Home > Security Experts Alarmed by Exposed Database Servers

News

Security Experts Alarmed by Exposed Database Servers

11/16/2007

Responding to a soon-to-be released study revealing that as many as a half a million database servers aren't protected by firewalls, security experts contend the findings constitute a call to action for security pros and database administrators everywhere.

David Litchfield, managing director of UK-based NGSSoftware, plans to publish the full survey report on Monday on his Website, Databasesecurity.com. Using a sample group of 157 SQL servers and 53 Oracle Database servers, Litchfield based his conclusions on the Ant Census from the University of Southern California's Information Sciences Institute. The census is a project that's mapped more than 4.3 billion IP addresses, collecting data to get a snapshot of the Internet. Based on those addresses, he projected that there are approximately 368,000 Microsoft SQL Servers and about 124,000 Oracle database servers directly accessible on the Internet, the report found.

"When you see something like this, it certainly does seem alarming," said Gil Kirkpatrick, an Expert in Residence for Phoenix-based IT consultancy NetPro. "Even though with surveys like this you want to know how many of the servers included were inactive or honey pots or non-relevant, I still don't see why anyone wouldn't want to protect their database."

Entry into a database server can give a hacker a doorway into a company's IP domain; it could even serve as a conduit to eventually taking control of the entire network. Equally concerning is that the number of exposed SQL servers has increased considerably from the 210,000 in Litchfield's last such report, in 2005.

"I'm surprised at the number of SQL servers that are exposed like that," said Ben Greenbaum, senior research manager with Symantec Security Response. "What this says is that many organizations don't have good patching policies and have adopted an "if-it works-don't-break-it' attitude."

Litchfield, who wrote the proof-of-concept code that later morphed into the "Slammer" worm that ravaged SQL servers four years ago, called the patching of SQL servers "atrocious." He also found that approximately 82 percent of the SQL servers were using older SQL versions, from SQL Server 2000 and back. Moreover, service pack updates were notably absent on most of the machines included in calculating the findings.

A Microsoft spokesman pointed out, via e-mail, that the findings don't mean that SQL server is inherently unsafe. "NGS Security has released a paper in which they looked for database servers directly accessible from public internet. No new vulnerabilities for SQL Server were found. Database and system administrators should ensure that the host firewall is configured properly, in accordance with local security policies," the statement read. The company further suggests that network administrators ensure that perimeter access is configured properly, and that interior hosts are not exposed to unwanted traffic. In most cases, that means blocking access to port 1433/TCP from outside the network perimeter.


Recommended Reading
  • College of Southern Nevada Implementing Angel To Run Online Courses

    The College of Southern Nevada (CSN), a community college in Las Vegas with 41,000 students, has adopted the Angel Learning Management Suite (LMS) to support its online course offerings. In Spring 2008 CSN began evaluating alternatives to WebCT, which it currently runs, and made the decision to adopt Angel in the fall. In January 2009, CSN's 865 sections of online enrollment will be delivered using the Angel LMS.

  • Toshiba Brings DisplayLink to Docking Station

    Toshiba has introduced a new USB docking station that incorporates DisplayLink--a technology that allows computers to connect to projectors and other types of displays through USB 2.0.

  • Mitsubishi Ships SXGA+ Projector with DICOM Simulation

    Mitsubishi has begun shipping a new LCD-based SXGA+ projector aimed at higher education, specifically medical schools. The new MH2850U, according to Mitsubishi, is "specially engineered for projecting DICOM simulation images for use in medical education and training."

  • First Look: Komodo IDE 5.0

    Last month, ActiveState released Komodo IDE 5.0, the company's latest integrated development environment (IDE). Komodo supports multiple programming and markup languages, including HTML, JavaScript, PHP, Perl, Java, Python, C++ and more. It does not support some .NET languages at present, such as ASP/ASP.NET, C# and VB.NET.

  • IBM Offers Cloud Computing Help

    IBM last week announced consulting services specifically designed to help organizations assess their options in using cloud computing technology. "Cloud computing" is a much argued term, but it typically refers to solutions delivered over the Internet, rather than via customer premises-installed software.

  • Hollins U Chooses Omnilert for Emergency Notification Ahead of VA Deadline

    Hollins University, among other higher ed institutions in Virginia, has implemented Omnilert's e2Campus emergency notification system (ENS) just ahead of a state-mandated deadline requiring them at every public institution of higher education by Jan. 1. Hollins itself isn't a public campus, but wished to implement an ENS before the end of the year, the school said in a company statement.