Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




Security Incidents mailing list archives

RE: Strange scan on 1433
From: "Blake Frantz" <blake () mc net>
Date: Tue, 21 May 2002 11:46:49 -0500

-----Original Message-----
From: David LaPorte [mailto:david_laporte () harvard edu] 
Sent: Tuesday, May 21, 2002 10:23 AM
To: Pavel Lozhkin; incidents () securityfocus com
Subject: RE: Strange scan on 1433

They're looking for MS-SQL servers with blank/default sa passwords that
are missing the MS02-020 



It's not limited to *blank* sa passwords:

From: http://www.incidents.org/diary/diary.php?id=156

<snip>
IMPORTANT ADDITION (thanks to George Bakos, ISTS for pointing this out):
The worm includes code to brute force the SA password. Using a password
larger than 8 characters, or a password containing non alphanumeric 
characters (punktuation) will defend against this brute forcing.
</snip>

Additionally, roelof () sensepost com / haroon () sensepost com from sensepost
wrote a .pl for finding blank sa passwords.  Some may find it useful.
http://www.sensepost.com/misc/SQLinsertion.htm

-Blake


----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]