Re: Blank passwords, TsInternetUser added to Administrators

From: Curt Wilson (netw3_security@hushmail.com)
Date: 01/17/03

  • Next message: Jim Harrison (ISA): "RE: AD replication over WAN"
    Date: 17 Jan 2003 17:26:24 -0000
    From: Curt Wilson <netw3_security@hushmail.com>
    To: focus-ms@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is) In-Reply-To: <333B07CC372AC246888DBEC1D4E4168B0184F1F1@whp-ex2kmb1.whp.owhc.net>

    After more analysis, it appears that the attacker cleared the password
    for the TsInternetUser account and then added to administrators group.
    System policy disallowed blank passwords, so I'm thinking that once the
    user got system level privs through the SQL Server exploit (UDP 1434
    publicized by David Litchfield) they used one of the net user commands to
    clear the password, or did it from the GUI after they logged in via
    RDP/term services. No firewall on the system or network, little
    hardening, and being behind on SQL Server post SP2 hotfixes caused the
    problem in the first place.

    Have performed some stack dump analysis on the SQL server dump, have
    found some data that appears to have come from the exploit published by
    Litchfield. The fact that the SQL Server faulted on SQLSORT.DLL, the
    vulnerable DLL in question, and the partial matching of stack/processor
    data has me pretty much convinced that this is what happened.

    Anyone know of SQL stack dump resources on the net?

    Curt Wilson
    www.netw3.com
    Netw3 Security



    Relevant Pages

    • anyone can give solution for this problem
      ... SQL Server is terminating this ... BEGIN STACK DUMP: ... Access Violation occurred reading address ...
      (microsoft.public.sqlserver.mseq)
    • Re: MSDE startup problem
      ... Seems like SQL Server craps out when trying to recover the model database. ... > * BEGIN STACK DUMP: ... SegSs: 000001A7: ...
      (microsoft.public.sqlserver.server)
    • Error 3624
      ... database, somebady can help me. ... SQL Server Assertion: File:, ... Stack Dump being sent to d:\MSSQL7\log\SQL00021.dmp ... This file is generated by Microsoft SQL Server ...
      (microsoft.public.sqlserver.odbc)
    • Help with error 3624.
      ... select in a database. ... SQL Server Assertion: File:, ... Stack Dump being sent to d:\MSSQL7\log\SQL00021.dmp ... This file is generated by Microsoft SQL Server ...
      (microsoft.public.sqlserver.server)
    • MSDE startup problem
      ... 2004-10-20 15:27:11.88 server Logging SQL Server messages in file 'C:\PROGRAM FILES\Microsoft SQL ... 2004-10-20 15:27:11.90 server SQL Server is starting at priority class 'normal'. ... BEGIN STACK DUMP: ... SegSs: 000001A7: ...
      (microsoft.public.sqlserver.server)