Tool: Sapphire SQL Worm Scanner

From: Marc Maiffret (marc@eeye.com)
Date: 01/26/03

  • Next message: Frog Man: "Re: Zorum Portal (PHP)"
    From: "Marc Maiffret" <marc@eeye.com>
    To: "BUGTRAQ" <BUGTRAQ@SECURITYFOCUS.COM>
    Date: Sat, 25 Jan 2003 20:49:34 -0800
    
    

    We had a lot of requests to put together a quick free scanner, like we've
    done in the past, for this SQL worm.

    This is the first version and it is bound to have bugs. Feel free to email
    me any issues directly and we can work on them.

    The scanner is non-intrusive, wont crash your servers, in identifying
    vulnerable systems. It WILL NOT identify already infected systems. Because
    of the nature of the worm it keeps any valid data from getting to the victim
    system. We suggest using sniffers and IDS's to determine already infected
    machines.

    You can download the scanner from:
    http://www.eeye.com/html/Research/Tools/SapphireSQL.html

    For more details about the Sapphire SQL Worm:
    http://www.eeye.com/html/Research/Flash/AL20030125.html

    If you have any questions or comments feel free to mail me directly. As we
    find bugs and make improvements the changes will be reflected on our
    website. So go there for the latest ... that way we don't have to flood this
    list with email.

    Thanks to NGSSoftware (http://www.nextgenss.com/) for discovering the flaw
    the SQL worm uses and for publishing a technical write up which made this
    scanner possible. Once again illustrating that details ARE needed to help
    the good guys.

    Signed,
    Marc Maiffret
    Chief Hacking Officer
    eEye Digital Security
    T.949.349.9062
    F.949.349.9538
    http://eEye.com/Retina - Network Security Scanner
    http://eEye.com/Iris - Network Traffic Analyzer
    http://eEye.com/SecureIIS - Stop known and unknown IIS vulnerabilities



    Relevant Pages

    • Tool: Sapphire SQL Worm Scanner
      ... We had a lot of requests to put together a quick free scanner, ... It WILL NOT identify already infected systems. ... For more details about the Sapphire SQL Worm: ... http://eEye.com/Retina - Network Security Scanner ...
      (NT-Bugtraq)
    • Tool: Sapphire SQL Worm Scanner
      ... We had a lot of requests to put together a quick free scanner, ... It WILL NOT identify already infected systems. ... For more details about the Sapphire SQL Worm: ... http://eEye.com/Retina - Network Security Scanner ...
      (Security-Basics)
    • [VulnWatch] Tool: Sapphire SQL Worm Scanner
      ... We had a lot of requests to put together a quick free scanner, ... It WILL NOT identify already infected systems. ... For more details about the Sapphire SQL Worm: ... http://eEye.com/Retina - Network Security Scanner ...
      (VulnWatch)
    • [Full-Disclosure] Tool: Sapphire SQL Worm Scanner
      ... We had a lot of requests to put together a quick free scanner, ... It WILL NOT identify already infected systems. ... For more details about the Sapphire SQL Worm: ... http://eEye.com/Retina - Network Security Scanner ...
      (Full-Disclosure)