I've just downloaded all 111MB of Compaq Insight Manager 7 SP1 and installed
it on one of my Compaq machines. When you run the install it has a text
based menu that contains choices that let you install MSDE and Insight
Manager as separate items. You have to actively choose to do the install, it
doesn't do it for you. The Insight Manager install does say it must have
either MS SQL Server or MSDE installed in order to run. I chose to install
MSDE and after the install of that component was complete I nmap'ed the box
and found that it now had an open port 1433 where it didn't have one before.

I then went on and ran through the rest of the install for Insight Manager
and let that complete in case it reconfigured the default MSDE install in
some way. Started nessus and ran the Blank Password and Brute Force MS SQL
password checks and it fails the blank password check.

However, don't forget this is the *manager* component of Insight Manager and
that's generally only installed on one or three boxes not on all machines.
It's the *agents* that are installed on the machines to be monitored and
they just report back to the manager - used to be via SNMP but it's been a
couple of years since I used it in anger so it may have changed since then.
I do not think that MSDE is going to be installed on the thousands of Compaq
servers that need to be monitored - they'll just be running the monitoring
agents that then report back to the manager component - though without going
off to grab the (yet more megabytes of) agents to install I cannot be 100%
sure of this.

So, for the Compaq Insight Manager example, it does install a copy of SQL
Server with the non-password protected sa account but it doesn't do the
install without telling you - it's a conscious choice to install it. It does
listen on port 1433 on its external IP address and it does have a
non-password protected sa account so is probably vulnerable to the SQL Snake
worm. 

I can't verify the other products mentioned have the same set of exposures
but if they use MSDE then they probably do.


-----Original Message-----
From: H D Moore [mailto:[EMAIL PROTECTED]]
Sent: 30 May 2002 23:46
To: Brian Anon; [EMAIL PROTECTED]
Cc: [EMAIL PROTECTED]
Subject: Re: SQLworm on other ports


On Thursday 30 May 2002 15:57, Brian Anon wrote:
> Compaq Insight Manager does not listen on port TCP/1433 (I expect other
> MSDE products may also listen on a different port).

It could be that CIM only listens on a named pipe, no plugins currently
exist 
to check for SQL Server on a named pipe.  If it is indeed running on a 
different port, let me know what that port is and I will update the plugin.

> Does the Nessus script test all open ports to determine if they are MSDE?
> Or does it only look for port TCP/1433?

The mssql_blank_password.nasl only checks for port 1433/tcp right now. I
have 
seen a few cases where mssql_ping.nasl will trigger, but port 1433/tcp is
not 
open, usually on multi-homed machines where SQL Server was only bound to the

primary address. It may be possible to add a SQL Server check to the 
find_service plugin, but I haven't run across on any instances where the 
server was configured to use TCP/IP as a network transport and port 1433 
wasn't open on at least one address.

-HD

Reply via email to