Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - MSSQL set up security??
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

MSSQL set up security??

 Post Reply Post Reply Page  12>
Author
ljamal View Drop Down
Mod Builder Group
Mod Builder Group


Joined: 16 April 2003
Status: Offline
Points: 888
Post Options Post Options   Thanks (0) Thanks(0)   Quote ljamal Quote  Post ReplyReply Direct Link To This Post Topic: MSSQL set up security??
    Posted: 16 January 2004 at 9:43pm
In doing a forum update to a SQL version of the forum, I stumbled upon a security hole.

When you run the sql setup file on top of an installation it creates a new admin account with the widely distributed username and password. This means that if you do not delete the sql setup file, it can be run and give someone admin access to your forum. Those that have installed the username change MOD should be even more cautious as they will not notice the new admin user if the person changes the username.

My suggestion for closing the hole would be to have the setup file check to be sure the database is empty before adding the admin and guest accounts during set-up.
Back to Top
MadDog View Drop Down
Mod Builder Group
Mod Builder Group
Avatar

Joined: 01 January 2002
Status: Offline
Points: 3008
Post Options Post Options   Thanks (0) Thanks(0)   Quote MadDog Quote  Post ReplyReply Direct Link To This Post Posted: 16 January 2004 at 11:38pm
This is not a bug because the person would have to know your username and password to re-run the script.
Back to Top
ljamal View Drop Down
Mod Builder Group
Mod Builder Group


Joined: 16 April 2003
Status: Offline
Points: 888
Post Options Post Options   Thanks (0) Thanks(0)   Quote ljamal Quote  Post ReplyReply Direct Link To This Post Posted: 16 January 2004 at 11:49pm
True, but you run it yourself with an upgrade in order to upgrade the stored procedures and add another admin and forget (or not know to) delete it.

Either way it should check to avoid adding another admin, it such an easy fix, it seems lax not to do it.

Edited by ljamal
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 17 January 2004 at 4:31am
The sql setup file should only be run once and is NOT for upgrades so this shouldn't be a problem.

It does also say in the install instructions to delete the file from the server once the database is created.

DO NOT RUN THE SETUP FILE MORE THAN ONCE ON INITIAL INSTALL.

IT IS NOT AN UPGRADE FILE!!!


Edited by -boRg-
Back to Top
ljamal View Drop Down
Mod Builder Group
Mod Builder Group


Joined: 16 April 2003
Status: Offline
Points: 888
Post Options Post Options   Thanks (0) Thanks(0)   Quote ljamal Quote  Post ReplyReply Direct Link To This Post Posted: 17 January 2004 at 11:48am
You can shoot it to the mountain top, but that doesn't mean it won't be done. I always thought the idea behind building applications was to make them as idiot proof as possible. A simple SQL if clause would make this a unfactor, so why all the opposition?

Back to Top
michael View Drop Down
Senior Member
Senior Member
Avatar

Joined: 08 April 2002
Location: United States
Status: Offline
Points: 4670
Post Options Post Options   Thanks (0) Thanks(0)   Quote michael Quote  Post ReplyReply Direct Link To This Post Posted: 17 January 2004 at 10:16pm
I kind of have to agree with Jamal, even though I would not consider that a hole or bug but more of a cosmetic improvement. You know how many people do what they are not supposed to, if the setup is somewhat slow they may hit refresh on the page and yit they have two admin accounts. Agreed though, this file should be deleted immediately....
Back to Top
dpyers View Drop Down
Senior Member
Senior Member


Joined: 12 May 2003
Status: Offline
Points: 3937
Post Options Post Options   Thanks (0) Thanks(0)   Quote dpyers Quote  Post ReplyReply Direct Link To This Post Posted: 17 January 2004 at 10:53pm
Make something idiot proof, and they'll build a better idiot. Many don't read installation instructions. You just know they're not going to read post-installation instructions.

Lead me not into temptation... I know the short cut, follow me.
Back to Top
ljamal View Drop Down
Mod Builder Group
Mod Builder Group


Joined: 16 April 2003
Status: Offline
Points: 888
Post Options Post Options   Thanks (0) Thanks(0)   Quote ljamal Quote  Post ReplyReply Direct Link To This Post Posted: 18 January 2004 at 9:46am
Originally posted by dpyers dpyers wrote:

Many don't read installation instructions. You just know they're not going to read post-installation instructions.


Exactly, so addressing issues that you can control is the best solution over ignoring them and telling people over and over to read the instructions.
Back to Top
 Post Reply Post Reply Page  12>

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.