05.31.09

Gemini version available ♊︎

Microsoft SQL Server and DirectX Enable Full Machine Compromise

Posted in Microsoft, Security, Windows at 9:38 am by Dr. Roy Schestowitz

Network server
Microsoft still the weakest link in networked computing

Summary: Complete systems compromised, all caused by proprietary Microsoft software and APIs

YESTERDAY WE wrote about Windows compromising the national security of the United States. It is now confirmed that a Microsoft component is the culprit. It’s not just Windows though; it’s apparently Microsoft SQL Server, according to CNET.

Investigators believe an SQL injection attack was used to exploit a vulnerability in Microsoft’s SQL Server database in order to gain access to the servers.

How can a database lead to full compromise? It's surely a design problem and we append at the bottom some references of interest, including the fairly recent news about head of Microsoft SQL Server quitting Microsoft.

As Oiaohm put it, “Does MySQL on Linux run as a root user? Not running as root lowers the damage [...] Has happened in the past with old Microsoft SQL worms. [...] We don’t know how old [a] Microsoft SQL Server this was.”

In CNET, we have also found this report about a DirectX hole which enables the entire system to be compromised. This is madness. How can a proprietary API achieve this? Is it truly as insecure-by-design as ActiveX? Many examples of ActiveX nightmares are accumulated here.

Microsoft on Thursday said it is working on a security patch for a vulnerability in its DirectX streaming media technology in Windows that could allow someone to take complete control of a computer using a maliciously crafted QuickTime file.

Marvelous. Why not just stick to open and free APIs like OpenGL?
_______
[1] Database head to leave daily duties at Microsoft

Paul Flessner, who leads Microsoft’s data storage and platform division, will step down from his daily duties after the new year.

[2] New attack technique threatens databases

A noted database security expert, Litchfield is perhaps best known for uncovering a bug in Microsoft SQL Server database server that was subsequently used by the SQL Slammer worm. Litchfield has long criticised Oracle for the time it takes to fix vulnerabilities in its database software.  

[3] SQL Injection Attacks on IIS Web Servers

[4] Microsoft offers assistance to combat mass SQL injection

[5] Huge Web Hack Attack Infects 500,000 Pages

One anti-virus vendor said the sites might have been compromised through a “security issue” in Microsoft’s Web server software that has been reported to Microsoft’s engineers.  

[6] Study Says Linux More Secure

More than 70 percent people surveyed said they found Red Hat Linux less vulnerable to security issues than Microsoft’s operating system.

[7] Study: 70 percent say Red Hat more secure than Windows

[8] Microsoft officially 425 years behind the times

It’s not just Excel and Exchange that ignore the Gregorian calendar. The Reg has also confirmed that SQL Server 2008, Windows Small Business Server, and Windows Mobile are ignorant as well.  

[9] SQL Server 2005 SP1 won’t work with Vista

It’s no secret that a number of applications, including several of Microsoft?s own, are not going to work properly with Windows Vista when the product ships.

[10] SQL Server 2005 SP2 Critical Update Available

Microsoft is seeking to resolve a technical glitch caused by Service Pack 2. For some installations, cleanup tasks stop prematurely after applying the service pack.

The hotfix, which Microsoft has designated a “critical update,” is available for existing SQL Server 2005 installations with Service Pack 2.

[11] Vista-compatible SQL Server 2005 SP2 likely February 19

Microsoft began warning users of SQL Server 2005 Vista incompatibilities last Fall.

[12] Vista flaw could haunt Microsoft

Microsoft wants a bigger piece of Oracle and IBM’s database business, but an oversight in its new operating system could cost the company plenty.

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

DecorWhat Else is New


  1. From Competitive (Top-Level, High-Calibre, Well-Paid) Jobs to 2,000 Euros a Month -- How the EPO is Becoming a Sweatshop by Patent Examiners' Standards

    A longish video about the dreadful situation at the EPO, where staff is being ‘robbed’ and EPO funds get funnelled into some dodgy stock market investments (a clear violation of the institution’s charter)



  2. [Meme] Protecting European Patent Courts From EPO 'Mafia'

    With flagrant disregard for court rulings (or workarounds to dodge actual compliance) it seems clear that today's EPO management is allergic to justice and to judges; European Patents perish at unprecedented levels in national European courts and it should be kept that way



  3. Links 15/10/2021: Pine64's New PinePhone Pro and Ubuntu 22.04 LTS Codename

    Links for the day



  4. [Meme] GitHub Isn't Free Hosting, It's All About Control by Microsoft

    Deleting GitHub isn’t a political statement but a pragmatic decision, seeing how Microsoft routinely misuses its control over GitHub to manipulate the market



  5. With EPO 'Strike Regulations' Belatedly Ruled Unlawful, EPO Management May be Lowering the Salary Even Further by Introducing Outside 'Temps' or Casual Workers

    Institutional capture by an 'IP' (litigation) Mafia is nearly complete; with illegal so-called (anti) 'Strike Regulations' out the door, they're quickly moving on to another plan, or so it seems on the surface



  6. Links 15/10/2021: 95% of Ransomware Targets Windows

    Links for the day



  7. IRC Proceedings: Thursday, October 14, 2021

    IRC logs for Thursday, October 14, 2021



  8. The EPO’s Overseer/Overseen Collusion — Part XII: The French Connection

    The EPO‘s presidency (led by Frenchmen for nearly 15 years out of the past 18 years; Benoît Battistelli and António Campinos are both French despite their somewhat misleading surnames) is extremely unlikely to even be mildly scrutinised by the French delegates because of a web of nepotism and protectionism



  9. [Meme] Another Maladministration Meeting Comes to an End

    Did the EPO‘s overseeing body properly tackle Benoît Battistelli‘s illegal acts, authorised by that very same overseeing body? Don’t hold your breath as António Campinos continues to crack down on staff (maybe ILOAT will rule on it in 2030)



  10. Links 14/10/2021: LibreOffice 7.2.2, Happy Birthday to Jolla, Ubuntu 21.10, Devuan GNU+Linux 4.0, OpenBSD 7.0

    Links for the day



  11. [Teaser] What Miguel de Icaza Really Thinks of the CEO of Microsoft GitHub

    Following the opening of a new series about Microsoft GitHub we drop a little teaser today; we expect dozens of parts to be released in the coming weeks/months as facts are being validated and organised



  12. Splitting the Time to Cover More Leaks and Exposés

    We take stock of Part 11 of the ongoing EPO series (“EPO’s Overseer/Overseen Collusion”) and explain what caused various delays yesterday; we may have to up our pace a little in order to keep up with an influx of leaks and whistleblowers



  13. [Meme] Destroying the Workplace

    The working conditions at the EPO continue to worsen under the António Campinos regime, perpetuating the decade-long 'demolition project' of Benoît Battistelli and his cohorts in the complicit Administrative CouncilThe working conditions at the EPO continue to worsen under the António Campinos regime, perpetuating the decade-long 'demolition project' of Benoît Battistelli and his cohorts in the complicit Administrative Council



  14. Microsoft GitHub Exposé — Part I — Inside a Den of Corruption and Misogynists

    Today we commence a new series that implicates Microsoft, GitHub, Copilot, and Team Mono



  15. EPO Management Tricks EPO Staff Into Taking More Paycuts

    “Education and childcare reform” [sic] is an António Campinos "reform" in the same sense regressive salary reductions are just “adjustments” (euphemism); Electronic opt-in gaffes, according to staff representatives, show that the tradition of Benoît Battistelli carries on at the Office, taking away from staff for a few corrupt officials to milk the institution to death



  16. Links 14/10/2021: Whisker Menu 2.6.1 and KDE's Birthday

    Links for the day



  17. Links 14/10/2021: DragonFly 6.0.1 Released and Red Hat Loses Another Top Executive

    Links for the day



  18. IRC Proceedings: Wednesday, October 13, 2021

    IRC logs for Wednesday, October 13, 2021



  19. Süddeutsche Zeitung Became a Propaganda Arm of EPO Management (and by Extension Software Patents/Patent Lobbyists)

    EPO ‘genius’ António Campinos enjoys shallow press coverage, which echoes or resembles Benoît Battistelli‘s corruption of the media (paid-for fluff)



  20. GNOME (and Debian) Infringe Human Rights by Shipping Parental Control Software (Internally Called “Malcontent”)

    Guest post by Ryan, reprinted with permission



  21. No, JWZ, Discord is Not “IRC With Pictures”

    Guest post by Ryan, reprinted with permission



  22. The EPO’s Overseer/Overseen Collusion — Part XI: “General Bock” - Battistelli's Swiss Apprentice?

    The António Campinos-led EPO won’t be subjected to real oversight by the Administrative Council, which ‘met’ (online) earlier today; so we look at who in the Administrative Council did what; today we wrap up the parts about Switzerland (third part of three)



  23. Links 13/10/2021: Sparky 2021.10 and New Archcraft

    Links for the day



  24. Links 13/10/2021: Firefox Keylogger on (By Default), GNOME Platform Design Discussed

    Links for the day



  25. [Meme] [Teaser] Swiss Alexandre Benallas

    The EPO‘s French dictator, Benoît ‘Vichy’ Battistelli, might be relieved to hear that his enabler in the adjacent Switzerland also enlisted armed bullies to keep the population down (the father of António Campinos might know a thing or two about those; it’s why he fled to France)



  26. IRC Proceedings: Tuesday, October 12, 2021

    IRC logs for Tuesday, October 12, 2021



  27. A Tale of Two KDE Distributions: Kubuntu 21.10 and Debian 11 GNU/Linux

    Guest post by Ryan, reprinted with permission



  28. Citation/Atlas 'Security' Exam is a Total Farce, But It's Still Good for Entertainment Purposes

    What are people being taught about so-called 'security'? Might that explain so many security breaches? (Poor training, wrong assumptions)



  29. [Meme] [Teaser] Swiss Rumbustious Alpha-Rambos

    Aggressive men tarnish the image of Switzerland as a soft nation of peace; details tomorrow...



  30. Unqualified Managers and Demoralising Leadership in Switzerland (Like in EPO)

    Switzerland’s media (what’s left of it) is currently looking into new scandals associated with Christian Bock, who back in 2013 helped back the EPO's illegal anti-strike regulations


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts