Re: SQL 2000 Server gets hacked

From: Beth Breidenbach (beth.breidenbach@getronics.com)
Date: 01/02/03


From: "Beth Breidenbach" <beth.breidenbach@getronics.com>
Date: Thu, 2 Jan 2003 09:52:15 -0800


The hole could be from any number of areas, many of which have nothing to do
with service pack and patch levels. You'll need to give us more
information....

1) Is the box itself accessible to the Internet?

2) Does the database accept queries from any website?

3) Have you configured your box with protection in mind (which is
different than just applying patches -- see www.sqlsecurity.com for a
checklist of things to lock down)?

Beth

"Wilhelm Seucan" <ws@centron.de> wrote in message
news:av1sv1$r93$06$1@news.t-online.com...
> Hi,
>
> we have a SQL 2000 Server with SP2 and the latest Patch installed.
> Some hackers are able to penetrate the server and install hidden FTP
> Programs.
>
> Anyone an idea where the security hole in MS SQL Server is?
>
> Thanks.
>
> William
>
>



Relevant Pages

  • Re: MSAccess ADO database via Internet
    ... > a hole in the filewall and punched on through.. ... > It is both possible and easy to connect to a server database (SQL Server ...
    (borland.public.delphi.database.ado)
  • RE: Iptables Clues and Advices.
    ... >it will also result into a mess, because the server will be a ... >hole in space (regarding the blocked ports). ...
    (Security-Basics)
  • Re: FS: Bunch of WPC game specific small parts
    ... You don't have permission to access /stuff/rsradio1.jpg on this server. ... Whitewater Bigfoot Cave plastic mountain - $5 ... Small hole in each one as pictured, mount towards the back and no one ... Bunch of promo and game specific plastics. ...
    (rec.games.pinball)
  • Re: Cannot connect client to SBS 2003 server
    ... > allowed the server to do it. ... > You need the comcast suffix like you need a hole in the head. ... >> 3) manually pointed my client to the server for DNS. ...
    (microsoft.public.windows.server.sbs)
  • Re: Comprimised Linux server!
    ... Instead spending days trying to find the perpetrators and then ... downtime and no customers lost. ... You boat has a hole in it. ... from the server to look around, ...
    (comp.os.linux.security)