I've just downloaded all 111MB of Compaq Insight Manager 7 SP1 and installed it on one of my Compaq machines. When you run the install it has a text based menu that contains choices that let you install MSDE and Insight Manager as separate items. You have to actively choose to do the install, it doesn't do it for you. The Insight Manager install does say it must have either MS SQL Server or MSDE installed in order to run. I chose to install MSDE and after the install of that component was complete I nmap'ed the box and found that it now had an open port 1433 where it didn't have one before.
I then went on and ran through the rest of the install for Insight Manager and let that complete in case it reconfigured the default MSDE install in some way. Started nessus and ran the Blank Password and Brute Force MS SQL password checks and it fails the blank password check. However, don't forget this is the *manager* component of Insight Manager and that's generally only installed on one or three boxes not on all machines. It's the *agents* that are installed on the machines to be monitored and they just report back to the manager - used to be via SNMP but it's been a couple of years since I used it in anger so it may have changed since then. I do not think that MSDE is going to be installed on the thousands of Compaq servers that need to be monitored - they'll just be running the monitoring agents that then report back to the manager component - though without going off to grab the (yet more megabytes of) agents to install I cannot be 100% sure of this. So, for the Compaq Insight Manager example, it does install a copy of SQL Server with the non-password protected sa account but it doesn't do the install without telling you - it's a conscious choice to install it. It does listen on port 1433 on its external IP address and it does have a non-password protected sa account so is probably vulnerable to the SQL Snake worm. I can't verify the other products mentioned have the same set of exposures but if they use MSDE then they probably do. -----Original Message----- From: H D Moore [mailto:[EMAIL PROTECTED]] Sent: 30 May 2002 23:46 To: Brian Anon; [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] Subject: Re: SQLworm on other ports On Thursday 30 May 2002 15:57, Brian Anon wrote: > Compaq Insight Manager does not listen on port TCP/1433 (I expect other > MSDE products may also listen on a different port). It could be that CIM only listens on a named pipe, no plugins currently exist to check for SQL Server on a named pipe. If it is indeed running on a different port, let me know what that port is and I will update the plugin. > Does the Nessus script test all open ports to determine if they are MSDE? > Or does it only look for port TCP/1433? The mssql_blank_password.nasl only checks for port 1433/tcp right now. I have seen a few cases where mssql_ping.nasl will trigger, but port 1433/tcp is not open, usually on multi-homed machines where SQL Server was only bound to the primary address. It may be possible to add a SQL Server check to the find_service plugin, but I haven't run across on any instances where the server was configured to use TCP/IP as a network transport and port 1433 wasn't open on at least one address. -HD
