Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

revelaing sa username and password 1

Status
Not open for further replies.

richey1

Technical User
Oct 5, 2004
184
GB
just a quick question.....................

what is the impact if ou sa username and password are revelaed ? how can someone hack in ?
even if the password is changed is there any checks that can be done that check nobody has added users or changed the master tables or something else whilst the password was revealed that would harm us even after changing the password ?

thanks
tony
 
Say after me....revealing the SA password is VERY BAD!

Remember the worm that went around the world quickly and targetted SQL Server machines. That was because it was revealed that SQL Server's SA account has a blank password and most people weren't changing it.

Bottom line: Anyone with the SA password has just become GOD on your SQL Server. You can't catch them doing anything (at least not easily)...why not - they are GOD on the system, they are allowed to do anything they want.

Why would you need to reveal the password? Just give the user the permissions they need to do the job.

-SQLBill
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top