RE: joehack, SQL and the 1433 Scans....

"Crossman, James" <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <8A65F8FC7103B14DB45BAAD6F198E6438CA317@VCHOUXCH02.vcdom.vericenter.com>
Just to prove that old cases never go away, they just go idle for years.
:-)  

Thanks for quoting my old post, I was trying to remember the details as
I was reading the thread but couldn't remember when it happened.  It let
me go pull my notes from October 2001 to check my memory.  My notes (and
another engineer's memory) show it to have been benign in our case.  We
both remember it as a poor choice of names within the stored procedure.
Other engineer remembers it as being within a MS stored procedure - my
memory is it was the developer who cleared the situation up for us - we
may both be right.

Don't know if this is your situation or not.  But if the data from my
post back then is increasing your concern, don't let it.  I did a quick
google too, and it looks like one other forum used my original post to
base their warnings as well.  I see no indicators on the web that
'joehack' strings are known to be hostile in SQL.

And let this be a reminder that our notes should be clear enough to help
us remember something three years after the fact - even if it was
benign.  At least the notes let me know who to go ask, and confirmed
that it was a false positive alarm in our case.  :-)  

I hope this helps,
James


-----Original Message-----
From: [email protected]
[mailto:[email protected]] On Behalf Of Hensinger Aaron
D Contr MCOM
Sent: Thursday, November 11, 2004 10:13 AM
To: Intrusions List (GCIA Practicals)
Subject: RE: [Intrusions] joehack, SQL and the 1433 Scans....

I found some articles relating to this. It appears that it may be used
as a
backdoor. I don't administer SQL so cannot validate this. I just found
several messages relating to backdoor.joehack so would be concerned. You
may
want to sniff the traffic and see if anything surprising comes across.

http://www.dshield.org/pipermail/intrusions/2001-October/001936.php



-----Original Message-----
From: Scott Sanders [mailto:[email protected]] 
Sent: Wednesday, November 10, 2004 12:56 AM
To: [email protected]
Subject: [Intrusions] joehack, SQL and the 1433 Scans....

Hi there... 

I'm hoping somebody can help shed light on this issue as we have an 
identical situation here and I'm not having much luck gathering info on 
this. 

We have been investigating processor spikes on a SQL server and we have 
also found a stored procedure running with this 'joehack' string. The 
details are below: 

DECLARE @OUTPAR1 int 
 execute  sp_<removed string>  @OUTPAR1  output   
select @OUTPAR1 'joehack' 

This seems to be running under a valid SQL account. 

Any advice is appreciated. 

Regards,
Scott Sanders
IT Operations
Europe & Africa Region
Toyota Financial Services (UK)
D +44 (0)1737 365512
F +44 (0)1737 365520
M +44 (0)7810 884614
E [email protected] 


This correspondence is for the intended recipient only. It may contain 
confidential or legally privileged information or both. No 
confidentiality or privilege is waived or lost by any mistransmission 
or unauthorised alteration during transmission. 

If you are not the intended recipient, any disclosure, copying, 
distribution or any action taken or omitted to be taken in reliance on 
it, is prohibited and may be unlawful. If you receive this 
correspondence in error, please immediately delete it from your system 
and notify the sender. 

Any views expressed in this message are those of the individual sender, 
except where the sender expressly, and with authority, states them to 
be the views of Toyota. 

This message has been checked for viruses but the recipient is strongly 
advised to rescan the message before opening any attachments or 
attached executable files. 
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions


_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.