RSS



Go Back   bit-tech.net Forums > bit-tech.net > Article Discussion

Reply
 
Thread Tools
Old 24th Dec 2008, 12:22   #1
CardJoe
Player Character
bit-tech Staff
 
CardJoe's Avatar
 
Join Date: Apr 2007
Posts: 7,940
CardJoe is a splendid one to beholdCardJoe is a splendid one to beholdCardJoe is a splendid one to beholdCardJoe is a splendid one to beholdCardJoe is a splendid one to beholdCardJoe is a splendid one to beholdCardJoe is a splendid one to beholdCardJoe is a splendid one to behold
SQL Server on security alert

http://www.bit-tech.net/news/2008/12...curity-alert/1

Microsoft has issued a bulletin announcing an as-yet unpatched hole in its SQL Server database software which can lead to remote code execution.

__________________
CardJoe is offline   Reply With Quote
Old 24th Dec 2008, 14:33   #2
sfrigard
What's a Dremel?
 
Join Date: Dec 2008
Posts: 1
sfrigard is on a distinguished road
I am a DBA and find the comments at the end on this article nothing short of flame baiting. According to Secunia, SQL Server 2005 has had only three advisories. The current advisory requires a user to successfully logon to SQL Server in order to exploit. You mention that there is an unofficial workaround requiring the dropping of the extended procedure. You fail to mention that installing Service Pack 3 for SQL Server also resolves this issue. Please, do your research next time.
sfrigard is offline   Reply With Quote
Old 24th Dec 2008, 17:22   #3
n3mo
Multimodder
 
Join Date: Oct 2007
Posts: 184
n3mo is on a distinguished road
This way or another working with SQL Server was the worst time of my life, a real pain in the ass. Only worse thing I can think of is Oracle.
n3mo is offline   Reply With Quote
Old 24th Dec 2008, 23:05   #4
Firehed
Why not? I own a domain to match.
 
Firehed's Avatar
 
Join Date: Feb 2004
Location: An hour north of Boston
Posts: 12,576
Firehed has a spectacular aura aboutFirehed has a spectacular aura aboutFirehed has a spectacular aura about
I hate working with SQL server, but more often than not any SQL security issues are much more related to interacting with the DB at the app level than the server itself (not sanitizing user-provided data, etc).
__________________
hire me @ eric-stern.com - web developer and php ninja
pics @ my smugmug :: Twitter @firehed :: blog @ firehed.net
40D|580EXII|285HV|AB800|70-200f/4LIS|17-50f/2.8|150f/2.8Macro|50f/1.8
MacPro @ 8x2.8GHz, 10GB FBDDR2, 3TB HD :: MBP @ 2x2.2GHz, 4GB DDR2, 320GB HD
Firehed is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 19:32.
Powered by: vBulletin Version 3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.