[25165] in bugtraq

home help back first fref pref prev next nref lref last post

Re: List of extended sprocs that are vulnerable? FW: Microsoft Security Bulletin MS02-020

daemon@ATHENA.MIT.EDU (Bronek Kozicki)
Fri Apr 19 13:43:31 2002

Message-ID: <006d01c1e768$56cc01f0$7507b33e@luscinia>
From: "Bronek Kozicki" <brok@rubikon.pl>
To: "Toni Lassila" <toni.lassila@mc-europe.com>
Cc: <bugtraq@securityfocus.com>
Date: Fri, 19 Apr 2002 08:06:26 +0200
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit

> This MS bulletin mentions several extended stored procedures are
> vulnerable, does anyone have a list or an idea if any of these have by
> default exec permissions for the group 'public'?

As stated on http://www.appsecinc.com/resources/alerts/mssql/02-0000.html
following ext. procedures are available to 'public':
* xp_mergelineages  (MSSQL2K)
* xp_proxiedmetadata (MSSQL2K and MSSQL7)

I verified this on SQL2K - indeed, everyone with access to SQL Server may
use them.

> If this is indeed is the case then the patch is a "must-install" if you
> allow workstations to connect directly and login to your SQL Server.

Exactly.


B.



home help back first fref pref prev next nref lref last post