You can't secure what you don't acknowledge.SM

Wednesday, June 25, 2008

Ignorance is bliss when it comes to patching database servers

I just saw this bit today on about admins not patching database servers. So, it's not just me that sees ignorance in action when it comes to admins not wanting to patch their database servers. I can't tell you how many times I've found database flaws directly-exploitable from the inside all because an admin didn't want to patch the system. I'm talking about full command prompt access to database servers in a matter of minutes using nothing but free tools. You can't tell me everyone on the network can be trusted!

I wrote an article about this VERY thing for to hear it, here it go:
SQL Server patch pros and cons doesn't much more bury-your-head-in-the-sand ridiculous than this. Oh wait, why am I complaining! This is the kind of stuff that keeps me employed. :)

No comments:

Post a Comment