all groups > dotnet security > june 2007 >
You're in the

dotnet security

group:

Dot Net Security


Dot Net Security tomcharnley NO[at]SPAM yahoo.com
6/1/2007 3:19:49 AM
dotnet security: Hi

I'm an MCT and came across this little nugget last week.

Using Reflector, I created a project from the Integration services Dll
from sql2005.
I took off the assembly signing, added some code to write to a file.

I dropped the dll in the directory where sqlservr.exe is

I created a new text file in the same directory called
sqlservr.exe.local

Using Sql2005 SIS, it ran my version of the dll!!!!!

Whoops!


I'm waiting to see if Office2007 etc can be controlled in the same way

Hmm...

Tom
Re: Dot Net Security Dominick Baier
6/1/2007 1:06:32 PM
well - to replace this dll you need admin privileges. As admin you own the
box anyway...so what's the deal?


-----
Dominick Baier (http://www.leastprivilege.com)

Developing More Secure Microsoft ASP.NET 2.0 Applications (http://www.microsoft.com/mspress/books/9989.asp)

[quoted text, click to view]

AddThis Social Bookmark Button