Insecure Default Installation Process for Microsoft SQL Server
A vulnerability exists in SQL Server 2000 and SQL Server 7.0 (including MSDE 1.0) that can let an attacker compromise the vulnerable server.
July 14, 2002
Reported July 11, 2002, byMicrosoft.
VERSIONS AFFECTED
· Microsoft SQL Server 2000, all editions.
· Microsoft SQL Server 7.0, including Microsoft Data Engine (MSDE1.0)
DESCRIPTION
A vulnerability exists in SQLServer 2000 and SQL Server 7.0 (including MSDE 1.0) that can let an attackercompromise the vulnerable server. This vulnerability stems from the fact thatthe system stores the systems administrator password in the setup.iss and logfiles and doesn't remove the password when the installation is complete. Anyonecapable of doing an interactive logon can access this password and these files.
VENDOR RESPONSE
Thevendor, Microsoft, has released SecurityBulletin MS02-035(SQL Server Installation Process May Leave Password on System) to address thisvulnerability and recommends that affected users download and apply theappropriate patch mentioned in the bulletin. These patches are cumulative andaddress all previously discovered vulnerabilities in the affected product.
CREDIT
Discovered by CesarCerrudo and Mark Litchfieldof Next Generation Security Software.
Read more about:
MicrosoftAbout the Author
You May Also Like