[Full-Disclosure] Gates: 'You don't need perfect code' for good security
Valdis.Kletnieks at vt.edu
Valdis.Kletnieks at vt.edu
Tue Nov 4 14:22:44 GMT 2003
On Tue, 04 Nov 2003 06:03:40 EST, Geoincidents <geoincidents at getinfo.org> said:
> Nonsense, you read to many MS papers <g>. Lots of ISP's run SQL servers on
> the internet for radius authentication, where the database and stored
> procedures are not exposed.
The SQL server doesn't have to be accessible to the Internet. It only
has to be accessible to those machines authorized to do authentication
lookups.
There's reasons why 'best practices' call for a physically separate
management network....
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 226 bytes
Desc: not available
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20031104/aabddfef/attachment.bin
Full-Disclosure is hosted and sponsored by Secunia.