Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

DB:MS-SQL:DOS1

Severity

Low

Recommended

No

Category

DB

Keywords

MS-SQL Server Network-Based DoS

Release Date

2003/04/22

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

DB: MS-SQL Server Network-Based DoS


This signature detects attempts to exploit a known vulnerability in Microsoft SQL Server. When the SQL Server receives 0x0A as the first byte of a UDP/1434 packet, the server sends a similar packet to the source (as in a ping response). Attackers can spoof the source address to be another Microsoft SQL Server, creating a network-based denial-of-service (DoS) attack against both servers that consumes bandwidth and CPU resources.

Extended Description

Microsoft SQL Server 2000 uses a keep-alive mechanism which operates through the Resolution Service. If a particularly crafted data packet is sent to the SQL Server's keep-alive function, it will respond with an identical packet. If one such packet was sent to an SQL Server from another SQL Server, they would begin an infinite loop of keep-alive packets. Eventually, the servers will consume all available resources, resulting in a denial of services.

Affected Products

  • Microsoft SQL Server 2000 SP1
  • Microsoft SQL Server 2000 SP2
  • Microsoft SQL Server 2000

References

  • BugTraq: 5312
  • CVE: CVE-2002-0650
  • URL: http://www.microsoft.com/technet/security/bulletin/ms02-039.asp
  • URL: http://www.iss.net/security_center/static/9662.php

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out