WebApp Sec mailing list archives

RE: MS SQL Inter-database query question


From: "Michael Howard" <mikehow () microsoft com>
Date: Sun, 14 Mar 2004 22:28:06 -0800

Use sockets, and no other protocol - and use SSL. 

Cheers, Michael

[Writing Secure Code 2nd Edition]
http://www.microsoft.com/mspress/books/5957.asp
[Protect Your PC] http://www.microsoft.com/protect
[Blog] http://blogs.msdn.com/michael_howard

-----Original Message-----
From: Michael Silk [mailto:silkm () hushmail com] 
Sent: Sunday, March 14, 2004 3:04 PM
To: webappsec () securityfocus com; secprog () securityfocus com
Subject: MS SQL Inter-database query question

Hello ...

  Just a quick question:

  When a query is performed from one database to another
  database on the same server, does the information pass
  over a socket ? or some other system ?

  If it is a socket, is it sent such that sniffing of the 
  information is possible (i.e. sniffer on a computer in
  the same network can view data transfer) ?

  Thanks ...

-- Michael



Concerned about your privacy? Follow this link to get
FREE encrypted email: https://www.hushmail.com/?l=2

Free, ultra-private instant messaging with Hush Messenger
https://www.hushmail.com/services.php?subloc=messenger&l=434

Promote security and make money with the Hushmail Affiliate Program: 
https://www.hushmail.com/about.php?subloc=affiliate&l=427


Current thread: