Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Web-Based SQL Access

Status
Not open for further replies.

ATCal

MIS
Apr 1, 2000
308
US
I apologize if this is an oft asked question.

We have a web server in our DMZ that needs access to a SQL server on the inside. We have been pulled two ways as to how to grant this access. One programmer says to create a Domain containing both machines and use NT authentication because SQL authent. can be easily compromised if the web server is hacked.
The other programmer suggests keeping the machines seperate and use SQL authent. because if the web server gets compromised they now have access to Domain wide services.

Any idea on which is more secure?
Are there any good white papers on this issue?

Thanks Al
atc-computing@comcast.net

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top