eeye has released a free tool (windows only) that will scan a class C addressing on any port you specify for vulnerable sql boxes (this includes those running msde). Another company called Whitebear Consulting sells a product (about $30US for single person use) that will help in changing passwords (and it does a few other things) for places that have installed msde and do not know how or have a direct way to change the sa password.
John Brian Anon wrote: > Products that embed Microsoft Database Engine (MSDE) are vulnerable. > > I use Compaq Insight Manager (on thousands of servers!) which embeds > MSDE, and thus vulnerable to the worm. I have contacted Compaq and > there has still been no official statement acknowledging or denying > the issue. > > Compaq Insight Manager does not listen on port TCP/1433 (I expect > other MSDE products may also listen on a different port). > > Does the Nessus script test all open ports to determine if they are > MSDE? Or does it only look for port TCP/1433? > > Regards, > Brian > >> From: Shane Williams <[EMAIL PROTECTED]> >> Subject: Re: The SQLworm >> Date: Thu, 30 May 2002 13:36:09 -0500 (CDT) >> >> On Thu, 30 May 2002, twig les wrote: >> >> > I suppose I'm just taking the lazy admins way out >> > again, but I simply sniff my network looking for port >> > 1433 crap. Since we don't allow it through the >> > borders it would have to be coming from an inside >> > host. Of course it's all pretty academic since we >> > don't actually *have* a MSSql box. >> >> Keep in mind that there are MSSQL(like) systems embedded in other >> software. Many are other MS products, but not all. Just something to >> keep in mind. > > > _________________________________________________________________ > Chat with friends online, try MSN Messenger: http://messenger.msn.com > >
