Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

security issues for an application server

Posted on 2013-02-07
6
Medium Priority
?
184 Views
Last Modified: 2013-02-27
I am not a systems developer, but we have an internal payroll application, that essentially has 2 servers in its architecture, a database server running MS-SQL Server, and an application server, both have windows 2008 server as OS. A security audit has found a weak password associated with a local OS account which is members of the admins group. My question is what is the overall risk, the data is stored on the database server not the application server, so if someone exploited this weak password and got admin access to the application server, what’s the risk, what could they? What “data” is typically installed an the application server? Surely the higher risk server is the database server which houses the actual data.
0
Comment
Question by:pma111
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 7

Accepted Solution

by:
CorinTack earned 1000 total points
ID: 38864430
There is a large risk here, as someone compromising an administrative account on a server machine could use it to then create administrative other accounts that could, potentially, be used to access other networked devices. This would give them access to the data server also, and you're obviously trying to avoid that.

Any administrator accounts should always have strong passwords. Just because the server that the account sits on (or is used on) doesn't host important data itself, that doesn't mean it can't be used to get access to that data.
0
 
LVL 3

Author Comment

by:pma111
ID: 38864476
Thanks.... How so? I appreciate if you get local admin access you could create additional local admins, but that's just on that server isn't it? Ie if I have local admin access on my domain laptop I can't access or create additional admins on another laptop.
0
 
LVL 83

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 1000 total points
ID: 38866223
You're missing the point all administrative accounts MUST have strong passwords.. Having 1 weak password opens an attack vector i.e. the ability to modify an application, add malicious code and wait ... thus gaining the ability to compromise the network...
0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 
LVL 3

Author Comment

by:pma111
ID: 38875511
I am not missing the point at all, I am fully aware they all MUST have strong passwords, but from a risk perspective I want to understand what the ultimate is as per the question.
0
 
LVL 3

Author Comment

by:pma111
ID: 38933826
Still awaitng some clarifacation on:

How so? I appreciate if you get local admin access you could create additional local admins, but that's just on that server isn't it? Ie if I have local admin access on my domain laptop I can't access or create additional admins on another laptop.
0
 
LVL 83

Expert Comment

by:David Johnson, CD, MVP
ID: 38934139
Depends if the local admin has access to the sql db server .. sql has different security rules than the operating system. but they could always just copy the entire database if located on the database server.
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question