I just saw this bit today on SearchSecurity.com about admins not patching database servers. So, it’s not just me that sees ignorance in action when it comes to admins not wanting to patch their database servers. I can’t tell you how many times I’ve found database flaws directly-exploitable from the inside all because an admin didn’t want to patch the system. I’m talking about full command prompt access to database servers in a matter of minutes using nothing but free tools. You can’t tell me everyone on the network can be trusted!
I wrote an article about this VERY thing for SearchSQLServer.com…Like to hear it, here it go:
SQL Server patch pros and cons
Wow…it doesn’t much more bury-your-head-in-the-sand ridiculous than this. Oh wait, why am I complaining! This is the kind of stuff that keeps me employed. 🙂
“A business associate referred our company to Principle Logic when we were seeking a resource to perform vulnerability /penetration testing for our external and internal networks. We found Kevin Beaver to be professional, well informed, and easy to work with. His testing did not disrupt our networks, and his progress updates were timely.
His final report was very thorough and included security recommendations for our network environment. The executive leadership was so impressed with Kevin’s security expertise, they have extended their agreement to continue to perform periodic testing. We highly recommend Kevin Beaver and Principle Logic as a resource for network security testing.”