This page permanently redirects to gemini://gemini.techrights.org/2009/05/31/ms-sql-server-directx-holes/.

● 05.31.09

●● Microsoft SQL Server and DirectX Enable Full Machine Compromise

Posted in Microsoft, Security, Windows at 9:38 am by Dr. Roy Schestowitz

Microsoft still the weakest link in networked computing

Summary: Complete systems compromised, all caused by proprietary Microsoft software and APIs

YESTERDAY WE wrote about Windows compromising the national security of the United States. It is now confirmed that a Microsoft component is the culprit. It’s not just Windows though; it’s apparently Microsoft SQL Server, according to CNET.

=> Windows compromising the national security of the United States | ↺ according to CNET

Investigators believe an SQL injection attack was used to exploit a vulnerability in Microsoft’s SQL Server database in order to gain access to the servers.

How can a database lead to full compromise? It's surely a design problem and we append at the bottom some references of interest, including the fairly recent news about head of Microsoft SQL Server quitting Microsoft.

=> It's surely a design problem

As Oiaohm put it, “Does MySQL on Linux run as a root user? Not running as root lowers the damage [...] Has happened in the past with old Microsoft SQL worms. [...] We don’t know how old [a] Microsoft SQL Server this was.”

In CNET, we have also found this report about a DirectX hole which enables the entire system to be compromised. This is madness. How can a proprietary API achieve this? Is it truly as insecure-by-design as ActiveX? Many examples of ActiveX nightmares are accumulated here.

=> ↺ this report | here

Microsoft on Thursday said it is working on a security patch for a vulnerability in its DirectX streaming media technology in Windows that could allow someone to take complete control of a computer using a maliciously crafted QuickTime file.

Marvelous. Why not just stick to open and free APIs like OpenGL? █ _______ [1] Database head to leave daily duties at Microsoft

=> ↺ Database head to leave daily duties at Microsoft

Paul Flessner, who leads Microsoft’s data storage and platform division, will step down from his daily duties after the new year.

[2] New attack technique threatens databases

=> ↺ New attack technique threatens databases

A noted database security expert, Litchfield is perhaps best known for uncovering a bug in Microsoft SQL Server database server that was subsequently used by the SQL Slammer worm. Litchfield has long criticised Oracle for the time it takes to fix vulnerabilities in its database software.  

[3] SQL Injection Attacks on IIS Web Servers

=> ↺ SQL Injection Attacks on IIS Web Servers

[4] Microsoft offers assistance to combat mass SQL injection

=> ↺ Microsoft offers assistance to combat mass SQL injection

[5] Huge Web Hack Attack Infects 500,000 Pages

=> ↺ Huge Web Hack Attack Infects 500,000 Pages

One anti-virus vendor said the sites might have been compromised through a “security issue” in Microsoft’s Web server software that has been reported to Microsoft’s engineers.  

[6] Study Says Linux More Secure

=> ↺ Study Says Linux More Secure

More than 70 percent people surveyed said they found Red Hat Linux less vulnerable to security issues than Microsoft’s operating system.

[7] Study: 70 percent say Red Hat more secure than Windows

=> ↺ Study: 70 percent say Red Hat more secure than Windows

[8] Microsoft officially 425 years behind the times

=> ↺ Microsoft officially 425 years behind the times

It’s not just Excel and Exchange that ignore the Gregorian calendar. The Reg has also confirmed that SQL Server 2008, Windows Small Business Server, and Windows Mobile are ignorant as well.  

[9] SQL Server 2005 SP1 won’t work with Vista

=> ↺ SQL Server 2005 SP1 won’t work with Vista

It’s no secret that a number of applications, including several of Microsoft?s own, are not going to work properly with Windows Vista when the product ships.

[10] SQL Server 2005 SP2 Critical Update Available

=> ↺ SQL Server 2005 SP2 Critical Update Available

Microsoft is seeking to resolve a technical glitch caused by Service Pack 2. For some installations, cleanup tasks stop prematurely after applying the service pack.The hotfix, which Microsoft has designated a “critical update,” is available for existing SQL Server 2005 installations with Service Pack 2.

[11] Vista-compatible SQL Server 2005 SP2 likely February 19

=> ↺ Vista-compatible SQL Server 2005 SP2 likely February 19

Microsoft began warning users of SQL Server 2005 Vista incompatibilities last Fall.

[12] Vista flaw could haunt Microsoft

=> ↺ Vista flaw could haunt Microsoft

Microsoft wants a bigger piece of Oracle and IBM’s database business, but an oversight in its new operating system could cost the company plenty.

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.

Permalink  Send this to a friend

=> Permalink | ↺ Send this to a friend


=> Techrights

➮ Sharing is caring. Content is available under CC-BY-SA.

Proxy Information
Original URL
gemini://gemini.techrights.org/2009/05/31/ms-sql-server-directx-holes
Status Code
Success (20)
Meta
text/gemini;lang=en-GB
Capsule Response Time
281.068716 milliseconds
Gemini-to-HTML Time
2.626304 milliseconds

This content has been proxied by September (ba2dc).