| 
 Posted by m.bohse on 08/08/06 09:53 
Ward, 
 
I would say as long as your permissions are set right you don't have to 
worry. If your user only have rights in their own databases they 
shouldn't be able to accessother user databases. Xp_Cmdshell which 
would be able to delete files or run other OS commands is (by default) 
only available to members of the sysadmin role. 
So I would say create a empty datbase and grant the user only db_owner 
or ddl_admin rights within the database. 
 
Markus
 
  
Navigation:
[Reply to this message] 
 |