Showing posts with label document. Show all posts
Showing posts with label document. Show all posts

Wednesday, March 28, 2012

Microsoft Search service vulnerabilities

I am working on a "best practices" document for my company and came across
the suggestion to disable any unnecessary SQL Server services. We do not us
e
full-text search so we have no need for the service. However, I would like
to be able to provide reasons why this service should be disabled. I've
searched for vulnerabilites related to the Microsoft Search service and have
come up empty. Does anyone know of any vulnerabilities?
Thanks!I'm not aware of any vulnerabilities but it's still a good idea to shut it
down if you know you are not going to use it. That way, if someone comes up
with an attack later, you aren't at risk. Reducing the surface that an
attacker can attack to only what's required is always a good idea.
This posting is provided "AS IS" with no warranties, and confers no rights.
Use of included script samples are subject to the terms specified at
http://www.microsoft.com/info/cpyright.htm
"cltdba" <cltdba@.discussions.microsoft.com> wrote in message
news:14FA55C3-C274-458F-B7A8-ABB90EAD3E2C@.microsoft.com...
>I am working on a "best practices" document for my company and came across
> the suggestion to disable any unnecessary SQL Server services. We do not
> use
> full-text search so we have no need for the service. However, I would
> like
> to be able to provide reasons why this service should be disabled. I've
> searched for vulnerabilites related to the Microsoft Search service and
> have
> come up empty. Does anyone know of any vulnerabilities?
> Thanks!

Monday, March 19, 2012

Microsoft Cluster Server health check.

Hello,

Is there any Document for Microsoft Cluster Server health check for the existing SQL2000 EE on Win2003 EE.

If anyone knows about it OR anyone has the doc, Please let me know.

Thanks
mka

Doesn't look like you've gotten an answer on this in some time. Lot's of info here:

http://www.microsoft.com/sql/technologies/highavailability/default.mspx

|||

What do you mean by "Cluster Server health check"?

Microsoft Cluster Server health check.

Hello,

Is there any Document for Microsoft Cluster Server health check for the existing SQL2000 EE on Win2003 EE.

If anyone knows about it OR anyone has the doc, Please let me know.

Thanks
mka

Doesn't look like you've gotten an answer on this in some time. Lot's of info here:

http://www.microsoft.com/sql/technologies/highavailability/default.mspx

|||

What do you mean by "Cluster Server health check"?

Monday, March 12, 2012

MIcrosft SQLServer Best Practices document on securing SQLServer

I'm chasing after a documetn that was available on one of the Microsoft
websites that was titled somethign like "MS SQL Server Best Practices"
and detailed a nyumber of best practices about securing the server.

Included in this was revoking public access to the system table
objects.

Can someone post the URL where I can pick this up, or drop me a note on
contacting them for a copy of the document?"byrocat" <bdealhoy@.sympatico.ca> wrote in message
news:1122653744.611069.56230@.o13g2000cwo.googlegro ups.com...
> I'm chasing after a documetn that was available on one of the Microsoft
> websites that was titled somethign like "MS SQL Server Best Practices"
> and detailed a nyumber of best practices about securing the server.
> Included in this was revoking public access to the system table
> objects.
> Can someone post the URL where I can pick this up, or drop me a note on
> contacting them for a copy of the document?

You can find the Microsoft security docs, including a best practices white
paper, here:

http://www.microsoft.com/sql/techin...ty/default.mspx

I don't know of any good reason to revoke public permissions on system
tables - it might actually break something if users can't retrieve metadata
for some operations. Books Online states that a REVOKE applied to the public
role applies to all database users, which is probably not desirable in many
cases.

This issue often seems to be raised by IT auditors, probably because it has
somehow became part of an industry-standard audit checklist, but the MS best
practices document says only "do not grant additional permissions to this
role", implying that the existing permissions are fine:

http://www.microsoft.com/technet/pr...n/sp3sec02.mspx

Simon|||byrocat (bdealhoy@.sympatico.ca) writes:
> I'm chasing after a documetn that was available on one of the Microsoft
> websites that was titled somethign like "MS SQL Server Best Practices"
> and detailed a nyumber of best practices about securing the server.
> Included in this was revoking public access to the system table
> objects.

I would not do this. At least not without extensive testing first.

The fact that all metadata is open to anyone is not entirely
satisfyable, but the opposite is not good either.

In SQL 2005 things are different. Here you can only see metadata
for objects that you have access to. Unfortunately, this important
distinction is not possible to make in SQL 2000.

--
Erland Sommarskog, SQL Server MVP, esquel@.sommarskog.se

Books Online for SQL Server SP3 at
http://www.microsoft.com/sql/techin.../2000/books.asp

Wednesday, March 7, 2012

Metadata documentation

We're getting ready to launch Reporting Services and are looking for a way to
document the business logic and metadata behind the reports. Does reporting
Svc. offer a quick & easy way to do this?You have access to the RDL, which is stored in the database, along with the
other metadata... Perhaps you can write something to do what you wish...
What exactly do you want to do?
--
Wayne Snyder, MCDBA, SQL Server MVP
Mariner, Charlotte, NC
www.mariner-usa.com
(Please respond only to the newsgroups.)
I support the Professional Association of SQL Server (PASS) and it's
community of SQL Server professionals.
www.sqlpass.org
"BL" <BL@.discussions.microsoft.com> wrote in message
news:41C4F351-A803-4445-8F15-B855B74DD86F@.microsoft.com...
> We're getting ready to launch Reporting Services and are looking for a way
> to
> document the business logic and metadata behind the reports. Does
> reporting
> Svc. offer a quick & easy way to do this?
>|||We want to be able to document the business logic behind the report, and
store it with the report so that it's readily available.
What's the RDL stand for?|||RDL = Report Definition Language
See also: http://www.microsoft.com/sql/reporting/techinfo/rdlspec.mspx
-- Robert
This posting is provided "AS IS" with no warranties, and confers no rights.
"BL" <BL@.discussions.microsoft.com> wrote in message
news:B23DC42D-CAE1-4AE0-A391-40F27C121AC5@.microsoft.com...
> We want to be able to document the business logic behind the report, and
> store it with the report so that it's readily available.
> What's the RDL stand for?
>|||Hi,
I am also interested in metadata documentation and report specification.
Did you find any useful tools, or does anyone else know of any?
Richard
"BL" wrote:
> We want to be able to document the business logic behind the report, and
> store it with the report so that it's readily available.
> What's the RDL stand for?
>

Metadata Definition ?

Hello, i would like to know if it's possible to generate automatically a word document or an excel document that will contain all the metadata definition, for example containing the source columns names, their datatype, and the destination with their datatypes, so that it would easy to create a data dictionnary .

Thank you in advance.

Microsoft have talked about a tool called "SQL Dcoumenter" that will do this. No news about when it will be released though.

-Jamie

|||Thank you for your answer, i will do that manually.