All the latest UK technology news, reviews and analysis

MS server port under hack attack

by James Middleton

21 May 2002

Be the first to comment

  • Tweet this

Security watchers have warned of a huge increase in the number of connection attempts made on port 1433, the Microsoft SQL server port, in the last 24 hours.

An advisory released this morning by security firm Trend Micro said that the significant increase in connection attempts could signify hack attacks.

The company said that firewall logs at customer sites revealed that the attacks started to rocket yesterday (May 20).

Indeed, a quick glance at the "top ten ports under attack" list on the Sans Institute's Internet Storm Centre website shows port 1433 at number five.

Connection attempts on the Microsoft SQL server port usually number between zero and three per cent, according to the Internet Storm Centre, but yesterday they leapt into the red at 57 per cent.

"The connection attempts look like a hacking attack; at first a MSSQL handshake is transferred, which is not unusual," said the Trend Micro advisory. "But afterwards, a second packet is sent, and this packet is an attempt to login to the MSSQL server, using the account name 'sa' and an empty password. This is the default authentication set-up for MSSQL installation."

Neither the source of these attacks nor the motives behind them have yet been determined. But the increase in attacks on port 1433 should serve as a warning to administrators to check the security of SQL server installations.

On 17 April, Microsoft issued an advisory about an unchecked buffer in extended procedure functions in the SQL server that could have allowed attackers to run arbitrary code on the system.

It is possible that this latest attack could have been carried out by someone looking to exploit this vulnerability.

More details can be found here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

27%

1%

11%

61%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Buyer/Procurement Specialist

Buyer/Procurement Specialist x 8 £30,000 - £40...

Systems Analyst/Architect

Systems Analyst/Architect £30,000 - £40,000 + excellent...

Software Developer

Software Developer Up to £27,000 + excellent...

Software Engineer/Developer (C#, C++)

Software Engineer/Developer (C++) £25,000 - £40...

To send to more than one email address, simply separate each address with a comma.