I too saw this posted on mailing.unix.bugtraq.  

>From looking at the plugin source, it appears that when the first packet
(the 'hello' packet) is sent to MS SQL Server, if you replace the usual
identifying string, "MSSQLServer", with a large string of garbage,
something bad happens. :-)  My guess is the usual buffer overflow, so if
the string of 'garbage' is instead a string of commands or the like,
then your server is in trouble.  I don't have access to a MSSQL server
to test it though.

The plugin mentions that to thoroughly test, you also need to check the
resolver service (port 1434) for ports of other MS SQL server instances
on the same machine and test them as well.  Right now, only the default
port of 1433 is tested.



After a quick look at the plugin source

On Thu, 2002-08-08 at 15:04, Datdamwuf of wolf wrote:
> Can someone help me identify this plugin and possible
mitigation/resolution? 
>   There is nothing identifying the vuln and I can't find any refs to
it on 
> MS or other sites so I don't know how to verify it.  The solution is
not 
> possible, have to run SQL server....plugin info below.  Any help 
> appreciated!
> 
> Family:  Windows
> Plugin:  Microsoft's SQL Hello Overflow
> Author:  Dave Aitel
> 
> Description:
> The remote MS SQL server is vulnerable to the Hello overflow.
> 
> An attacker may use this flaw to execute commands against
> the remote host as LOCAL/SYSTEM,
> as well as read your database content.
> 
> Solution : disable this service (Microsoft SQL Server).
> 
> Risk factor : High
> 
> TIA,
> Diana
> 
> _________________________________________________________________
> MSN Photos is the easiest way to share and print your photos: 
> http://photos.msn.com/support/worldwide.aspx
> 
> -
> [EMAIL PROTECTED]: general discussions about Nessus.
> * To unsubscribe, send a mail to [EMAIL PROTECTED] with
> "unsubscribe nessus" in the body.


-
[EMAIL PROTECTED]: general discussions about Nessus.
* To unsubscribe, send a mail to [EMAIL PROTECTED] with
"unsubscribe nessus" in the body.

Reply via email to