Advertisement

06.07.2008 at 01:09AM PDT, ID: 23465763
[x]
Attachment Details

Changing permissions for sysobjects and syscolumns

Asked by Kirsbo in SQL Server 2005, Databases Miscellaneous, Windows 2003 Server

Tags: Microsoft, SQL server, 2005

Hello,

We're running a hosted CMS system based on ASP and SQL server 2005. Now we've encountered a typical SQL injection attack, where the "hacker" tries to execute an sql query in the querystring or through forms.

The query selects * from sysobjects and syscolumns and then iterates through all tables and add a url to all fields. We're in the unfortunate situation that we do not have a systems administrator or engineer on location and we need this fixed by today or sunday at the latest. We of course have access to the database, but we're novices in everything related to roles, permissions, users, schemas etc.

Revising the code is not an option at this time, as the codebase is huge. We've come to the conclusion that this particular attack can be eliminated by removing the webusers permission to select from the sysobjects and syscolumns tables, but we do not know how to actually do it.

What we are looking for is therefore a step by step guide on how to remove those permissions. We're running on Windows Server 2003 and as mentioned SQL server 2005.

Hope someone can help, if you need more info please feel free to comment.

Thanks on advance.Start Free Trial
[+][-]06.07.2008 at 01:22AM PDT, ID: 21734710

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]06.07.2008 at 01:36AM PDT, ID: 21734748

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]06.07.2008 at 02:02AM PDT, ID: 21734799

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: SQL Server 2005, Databases Miscellaneous, Windows 2003 Server
Tags: Microsoft, SQL server, 2005
Sign Up Now!
Solution Provided By: angelIII
Participating Experts: 1
Solution Grade: B
 
 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628