Description
If a SQL Server client does not require encryption of all traffic or skips server certificate validation, database traffic can be exposed to a network attacker. A server can force encryption even with Encrypt=False, so check the server settings and driver version when assessing the actual protection.
Potential impact
- Database credentials and query results can be exposed or modified through a man-in-the-middle attack.
Remediation
Use Encrypt=true and validate the server certificate. Do not use Encrypt=false or TrustServerCertificate=true outside temporary development environments.
Examples
Before
csharp
using var connection = new SqlConnection(
"Server=db;Database=App;Encrypt=False");
After
csharp
using var connection = new SqlConnection(
"Server=db;Database=App;Encrypt=True;TrustServerCertificate=False");
Explanation:
- Before:
Encrypt=Falsemeans that the client does not require encryption of all traffic. The actual protection depends on the server's forced-encryption setting and the driver. - After: Require an encrypted SQL connection and validate the server certificate instead of setting
Encrypt=falseorTrustServerCertificate=true.