Posted Wednesday 21st May 2008 11:45 GMT
re: direct db access?
mssql's default admin password is (or at least used to be) notoriously commonly left as-is, which probably makes it worth checking any system for it. You don't need sql injection for that though.