[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Missing admin sql password in Okena StormWatch
I was working with Okena StormWatch - a really interesting commercial
intrusion prevention product - and saw that there is the SQL password
for the admin account (sa) missing.
With a SQL client and a blank password it's possible for everyone who
can connect to the manager to compromise the whole system/network.
My notification was sent on Fri, 15 Nov 2002 14:21:01 +0100 to
info@xxxxxxxxx - Nothing came back.
Thanks to Mario Robic for helping discovering this problem.
Computer, Technik und Security