Take note of products that don't "advertise" they have MSDE/SQL i ntegration.

From: Shaw, Kevin (kevin.shaw@mail.va.gov)
Date: 01/28/03

  • Next message: Johan Augustsson: "Re: MSDE contained in..."
    From: "Shaw, Kevin" <kevin.shaw@mail.va.gov>
    To: incidents@securityfocus.com
    Date: Tue, 28 Jan 2003 16:05:03 -0500
    
    

    We noticed some instances where medical and photography equipment has MSDE
    as part of the storage or image-forwarding software that comes with the
    device; so it is not widely advertised that it uses it at all. I also have
    acquaintances that work for pharmaceutical manufacturers and they
    encountered some process automation tools and other devices - like post Y2K
    stuff - that had this in place. I'm not making an official statement at
    all; but I thought I'd put a warning out to the community. You can probably
    find the FedCIRC or VA-CIRC bulletins that identify anything they (we)
    specifically know about.

    Kevin Shaw
    Security Analyst 1
    VA Security Operations Center

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management
    and tracking system please see: http://aris.securityfocus.com



    Relevant Pages

    • Re: [mosty OT] trollfilter software
      ... not disputing access issues requiring Internet connection or security ... concerns w/r/t others handling the storage and ignoring the basic fact ... the level of security we want to apply, let us decide where we want to ... indexed/read your e-mails... ...
      (Fedora)
    • [security bulletin] HPSBST03039 rev.1 - HP StoreVirtual 4000 Storage and StoreVirtual VSA, Remot
      ... SUPPORT COMMUNICATION - SECURITY BULLETIN ... The information in this Security Bulletin should be acted upon as ... HP StoreVirtual 4000 Storage and StoreVirtual VSA 11.0 ... Support: For issues about implementing the recommendations of this Security ...
      (Bugtraq)
    • Re: PCanywhere security
      ... how about letting employees store their work on ... What someone puts in their storage space, ... As a security controller for our company, I can assure you that I would ... new firewall rules, only select individuals get external access, and ...
      (comp.security.firewalls)
    • Re: PCanywhere security
      ... how about letting employees store their work on ... What someone puts in their storage space, ... As a security controller for our company, I can assure you that I would ... new firewall rules, only select individuals get external access, and ...
      (comp.security.firewalls)
    • CFP: StorageSS 08
      ... 4th International Workshop on Storage Security and Survivability ... storage protection deployment ... storage encryption techniques (modes of operation, ...
      (sci.crypt.research)