ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Server platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Automated worm attacks MS SQL Server

John McCormick

Published: 05 Jun 2002 14:09 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Details
The Incidentes.org (SANS Institute) report on this worm lists the following files as being enclosed in SQLSnake:drivers/services.exe -- Foundstone's fscan.exe (UPX packed)
clemail.exe
pwdump2.exe
run.js
samdump.dll
sqldir.js
sqlexec.js
sqlinstall.bat
sqlprocess.js
timer.dll

According to a CNET News Report, within two days of the worm's appearance, 2,450 SQL servers had been infected and 74,000 had been targeted for attack.

The following sources also have advisories or reports on the SQLSnake worm:

Final word
Once again, IT pros will probably direct most of the blame for this attack at Microsoft for configuring poor defaults on earlier versions of SQL Server. But in this instance, the company's big mistake was relying on administrators to install its software with a minimum of common sense by altering the default installation password.

Even if only a small percentage of users have failed to properly secure their systems, this will still be a dangerous worm because Microsoft SQL database has a large market share, especially in small to midsize businesses.

To make matters worse, this isn't some newly discovered problem. Several previous warnings have been issued, including at least one directly from Microsoft, telling SQL Server admins that they need to set passwords on the sa account. For those who have missed or ignored earlier warnings, it's definitely time to get around to fixing this problem.


Have your say instantly in the Tech Update forum.

Find out what's where in the new Tech Update with our Guided Tour.

Let the editors know what you think in the Mailroom.

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
94 out of 189 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:
















Related Jobs

Senior SQL Server DBA Oxfordshire - 40-45k + Bens

A fantastic opportunity has come about for a Senior SQL Server Database Administrator to join a global provider of Supplier Management Software ...

SAN Systems Administrator

Storage Management Team Responsibilities:- SAN Configuration Zoning / Masking / Switch & port configuration Storage Allocation Port allocation ...

Systems Administrator (CCTV)

The key tasks of the Systems Administrator (CCTV) will include; providing technical administration support for the City of London Police systems ...