欢迎来到天天文库
浏览记录
ID:240374
大小:705.12 KB
页数:23页
时间:2017-07-12
《SQL Server在Web应用中的安全 毕业论文外文翻译》由会员上传分享,免费在线阅读,更多相关内容在学术论文-天天文库。
1、SecuringSQLServerforWebApplicationsByAndrewNovickIntroductionIfyourSQLServerisexposedtotheInternet,hackersareprobingit.Probablyrightnow.ThisarticleshowshowtosecureaSQLServerdatabasethat'sbeingusedwithaWebapplication.Bydefinitiontheseserversareexposed.Notsuret
2、hatthereisaproblem?We'llstartwiththetwoelementsthatcreatetheproblem:vulnerabilitiesinWindows,IIS,andSQLServerandtheattacksthatattempttoexploitthem.AsMicrosofthasincreaseditsfocusonsecurity,thenumberofhotfixesforSQLServerhasbeenontherise.However,themostexploit
3、edvulnerabilityisstillthegoodoldblankpasswordfortheSAaccount.ThereAreVulnerabilitiesinSQLServerLikeallsoftwareSQLServerhassecurityvulnerabilities.DocumentationforthevulnerabilitiesthatMicrosoftiswillingtotalkaboutislocatedat:www.microsoft.com/technet/security
4、/current.asp?productid=30&servicepackid=0.You'llfindhalfadozenormoreSQLServerspecificsecuritybulletinsandinformationaboutpatchingthem.Itseemsanewvulnerabilityisfoundalmosteveryweek.StartbymakingsureyourSQLServerhasallthelatestandgreatesthotfixes.Lateronwe'llt
5、alkaboutthetoolsthatgoouttothenettocheckforupdates.Themostwidespreadattackisn'tcoveredbyasecuritybulletin.It'sastraightforwardloginattemptmadeontheSAaccountwithablankpassword.Sincesomeadministratorsneverbothertochangethedefaultpassword,thereareamplevictimstob
6、einfected.Microsoftdoesn'tevenconsiderthisvulnerabilityandwon'tbeissuingapatch.Afterall,theblankpasswordis"bydesign".SeeMicrosoftKnowledgeBasearticleQ313418athttp://support.microsoft.com/default.aspx?scid=kb;EN-US;q313418Acommoncauseoftheblankpasswordisproduc
7、ts.ForexamplesomeversionsVisioinstallMSDEandneverchangetheSApassword.TheusermaynotevenknowthattheyhaveMSDErunning.TocheckyournetworkyoucandownloadaprogramthatscansforSQLServerswithSAaccountsthathaveblankpasswordsonyournetwork.It'sfromeEye,asecuritycompanythat
8、spendsalotoftimelookingforwholesinMicrosoftproducts.Downloaditat:http://www.eeye.com/html/Research/Tools/sqlworm.html.Figure1showsthetoolafterithasscannedonlyoneaddress,127.0.0.1,thelocal
此文档下载收益归作者所有