Bonus summary: xp_cmdshell is limited to admins, unless you specifically grant permissions to users. And if you’re an admin, you have the power to turn on and use xp_cmdshell anyway. Xp_cmdshell is not a security hole. This is a reprint of Sean McCown’s original post on DBARant. You know, reprinted with permission and all that. I’ve […]
XP_CmdShell isn’t Evil
- Post author By Jen McCown
- Post date
- Categories In Admin, Security, sqlserverpedia-syndication, SSC, Tech and Learning
- 45 Comments on XP_CmdShell isn’t Evil