MS SQL server worm logs question

From: Ian O'Brien (iob@xilinx.com)
Date: 01/27/03

  • Next message: Marc Maiffret: "RE: SQL Sapphire Worm Analysis"
    Date: Mon, 27 Jan 2003 01:08:57 -0800
    From: "Ian O'Brien" <iob@xilinx.com>
    To: incidents@securityfocus.com
    
    

    So, after cleaning up the mess does anyone know if there are any logs of any
    kind typically left behind on the actual machines themselves. I'm trying to see
    if I can piece together the actual path taken for the original infection.

    I had a very quick look at a patched / rebooted machine this evening but didn't
    se anything obvious in the event viewer. Are there logfiles kept in any standard
    places for MSDE and MS SQL Server?

    ian

    -- 
    Ian O'Brien    - Xilinx Network Security Engineer
         -=-        = Pager 408-696-2182 -=- Phone 408-879-5206
    iob@xilinx.com - Please state the nature of your architectural emergency
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    


    Relevant Pages

    • SID Issue after Upgrading to AD to W2K3?
      ... A user starts to get the logon prompt when opening Outlook from a computer ... This also seems to generate the following logs in the users System Event log ... Changing the SID of the machines seems to correct the problem, ... We do Ghost machines, however, we use SysPrep. ...
      (microsoft.public.windows.server.general)
    • Re: shop life ..
      ... sure it's not nearly as available as kerosene once was. ... it's for that reason it was recommended for cleaning. ... I've used that system as long as I've owned my machines. ...
      (rec.crafts.metalworking)
    • RE: Default printer keeps changing on its own for every user
      ... Are users logging in from different machines? ... i.e. Julie logs on in the office where her default printer is ... Microsoft MVP - Terminal Server ... > auto create only the default printer and all pritner are installed as local ...
      (microsoft.public.windows.terminal_services)
    • Re: Logon type 3 - ID 529
      ... nothing has been installed recently on these machines. ... I couldnt see anything in the logs too. ... the alert appeared. ... I've read logon type 3 can be caused due to access of shared ...
      (microsoft.public.windows.server.sbs)
    • Re: [SLE] logdigest and mail problem
      ... I have two SUSE Linux 9.3 Professional machines here. ... still have off site logs. ... I just installed another fresh install and set up everything, ... Your sender address uses a domain name that is not resolvable outside your network. ...
      (SuSE)