Microsoft SQL Server Login Weak Authentication Mechanism
BID:6097
Info
Microsoft SQL Server Login Weak Authentication Mechanism
| Bugtraq ID: | 6097 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 02 2002 12:00AM |
| Updated: | Nov 02 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to David Litchfield. |
| Vulnerable: |
Microsoft SQL Server 2000 SP2 Microsoft SQL Server 2000 SP1 Microsoft SQL Server 2000 Microsoft SQL Server 7.0 SP4 Microsoft SQL Server 7.0 SP3 Microsoft SQL Server 7.0 SP2 Microsoft SQL Server 7.0 SP1 Microsoft SQL Server 7.0 Microsoft SQL Server 6.5 Microsoft SQL Server 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft SQL Server Login Weak Authentication Mechanism
Reportedly, passwords used for SQL Server Logins are sent across the network using a weak obfuscation algorithm.
An attacker can exploit this weakness to sniff network traffic to obtain SQL Server user and related password authentication credentials.
Reportedly, passwords used for SQL Server Logins are sent across the network using a weak obfuscation algorithm.
An attacker can exploit this weakness to sniff network traffic to obtain SQL Server user and related password authentication credentials.
Exploit / POC
Microsoft SQL Server Login Weak Authentication Mechanism
There is no exploit code required.
There is no exploit code required.
References
Microsoft SQL Server Login Weak Authentication Mechanism
References:
References:
- Chapter 5 - Microsoft SQL Server 2000 Security (Microsoft)
- Weak Password Encryption Scheme in MS SQL Server ("K. K. Mookhey"
)