Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Scanning for SQL vulnerabilities

Posted on 2012-03-22
5
Medium Priority
?
281 Views
Last Modified: 2012-04-01
I'm preparing for a security audit next week and have been tasks with checking for SQL vulnerabilities.  I've compiled a list of all the various SQL servers on the LAN and I'm looing for some type of (free) utility that will let me scan them for known security issues.  Can you recommend one that may help with the audit?
0
Comment
Question by:First Last
  • 3
  • 2
5 Comments
 
LVL 17

Expert Comment

by:Barry Cunney
ID: 37752329
May be worth looking into Policy Based Management in SQL Server itself
http://msdn.microsoft.com/en-us/security/Video/ee216343
0
 
LVL 1

Author Comment

by:First Last
ID: 37752340
That looks like a cool way to lock things down across multiple SQL servers but really for now I just need a way to find out where I'm vulnerable in order to lock it down for the audit.  I'll definately look into that one once things have settled down next week.
0
 
LVL 17

Expert Comment

by:Barry Cunney
ID: 37752857
Here is an article on SQL Server Security Best Practices - I think if you examine each of the areas discussed in this article you should have most areas covered for the audit.

http://www.greensql.com/content/sql-server-security-best-practices

Examine the 'sa' profile - best if it is disabled but if it is used make sure only privileged persons are using it and it has a very strong password - make sure it is not used in connection strings or other login configurations in apps.

You can also use SQL Profiler to monitor who/what is connecting to the SQL Server's - may be worth doing this to try and identify items that may need to be locked down.

Also you can administer multiple servers from one single server using CMS
http://www.brentozar.com/archive/2008/08/sql-server-2008s-new-central-management-server/
0
 
LVL 1

Accepted Solution

by:
First Last earned 0 total points
ID: 37773683
I found a good one though it wasn't free:  Secure Auditor by Secure Bytes
0
 
LVL 1

Author Closing Comment

by:First Last
ID: 37792747
Found my own
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Considering today’s continual security threats, which affect Information technology networks and systems worldwide, it is very important to practice basic security awareness. A normal system user can secure himself or herself by following these simp…
When you put your credit card number into a website for an online transaction, surely you know to look for signs of a secure website such as the padlock icon in the web browser or the green address bar.  This is one way to protect yourself from oth…
Viewers will learn how to use the SELECT statement in SQL and will be exposed to the many uses the SELECT statement has.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

782 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question