I too saw this posted on mailing.unix.bugtraq. >From looking at the plugin source, it appears that when the first packet (the 'hello' packet) is sent to MS SQL Server, if you replace the usual identifying string, "MSSQLServer", with a large string of garbage, something bad happens. :-) My guess is the usual buffer overflow, so if the string of 'garbage' is instead a string of commands or the like, then your server is in trouble. I don't have access to a MSSQL server to test it though.
The plugin mentions that to thoroughly test, you also need to check the resolver service (port 1434) for ports of other MS SQL server instances on the same machine and test them as well. Right now, only the default port of 1433 is tested. After a quick look at the plugin source On Thu, 2002-08-08 at 15:04, Datdamwuf of wolf wrote: > Can someone help me identify this plugin and possible mitigation/resolution? > There is nothing identifying the vuln and I can't find any refs to it on > MS or other sites so I don't know how to verify it. The solution is not > possible, have to run SQL server....plugin info below. Any help > appreciated! > > Family: Windows > Plugin: Microsoft's SQL Hello Overflow > Author: Dave Aitel > > Description: > The remote MS SQL server is vulnerable to the Hello overflow. > > An attacker may use this flaw to execute commands against > the remote host as LOCAL/SYSTEM, > as well as read your database content. > > Solution : disable this service (Microsoft SQL Server). > > Risk factor : High > > TIA, > Diana > > _________________________________________________________________ > MSN Photos is the easiest way to share and print your photos: > http://photos.msn.com/support/worldwide.aspx > > - > [EMAIL PROTECTED]: general discussions about Nessus. > * To unsubscribe, send a mail to [EMAIL PROTECTED] with > "unsubscribe nessus" in the body. - [EMAIL PROTECTED]: general discussions about Nessus. * To unsubscribe, send a mail to [EMAIL PROTECTED] with "unsubscribe nessus" in the body.
