The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


New Paper: Microsoft SQL Server Passwords


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: Mon, 8 Jul 2002 15:32:47 +0100
From: NGSSoftware Insight Security Research <[email protected]>
To: [email protected]
Subject: New Paper: Microsoft SQL Server Passwords

Hi all,
I've written a paper on how users' passwords, or rather their hashes, are
stored in Microsoft's SQL Server. The paper discusses the manner in which
they are hashed and how they can be more easily brute forced as two hashes
are stored: a case sensitive password hash and an upper case password hash
are produced. Needless to say, when auditing password strength, it is far
easier to go after the UPPER cased version. The paper contains also contains
some demonstration source code for performing a dictionary based audit
against the hashes and NGSSoftware have produced an optomized GUI based
tool, as well.

Microsoft's SQL best practices dictate that SQL logins should not be used in
favour of native Windows Authentication using an operating system account,
but we recognize that often consumers of SQL Server do not often want to do
this. (With a Windows account people have access to other operating system
services as well as SQL Server, but with just an SQL login they should only
be able to access the SQL Services. The latter is the 'more safe' option in
the author's opinion)

Anyway, you can get the paper in the researcher section of the NGSSite @
http://www.nextgenss.com/ .

Cheers,
David Litchfield
NGSSoftware Ltd
+44(0)208 401 0070





<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру