Fortsatt mildväder över nyår SvD Inrikes(cached at December 26, 2013, 11:32 pm)

Ivrig att testa julklappsskidorna? Tyvärr hänger mildvädret kvar ett tag till.
Default configuration check for Microsoft SQL Server - Taking advantage of quiet day SANS Internet Storm Center, InfoCON: green(cached at December 26, 2013, 11:30 pm)

This time of the year is pretty good in companies. Many people are enjoying the holidays, there's not that many problems in day-to-day job and everything is quiet. Perfect time of the year to perform some default configuration check that might be used by an attacker to compromise windows servers, data and any other information asset within the domain.

There's a pretty old extended stored procedure available in Microsoft SQL Server called xp_cmdshell. This procedure allows to execute commands in the operating system with the same rights as the Microsoft SQL Server service account. The procedure is pretty insecure and as of today is disable by default. It is used by many developers as a shortcut to easily develop distributed applications by invoking external applications and passing arguments as plain-text files.

So, what's the vulnerability? If you instruct your developers to always place a password to the SA user on their machines and tell them not to use xp_cmdshell, you are fine. Otherwise, people could connect to the Microsoft SQL Server instance using utilities like sqlcmd and execute commands like user creation and user group modification to add it to the administrators group.

How can you tell if there are Microsoft SQL Instances with a blank password for the SA user? You can take advantage of the ms-sql-empty-password nmap script. This script allows to perform a quick check in your network for that vulnerability. For example, if you want to check the empty password for the 192.168.0.0/24 network, you only need to execute the following command: nmap -p 1433 --script ms-sql-empty-password --script-args mssql.instance-all 192.168.0.0/24.

If you get any outputs like the following:

Nmap scan report for 192.168.0.144
Host is up (0.00s latency).
PORT     STATE  SERVICE
1433/tcp open ms-sql-s

Host script results:
| ms-sql-empty-password:
|   [192.168.0.144\MSSQLSERVER]
|_    sa:<empty> => Login Success

 

That means the computer has the vulnerability. If you can execute the following command successfully without any errors, you might be prone to other nasty vulnerabilities like windows local user creation, adding users to the windows Administrators group, changing windows user passwords, among many others:

sqlcmd -q "exec xp_cmdshell 'dir c:\'"

So, what do we need to enforce to prevent this problems? First, ensure that the SA user has a password by placing it. Second, disable the xp_cmdshell if you don't need it.

Manuel Humberto Santander Peláez
SANS Internet Storm Center - Handler
Twitter: @manuelsantander
Web:http://manuel.santander.name
e-mail: msantand at isc dot sans dot org

(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Obama undertecknar försvaranslag SvD Utrikes(cached at December 26, 2013, 11:02 pm)

USA:s president Barack Obama har undertecknat försvarsbudgeten för 2014.
Obama undertecknar försvaranslag SvD Utrikes(cached at December 26, 2013, 11:02 pm)

USA:s president Barack Obama har undertecknat försvarsbudgeten för 2014.
Houston Expands Downtown Surveillance, Unsure If It Helps Slashdotby timothy on crime at January 1, 1970, 1:00 am (cached at December 26, 2013, 11:02 pm)

SpaceGhost writes "The Associated Press reports that the Houston (Texas) Police will be adding 180 surveillance cameras in the downtown area, bringing the total to close to 1000. While most cover public areas (stadiums, theater district) the police suggest that Houston also has more 'critical infrastructure' (energy companies) than other cities. Interestingly AP points out that 'Officials say data is not kept to determine if the cameras are driving down crime.' Didn't London face the same issue?"

Read more of this story at Slashdot.








CVE-2013-6795 (Natl. Vulnerability Database) SANS ISC SecNewsFeed(cached at December 26, 2013, 11:00 pm)

Rebeller har tagit över flera oljekällor SvD Utrikes(cached at December 26, 2013, 10:32 pm)

90 000 människor har flytt de senaste tio dagarna.
Rebeller har tagit över flera oljekällor SvD Utrikes(cached at December 26, 2013, 10:32 pm)

90 000 människor har flytt de senaste tio dagarna.
Dom om barnsexövergrepp upphävs SvD Utrikes(cached at December 26, 2013, 10:32 pm)

Domen mot en anställd i katolska kyrkan som hållit tyst om en barnsexskandal har upphävts av en appellationsdomstol i Pennsylvania.
Dom om barnsexövergrepp upphävs SvD Utrikes(cached at December 26, 2013, 10:32 pm)

Domen mot en anställd i katolska kyrkan som hållit tyst om en barnsexskandal har upphävts av en appellationsdomstol i Pennsylvania.
Antarctic Climate Research Expedition Trapped In Sea Ice Slashdotby timothy on earth at January 1, 1970, 1:00 am (cached at December 26, 2013, 10:32 pm)

First time accepted submitter Stinky Cheese Man writes "An Antarctic climate research expedition, led by climate researcher Chris Turney of the University of New South Wales, has become trapped in heavy ice near the coast of Antarctica. The captain has issued a distress call and three nearby icebreaker ships are on their way to the rescue. According to Turney's web site, the purpose of the expedition is 'to discover and communicate the environmental changes taking place in the south.'"

Read more of this story at Slashdot.








Allt friare Burma ger tidningsboom SvD Utrikes(cached at December 26, 2013, 10:03 pm)

Plötsligt finns 15 dagstidningar.
Allt friare Burma ger tidningsboom SvD Utrikes(cached at December 26, 2013, 10:03 pm)

Plötsligt finns 15 dagstidningar.
Mest utevåld i huvudstaden SvD Inrikes(cached at December 26, 2013, 10:02 pm)

I Stockholm och Sörmland är misshandel ute på stan vanligast i landet i förhållande till hur många som bor i länet, skriver svd.
Business-OnlinePayment-Braintree-0.003 search.cpan.orgby Stefan Hornburg (Racke) at January 1, 1970, 1:00 am (cached at December 26, 2013, 10:02 pm)

Online payment processing through Braintree