Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Warning!!!! MS SQL Worm on the loose

Thread Tools
 
Search this Thread
 
Old 22 May 2002, 07:06 AM
  #1  
Jeff Wiltshire
Scooby Regular
Thread Starter
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

There appears to be a self-propergating worm on the loose which attacks MS SQL servers on port 1433 by first pinging the port and then trying to logon with as SA using a blank password (the default config). It then runs a script to report back that the box has been rooted.

If you are running MS SQL make sure that you do the following

1. Make sure you block Internet access to TCP1433
2. Make sure you have a password on your SA account.
3. Disable TCP/IP Network Libraries if you're not using them.
4. Drop all eXtended Procedures (XP_) if you can.

More information as I get it.



Jeff
Old 22 May 2002, 07:20 AM
  #2  
mega_stream
Scooby Regular
 
mega_stream's Avatar
 
Join Date: May 2001
Location: Scotland
Posts: 4,580
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

A nice busy morning for me then
Cheers for the warning Jeff
Old 22 May 2002, 07:46 AM
  #3  
boomer
Scooby Senior
 
boomer's Avatar
 
Join Date: Feb 2000
Location: West Midlands
Posts: 5,763
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

Jeff,

i was just about to start a new topic with a question about the MS-SQL-S port, because i have been getting loads of firewall blocks happening recently (e.g. this morning only FIVE seconds after connecting!).

Seems like you have already answered my question

Thanks for the info, and let us know if you find out any more,

cheers,

mb

p.s. A blank default password? - madness [img]images/smilies/mad.gif[/img]
Old 22 May 2002, 08:08 AM
  #4  
Jeff Wiltshire
Scooby Regular
Thread Starter
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

It now appears that there are 2 seperate worms running around (do worms run ?). Both of them appear to be doing similar things. They both appear to have orginated from South Korea....!



Jeff
Old 22 May 2002, 08:14 AM
  #5  
Jeff Wiltshire
Scooby Regular
Thread Starter
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

If you want early warning of this type of event you should subscibe to DShield at
www.dshield.org



Jeff
Old 22 May 2002, 08:56 AM
  #6  
shunty
Scooby Regular
 
shunty's Avatar
 
Join Date: Aug 2001
Location: wakefield
Posts: 2,082
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

Jeff..thanks, that is very useful info

shunty
Old 22 May 2002, 09:44 AM
  #7  
Jeff Wiltshire
Scooby Regular
Thread Starter
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

About 4000 SQL machines have been compromised now....more info at

http://www.incidents.org/diary/diary.php?id=156

It will also infect versions of

Visio
Access
Project
Visual Studio 6

All of these have the ability to run a cut down version of SQL callled MSDE which installs without an SA password (!)



Jeff

[Edited by Jeff Wiltshire - 5/22/2002 9:47:46 AM]
Old 22 May 2002, 01:37 PM
  #8  
Jeff Wiltshire
Scooby Regular
Thread Starter
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

The AV vendors have started putting out updated files to detect this now.....

It turns out that this worm (SQLsnake) adds a guest account into your Domain Admin group as part of the script......



Jeff
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Frizzle-Dee
Essex Subaru Owners Club
13
09 March 2019 07:35 PM
dpb
Non Scooby Related
14
03 October 2015 10:37 AM
fumbduck
ScoobyNet General
18
29 September 2015 09:16 PM
charlesr
General Technical
9
28 September 2015 09:16 AM
TylerD529
Lighting and Other Electrical
5
20 September 2015 12:10 PM



Quick Reply: Warning!!!! MS SQL Worm on the loose



All times are GMT +1. The time now is 09:51 PM.