954,178 Members — Technology Publication meets Social Media
Username:
Password:
Lost login information?
Have something to say? Contribute New Article Reply to this Article

Microsoft SQL Server 2000 Exploit!

Well, if you haven't noticed already, some to most of the internet is down! This is due to an exploit in Microsoft SQL Server SP2 and lower.

A buffer overrun can allow hackers to run code on the SQL Server. This worm, infects an SQL Server and then that SQL Server infects others.

My reccomendation? APPLY SP3!

If you have been infected, these steps should be taken:

1. Stop and DISABLE the MSSql Service, and all related ones
2. Stop and DISABLE IIS (if running)
3. Apply the SP3 Support Pack
4. Restart
5. Start and ENABLE the core MSSql Server (Not the Transaction Coordinator, etc)
6. Change your SA password!
7. Start and ENABLE all other stopped services.

Tekmaven
Software Architect
Moderator
1,274 posts since Feb 2002
Reputation Points: 322
Solved Threads: 28
 

We noticed this Saturday morning at work. Something wrong with SQL Server 2000. We didn't think it was going to be that big. I was surprised how big it was when I saw it on the news and heard about it at CNET News.

samaru
a.k.a inscissor
Team Colleague
1,256 posts since Feb 2002
Reputation Points: 262
Solved Threads: 18
 

Here are instructions from Microsoft and where to download the files for SQL Server 2000 SP3:

http://www.microsoft.com/downloads/details.aspx?FamilyId=9032F608-160A-4537-A2B6-4CB265B80766&displaylang=en

samaru
a.k.a inscissor
Team Colleague
1,256 posts since Feb 2002
Reputation Points: 262
Solved Threads: 18
 

This article has been dead for over three months

Post: Markdown Syntax: Formatting Help
You