Re: [VulnDiscuss] RE: Re: [VulnDiscuss] eEye - SQL Sapphire Worm Analysis
"Mark Litchfield" <[email protected]>
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general,gmane.comp.security.bugtraq |
|---|---|
| Message-ID | <002701c2c509$14f45690$0100a8c0@liberty> |
In the first instance thanks for the entertaining mail The worm look something like this? http://www.nextgenss.com/papers/tp-SQL2000.pdf Appendix A of Threat Profiling Microsoft SQL Server (A guide to security Auditing) > No worries though... next time we are trying to get an alert out to the > community, to let them know what's going on, well make sure to stop and ask > the person who found the flaw Maybe you should consider it next time then you won't have to waste 40 hours. Just a suggestion. Enough bitching. To be perfectly frank, I did not read your entire mail, maybe next time if I am to make any sort of response, it may help in reading all it's content :) At least the 'Sapphire Worm' was not of a malicious nature, which it could quite have as easily been. The six months to the day is also an interesting point. Have the servers been infected with this for a while, with a built in pay load date? Based on your research, is there anything to indicate this? Regards Mark Litchfield NGS Software Ltd http://www.ngssoftware.com/ Tel: +44 208 40 100 70 (London) Tel: +44 1241 431 267 Mobile: +44 790 069 5236 Email: [email protected] ----- Original Message ----- From: "Marc Maiffret" <[email protected]> To: "Steve W. Manzuik" <[email protected]>; <[email protected]> Cc: <[email protected]>; <[email protected]> Sent: Saturday, January 25, 2003 1:24 PM Subject: [VulnDiscuss] RE: [VulnWatch] Re: [VulnDiscuss] eEye - SQL Sapphire Worm Analysis > Actually I must have missed where in > "http://www.nextgenss.com/advisories/mssql-udp.txt" did you disassemble the > current worm going on? Ahh right we must have "recited" the worm disassembly > from somewhere else hidden on your website. Right. > > There is a worm out there, it is affecting people, people need to know what > is going on. Yah its a 6 month old vulnerability... great that shows people > are not paying attention (Just like Codered). Even more of a reason to do > the research to see what is going on and try to educate people further. But > no your right never mind... its an old flaw people should have known > better... we should all have not done any analysis of the worm because yah > its using an old flaw that you found. Great. > > ISS, eEye, Symantec.... the analysis was for getting the cool name. I know > ours was... Sapphire and Tonic rules. I mean we couldn't possibly have > wanted to do research to answer the million and one emails that have been > flying across mailing lists the last two days with people wondering what in > the hell is going on with their networks and SQL servers. You know it IS all > for the name. Maybe that makes it worthwhile to me to have been up for over > 40 hours now and finishing up a free scanning tool to give to people to help > them out. Yes, its all for the name, _seriously_... > > Oh and Symantec's/Securityfocus's "Voyager Alpha Force" "worm" is an IRC bot > controlled system... which has nothing to do with this current worm. But I > am sure you knew that in your quick haste to get in on things. > > No worries though... next time we are trying to get an alert out to the > community, to let them know what's going on, well make sure to stop and ask > the person who found the flaw what they want to name to it. Obviously its > not good enough to credit their research and link back to them from our > website. > > Oh... you already missed the wagon. But thanks for the zero substance email, > after the fact, stating the pointlessly obvious. > > Signed, > Marc Maiffret > Chief Hacking Officer > eEye Digital Security > T.949.349.9062 > F.949.349.9538 > http://eEye.com/Retina - Network Security Scanner > http://eEye.com/Iris - Network Traffic Analyzer > http://eEye.com/SecureIIS - Stop known and unknown IIS vulnerabilities > > | -----Original Message----- > | From: Mark Litchfield [mailto:[email protected]] > | Sent: Saturday, January 25, 2003 8:01 PM > | To: Steve W. Manzuik; [email protected] > | Cc: [email protected]; [email protected] > | Subject: [VulnWatch] Re: [VulnDiscuss] eEye - SQL Sapphire Worm Analysis > | > | > | I find it very interesting that Eeye and ISS Xforce seem to be more > | interested in giving the worm a name and basically reciting what > | was already > | posted in David's advisory > | http://www.nextgenss.com/advisories/mssql-udp.txt > | on the 25th July 2002, media attention I wonder ;) and with Security > | Focus naming it Voyager Alpha Force. > | > | Not to miss the wagon: > | > | Based on the fact that it affects SQL servers, and interestingly enough 6 > | months to the day, that remain unpatched, and would have been protected, > | before everyone goes and starts to blame MS, I've scraped the barrel to > | produce the following, > | > | Regards Mark > | > | > | Security Quite Late worm J > > ----- Original Message ----- From: "Marc Maiffret" <[email protected]> To: "Steve W. Manzuik" <[email protected]>; <[email protected]> Cc: <[email protected]>; <[email protected]> Sent: Saturday, January 25, 2003 1:24 PM Subject: [VulnDiscuss] RE: [VulnWatch] Re: [VulnDiscuss] eEye - SQL Sapphire Worm Analysis > Actually I must have missed where in > "http://www.nextgenss.com/advisories/mssql-udp.txt" did you disassemble the > current worm going on? Ahh right we must have "recited" the worm disassembly > from somewhere else hidden on your website. Right. > > There is a worm out there, it is affecting people, people need to know what > is going on. Yah its a 6 month old vulnerability... great that shows people > are not paying attention (Just like Codered). Even more of a reason to do > the research to see what is going on and try to educate people further. But > no your right never mind... its an old flaw people should have known > better... we should all have not done any analysis of the worm because yah > its using an old flaw that you found. Great. > > ISS, eEye, Symantec.... the analysis was for getting the cool name. I know > ours was... Sapphire and Tonic rules. I mean we couldn't possibly have > wanted to do research to answer the million and one emails that have been > flying across mailing lists the last two days with people wondering what in > the hell is going on with their networks and SQL servers. You know it IS all > for the name. Maybe that makes it worthwhile to me to have been up for over > 40 hours now and finishing up a free scanning tool to give to people to help > them out. Yes, its all for the name, _seriously_... > > Oh and Symantec's/Securityfocus's "Voyager Alpha Force" "worm" is an IRC bot > controlled system... which has nothing to do with this current worm. But I > am sure you knew that in your quick haste to get in on things. > > No worries though... next time we are trying to get an alert out to the > community, to let them know what's going on, well make sure to stop and ask > the person who found the flaw what they want to name to it. Obviously its > not good enough to credit their research and link back to them from our > website. > > Oh... you already missed the wagon. But thanks for the zero substance email, > after the fact, stating the pointlessly obvious. > > Signed, > Marc Maiffret > Chief Hacking Officer > eEye Digital Security > T.949.349.9062 > F.949.349.9538 > http://eEye.com/Retina - Network Security Scanner > http://eEye.com/Iris - Network Traffic Analyzer > http://eEye.com/SecureIIS - Stop known and unknown IIS vulnerabilities > > | -----Original Message----- > | From: Mark Litchfield [mailto:[email protected]] > | Sent: Saturday, January 25, 2003 8:01 PM > | To: Steve W. Manzuik; [email protected] > | Cc: [email protected]; [email protected] > | Subject: [VulnWatch] Re: [VulnDiscuss] eEye - SQL Sapphire Worm Analysis > | > | > | I find it very interesting that Eeye and ISS Xforce seem to be more > | interested in giving the worm a name and basically reciting what > | was already > | posted in David's advisory > | http://www.nextgenss.com/advisories/mssql-udp.txt > | on the 25th July 2002, media attention I wonder ;) and with Security > | Focus naming it Voyager Alpha Force. > | > | Not to miss the wagon: > | > | Based on the fact that it affects SQL servers, and interestingly enough 6 > | months to the day, that remain unpatched, and would have been protected, > | before everyone goes and starts to blame MS, I've scraped the barrel to > | produce the following, > | > | Regards Mark > | > | > | Security Quite Late worm J > >