Microsoft SQL密码弱加密漏洞

漏洞信息详情

Microsoft SQL密码弱加密漏洞

漏洞简介

Microsoft SQL 7.0存在漏洞,企业管理员在注册时,如果\”Always prompt for login name and password\” 选项没有设置,就可以使用一个弱强度的用户名和密码登陆。

漏洞公告

Microsoft suggests using Windows Integrated Security. In this mode, SQL user access is tied to Windows user accounts, and no seperate IDs are created. In addition, selecting the option ‘Always prompt for login name and password’ will prevent passwords from being written to the registry.

参考网址

来源: BID
名称: 1055
链接:http://www.securityfocus.com/bid/1055

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享