Port Details - Port 1433

Aug 07 805 Aug 08 891 Aug 09 953 Aug 10 936 Aug 11 906 Aug 12 912 Aug 13 926 Aug 14 897 Aug 15 897 Aug 16 963 Aug 17 981 Aug 18 934 Aug 19 959 Aug 20 944 Aug 21 870 Aug 22 898 Aug 23 890 Aug 24 905 Aug 25 839 Aug 26 874 Aug 27 898 Aug 28 801 Aug 29 799 Aug 30 896 Aug 31 855 Sep 01 968 Sep 02 769 Sep 03 770 Sep 04 807 Sep 05 804 Sep 06 718 Aug 07 78,248 Aug 08 79,458 Aug 09 78,253 Aug 10 66,207 Aug 11 76,734 Aug 12 53,428 Aug 13 78,269 Aug 14 77,239 Aug 15 74,636 Aug 16 74,086 Aug 17 76,346 Aug 18 59,265 Aug 19 64,348 Aug 20 78,000 Aug 21 74,082 Aug 22 73,277 Aug 23 77,344 Aug 24 77,822 Aug 25 76,840 Aug 26 39,434 Aug 27 47,026 Aug 28 73,437 Aug 29 76,797 Aug 30 77,258 Aug 31 65,947 Sep 01 77,874 Sep 02 78,098 Sep 03 76,886 Sep 04 74,860 Sep 05 76,862 Sep 06 73,656
[show ascii data]
  • Start Date:
  • End Date:
  • Port:
  • Left Graph:
  • Right Graph:
  • Show Range:Yes No

Port Information

ProtocolServiceName
tcpms-sql-sMicrosoft-SQL-Server
udpms-sql-sMicrosoft-SQL-Server
[get complete service list]

User Comment

Submitted ByDate
Comment
Marcus H. Sachs, SANS Institute2003-10-10 00:50:59
SANS Top-20 Entry: W2 Microsoft SQL Server (MSSQL) http://isc.sans.org/top20.html#w2 The Microsoft SQL Server (MSSQL) contains several serious vulnerabilities that allow remote attackers to obtain sensitive information, alter database content, compromise SQL servers, and, in some configurations, compromise server hosts. MSSQL vulnerabilities are well-publicized and actively under attack. Two recent MSSQL worms in May 2002 and January 2003 exploited several known MSSQL flaws. Hosts compromised by these worms generate a damaging level of network traffic when they scan for other vulnerable hosts.
Johannes Ullrich2002-10-10 17:21:35
Port 1433 is used by Microsoft SQL Server. SQLSnake is one worm taking advantage of SQL Server installs without password. As SQL Server is able to run batch files and command line programs, it can be used to download and install malware. Basic Protection: Use good passwords for all SQL Server accounts.
Add a comment

CVE Links

CVE #Description
CVE-1999-287 "Vulnerability in the Wguest CGI program."
CVE-2000-1081 "The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP)
CVE-2000-1082 "The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP)
CVE-2000-1083 "The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP)
CVE-2000-1084 "The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP)
CVE-2000-1085 "The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP)
CVE-2000-1086 "The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP)
CVE-2000-1088 "The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP)
CVE-2001-542 "Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror
CVE-2002-642 "The registry key containing the SQL Server service account information in Microsoft SQL Server 2000