I use Aqua Data Studio to access my SQL Server DB, and I am able to view tables, roles, users, stored procedures, etc., of other users! X( It is very disconcerting that we can see each other’s info.
I am new to SQL Server, and I don’t know if this is normal, but if it is, IT NEEDS TO CHANGE!!
I also use Dreamweaver 8, and I am able to see other DSNs from the list of DSNs when creating a connection.
Please don’t try to reassure me that this is OK. It is not OK. It is a serious security issue.
I checked it pretty thooughly just a moment ago, and while it is not normal, you can’t actually view DB data or edit this SP, I am not sure why you can view the SP even. I will research it more, but at this point it is pretty minor as far as how far it can go, as you can’t view table data, but it is not right either. Edit: I am going to edit your post as I have seen it now. If you wish to continue i’d appreciate you do it in PM, while I am still researching this.
OH!
I just found it, you can VIEW SPs of anyone that has “guest” as a user with “public” records, I will send you a list of DBs that I am getting when using ADS, and see if it is the same you are getting to 100% confirm this, I think only 2 DBs have guest user(and I don’t know why!)
Hi Stephen, could you please explain why is this in a little more detail? I’m connected to mssql6 and can actually see 4 other users’ databases. I would like to protect mines from having this problem.