l i n u x - u s e r s - g r o u p - o f - d a v i s
L U G O D
 
Next Meeting:
April 21: Google Glass
Next Installfest:
TBD
Latest News:
Mar. 18: Google Glass at LUGOD's April meeting
Page last updated:
2003 Jan 25 21:37

The following is an archive of a post made to our 'vox mailing list' by one of its subscribers.

Report this post as spam:

(Enter your email address)
Re: [vox] OT: Hole in MS SQL server (unpatched)
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [vox] OT: Hole in MS SQL server (unpatched)



on Sat, Jan 25, 2003 at 04:13:22PM -0800, Rick Moen (rick@linuxmafia.com) wrote:
> Quoting Karsten M. Self (kmself@ix.netcom.com):
> 
> > Several friends have noted that routing has been seriously disrupted,
> > though this may actually predate the MSSQL worm.  One thought is that
> > some ISPs may backend their DNS on MS SQL.  That's sourced straight out
> > of /dev/ass, anyone know if there might be some merit to this
> > hypothesis?
> 
> This hypothetical threat mode would involve not only back-ending against
> MS SQL Server, but also directly exposing that database to the Internet.
> The one certainly doesn't require the other -- and taking the latter
> step would be,... um, contraindicated, on general grounds, even without
> the current vulnerability to highlight why.

Hmm.  Exposing the DNS DB to an exposed/infected instance would seem to be
sufficient.  Not that this is indeed the case.  But my interest is
piqued.

Peace.

-- 
Karsten M. Self <kmself@ix.netcom.com>        http://kmself.home.netcom.com/
 What Part of "Gestalt" don't you understand?
   Iomega:  click of death, Jaz Junk, and now, NAS?  Not!
     http://www.google.com/search?q=iomega+jaz+drive+failure
_______________________________________________
vox mailing list
vox@lists.lugod.org
http://lists.lugod.org/mailman/listinfo/vox



LinkedIn
LUGOD Group on LinkedIn
Sign up for LUGOD event announcements
Your email address:
facebook
LUGOD Group on Facebook
'Like' LUGOD on Facebook:

Hosting provided by:
Sunset Systems
Sunset Systems offers preconfigured Linux systems, remote system administration and custom software development.

LUGOD: Linux Users' Group of Davis
PO Box 2082, Davis, CA 95617
Contact Us

LUGOD is a 501(c)7 non-profit organization
based in Davis, California
and serving the Sacramento area.
"Linux" is a trademark of Linus Torvalds.

Sponsored in part by:
Appahost Applications
For a significant contribution towards our projector, and a generous donation to allow us to continue meeting at the Davis Library.