Solved

SQL Local System Account Privledges

Posted on 2010-11-17
4
258 Views
Last Modified: 2012-05-10
Consider the following:

SQL server and agent services run under the local system account
A user has db_owner of all databases other than system
User has local admin rights on the box
SQL builtin\administrator has been removed
User also has SQLAgentReaderRole rights
User does not have 'sa' password

Can the user in any way initiate a job that runs as 'sa'? Also, can the user create a job that runs against the master or msdb databases?

Thanks
0
Comment
Question by:barnesco
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 50

Expert Comment

by:Vitor Montalvão
ID: 34162453
barnesco, for security reasons you shouldn't use Local System Account for SQL Server services.
Check this http://msdn.microsoft.com/en-us/library/ms191543.aspx

Cheers
0
 
LVL 22

Expert Comment

by:8080_Diver
ID: 34165425
If the Pkg owner is sa, then I believe that the user will have to know the sa password in order to execute the package.  That is the nature of sceurity. ;-)  If you don't have sufficient rights, you can't do it and sa rights are a super set of the local admin rights.
0
 
LVL 20

Accepted Solution

by:
Marten Rune earned 500 total points
ID: 34166404
Quote: "User has local admin rights on the box"

Yes he can do all of this with a little knowledge.

//Marten
0
 

Author Comment

by:barnesco
ID: 34166406
I know, but it's not my call.
0

Featured Post

Major Incident Management Communications

Major incidents and IT service outages cost companies millions. Often the solution to minimizing damage is automated communication. Find out more in our Major Incident Management Communications infographic.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Load balancing is the method of dividing the total amount of work performed by one computer between two or more computers. Its aim is to get more work done in the same amount of time, ensuring that all the users get served faster.
International Data Corporation (IDC) prognosticates that before the current the year gets over disbursing on IT framework products to be sent in cloud environs will be $37.1B.
Using examples as well as descriptions, and references to Books Online, show the different Recovery Models available in SQL Server and explain, as well as show how full, differential and transaction log backups are performed
Viewers will learn how the fundamental information of how to create a table.

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question