SQLRecon released by Special Ops Labs!!!

From: Erik Pace Birkholz (erik_at_specialopssecurity.com)
Date: 03/22/05

  • Next message: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]: "Re: Windows firewall scopes for notebook users ex office..."
    Date: Tue, 22 Mar 2005 04:50:27 -0500
    To: "Erik Pace Birkholz" <erik@specialopssecurity.com>, <focus-ms@securityfocus.com>
    
    

    Chip Andrews of SQL Server Security fame has completed SQLRecon v1.0,
    the successor to SQLPing2, which aggregates multiple SQL Server
    discovery methods into a single, easy-to-use tool.

    And now for the good news! SQLRecon v1.0 has been released to the public
    as a free tool.

    SQLRecon performs both active and passive scans of your network in order
    to identify all of the SQL Server/MSDE installations in your enterprise.

    Due to the proliferation of personal firewalls, inconsistent network
    library configurations, and multiple-instance support, SQL Server
    installations are becoming increasingly difficult to discover, assess,
    and maintain. SQLRecon is designed to remedy this problem by combining
    all known means of SQL Server/MSDE discovery into a single tool which
    can be used to ferret-out servers you never knew existed on your network
    so you can properly secure them.

    FEATURES

    * Multi-threaded scanning engine
    * 6 Active scanning techniques
    * 2 Stealth scanning techniques
    * IP Range scanning
    * IP List scanning
    * Export results as XML or text file
    * Export IP list for use in future scans (i.e. Passive to Active)
    * ICMP check to increase scan speed
    * Debug mode to allow for greater scan visibility
    * Allows alternate credentials
    * Custom source port for UDP packets for firewall evasion

    Features, screenshots, documentation and download available here:
    http://www.specialopssecurity.com/labs/sqlrecon/
    <http://www.specialopssecurity.com/labs/sqlrecon/>
     
    The press release is available here:
    http://www.specialopssecurity.com/news/2005/
     
    ABOUT SPECIAL OPS LABS:
    Led by industry expert and co-founder of Special Ops Security, Inc.,
    Chip Andrews (Founder of SQLSecurity.com), Special Ops Labs is a
    dedicated research and development team tasked with the creation and
    evolution of applications, scripts, templates, utilities and tools for
    use during consulting and training engagements. When appropriate,
    Special Ops Labs freely provides these tools to the security community.
     
    P.S. Stay tuned for SQLassault. If you have product feature suggestions,
    please go here http://www.specialopssecurity.com/labs/sqlassault/ and
    let us know.
     
    Enjoy,

            Erik

    ________________________________

    Erik Pace Birkholz CISSP,ISSAP,MCSE
    President/CEO

    Special Ops Security <http://sopsec.com/>
    888-R-U-OWNED x187
    ERIK@SpecialOpsSecurity.com
    vCard <http://sopsec.com/pgp/birkholz.vcf>
    PGP Public Key <http://sopsec.com/pgp/birkholz.pgp>

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]: "Re: Windows firewall scopes for notebook users ex office..."

    Relevant Pages

    • SQLRecon released by Special Ops Labs!!!
      ... Chip Andrews of SQL Server Security fame has completed SQLRecon v1.0, ... Led by industry expert and co-founder of Special Ops Security, Inc., ...
      (Pen-Test)
    • Re: SQL or Access DB
      ... As far as encryption goes though... ... with Sql Server you can use SQL DMO and encrypt your stored procedures ... installation - Security was absolutely critical and in most instances, ... > then we create a nice gui around this database and sell it to automotive ...
      (microsoft.public.dotnet.languages.vb)
    • Re: Is there any way to prevent hacker trying to guess sa password?
      ... and port 1433 will not be open. ... If someone can crash SQL Server by connecting to port 1433, ... You don't need multiple security experts. ...
      (microsoft.public.sqlserver.security)
    • Re: Getting to the bottom of MSDE network connection problems ...
      ... Brilliant, Nick, especially the explanation for local network user being ... authenticated as GUEST in WinXP SP2. ... > on a desktop OS like XP (meaning that, you can not compare SQL Server ... > again and selected the security tab. ...
      (microsoft.public.sqlserver.msde)
    • [NT] SQL Extended Procedure Functions Contain Unchecked Buffers
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... SQL Server 7.0 and 2000 provide extended stored procedures, ... Several of the Microsoft-provided extended stored procedures have been ... Exploiting the flaw could enable an attacker to either cause the SQL ...
      (Securiteam)