Groups | Search | Server Info | Login | Register


Groups > comp.databases.ms-sqlserver > #2264

Re: Determine what password is used during a login attempt

From Anton Shepelev <anton.txt@g{oogle}mail.com>
Newsgroups comp.databases.ms-sqlserver
Subject Re: Determine what password is used during a login attempt
Date 2025-03-06 13:35 +0300
Organization A noiseless patient Spider
Message-ID <20250306133518.75149761831624191f3d21bd@g{oogle}mail.com> (permalink)
References <20250305142848.fc47cf2469d2b8e8a1b6675d@g{oogle}mail.com> <XnsB299CAB9E3DDFYazorman@127.0.0.1>

Show all headers | View raw


Erland Sommarskog to Anton Shepelev:

> > Hello, all
>
> Yeah "all", it's soooo crowded here. :-)

According to the statistics, it is quite crowded -- 100% of
questions in this newsgroup receive a meaningful answer from
an MSSQL expert.  How many forums can boast of that?

You could mention this group in the SQL section of your
website, or in your contacts, to remind the readers that
Usenet lives on.

> > Is it possible determine the password it tries to use,
> > if we have full admin access to that database (and the
> > entire server) under the 'sa' user?
>
> No. It's an encrypted hash. If it was reversible that
> would be a major security issue.

So, only password hashes are sent from client to server?
Makes sense.

I had a withering weak hope, however, that a complete
administrator access to the server would let me do something
about it.  We all wish security were weaker when dealing
with the aftermath of bugs or poor work discipline, and wish
it were stronger every time our system was hacked and
encrypted by ransomware.

-- 
()  ascii ribbon campaign -- against html e-mail
/\  www.asciiribbon.org   -- against proprietary attachments

Back to comp.databases.ms-sqlserver | Previous | NextPrevious in thread | Find similar


Thread

Determine what password is used during a login attempt Anton Shepelev <anton.txt@g{oogle}mail.com> - 2025-03-05 14:28 +0300
  Re: Determine what password is used during a login attempt Erland Sommarskog <esquel@sommarskog.se> - 2025-03-05 19:55 +0100
    Re: Determine what password is used during a login attempt Anton Shepelev <anton.txt@g{oogle}mail.com> - 2025-03-06 13:35 +0300

csiph-web