Re: [VulnDiscuss] RE: Re: [VulnDiscuss] eEye - SQL Sapphire Worm Analysis

"Mark Litchfield" <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.general,gmane.comp.security.bugtraq
Message-ID <002701c2c509$14f45690$0100a8c0@liberty>
In the first instance thanks for the entertaining mail

The worm look something like this?

http://www.nextgenss.com/papers/tp-SQL2000.pdf     Appendix A of Threat
Profiling Microsoft SQL Server (A guide to security Auditing)

> No worries though... next time we are trying to get an alert out to the
> community, to let them know what's going on, well make sure to stop and
ask
> the person who found the flaw

Maybe you should consider it next time then you won't have to waste 40
hours.  Just a suggestion.

Enough bitching.  To be perfectly frank, I did not read your entire mail,
maybe next time if I am to make any sort of response, it may help in reading
all it's content :)

At least the 'Sapphire Worm' was not of a malicious nature, which it could
quite have as easily been.  The six months to the day is also an interesting
point.  Have the servers been infected with this for a while, with a built
in pay load date?  Based on your research, is there anything to indicate
this?

Regards


Mark Litchfield
NGS Software Ltd
http://www.ngssoftware.com/
Tel: +44 208 40 100 70 (London)
Tel: +44 1241 431 267
Mobile: +44 790 069 5236
Email: [email protected]



----- Original Message -----
From: "Marc Maiffret" <[email protected]>
To: "Steve W. Manzuik" <[email protected]>; <[email protected]>
Cc: <[email protected]>; <[email protected]>
Sent: Saturday, January 25, 2003 1:24 PM
Subject: [VulnDiscuss] RE: [VulnWatch] Re: [VulnDiscuss] eEye - SQL Sapphire
Worm Analysis


> Actually I must have missed where in
> "http://www.nextgenss.com/advisories/mssql-udp.txt" did you disassemble
the
> current worm going on? Ahh right we must have "recited" the worm
disassembly
> from somewhere else hidden on your website. Right.
>
> There is a worm out there, it is affecting people, people need to know
what
> is going on. Yah its a 6 month old vulnerability... great that shows
people
> are not paying attention (Just like Codered). Even more of a reason to do

> the research to see what is going on and try to educate people further.
But
> no your right never mind... its an old flaw people should have known
> better... we should all have not done any analysis of the worm because yah
> its using an old flaw that you found. Great.
>
> ISS, eEye, Symantec.... the analysis was for getting the cool name. I know
> ours was... Sapphire and Tonic rules. I mean we couldn't possibly have
> wanted to do research to answer the million and one emails that have been
> flying across mailing lists the last two days with people wondering what
in
> the hell is going on with their networks and SQL servers. You know it IS
all
> for the name. Maybe that makes it worthwhile to me to have been up for
over
> 40 hours now and finishing up a free scanning tool to give to people to
help
> them out. Yes, its all for the name, _seriously_...
>
> Oh and Symantec's/Securityfocus's "Voyager Alpha Force" "worm" is an IRC
bot
> controlled system... which has nothing to do with this current worm. But I
> am sure you knew that in your quick haste to get in on things.
>
> No worries though... next time we are trying to get an alert out to the
> community, to let them know what's going on, well make sure to stop and
ask
> the person who found the flaw what they want to name to it. Obviously its
> not good enough to credit their research and link back to them from our
> website.
>
> Oh... you already missed the wagon. But thanks for the zero substance
email,
> after the fact, stating the pointlessly obvious.
>
> Signed,
> Marc Maiffret
> Chief Hacking Officer
> eEye Digital Security
> T.949.349.9062
> F.949.349.9538
> http://eEye.com/Retina - Network Security Scanner
> http://eEye.com/Iris - Network Traffic Analyzer
> http://eEye.com/SecureIIS - Stop known and unknown IIS vulnerabilities
>
> | -----Original Message-----
> | From: Mark Litchfield [mailto:[email protected]]
> | Sent: Saturday, January 25, 2003 8:01 PM
> | To: Steve W. Manzuik; [email protected]
> | Cc: [email protected]; [email protected]
> | Subject: [VulnWatch] Re: [VulnDiscuss] eEye - SQL Sapphire Worm Analysis
> |
> |
> | I find it very interesting that Eeye and ISS Xforce seem to be more
> | interested in giving the worm a name and basically reciting what
> | was already
> | posted in David's advisory
> | http://www.nextgenss.com/advisories/mssql-udp.txt
> | on the 25th July 2002,    media attention I wonder ;) and with Security
> | Focus naming it Voyager Alpha Force.
> |
> | Not to miss the wagon:
> |
> | Based on the fact that it affects SQL servers, and interestingly enough
6
> | months to the day, that remain unpatched, and would have been protected,
> | before everyone goes and starts to blame MS, I've scraped the barrel to
> | produce the following,
> |
> | Regards Mark
> |
> |
> | Security Quite Late worm  J
>
>

----- Original Message -----
From: "Marc Maiffret" <[email protected]>
To: "Steve W. Manzuik" <[email protected]>; <[email protected]>
Cc: <[email protected]>; <[email protected]>
Sent: Saturday, January 25, 2003 1:24 PM
Subject: [VulnDiscuss] RE: [VulnWatch] Re: [VulnDiscuss] eEye - SQL Sapphire
Worm Analysis


> Actually I must have missed where in
> "http://www.nextgenss.com/advisories/mssql-udp.txt" did you disassemble
the
> current worm going on? Ahh right we must have "recited" the worm
disassembly
> from somewhere else hidden on your website. Right.
>
> There is a worm out there, it is affecting people, people need to know
what
> is going on. Yah its a 6 month old vulnerability... great that shows
people
> are not paying attention (Just like Codered). Even more of a reason to do
> the research to see what is going on and try to educate people further.
But
> no your right never mind... its an old flaw people should have known
> better... we should all have not done any analysis of the worm because yah
> its using an old flaw that you found. Great.
>
> ISS, eEye, Symantec.... the analysis was for getting the cool name. I know
> ours was... Sapphire and Tonic rules. I mean we couldn't possibly have
> wanted to do research to answer the million and one emails that have been
> flying across mailing lists the last two days with people wondering what
in
> the hell is going on with their networks and SQL servers. You know it IS
all
> for the name. Maybe that makes it worthwhile to me to have been up for
over
> 40 hours now and finishing up a free scanning tool to give to people to
help
> them out. Yes, its all for the name, _seriously_...
>
> Oh and Symantec's/Securityfocus's "Voyager Alpha Force" "worm" is an IRC
bot
> controlled system... which has nothing to do with this current worm. But I
> am sure you knew that in your quick haste to get in on things.
>
> No worries though... next time we are trying to get an alert out to the
> community, to let them know what's going on, well make sure to stop and
ask
> the person who found the flaw what they want to name to it. Obviously its
> not good enough to credit their research and link back to them from our
> website.
>
> Oh... you already missed the wagon. But thanks for the zero substance
email,
> after the fact, stating the pointlessly obvious.
>
> Signed,
> Marc Maiffret
> Chief Hacking Officer
> eEye Digital Security
> T.949.349.9062
> F.949.349.9538
> http://eEye.com/Retina - Network Security Scanner
> http://eEye.com/Iris - Network Traffic Analyzer
> http://eEye.com/SecureIIS - Stop known and unknown IIS vulnerabilities
>
> | -----Original Message-----
> | From: Mark Litchfield [mailto:[email protected]]
> | Sent: Saturday, January 25, 2003 8:01 PM
> | To: Steve W. Manzuik; [email protected]
> | Cc: [email protected]; [email protected]
> | Subject: [VulnWatch] Re: [VulnDiscuss] eEye - SQL Sapphire Worm Analysis
> |
> |
> | I find it very interesting that Eeye and ISS Xforce seem to be more
> | interested in giving the worm a name and basically reciting what
> | was already
> | posted in David's advisory
> | http://www.nextgenss.com/advisories/mssql-udp.txt
> | on the 25th July 2002,    media attention I wonder ;) and with Security
> | Focus naming it Voyager Alpha Force.
> |
> | Not to miss the wagon:
> |
> | Based on the fact that it affects SQL servers, and interestingly enough
6
> | months to the day, that remain unpatched, and would have been protected,
> | before everyone goes and starts to blame MS, I've scraped the barrel to
> | produce the following,
> |
> | Regards Mark
> |
> |
> | Security Quite Late worm  J
>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.