SQL Server Security (Osborne Networking) and over one million other books are available for Amazon Kindle. Learn more

Buy New

or
Sign in to turn on 1-Click ordering.
or
Amazon Prime Free Trial required. Sign up when you check out. Learn More
Buy Used
Used - Good See details
$4.98 & eligible for FREE Super Saver Shipping on orders over $25. Details

or
Sign in to turn on 1-Click ordering.
 
   
More Buying Choices
Have one to sell? Sell yours here
SQL Server Security
 
 
Start reading SQL Server Security (Osborne Networking) on your Kindle in under a minute.

Don't have a Kindle? Get your Kindle here, or download a FREE Kindle Reading App.

SQL Server Security [Paperback]

David Litchfield (Author)
4.8 out of 5 stars  See all reviews (4 customer reviews)

List Price: $49.99
Price: $32.49 & this item ships for FREE with Super Saver Shipping. Details
You Save: $17.50 (35%)
  Special Offers Available
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.
Only 2 left in stock--order soon (more on the way).
Want it delivered Monday, January 30? Choose One-Day Shipping at checkout. Details
Textbook Student FREE Two-Day Shipping for Students. Learn more

Formats

Amazon Price New from Used from
Kindle Edition $29.24  
Paperback $32.49  

Book Description

0072225157 978-0072225150 August 27, 2003 1
Addresses SQL Server vulnerabilities and provides security solutions. Covers installation, administration, and programming--plus security issues such as authentication, encryption, intrusion detection, and more. Written for IT professionals administering or programming any SQL Server-based application--includes coverage of SQL Server 7, SQL Server 2000, and SQL Server (Yukon).

Special Offers and Product Promotions

  • Buy $50 in qualifying physical textbooks, get $5 in Amazon MP3 Credit. Here's how (restrictions apply)

Frequently Bought Together

Customers buy this book with SQL Server Security Distilled $33.15

SQL Server Security + SQL Server Security Distilled
  • This item: SQL Server Security

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details

  • SQL Server Security Distilled

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details


Customers Who Bought This Item Also Bought


Editorial Reviews

From the Back Cover

Protect your data from the most sophisticated hackers with hands-on examples and sure-fire measures in SQL Server Security. Understand the ways in which SQL Server can be hacked, and what you can do to prevent exploitation of your data. Install, administer, and program secure Microsoft SQL Server environments and applications. Assess your risk and threat levels when designing a secure system. Make sure your defensive strategies match the threat when considering encryption options. Extend your defenses to include security auditing and intrusion detection. Implementing the techniques in this indispensable security resource is as close as you can get to guaranteed prevention against hackers without turning off the power switch.

Covers the latest techniques:

  • Install and configure your SQL Server environment for maximum security
  • Build and maintain a robust and protected database server
  • Protect valuable customer information, human resources data, and more
  • Defend against application software vulnerabilities and configuration issues
  • Ensure that access to data is only granted when appropriate
  • Encrypt data into an unreadable form to preserve confidentiality
  • Understand the mistakes that contributed to the spread of the SQL Slammer worm
  • Rid your applications of SQL injection bugs
  • Permit client applications to access the server securely
  • Build and utilize an effective auditing and intrusion detection plan

About the Author

Chip Andrews, MCDBA, MCSE+I, is a Software Security Architect for Claris Corporation as well as an independent security consultant. Chip has more than 16 years of software development experience in the C++, Visual Basic, Java, C#, and T-SQL languages. He is a contributing author to several periodicals including Microsoft Certified Professional Magazine, SQL Server Magazine, and Dr. Dobbs Journal. Chip also has contributed a chapter on SQL Server Security to the book Hacking Exposed Windows 2000 by Osborne. He has given presentations at Black Hat computer security conferences concerning SQL Server security and its role in the secure enterprise.

Product Details

  • Paperback: 352 pages
  • Publisher: McGraw-Hill Osborne Media; 1 edition (August 27, 2003)
  • Language: English
  • ISBN-10: 0072225157
  • ISBN-13: 978-0072225150
  • Product Dimensions: 9.2 x 7.4 x 0.8 inches
  • Shipping Weight: 1.6 pounds (View shipping rates and policies)
  • Average Customer Review: 4.8 out of 5 stars  See all reviews (4 customer reviews)
  • Amazon Best Sellers Rank: #1,356,193 in Books (See Top 100 in Books)

More About the Author

Discover books, learn about writers, read author blogs, and more.

 

Customer Reviews

4 Reviews
5 star:
 (3)
4 star:
 (1)
3 star:    (0)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.8 out of 5 stars (4 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

7 of 7 people found the following review helpful:
5.0 out of 5 stars Chip Andrews and crew deliver a title worthy of its lineage, October 12, 2003
This review is from: SQL Server Security (Paperback)
"SQL Server Security" (SSS) is a great security book, free of the bloat the affects both operating systems and many technical volumes. Weighing in at 322 pages, it's packed with the detail needed to securely deploy Microsoft SQL servers. Although many people contributed to the text, it doesn't suffer from internal redundancy. I highly recommend anyone operating SQL servers devour this book.

In the "Acknowledgements," lead author Chip Andrews writes "I wanted this book to give security and database professionals the same readability, reference ability, and red-eyed wonder that 'Hacking Exposed' gave me a few years back." My favorite aspect of the HE line was the material's ability to explain attack and defense concepts while illuminating the internal operation of victimized systems. SSS follows this lead by devoting entire chapters to SQL Server components, like Network-Libraries (ch. 4) and Authentication and Authorization (ch. 5). My favorite sections appear in chapter 7, where the authors describe novel ways to leverage SQL Server's "C-2 auditing" features for purposes of intrusion detection.

SSS dispenses an immense amount of useful advice, whether it's a whole chapter on secure installation (ch. 3), best practices found in most chapters, or the appendices on stored procedures and integration with other Microsoft technologies. The only downside I found appears in chapter 2, where SQL samurai David Litchfield uses language outside the realm of most readers' understanding. For example, "the import address entry for GetProcAddress() in sqlsort.dll shifts by 12. With no SQL Server service pack, the address of the entry is at 0x42AE1010, and on SP1 and SP2, it is at 0x42AE101C" (p. 29). The uninitiated should skim this chapter and trust the authors when they claim SQL Server can be attacked by multiple means.

SSS is a must-buy if you operate SQL Server. It's the manual Microsoft forgot to ship.

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


3 of 3 people found the following review helpful:
5.0 out of 5 stars Excellent coverage, December 28, 2003
By A Customer
Amazon Verified Purchase(What's this?)
This review is from: SQL Server Security (Paperback)
Having read about half of this book, I can say that each chapter has not disappointed me. As a mid-level DBA, this book has helped bring things together in my mind that seemed like a loose collection before. I would highly recommend this book to anyone wanting to beef up their knowledge of security with SQL Server. The authors have done an excellent job. It's easy to read and chapters are reasonably short and concise with just the right amount of illustrations.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


2 of 3 people found the following review helpful:
5.0 out of 5 stars Clearly addresses SQL Server vulnerabilities, January 12, 2004
This review is from: SQL Server Security (Paperback)
SQL Server Security by David Lichtfield clearly addresses SQL Server vulnerabilities and provides security solutions, as well as covering installation, administration, and programming, plus security issues such as authentication, encryption, intrusion detection, and more. Written for IT professionals administering or programming any SQL Server-based application, SQL Server Security includes coverage of SQL Server 7, SQL Server 2000, and SQL Server (Yukon).
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No

Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews


Only search this product's reviews



Inside This Book (learn more)
First Sentence:
In the early days of personal computing, security was often an afterthought, if it was never thought of at all. Read the first page
Key Phrases - Statistically Improbable Phrases (SIPs): (learn more)
obfuscated password, multiserver administration, fixed server roles, extended stored procedures, msdb database, authenticated logins, sql server, snapshot folder, server login, statement permissions, injection attacks, standard logins, transactional replication, horse code, sysadmin role, database username, ownership chain, database roles, snapshot files, connection string, exploit code, level auditing, input validation, buffer overflow vulnerabilities, server authentication
Key Phrases - Capitalized Phrases (CAPs): (learn more)
Enterprise Manager, Active Directory, Server Agent, Database File, Server Network Utility, Distribution Agent, Windows Synchronization Manager, Cancel Figure, Cancel Help Figure, Client Network Utility, Server Books Online, Login Failed, Login Success, Logout Success, Mixed Mode, Server Group, Code Listing, Event Viewer, Multiprotocol Net-Library, The Basics, Windows Authentication Mode, Latinl General, Meta Data Services, Object Properties, Back Next
New!
Books on Related Topics | Concordance | Text Stats
Browse Sample Pages:
Front Cover | Table of Contents | First Pages | Index | Back Cover | Surprise Me!
Search Inside This Book:




What Other Items Do Customers Buy After Viewing This Item?


Suggested Tags from Similar Products

 (What's this?)
Be the first one to add a relevant tag (keyword that's strongly related to this product).
 
(1)

Your tags: Add your first tag
 

Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Search Customer Discussions
Search all Amazon discussions
   
Related forums



So You'd Like to...


Create a guide


Look for Similar Items by Category


Look for Similar Items by Subject