THE SERVER SHOULD NOT TRUST THE CLIENT.
If the client can obtain and use credentials to enter the database server, you are frying.
If your server is only a database server, and your application does not use reliable connections, and your application does not ask for the db credentials that you are using. (See Previous Report.)
I am lazy. I will fix WindowsIdentity.GetCurrent (). Name to return "Administrator" if I like it.
source share