Re: Port 1443



On 22/12/06, Richards, Jim <jim.richards@xxxxxxxxxxxxxxx> wrote:
Isn't that the admin port for sql-server

[resend, bounced due to nonsubcribed address]

Nearly. Slammer exploited a flaw in SQL server on 1434/udp. SQL server
also uses 1433/tcp IIRC.

"The worm targeting SQL Server computers is self-propagating malicious
code that exploits the vulnerability described in VU#484891
(CAN-2002-0649). This vulnerability allows for the execution of
arbitrary code on the SQL Server computer due to a stack buffer
overflow.

Once the worm compromises a machine, it will try to propagate itself.
The worm will craft packets of 376-bytes and send them to randomly
chosen IP addresses on port 1434/udp. If the packet is sent to a
vulnerable machine, this victim machine will become infected and will
also begin to propagate. Beyond the scanning activity for new hosts,
the current variant of this worm has no other payload." --
http://www.cert.org/advisories/CA-2003-04.html

cheers,
Jamie
--
Jamie Riden, CISSP / jamesr@xxxxxxxxxx / jamie.riden@xxxxxxxxx
NZ Honeynet project - http://www.nz-honeynet.org/



Relevant Pages

  • Re: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434!
    ... And there's no SP3 for MSDE, ... Make sure SQL Server is not running while you copy over the files ... If anyone writes a worm for the Hello bug, I hereby pre-name it the "Yo ... > A worm which exploits a vulnerability in SQL Server is bringing ...
    (Bugtraq)
  • Re: URGENT: New SQL Worm?
    ... MS02-039 patches the vulnerability this new worm is attacking. ... Blocking inbound access to UDP1434, the SQL Server 2000 Resolution ... Service port. ... Russ - Surgeon General of TruSecure Corporation/NTBugtraq Editor ...
    (NT-Bugtraq)
  • Re: Massive SQL Server attack
    ... MS02-039 patches the vulnerability this new worm is attacking. ... Blocking inbound access to UDP1434, the SQL Server 2000 Resolution ... Service port. ...
    (microsoft.public.win2000.security)
  • URGENT: New SQL Worm?
    ... installations were compromised by some sort of SQL Server Worm. ... Installation of the SP3 after compromise seemed to resolve ... system outside of SQL Server, and whether trojans have been installed. ...
    (NT-Bugtraq)
  • RE: Does Slammer effect my VPN?
    ... the "Slammer" worm is an Internet worm ... and begin evaluation and deployment of SQL Server 2000 SP3 or MSDE ... Check to see if there is a real network problem or if you have any ...
    (microsoft.public.sqlserver.security)