TUCoPS :: Web :: Apps :: web5489.htm

SQL server 2000 hex padding to fool trustees
27th Jun 2002 [SBWID-5489]

	SQL server 2000, probably all releases


	Chris Anley of NGSSoftware posted a whitepaper available at :



	\"It  discusses  \"runtime  patching\"  exploits,  specifically  in  the
	context of Microsoft SQL Server 2000, but  the  techniques  apply  to  a
	wide variety of targets. The paper also documents  a  three  byte  patch
	that disables access control in SQL Server, resulting (by  way  of  some
	tricks) in sysadmin access for all.\"

	Cool enough to be mentioned :-)



