On Thursday 08 August 2002 15:04, Datdamwuf of wolf wrote:
> Can someone help me identify this plugin and possible
> mitigation/resolution? There is nothing identifying the vuln and I
> can't find any refs to it on MS or other sites so I don't know how to
> verify it.  The solution is not possible, have to run SQL
> server....plugin info below.  Any help appreciated!


I think the plugin refers to:

http://www.microsoft.com/technet/security/bulletin/MS02-039.asp

The Bugtraq post really didn't contain enough information to fix the 
problem since neither the MSB or CVE ID was referenced. SQL Server has 
always had a ton of problems in the TCP listener, just the majority of 
the will take down the service and hence can't be tested for in a live 
environment... Maybe we need to write a plugin which does "banner checks" 
of against the output of mssql_ping.nasl (since the version number is 
available there). Not perfect, but at least it would allow people to test 
machines without taking down their operations...

Dave Aitel's Original Post
============
SPIKE 2.5 is now available at http:/www.immunitysec.com/spike.html

This release (see the "audits" directory) includes:
  o one new remotely exploitable pre-auth bug on all versions of
Microsoft SQL Server. I call it the "Hello" bug as in "You had me at
hello" since the overflow occurs during the first possible opportunity.
For reference, the bug itself is on TCP port 1433, and is a remote
SYSTEM bug in the default configurations tested. There are some
restrictions on the process's access token, but this is easily taken
care of in many ways. 



Dave's Follow-Up Bugtraq Post
====================
Since people seem unable to type: export LD_LIBRARY_PATH=. ;
./generic_send_tcp target 1433 audits/MSSQL/mssql.spk; I've attached a
NASL script that will also demonstrate the vulnerability. It even has
the correct ID number and will soon be available from the Nessus
homepage as well, for those of you who do a daily auto-update.

I'm not, however, planning to release NASL scripts for the Exchange 2000
vulnerabilities, nor do I plan to release a working exploit for the SQL
Server vulnerability (except to Immunity, Inc. larger customers, who
have access to all of Immunity's ongoing research.) 

-
[EMAIL PROTECTED]: general discussions about Nessus.
* To unsubscribe, send a mail to [EMAIL PROTECTED] with
"unsubscribe nessus" in the body.

Reply via email to