Author: way0utwest

  • Speaking at SQL Saturday #183 – Albuquerque

    sqlsat183I’ve been accepted to speak at SQL Saturday #183 in Albuquerque, NM on Feb 9, 2013. This is the first SQL Saturday in New Mexico, and I’m excited to drive down and meet the SQL Server pros down there.

    My brother used to live in Albuquerque, and I’ve been there 2 or 3 times, but not in a long time. I was debating if I should fly or drive, but with Taos on the way, I’m thinking to stop by on the trip down and spend a day skiing before the event. If anyone’s interested in a Friday or Sunday out, let me know. I’m not sure which day to hit the mountain.

    I’ll be delivering my Branding Yourself for a Dream Job presentation at the event, but there will be a lot of SQL Server learning to be had. Denny Cherry, Aaron Bertrand, Jason Brimhall, TJay Belt, Mike Fal, Ben Miller, Reeves Smith, Caros Bossy and more are coming from out of town to give, and receive a day of training.

    Yes, most of us come to learn as well as speak. I’m not sure how busy my day will be or if I’ll be giving a lunchtime talk for Red Gate, but I am hoping to see a few sessions. These are on my list.

    If you are within driving distance, consider coming out and enjoying a Saturday of SQL learning.

  • Checking the Instance Fill Factor

    I was reading a post from Paul Randal recently and noted that he recommends not changing the instance’s default fill factor. I agree, and you shouldn’t alter it. However if you aren’t sure if it’s been changed on any of your instances, here’s how to check it.

    I’ll show both the GUI and code ways to do this.

    SSMS

    In SSMS, right click your server instance in Object Explorer and choose properties.

    fillfactor1

    This will open a dialog that has a number of tabs. If you click the “Database Settings” item on the left, you will have various settings appear on the right side. One of these is the default fill factor.

    fillfactor2

    It should be zero or 100. Nothing else.

    T-SQL

    In T-SQL, we can also check by opening a query window and typing:

    EXEC sp_configure 'show advanced options', 1;
    GO
    RECONFIGURE
    GO
    EXEC sys.sp_configure;
    

    This will return all the settings on the server. This is an advanced setting, so you don’t need to enable those.

    If you scroll through the list of items, you will find one that is labeled “fill factor (%)”

    fillfactor3

    Again, this should be zero or 100 in the config_value and the run_value columns. To change this, run this code:

    sp_configure 'show advanced options', 1;
    GO
    RECONFIGURE;
    GO
    sp_configure 'fill factor', 100;
    GO
    RECONFIGURE;
    GO
    
  • Vote for my SQL Bits sessions

    “Rob? Tsk tsk tsk. That’s a naughty word. We never rob. We just sort of borrow a bit from those who can afford it. “

    Robin Hood

    SQLBitsLogoSQL Bits XI is coming to Nottingham forest, home of Robin Hood and Sherwood Forest in Nottinghamshire. This is a fun three day event, with a day of pre-cons, a paid day of sessions, and a free day. It has taken place twice a year in the UK, though the organizers skipped this past fall.

    I’ve submitted a few sessions and I need your votes to get the chance to go back. I’d really like to since I really enjoyed the conference.

    You can vote for these by logging into the site and clicking on the description for the sessions. You get to vote for ten sessions, so pick the ones you are most interested. I’m hoping you pick a few of mine, but whether you vote for me or not, vote.

    I really enjoyed SQL Bits a couple years ago and I’m hoping to get the chance to go back this spring.

  • Hacked

    Getting hacked is never fun, and it can happen in so many ways.
    Getting hacked is never fun, and it can happen in so many ways.

    I’ve been hacked before. My personal web site has been hacked with a variety of injection and XSS attacks over the years. None too serious, and I’ve had backups that allowed me to fix things fairly easily, especially once I had a copy of Data Compare, which saved me a lot of time. At SQLServerCentral, we’ve been hacked as well, though not in a long time. I think we’ve closed most of the security holes, and I haven’t had any issues to deal with in quite some time.

    However as I was reading a note from Richard Douglas about being hacked, it brought back memories of working at JD Edwards. Richard was hacked at work, on his personal system. At JD Edwards, we were required to lock our workstations at all times when we were not physically in front of them. We also had two accounts: a normal user and a domain admin “privileged” user. As you might expect, there were numerous lapses of people walking to the kitchen or bathroom and forgetting to lock their workstations. It was considered fair game to change settings, send email to our group, even place semi-SFW pictures on someone’s desktop. It was quite embarrassing to be caught, and was much more a an effective security reminder than a reprimand from our boss.

    However there is a serious security problem here. Many of us would use our privileged account all too often, since it was a hassle to log out and back in. The “run as” option didn’t work well for some applications, and we were less secure than we probably should have been. If someone walking by, whether an employee, guest, consultant, or someone else noticed SSMS running, how long would it take them to type:

      sp_addlogin 'joeuser', 'joeuser'
      sp_addrole 'joeuser', sysadmin

    I type quickly and that took me less than 30 seconds. I’m sure even a slow typist could get that entered, and erased, inside of a minute. That might result in a serious security breech, if the system to which you were connected contained HIPAA, PCI, or any identity information. Perhaps even worse these days is the chance someone might attach a USB key logger to your keyboard.

    You might be safe in your environment, but you can never be sure. A little care in ensuring you are not unnecessarily exposing security holes, and making sure that outsiders are always escorted can prevent embarrassing incidents from occurring.

    Steve Jones


    The Voice of the DBA Podcasts

    We publish three versions of the podcast each day for you to enjoy.