Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

SA blank password

Status
Not open for further replies.

EscapeUK

Programmer
Jul 7, 2000
438
GB
My SQL install uses SA with a blank password. Is the a sencible thing to do. I have heared that there is a virus that uses this.
 
It really depends on the enviornment the sql server will be going in.

In development envos, it really does not matter a great deal unless you do not want other developers to be able to see what you are working with. If working with information that is senseative(sp), then change it.

For testing or development, change it.

I always change it out of habit. If security is not a worry, have all of them set to the same password, just not blank.
 
Put a password on SA!

If you don't, you leave your entire network at risk - not just SQL Server. Do you wonder why the latest SQL Server Worm spread so quickly and infected 1000's of servers in a couple of days? Those servers did not have an SA password. The worm took advantage of that.

Please read the following threads and the links in the threads to get an idea about how much more seriously SQL DBAs and developers need to be regarding security. This is not just about data confidentiality. It is about having a network that functions properly as well.

thread183-280043
thread183-279012 Terry L. Broadbent - DBA
Computing Links:
faq183-874 contains "Suggestions for Getting Quick and Appropriate Answers" to your questions.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top