subject: (Fwd) RE: Strange scan on 1433
posted: Wed, 22 May 2002 23:45:38 +0100


fix for sqlsnake/sql spider

------- Forwarded message follows -------
From: "Blake Frantz" <[email protected]>
To: <[email protected]>, "'Pavel Lozhkin'" <[email protected]>,
<[email protected]>
Subject: RE: Strange scan on 1433
Date sent: Tue, 21 May 2002 11:46:49 -0500

[ Double-click this line for list subscription options ]

>-----Original Message-----
>From: David LaPorte [mailto:[email protected]]
>Sent: Tuesday, May 21, 2002 10:23 AM
>To: Pavel Lozhkin; [email protected]
>Subject: RE: Strange scan on 1433
>
>They're looking for MS-SQL servers with blank/default sa passwords that
are missing the MS02-020
>
>

It's not limited to *blank* sa passwords:

From: http://www.incidents.org/diary/diary.php?id=156


IMPORTANT ADDITION (thanks to George Bakos, ISTS for pointing this out):
The worm includes code to brute force the SA password. Using a password
larger than 8 characters, or a password containing non alphanumeric
characters (punktuation) will defend against this brute forcing.


Additionally, [email protected] / [email protected] from sensepost
wrote a .pl for finding blank sa passwords. Some may find it useful.
http://www.sensepost.com/misc/SQLinsertion.htm

-Blake


----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com
------- End of forwarded message -------

generated by msg2page 0.06 on Jul 21, 2006 at 19:04:39

 search: