Security note: MS SQL is current worm vector

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Security note: MS SQL is current worm vector
Дата
Msg-id 2898.1006665617@sss.pgh.pa.us
обсуждение исходный текст
Ответы Re: Security note: MS SQL is current worm vector  (Lincoln Yeoh <lyeoh@pop.jaring.my>)
Re: Security note: MS SQL is current worm vector  ("Dalibor Andzakovic" <dali@dali.net.nz>)
Список pgsql-hackers
According to incidents.org, a new worm that infects MS SQL servers
is currently spreading fast, and it's being used to lauch distributed
denial-of-service attacks against various sites: see
http://www.incidents.org/diary/diary.php?id=82

The security flaw that the worm exploits is not, um, deep.  It seems
that Microsoft ships MS SQL with a default system-admin account having
the fixed name "sa" and no password.  If that hasn't been changed,
anyone can do anything they want using the server machine.

While Microsoft's carelessness about security is (justly) infamous,
I'm not as inclined to say "Redmond is a bunch of bozos" as "there
but for the grace of God go we".  This is a heads-up that security
issues *do* matter, even for databases.
        regards, tom lane


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: anoncvs busted (was Re: v7.2b3 packages rebuilt ...)
Следующее
От: Lincoln Yeoh
Дата:
Сообщение: Re: Security note: MS SQL is current worm vector