Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

DB:MS-SQL:NULL-PASSWORD

Severity

Medium

Recommended

No

Category

DB

Release Date

2004/07/07

Update Number

1213

Supported Platforms

di-5.3+

DB: MS-SQL Server Null Password


This signature detects attempts to login using a zero-length (null) password to a Microsoft SQL Database Server. Null passwords are insecure and can indicate that attackers are probing your network.

Extended Description

This vulnerability makes the server subject to attacks by worms such as Voyager Alpha Force, Spida, and Cblade, and enables attackers to gain administrative privileges.

References

  • URL: http://www.microsoft.com/sql/techinfo/administration/2000/security/default.asp
  • URL: http://msdn.microsoft.com/library/default.asp?url=/library/en-us/modadmin/html/deconchangingsqlserveradministratorlogin.asp
  • URL: http://support.microsoft.com/default.aspx?scid=kb;EN-US;313418

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy & Policy
Legal Notices
Copyright© 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out