Microsoft SQL Server
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
 
User Name:
Password:
Remember me
Go Back   ASP Free ForumsDatabaseMicrosoft SQL Server

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread ASP Free Forums Sponsor:
  #1  
Old December 29th, 2004, 04:42 AM
lmaximo lmaximo is offline
Registered User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 4 lmaximo User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Red face ASP Connection with SQL 2000

Hi to all and sorry for my english.

I'm newbie in sql world.

I have installed SQL 2000 in Windows 2003 Server, i have create a simple database "testdb", a sample table "testtable" and populate it with some row.

After i have made an aspx page in a different Windows 2003 IIS server with this string connection:

MyConnection = New SqlConnection("server=nameofsqlserver;database=testdb;UID=sa;pwd= mysastrongpassword")

and all work fine (i can view a table with all record).

This is my question. Is correct to use SA account in aspx page? I think is not a "safety" solution!
If the answer is "no", which the correct and secure solution?

Thanks in advanced for any help and best regards.

Reply With Quote
  #2  
Old December 29th, 2004, 05:25 PM
Doug G Doug G is offline
Grumpier Old Moderator
ASP Free God 11th Plane (10000 - 10499 posts)
 
Join Date: Sep 2003
Posts: 10,143 Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 3 Weeks 4 Days 23 h 19 m 36 sec
Reputation Power: 181
Quote:
This is my question. Is correct to use SA account in aspx page? I think is not a "safety" solution!
If the answer is "no", which the correct and secure solution?

Use another sql user with only privileges you want to allow.
__________________
======
Doug G
======
I didn't attend the funeral, but I sent a nice letter saying I approved of it. --Mark Twain

Reply With Quote
  #3  
Old December 30th, 2004, 02:52 AM
lmaximo lmaximo is offline
Registered User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 4 lmaximo User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Red face

Quote:
Originally Posted by Doug G
Use another sql user with only privileges you want to allow.
Thanks Doug G,

but how i can create this new user and how i can assigne specified privileges?

I have tried to make this but without valid result.

Best regards.

Reply With Quote
  #4  
Old December 30th, 2004, 03:48 AM
nofriends's Avatar
nofriends nofriends is offline
Senior Water Wizard
ASP Free God 11th Plane (10000 - 10499 posts)
 
Join Date: Aug 2004
Location: Cape Town, RSA
Posts: 10,186 nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)  Folding Points: 106940 Folding Title: Super Ultimate Folder - Level 1Folding Points: 106940 Folding Title: Super Ultimate Folder - Level 1Folding Points: 106940 Folding Title: Super Ultimate Folder - Level 1Folding Points: 106940 Folding Title: Super Ultimate Folder - Level 1Folding Points: 106940 Folding Title: Super Ultimate Folder - Level 1Folding Points: 106940 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Months 2 Weeks 2 Days 7 h 36 m 24 sec
Reputation Power: 699
hi,

open your enterprise manager, goto your database, then Security, then Logins.

Right Click and select new Login.

under the general tab, enter a login name and choose sql Server Authentication, and type in a good pw, then goto the ServerRoles, and Database Access tabs, and select the databases and roles for this new user.

Good luck!

Reply With Quote
  #5  
Old December 30th, 2004, 04:02 AM
lmaximo lmaximo is offline
Registered User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 4 lmaximo User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Question

Quote:
Originally Posted by nofriends
then goto the ServerRoles, and Database Access tabs, and select the databases and roles for this new user.
Hi, nofriends

This is my problem!
Which are the correct roles?
Are dipendent from the action made in the aspx page?
Which correct if the aspx page read only the table and which correct if the aspx need to write to the table?

Thanks for this help.

Reply With Quote
  #6  
Old December 30th, 2004, 04:06 AM
nofriends's Avatar
nofriends nofriends is offline
Senior Water Wizard
ASP Free God 11th Plane (10000 - 10499 posts)
 
Join Date: Aug 2004
Location: Cape Town, RSA
Posts: 10,186 nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)nofriends User rank is Brigadier General (60000 - 70000 Reputation Level)  Folding Points: 106940 Folding Title: Super Ultimate Folder - Level 1Folding Points: 106940 Folding Title: Super Ultimate Folder - Level 1Folding Points: 106940 Folding Title: Super Ultimate Folder - Level 1Folding Points: 106940 Folding Title: Super Ultimate Folder - Level 1Folding Points: 106940 Folding Title: Super Ultimate Folder - Level 1Folding Points: 106940 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Months 2 Weeks 2 Days 7 h 36 m 24 sec
Reputation Power: 699
Hi,

if you only want the user to read records then use the "db_datareader", and if you want the user to write to the database
then use "db_datawriter".

Hope this helps.

Reply With Quote
  #7  
Old December 30th, 2004, 09:15 AM
lmaximo lmaximo is offline
Registered User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 4 lmaximo User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Red face

Quote:
Originally Posted by nofriends
if you only want the user to read records then use the "db_datareader", and if you want the user to write to the database
then use "db_datawriter".
This is ok for Database Access Page, but for the server role?
I can leave any check box clear?

Thanks another time.

Reply With Quote
Reply

Viewing: ASP Free ForumsDatabaseMicrosoft SQL Server > ASP Connection with SQL 2000


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 4 hosted by Hostway
Stay green...Green IT