RE: joehack, SQL and the 1433 Scans....
"Crossman, James" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <8A65F8FC7103B14DB45BAAD6F198E6438CA317@VCHOUXCH02.vcdom.vericenter.com> |
Just to prove that old cases never go away, they just go idle for years. :-) Thanks for quoting my old post, I was trying to remember the details as I was reading the thread but couldn't remember when it happened. It let me go pull my notes from October 2001 to check my memory. My notes (and another engineer's memory) show it to have been benign in our case. We both remember it as a poor choice of names within the stored procedure. Other engineer remembers it as being within a MS stored procedure - my memory is it was the developer who cleared the situation up for us - we may both be right. Don't know if this is your situation or not. But if the data from my post back then is increasing your concern, don't let it. I did a quick google too, and it looks like one other forum used my original post to base their warnings as well. I see no indicators on the web that 'joehack' strings are known to be hostile in SQL. And let this be a reminder that our notes should be clear enough to help us remember something three years after the fact - even if it was benign. At least the notes let me know who to go ask, and confirmed that it was a false positive alarm in our case. :-) I hope this helps, James -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Hensinger Aaron D Contr MCOM Sent: Thursday, November 11, 2004 10:13 AM To: Intrusions List (GCIA Practicals) Subject: RE: [Intrusions] joehack, SQL and the 1433 Scans.... I found some articles relating to this. It appears that it may be used as a backdoor. I don't administer SQL so cannot validate this. I just found several messages relating to backdoor.joehack so would be concerned. You may want to sniff the traffic and see if anything surprising comes across. http://www.dshield.org/pipermail/intrusions/2001-October/001936.php -----Original Message----- From: Scott Sanders [mailto:[email protected]] Sent: Wednesday, November 10, 2004 12:56 AM To: [email protected] Subject: [Intrusions] joehack, SQL and the 1433 Scans.... Hi there... I'm hoping somebody can help shed light on this issue as we have an identical situation here and I'm not having much luck gathering info on this. We have been investigating processor spikes on a SQL server and we have also found a stored procedure running with this 'joehack' string. The details are below: DECLARE @OUTPAR1 int execute sp_<removed string> @OUTPAR1 output select @OUTPAR1 'joehack' This seems to be running under a valid SQL account. Any advice is appreciated. Regards, Scott Sanders IT Operations Europe & Africa Region Toyota Financial Services (UK) D +44 (0)1737 365512 F +44 (0)1737 365520 M +44 (0)7810 884614 E [email protected] This correspondence is for the intended recipient only. It may contain confidential or legally privileged information or both. No confidentiality or privilege is waived or lost by any mistransmission or unauthorised alteration during transmission. If you are not the intended recipient, any disclosure, copying, distribution or any action taken or omitted to be taken in reliance on it, is prohibited and may be unlawful. If you receive this correspondence in error, please immediately delete it from your system and notify the sender. Any views expressed in this message are those of the individual sender, except where the sender expressly, and with authority, states them to be the views of Toyota. This message has been checked for viruses but the recipient is strongly advised to rescan the message before opening any attachments or attached executable files. _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions