RE: MS-SQL Blank Password Enumeration

From: O'Malley, William (womalley@freemarkets.com)
Date: 05/28/02


Date: Tue, 28 May 2002 07:16:34 -0400
From: "O'Malley, William" <womalley@freemarkets.com>
To: "Don Wolf" <don.wolf@securedsite.org>, "Focus-MS - Security Focus" <focus-ms@securityfocus.com>

eEye has a free tool for doing this.
http://www.eeye.com/html/Research/Tools/sqlworm.html

I've been using that and Nessus to find any open servers.

-----Original Message-----
From: Don Wolf [mailto:securedsite@hotmail.com]
Sent: Monday, May 27, 2002 3:30 PM
To: Focus-MS - Security Focus
Subject: MS-SQL Blank Password Enumeration

Greetings All, a quick question for any MS-SQL folks:

How can I determine which databases have blank passwords on SQL servers
with
multiple databases? I've already determined the servers which contain
blank
passwords, but the tool I am using (sqlbf.c) doesn't display the
individual
database, e.g. Northwind, etc. On one particular server we have 5
databases
and I need to determine which is running blank and what dept. will need
to
fix it. I am asking this question assuming the SA account is not global
and
is configured on each individual database?

Any assistance would be greatly appreciated.

Brian.



Relevant Pages

  • MS-SQL Blank Password Enumeration
    ... How can I determine which databases have blank passwords on SQL servers with ... I've already determined the servers which contain blank ... passwords, but the tool I am using doesn't display the individual ... is configured on each individual database? ...
    (Focus-Microsoft)
  • Re: SQL active - active cluster hardware design?
    ... if you can find TPC-C benchmarks to be better on Itanium, ... For x64 vs IA-64, as I said it depends a lot on how the system vendors make ... x64 servers may be sufficient. ... You will need to know number of users and databases. ...
    (microsoft.public.sqlserver.clustering)
  • Re: SQL active - active cluster hardware design?
    ... if you can find TPC-C benchmarks to be better on Itanium, ... For x64 vs IA-64, as I said it depends a lot on how the system vendors make ... x64 servers may be sufficient. ... You will need to know number of users and databases. ...
    (microsoft.public.sqlserver.clustering)
  • Re: nessus scan
    ... Null sessions do NOT allow unauthenticated access to data on ... > when XP Pro users try to change their domain passwords at logon. ... > downlevel clients to access those servers. ... > auditing for account logons events and account management on domain ...
    (microsoft.public.win2000.security)
  • Re: SAN (NetApp SnapMirror) replicated Exchange databases usability
    ... to stage Exchange 2007 servers at siteB with SG's and databases that are ... This is achieved by having Exchange ...
    (microsoft.public.exchange.design)