Thinking...
[get complete service list]
Port Information
Protocol Service Name
tcp ms-sql-s Microsoft-SQL-Server
udp ms-sql-s Microsoft-SQL-Server
Top IPs Scanning
Today Yesterday
123.138.18.10 (6)3.136.208.236 (340)
58.20.243.17 (4)78.128.114.38 (254)
212.64.201.227 (2)139.162.117.40 (167)
171.121.253.17 (2)3.16.213.130 (89)
103.116.247.192 (2)123.138.18.10 (63)
147.185.133.10 (2)197.248.29.234 (62)
180.252.87.114 (2)111.11.250.195 (60)
36.94.248.177 (2)3.90.12.192 (58)
103.168.29.186 (2)112.161.49.227 (50)
139.162.117.40 (2)3.237.173.220 (48)
Port diary mentions
URL
Mailbag Items for Ports 1433 and 113
Solution to the TCP 1433 Traffic
Port 1433 scanning
If there are some unexploited MSSQL Servers With Weak Passwords Left: They got you now (again)
User Comments
Submitted By Date
Comment
Marcus H. Sachs, SANS Institute 2003-10-10 00:50:59
SANS Top-20 Entry: W2 Microsoft SQL Server (MSSQL) http://isc.sans.org/top20.html#w2 The Microsoft SQL Server (MSSQL) contains several serious vulnerabilities that allow remote attackers to obtain sensitive information, alter database content, compromise SQL servers, and, in some configurations, compromise server hosts. MSSQL vulnerabilities are well-publicized and actively under attack. Two recent MSSQL worms in May 2002 and January 2003 exploited several known MSSQL flaws. Hosts compromised by these worms generate a damaging level of network traffic when they scan for other vulnerable hosts.
Johannes Ullrich 2002-10-10 17:21:35
Port 1433 is used by Microsoft SQL Server. SQLSnake is one worm taking advantage of SQL Server installs without password. As SQL Server is able to run batch files and command line programs, it can be used to download and install malware. Basic Protection: Use good passwords for all SQL Server accounts.
CVE Links
CVE # Description