The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin MS02-035: SQL Server Installation Process May Leave Passwords on System (Q263968)
Time: 03:52 EST/08:52 GMT | News Source: Microsoft TechNet Security | Posted By: Matthew Sabean

When installing SQL Server 7.0 (including MSDE 1.0), SQL Server 2000, or a service pack for SQL Server 7.0 or SQL Server 2000, the information provided for the install process is collected and stored in a setup file called setup.iss. The setup.iss file can then be used to automate the installation of additional SQL Server systems. SQL Server 2000 also includes the ability to record an unattended install to the setup.iss file without having to actually perform an installation. The administrator setting up the SQL Server can supply a password to the installation routine under the following circumstances:
- If the SQL Server is being set up in "Mixed Mode", a password for the SQL Server administrator (the "sa" account) must be supplied.
- Whether in Mixed Mode or Windows Authentication Mode, a User ID and password can optionally be supplied for the purpose of starting up SQL Server service accounts.

In either case, the password would be stored in the setup.iss file. Prior to SQL Server 7.0 Service Pack 4, the passwords were stored in clear text. For SQL Server 7.0 Service Pack 4 and SQL Server 2000 Service Packs 1 and 2, the passwords are encrypted and then stored. Additionally, a log file is created during the installation process that shows the results of the installation. The log file would also include any passwords that had been stored in the setup.iss file.
A security vulnerability results because of two factors:
- The files remain on the server after the installation is complete. Except for the setup.iss file created by SQL Server 2000, the files are in directories that can be accessed by anyone who can interactively log on to the system.
- The password information stored in the files is either in clear text (for SQL Server 7.0 prior to Service Pack 4) or encrypted using fairly weak protection. An attacker who recovered the files could subject them to a password cracking attack to learn the passwords, potentially compromising the sa password and/or a domain account password.

Download locations for this patch The KillPwd utility can be obtained at the following location:
Microsoft SQL 7, MSDE 1.0, and Microsoft SQL Server 2000:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=40205

Write Comment
Return to News

  Displaying 751 through 763 of 763
Prev | First
  The time now is 2:00:34 PM ET.
Any comment problems? E-mail us
#751 By 4240821 (82.115.4.100) at 1/2/2026 9:09:39 AM
https://www.pillowfort.social/posts/6554247
https://www.pillowfort.social/posts/6554069
https://www.pillowfort.social/posts/6553924
https://www.pillowfort.social/posts/6553841
https://www.pillowfort.social/posts/6553753
https://www.pillowfort.social/posts/6553681
https://www.pillowfort.social/posts/6553613
https://www.pillowfort.social/posts/6553526
https://www.pillowfort.social/posts/6553408
https://www.pillowfort.social/posts/6553278

#752 By 4240821 (82.115.4.100) at 1/4/2026 1:45:48 AM
https://www.pillowfort.social/posts/6985400
https://www.pillowfort.social/posts/6985346
https://www.pillowfort.social/posts/6985257
https://www.pillowfort.social/posts/6985196
https://www.pillowfort.social/posts/6985089
https://www.pillowfort.social/posts/6984976
https://www.pillowfort.social/posts/6984906
https://www.pillowfort.social/posts/6984867
https://www.pillowfort.social/posts/6984760
https://www.pillowfort.social/posts/6984681

#753 By 4240821 (82.115.4.100) at 1/4/2026 9:31:56 AM
https://www.pillowfort.social/posts/6893621
https://www.pillowfort.social/posts/6893449
https://www.pillowfort.social/posts/6893352
https://www.pillowfort.social/posts/6893270
https://www.pillowfort.social/posts/6893101
https://www.pillowfort.social/posts/6893015
https://www.pillowfort.social/posts/6892955
https://www.pillowfort.social/posts/6892895
https://www.pillowfort.social/posts/6892823
https://www.pillowfort.social/posts/6892689

#754 By 4240821 (82.115.4.100) at 1/5/2026 2:56:54 PM
https://www.pillowfort.social/posts/6690263
https://www.pillowfort.social/posts/6690078
https://www.pillowfort.social/posts/6689906
https://www.pillowfort.social/posts/6689716
https://www.pillowfort.social/posts/6689536
https://www.pillowfort.social/posts/6689457
https://www.pillowfort.social/posts/6689393
https://www.pillowfort.social/posts/6689297
https://www.pillowfort.social/posts/6689160
https://www.pillowfort.social/posts/6689108

#755 By 4240821 (82.115.4.100) at 1/6/2026 5:57:35 AM
https://www.pillowfort.social/posts/6757669
https://www.pillowfort.social/posts/6757441
https://www.pillowfort.social/posts/6757182
https://www.pillowfort.social/posts/6757012
https://www.pillowfort.social/posts/6756863
https://www.pillowfort.social/posts/6756641
https://www.pillowfort.social/posts/6756508
https://www.pillowfort.social/posts/6756235
https://www.pillowfort.social/posts/6756065
https://www.pillowfort.social/posts/6756010

#756 By 4240821 (82.115.4.100) at 1/6/2026 7:24:37 AM
https://www.pillowfort.social/posts/6906005
https://www.pillowfort.social/posts/6905946
https://www.pillowfort.social/posts/6905835
https://www.pillowfort.social/posts/6905725
https://www.pillowfort.social/posts/6905674
https://www.pillowfort.social/posts/6905627
https://www.pillowfort.social/posts/6905512
https://www.pillowfort.social/posts/6905449
https://www.pillowfort.social/posts/6905336
https://www.pillowfort.social/posts/6905262

#757 By 4240821 (82.115.4.100) at 1/6/2026 11:10:15 AM
https://www.pillowfort.social/posts/6678434
https://www.pillowfort.social/posts/6678303
https://www.pillowfort.social/posts/6678181
https://www.pillowfort.social/posts/6677750
https://www.pillowfort.social/posts/6677403
https://www.pillowfort.social/posts/6677322
https://www.pillowfort.social/posts/6676807
https://www.pillowfort.social/posts/6676620
https://www.pillowfort.social/posts/6676402
https://www.pillowfort.social/posts/6676237

#758 By 4240821 (82.115.4.100) at 1/7/2026 12:29:55 AM
https://www.pillowfort.social/posts/6689108
https://www.pillowfort.social/posts/6689015
https://www.pillowfort.social/posts/6688921
https://www.pillowfort.social/posts/6688839
https://www.pillowfort.social/posts/6688675
https://www.pillowfort.social/posts/6688560
https://www.pillowfort.social/posts/6688473
https://www.pillowfort.social/posts/6688383
https://www.pillowfort.social/posts/6688276
https://www.pillowfort.social/posts/6688184

#759 By 4240821 (82.115.4.100) at 1/7/2026 1:49:14 AM
https://www.pillowfort.social/posts/6779651
https://www.pillowfort.social/posts/6779265
https://www.pillowfort.social/posts/6779090
https://www.pillowfort.social/posts/6779038
https://www.pillowfort.social/posts/6778954
https://www.pillowfort.social/posts/6778753
https://www.pillowfort.social/posts/6777854
https://www.pillowfort.social/posts/6777694
https://www.pillowfort.social/posts/6777424
https://www.pillowfort.social/posts/6777156

#760 By 4240821 (82.115.4.100) at 1/7/2026 10:08:23 PM
https://www.pillowfort.social/posts/7089318
https://www.pillowfort.social/posts/7089134
https://www.pillowfort.social/posts/7088938
https://www.pillowfort.social/posts/7088854
https://www.pillowfort.social/posts/7088806
https://www.pillowfort.social/posts/7088719
https://www.pillowfort.social/posts/7088654
https://www.pillowfort.social/posts/7088581
https://www.pillowfort.social/posts/7088511
https://www.pillowfort.social/posts/7088429

#761 By 4240821 (82.115.4.100) at 1/9/2026 3:43:49 PM
https://www.pillowfort.social/posts/6532887
https://www.pillowfort.social/posts/6532811
https://www.pillowfort.social/posts/6532680
https://www.pillowfort.social/posts/6532547
https://www.pillowfort.social/posts/6532448
https://www.pillowfort.social/posts/6532259
https://www.pillowfort.social/posts/6532022
https://www.pillowfort.social/posts/6531850
https://www.pillowfort.social/posts/6531686
https://www.pillowfort.social/posts/6531529

#762 By 4240821 (82.115.4.100) at 1/10/2026 12:47:07 AM
https://www.pillowfort.social/posts/6617780
https://www.pillowfort.social/posts/6617645
https://www.pillowfort.social/posts/6617474
https://www.pillowfort.social/posts/6617114
https://www.pillowfort.social/posts/6616864
https://www.pillowfort.social/posts/6616769
https://www.pillowfort.social/posts/6616355
https://www.pillowfort.social/posts/6616136
https://www.pillowfort.social/posts/6615938
https://www.pillowfort.social/posts/6615786

#763 By 4240821 (82.115.4.100) at 1/10/2026 10:27:25 AM
https://www.pillowfort.social/posts/6441055
https://www.pillowfort.social/posts/6440937
https://www.pillowfort.social/posts/6440796
https://www.pillowfort.social/posts/6440707
https://www.pillowfort.social/posts/6440399
https://www.pillowfort.social/posts/6440359
https://www.pillowfort.social/posts/6440301
https://www.pillowfort.social/posts/6440215
https://www.pillowfort.social/posts/6440119
https://www.pillowfort.social/posts/6439967

Write Comment
Return to News
  Displaying 751 through 763 of 763
Prev | First
  The time now is 2:00:34 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *