-
1
- #1
Bernadette
MIS
XP_Cmdshell runs with the full permissions of the account it is running under so if your SQL Server is running under a domain administrator's account - then the 'sa' account will have control over the NT network using xp_cmdshell. The 'sa' account can run any OS Command including "format c:".
Make sure you restrict the ability to execute xp_cmdshell amd runCmdExec amd ActiveScripting jobs or you are leaving yourself open to security breeches which could lead to someone deleting files from your network or worse - formatting the drives on your server !!!
Hope This Helps
Bernadette
Make sure you restrict the ability to execute xp_cmdshell amd runCmdExec amd ActiveScripting jobs or you are leaving yourself open to security breeches which could lead to someone deleting files from your network or worse - formatting the drives on your server !!!
Hope This Helps
Bernadette