Microsoft SQL Server
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
User Name:
Password:
Remember me
Go Back   ASP Free ForumsDatabaseMicrosoft SQL Server

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread ASP Free Forums Sponsor:
  #1  
Old December 29th, 2004, 03:42 AM
lmaximo lmaximo is offline
Registered User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 4 lmaximo User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Red face ASP Connection with SQL 2000

Hi to all and sorry for my english.

I'm newbie in sql world.

I have installed SQL 2000 in Windows 2003 Server, i have create a simple database "testdb", a sample table "testtable" and populate it with some row.

After i have made an aspx page in a different Windows 2003 IIS server with this string connection:

MyConnection = New SqlConnection("server=nameofsqlserver;database=testdb;UID=sa;pwd= mysastrongpassword")

and all work fine (i can view a table with all record).

This is my question. Is correct to use SA account in aspx page? I think is not a "safety" solution!
If the answer is "no", which the correct and secure solution?

Thanks in advanced for any help and best regards.

Reply With Quote
  #2  
Old December 29th, 2004, 04:25 PM
Doug G Doug G is offline
Grumpier Old Moderator
ASP Free God 11th Plane (10000 - 10499 posts)
 
Join Date: Sep 2003
Posts: 10,143 Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 3 Weeks 5 Days 9 h 16 m 25 sec
Reputation Power: 182
Quote:
This is my question. Is correct to use SA account in aspx page? I think is not a "safety" solution!
If the answer is "no", which the correct and secure solution?

Use another sql user with only privileges you want to allow.
__________________
======
Doug G
======
I didn't attend the funeral, but I sent a nice letter saying I approved of it. --Mark Twain

Reply With Quote
  #3  
Old December 30th, 2004, 01:52 AM
lmaximo lmaximo is offline
Registered User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 4 lmaximo User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Red face

Quote:
Originally Posted by Doug G
Use another sql user with only privileges you want to allow.
Thanks Doug G,

but how i can create this new user and how i can assigne specified privileges?

I have tried to make this but without valid result.

Best regards.

Reply With Quote
  #4  
Old December 30th, 2004, 02:48 AM
nofriends's Avatar
nofriends nofriends is offline
Senior Water Wizard
ASP Free God 11th Plane (10000 - 10499 posts)
 
Join Date: Aug 2004
Location: Cape Town, RSA
Posts: 10,203 nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)  Folding Points: 189791 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189791 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189791 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189791 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189791 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189791 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Months 2 Weeks 2 Days 8 h 44 m 57 sec
Reputation Power: 767
hi,

open your enterprise manager, goto your database, then Security, then Logins.

Right Click and select new Login.

under the general tab, enter a login name and choose sql Server Authentication, and type in a good pw, then goto the ServerRoles, and Database Access tabs, and select the databases and roles for this new user.

Good luck!

Reply With Quote
  #5  
Old December 30th, 2004, 03:02 AM
lmaximo lmaximo is offline
Registered User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 4 lmaximo User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Question

Quote:
Originally Posted by nofriends
then goto the ServerRoles, and Database Access tabs, and select the databases and roles for this new user.
Hi, nofriends

This is my problem!
Which are the correct roles?
Are dipendent from the action made in the aspx page?
Which correct if the aspx page read only the table and which correct if the aspx need to write to the table?

Thanks for this help.

Reply With Quote
  #6  
Old December 30th, 2004, 03:06 AM
nofriends's Avatar
nofriends nofriends is offline
Senior Water Wizard
ASP Free God 11th Plane (10000 - 10499 posts)
 
Join Date: Aug 2004
Location: Cape Town, RSA
Posts: 10,203 nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)nofriends User rank is Major General (70000 - 90000 Reputation Level)  Folding Points: 189791 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189791 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189791 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189791 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189791 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189791 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Months 2 Weeks 2 Days 8 h 44 m 57 sec
Reputation Power: 767
Hi,

if you only want the user to read records then use the "db_datareader", and if you want the user to write to the database
then use "db_datawriter".

Hope this helps.

Reply With Quote
  #7  
Old December 30th, 2004, 08:15 AM
lmaximo lmaximo is offline
Registered User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 4 lmaximo User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Red face

Quote:
Originally Posted by nofriends
if you only want the user to read records then use the "db_datareader", and if you want the user to write to the database
then use "db_datawriter".
This is ok for Database Access Page, but for the server role?
I can leave any check box clear?

Thanks another time.

Reply With Quote
Reply

Viewing: ASP Free ForumsDatabaseMicrosoft SQL Server > ASP Connection with SQL 2000


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump





 Free IT White Papers!
 
Create the Optimal Architecture for your Critical Applications
Warburton's the largest independently owned bakery in the UK faced a number of difficult challenges in providing the most robust yet efficient IT infrastructure for their organization's success. IBM's services combined with their xSeries servers created the perfect platform for their SAP environment with sufficient flexibility, and did so in very time effective fashion.

 
Five Best Practices for Deploying a Successful Service-Oriented Architecture
This white paper describes the benefits you can expect with SOA, and how IBM can help take your business there.

 
Gartner Magic Quadrant for Application Delivery Controllers
Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses of solutions, and provides Magic Quadrant reporting for a quick comparison across all vendors. Learn from Gartner how you can benefit from an all-in-one device like Citrix NetScaler that delivers the highest levels of availability, performance and security.

 
Knowledge is Power
What you don't know can hurt you, and is likely costing you money and increasing your security risks during an era of scarce resources. This white paper proposes six key strategies that enterprise security managers can use to improve their network defense posture.

 
Rationalizing the Multi-Tool Environment
The rationalized multi-tool approach is flexible, scalable and cost effective. It provides the necessary input to the IT service management business processes. It preserves prior investments in monitoring tools, empowers technologists to select the best tools with which to do their jobs, and enhances effective response to incidents.

 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2010 by Developer Shed. All rights reserved. DS Cluster 2 Hosted by Hostway
For more Enterprise Application Development news, visit eWeek