mvps.org
DbaMgr2k ver 0.16.0 - DbaMgr ver 0.61.0
(my vb6+sql-dmo little try to provide MS MSDE 1.0 and MSDE 2000 a visual
interface)
-- remove DMO to reply