Short Name |
DB:MS-SQL:NULL-PASSWORD |
|---|---|
Severity |
Medium |
Recommended |
No |
Category |
DB |
Release Date |
2004/07/07 |
Update Number |
1213 |
Supported Platforms |
di-5.3+ |
This signature detects attempts to login using a zero-length (null) password to a Microsoft SQL Database Server. Null passwords are insecure and can indicate that attackers are probing your network.
This vulnerability makes the server subject to attacks by worms such as Voyager Alpha Force, Spida, and Cblade, and enables attackers to gain administrative privileges.