eeye has released a free tool (windows only) that will scan a class C 
addressing on any port you specify for vulnerable sql boxes (this 
includes those running msde).  Another company called Whitebear 
Consulting sells a product (about $30US for single person use)  that 
will help in changing passwords (and it does a few other things) for 
places that have installed msde and do not know how or have a direct way 
to change the sa password.

John

Brian Anon wrote:

> Products that embed Microsoft Database Engine (MSDE) are vulnerable.
>
> I use Compaq Insight Manager (on thousands of servers!) which embeds 
> MSDE, and thus vulnerable to the worm.  I have contacted Compaq and 
> there has still been no official statement acknowledging or denying 
> the issue.
>
> Compaq Insight Manager does not listen on port TCP/1433 (I expect 
> other MSDE products may also listen on a different port).
>
> Does the Nessus script test all open ports to determine if they are 
> MSDE?  Or does it only look for port TCP/1433?
>
> Regards,
> Brian
>
>> From: Shane Williams <[EMAIL PROTECTED]>
>> Subject: Re: The SQLworm
>> Date: Thu, 30 May 2002 13:36:09 -0500 (CDT)
>>
>> On Thu, 30 May 2002, twig les wrote:
>>
>> > I suppose I'm just taking the lazy admins way out
>> > again, but I simply sniff my network looking for port
>> > 1433 crap.  Since we don't allow it through the
>> > borders it would have to be coming from an inside
>> > host.  Of course it's all pretty academic since we
>> > don't actually *have* a MSSql box.
>>
>> Keep in mind that there are MSSQL(like) systems embedded in other
>> software.  Many are other MS products, but not all.  Just something to
>> keep in mind.
>
>
> _________________________________________________________________
> Chat with friends online, try MSN Messenger: http://messenger.msn.com
>
>



Reply via email to