Home > Security Experts Alarmed by Exposed Database Servers

News

Security Experts Alarmed by Exposed Database Servers

11/16/2007

Responding to a soon-to-be released study revealing that as many as a half a million database servers aren't protected by firewalls, security experts contend the findings constitute a call to action for security pros and database administrators everywhere.

David Litchfield, managing director of UK-based NGSSoftware, plans to publish the full survey report on Monday on his Website, Databasesecurity.com. Using a sample group of 157 SQL servers and 53 Oracle Database servers, Litchfield based his conclusions on the Ant Census from the University of Southern California's Information Sciences Institute. The census is a project that's mapped more than 4.3 billion IP addresses, collecting data to get a snapshot of the Internet. Based on those addresses, he projected that there are approximately 368,000 Microsoft SQL Servers and about 124,000 Oracle database servers directly accessible on the Internet, the report found.

"When you see something like this, it certainly does seem alarming," said Gil Kirkpatrick, an Expert in Residence for Phoenix-based IT consultancy NetPro. "Even though with surveys like this you want to know how many of the servers included were inactive or honey pots or non-relevant, I still don't see why anyone wouldn't want to protect their database."

Entry into a database server can give a hacker a doorway into a company's IP domain; it could even serve as a conduit to eventually taking control of the entire network. Equally concerning is that the number of exposed SQL servers has increased considerably from the 210,000 in Litchfield's last such report, in 2005.

"I'm surprised at the number of SQL servers that are exposed like that," said Ben Greenbaum, senior research manager with Symantec Security Response. "What this says is that many organizations don't have good patching policies and have adopted an "if-it works-don't-break-it' attitude."

Litchfield, who wrote the proof-of-concept code that later morphed into the "Slammer" worm that ravaged SQL servers four years ago, called the patching of SQL servers "atrocious." He also found that approximately 82 percent of the SQL servers were using older SQL versions, from SQL Server 2000 and back. Moreover, service pack updates were notably absent on most of the machines included in calculating the findings.

A Microsoft spokesman pointed out, via e-mail, that the findings don't mean that SQL server is inherently unsafe. "NGS Security has released a paper in which they looked for database servers directly accessible from public internet. No new vulnerabilities for SQL Server were found. Database and system administrators should ensure that the host firewall is configured properly, in accordance with local security policies," the statement read. The company further suggests that network administrators ensure that perimeter access is configured properly, and that interior hosts are not exposed to unwanted traffic. In most cases, that means blocking access to port 1433/TCP from outside the network perimeter.


Recommended Reading
  • Talisma Launches New Version of CRM with Built-in Application Management

    Talisma Corp. announced version 8.0 of its constituent relationship management (CRM) application for higher education. The new release includes application management, a revamped user interface, two-way text messaging, personalized Web portals, and an ADA-compliant Web client, among other enhancements.

  • Bringing Composers into Classrooms Through Skype

    Two Pennsylvania teaching colleagues with an interest in music and technology are bringing remote experts into classrooms at almost no cost, using Skype's free videoconferencing technology.

  • Columbia U Going Live on iTunes U

    Columbia University has been beta testing its content through iTunes U, the Apple desktop media player for education-related podcasting. The New York-based university expects to go live with its release at the start of the fall semester.

  • Let the Games Begin! Google vs. Microsoft

    Pursuing a strategy as a consumer of services and choice, Drexel University has partnered with both Google and Microsoft to provide students with massive e-mail mailboxes, gigabytes of file storage with collaboration tools, Web-based calendars, personal blogs, and more.

  • Ferrum College Enrolls Juniper Networks To Extend 10 Gigabit Ethernet

    Ferrum College in southwestern Virginia has chosen to replace its campus-wide legacy Cisco network infrastructure with Juniper Network switching, network access control (NAC), and firewall/virtual private network (VPN) solutions. The college chose the new equipment after deciding to extend 10 Gigabit Ethernet (10GbE) throughput across the network in support of advanced voice over IP (VoIP) by fall 2009.

  • Tiffin U's New Online College to Use Pearson's eCollege for Course Management

    Beginning this fall, students in Tiffin University's newest online program, Ivy Bridge College, will use eCollege, a course management system from Pearson, for all of their online courses. The 2,350-student Tiffin U is located in Tiffin, OH and offers both on-campus and online classes. Since 2005, those online courses have been managed through Jenzabar Internet Campus Solution.