Product Reviews

AppDetective for SQL Server

Exposing holes in your SQL security

AppDetective is a new security auditing tool that actually covers a variety of servers, including Oracle and Lotus Domino as well as SQL Server, with more editions planned for the future. I took a look at the SQL Server version, testing it with some SQL Server databases on my network—one "out of the box" and one that I thought was pretty well up to date.

Using AppDetective is a three-step process. First, you scan your network, looking for servers using the target software. Second, you can run "Pen Tests" against any server. A Pen Test (or penetration test) is a test that doesn't use any special knowledge about the server; it just looks for problems that can be found from outside. Third, you can run audits, which require a valid login for the server. An audit can check for problems such as easy-to-crack passwords and buffer overflows.

Well, it turns out that even my "up to date" server had problems—there's a Microsoft hot fix that I'd missed installing. And the out of the box server was, of course, a security disaster waiting to happen. AppDetective made short work of even comprehensive scans against these servers, coming back with results in a matter of minutes.

You can download a functioning evaluation copy from the Application Security web site. If you choose to purchase, you also get access to periodic updates so that it can continue to monitor your network for the latest vulnerabilities.

About the Author

Mike Gunderloy, MCSE, MCSD, MCDBA, is a former MCP columnist and the author of numerous development books.

comments powered by Disqus

Reader Comments:

Wed, Sep 24, 2003 Anonymous Anonymous

Works as stated!

Tue, Jan 28, 2003 Amanda from New York

Great tool! Timely update mechanism helped us find out if we were vulnerable to the SQL Slammer/Sapphire Worm.

Thu, Aug 15, 2002 Adriana Negrila Romania

it's an excellent tool !!!

Fri, May 3, 2002 robert chen Anonymous

this product help locate potential holes in our dbs. but what i like most is that they also support sybase and oracle. this provided nice coverage for us.

Fri, May 3, 2002 Adam Boston

very impressed with the products. some interesting groupware products as well (notes, domino, exchange) that are definitely worth checking out. saved me significant time/money locking down my databases. i was actually surprised at the number of holes on what I thought were pretty hardened databases. Liked autodiscovery feature, comprehensive pen testing; reports were to the point, easy to pass on to less technical VP. automatic updating saves me a lot of time on an ongoing basis.

Fri, May 3, 2002 John Brooks MLE

cool tool, great support, didn't like that I had to keep reinstalling for latest stuff with previous versions, but now they have an updater!

Fri, May 3, 2002 Jim Ray Pennsylvania

On top of a great product, greatest tech support I've seen in a while. They'll get back to you within a few hours of your email. Or you can call them and they'll talk to you then and there usually.

Fri, May 3, 2002 jennifer newman

Great product - saved my lots of time securing my network!

Add Your Comment Now:

Your Name:(optional)
Your Email:(optional)
Your Location:(optional)
Please type the letters/numbers you see above

Redmond Tech Watch

Sign up for our newsletter.

I agree to this site's Privacy Policy.