hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Feanor
I've heard of a new exploit that exploits SQL servers without a need for password, but i can't lay my hands upon the source code.

Maybe somebody here has it?
Krogoth
no new mssql xploit... lol
maybe you're referring to mysql?

http://www.governmentsecurity.org/forum/in...showtopic=10022
isaiah
there is a new expliot for sql but it sucks i have it and you get 1 result in 10000 ips tested
The Storm
can you share it with us pls ? would be nice
kenshin_efx
yeah, you can share this whit us wink.gif
flashb4ck
why do ya want this shit when he say that it S works on 1 from 10000 ips ^^


gR€€tTz fL4$hB4Ck
Stevy
it's included in the metasploit project

[ 08/13/2004 ] New exploit module added: mssql2000_preauthentication

but it sucks wink.gif
yuliang11
QUOTE


I've heard of a new exploit that exploits SQL servers without a need for password, but i can't lay my hands upon the source code.




Has to be the mysql...
Reaper527
QUOTE (yuliang11 @ Aug 19 2004, 10:53 AM)
QUOTE


I've heard of a new exploit that exploits SQL servers without a need for password, but i can't lay my hands upon the source code.




Has to be the mysql...

stevy specifially said the new MSsql exploit is in the metasploit framework
twistedps
hehe, yeah the metasploit framework has it along with the unreal engine stuff which i was dissapointed to see released since i had private code for it sad.gif
over 4,000 vulnerable ut2k3 servers alone.
yuliang11

New exploit module added: mssql2000_preauthentication ? or is it a new exploit? wink.gif get what i mean?



QUOTE


it's included in the metasploit project

[ 08/13/2004 ] New exploit module added: mssql2000_preauthentication

but it sucks 



QUOTE (yuliang11 @ Aug 19 2004, 10:53 AM)
QUOTE 


I've heard of a new exploit that exploits SQL servers without a need for password, but i can't lay my hands upon the source code.






Has to be the mysql... 


stevy specifially said the new MSsql exploit is in the metasploit framework
cougar
its the sqlhello exploit.

not mysql wink.gif
prog
QUOTE (flashb4ck @ Aug 19 2004, 02:32 AM)
why do ya want this shit when he say that it S works on 1 from 10000 ips ^^


gR€€tTz fL4$hB4Ck

maybe some ppl wanna test for security, and NOT go and hack a bunch of boxes
The Storm
QUOTE (prog @ Aug 20 2004, 02:00 PM)
QUOTE (flashb4ck @ Aug 19 2004, 02:32 AM)
why do ya want this shit when he say that it S works on 1 from 10000 ips ^^


gR€€tTz fL4$hB4Ck

maybe some ppl wanna test for security, and NOT go and hack a bunch of boxes

yes there you are rigth!
nowhere
this is the name i think: SQL Hello Exploit - Remote Shell Callback by JoePub
Hellraiseruk
CODE
##
#
# this script tests for the "You had me at hello" overflow
# in MSSQL (tcp/1433)
# Copyright Dave Aitel (2002)
# Bug found by: Dave Aitel (2002)
#
##
#TODO:
#techically we should also go to the UDP 1434 resolver service
#and get any additional ports!!!


if(description)
{
script_id(11067);
# script_cve_id("CVE-2000-0402");
script_version ("$Revision: 0.1 $");
name["english"] = "Microsoft SQL Server Hello Overflow";
script_name(english:name["english"]);

desc["english"] = "
The remote MS SQL server is vulnerable to the Hello overflow.

An attacker may use this flaw to execute commands against
the remote host as LOCAL/SYSTEM,
as well as read your database content.

Solution : disable this service (Microsoft SQL Server).

Risk factor : High";

script_description(english:desc["english"]);

summary["english"] = "Microsoft SQL Server Hello Overflow";
script_summary(english:summary["english"]);

script_category(ACT_ATTACK);

script_copyright(english:"This script is Copyright (C) 2002 Dave Aitel");
family["english"] = "Windows";
script_family(english:family["english"]);
script_require_ports(1433);
exit(0);
}

#
# The script code starts here
#
#taken from mssql.spk
pkt_hdr = raw_string(
0x12 ,0x01 ,0x00 ,0x34 ,0x00 ,0x00 ,0x00 ,0x00  ,0x00 ,0x00 ,0x15 ,0x00 ,0x06 ,0x01 ,0x00 ,0x1b
,0x00 ,0x01 ,0x02 ,0x00 ,0x1c ,0x00 ,0x0c ,0x03  ,0x00 ,0x28 ,0x00 ,0x04 ,0xff ,0x08 ,0x00 ,0x02
,0x10 ,0x00 ,0x00 ,0x00
);

#taken from mssql.spk
pkt_tail = raw_string (
0x00 ,0x24 ,0x01 ,0x00 ,0x00
);

#techically we should also go to the UDP 1434 resolver service
#and get any additional ports!!!
port = 1433;
found = 0;
report = "The SQL Server is vulnerable to the Hello overflow.

An attacker may use this flaw to execute commands against
the remote host as LOCAL/SYSTEM,
as well as read your database content.

Solution : disable this service (Microsoft SQL Server).

Risk factor : High";


if(get_port_state(port))
{
   soc = open_sock_tcp(port);

   if(soc)
   {
    #uncomment this to see what normally happens
       #attack_string="MSSQLServer";
#uncomment next line to actually test for overflow
attack_string=crap(560);
       # this creates a variable called sql_packet
sql_packet = pkt_hdr+attack_string+pkt_tail;
send(socket:soc, data:sql_packet);

    r  = recv(socket:soc, length:4096);
    close(soc);
#display ("Result:",r,"\n");
   if(!r)
    {
    # display("Security Hole in MSSQL\n");
           security_hole(port:port, data:report);
    }
   }
}

JoePub
What you have there is the NASL detection script for it im affraid. The source code for it is not available as I decided not to release it
ivan288
and what about the new version of your sploit joepub?
heard it can bypass the patch.
good job biggrin.gif
TheOther
Why not JoePub? This is discovered months ago. Everybody should be patched by now, don't you think?
Why should big cooperations pay thousands of dollars for IT's when they can't patch there system. It's there own fault.
But on the other hand I respect your desision.

sry for my bad english.
JoePub
You heard wrong, my latest one doesn't get around the patch at all. And admins wont really be up to date considering this vulnerability has been known since 2002
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.