Port Details - Port 1433

Jun 30 1,171 Jul 01 1,167 Jul 02 1,108 Jul 03 1,053 Jul 04 1,081 Jul 05 1,187 Jul 06 1,121 Jul 07 1,078 Jul 08 1,111 Jul 09 1,174 Jul 10 1,050 Jul 11 927 Jul 12 1,112 Jul 13 1,081 Jul 14 1,058 Jul 15 1,001 Jul 16 986 Jul 17 988 Jul 18 934 Jul 19 1,052 Jul 20 1,071 Jul 21 1,049 Jul 22 1,019 Jul 23 1,062 Jul 24 905 Jul 25 997 Jul 26 1,089 Jul 27 1,012 Jul 28 1,011 Jul 29 892 Jul 30 190 Jun 30 77,587 Jul 01 78,727 Jul 02 78,969 Jul 03 77,381 Jul 04 77,297 Jul 05 76,729 Jul 06 62,965 Jul 07 66,036 Jul 08 78,715 Jul 09 71,648 Jul 10 62,878 Jul 11 78,286 Jul 12 77,827 Jul 13 78,499 Jul 14 78,561 Jul 15 78,460 Jul 16 68,388 Jul 17 75,961 Jul 18 78,312 Jul 19 66,909 Jul 20 54,060 Jul 21 69,545 Jul 22 68,444 Jul 23 77,907 Jul 24 25,943 Jul 25 77,265 Jul 26 32,572 Jul 27 78,437 Jul 28 77,313 Jul 29 72,920 Jul 30 66,583
[show ascii data]
  • Start Date:
  • End Date:
  • Port:
  • Left Graph:
  • Right Graph:
  • Show Range:Yes No

Port Information

ProtocolServiceName
tcpms-sql-sMicrosoft-SQL-Server
udpms-sql-sMicrosoft-SQL-Server
[get complete service list]

User Comment

Submitted ByDate
Comment
Marcus H. Sachs, SANS Institute2003-10-10 00:50:59
SANS Top-20 Entry: W2 Microsoft SQL Server (MSSQL) http://isc.sans.org/top20.html#w2 The Microsoft SQL Server (MSSQL) contains several serious vulnerabilities that allow remote attackers to obtain sensitive information, alter database content, compromise SQL servers, and, in some configurations, compromise server hosts. MSSQL vulnerabilities are well-publicized and actively under attack. Two recent MSSQL worms in May 2002 and January 2003 exploited several known MSSQL flaws. Hosts compromised by these worms generate a damaging level of network traffic when they scan for other vulnerable hosts.
Johannes Ullrich2002-10-10 17:21:35
Port 1433 is used by Microsoft SQL Server. SQLSnake is one worm taking advantage of SQL Server installs without password. As SQL Server is able to run batch files and command line programs, it can be used to download and install malware. Basic Protection: Use good passwords for all SQL Server accounts.
Add a comment

CVE Links

CVE #Description
CVE-1999-287 "Vulnerability in the Wguest CGI program."
CVE-2000-1081 "The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP)
CVE-2000-1082 "The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP)
CVE-2000-1083 "The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP)
CVE-2000-1084 "The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP)
CVE-2000-1085 "The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP)
CVE-2000-1086 "The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP)
CVE-2000-1088 "The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP)
CVE-2001-542 "Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror
CVE-2002-642 "The registry key containing the SQL Server service account information in Microsoft SQL Server 2000