Warning about serious vulnerabilities in SQL Server
Microsoft has announced yesterday that an attack code has been issued aimed at a serious vulnerability in previous versions of its SQL Server database software, besides Microsoft. It also advises users to use this temporary solution.
This security error was first reported to Microsoft in April 2008 by an Austrian security consulting company called SEC Consult. However, the company says it can't wait for Microsoft to decide when to release the patch and has revealed the flaw in the past two weeks with the release of proof-of-concept exploit code.
According to SEC Consult, Microsoft may already have a patch ready in the last three months but has not released a patch yet.
On Microsoft, in a security advisory released on Monday, Microsoft also said that systems running SQL Server 2000, SQL Server 2005, SQL Server 2005 Express Edition, and SQL Server 2000 Desktop Engine (MSDE 2000), Microsoft SQL Server 2000 Desktop Engine (WMSDE) and Windows Internal Database (WYukon) can be exploited and controlled by hackers.
This error has been detected in the SQL Server "sp_replwritetovarbin" extension stored procedure.
However, recent versions of this popular software, used for many Web sites to provide more power to their back-end databases, are not attacked. These versions include SQL Server 7.0 Service Pack 4 (SP4), SQL Server 2005 SP3 and SQL Server 2008. The latest, most recent version of this product line has been released to manufacturers from the end. August.
As the previous moves, Microsoft has taken actions to reduce their losses. 'We already know the exploit code is published on the Internet. Still, it has not been seen about any attacks trying to use the reported vulnerability, 'said company spokesman Bill Sisk in an email Monday.
Attackers can exploit this vulnerability remotely if they are able to increase access to the server through SQL injection attacks on the Web application on the system, Sisk said.
SQL injection attacks were successful; Hackers have taken control to compromise a large number of sites, even famous commercial domain names, with such attacks. Thousands of legitimate sites have been hacked through SQL injection attacks in recent weeks by criminal organizations, after which hackers have plugged fake code into their pages and attacked visitors. Use Internet Explorer (IE). In this security flaw, Microsoft blocked the flaw in IE last Wednesday with a second emergency patch within two months.
Microsoft has said that refusing the terms for the "sp_replwritetovarbin" extension stored procedures will create a vulnerability for the system, and also provide instructions on how to implement against attacks. this.
However, Sisk did not commit a fix or a timeline to the fix, but he proved - 'Microsoft will continue to study the flaw and proceed to finalize this research, in the process. Research, the company will take appropriate actions' - typical instructions at some point for the patch.
However, SEC Consult has made claims to Microsoft to complete the revision in September.
The Vienna-based company published the vulnerability in 9.12 through a published information, along with a sample attack code in an advisory section on their site, as well as several secure mailing lists: Bugtraq and Full Disclosure.
Also in this disclosure, SEC Consult said that it was announced by Microsoft in September via a mail that the patch has been completed. However, 'The release schedule for this fix has not been announced'.
This Austrian security company also included a timeline reflecting communication between the company and Microsoft. At that time table, SEC Consult reported this vulnerability to Microsoft on April 17, 2008 and the most recent response from Microsoft was on September 29. Four times since then 14.10, 29.10, 12.11 and 28.11 - SEC Consult questioned Microsoft about the patch upgrade but never received feedback from Microsoft.
Microsoft did not respond to SEC Consult's questions about the availability of its patch and timeline.
You should read it
- Chrome and Firefox have a serious security flaw, there is no way to fix it
- Firefox 56 released with a new screen capture, settings panel
- How to enable Tor features in Firefox increases security when browsing the web
- Summarizing the Pwn2Own 2019: Safari, VirtualBox was 'pierced' on the first day, Firefox, Edge on the second day and Tesla Model 3 'closed the window'
- Download Firefox 58 for Windows, Mac and Linux
- Firefox 16 was released again after updating the vulnerability patch
- Microsoft urgently fixes SQL Server errors
- The unsafe 'feature' on UC Browser allows hackers to take control of Android phones remotely
May be interested
- The Mail app on iOS has serious vulnerabilitiessecurity researchers at zecops have discovered two serious vulnerabilities that exist on the default mail application pre-installed on millions of iphones and ipads.
- The first warning about malicious code hidden in the .zip filesecurity researchers have discovered vulnerabilities in common file formats, including .zip.
- The difference between web server and app serveryou have probably seen that the terms web server and app server are often used interchangeably as if they are related to the same thing and also facilitate the website to function properly. but in reality, they are not the same.
- Warning: The number of vulnerabilities in open source software are increasing rapidlybesides malware, spam emails or ddos attacks, vulnerabilities in open source software are also considered as one of the most significant security threats at the moment.
- Microsoft expert discovered a series of serious code execution errors in IoT, OT devicesmicrosoft security researchers announced that they discovered more than two dozen serious remote code execution (rce) vulnerabilities related to internet of things (iot) and operational technology (ot) devices being used. relatively popular use today.
- Network basics: Part 3 - DNS Servera dns server is a server that contains a database of public ip addresses and hostnames associated with them. in most cases, the dns server is used to resolve or translate those common names into ip addresses as required.
- More than 70,000 Memcached servers are still capable of being hacked remotelynothing in this world is 100% safe, from the real world to cyberspace. the vulnerabilities are troublesome but worse than that, we didn't update the patches in time.
- New dangerous vulnerability in Intel CPU: Works like Specter and Meltdown, threatening all PCs and the cloudan extremely serious new class of intel chip vulnerabilities has been discovered by security researchers at graz university of technology, if successful exploitation of the bad guys can take advantage of it to steal sensitive information online. next from the processor.
- Warning of dangerous vulnerabilities on WinRAR, users should uninstall or upgrade to a new versionrarlab, the developer of winrar, has just released an urgent update to patch a dangerous vulnerability in their software.
- Windows Server 2003 died after July 14microsoft announced it would stop supporting windows server 2003 from july 14, before windows 10 officially launched two weeks.