does anyone know of any security risks with the default PUBLIC settings for sql 2005/8?
i ran sp_helprotect and it listed out the PUBLIC grants, and now i have an auditor telling me that i have a security risk because PUBLIC has access to system information. before i start to present my case i wanted to see if anyone has any links or information they can provide that would detail how the default settings allow for a security risk.
for the record, the auditor mentioned that these setting allow for the ability to crack passwords because they can view the password hash. i have not been able to verify that the setting allow for such an ability to see that information through the sys catalog views.
thanks in advance