Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - SQL server sa account
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

SQL server sa account

 Post Reply Post Reply
Author
theSCIENTIST View Drop Down
Senior Member
Senior Member


Joined: 31 July 2003
Location: United Kingdom
Status: Offline
Points: 440
Post Options Post Options   Thanks (0) Thanks(0)   Quote theSCIENTIST Quote  Post ReplyReply Direct Link To This Post Topic: SQL server sa account
    Posted: 04 October 2004 at 8:12pm
Hi all, I've been looking around for information on the sa account in SQL server, and found no answer to my questions.

My SQL server 2000 is set in mixed mode, because it has to make use of SQL accounts, and I find in my server logs, especially in the firewall logs, that the sa account is being constantly tested with some kind of brute force password cracker, last log was 45MB (not to mention SQL server logs) just on (sa account login failed) I was wondering whether I can either delete and create another SrvAdmin account or if I can just rename the default sa account, so when this people try to crack the password next time, there won't be an sa account to crack.

Other tips and tricks on securing SQL server are appreciated.
Back to Top
michael View Drop Down
Senior Member
Senior Member
Avatar

Joined: 08 April 2002
Location: United States
Status: Offline
Points: 4670
Post Options Post Options   Thanks (0) Thanks(0)   Quote michael Quote  Post ReplyReply Direct Link To This Post Posted: 04 October 2004 at 9:39pm
Up to sql server 2000 there is no way to disable or rename the sa account or the sysadmin role. In 2005 aka yukon you will be able to do either. I recommend to just give the sa account a unbelievable long password with special charachters etc. Then just use custom accounts.
Back to Top
theSCIENTIST View Drop Down
Senior Member
Senior Member


Joined: 31 July 2003
Location: United Kingdom
Status: Offline
Points: 440
Post Options Post Options   Thanks (0) Thanks(0)   Quote theSCIENTIST Quote  Post ReplyReply Direct Link To This Post Posted: 05 October 2004 at 10:06am
Thx michael, will do that, I gather the maximum lenght the password can have are 20 chars, can you or anyone else confirm that?

Humm, I might have forgoten the sa account password :(, if this is true, how can I reset it?

Thx.
Back to Top
Mart View Drop Down
Senior Member
Senior Member
Avatar

Joined: 30 November 2002
Status: Offline
Points: 2304
Post Options Post Options   Thanks (0) Thanks(0)   Quote Mart Quote  Post ReplyReply Direct Link To This Post Posted: 05 October 2004 at 11:20am
Not sure about length of passwords but to reset sa password try logging in with a differant account and try this:

UPDATE
master.dbo.syslogins
SET
password = pwdencrypt('newpassword')
WHERE
name = 'sa'
Back to Top
michael View Drop Down
Senior Member
Senior Member
Avatar

Joined: 08 April 2002
Location: United States
Status: Offline
Points: 4670
Post Options Post Options   Thanks (0) Thanks(0)   Quote michael Quote  Post ReplyReply Direct Link To This Post Posted: 05 October 2004 at 11:20am
No, they are not limited to 20, i think it's 255 but not 100% off hand. If you forgot the pass, just log in using windows auth and reset it.
Back to Top
michael View Drop Down
Senior Member
Senior Member
Avatar

Joined: 08 April 2002
Location: United States
Status: Offline
Points: 4670
Post Options Post Options   Thanks (0) Thanks(0)   Quote michael Quote  Post ReplyReply Direct Link To This Post Posted: 05 October 2004 at 11:22am
Originally posted by Mart Mart wrote:

Not sure about length of passwords but to reset sa password try logging in with a differant account and try this:

UPDATE
master.dbo.syslogins
SET
password = pwdencrypt('newpassword')
WHERE
name = 'sa'



Don't do that. Never update sysdatabases manually.
Back to Top
Mart View Drop Down
Senior Member
Senior Member
Avatar

Joined: 30 November 2002
Status: Offline
Points: 2304
Post Options Post Options   Thanks (0) Thanks(0)   Quote Mart Quote  Post ReplyReply Direct Link To This Post Posted: 05 October 2004 at 11:32am
lol ok
Back to Top
theSCIENTIST View Drop Down
Senior Member
Senior Member


Joined: 31 July 2003
Location: United Kingdom
Status: Offline
Points: 440
Post Options Post Options   Thanks (0) Thanks(0)   Quote theSCIENTIST Quote  Post ReplyReply Direct Link To This Post Posted: 06 October 2004 at 5:28pm
Thx, I didn't update it manually without reading more about it first, but your coments helped me to do the right thing, all sorted, thx once again.
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.