• RSS
  • Twitter
  • FaceBook

SQL Server worm exploits blank sa password

  • Section(s): Security, Security , Miscellaneous
  • Published on Apr 20, 2004.
  • Last Modified on Apr 20, 2004.
  • Last Modified by Wayne Maples.
  • Rated 4.3 out of 5 based on 4 votes.
Douglas Brown discovered a new worm that targets Microsoft SQL Server installations where the SQL Administrator password is blank (note that this is the default configuration for SQL Server v7.0 and earlier). The worm logs in using the Administrator account, then calls a command shell to FTP and install a Trojan. The Trojan communicates with the attacker via IRC, where the attacker is able to utilize the infected systems to launch Distributed Denial of Service (DDoS) attacks.

The original SecurityFocus Report: MS-SQL Worm?

SQL Server's default behavior of blank admin password is a disaster. If you want your network to be secure, automate a scan for port 1433, used by sql server, and check for sa admin accounts with blank passwords. By using SQL's command shell, a hacker (if you are unlucky) or penetration tester (if you are lucky) can take over the server. The extent of the exposure depends on what account sql service is running under. Some sites run the service using a domain admin account. Wonderful! If you can break the sa password, or if its blank, you can use the command shell to create a new account and add it to the domain administrator's group. A blank sa password can expose the entire enterprise.

Related Tips:

About Wayne Maples


Article not looking right or info is missing? Let us know so that we can fix it: .


Receive all the latest articles by email!

Receive Real-Time & Monthly WindowsNetworking.com article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become a WindowsNetworking.com member!

Discuss your network issues with thousands of other network administrators. Click here to join!

Community Area

Log in | Register

Readers' Choice

Which is your preferred Network Monitoring & Management solution?