Welcome to dbFreaks.com!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

sp_replwritetovarbin memory overwrite Security threat

 
Goto page 1, 2
   Database Help (Home) -> Security RSS
Next:  Caculated Measure - Date Filter - Range  
Author Message
jaylou

External


Since: Oct 12, 2004
Posts: 35



(Msg. 1) Posted: Thu Dec 11, 2008 7:13 am
Post subject: sp_replwritetovarbin memory overwrite Security threat
Archived from groups: microsoft>public>sqlserver>security (more info?)

I recieved an email about this procedure sp_replwritetovarbin. one
recomendation is to remove it from your system.

Does anyone know what this proc is for and what will break if removed?

Also does anyone know if this is a real threat?

TIA,
Joe

 >> Stay informed about: sp_replwritetovarbin memory overwrite Security threat 
Back to top
Login to vote
Chris Wood

External


Since: Jan 22, 2008
Posts: 93



(Msg. 2) Posted: Fri Dec 12, 2008 9:45 am
Post subject: Re: sp_replwritetovarbin memory overwrite Security threat [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Joe,

You saw this alert
http://www.sec-consult.com/files/20081209_mssql-2000-sp_replwritetovar..._memwri
right?

Chris

"jaylou" wrote in message

>I recieved an email about this procedure sp_replwritetovarbin. one
> recomendation is to remove it from your system.
>
> Does anyone know what this proc is for and what will break if removed?
>
> Also does anyone know if this is a real threat?
>
> TIA,
> Joe

 >> Stay informed about: sp_replwritetovarbin memory overwrite Security threat 
Back to top
Login to vote
jaylou

External


Since: Oct 12, 2004
Posts: 35



(Msg. 3) Posted: Fri Dec 12, 2008 9:45 am
Post subject: Re: sp_replwritetovarbin memory overwrite Security threat [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Yes I did. Do you know anything about this? I haven't been able to find
much more then more articles pointing back to this alert.

"Chris Wood" wrote:

> Joe,
>
> You saw this alert
> http://www.sec-consult.com/files/20081209_mssql-2000-sp_replwritetovar..._memwri
> right?
>
> Chris
>
> "jaylou" wrote in message
>
> >I recieved an email about this procedure sp_replwritetovarbin. one
> > recomendation is to remove it from your system.
> >
> > Does anyone know what this proc is for and what will break if removed?
> >
> > Also does anyone know if this is a real threat?
> >
> > TIA,
> > Joe
>
>
>
 >> Stay informed about: sp_replwritetovarbin memory overwrite Security threat 
Back to top
Login to vote
Chris Wood

External


Since: Jan 22, 2008
Posts: 93



(Msg. 4) Posted: Fri Dec 12, 2008 11:15 am
Post subject: Re: sp_replwritetovarbin memory overwrite Security threat [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Joe,

if they are serious about this I would expect a Security Advisory to appear
here http://www.microsoft.com/technet/security/advisory/default.mspx as the
problem has been publically announced.

Chris

"jaylou" wrote in message

> Yes I did. Do you know anything about this? I haven't been able to find
> much more then more articles pointing back to this alert.
>
> "Chris Wood" wrote:
>
>> Joe,
>>
>> You saw this alert
>> http://www.sec-consult.com/files/20081209_mssql-2000-sp_replwritetovar..._memwri
>> right?
>>
>> Chris
>>
>> "jaylou" wrote in message
>>
>> >I recieved an email about this procedure sp_replwritetovarbin. one
>> > recomendation is to remove it from your system.
>> >
>> > Does anyone know what this proc is for and what will break if removed?
>> >
>> > Also does anyone know if this is a real threat?
>> >
>> > TIA,
>> > Joe
>>
>>
>>
 >> Stay informed about: sp_replwritetovarbin memory overwrite Security threat 
Back to top
Login to vote
jaylou

External


Since: Oct 12, 2004
Posts: 35



(Msg. 5) Posted: Fri Dec 12, 2008 11:15 am
Post subject: Re: sp_replwritetovarbin memory overwrite Security threat [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

OK thank,
I just subscribed to the feed.

Thanks again for the info.

"Chris Wood" wrote:

> Joe,
>
> if they are serious about this I would expect a Security Advisory to appear
> here http://www.microsoft.com/technet/security/advisory/default.mspx as the
> problem has been publically announced.
>
> Chris
>
> "jaylou" wrote in message
>
> > Yes I did. Do you know anything about this? I haven't been able to find
> > much more then more articles pointing back to this alert.
> >
> > "Chris Wood" wrote:
> >
> >> Joe,
> >>
> >> You saw this alert
> >> http://www.sec-consult.com/files/20081209_mssql-2000-sp_replwritetovar..._memwri
> >> right?
> >>
> >> Chris
> >>
> >> "jaylou" wrote in message
> >>
> >> >I recieved an email about this procedure sp_replwritetovarbin. one
> >> > recomendation is to remove it from your system.
> >> >
> >> > Does anyone know what this proc is for and what will break if removed?
> >> >
> >> > Also does anyone know if this is a real threat?
> >> >
> >> > TIA,
> >> > Joe
> >>
> >>
> >>
>
>
>
 >> Stay informed about: sp_replwritetovarbin memory overwrite Security threat 
Back to top
Login to vote
Chris Wood

External


Since: Jan 22, 2008
Posts: 93



(Msg. 6) Posted: Tue Dec 16, 2008 7:47 am
Post subject: Re: sp_replwritetovarbin memory overwrite Security threat [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Joe,

MS just released SQL2005 SP2 CU11 and SP3 so don't be surprised that the fix
is announced in these builds when the January patches are announced. The
original advisory shows that MS were told about this a few months ago so I
would expect them to have looked at SQL2000/SQL2005 and SQL2008 at that
time. They would have seen that if it was in SQL2000 that it was also be in
SQL2005 and check out SQL2008 as well.

Chris

"jaylou" wrote in message

> OK thank,
> I just subscribed to the feed.
>
> Thanks again for the info.
>
> "Chris Wood" wrote:
>
>> Joe,
>>
>> if they are serious about this I would expect a Security Advisory to
>> appear
>> here http://www.microsoft.com/technet/security/advisory/default.mspx as
>> the
>> problem has been publically announced.
>>
>> Chris
>>
>> "jaylou" wrote in message
>>
>> > Yes I did. Do you know anything about this? I haven't been able to
>> > find
>> > much more then more articles pointing back to this alert.
>> >
>> > "Chris Wood" wrote:
>> >
>> >> Joe,
>> >>
>> >> You saw this alert
>> >> http://www.sec-consult.com/files/20081209_mssql-2000-sp_replwritetovar..._memwri
>> >> right?
>> >>
>> >> Chris
>> >>
>> >> "jaylou" wrote in message
>> >>
>> >> >I recieved an email about this procedure sp_replwritetovarbin. one
>> >> > recomendation is to remove it from your system.
>> >> >
>> >> > Does anyone know what this proc is for and what will break if
>> >> > removed?
>> >> >
>> >> > Also does anyone know if this is a real threat?
>> >> >
>> >> > TIA,
>> >> > Joe
>> >>
>> >>
>> >>
>>
>>
>>
 >> Stay informed about: sp_replwritetovarbin memory overwrite Security threat 
Back to top
Login to vote
jaylou

External


Since: Oct 12, 2004
Posts: 35



(Msg. 7) Posted: Tue Dec 16, 2008 7:47 am
Post subject: Re: sp_replwritetovarbin memory overwrite Security threat [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Thank you again!!

"Chris Wood" wrote:

> Joe,
>
> MS just released SQL2005 SP2 CU11 and SP3 so don't be surprised that the fix
> is announced in these builds when the January patches are announced. The
> original advisory shows that MS were told about this a few months ago so I
> would expect them to have looked at SQL2000/SQL2005 and SQL2008 at that
> time. They would have seen that if it was in SQL2000 that it was also be in
> SQL2005 and check out SQL2008 as well.
>
> Chris
>
> "jaylou" wrote in message
>
> > OK thank,
> > I just subscribed to the feed.
> >
> > Thanks again for the info.
> >
> > "Chris Wood" wrote:
> >
> >> Joe,
> >>
> >> if they are serious about this I would expect a Security Advisory to
> >> appear
> >> here http://www.microsoft.com/technet/security/advisory/default.mspx as
> >> the
> >> problem has been publically announced.
> >>
> >> Chris
> >>
> >> "jaylou" wrote in message
> >>
> >> > Yes I did. Do you know anything about this? I haven't been able to
> >> > find
> >> > much more then more articles pointing back to this alert.
> >> >
> >> > "Chris Wood" wrote:
> >> >
> >> >> Joe,
> >> >>
> >> >> You saw this alert
> >> >> http://www.sec-consult.com/files/20081209_mssql-2000-sp_replwritetovar..._memwri
> >> >> right?
> >> >>
> >> >> Chris
> >> >>
> >> >> "jaylou" wrote in message
> >> >>
> >> >> >I recieved an email about this procedure sp_replwritetovarbin. one
> >> >> > recomendation is to remove it from your system.
> >> >> >
> >> >> > Does anyone know what this proc is for and what will break if
> >> >> > removed?
> >> >> >
> >> >> > Also does anyone know if this is a real threat?
> >> >> >
> >> >> > TIA,
> >> >> > Joe
> >> >>
> >> >>
> >> >>
> >>
> >>
> >>
>
>
>
 >> Stay informed about: sp_replwritetovarbin memory overwrite Security threat 
Back to top
Login to vote
lmpreiki

External


Since: Dec 17, 2008
Posts: 2



(Msg. 8) Posted: Wed Dec 17, 2008 1:11 pm
Post subject: RE: sp_replwritetovarbin memory overwrite Security threat [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Was anyone able to identify what this proc does or what might break if removed?

Thanks,

"jaylou" wrote:

> I recieved an email about this procedure sp_replwritetovarbin. one
> recomendation is to remove it from your system.
>
> Does anyone know what this proc is for and what will break if removed?
>
> Also does anyone know if this is a real threat?
>
> TIA,
> Joe
 >> Stay informed about: sp_replwritetovarbin memory overwrite Security threat 
Back to top
Login to vote
jaylou

External


Since: Oct 12, 2004
Posts: 35



(Msg. 9) Posted: Thu Dec 18, 2008 4:58 am
Post subject: RE: sp_replwritetovarbin memory overwrite Security threat [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Not yet, and I still havent seen any alerts from Microsoft on this.


"lmpreiki" wrote:

> Was anyone able to identify what this proc does or what might break if removed?
>
> Thanks,
>
> "jaylou" wrote:
>
> > I recieved an email about this procedure sp_replwritetovarbin. one
> > recomendation is to remove it from your system.
> >
> > Does anyone know what this proc is for and what will break if removed?
> >
> > Also does anyone know if this is a real threat?
> >
> > TIA,
> > Joe
 >> Stay informed about: sp_replwritetovarbin memory overwrite Security threat 
Back to top
Login to vote
lmpreiki

External


Since: Dec 17, 2008
Posts: 2



(Msg. 10) Posted: Thu Dec 18, 2008 5:43 am
Post subject: RE: sp_replwritetovarbin memory overwrite Security threat [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Even though I've searched the Microsoft website and anywhere else I can think
of several times I haven't found anything either. I can't possibly delete a
procedure on without knowing what impact it might have.

"jaylou" wrote:

> Not yet, and I still havent seen any alerts from Microsoft on this.
>
>
> "lmpreiki" wrote:
>
> > Was anyone able to identify what this proc does or what might break if removed?
> >
> > Thanks,
> >
> > "jaylou" wrote:
> >
> > > I recieved an email about this procedure sp_replwritetovarbin. one
> > > recomendation is to remove it from your system.
> > >
> > > Does anyone know what this proc is for and what will break if removed?
> > >
> > > Also does anyone know if this is a real threat?
> > >
> > > TIA,
> > > Joe
 >> Stay informed about: sp_replwritetovarbin memory overwrite Security threat 
Back to top
Login to vote
jaylou

External


Since: Oct 12, 2004
Posts: 35



(Msg. 11) Posted: Thu Dec 18, 2008 6:17 am
Post subject: RE: sp_replwritetovarbin memory overwrite Security threat [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

I agree. I am waiting until I hear from Microsoft. I think the alert came
from a third party consulting group. looking for work maybe? Smile

"lmpreiki" wrote:

> Even though I've searched the Microsoft website and anywhere else I can think
> of several times I haven't found anything either. I can't possibly delete a
> procedure on without knowing what impact it might have.
>
> "jaylou" wrote:
>
> > Not yet, and I still havent seen any alerts from Microsoft on this.
> >
> >
> > "lmpreiki" wrote:
> >
> > > Was anyone able to identify what this proc does or what might break if removed?
> > >
> > > Thanks,
> > >
> > > "jaylou" wrote:
> > >
> > > > I recieved an email about this procedure sp_replwritetovarbin. one
> > > > recomendation is to remove it from your system.
> > > >
> > > > Does anyone know what this proc is for and what will break if removed?
> > > >
> > > > Also does anyone know if this is a real threat?
> > > >
> > > > TIA,
> > > > Joe
 >> Stay informed about: sp_replwritetovarbin memory overwrite Security threat 
Back to top
Login to vote
Chris Wood

External


Since: Jan 22, 2008
Posts: 93



(Msg. 12) Posted: Thu Dec 18, 2008 8:03 am
Post subject: Re: sp_replwritetovarbin memory overwrite Security threat [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Joe,

If you are talking SQL2005 you cannot delete it but you can take away the
public access to it. I would do the same on SQL2000, just stop it being
accessed by the public role.

Chris

"jaylou" wrote in message

>I agree. I am waiting until I hear from Microsoft. I think the alert came
> from a third party consulting group. looking for work maybe? Smile
>
> "lmpreiki" wrote:
>
>> Even though I've searched the Microsoft website and anywhere else I can
>> think
>> of several times I haven't found anything either. I can't possibly
>> delete a
>> procedure on without knowing what impact it might have.
>>
>> "jaylou" wrote:
>>
>> > Not yet, and I still havent seen any alerts from Microsoft on this.
>> >
>> >
>> > "lmpreiki" wrote:
>> >
>> > > Was anyone able to identify what this proc does or what might break
>> > > if removed?
>> > >
>> > > Thanks,
>> > >
>> > > "jaylou" wrote:
>> > >
>> > > > I recieved an email about this procedure sp_replwritetovarbin. one
>> > > > recomendation is to remove it from your system.
>> > > >
>> > > > Does anyone know what this proc is for and what will break if
>> > > > removed?
>> > > >
>> > > > Also does anyone know if this is a real threat?
>> > > >
>> > > > TIA,
>> > > > Joe
 >> Stay informed about: sp_replwritetovarbin memory overwrite Security threat 
Back to top
Login to vote
jaylou

External


Since: Oct 12, 2004
Posts: 35



(Msg. 13) Posted: Thu Dec 18, 2008 8:03 am
Post subject: Re: sp_replwritetovarbin memory overwrite Security threat [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

this is true.

In my spare time, I am researching what this proc is for and what needs
acces to it.

I will remove the access on a dev server and see what happens.

Thanks Again,
Joe




"Chris Wood" wrote:

> Joe,
>
> If you are talking SQL2005 you cannot delete it but you can take away the
> public access to it. I would do the same on SQL2000, just stop it being
> accessed by the public role.
>
> Chris
>
> "jaylou" wrote in message
>
> >I agree. I am waiting until I hear from Microsoft. I think the alert came
> > from a third party consulting group. looking for work maybe? Smile
> >
> > "lmpreiki" wrote:
> >
> >> Even though I've searched the Microsoft website and anywhere else I can
> >> think
> >> of several times I haven't found anything either. I can't possibly
> >> delete a
> >> procedure on without knowing what impact it might have.
> >>
> >> "jaylou" wrote:
> >>
> >> > Not yet, and I still havent seen any alerts from Microsoft on this.
> >> >
> >> >
> >> > "lmpreiki" wrote:
> >> >
> >> > > Was anyone able to identify what this proc does or what might break
> >> > > if removed?
> >> > >
> >> > > Thanks,
> >> > >
> >> > > "jaylou" wrote:
> >> > >
> >> > > > I recieved an email about this procedure sp_replwritetovarbin. one
> >> > > > recomendation is to remove it from your system.
> >> > > >
> >> > > > Does anyone know what this proc is for and what will break if
> >> > > > removed?
> >> > > >
> >> > > > Also does anyone know if this is a real threat?
> >> > > >
> >> > > > TIA,
> >> > > > Joe
>
>
>
 >> Stay informed about: sp_replwritetovarbin memory overwrite Security threat 
Back to top
Login to vote
Chris Wood

External


Since: Jan 22, 2008
Posts: 93



(Msg. 14) Posted: Tue Dec 23, 2008 7:58 am
Post subject: Re: sp_replwritetovarbin memory overwrite Security threat [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Joe,

Microsoft issued a security advisory, as expected, and it mentions that they
fixed it in SQL2005 SP3 so it could be in SP2 CU10 or CU11 as well. See
http://www.microsoft.com/technet/security/advisory/961040.mspx

Chris

"jaylou" wrote in message

> Thank you again!!
>
> "Chris Wood" wrote:
>
>> Joe,
>>
>> MS just released SQL2005 SP2 CU11 and SP3 so don't be surprised that the
>> fix
>> is announced in these builds when the January patches are announced. The
>> original advisory shows that MS were told about this a few months ago so
>> I
>> would expect them to have looked at SQL2000/SQL2005 and SQL2008 at that
>> time. They would have seen that if it was in SQL2000 that it was also be
>> in
>> SQL2005 and check out SQL2008 as well.
>>
>> Chris
>>
>> "jaylou" wrote in message
>>
>> > OK thank,
>> > I just subscribed to the feed.
>> >
>> > Thanks again for the info.
>> >
>> > "Chris Wood" wrote:
>> >
>> >> Joe,
>> >>
>> >> if they are serious about this I would expect a Security Advisory to
>> >> appear
>> >> here http://www.microsoft.com/technet/security/advisory/default.mspx
>> >> as
>> >> the
>> >> problem has been publically announced.
>> >>
>> >> Chris
>> >>
>> >> "jaylou" wrote in message
>> >>
>> >> > Yes I did. Do you know anything about this? I haven't been able to
>> >> > find
>> >> > much more then more articles pointing back to this alert.
>> >> >
>> >> > "Chris Wood" wrote:
>> >> >
>> >> >> Joe,
>> >> >>
>> >> >> You saw this alert
>> >> >> http://www.sec-consult.com/files/20081209_mssql-2000-sp_replwritetovar..._memwri
>> >> >> right?
>> >> >>
>> >> >> Chris
>> >> >>
>> >> >> "jaylou" wrote in message
>> >> >>
>> >> >> >I recieved an email about this procedure sp_replwritetovarbin.
>> >> >> >one
>> >> >> > recomendation is to remove it from your system.
>> >> >> >
>> >> >> > Does anyone know what this proc is for and what will break if
>> >> >> > removed?
>> >> >> >
>> >> >> > Also does anyone know if this is a real threat?
>> >> >> >
>> >> >> > TIA,
>> >> >> > Joe
>> >> >>
>> >> >>
>> >> >>
>> >>
>> >>
>> >>
>>
>>
>>
 >> Stay informed about: sp_replwritetovarbin memory overwrite Security threat 
Back to top
Login to vote
Chris Wood

External


Since: Jan 22, 2008
Posts: 93



(Msg. 15) Posted: Fri Jan 09, 2009 3:02 pm
Post subject: Re: sp_replwritetovarbin memory overwrite Security threat [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Joe,

Seems that it didn't make a security bulletin this month.

Chris

"Chris Wood" wrote in message

> Joe,
>
> Microsoft issued a security advisory, as expected, and it mentions that
> they fixed it in SQL2005 SP3 so it could be in SP2 CU10 or CU11 as well.
> See http://www.microsoft.com/technet/security/advisory/961040.mspx
>
> Chris
>
> "jaylou" wrote in message
>
>> Thank you again!!
>>
>> "Chris Wood" wrote:
>>
>>> Joe,
>>>
>>> MS just released SQL2005 SP2 CU11 and SP3 so don't be surprised that the
>>> fix
>>> is announced in these builds when the January patches are announced. The
>>> original advisory shows that MS were told about this a few months ago so
>>> I
>>> would expect them to have looked at SQL2000/SQL2005 and SQL2008 at that
>>> time. They would have seen that if it was in SQL2000 that it was also be
>>> in
>>> SQL2005 and check out SQL2008 as well.
>>>
>>> Chris
>>>
>>> "jaylou" wrote in message
>>>
>>> > OK thank,
>>> > I just subscribed to the feed.
>>> >
>>> > Thanks again for the info.
>>> >
>>> > "Chris Wood" wrote:
>>> >
>>> >> Joe,
>>> >>
>>> >> if they are serious about this I would expect a Security Advisory to
>>> >> appear
>>> >> here http://www.microsoft.com/technet/security/advisory/default.mspx
>>> >> as
>>> >> the
>>> >> problem has been publically announced.
>>> >>
>>> >> Chris
>>> >>
>>> >> "jaylou" wrote in message
>>> >>
>>> >> > Yes I did. Do you know anything about this? I haven't been able
>>> >> > to
>>> >> > find
>>> >> > much more then more articles pointing back to this alert.
>>> >> >
>>> >> > "Chris Wood" wrote:
>>> >> >
>>> >> >> Joe,
>>> >> >>
>>> >> >> You saw this alert
>>> >> >> http://www.sec-consult.com/files/20081209_mssql-2000-sp_replwritetovar..._memwri
>>> >> >> right?
>>> >> >>
>>> >> >> Chris
>>> >> >>
>>> >> >> "jaylou" wrote in message
>>> >> >>
>>> >> >> >I recieved an email about this procedure sp_replwritetovarbin.
>>> >> >> >one
>>> >> >> > recomendation is to remove it from your system.
>>> >> >> >
>>> >> >> > Does anyone know what this proc is for and what will break if
>>> >> >> > removed?
>>> >> >> >
>>> >> >> > Also does anyone know if this is a real threat?
>>> >> >> >
>>> >> >> > TIA,
>>> >> >> > Joe
>>> >> >>
>>> >> >>
>>> >> >>
>>> >>
>>> >>
>>> >>
>>>
>>>
>>>
>
>
 >> Stay informed about: sp_replwritetovarbin memory overwrite Security threat 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Security Audit - I have problem with opening a SQL Server Logs. It takes over 5-10minutes to open the log file (Under Management->SQL Server Logs->Current). I have Audit level to log "ALL" due to SOX compliance. The errorlog files are about 19 megaby...

Integrated Security in the DMZ - I have a test web server in a domain. The IIS identity as a domain account. The website can access SQl Server (2005) using integrated security. I have a production web server in DMZ out side the domain. How can I setup the webserver to use integrated....

Record level security? - Hello, is it possible to not allow changes to certain records in a sql2k user table? We have a table that holds data for a periodic report and was wondering if it would be possible to not allow any changes/deletions to certain records that fall withi...

Security - Lock Database - I want to make some changes regarding accessing my SQL Server Database, but before I start playing around with it, I want to post something to see if anyone can give me some guidence so I don't end up locking myself out of my SQL Server Database or SQ...

ODBC Connection security - I have a need to find out when any ODBC connection is made to a certain SQL Server. I assume any/all ODBC connections will have to use TCP port 1433 - since SQL uses only TCP 1433 in this server's case. Is there any SQL method to detect a new ODBC..
   Database Help (Home) -> Security All times are: Pacific Time (US & Canada)
Goto page 1, 2
Page 1 of 2

 
You can post new topics in this forum
You can reply to topics in this forum
You can edit your posts in this forum
You can delete your posts in this forum
You can vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]