VID |
27112 |
Severity |
30 |
Port |
135 |
Protocol |
TCP |
Class |
DB |
Detailed Description |
The MS SQL server does not have password protection.
* Platforms Affected: Microsoft SQL Server |
Recommendation |
* Windows [Administrative Tools/ Local Security Policy (secpol.msc)], and then click [Account Policies]/ [Account Lockout Policy] Ensure that the Account Lockout Threshold is set to 5 or less, make sure Account Lockout Period is set to 30 or higher
* MSSQL [SQL Server Management Studio/ Connect to Diagnostic Server/ Account Properties]. Check [Force password policy] |
Related URL |
(CVE) |
Related URL |
(SecurityFocus) |
Related URL |
(ISS) |
|