11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 18: Securing Your Database Server 527Step 10. SQL Server <strong>Security</strong>The settings discussed in this section are configured using the <strong>Security</strong> tab of theSQL Server Properties dialog box in Enterprise Manager. The settings apply to all thedatabases in a single instance of SQL Server. The SQL Server Properties dialog box isshown in Figure 18.5.Figure 18.5SQL Server security propertiesIn this step, you:● Set SQL Server authentication to Windows only.●●Set SQL Server audit level to Failure or All.Run SQL Server using a least privileged account.Set SQL Server Authentication to Windows OnlyYou should configure SQL Server to support Windows-only authentication because itprovides a number of benefits. Credentials are not passed over the network, youavoid embedding usernames <strong>and</strong> passwords in database connection strings, securityis easier to manage because you work with the single Windows security modelinstead of a separate SQL Server security model, <strong>and</strong> login security improves throughpassword expiration periods, minimum lengths, <strong>and</strong> account lockout policies.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!