Re: Microsoft Informational Alert

From: sms admin \(real name david manor\) (dmanor01@dontspammecomcast.net)
Date: 05/23/02


From: "sms admin \(real name david manor\)" <dmanor01@dontspammecomcast.net>
Date: Wed, 22 May 2002 20:12:46 -0400


does sql 7.0 sp4 supersede this patch, or do you still need it if you
install sp4 on a sql7 server?

"Jerry Bryant [MS]" <jbryant@online.microsoft.com> wrote in message
news:#Q4IPwcACHA.2420@tkmsftngp02...
> PSS Security Response Team Alert - SQL Security Recommendations
>
> SEVERITY: INFORMATIONAL
> DATE: 05/21/2002
> PRODUCTS AFFECTED: SQL Server
>
> **********************************************************************
>
> What is It?
>
> What is It?
>
> The Microsoft Product Support Services Security Team is issuing this alert
> to advise our customers to take precautionary action for the following two
> reasons:
>
> 1) Exploit Code is now available for the vulnerability patched by
Microsoft
> Security Bulletin MS02-020. While the release of exploit code alone does
> not mean that an attack tool will be developed the Product Support
Services
> Security Team feels that this along with the developments below warrant
> increased attention and vigilance.
>
> 2) Increased attempts to log into Internet facing SQL servers with blank
> passwords are being seen on the Internet.
>
> Based on these two items the Microsoft Product Support Services Security
> Team is advising customers to test and deploy the patch for Microsoft
> Security Bulletin MS02-020 if they have not already done so:
>
>
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/
> bulletin/MS02-020.asp
>
> We are also advising customers to follow the following best practices for
> utilizing SQL securely within their environments:
>
> . Secure your SA login account with a non-NULL password. The worm only
works
> if you have no security on your SA login account. Therefore, you should
> follow the recommendation from the "System Administrator (SA) Login" topic
> in SQL Server Books Online to make sure that the built-in SA account has a
> strong password, even if you never directly use the SA account yourself.
>
> . Block port 1433 at your Internet gateways and/or assign SQL Server to
> listen on an alternate port.
>
> . If port 1433 needs to be available on your Internet gateways, enable
> egress/ingress filtering to prevent misuse of this port.
>
> . Run the SQLServer service and SQL Server Agent under a Microsoft Windows
> NT account, not localsystem.
>
> . Enable Windows NT Authentication, enable auditing for successful and
> failed logins, and then stop and restart the MSSQLServer service.
Configure
> your clients to use NT Authentication.
>
> --
> Regards,
>
> Jerry Bryant - MCSE, MCDBA
> Microsoft IT Communities
>
> Get Secure! www.microsoft.com/security
>
>
> This posting is provided "AS IS" with no warranties, and confers no
rights.
>
>



Relevant Pages

  • [NEWS] Xpede Found to Contain Multiple Vulnerabilities
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Intellisol Xpede ... anyone with a valid Xpede user account to issue requests to the Xpede's ... name used by Xpede to perform all its SQL queries. ...
    (Securiteam)
  • Re: SQL account rights
    ... Please advice what is the best, suitable rights rather than domain admin ... Warren Brunk - MCITP - SQL 2005, ... Add it as a login to the SQL Server ... files, or backups, make sure that the service account has Full ...
    (microsoft.public.sqlserver.security)
  • Re: ASP.NET Process Identity???
    ... In the application I not need/want to create user accounts into SQL Server. ... To control the security I have created a personalized security system. ... you can switch back to normal ASPNET machine account for the ... >> Public Class Personificacion ...
    (microsoft.public.dotnet.security)
  • Re: SMS_MP_Control_Manager Errors
    ... A colleage of mine figure it out, it was "local security policy" problem, he ... IUSR_"Computer account" must be able to access the computer from the network. ... delete the Guests group from it. ... Verify that the SQL server is properly configured to ...
    (microsoft.public.sms.admin)
  • Re: User authentication
    ... There are 2 SQL Server 2005 ... 1 SQL Server 2000 installed on another server ... Windows account instead to run backup jobs. ...
    (microsoft.public.sqlserver.clients)