Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
The Case of the Unexplained FTP Connections (technet.com)
4 points by aespinoza on Nov 14, 2012 | hide | past | favorite | 1 comment


"Not realizing the server was on the perimeter, they had opened the SQL Server’s port in the local firewall, left it with a blank admin account, and enabled xp_cmdshell"

As the Mark states in the article, this is terrible even within the network, let alone on the perimeter. Microsoft actually recommends against running Exchange and SQL Server on the same box anyways [1] for performance reasons.

Is there a good intention that would motivate someone to install something on a production box, leave it in an insecure config, and not document it?

[1] http://technet.microsoft.com/en-us/library/aa997379(v=exchg....




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: