ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Enterprise applications Toolkit

Protect your SQL Server database

Arthur Fuller

Published: 27 Oct 2005 10:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Do you worry that someone with devious plans could break into your SQL Server database? If not, you should because this may be a very real and dangerous possibility. First, I'll cite an example from a previous job to demonstrate how easy it is to access a database.

Why a DBA might break into your database
I used to be part of a team that was responsible for an enterprise application designed to run a pulp and paper mill. The software sold for $1.2m as the base price. As the customer selected various options, the price went up in rather large increments. A sale of the application with all features working could amount to $3 million. We didn't create separate executables for each possible configuration because that would have been a nightmare. Instead, we created an encrypted procedure that read a table and made the functionality available that the client had licensed.

The local DBA with even a little savvy and an Internet connection could crack our code wide open in five minutes, gaining full functionality of the application and thereby saving her firm at least a million dollars. This is against the law, but some DBAs will take the chance to save their companies such large sums of money.

How a DBA could decrypt your database
If you don't buy into my scenario, then I encourage you to try it. Create one or more stored procedures, views, and triggers with encryption using the standard "with encryption" phrase. Then follow the steps in this recipe, and see how easy it is to shatter your alleged defence:

  1. Grab a free SQL decryption tool.
  2. Install it.
  3. Run it and choose the server and database of interest. (You must be able to log in.)
  4. Select the procedures, views, and triggers you wish to decrypt.
  5. Choose a directory in which to save the decrypted files and click Save.
  6. Protect your database with these resources
  7. You must assume that a DBA will try to break into your database. If the DBA succeeds, the vendor of the application may be out a significant amount of money.

Simply adding encryption to your database will only protect you from entry-level or inexperienced DBAs. If encrypted procedures, views, and triggers are important to you and your firm (and they should be), then you have no choice but to spend some money and license real encryption, or to download one of the following alternatives (both commercial and free) and beef up your encryption efforts.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
36 out of 71 people found this useful


Full Talkback thread

1 comment

  1. Just a follow-up. I posted an update to the Free... Michael Coles

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

SQL DBA (Oracle) - Chester - up to 28k + benefits

A new and exciting opportunity has arisen working as a SQL Server (Oracle) DBA working for one of the largest environmental organisations in Chester. ...

SQL Server Analyst Programmer. Senior banking position. Canary Wharf.

The team is seeking a SQL Server developer with the following skillset: SQL Server 2000/2005 hands on development (stored procedures, triggers, ...

SQL Server Development DBA - Brighton - Upto 43,000 - SQL Server

The company are looking to expand their data team and due to critical projects they require a SQL Server Development DBA to work on their SQL ...

Featured Talkback

The internet is going to have do a lot of maturing before it is ready for this kind of traffic. Security is always going to be a problem, connectivity is poor, and most business's are unwilling for their employees to have open access.

By: ator1940

Read full story:
Microsoft prepares to take Office online