<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Mssql Guru's Blog</title>
	<atom:link href="http://mssqlguru.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://mssqlguru.wordpress.com</link>
	<description></description>
	<lastBuildDate>Wed, 06 May 2009 13:52:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='mssqlguru.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Mssql Guru's Blog</title>
		<link>http://mssqlguru.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://mssqlguru.wordpress.com/osd.xml" title="Mssql Guru&#039;s Blog" />
	<atom:link rel='hub' href='http://mssqlguru.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Asymmetric Keys: specify DoD PKI</title>
		<link>http://mssqlguru.wordpress.com/2009/05/05/asymmetric-keys-specify-dod-pki/</link>
		<comments>http://mssqlguru.wordpress.com/2009/05/05/asymmetric-keys-specify-dod-pki/#comments</comments>
		<pubDate>Tue, 05 May 2009 14:06:23 +0000</pubDate>
		<dc:creator>mssqlguru</dc:creator>
				<category><![CDATA[Automation: Verify]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security SQL 2000]]></category>
		<category><![CDATA[Security SQL 2005]]></category>

		<guid isPermaLink="false">http://mssqlguru.wordpress.com/?p=367</guid>
		<description><![CDATA[Asymmetric keys derived from self-signed certificates or self-generated by other means do not meet the security requirements of DoD that require validation by DoD trusted certificate authorities.....<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=mssqlguru.wordpress.com&amp;blog=7611186&amp;post=367&amp;subd=mssqlguru&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://mssqlguru.wordpress.com/2009/05/05/asymmetric-keys-specify-dod-pki/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b278d5470b0697d9308fee0680a7b295?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mssqlguru</media:title>
		</media:content>
	</item>
		<item>
		<title>Symmetric Keys: encrypting_mechanism</title>
		<link>http://mssqlguru.wordpress.com/2009/05/05/symmetric-keys-encrypting_mechanism/</link>
		<comments>http://mssqlguru.wordpress.com/2009/05/05/symmetric-keys-encrypting_mechanism/#comments</comments>
		<pubDate>Tue, 05 May 2009 14:05:36 +0000</pubDate>
		<dc:creator>mssqlguru</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security SQL 2000]]></category>
		<category><![CDATA[Security SQL 2005]]></category>

		<guid isPermaLink="false">http://mssqlguru.wordpress.com/?p=365</guid>
		<description><![CDATA[Symmetric keys are vulnerable if the symmetric key encryption is not protected from disclosure.  Symmetric keys are well protected by use of either the database or service master key.  Where.....<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=mssqlguru.wordpress.com&amp;blog=7611186&amp;post=365&amp;subd=mssqlguru&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://mssqlguru.wordpress.com/2009/05/05/symmetric-keys-encrypting_mechanism/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b278d5470b0697d9308fee0680a7b295?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mssqlguru</media:title>
		</media:content>
	</item>
		<item>
		<title>Database Master key: is_master_key_encrypted_by_Server</title>
		<link>http://mssqlguru.wordpress.com/2009/05/05/database-master-key-is_master_key_encrypted_by_server/</link>
		<comments>http://mssqlguru.wordpress.com/2009/05/05/database-master-key-is_master_key_encrypted_by_server/#comments</comments>
		<pubDate>Tue, 05 May 2009 14:05:08 +0000</pubDate>
		<dc:creator>mssqlguru</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security SQL 2000]]></category>
		<category><![CDATA[Security SQL 2005]]></category>

		<guid isPermaLink="false">http://mssqlguru.wordpress.com/?p=363</guid>
		<description><![CDATA[Protection of the Database Master Key is necessary to protect the confidentiality of sensitive data.  When encrypted by the Service Master Key, SYSADMINs may access and use the key to view sensitive data that they are not authorized to view.  Where .....<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=mssqlguru.wordpress.com&amp;blog=7611186&amp;post=363&amp;subd=mssqlguru&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://mssqlguru.wordpress.com/2009/05/05/database-master-key-is_master_key_encrypted_by_server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b278d5470b0697d9308fee0680a7b295?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mssqlguru</media:title>
		</media:content>
	</item>
		<item>
		<title>Database Master key: Access control.</title>
		<link>http://mssqlguru.wordpress.com/2009/05/05/database-master-key-access-control/</link>
		<comments>http://mssqlguru.wordpress.com/2009/05/05/database-master-key-access-control/#comments</comments>
		<pubDate>Tue, 05 May 2009 14:04:31 +0000</pubDate>
		<dc:creator>mssqlguru</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security SQL 2000]]></category>
		<category><![CDATA[Security SQL 2005]]></category>

		<guid isPermaLink="false">http://mssqlguru.wordpress.com/?p=361</guid>
		<description><![CDATA[Severity: CAT 2 Description: Unauthorized access to the database master key could jeopardize the confidentiality of sensitive data stored in the database.  Access to the database master key should be strictly assigned to a limited number of  individuals authorized to use and maintain the key. Check: From the query prompt: for each database: use &#60;database [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=mssqlguru.wordpress.com&amp;blog=7611186&amp;post=361&amp;subd=mssqlguru&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://mssqlguru.wordpress.com/2009/05/05/database-master-key-access-control/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b278d5470b0697d9308fee0680a7b295?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mssqlguru</media:title>
		</media:content>
	</item>
		<item>
		<title>Database Master key: encryption password.</title>
		<link>http://mssqlguru.wordpress.com/2009/05/05/database-master-key-encryption-password/</link>
		<comments>http://mssqlguru.wordpress.com/2009/05/05/database-master-key-encryption-password/#comments</comments>
		<pubDate>Tue, 05 May 2009 14:03:31 +0000</pubDate>
		<dc:creator>mssqlguru</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security SQL 2000]]></category>
		<category><![CDATA[Security SQL 2005]]></category>

		<guid isPermaLink="false">http://mssqlguru.wordpress.com/?p=359</guid>
		<description><![CDATA[Severity: CAT 2 Description: Weak passwords may be easily guessed.  When passwords used to encrypt keys used for encryption of sensitive data, then the confidentiality of all data encrypted using that key is at risk. Check: From the query prompt: For each database : use &#60;database name&#62; select count(name) from sys.symmetric_keys s, sys.key_encryptions k where [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=mssqlguru.wordpress.com&amp;blog=7611186&amp;post=359&amp;subd=mssqlguru&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://mssqlguru.wordpress.com/2009/05/05/database-master-key-encryption-password/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b278d5470b0697d9308fee0680a7b295?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mssqlguru</media:title>
		</media:content>
	</item>
		<item>
		<title>WITH GRANT privilege assignments</title>
		<link>http://mssqlguru.wordpress.com/2009/05/05/with-grant-privilege-assignments/</link>
		<comments>http://mssqlguru.wordpress.com/2009/05/05/with-grant-privilege-assignments/#comments</comments>
		<pubDate>Tue, 05 May 2009 14:02:58 +0000</pubDate>
		<dc:creator>mssqlguru</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security SQL 2000]]></category>
		<category><![CDATA[Security SQL 2005]]></category>

		<guid isPermaLink="false">http://mssqlguru.wordpress.com/?p=357</guid>
		<description><![CDATA[Severity: CAT 2 Description: The WITH GRANT option assigned with privileges, allows the grantee of the privilege to re-grant the privilege to other accounts.  Unauthorized or unmanaged assignment of privileges may result in a compromise of data confidentiality and database operation. Privilege assignment should be restricted to DBA, application object owner accounts, and application administration [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=mssqlguru.wordpress.com&amp;blog=7611186&amp;post=357&amp;subd=mssqlguru&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://mssqlguru.wordpress.com/2009/05/05/with-grant-privilege-assignments/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b278d5470b0697d9308fee0680a7b295?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mssqlguru</media:title>
		</media:content>
	</item>
		<item>
		<title>Application/custom stored procedure encryption</title>
		<link>http://mssqlguru.wordpress.com/2009/05/05/applicationcustom-stored-procedure-encryption/</link>
		<comments>http://mssqlguru.wordpress.com/2009/05/05/applicationcustom-stored-procedure-encryption/#comments</comments>
		<pubDate>Tue, 05 May 2009 14:02:23 +0000</pubDate>
		<dc:creator>mssqlguru</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security SQL 2000]]></category>
		<category><![CDATA[Security SQL 2005]]></category>

		<guid isPermaLink="false">http://mssqlguru.wordpress.com/?p=355</guid>
		<description><![CDATA[Severity: CAT 3 Description: Application code may contain indications of sensitive data relationships that may aid an unauthorized user in discovering methods to circumvent other access controls.  Vulnerabilities may also be discovered during an unauthorized code review that can assist a malicious user in an attack that compromises the DBMS or its data.  Application code [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=mssqlguru.wordpress.com&amp;blog=7611186&amp;post=355&amp;subd=mssqlguru&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://mssqlguru.wordpress.com/2009/05/05/applicationcustom-stored-procedure-encryption/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b278d5470b0697d9308fee0680a7b295?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mssqlguru</media:title>
		</media:content>
	</item>
		<item>
		<title>DDL permission assignments.</title>
		<link>http://mssqlguru.wordpress.com/2009/05/05/ddl-permission-assignments/</link>
		<comments>http://mssqlguru.wordpress.com/2009/05/05/ddl-permission-assignments/#comments</comments>
		<pubDate>Tue, 05 May 2009 14:01:52 +0000</pubDate>
		<dc:creator>mssqlguru</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security SQL 2000]]></category>
		<category><![CDATA[Security SQL 2005]]></category>

		<guid isPermaLink="false">http://mssqlguru.wordpress.com/?p=353</guid>
		<description><![CDATA[Severity: CAT 2 Description: Data Definition Language (DDL) commands include CREATE, ALTER, and DROP object actions.  These actions cause changes to the structure, definition, and configuration of the DBMS as well as to the objects themselves that can affect any or all operations of the database.  Such privileged actions, when not restricted to authorized persons [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=mssqlguru.wordpress.com&amp;blog=7611186&amp;post=353&amp;subd=mssqlguru&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://mssqlguru.wordpress.com/2009/05/05/ddl-permission-assignments/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b278d5470b0697d9308fee0680a7b295?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mssqlguru</media:title>
		</media:content>
	</item>
		<item>
		<title>Unauthorized object permission grants</title>
		<link>http://mssqlguru.wordpress.com/2009/05/05/unauthorized-object-permission-grants/</link>
		<comments>http://mssqlguru.wordpress.com/2009/05/05/unauthorized-object-permission-grants/#comments</comments>
		<pubDate>Tue, 05 May 2009 14:00:28 +0000</pubDate>
		<dc:creator>mssqlguru</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security SQL 2000]]></category>
		<category><![CDATA[Security SQL 2005]]></category>

		<guid isPermaLink="false">http://mssqlguru.wordpress.com/?p=351</guid>
		<description><![CDATA[Severity: CAT 2 Description: Securely designed applications require only that database application user accounts have permissions to access and manipulate only the application data assigned to them in accordance with the their job function.  Restrictions may be further restricted by granting data access to users only through execution of database procedures.  Excess privileges can lead [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=mssqlguru.wordpress.com&amp;blog=7611186&amp;post=351&amp;subd=mssqlguru&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://mssqlguru.wordpress.com/2009/05/05/unauthorized-object-permission-grants/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b278d5470b0697d9308fee0680a7b295?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mssqlguru</media:title>
		</media:content>
	</item>
		<item>
		<title>Fixed database role members</title>
		<link>http://mssqlguru.wordpress.com/2009/05/05/fixed-database-role-members/</link>
		<comments>http://mssqlguru.wordpress.com/2009/05/05/fixed-database-role-members/#comments</comments>
		<pubDate>Tue, 05 May 2009 13:58:49 +0000</pubDate>
		<dc:creator>mssqlguru</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security SQL 2000]]></category>
		<category><![CDATA[Security SQL 2005]]></category>

		<guid isPermaLink="false">http://mssqlguru.wordpress.com/?p=349</guid>
		<description><![CDATA[Severity: CAT 2 Description: Fixed database roles provide a mechanism to grant groups of privileges to users. These privilege groupings are defined by the installation or upgrade of the SQL Server software at the discretion of Microsoft. Memberships in these roles granted to users should be strictly controlled and monitored. Privileges assigned to these roles [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=mssqlguru.wordpress.com&amp;blog=7611186&amp;post=349&amp;subd=mssqlguru&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://mssqlguru.wordpress.com/2009/05/05/fixed-database-role-members/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b278d5470b0697d9308fee0680a7b295?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mssqlguru</media:title>
		</media:content>
	</item>
	</channel>
</rss>
