New Paper - Violating Database Enforced Security Mechanisms

From: Chris Anley (chris@ngssoftware.com)
Date: 06/24/02


From: "Chris Anley" <chris@ngssoftware.com>
To: <bugtraq@securityfocus.com>
Date: Mon, 24 Jun 2002 19:19:04 +0100

Hi folks,

I've written a paper on runtime patching of database server code, which can
be found here:

http://www.ngssoftware.com/papers/violating_database_security.pdf

It discusses "runtime patching" exploits, specifically in the context of
Microsoft SQL Server 2000, but the techniques apply to a wide variety of
targets. The paper also documents a three byte patch that disables access
control in SQL Server, resulting (by way of some tricks) in sysadmin access
for all.

I think this kind of exploit is pretty dangerous and well worth thinking
about, hence the paper. As always, any questions, comments, flames etc will
be gratefully received. Well, received, anyhow. :o)

     -chris.



Relevant Pages

  • RE: SBS 2003 Unable to connect to database STS_Config
    ... Uninstall the SQL server from the SBS 2k3 server from add/remove programs ... Uninstall Microsoft SQL Server Desktop Engine (SHAREPOINT) ... If AV software install any extra IIS virtual directory, ...
    (microsoft.public.windows.server.sbs)
  • Re: Memory issues with 64-bit SQL Server 2005 on 64-bit Win 2003 C
    ... I also checked the individual patch levels for the .NET drivers, SQL Server ... The SQL Server is fully patched, however Windows Update reported that the OS ... Lock pages in memory -- I guess you might have taken care of it as well. ...
    (microsoft.public.sqlserver.clustering)
  • RE: migrating from wmsde to sql server
    ... Click Start, point to All Programs\Microsoft SQL Server, and then click ... then click New SQL Server Registration. ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • RE: SBS 2003 Unable to connect to database STS_Config
    ... Uninstall the SQL server from the SBS 2k3 server from add/remove programs ... Uninstall Microsoft SQL Server Desktop Engine (SHAREPOINT) ... If AV software install any extra IIS virtual directory, ...
    (microsoft.public.windows.server.sbs)
  • Re: Best replication architecture?
    ... Looking for a SQL Server replication book? ... So if it is subscribing to Publisher 1, ...
    (microsoft.public.sqlserver.replication)