Re: SQL Server for Oracle DBAs



Tony Rogerson wrote:
I will show you how quickly some of my former students can turn it
into burnt toast.

Name 1 that exposes a physical security software defect in SQL Server 2005.

Don't forget to post the URL to the KB article or independent security bulletin.

http://www.google.com/search?hl=en&q=%22Advanced+Automated+SQL+Injection+Tool+for+MS-SQL%22&btnG=Search

returns 3,180 hits. Tell us it isn't possible.

Then go back to the SQL Server usenet group where you might contribute
something that doesn't have a troll factor of 100.

Here, I've even done the work for you...

http://www.securityfocus.com/infocus/1644
"SQL Injection and Oracle, Part One"

Let me see if I can draw a straight line for you.
You asked for a security defect in SQL Server.
I gave you one.
You went searching for issues in Oracle.

You've got a troll factor of 100
You've got an integrity factor of 0

Please take your pathetic trolling somewhere where it is appreciated.

Oh that's right ... you aren't appreciated anywhere so you hang out
here. You earn yet another email to your employer if you don't either
stay on topic or get lost. Choice is yours.
--
Daniel A. Morgan
Puget Sound Oracle Users Group
www.psoug.org
.



Relevant Pages

  • Re: "Which is more secure? Oracle vs. Microsoft" (is it a fair comparison?)
    ... "SQL Server code is just more secure than Oracle code." ... "Does Oracle have an equivalent of SDL? ... David Litchfield is one of the most predominant security researchers in the ... SQL Server because there would be no point at all in considering Microsoft's ...
    (Bugtraq)
  • Re: Oracle licence question
    ... Edition to SQL Server Enterprise it is not. ... Oracle standard has no Business Intelligence; ... Data Encryption is included with SQL Server Standard, ... Advanced Security is not included with Oracle Standard, ...
    (comp.databases.oracle.server)
  • Re: SQL or Access DB
    ... As far as encryption goes though... ... with Sql Server you can use SQL DMO and encrypt your stored procedures ... installation - Security was absolutely critical and in most instances, ... > then we create a nice gui around this database and sell it to automotive ...
    (microsoft.public.dotnet.languages.vb)
  • Re: Is there any way to prevent hacker trying to guess sa password?
    ... and port 1433 will not be open. ... If someone can crash SQL Server by connecting to port 1433, ... You don't need multiple security experts. ...
    (microsoft.public.sqlserver.security)
  • Re: Getting to the bottom of MSDE network connection problems ...
    ... Brilliant, Nick, especially the explanation for local network user being ... authenticated as GUEST in WinXP SP2. ... > on a desktop OS like XP (meaning that, you can not compare SQL Server ... > again and selected the security tab. ...
    (microsoft.public.sqlserver.msde)