Editorials

U.N. Site Hacked with SQL Server Injection…

Webcast Tomorrow – Register Now
Day 30 as DBA
This follow-on to the Day 1 as DBA show will go into the things you can do now that you’re semi-established in your routines. Daily maintenance, auditing, security checks, best practices and more. There is a lot to consider and think about when you’re putting a good foundation in place for your systems, we’ll cover check point items here and keep you up to speed on "what’s next."

> Register Now to save your spot
> Webcast date: 8/14/2007 12:00pm Noon Pacific

Watch the Latest SQL Server Weekly Show
We posted the latest show on Friday – have you seen it yet? Lots of great information about SQL Server, upcoming events, the 60 second SQL Server tip of the day and much more.

> Watch the show here.

Featured Article(s)
Prioritize your Work Load (Finding Low Hanging Fruit)
Have you heard management talking about low hanging fruit? Do you know what they are talking about, and how to find yours?

Looking to Build a Data Warehouse with Axapta and Navision?
Looking to do it quickly and fully integrate Analysis Services? You might be thinking that this is a project for the ages – that it’s going to take a huge effort and significant resources. Fortunately, you can have it up and running within a week – check out the PrecisionPoint Business Warehouse – you’ll be amazed at what you can do with the self-generating, self-maintaining SQL Server Business Warehouse. Get more information here.

Yikes… the UN Falls Subject to SQL Injection of the Most Simple Kind…
The U.N.’s website fell prey to hackers using SQL injection and it’s been widely reported that the vulnerability may still even exist, though they’ve corrected the text on the home page appropriately. If you’re not familiar with the whole concept and prevention of SQL injection, and you’re building applications, you need to become aware of it, understand it and prevent it in your work.

Essentially, SQL injection let’s someone else work with your database and do just about anything they please. "Injection" refers to the process of playing on SQL Server’s expectation of certain statement elements (like single quotes, language constructs, etc.) and the fact that, if you allow people to enter information to be stored, queried or otherwise sent to SQL Server, and you’re doing so by building a statement using their input directly, you’re opening yourself up to all sorts of issues.

If you’d like to read more about the U.N. hack, click here. To learn more about SQL Injection and mitigating it’s effectiveness, click here.

New OFFICEtv Show Posted
Check out the latest OFFICEtv Show here, with information about everything from macros to Access to Excel and more.
> Watch Now

Featured White Paper(s)
ESG Lab Validation Report of the HP PolyServe Database Utility for SQL Server
ESG Lab, the testing facility of industry analyst firm Enterprise Strategy Group, reports its comprehensive testing of HP’s s… (read more)

Enterprise Data Management.. Strategies to Increase Business Effectiveness
As the amount of information you collect expands and the number of recorded data transactions grow, your ability to manage ap… (read more)

Transforming Enterprise Backups: How Using a Third-Party Tool Can Improve Backup Strategies
The backup and restore facilities in native SQL Server are robust, and once a backup routine is established, the DBA needs to… (read more)