Related Links

Related Stories

  • Microsoft IIS security flaws cause a stir
    A steady stream of security flaws in the Microsoft Internet Information Services (IIS) software is causing a stir in security researcher circles, with hackers reportedly issuing details of the flaws faster than Microsoft's R&D staff can patch them.
  • Businesses face deluge of patches from Microsoft and Oracle
    IT security administrators will have to deal with more than 10 security patches from Oracle and nine from Microsoft this week.
  • Prepare for end of Office 2000 security updates
    Users of Office 2000 should start preparing for Microsoft’s withdrawal of its security update service for Office 2000 from 14 July this year, warns California-based security software provider Fortify Software.
  • Keeping sensitive information secure when staff is leaving
    Career loyalty is an endangered creature. Unlike our predecessors, today’s workforce is unlikely to stay committed to a job for five years, let alone their entire lives. But with such a fluid stream of employees keeping human resources busy, and countless eyes being cast over company data, Rob Stringer investigates how sensitive information can stay faithful to its organisation, even if its staff don’t...
  • Batten down the hatches
    Due to the horrifying quantity of vulnerabilities, and often limited time and budget, application and database security can be quite a headache. Limiting privileges and access, however, is a good place to start, finds Danny Bradbury

News

Public row developing between Sentrigo and Microsoft

10 September 2009

A row is developing between Sentrigo, a database security specialist, and Microsoft, over the security of Microsoft's SQL Server software.

The spat started developing last week when Sentrigo announced it had discovered a significant vulnerability in Microsoft SQL Server, that potentially allows any user with administrative privileges to openly see the unencrypted passwords of other users - or the credentials presented by applications accessing the server using SQL Server authentication.

At the time, Sentrigo said that, in order to ensure all SQL Server users are able to quickly protect their systems, it had released a free utility to erase these passwords, which can be downloaded starting today from the company's website.

Since Microsoft SQL Server saves its login passwords to memory in plain text, Sentrigo said they can be read by administrators.

The problem is made worse, according to Sentrigo, because IT users often use the same password for different computer systems.

Microsoft has confirmed the SQL Server security flaw, but has said in forum postings that an attacker must have administrator access to the system in order to be able to read from memory.

And if they have admin level privileges, Microsoft argued, the hacker has full system access. For this reason, the software giant said that the security issue is not a flaw.

Heise Online, the German IT newswire, noted that if an administrator's password has been stolen or cracked - perhaps via an SQL injection attack - then non-administrators may also be able to get hold of these passwords.

"In Sentrigo's opinion, for an administrator, be he good or bad, to be able to view passwords is anyway a contravention of standard security best practice", the newswire said.

"(Sentrigo) also notes that companies frequently have in place a role and privileges concept which forbids or prevents administrators from doing this. Most applications store passwords as hashes both on the hard drive and in memory."

 

 

This article is featured in:
Application Security Compliance and Policy Internet and Network Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.