Bonum Certa Men Certa

Microsoft SQL Server and DirectX Enable Full Machine Compromise

Network server
Microsoft still the weakest link in networked computing



Summary: Complete systems compromised, all caused by proprietary Microsoft software and APIs

YESTERDAY WE wrote about Windows compromising the national security of the United States. It is now confirmed that a Microsoft component is the culprit. It's not just Windows though; it's apparently Microsoft SQL Server, according to CNET.

Investigators believe an SQL injection attack was used to exploit a vulnerability in Microsoft's SQL Server database in order to gain access to the servers.


How can a database lead to full compromise? It's surely a design problem and we append at the bottom some references of interest, including the fairly recent news about head of Microsoft SQL Server quitting Microsoft.

As Oiaohm put it, "Does MySQL on Linux run as a root user? Not running as root lowers the damage [...] Has happened in the past with old Microsoft SQL worms. [...] We don't know how old [a] Microsoft SQL Server this was."

In CNET, we have also found this report about a DirectX hole which enables the entire system to be compromised. This is madness. How can a proprietary API achieve this? Is it truly as insecure-by-design as ActiveX? Many examples of ActiveX nightmares are accumulated here.

Microsoft on Thursday said it is working on a security patch for a vulnerability in its DirectX streaming media technology in Windows that could allow someone to take complete control of a computer using a maliciously crafted QuickTime file.


Marvelous. Why not just stick to open and free APIs like OpenGL? _______ [1] Database head to leave daily duties at Microsoft

Paul Flessner, who leads Microsoft's data storage and platform division, will step down from his daily duties after the new year.


[2] New attack technique threatens databases

A noted database security expert, Litchfield is perhaps best known for uncovering a bug in Microsoft SQL Server database server that was subsequently used by the SQL Slammer worm. Litchfield has long criticised Oracle for the time it takes to fix vulnerabilities in its database software. € 


[3] SQL Injection Attacks on IIS Web Servers

[4] Microsoft offers assistance to combat mass SQL injection

[5] Huge Web Hack Attack Infects 500,000 Pages

One anti-virus vendor said the sites might have been compromised through a "security issue" in Microsoft's Web server software that has been reported to Microsoft's engineers. € 


[6] Study Says Linux More Secure

More than 70 percent people surveyed said they found Red Hat Linux less vulnerable to security issues than Microsoft's operating system.


[7] Study: 70 percent say Red Hat more secure than Windows

[8] Microsoft officially 425 years behind the times

It's not just Excel and Exchange that ignore the Gregorian calendar. The Reg has also confirmed that SQL Server 2008, Windows Small Business Server, and Windows Mobile are ignorant as well. € 


[9] SQL Server 2005 SP1 won't work with Vista

It's no secret that a number of applications, including several of Microsoft?s own, are not going to work properly with Windows Vista when the product ships.


[10] SQL Server 2005 SP2 Critical Update Available

Microsoft is seeking to resolve a technical glitch caused by Service Pack 2. For some installations, cleanup tasks stop prematurely after applying the service pack.

The hotfix, which Microsoft has designated a "critical update," is available for existing SQL Server 2005 installations with Service Pack 2.


[11] Vista-compatible SQL Server 2005 SP2 likely February 19

Microsoft began warning users of SQL Server 2005 Vista incompatibilities last Fall.


[12] Vista flaw could haunt Microsoft

Microsoft wants a bigger piece of Oracle and IBM's database business, but an oversight in its new operating system could cost the company plenty.


Recent Techrights' Posts

IBM 'Value' Fell 20%, The Executives Took Bonuses and Bonus Hikes
IBM is paying more and more money to the executives
More Information on IBM Red Hat Layoffs in April 2026, Hundreds of Skilled GNU/Linux Engineers Laid Off (300+ Simultaneously)
How long can the corporate media ignore IBM layoffs for?
SLAPP Censorship - Part 41 Out of 200: More Misuse of UK-GDPR (for US Citizens), More Copy-Pasting for Garrett and Graveley, Alleging That Publishing Unflattering Information is a 'Privacy' Issue
No wonder his own colleagues thought poorly of him (the junior barrister)
Dr. Andy Farnell Blasts Misuse of the Term "AI" to Describe Plagiarism, Plunder, and Misinformation
Dr. Stallman wrote about it back in the early 1980s
A Sign of Progress?
We'll solve war hunger and colonise Mars soon, according to men who never graduated from College
The Slop Delusion: This Morning We Broke Story on Red Hat Layoffs in Two Posts, Google is Already Plagiarising Them With Slop and Getting the Basic Facts Wrong
Google does not have "AI"; it has slop, which means it scrapes other people's work, then imitates it poorly
 
The Register MS, About 6 Million Pounds in Debt, Helps Promote Microsoft's Gartner Group and Prop Up the Ponzi Scheme of Slop Plagiarism, Fake Article Mentions "AI" About 20 Times
What was now known as The Register UK not only works against the interests of the UK; it works for charlatans and frauds
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, April 10, 2026
IRC logs for Friday, April 10, 2026
Three Years Ago We Disconnected From the United States, Now France Does the Same
Maybe in the coming months France will recruit loads of UNIX/Linux specialists
While Thousands of EPO Workers Are on Strike the President of the EPO, Who Bribes His Voters, Gives Himself Millions of Euros and 5,000 Euros Per Month in Housing Allowance
Campinos is immune, inherently corrupt, and habitual briber of his 'voters'
IBM and Red Hat Whistleblowers Versus a Dying Fourth Estate (Journalism Seems to Have Died as Silently as IBM RAs Go)
What a crazy world we live in!
Slopfarms We Forget About Because They Silently Die
The hard reality (for slobs and sloppers) is, slopfarms have no future
Gemini Links 10/04/2026: Flexiveganism, What Happened to Twitter, and Algorithm Fetishes
Links for the day
Links 10/04/2026: Indonesia's Social Control Media Bans Extend to Google YouTube, "I.M.F. Says Iran War Will Drag Global Growth Lower"
Links for the day
Media Blackout Regarding Mass Layoffs at Red Hat
To be very clear, what happened is certainly real
SLAPP Censorship - Part 42 Out of 200: Getting the Very Basic Technical Concepts Very Wrong, or Where Miscomprehension Begets "Plausible Deniability"
It's difficult to argue with people over things that they do not even understand
This Coming Weekend and Next Week We'll Cover EPO Scandals a Lot, There Are Still Perpetual Strikes That the Media Intentionally Avoids Covering
Expect our focus on EPO corruption to grow again
Raw: Extensive Evidence of Red Hat's Mass Layoffs in China (IBM Meets Geopolitics)
This has nothing to do with workers' performance
We'll Never Ever Do Social Control Media, Nate Silver's Article Helps Explain Why
If you want to research and publish, stay away from it
Links 10/04/2026: Pseudoscience and "Amazon Pulls Support for Perfectly Fine Older Kindles" and More Attacks on American Journalism
Links for the day
"IBM is Constantly Laying Off People" (Not Just in Red Hat)
IBM as a company is collapsing
Many Layoffs at IBM Red Hat, as the Rumours Said
Red Hat mass layoffs [...] "this was a difficult decision to make."
Microsoft, Drowning in Net Debt, Will Make Many More Cuts
The company is a net negative to society
April 15: Richard Stallman to Speak at the University of Texas in Austin, Texas
Next Wednesday in the afternoon Dr. Stallman will speak in a US college for the second time this year and for the second time in nearly 8 years
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, April 09, 2026
IRC logs for Thursday, April 09, 2026
Gemini Links 10/04/2026: Cycling, Slop, and Software to Keep Photos Organised
Links for the day
Henry Abbott (TrueHoop) Says Microsoft Taken Public by Alvin Bernard "Buzzy" Krongard (in New Interview About Jeffrey Epstein)
He has claimed that the man who took Microsoft public was a banker and also connected to the CIA (former Executive Director)
Quick Roundup of "Linux" Slop
Today we saw a slopfarm again in Google News
Links 09/04/2026: Microsoft Attacking VeraCrypt and "Canada’s New Surveillance Law"
Links for the day
Gemini Links 09/04/2026: Shopping, LLMs That Ruin the Net, and Moving to GNU/Linux
Links for the day
Links 09/04/2026: TikTok Sets Up Another Outpost in Finland (EU), "Trump Attacks On Public Media Blocked by Judge"
Links for the day
Microsoft's DevDiv Executive Has Quit (Is GitHub on the Chopping Block?)
CodePlex all over again?
Chatbots (or LLMs) Are Killing Us, and We Ought to Talk About It
We need to talk (to each other, not to bots)
Microsoft Also Fires Senior Executives
Microsoft is a very feeble company pretending to be a giant
Microsoft Windows in Ireland: From 90% to Just 16%
When it comes to Ireland's Web usage, not much of it is from Windows anymore
SLAPP Censorship - Part 40 Out of 200: Putting Forth Frivolous Claim Only a Few Days Before Running Out of Time (12 Months)
my response to a frivolous claim from Graveley
IBM Layoffs by Performance Improvement Plan (PIP) and More Evidence of Layoffs at HashiCorp After IBM Took Over
Notice how the media does not cover IBM layoffs
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, April 08, 2026
IRC logs for Wednesday, April 08, 2026
Gemini Links 09/04/2026: On the Radio, Boogie Notes, Slop in Search Engines and USENET
Links for the day