K. Brian Kelley - Databases, Infrastructure, and Security

IT Security, MySQL, Perl, SQL Server, and Windows technologies.

Syndication

News

Links

Browse by Tags

All Tags » Tools (RSS)
Check Authentication Scheme (Kerberos) on SQL Server 2005
I had to redo SPNs today because we swapped out service accounts on some of our non-production SQL Servers. I wanted to verify that connections in bound were being made with Kerberos. If you've ever dealt with this, if the SPNs are wrong you usually...

Posted 07 August 2008 13:02 by bkelley | with no comments

Nmap 4.68 Available
The network scanner Nmap has a new version out, 4.68. The GUI interface (Zenmap) which comes with the Windows installer version is pretty sharp. A lot of changes in this version. I just did a test run and it correctly identified OS and services on the...

Posted 01 August 2008 18:04 by bkelley | with no comments

SQL Compare 7 Beta
Red Gate's schema comparison tool, SQL Compare , is in beta for the newest version, SQL Compare 7. You can find details and a link to download here: Red Gate Forums: SQL Compare 7 Beta This version does include support for SQL Server 2008 (through...

Posted 07 April 2008 09:34 by bkelley | with no comments

Changing the Command Prompt
I spend a lot of time at the command prompt and to be perfectly honest, I'm tired of looking at: C:\Documents and Settings\Brian> Or whatever directory I happen to be in. Back in the old DOS days we got rather creative with command prompts, usually...

Posted 20 February 2008 09:08 by bkelley | with no comments

Filed under:

Metasploit 3.1 is out
The new version of Metasploit is out. Included is a GUI interface. It's a complete re-write in Ruby (note to self, learn more about Ruby) whereas the previous version were in Perl. The Metasploit Framework site If you aren't familiar with Metasploit...

Posted 28 January 2008 13:42 by bkelley | with no comments

Honeypots in the Database
As a follow up to my post about Cesar Cerrudo's new whitepaper , earlier this month David Litchfield talked about putting honeypots in the database in his blog post, Database tripwires... , to catch someone snooping around. The basic idea for non-Oracle...

Posted 23 November 2007 18:06 by bkelley | 2 comment(s)

Resources: SQL Server 2005 Security
Work responsibilities took up my time on Thursday and Friday, so I never got around to posting. Here's the resources I planned on covering on Friday: online sources for SQL Server security. Website: Center for Internet Security - SQL Server Benchmarks...

Posted 11 November 2007 02:07 by bkelley | with no comments

Tools: Apex SQL Log, Apex SQL Log API, Sample Corrupted Databases
Apex SQL has announced a new version of Apex SQL Log as well as an API for it. Release Notes for Apex SQL Log Apex SQL Log API product page From the product page, it looks like the API can be used to create auditing capabilities using the transaction...

Posted 07 November 2007 14:43 by bkelley | with no comments

Online Resource: Safari Tech Books Online
I've used Safari (the O'Reilly version ) for a number of years now and it is a resource I often recommend to coworkers. Basically, it's an on-line library of technical books (since expanded to include video) from a group of publishers. O'Reilly, Microsoft...

Posted 02 November 2007 08:55 by bkelley | 5 comment(s)

Tool: KeePass Password Safe password manager/vault
Some time ago I was looking for a password vault and came across some recommendations for KeePass . KeePass is open source and free. It's a nice password manager and some of the features I like are: Strong encryption of the password database The ability...

Posted 31 October 2007 08:00 by bkelley | 1 comment(s)

Structuring the Blog Better
For a variety reasons, including personal/family concerns and workload, I've not been able to write as often as I'd like. That doesn't just include the blog, but also writing articles. It's been a long while since I've written an article for SSC . I want...

Posted 28 October 2007 22:59 by bkelley | with no comments

Alpha Version of SQLPing3 Command Line Available
Noted SQL Server security expert, Chip Andrews, has released an alpha version of a command-line version of SQLPing3. You can find it at his free tools location on SQLSecurity.com : SQLSecurity.com Free Tools If you aren't familiar with the SQLPing series...

Posted 25 October 2007 09:06 by bkelley | with no comments

My Book is Out!
How to Cheat at Securing SQL Server 2005 I recently had the opportunity to contribute a couple of chapters to this new SQL Server security book from Syngress. The concept of the book is to provide a fundamental understanding for harried IT workers on...

Posted 04 October 2007 08:28 by bkelley | 3 comment(s)

Midlands PASS October Meeting
Taya Blanchard to speak on A Practical Guide to Making Sense of Your SQL Server Application Performance Midlands PASS Chapter - October 4, 2007 Meeting Sponsored by Quest Software The Midlands PASS Chapter is pleased to announce Taya Blanchard as our...

Posted 03 October 2007 09:02 by bkelley | with no comments

Midlands PASS Chapter - August 2, 2007
"Database Professional Toolkit" with Brian and Jeremy Midlands PASS Chapter - August 2, 2007 Meeting Sponsored by Red Gate Software The Midlands PASS Chapter is pleased to announce our first member-led "Database Professional Toolkit" which features our...

Posted 31 July 2007 13:33 by bkelley | with no comments

More Posts Next page »