Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, March 30, 2012

Norton Internet Security & SQL Server

Hi,

Just installed Norton Internet Security on an XP workstation that also has
SQL Server on it.

I now find that I cannot access SQL Server and multiple messages are being
issued by NIS.

When I switch off the Firewall & Intrusion Detection I can access SQL
Server.

Does anyone know how to configure NIS so that I can use it alongside SQL
Server?

Thanks,

Mike.Uytkownik "Mike Stogden" <news@.uniquest.demon.co.uk> napisa w wiadomoci
news:bhaolh$i5i$1$8300dec7@.news.demon.co.uk...
> Hi,
> Just installed Norton Internet Security on an XP workstation that also has
> SQL Server on it.
> I now find that I cannot access SQL Server and multiple messages are being
> issued by NIS.
> When I switch off the Firewall & Intrusion Detection I can access SQL
> Server.
> Does anyone know how to configure NIS so that I can use it alongside SQL
> Server?
Hi, try this:

permit UDP OUT and IN protocol for

SQL Server Service Manager (sqlmangr.exe)
SQL Server Windows NT (sqlserver.exe)

And TCP OUT and IN protocol for

SQL Tracing Tool (profiler.exe)
ISQL (isqlw.exe)

from any adress:any port and this should work, and then try fit your rules
to be more security

best regards
Marcin D

Norton anti virus on Sql server

As part of the Security Initiative, Our security team wants to put
Anti-Virus protection on All Sql server database.
Is it good a practice to Install Anti Virus software on Sql servers?
Has anybody installed it on their production system? Any issues with it?
I appreciate your answer.
James,
[vbcol=seagreen]
I certainly would.No compromise, even when the server is not connected to
internet.
[vbcol=seagreen]
Exclude the SQLServer files - mdf,ndf and ldf etc from being scanned.Also,
whenever you are doing any setup from a recognised media, make sure to stop
the AV service and turn it back on when you are done.
'INF: Consideration for a Virus Scanner on a Computer That Is Running SQL
Server'
http://support.microsoft.com/default.aspx?id=309422
Dinesh
SQL Server MVP
--
SQL Server FAQ at
http://www.tkdinesh.com
"james" <kush@.brandes.com> wrote in message
news:uF$IIA8MEHA.3636@.TK2MSFTNGP09.phx.gbl...
> As part of the Security Initiative, Our security team wants to put
> Anti-Virus protection on All Sql server database.
> Is it good a practice to Install Anti Virus software on Sql servers?
> Has anybody installed it on their production system? Any issues with it?
> I appreciate your answer.
>

Norton anti virus on Sql server

As part of the Security Initiative, Our security team wants to put
Anti-Virus protection on All Sql server database.
Is it good a practice to Install Anti Virus software on Sql servers?
Has anybody installed it on their production system? Any issues with it?
I appreciate your answer.James,

I certainly would.No compromise, even when the server is not connected to
internet.
[vbcol=seagreen]
Exclude the SQLServer files - mdf,ndf and ldf etc from being scanned.Also,
whenever you are doing any setup from a recognised media, make sure to stop
the AV service and turn it back on when you are done.
'INF: Consideration for a Virus Scanner on a Computer That Is Running SQL
Server'
http://support.microsoft.com/default.aspx?id=309422
Dinesh
SQL Server MVP
--
--
SQL Server FAQ at
http://www.tkdinesh.com
"james" <kush@.brandes.com> wrote in message
news:uF$IIA8MEHA.3636@.TK2MSFTNGP09.phx.gbl...[vbcol=seagreen]
> As part of the Security Initiative, Our security team wants to put
> Anti-Virus protection on All Sql server database.
> Is it good a practice to Install Anti Virus software on Sql servers?
> Has anybody installed it on their production system? Any issues with it?
> I appreciate your answer.
>

Norton anti virus on Sql server

As part of the Security Initiative, Our security team wants to put
Anti-Virus protection on All Sql server database.
Is it good a practice to Install Anti Virus software on Sql servers?
Has anybody installed it on their production system? Any issues with it?
I appreciate your answer.James,
>> Is it good a practice to Install Anti Virus software on Sql servers?
I certainly would.No compromise, even when the server is not connected to
internet.
>>Any issues with it?
Exclude the SQLServer files - mdf,ndf and ldf etc from being scanned.Also,
whenever you are doing any setup from a recognised media, make sure to stop
the AV service and turn it back on when you are done.
'INF: Consideration for a Virus Scanner on a Computer That Is Running SQL
Server'
http://support.microsoft.com/default.aspx?id=309422
--
Dinesh
SQL Server MVP
--
--
SQL Server FAQ at
http://www.tkdinesh.com
"james" <kush@.brandes.com> wrote in message
news:uF$IIA8MEHA.3636@.TK2MSFTNGP09.phx.gbl...
> As part of the Security Initiative, Our security team wants to put
> Anti-Virus protection on All Sql server database.
> Is it good a practice to Install Anti Virus software on Sql servers?
> Has anybody installed it on their production system? Any issues with it?
> I appreciate your answer.
>

Friday, March 23, 2012

Non-Sysadmins Running xp_cmdshell

I know about the security risks of running xp_cmdshell by
non-sysadmins and I am already taking those issues into
account. I have a question about a problem I am having
letting users run this extended stored procedure.
I have created an Active Directory group and added it to
our SQL Server as a login and made it a user on the master
database. The only thing this user has authority to do is
execute xp_cmdshell. I made one of our users a member of
this AD group and had him execute a stored procedure that
executes the xp_cmdshell procedure. (We are sure he has
execute permissions on the stored procedure that executes
xp_cmdshell.)
When he runs the stored procedure he gets an error that
access is denied.
Next I removed him from the AD group and added a login for
him, with Windows authentication, and added him as a user
to the master database, then I granted execute permissions
on xp_cmdshell. When he runs the stored procedure now, it
executes the xp_cmdshell procedure properly.
Is there some rule about how permissions can be granted to
xp_cmdshell? The only difference between my two scenarios
is in one case he is executing with a connection directly
based on his personal AD account and in the other case,
the permissions are set via an AD group.
Thanks for any help.Hi Jason,
Thank you for using MSDN Newsgroup! It's my pleasure to assist you with
your issue.
From you description, in your system, you have a login account in a group.
In the SQL Server, you set it to Windows authentication and you grant the
execute permission of 'xp_cmdshell' to the user, but it failed with an
error message 'access is denied', while when you grant the execute
permission of the 'xp_cmdshell' to the group the user is belong in, no
message with it. You wonder if there is any rules for these, right? If I
misunderstood you, pleae feel free to let me know.
Well, I create a user 'test1' and 'test2' on my system belongs to 'testing
group', in my SQL Server Enterprise Manager, I grant the permission of
execute 'xp_cmdshell' to 'test1' and 'testing group'. Then I login with
account 'test1' and 'test2', both could execute " xp_cmdshell 'dir c:' ".
So, you could grant the permissions to either user or group. Well, as we
always emphasize, it strongly recommend that it should be run by limited,
system administrator account for security concern.
Could you tell me which statement you are running in the xp_cmdshell? When
this user login in you system(not sql server), could he run the same
statements in command prompt? I am looking forward to your information.
Thanks!
Best regards
Baisong Wei
Microsoft Online Support
----
Get Secure! - www.microsoft.com/security
This posting is provided "as is" with no warranties and confers no rights.
Please reply to newsgroups only. Thanks.|||Two things. One, your understanding is backwards. When I
granted rights to individuals it worked. When I granted
rights to the group it did not work.
More importantly, however, IT STARTED WORKING TODAY! The
setup is still exactly as it was when I started having
this problem. I did make some changes about removing
permissions and re-adding permissions trying to make it
work but it ultimately went back to how it was in the
beginning.
Anyway, thanks for the responses.
quote:

>--Original Message--
>Hi Jason,
>Thank you for using MSDN Newsgroup! It's my pleasure to

assist you with
quote:

>your issue.
>From you description, in your system, you have a login

account in a group.
quote:

>In the SQL Server, you set it to Windows authentication

and you grant the
quote:

>execute permission of 'xp_cmdshell' to the user, but it

failed with an
quote:

>error message 'access is denied', while when you grant

the execute
quote:

>permission of the 'xp_cmdshell' to the group the user is

belong in, no
quote:

>message with it. You wonder if there is any rules for

these, right? If I
quote:

>misunderstood you, pleae feel free to let me know.
>Well, I create a user 'test1' and 'test2' on my system

belongs to 'testing
quote:

>group', in my SQL Server Enterprise Manager, I grant the

permission of
quote:

>execute 'xp_cmdshell' to 'test1' and 'testing group'.

Then I login with
quote:

>account 'test1' and 'test2', both could execute "

xp_cmdshell 'dir c:' ".
quote:

>So, you could grant the permissions to either user or

group. Well, as we
quote:

>always emphasize, it strongly recommend that it should be

run by limited,
quote:

>system administrator account for security concern.
>Could you tell me which statement you are running in the

xp_cmdshell? When
quote:

>this user login in you system(not sql server), could he

run the same
quote:

>statements in command prompt? I am looking forward to

your information.
quote:

>Thanks!
>Best regards
>Baisong Wei
>Microsoft Online Support
>----
>Get Secure! - www.microsoft.com/security
>This posting is provided "as is" with no warranties and

confers no rights.
quote:

>Please reply to newsgroups only. Thanks.
>.
>
|||Hi Jason,
Thank you for using MSDN Newsgroup! It's my pleasure to assist you with
your issue.
Sorry for the misunderstanding for the first time. It is good to here that
you have solved the problem. Here I just want to add some information about
the logins and users in the SQL Server 2000. Windows accounts (users or
groups) must be granted permissions to connect to an instance of Microsoft
SQL Server? before they can access a database. You could grant the
permissions to connect the SQL Server by expand a server group, and then
expand a server, then expand Security, right-click Logins, and then click
New Login. In the Name box, enter the Windows account (in the form
DOMAIN\User) to be granted access to SQL Server. Under Authentication,
click Windows Authentication. Then, in a database, you add them as database
user or add in a database roles. Then you could grant, deny and revoke the
permissions to operations such as select, insert, update, execute a stored
procedure on the database objects to the database users or apply this on a
specified role.
Again, glad to hear that you solved your problem and if you have any
questions about SQL server, please feel free to post message here and I am
ready to help!
Best regards
Baisong Wei
Microsoft Online Support
----
Get Secure! - www.microsoft.com/security
This posting is provided "as is" with no warranties and confers no rights.
Please reply to newsgroups only. Thanks.

Non-Sysadmins Running xp_cmdshell

I know about the security risks of running xp_cmdshell by
non-sysadmins and I am already taking those issues into
account. I have a question about a problem I am having
letting users run this extended stored procedure.
I have created an Active Directory group and added it to
our SQL Server as a login and made it a user on the master
database. The only thing this user has authority to do is
execute xp_cmdshell. I made one of our users a member of
this AD group and had him execute a stored procedure that
executes the xp_cmdshell procedure. (We are sure he has
execute permissions on the stored procedure that executes
xp_cmdshell.)
When he runs the stored procedure he gets an error that
access is denied.
Next I removed him from the AD group and added a login for
him, with Windows authentication, and added him as a user
to the master database, then I granted execute permissions
on xp_cmdshell. When he runs the stored procedure now, it
executes the xp_cmdshell procedure properly.
Is there some rule about how permissions can be granted to
xp_cmdshell? The only difference between my two scenarios
is in one case he is executing with a connection directly
based on his personal AD account and in the other case,
the permissions are set via an AD group.
Thanks for any help.In EM RClick SQL Server Agent/ props/ job system/ uncheck
only users with Sysadmin bla bla. Put in a valid Adimn
Login and Password. You never want to grant direct access
to xp_cmdshell. Users can do lots more than your intended
proc if you do this.
>--Original Message--
>I know about the security risks of running xp_cmdshell by
>non-sysadmins and I am already taking those issues into
>account. I have a question about a problem I am having
>letting users run this extended stored procedure.
>I have created an Active Directory group and added it to
>our SQL Server as a login and made it a user on the
master
>database. The only thing this user has authority to do
is
>execute xp_cmdshell. I made one of our users a member of
>this AD group and had him execute a stored procedure that
>executes the xp_cmdshell procedure. (We are sure he has
>execute permissions on the stored procedure that executes
>xp_cmdshell.)
>When he runs the stored procedure he gets an error that
>access is denied.
>Next I removed him from the AD group and added a login
for
>him, with Windows authentication, and added him as a user
>to the master database, then I granted execute
permissions
>on xp_cmdshell. When he runs the stored procedure now,
it
>executes the xp_cmdshell procedure properly.
>Is there some rule about how permissions can be granted
to
>xp_cmdshell? The only difference between my two
scenarios
>is in one case he is executing with a connection directly
>based on his personal AD account and in the other case,
>the permissions are set via an AD group.
>Thanks for any help.
>.
>|||Hi Jason,
Thank you for using MSDN Newsgroup! It's my pleasure to assist you with
your issue.
From you description, in your system, you have a login account in a group.
In the SQL Server, you set it to Windows authentication and you grant the
execute permission of 'xp_cmdshell' to the user, but it failed with an
error message 'access is denied', while when you grant the execute
permission of the 'xp_cmdshell' to the group the user is belong in, no
message with it. You wonder if there is any rules for these, right? If I
misunderstood you, pleae feel free to let me know.
Well, I create a user 'test1' and 'test2' on my system belongs to 'testing
group', in my SQL Server Enterprise Manager, I grant the permission of
execute 'xp_cmdshell' to 'test1' and 'testing group'. Then I login with
account 'test1' and 'test2', both could execute " xp_cmdshell 'dir c:\' ".
So, you could grant the permissions to either user or group. Well, as we
always emphasize, it strongly recommend that it should be run by limited,
system administrator account for security concern.
Could you tell me which statement you are running in the xp_cmdshell? When
this user login in you system(not sql server), could he run the same
statements in command prompt? I am looking forward to your information.
Thanks!
Best regards
Baisong Wei
Microsoft Online Support
----
Get Secure! - www.microsoft.com/security
This posting is provided "as is" with no warranties and confers no rights.
Please reply to newsgroups only. Thanks.|||Two things. One, your understanding is backwards. When I
granted rights to individuals it worked. When I granted
rights to the group it did not work.
More importantly, however, IT STARTED WORKING TODAY! The
setup is still exactly as it was when I started having
this problem. I did make some changes about removing
permissions and re-adding permissions trying to make it
work but it ultimately went back to how it was in the
beginning.
Anyway, thanks for the responses.
>--Original Message--
>Hi Jason,
>Thank you for using MSDN Newsgroup! It's my pleasure to
assist you with
>your issue.
>From you description, in your system, you have a login
account in a group.
>In the SQL Server, you set it to Windows authentication
and you grant the
>execute permission of 'xp_cmdshell' to the user, but it
failed with an
>error message 'access is denied', while when you grant
the execute
>permission of the 'xp_cmdshell' to the group the user is
belong in, no
>message with it. You wonder if there is any rules for
these, right? If I
>misunderstood you, pleae feel free to let me know.
>Well, I create a user 'test1' and 'test2' on my system
belongs to 'testing
>group', in my SQL Server Enterprise Manager, I grant the
permission of
>execute 'xp_cmdshell' to 'test1' and 'testing group'.
Then I login with
>account 'test1' and 'test2', both could execute "
xp_cmdshell 'dir c:\' ".
>So, you could grant the permissions to either user or
group. Well, as we
>always emphasize, it strongly recommend that it should be
run by limited,
>system administrator account for security concern.
>Could you tell me which statement you are running in the
xp_cmdshell? When
>this user login in you system(not sql server), could he
run the same
>statements in command prompt? I am looking forward to
your information.
>Thanks!
>Best regards
>Baisong Wei
>Microsoft Online Support
>----
>Get Secure! - www.microsoft.com/security
>This posting is provided "as is" with no warranties and
confers no rights.
>Please reply to newsgroups only. Thanks.
>.
>|||Hi Jason,
Thank you for using MSDN Newsgroup! It's my pleasure to assist you with
your issue.
Sorry for the misunderstanding for the first time. It is good to here that
you have solved the problem. Here I just want to add some information about
the logins and users in the SQL Server 2000. Windows accounts (users or
groups) must be granted permissions to connect to an instance of Microsoft
SQL Server? before they can access a database. You could grant the
permissions to connect the SQL Server by expand a server group, and then
expand a server, then expand Security, right-click Logins, and then click
New Login. In the Name box, enter the Windows account (in the form
DOMAIN\User) to be granted access to SQL Server. Under Authentication,
click Windows Authentication. Then, in a database, you add them as database
user or add in a database roles. Then you could grant, deny and revoke the
permissions to operations such as select, insert, update, execute a stored
procedure on the database objects to the database users or apply this on a
specified role.
Again, glad to hear that you solved your problem and if you have any
questions about SQL server, please feel free to post message here and I am
ready to help!
Best regards
Baisong Wei
Microsoft Online Support
----
Get Secure! - www.microsoft.com/security
This posting is provided "as is" with no warranties and confers no rights.
Please reply to newsgroups only. Thanks.