| Legend | ||||||||||||||||
|
||||||||||||||||
1. Blank sa Password
2. Default Login
3. DTS password table publicly viewable
4. Guest Account
5. Integrated Logins
6. Login mode
7. Mismatched User IDs
8. Orphaned User IDs
9. SQL Agent password publically viewable
10. SQLServerAgent password in registry
11. SQLServerAgent password in secure registry key
12. Access to CmdExec and Active Scripting job
13. Agent job privilege escalation
14. Allow Remote Access
15. Allow Updates to System Tables
16. BUILTIN/Administrators not removed
17. Case-insensitive sort order
18. Extended Stored Procedures
19. JET running in sandbox mode
20. Logins with default Database as master
21. Ole Automation Procedure Permission
22. Permission on sp_readwebtask
23. Permission on sp_runwebtask
24. Permission on stored procedures in msdb
25. Permission to select from syslogins
26. Permissions given to each Role
27. Permissions granted directly to user
28. Permissions on DTS Package
29. Permissions on sp_MSsetalertinfo
30. Permissions on sp_MSSetServerProperties
31. Permissions on system tables
32. Permissions on sysxlogins table
33. Permissions on xp_cmdshell
34. Permissions on xp_sprintf
35. Public can create Agent jobs
36. Sample database not removed
37. Scan for Startup Procedures
38. Scheduled jobs
39. SQL Agent procedures granted to public
40. SQL Mail procedure permissions
41. Startup Stored Procedures
42. Statement Permissions
43. Temporary Stored Procedures
44. Unauthorised Object Owners
45. User present in Database creator Role
46. User-defined Roles and Users
47. Users in this database
48. Users present in Diskadmin Role
49. Users present in Processadmin Role
50. Users present in securityadmin Role
51. Users present in Serveradmin Role
52. Users present in Setupadmin Role
53. Users present in sysadmin Role
54. WITH GRANT Options
55. Audit Trail Location
56. Auditing level
57. Auditing of Security Events
58. BlackBox Trace
59. c2 Audit mode
60. Database Backup Files
61. Database Backups
62. Force SSL Encryption
63. MS SQL Server Service Packs
64. Number of Error Logs
65. Registry Procedure Permissions
66. Server Account
67. SQL Mail
68. SQL Server in Cluster Mode
69. SQL Server Protocols listening for
70. Trace File Roleover
71. Trace Status
72. Trace Stop Time
73. Vulnerability Checks
74. Windows NT Service Packs
| Authentication/Password Control |
| Check : Blank sa Password | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Default Login | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : DTS password table publicly viewable | ||||||||||||||||||||||||||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||||||||||||||||||||||||||||||
| Check : Guest Account | ||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||
| Check : Integrated Logins | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Login mode | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Mismatched User IDs | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Orphaned User IDs | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : SQL Agent password publically viewable | ||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||
| Authorization |
| Check : Access to CmdExec and Active Scripting job | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Agent job privilege escalation | ||||||||||||||||||||||||||||||||||||||
|
Description: CVE Reference No.: CAN-2002-0721
|
||||||||||||||||||||||||||||||||||||||
| Check : Allow Remote Access | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Allow Updates to System Tables | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : BUILTIN/Administrators not removed | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : JET running in sandbox mode | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Logins with default Database as master | |||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
|||||||||||
| Check : Permission on sp_readwebtask | ||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||
| Check : Permission on sp_runwebtask | ||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||
| Check : Permission on stored procedures in msdb | ||||||||||||||||||||||||||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||||||||||||||||||||||||||||||
| Check : Permission to select from syslogins | ||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||||||
| Check : Permissions given to each Role | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Permissions granted directly to user | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Permissions on sp_MSsetalertinfo | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Permissions on sp_MSSetServerProperties | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Permissions on system tables | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Check : Permissions on sysxlogins table | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Permissions on xp_cmdshell | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Permissions on xp_sprintf | ||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||
| Check : Public can create Agent jobs | ||||||||||||||||||||||||||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||||||||||||||||||||||||||||||
| Check : Sample database not removed | ||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||||||
| Check : Scan for Startup Procedures | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Scheduled jobs | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : SQL Agent procedures granted to public | ||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||
| Check : Startup Stored Procedures | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Statement Permissions | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Temporary Stored Procedures | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Unauthorised Object Owners | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : User present in Database creator Role | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : User-defined Roles and Users | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Users in this database | ||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||||
| Check : Users present in Diskadmin Role | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Users present in Processadmin Role | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Users present in securityadmin Role | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| < |