Re: Connection hijacking in SQL Server 2000

From: Bernd Eckenfels (ecki-news2002-06@lina.inka.de)
Date: 06/28/02


From: Bernd Eckenfels <ecki-news2002-06@lina.inka.de>
Date: 28 Jun 2002 02:00:49 GMT

In comp.security.misc Wes Gamble <w.gamble@pentasafe.com> wrote:
  I would assume that an exploiter would have to know the
> protocol used by SQL Server so that they could construct reasonable
> looking packets to send to SQL Server.

The TDS Protocol is open so this is not an issue. Highjacking those
connections would involve eighter spoofing on TCP connections, which require
physical access to the network and is hard to achieve if encryption is
turned on, or you modify the connection pool. I am not sure how much work
that is, but i simply *asume* you have to be local admin on the machine.

The simplest protection is not to allow untrusted access to your network or
clients.

Greetings
Bernd



Relevant Pages

  • Re: Access 2007->SQL Server2005 "connection was forcibly closed",G
    ... But maybe the "faulty switch in the dusty corner of the rack" is the ... connections and so maybe the network must be tested against this new network ... Hope I get at least the SQL Server log today to look if there is something ... It's a bit funny, though, that it is correlated with many connections ...
    (microsoft.public.sqlserver.connect)
  • Re: VPN with Netopia R910, private lan ip
    ... client's network to be able to develop the things I do. ... I'm getting Sql Server Developer ... > worked with Netopia routers before with a dedicated VPN and dynamic IP. ... I wanted to use it to make automatic VPN connections so that ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: sql server2000; TCP/IP vs Named Pipes
    ... wireshark.org have an excellent protocol analyser. ... My company is running an application that uses sql server 2000 sp3. ... We prefer to use TCP/IP but we are having issues with users losing there ... How can I isolate the problem to th network? ...
    (microsoft.public.sqlserver.tools)
  • Re: sql server2000; TCP/IP vs Named Pipes
    ... wireshark.org have an excellent protocol analyser. ... My company is running an application that uses sql server 2000 sp3. ... We prefer to use TCP/IP but we are having issues with users losing there ... How can I isolate the problem to th network? ...
    (microsoft.public.sqlserver.tools)
  • =?iso-8859-1?Q?Remote_connection_f=FCr_2008Express_zulassen?=
    ... A network-related or instance-specific error occurred while establishing a connection to SQL Server. ... Verify that the instance name is correct and that SQL Server is configured to allow remote connections. ... (provider: SQL Network Interfaces, error: 26 - Error Locating Server/Instance Specified) ... Und wie kann ich die Remote Connections zu lassen? ...
    (microsoft.public.de.sqlserver)