Sign in
MSDN Blogs
Microsoft Blog Images
More ...
Blog - Title
MSDN Blogs
>
SQL Server Security
Server & Tools Blogs
>
Data Platform Blogs
>
SQL Server Security Blog
All About Data Platform
All About Data Platform
Data Development
ADO.NET (Managed Providers, DataSet & EF)
WCF Data Services
SQL Server Customer Advisory Team
SQL Server Protocols
Microsoft XML Team
JDBC
Microsoft Drivers for PHP for SQL Server
Sync
SQL Server Data Tools
StreamInsight
Data Quality Services
Data Quality Services
SQL Server Customer Advisory Team
Jessica Meats’ Blog
All MSDN DQS Postings
OLTP
SQL Server Team
ADO.NET (Managed Providers, DataSet & EF)
SQL Server Customer Advisory Team
SQL Release Services
SQL OS
Running SAP on SQL Server
Conor vs. SQL
SQL AlwaysOn Team
SQL Server Manageability
Integration Services
SSIS
Data Quality Services
SQL Server Customer Advisory Team
All MSDN SSIS Postings
Data Security & Storage
SQL Server Security
SQL Server Storage Engine
SQL OS
SQL Server Customer Advisory Team
Data in the Cloud
Windows Azure
Your Data in the Cloud
SQL Server Team
Silver Lining
SQL Server Security Blog
Live Now on Server & Tools Blogs
Subscribe
Comments
Contact
Menu
Blog Home
Atom
Translate this page
Powered by
Microsoft® Translator
Tags
"Transparent Database Encryption" Database Security Encryption TDE DEK database encryption key
25713
action_id
Checksum
class_type
Compliance
Cryptography
Execution context
firewall
HashBytes
Hashing
Microsoft Source Code Analyzer for SQL Injeciton
network security
Permission Hierarchy
Permission Model
Permissions
RC4
RC4_128
Salting
SQL Injection ASP
SQL Server Audit
More
▼
Less
▲
Archives
Archives
October 2012
(1)
April 2012
(1)
March 2012
(1)
February 2012
(2)
October 2011
(1)
August 2011
(2)
July 2011
(1)
April 2011
(1)
February 2011
(2)
January 2011
(1)
December 2010
(4)
September 2010
(2)
July 2010
(2)
June 2010
(2)
April 2010
(1)
March 2010
(2)
February 2010
(4)
November 2009
(1)
October 2009
(1)
June 2009
(2)
May 2009
(2)
April 2009
(2)
March 2009
(4)
February 2009
(2)
January 2009
(3)
December 2008
(3)
November 2008
(1)
October 2008
(2)
August 2008
(1)
July 2008
(2)
June 2008
(2)
March 2008
(1)
January 2008
(1)
December 2007
(1)
November 2007
(1)
More
▼
Less
▲
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
SQL Server Security
SQL Audit Buffering and Error Handling
Posted
over 5 years ago
by
Jack Richins
1
Comments
I've had several questions about how exactly the buffering and error handling works in SQL Audit and thought it would help to give some more detail. For starters, let's break down the event firing workflow into the following stages: 1. Permission...
SQL Server Security
Data Protection Day, January 28th
Posted
over 4 years ago
by
Jack Richins
1
Comments
Thought some readers of this blog might be interested in Data Protection Day , tomorrow, January 28. The Council of Europe established this day to raise awareness of data privacy and data protection issues and how we, as technology professionals, can...
SQL Server Security
Auditing in SQL Server 2008 white paper
Posted
over 4 years ago
by
Il-Sung
1
Comments
In continuation to the post by Jack back in October, we've added Auditing in SQL Server 2008 to our list of security focused white papers ( http://msdn.microsoft.com/en-us/library/dd392015.aspx ). We'll let you know as more white papers are published...
SQL Server Security
Performance of Impact of Auditing in SQL Server 2008
Posted
over 4 years ago
by
Jack Richins
1
Comments
Il-Sung Lee and Art Rask’s whitepaper, Auditing in SQL Server 2008 , just hit the web. Congratulations! I just wanted to add to what Il-Sung already has said about this paper that this is a great resource that will answer some of the big questions we...
SQL Server Security
Feedback requested: Default schemas for Windows groups
Posted
over 4 years ago
by
Jack Richins
1
Comments
We would like your feedback on the scenarios where you need to assign default schemas to Windows groups. We have a post in the forums , but there has only been one reply so far. Please, if you have an opinion or even just want to express your support...
SQL Server Security
Interested in Compliance?
Posted
over 4 years ago
by
Il-Sung
1
Comments
I'm pretty sure that there are many of you who have to deal with regulatory compliance but how many of you are aware that we have a SQL Server Compliance web portal? Check out http://www.microsoft.com/sqlserver/2008/en/us/compliance.aspx . There's a lot...
SQL Server Security
SQL Server 2005 Encryption – Encryption and data length limitations (feedback page)
Posted
over 5 years ago
by
Raul Garcia - MS
1
Comments
We have received some feedback regarding the “SQL Server 2005 Encryption – Encryption and data length limitations” article, but unfortunately the owner of this blog is no longer a member of our team and we really don’t have access to it in order to answer...
SQL Server Security
OPEN SYMMETRIC KEY scope in SQL Server
Posted
over 6 years ago
by
Raul Garcia - MS
1
Comments
Recently I have heard a few questions regarding the scope of the SYMMETRIC KEY key-ring, especially when using modules (i.e. stored procedures) to open a key. One particular topic that got my attention is the impression that the OPEN SYMMETRIC KEY call...
SQL Server Security
The TRUSTWORHY bit database property in SQL Server 2005
Posted
over 6 years ago
by
Raul Garcia - MS
1
Comments
In SQL Server 2005 we introduced a new database property named TRUSTWORTHY bit (TW bit for short) at the database level in order to work as a safeguard to reduce the default surface area regarding some powerful new features: EXECUTE AS USER and CLR assemblies...
SQL Server Security
Getting started with Microsoft ® Source Code Analyzer for SQL Injection
Posted
over 5 years ago
by
Bala Neerumalla
1
Comments
Two days ago, we released Microsoft ® Source Code Analyzer for SQL Injection, June 2008 CTP which can analyze SQL injection vulnerabilities in Active Server Pages (ASP) code. In this blog, we will describe simple steps to help you start using the tool...
SQL Server Security
Microsoft ® Source Code Analyzer for SQL Injection – July 2008 CTP
Posted
over 5 years ago
by
Bala Neerumalla
1
Comments
Today we have released an updated Community Technology Preview of Microsoft Source Code Analyzer for SQL Injection. We made the following improvements based on community feedback: Included a GUI to view warnings generated by the tool. Downgraded...
SQL Server Security
HIPAA Compliance with SQL Server 2008
Posted
over 3 years ago
by
Il-Sung
1
Comments
Aside from PCI, I probably hear more about HIPAA compliance (the Health Insurance Portability and Accountability Act ) from our customers than other regulations. Although there is no formal certification around HIPAA at this point, health care providers...
SQL Server Security
PCI DSS Compliance with SQL Server 2008
Posted
over 4 years ago
by
Il-Sung
1
Comments
Since PCI Compliance seems to be popular subject for SQL Server users (by which I mean that a quite a few of you are forced to deal with it) here's something that may help. Parente Randolph is a PCI QSA (Qualified Security Assessor) and they recently...
SQL Server Security
Arx the latest vendor to support EKM
Posted
over 4 years ago
by
Il-Sung
0
Comments
With the increasing popularity of the EKM feature in SQL Server 2008, more vendors are adding their support for this great feature. I'm very happy to announce that Arx has just announced their releaese of their EKM provider dll: http://www.arx.com...
SQL Server Security
Link to Lyudmila’s blog
Posted
over 4 years ago
by
Raul Garcia - MS
0
Comments
My teammate Lyudmila is maintaining her own TechNet blog where she writes articles related to SQL Server security. You can access her blog at http://blogs.technet.com/lyudmila_fokina . Her blog is written in Russian, but the samples she includes should...
SQL Server Security
SQL Server EncryptByKey cryptographic message description
Posted
over 4 years ago
by
Raul Garcia - MS
0
Comments
Since the introduction of SQL Server 2008 extensible key management (EKM), new opportunities may arise to handle data encryption on the client while still making the plaintext data accessible to authorized users in SQL Server. One issue between SQL Server...
SQL Server Security
About DEK rotation and log backup in Transparent Database Encryption (TDE)
Posted
over 4 years ago
by
liyingj
0
Comments
Regarding the DEK rotation in TDE, after a DEK has been rotated twice, a log backup must be performed before the DEK can be modified again, otherwise in the third time of rotation the following error message will be popped up: “ This command requires...
SQL Server Security
RSA Conference 2010
Posted
over 3 years ago
by
Raul Garcia - MS
0
Comments
If anyone is planning to attend to the RSA Conference 2010 in San Francisco, please stop by and visit us at the Microsoft SQL Server booth and to the theater sessions we have prepared for the event: Title Schedule Speaker ...
SQL Server Security
Open positions @ SQL Server
Posted
over 3 years ago
by
Raul Garcia - MS
0
Comments
We wanted to post and let everyone know that the Microsoft SQL Server Base and Infrastructure (SBIA) team is hiring for various test positions. This includes the Security team (or Core Security Infrastructure team) and several other teams who are working...
SQL Server Security
Presentation on SQL Security
Posted
over 3 years ago
by
Jack Richins
0
Comments
The SQL Security Team's Raul Garcia and Il- Sung Lee are presenting at 1 PM PST today on SQL Security in an online webcast. http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032444124&Culture=en-US . Good, 300 level discussion on how to...
SQL Server Security
SQL Server Authentication Troubleshooter
Posted
over 3 years ago
by
Raul Garcia - MS
0
Comments
I am posting this article on behalf of my teammate Lyudmila. A new tool to help investigate ‘Login Failed’ errors in SQL Server has been recently implemented and published on CodePlex: http://ssat.codeplex.com/ The tool is implemented in C# and...
SQL Server Security
Quick security references (QSR) on Cross-Site scripting and SQL injection.
Posted
over 3 years ago
by
Raul Garcia - MS
0
Comments
Recently the Security Development Lifecycle (SDL) team announced the release of new type of security guidance papers called Quick security references (QSRs) . The first two papers focus on Cross-Site scripting and SQL Injection . I would strongly recommend...
SQL Server Security
How To: Share a Single EKM Credential among Multiple Users
Posted
over 4 years ago
by
Raul Garcia - MS
0
Comments
SQL Server Extensible Key Management (EKM) requires the authentication information (user/password) to be stored in a credential mapped to the primary identity. This version of EKM cannot be used under an impersonated context; that is, you cannot access...
SQL Server Security
Accessing the calling context in modules that use EXECUTE AS
Posted
over 5 years ago
by
Raul Garcia - MS
0
Comments
In many occasions, marking a module (i.e. SP, trigger, etc.) with execute as can be really useful as it allows a controlled impersonation during the module execution; but at the same time there are many cases that it is necessary to access information...
SQL Server Security
Caregroup CIO Blogs about using Auditing
Posted
over 5 years ago
by
Jack Richins
0
Comments
John Halamka , Harvard CIO, has blogged about the Caregroup Auditing project that was the basis for the Auditing portion of the Compliance SDK mentioned in my previous post . They did a lot of great work and we learned a lot from their feedback. And now...
Page 2 of 3 (62 items)
1
2
3