Exposed sa Account Password

Check Description

This check determines whether the SQL 7.0 and SQL 2000 sa account password is written in plaintext to the %temp%\sqlstp.log and %temp%\setup.iss files.

If you use SQL Server Authentication, also known as Standard Security, to install SQL Server 7.0 Service Packs, the system administrator (sa) password is saved in plaintext format in the Setup.iss file in the %winnt% directory and the Sqlstp.log file in the Temp directory.

Note: Microsoft recommends that you use Windows NT Security Authentication to install SQL Server 7.0 Service Packs to avoid this problem.
For this check to succeed, you must share the drive.

Additional Information

FIX: Service Pack Installation May Save Standard Security Password in File (Q263968)

Microsoft Security Bulletin (MS00-035): Frequently Asked Questions

⌐ 2002 Microsoft Corporation. All rights reserved.