Korean
<< Back
VID 27112
Severity 30
Port 135
Protocol TCP
Class DB
Detailed Description The MS SQL server does not have password protection.

* Platforms Affected:
Microsoft SQL Server
Recommendation * Windows
[Administrative Tools/ Local Security Policy (secpol.msc)], and then click [Account Policies]/ [Account Lockout Policy]
Ensure that the Account Lockout Threshold is set to 5 or less, make sure Account Lockout Period is set to 30 or higher

* MSSQL
[SQL Server Management Studio/ Connect to Diagnostic Server/ Account Properties].
Check [Force password policy]
Related URL (CVE)
Related URL (SecurityFocus)
Related URL (ISS)