Massive SQL Server attack

From: Alfred (mas89@cornell.edu)
Date: 01/26/03


From: "Alfred" <mas89@cornell.edu>
Date: Sat, 25 Jan 2003 16:00:03 -0800


Clint,

My server was attacked and doesn't see the outside
anymore, what can I do to fix the problems this attack
caused?

Thanks,
-Alfred

>-----Original Message-----
>Just an FYI, there's a big SQL server attack going on
>right now. If you don't have SQL Server SP3 installed
then
>you most likely are vulnerable since the MS02-39 patch
>wasn't included in SP2 for SQL Server.
>
>http://www.microsoft.com/technet/security/bulletin/MS02-
>039.asp
>http://www.kb.cert.org/vuls/id/370308
>.
>



Relevant Pages

  • [NT] Web Browsers Vulnerable to the Extended HTML Form Attack
    ... inject HTML scripts, which makes use of the same method described in the ... The Original HTML form attack: ... server 7 open ...
    (Securiteam)
  • Re: Problem with one table - Connection Timeout
    ... If you don't know what the problem is you can't fix it. ... You don't know what the problem is because you can't get on the server to ... We were using linked tables and ODBC connection ... worst is that I don't have the admin access to the SQL Server to run ...
    (comp.databases.ms-access)
  • [UNIX] DoS Attack Against FreeRADIUS (Other RADIUS Servers Affected)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... to create a high-performance and highly configurable GPL'd RADIUS server. ... program with failed requests causing a denial of service attack. ... Access-Request to the RADIUS server, ...
    (Securiteam)
  • Re: I was hacked
    ... > I have a Windows 2000 server that is current w/ the latest patches from MS. ... > It is running an IIS server that is configured w/ Microsoft's URLScan tool. ... > It is also running Terminal Services w/ 128 bit encryption turned on. ... > the first visible process of the attack. ...
    (alt.computer.security)
  • Re: I was hacked
    ... > I have a Windows 2000 server that is current w/ the latest patches from MS. ... > It is running an IIS server that is configured w/ Microsoft's URLScan tool. ... > It is also running Terminal Services w/ 128 bit encryption turned on. ... > the first visible process of the attack. ...
    (microsoft.public.inetserver.iis.security)