Urgent.News

What's breaking now, across thousands of outlets.

Tech

How I Recovered Deleted SQL Server Rows Without Ever Enabling CDC or Audit

Most data-recovery tools assume you turned on Change Data Capture, Change Tracking, or Audit before the incident happened. In the real world — small and mid-sized companies running their own SQL Server — almost nobody does that. By the time someone notices bad data, it's already too late to turn those features on retroactively. SQL Server's transaction log already records every change. The…

The article recounts how the author developed LogCarver, a tool to recover deleted SQL Server rows without enabling Change Data Capture, Change Tracking, or Audit. Most recovery tools assume these features were enabled beforehand, but in small and mid-sized businesses, this is rarely the case. SQL Server's transaction log already records every change, but the fn_dblog function that reads it is rarely used and its row image byte layout isn't published.

The author reverse-engineered the format from actual output, byte by byte, leading to the creation of LogCarver. Two bugs were discovered after releasing the tool: one affecting Heap tables and another caused by extra indexes. Debugging the issue required connecting to a live database and examining fn_dblog's raw output. The fix involved querying sys.indexes for the table's storage structure and building the exact AllocUnitName from that, instead of guessing string patterns.

All three bugs were only found by testing on actual SQL Server instances, not by relying on documentation or intuition. The current limitations of LogCarver include handling specific data types and TRUNCATE TABLE operations.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Saha Operasyonunda Canlı Konum Takibi: Gerçek Zamanlı Görünürlük Nasıl Kurulur

Saha operasyonu yürüten firmalarla konuştuğumuzda hep aynı cümleyle başlıyor sohbet: "Şoförün nerede olduğunu bilmiyoruz." İlk bakışta küçük, günlük bir operasyonel rahatsızlık gibi görünüyor.

  • Real-time location tracking crucial for Saha operation transparency
  • System transmits mobile data to server via socket connection
  • Improves operational efficiency and accountability

Two dashboards, one graph: 37 days of bounty-board logs vs 125 impressions and zero clicks

Mr Say Nothing's ledger and mine are the same experiment with different dashboards: a small number of things happen, almost nobody acts, and the number that matters is not the one you can polish.

  • First dashboard shows 79 visitors and 125 impressions with zero clicks
  • Second dashboard displays 37 days of bounty board logs with no orders
  • Repeated entries include unchanged eligibility, zero prepaid money, and burst completions

Outbox Pattern

The Outbox Pattern: Solving the Dual-Write Problem in Distributed Systems AnkitDevCode AnkitDevCode AnkitDevCode Follow Sep 10 The Outbox Pattern: Solving the Dual-Write Problem in Distributed Systems…

The Sea Looks Calm When It Isn't

I spent years reading water before I ever wrote a line of code. So when I say this, it comes from both sides of me: the sea on a map and the sea in front of you are not the same object.

  • Myrtos Beach, Kefalonia, appears safe but has hidden dangers.
  • Marine layer classified as high exposure on night of activity.
  • Beach safety tool, not rip current warning or lifeguard forecast.

More from Thursday 1 October →