Products that embed Microsoft Database Engine (MSDE) are vulnerable. I use Compaq Insight Manager (on thousands of servers!) which embeds MSDE, and thus vulnerable to the worm. I have contacted Compaq and there has still been no official statement acknowledging or denying the issue.
Compaq Insight Manager does not listen on port TCP/1433 (I expect other MSDE products may also listen on a different port). Does the Nessus script test all open ports to determine if they are MSDE? Or does it only look for port TCP/1433? Regards, Brian >From: Shane Williams <[EMAIL PROTECTED]> >Subject: Re: The SQLworm >Date: Thu, 30 May 2002 13:36:09 -0500 (CDT) > >On Thu, 30 May 2002, twig les wrote: > > > I suppose I'm just taking the lazy admins way out > > again, but I simply sniff my network looking for port > > 1433 crap. Since we don't allow it through the > > borders it would have to be coming from an inside > > host. Of course it's all pretty academic since we > > don't actually *have* a MSSql box. > >Keep in mind that there are MSSQL(like) systems embedded in other >software. Many are other MS products, but not all. Just something to >keep in mind. _________________________________________________________________ Chat with friends online, try MSN Messenger: http://messenger.msn.com
