<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://weblogs.asp.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Hundreds of websites under attack and Microsoft are you doing something?</title><link>http://weblogs.asp.net/pleloup/archive/2008/12/19/hundreds-of-websites-under-attack-and-microsoft-are-you-doing-something.aspx</link><description>Following my last post on the subject of SQL injection, this story is far from being finished. First thanks to all your comments, I really applied most of the advices, licke checking against query string vulnerabilities,XSS, etc... I don't use dynamic</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>re: Hundreds of websites under attack and Microsoft are you doing something?</title><link>http://weblogs.asp.net/pleloup/archive/2008/12/19/hundreds-of-websites-under-attack-and-microsoft-are-you-doing-something.aspx#6798578</link><pubDate>Fri, 19 Dec 2008 20:04:56 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:6798578</guid><dc:creator>tlichty</dc:creator><author>tlichty</author><description>&lt;p&gt;&lt;em&gt;&amp;quot;I agree with you. My SQL server is behind a second firewall. I am not using sa but a simple user with read access only&amp;nbsp;See my new post about the matter, it&amp;#39;s really new for me and apparently thousands of us, because this time it&amp;#39;s coming through a cookie executing some SQL commands along the request stream. Prove me wrong, but it&amp;#39;s the first time I heard that a cookie can execute itself! If it&amp;#39;s not a flaw, what is it? Paschal&amp;quot;&lt;/em&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I agree with tmorton and everyone else. No traffic from the internet should come any where NEAR your SQL server. We have a firewall in front of our web servers. Then a second firewall in front of our SQL servers that only allow traffic from the internal network to it.&lt;/p&gt;
&lt;p&gt;DB servers should never be accessible to the web. I&amp;#39;m not sure how you sleep at night if they are.&lt;/p&gt;&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=6798578" width="1" height="1"&gt;</description></item><item><title>re: Hundreds of websites under attack and Microsoft are you doing something?</title><link>http://weblogs.asp.net/pleloup/archive/2008/12/19/hundreds-of-websites-under-attack-and-microsoft-are-you-doing-something.aspx#6798468</link><pubDate>Fri, 19 Dec 2008 17:30:51 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:6798468</guid><dc:creator>tmorton</dc:creator><author>tmorton</author><description>&lt;p&gt;Not sure how your failure to secure your server is Microsoft's fault? &amp;nbsp;You say you have covered the basics, but that's really not good enough. &amp;nbsp;Your server security is only as good as your weakest point.&lt;/p&gt;
&lt;p&gt;My suggestion is to open a paid support ticket with Microsoft, so that they can formally help you resolve the issue(s).&lt;/p&gt;
&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=6798468" width="1" height="1"&gt;</description></item><item><title>re: Hundreds of websites under attack and Microsoft are you doing something?</title><link>http://weblogs.asp.net/pleloup/archive/2008/12/19/hundreds-of-websites-under-attack-and-microsoft-are-you-doing-something.aspx#6798427</link><pubDate>Fri, 19 Dec 2008 17:01:23 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:6798427</guid><dc:creator>Darren Kopp</dc:creator><author>Darren Kopp</author><description>&lt;p&gt;&lt;em&gt;&lt;strong&gt;&amp;nbsp;&amp;quot;Darren you are entittled to your opinions, but UrlScan is setup and installed. It has works for two days, and now the attacks are comng back. Then I tested mycode and servers using all the tools I could find, nothing has changed. Now you tell me why so many websites are caught with this crap. Do you call them all stupid? -- P.&amp;quot;&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;don&amp;#39;t b*tch about microsoft. secure your servers and your code. &lt;/p&gt;
&lt;p&gt;and why don&amp;#39;t you just install UrlScan. 3.0 is in beta right now.&lt;/p&gt;&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=6798427" width="1" height="1"&gt;</description></item><item><title>re: Hundreds of websites under attack and Microsoft are you doing something?</title><link>http://weblogs.asp.net/pleloup/archive/2008/12/19/hundreds-of-websites-under-attack-and-microsoft-are-you-doing-something.aspx#6798391</link><pubDate>Fri, 19 Dec 2008 15:59:11 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:6798391</guid><dc:creator>David Taylor</dc:creator><author>David Taylor</author><description>&lt;p&gt;Obvious question is do you have SQL open at the firewall to external users.&lt;/p&gt;
&lt;p&gt;Hey - is this your dedicated server? &amp;nbsp;If so why don&amp;#39;t you install a packet sniffer and actually see what they are doing instead of trying to guess ;-)&lt;/p&gt;
&lt;p&gt;Dave&lt;/p&gt;
&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=6798391" width="1" height="1"&gt;</description></item><item><title>re: Hundreds of websites under attack and Microsoft are you doing something?</title><link>http://weblogs.asp.net/pleloup/archive/2008/12/19/hundreds-of-websites-under-attack-and-microsoft-are-you-doing-something.aspx#6798347</link><pubDate>Fri, 19 Dec 2008 15:17:55 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:6798347</guid><dc:creator>gt1329a</dc:creator><author>gt1329a</author><description>&lt;p&gt;I&amp;#39;m glad you posted this. &amp;nbsp;I checked in on our servers and found one that&amp;#39;s been under a brute force attack for a couple days now.&lt;/p&gt;
&lt;p&gt;All of the attempts on our server have come from 72.26.227.42.&lt;/p&gt;
&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=6798347" width="1" height="1"&gt;</description></item><item><title>re: Hundreds of websites under attack and Microsoft are you doing something?</title><link>http://weblogs.asp.net/pleloup/archive/2008/12/19/hundreds-of-websites-under-attack-and-microsoft-are-you-doing-something.aspx#6798320</link><pubDate>Fri, 19 Dec 2008 14:50:05 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:6798320</guid><dc:creator>Jonathan</dc:creator><author>Jonathan</author><description>&lt;p&gt;Glad you found the source of it man. &amp;nbsp; I have my DB server safely locked away behind a firewall only access is via the main web servers &lt;/p&gt;
&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=6798320" width="1" height="1"&gt;</description></item><item><title>re: Hundreds of websites under attack and Microsoft are you doing something?</title><link>http://weblogs.asp.net/pleloup/archive/2008/12/19/hundreds-of-websites-under-attack-and-microsoft-are-you-doing-something.aspx#6798201</link><pubDate>Fri, 19 Dec 2008 13:29:07 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:6798201</guid><dc:creator>ca8msm</dc:creator><author>ca8msm</author><description>&lt;p&gt;It&amp;#39;s probably just a hex injection. Properly secured code and web pages shouldn&amp;#39;t be affected by this though and it&amp;#39;s not a new problem.&lt;/p&gt;
&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=6798201" width="1" height="1"&gt;</description></item><item><title>re: Hundreds of websites under attack and Microsoft are you doing something?</title><link>http://weblogs.asp.net/pleloup/archive/2008/12/19/hundreds-of-websites-under-attack-and-microsoft-are-you-doing-something.aspx#6798199</link><pubDate>Fri, 19 Dec 2008 13:28:11 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:6798199</guid><dc:creator>andrex</dc:creator><author>andrex</author><description>&lt;p&gt;Looks like server just scanned for specific for open MS SQL ports and brute force attack with dictionary. It&amp;#39;s not related to any site or web.config.&lt;/p&gt;
&lt;p&gt;I see this on few servers (for last, fresh server, attack was started in 3 hours after I am install MS SQL!!!)&lt;/p&gt;
&lt;p&gt;I am solve this problem very easy. Block access to MS SQL ports via firewall (access allowed only for specific IP)&lt;/p&gt;
&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=6798199" width="1" height="1"&gt;</description></item><item><title>re: Hundreds of websites under attack and Microsoft are you doing something?</title><link>http://weblogs.asp.net/pleloup/archive/2008/12/19/hundreds-of-websites-under-attack-and-microsoft-are-you-doing-something.aspx#6798164</link><pubDate>Fri, 19 Dec 2008 13:05:07 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:6798164</guid><dc:creator>Jonathan</dc:creator><author>Jonathan</author><description>&lt;p&gt;I know this is an obvious statement but have you tried encrypting your connection strings ? &lt;/p&gt;
&lt;p&gt;I hope you get to the bottom of it soon dude &lt;/p&gt;
&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=6798164" width="1" height="1"&gt;</description></item><item><title>Hundreds of websites under attack and Microsoft are you doing something? - help.net</title><link>http://weblogs.asp.net/pleloup/archive/2008/12/19/hundreds-of-websites-under-attack-and-microsoft-are-you-doing-something.aspx#6798147</link><pubDate>Fri, 19 Dec 2008 12:59:32 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:6798147</guid><dc:creator>Hundreds of websites under attack and Microsoft are you doing something? - help.net</dc:creator><author>Hundreds of websites under attack and Microsoft are you doing something? - help.net</author><description>&lt;p&gt;Pingback from &amp;nbsp;Hundreds of websites under attack and Microsoft are you doing something? - help.net&lt;/p&gt;
&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=6798147" width="1" height="1"&gt;</description></item></channel></rss>