security issues for an application server

Posted on 2013-02-07
Last Modified: 2013-02-27
I am not a systems developer, but we have an internal payroll application, that essentially has 2 servers in its architecture, a database server running MS-SQL Server, and an application server, both have windows 2008 server as OS. A security audit has found a weak password associated with a local OS account which is members of the admins group. My question is what is the overall risk, the data is stored on the database server not the application server, so if someone exploited this weak password and got admin access to the application server, what’s the risk, what could they? What “data” is typically installed an the application server? Surely the higher risk server is the database server which houses the actual data.
Question by:pma111
  • 3
  • 2

Accepted Solution

CorinTack earned 250 total points
ID: 38864430
There is a large risk here, as someone compromising an administrative account on a server machine could use it to then create administrative other accounts that could, potentially, be used to access other networked devices. This would give them access to the data server also, and you're obviously trying to avoid that.

Any administrator accounts should always have strong passwords. Just because the server that the account sits on (or is used on) doesn't host important data itself, that doesn't mean it can't be used to get access to that data.

Author Comment

ID: 38864476
Thanks.... How so? I appreciate if you get local admin access you could create additional local admins, but that's just on that server isn't it? Ie if I have local admin access on my domain laptop I can't access or create additional admins on another laptop.
LVL 78

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 250 total points
ID: 38866223
You're missing the point all administrative accounts MUST have strong passwords.. Having 1 weak password opens an attack vector i.e. the ability to modify an application, add malicious code and wait ... thus gaining the ability to compromise the network...
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.


Author Comment

ID: 38875511
I am not missing the point at all, I am fully aware they all MUST have strong passwords, but from a risk perspective I want to understand what the ultimate is as per the question.

Author Comment

ID: 38933826
Still awaitng some clarifacation on:

How so? I appreciate if you get local admin access you could create additional local admins, but that's just on that server isn't it? Ie if I have local admin access on my domain laptop I can't access or create additional admins on another laptop.
LVL 78

Expert Comment

by:David Johnson, CD, MVP
ID: 38934139
Depends if the local admin has access to the sql db server .. sql has different security rules than the operating system. but they could always just copy the entire database if located on the database server.

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Intermittent issues with RDP on domain servers 4 46
Remote Desktop Certificates 6 44
local administrator password solution 26 77
Sharepoint 2010 Audit Logs 11 84
Remote Apps is a feature in server 2008 which allows users to run applications off Remote Desktop Servers without having to log into them to run the applications.  The user can either have a desktop shortcut installed or go through the web portal to…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now