On Thursday 08 August 2002 15:04, Datdamwuf of wolf wrote: > Can someone help me identify this plugin and possible > mitigation/resolution? There is nothing identifying the vuln and I > can't find any refs to it on MS or other sites so I don't know how to > verify it. The solution is not possible, have to run SQL > server....plugin info below. Any help appreciated!
I think the plugin refers to: http://www.microsoft.com/technet/security/bulletin/MS02-039.asp The Bugtraq post really didn't contain enough information to fix the problem since neither the MSB or CVE ID was referenced. SQL Server has always had a ton of problems in the TCP listener, just the majority of the will take down the service and hence can't be tested for in a live environment... Maybe we need to write a plugin which does "banner checks" of against the output of mssql_ping.nasl (since the version number is available there). Not perfect, but at least it would allow people to test machines without taking down their operations... Dave Aitel's Original Post ============ SPIKE 2.5 is now available at http:/www.immunitysec.com/spike.html This release (see the "audits" directory) includes: o one new remotely exploitable pre-auth bug on all versions of Microsoft SQL Server. I call it the "Hello" bug as in "You had me at hello" since the overflow occurs during the first possible opportunity. For reference, the bug itself is on TCP port 1433, and is a remote SYSTEM bug in the default configurations tested. There are some restrictions on the process's access token, but this is easily taken care of in many ways. Dave's Follow-Up Bugtraq Post ==================== Since people seem unable to type: export LD_LIBRARY_PATH=. ; ./generic_send_tcp target 1433 audits/MSSQL/mssql.spk; I've attached a NASL script that will also demonstrate the vulnerability. It even has the correct ID number and will soon be available from the Nessus homepage as well, for those of you who do a daily auto-update. I'm not, however, planning to release NASL scripts for the Exchange 2000 vulnerabilities, nor do I plan to release a working exploit for the SQL Server vulnerability (except to Immunity, Inc. larger customers, who have access to all of Immunity's ongoing research.) - [EMAIL PROTECTED]: general discussions about Nessus. * To unsubscribe, send a mail to [EMAIL PROTECTED] with "unsubscribe nessus" in the body.
