It has been many years since I have touched a SQL server. My recollection is that for newer versions (2005 and later, or maybe after one of the later 2000 service packs) the "sa" account cannot be blank (in effect, the "default" password) and you MUST change/chose a password for it when installing/standing up SQL instance (you can still choose a crappy password, but at least it won't be easily guessable, in theory).
Can someone confirm that?
Thanks,
Jim Adgate
James Adgate, CISSP IT Auditor and Compliance Specialist Data Loss Prevention (DLP) IT Security Policy and Risk Mitigation for Enterprises http://linkedin.com/in/jamesadgatech