Re: [Full-Disclosure] David Litchfield talks about the SQL Worm in the Washington Post

From: Georgi Guninski (guninski@guninski.com)
Date: 01/29/03

  • Next message: Andrea Vecchio: "R: [Full-Disclosure] [Secure Network Operations, Inc.]FullDisclosure != Exploit Release"
    From: Georgi Guninski <guninski@guninski.com>
    To: "Richard M. Smith" <rms@computerbytesman.com>, full-disclosure@lists.netsys.com
    Date: Wed, 29 Jan 2003 19:17:36 +0200
    

    So what?
    This sql hype highly resembles the code red stuff. Then people accused eeye for
    releasing the bug, though they didn't provide exploit code. IIRC Litchfield also
    didn't provide exploit code. Should advisories be "There is a bug. Go patch. End."?

    Is there any real evidence that releasing PoC helps high scale incidents like
    this one? - Don't think so.

    Sure writing worms and virii is bad, but this sql worm has a positive side
    effect imho.
    The real damage done was very limitied (high traffic in m$ network according to
    the reg, some atms stopped working for strange reason, korean spammers off the
    net) compared to the potential long lasting damage from stealing info from these
    DBs.
    There wasn't such fuzz about the apache worm, though imho apache has much more
    market share than m$ sql.

    Georgi Guninski
    http://www.guninski.com

    Richard M. Smith wrote:
    > Hi,
    >
    > The following quote from David Litchfield appeared in a front-page
    > article in today's Washington Post:
    >
    > http://www.washingtonpost.com/wp-dyn/articles/A57550-2003Jan28.html
    >
    > "You have this ideal vision of doing something
    > for the greater good," said David Litchfield,
    > managing director of Next Generation Security
    > Software Ltd. of London, who acknowledged that
    > a small bit of his code might have been used in
    > the attack. "I will probably no longer publish such code."
    >
    > Perhaps David can put together a longer message for Bugtraq and
    > Full-Disclosure on his changing views of publishing proof-of-concept
    > code for security vulnerabilities.
    >
    > Richard M. Smith
    > http://www.ComputerBytesMan.com
    >
    > _______________________________________________
    > Full-Disclosure - We believe in it.
    > Charter: http://lists.netsys.com/full-disclosure-charter.html
    >
    >

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



    Relevant Pages

    • Re: Problem with XMLType indexing. Please confirm
      ... pasted your script verbatim into 10g release 10.1.0.2.0 personal on ... metalink for the bug fix. ... SQL> drop table bug; ... XMLType( ...
      (comp.databases.oracle.server)
    • RE: Undeclared tag ID % is used in a FOR XML Explicit Query
      ... As you have a test environment you should be able to test the change ... > In fact we have multiple SQL environment running the same config and Query, ... > on the SQL server running on Windows 2003. ... but is in fact a bug in SQL sever. ...
      (microsoft.public.sqlserver.programming)
    • Re: Quick Question
      ... but I'm not sure if it's a bug in SQL CE: ... Thanks for the information on RDA. ... >> Are there common reaons why a subscription would hang? ...
      (microsoft.public.sqlserver.ce)
    • Re: Bug in Database Maintenance Plans Enterprise Manager and MSDE v SQL
      ... Yep, this is a bug. ... Cannot Edit or Delete Database Maintenance Plan on MSDE Installation ... Looking for a SQL Server replication book? ... > The bug I am reporting is with the "Remove after X Weeks/Days" option for> Database Backup, Transaction Backup. ...
      (microsoft.public.sqlserver.server)
    • Re: Bug in Database Maintenance Plans Enterprise Manager and MSDE v SQL
      ... Yep, this is a bug. ... Cannot Edit or Delete Database Maintenance Plan on MSDE Installation ... Looking for a SQL Server replication book? ... > The bug I am reporting is with the "Remove after X Weeks/Days" option for> Database Backup, Transaction Backup. ...
      (microsoft.public.sqlserver.tools)