RE: Strange scan on 1433

From: Deus, Attonbitus (Thor@HammerofGod.com)
Date: 05/21/02


Date: Tue, 21 May 2002 10:01:48 -0700
To: <david_laporte@harvard.edu>, "Pavel Lozhkin" <pavel@atrivo.com>, <incidents@securityfocus.com>
From: "Deus, Attonbitus" <Thor@HammerofGod.com>


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

At 08:23 AM 5/21/2002, David LaPorte wrote:
>They're looking for MS-SQL servers with blank/default sa passwords that are
>missing the MS02-020 patch:
>
>http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/
>bulletin/MS02-020.asp

Others have mentioned the MS02-020 bulletin... The BO referenced requires
authenticated access to the box- thus the checks for blank SA. But, of
course, if you have a blank SA, there isn't really much point in worrying
about the overflow.

-----BEGIN PGP SIGNATURE-----
Version: PGP 7.1

iQA/AwUBPOp9fIhsmyD15h5gEQJQ0gCgv3ezP4Scr211WsfhlaSZvtFlcogAnjqR
YWWw6fbXaVhN1dF+JA22yQLC
=/hkB
-----END PGP SIGNATURE-----

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Q822925 problem
    ... Here's a link to the bulletin for this patch, ... Microsoft originally issued this bulletin on August 20th, ... systems that are configured as web servers serving ASP.NET web pages and ...
    (microsoft.public.security)
  • Re: Q822925 problem
    ... Here's a link to the bulletin for this patch, ... Microsoft originally issued this bulletin on August 20th, ... systems that are configured as web servers serving ASP.NET web pages and ...
    (microsoft.public.security)
  • Re: Conflicting info between the global Security Bulletin and some SPi Security Bulletin
    ... According the Security Bulletin for the release of SP4, ... you will see that the updated patch was first included in SP3 ... Later, install of an older ...
    (microsoft.public.win2000.security)
  • Re: [fw-wiz] An article from Peter Tippett/TruSecure...
    ... I don't have to patch portmapper bugs if I'm ... doesn't make much difference against an attacker of a certain level- just ... still leaves enough crackable passwords to make the expense of having ... If you haven't reduced the risk for an associated attacker set, ...
    (Firewall-Wizards)
  • Microsoft Security Bulletin MS03-023 - 823559
    ... The Security Bulletin says Windows 98 SE is affected ... But the information webpage for this ... vulnerability does not provide a patch for Windows 98 SE. ...
    (microsoft.public.security)