Customer Reviews


8 Reviews
5 star:
 (5)
4 star:
 (2)
3 star:
 (1)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
Share your thoughts with other customers
Create your own review
 
 
Only search this product's reviews

The most helpful favorable review
The most helpful critical review


5 of 5 people found the following review helpful:
5.0 out of 5 stars A Note from the Author
I spent just under 2 years doing the research for this book. In terms of breadth of coverage, there is no better book on the market. Rather than searching Microsoft's mammoth site for articles and white papers, everything you need to understand SQL Server security from version 6.5 to 2000 is in one book.

This book also goes deeper than the basic introduction to the...

Published on April 15, 2003 by Morris L.

versus
3.0 out of 5 stars Not approriate for SQL 2005, SQL 2008, SQL 2008 R2
Since it is not apparent from the book title or the publisher's review, I just wanted to emphasize this book only covers up to SQL 2000. Looking at the publication date of this 2nd edition, it's clear that it doesn't even cover up to the last SQL 2000 service pack (4).

I worked on the SQL Security team during the SQL 2005 "Yukon" release. I can tell you...
Published 20 months ago by DTC#


Most Helpful First | Newest First

5 of 5 people found the following review helpful:
5.0 out of 5 stars A Note from the Author, April 15, 2003
By 
Morris L. (Nashville, TN United States) - See all my reviews
I spent just under 2 years doing the research for this book. In terms of breadth of coverage, there is no better book on the market. Rather than searching Microsoft's mammoth site for articles and white papers, everything you need to understand SQL Server security from version 6.5 to 2000 is in one book.

This book also goes deeper than the basic introduction to the various security mechanisms. Many books will tell you what SQL Server offers, but very few provide detailed information on *how* and *why* it works the way it does. Each chapter provides insights into the inner workings of SQL Server's security architecture and provides practical advice on how to use that information to keep your systems safe.

There are some other books that focus on showing you "hackers' tricks" for attacking your database servers, but this book takes the premise that if you do things the right way from the beginning, no hacker is ever going to find a trick that works on your systems. As an example, this book recommended configuring firewalls to block the traffic used by the Spammer virus long before the virus became news. Those who read this book and followed its advice slept soundly the weekend that Spammer was taking the Internet down.

Since the future of Curlingstone is in doubt, support for the book has moved to www.,.,..com, and the author is not only committed to maintaining the current work but also planning to release an interim update in electronic format in the fall covering changes in SQL Server 2000 Service Pack 3 and any new discoveries found since December, 2002. The author also plans to release additional chapters on Yukon early next year for early adopters. This book is alive and will be updated periodically to keep its readers safe from the bad guys.

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


2 of 2 people found the following review helpful:
5.0 out of 5 stars Excellent Security Reference, January 6, 2003
I've been working with SQL Server for 11 years and run SQL Server Central.

And I learned a bunch from this book. This is one of the best references on SQL Server Security that I have seen written and I recommend it highly to every SQL Server DBA.

The book is written to cover versions 6.5, 7.0, and 2000. And it does a great job with each. It starts by looking at the way that logins are authenticated by the server. Great detail is given, even to the point of examining network sniffer traces to show how the communication occurs between the client and server.

From there, the database security is examined with separate chapters for v6.5 and 7/2000 since they work differently. Not only is the process explained, but the author notes where there are bugs and unforseen consequences of assigning security in certain ways.

The early chapters provide insight into how security works in SQL Server. The later chapters build on this to give hints and suggestions for implementing security in your applications, DTS, replication, and even SQL Server CE.

Overall, this is a must read for SQL Server DBAs. Developers will benefit as well since a thorough understanding can solve a great many problems and prevent even more.

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


1 of 1 people found the following review helpful:
5.0 out of 5 stars Very good book, i wish there is one book for 2005, November 6, 2007
Amazon Verified Purchase(What's this?)
It is good book for 6.5, 7.0 and 2000. But it does not cover 2005 i think manily because it is old publication.

Still reading some more chapter, after that i will review my review!
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


1 of 1 people found the following review helpful:
4.0 out of 5 stars Good book, but nothing extraordinary, November 4, 2003
Amazon Verified Purchase(What's this?)
This is a good book on security and covers most of the SQL security issues. It even goes in depth in describing the SQL security at the network layer. But if you already know that you should use Windows authentication, not use SA or other SQL accounts, stay away from port 1433, and regularly update SQL security patches, then you probably won't benefit substantially by reading this book. Nevertheless, it provides a comprehensive review of the SQL security.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


1 of 1 people found the following review helpful:
4.0 out of 5 stars Distilled - To separate or extract the essential elements of, January 6, 2003
A good definition for exactly what this book does. It breaks down every segment of the SQL Server security infrastructure in intricate detail so security professionals and DBAs alike can make the right decisions. The books is a good fit for anyone who must support multiple SQL Server versions (including SQL 6.5/7/2000 and CE) in almost every conceivable scenario including replicated deployments.

Noticably absent were any discussions of the security implications of MSDE or a detailed guide to setting up SSL on SQL Server. That said, the information in this book is absolutely vital to anyone who needs to get up to date on SQL Server security and doesn't have time to sort through Books Online, White Papers, and assorted websites on the subject.

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


1 of 1 people found the following review helpful:
5.0 out of 5 stars SQL Administrator - Beware!, January 6, 2003
By 
"imatest" (Mpls, MN United States) - See all my reviews
SQL Server Administrators need to beware because this book gives up the goods to any who read it. Morris Lewis does a great job of not only explaining how SQL Server implements Security and the weaknesses from mis-configuring the server, but also how to close those holes. With in-depth coverage of the topic and hands on examples you learn how to secure your database and server from likely hack attacks.

The book is well written, explains the subject matter well, and is very high on my list of suggested reading.

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


3.0 out of 5 stars Not approriate for SQL 2005, SQL 2008, SQL 2008 R2, May 31, 2010
Since it is not apparent from the book title or the publisher's review, I just wanted to emphasize this book only covers up to SQL 2000. Looking at the publication date of this 2nd edition, it's clear that it doesn't even cover up to the last SQL 2000 service pack (4).

I worked on the SQL Security team during the SQL 2005 "Yukon" release. I can tell you there is really a lot of new material (entirely new hierarchical permissions model, certificate and key management, catalog security, transparent data encryption, etc.). While this may be a fine book, I just wanted to warn you that if you're working with SQL 2005, SQL 2008, SQL 2008 R2 you need to get a more up-to-date source.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


5.0 out of 5 stars A holistic approach to security, April 18, 2004
By 
Joe Webb (Brentwood, TN USA) - See all my reviews
This review is from: SQL Server Security Distilled (Paperback)
If you are responsible for a SQL Server database, can you afford not to think about security? Of course not. And this book definitely puts you on the right track. It offers a great great and encompassing view of the issues we as IT professionals face when it comes to SQL Server Security. It's not the same old best practices, rather it explains the why's behind the how's.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


Most Helpful First | Newest First

This product

SQL Server Security Distilled
SQL Server Security Distilled by Morris Lewis (Paperback - July 1, 2003)
Used & New from: $0.01
Add to wishlist See buying options