Microsoft MSDE/SQL Server 2000 Desktop Engine Default Configuration Vulnerability
BID:4797
Info
Microsoft MSDE/SQL Server 2000 Desktop Engine Default Configuration Vulnerability
| Bugtraq ID: | 4797 |
| Class: | Configuration Error |
| CVE: |
CVE-2000-1209 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Credited to Adrian Romo of Quilogy. |
| Vulnerable: |
Optima Opty-Way Enterprise 1.0 Microsoft SQL Server 2000 Desktop Engine Microsoft MSDE 1.0 Compaq Open SAN Manager 1.0 c Compaq Insight Manager XE 2.2 Compaq Insight Manager XE 2.1 c Compaq Insight Manager XE 2.1 b Compaq Insight Manager XE 2.1 Compaq Insight Manager XE 1.21 Compaq Insight Manager XE 1.1 Compaq Insight Manager 7.0 SP1 Compaq Insight Manager 7.0 Avaya CentreVu Explorer II Avaya CentreVu / Nice Call Recording System 8.5 |
| Not Vulnerable: | |
Discussion
Microsoft MSDE/SQL Server 2000 Desktop Engine Default Configuration Vulnerability
It has been reported Microsoft MSDE and SQL Server 2000 Desktop Engine are configured by default with a null administrative password by default. Remote attackers may exploit this flaw to gain administrative access to the database if the password has not been manually changed.
Compaq Insight Manager XE versions 1.1 and later include the capability to use MSDE. MSDE is not installed as part of Compaq Insight Manager by default. When MSDE is installed via Compaq Insight Manager, it is recommended during that install that users change the 'sa' administrative password. Installs via Compaq Management CD or Insight Manager 7 softpaqs include no such recommendation.
It should be noted that a worm is currently propagating due to default null passwords in Microsoft SQL server and derived products such as MSDE and SQL Server 2000 Desktop Engine.
It has been reported Microsoft MSDE and SQL Server 2000 Desktop Engine are configured by default with a null administrative password by default. Remote attackers may exploit this flaw to gain administrative access to the database if the password has not been manually changed.
Compaq Insight Manager XE versions 1.1 and later include the capability to use MSDE. MSDE is not installed as part of Compaq Insight Manager by default. When MSDE is installed via Compaq Insight Manager, it is recommended during that install that users change the 'sa' administrative password. Installs via Compaq Management CD or Insight Manager 7 softpaqs include no such recommendation.
It should be noted that a worm is currently propagating due to default null passwords in Microsoft SQL server and derived products such as MSDE and SQL Server 2000 Desktop Engine.
Exploit / POC
Microsoft MSDE/SQL Server 2000 Desktop Engine Default Configuration Vulnerability
No exploit code is required.
No exploit code is required.
Solution / Fix
Microsoft MSDE/SQL Server 2000 Desktop Engine Default Configuration Vulnerability
Solution:
Avaya have released a security advisory that contains recommended actions to fix this issue in CentreVu Explorer II and CentreVu/Nice Call Recording System 8.5 and later. Please see the referenced advisory for further details.
Microsoft has released security recommendations for administrators of SQL server and related products. A link to this document is included in the links section of this record bulletin.
Some Compaq Insight Manager releases include the capability to use MSDE. If MSDE is installed, users are advised to ensure that the default null administrative password is changed. The service must be restarted for any changes to take effect.
HP has released a security advisory (HPSBMA01168) detailing a revision to the Compaq advisory SSRT2195. Please see the referenced advisory for further information.
Setting a hard-to-guess password will effectively eliminate this vulnerability.
A patch is available for Compaq Open SAN Manager:
Compaq Open SAN Manager 1.0 c
Solution:
Avaya have released a security advisory that contains recommended actions to fix this issue in CentreVu Explorer II and CentreVu/Nice Call Recording System 8.5 and later. Please see the referenced advisory for further details.
Microsoft has released security recommendations for administrators of SQL server and related products. A link to this document is included in the links section of this record bulletin.
Some Compaq Insight Manager releases include the capability to use MSDE. If MSDE is installed, users are advised to ensure that the default null administrative password is changed. The service must be restarted for any changes to take effect.
HP has released a security advisory (HPSBMA01168) detailing a revision to the Compaq advisory SSRT2195. Please see the referenced advisory for further information.
Setting a hard-to-guess password will effectively eliminate this vulnerability.
A patch is available for Compaq Open SAN Manager:
Compaq Open SAN Manager 1.0 c
References
Microsoft MSDE/SQL Server 2000 Desktop Engine Default Configuration Vulnerability
References:
References:
- Avaya Home Page (Avaya)
- Avaya Security Advisory: Avaya Products using Microsoft SQL Server (Avaya)
- Opty-Way Enterprise Homepage (Optima )
- Product Support Services Informational Alert on SQL Server (Microsoft)
- Q321081 Visio Installation of MSDE Creates an 'sa' Account with a Blank Password (Microsoft)
- Q322336 HOW TO: Verify and Change the System Administrator Password by Using MSD (Microsoft )