On Thu, 24 Feb 2005 16:54:37 -0500, Dave Watts <[EMAIL PROTECTED]> wrote:
> > Of course you can trust MS-SQL -- it's a great database. I'd
> > ask what kind of idiot leaves port 1433 open on a MS-SQL
> > server in the first place (due to the number of infections
> > with the various worms, apparently a lot)?
> 
> This doesn't really have anything to do with the thread, but to answer your
> question quite a few people do this, and those people aren't necessarily
> idiots. Remember that lots of products install some variant of SQL Server,
> like MSDE, for you, so there are quite a few people running SQL Server
> without necessarily knowing it, or thinking about having to secure it.

And remember that if you're implementing basic security measures --
specifically installing a firewall -- that you shouldn't automatically
leave port 1433 (or any other non-needed port) open to the world.

That precaution of course won't prevent problems from someone *inside*
the firewall infecting you, but again, that should be handled by basic
security measures.

As an aside, there are *plenty* of ways to scan for open SQL Sever
ports on your network to find those MSDE installs,  so I'll maintain
that anyone with an unsecured SQL Server of any type is, in fact, and
idiot.
 
> Dave Watts, CTO, Fig Leaf Software
> http://www.figleaf.com/
> 
> Fig Leaf Software provides the highest caliber vendor-authorized
> instruction at our training centers in Washington DC, Atlanta,
> Chicago, Baltimore, Northern Virginia, or on-site at your location.
> Visit http://training.figleaf.com/ for more information!
> 
> 
> 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
Logware (www.logware.us): a new and convenient web-based time tracking 
application. Start tracking and documenting hours spent on a project or with a 
client with Logware today. Try it for free with a 15 day trial account.
http://www.houseoffusion.com/banners/view.cfm?bannerid=67

Message: http://www.houseoffusion.com/lists.cfm/link=i:4:196923
Archives: http://www.houseoffusion.com/cf_lists/threads.cfm/4
Subscription: http://www.houseoffusion.com/lists.cfm/link=s:4
Unsubscribe: http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=89.70.4
Donations & Support: http://www.houseoffusion.com/tiny.cfm/54

Reply via email to