<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[静怡家园]]></title> 
<link>http://www.zhanghaijun.com/index.php</link> 
<description><![CDATA[书山有路勤为径，学海无涯苦作舟！]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[静怡家园]]></copyright>
<item>
<link>http://www.zhanghaijun.com/post//</link>
<title><![CDATA[事实证明初始安装MSSQL时选择低权限用户比事后修改方便的多]]></title> 
<author>碟舞飞扬 &lt;webmaster@zhanghaijun.com&gt;</author>
<category><![CDATA[服务器类]]></category>
<pubDate>Fri, 13 Feb 2009 13:12:09 +0000</pubDate> 
<guid>http://www.zhanghaijun.com/post//</guid> 
<description>
<![CDATA[ 
	&nbsp;&nbsp;&nbsp;&nbsp;初始安装MSSQL SERVER前，新建一个属于users组的用户，我这里名为SQLADMIN，建议密码尽量设置的复杂一点。<BR>然后在安装mssql进行到服务帐户这步时候，选择启动帐户用户名为sqladmin即可<br/>&nbsp;&nbsp;&nbsp;&nbsp;如图1所示： <br/><a href="http://www.zhanghaijun.com/attachment/2009-2/20090213211203255.JPG" target="_blank"><img src="http://www.zhanghaijun.com/attachment/2009-2/20090213211203255.JPG" class="insertimage" alt="点击在新窗口中浏览此图片" title="点击在新窗口中浏览此图片" border="0"/></a><br/>&nbsp;&nbsp;&nbsp;&nbsp;安装完毕，我先打上sp4补丁，在“服务管理器”中启动SQL server，完全没有问题<BR>如图2所示：<br/><a href="http://www.zhanghaijun.com/attachment/2009-2/20090213211204525.JPG" target="_blank"><img src="http://www.zhanghaijun.com/attachment/2009-2/20090213211204525.JPG" class="insertimage" alt="点击在新窗口中浏览此图片" title="点击在新窗口中浏览此图片" border="0"/></a><br/>&nbsp;&nbsp;&nbsp;&nbsp;原因是安装时候选择指定的帐户为服务启动用户，mssql为自动为以下目录添加sqladmin的完全控制权限，我的sql程序文件在C盘，数据库文件放D盘：<br/>C:&#92;Program Files&#92;Microsoft SQL Server&#92;MSSQL<br/>C:&#92;Program Files&#92;Microsoft SQL Server&#92;MSSQL&#92;Binn<br/>C:&#92;Program Files&#92;Microsoft SQL Server&#92;MSSQL&#92;Install<br/>C:&#92;Program Files&#92;Microsoft SQL Server&#92;MSSQL&#92;Upgrade<br/>D:&#92;Program Files&#92;Microsoft SQL Server&#92;MSSQL<br/>D:&#92;Program Files&#92;Microsoft SQL Server&#92;MSSQL&#92;BACKUP<br/>D:&#92;Program Files&#92;Microsoft SQL Server&#92;MSSQL&#92;Data<br/>D:&#92;Program Files&#92;Microsoft SQL Server&#92;MSSQL&#92;FTDATA<br/>D:&#92;Program Files&#92;Microsoft SQL Server&#92;MSSQL&#92;JOBS<br/>D:&#92;Program Files&#92;Microsoft SQL Server&#92;MSSQL&#92;LOG<br/>D:&#92;Program Files&#92;Microsoft SQL Server&#92;MSSQL&#92;REPLDATA<br/>以下注册表路径会被添加sqladmin的完全控制权限:<br/>HKEY_LOCAL_MACHINE&#92;SOFTWARE&#92;Microsoft&#92;MSSQLServer&#92;MSSQLServer<br/>HKEY_LOCAL_MACHINE&#92;SOFTWARE&#92;Microsoft&#92;MSSQLServer&#92;MSSQLServer&#92;SuperSocketNetLib<br/>HKEY_LOCAL_MACHINE&#92;SOFTWARE&#92;Microsoft&#92;MSSQLServer&#92;Providers<br/>HKEY_LOCAL_MACHINE&#92;SOFTWARE&#92;Microsoft&#92;MSSQLServer&#92;Replication<br/>HKEY_LOCAL_MACHINE&#92;SOFTWARE&#92;Microsoft&#92;MSSQLServer&#92;Setup<br/>HKEY_LOCAL_MACHINE&#92;SOFTWARE&#92;Microsoft&#92;MSSQLServer&#92;SQLServerAgent<br/>HKEY_LOCAL_MACHINE&#92;SOFTWARE&#92;Microsoft&#92;MSSQLServer&#92;Tracking<br/>SQLAGENT服务启动也完全没有问题<br/>&nbsp;&nbsp;&nbsp;&nbsp;PS：使用低权限用户启动SQL SERVER对于防止通过web sql注入和sql扩展提权具有重要意义，之所以建议使用users组用户启动，因为有可能目录和注册表还是需要有users组权限读取<br/>&nbsp;&nbsp;&nbsp;&nbsp;欢迎大家就此问题和我共同交流探讨<br/>Tags - <a href="http://www.zhanghaijun.com/tags/mssql/" rel="tag">mssql</a>
]]>
</description>
</item><item>
<link>http://www.zhanghaijun.com/post//#blogcomment</link>
<title><![CDATA[[评论] 事实证明初始安装MSSQL时选择低权限用户比事后修改方便的多]]></title> 
<author> &lt;user@domain.com&gt;</author>
<category><![CDATA[评论]]></category>
<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate> 
<guid>http://www.zhanghaijun.com/post//#blogcomment</guid> 
<description>
<![CDATA[ 
	
]]>
</description>
</item>
</channel>
</rss>