News

Microsoft Releases SQL Server Security Tools

Microsoft released a beta version of its Code Analysis Tool and Anti-Cross Site Scripting Library for developers.

Microsoft on Tuesday released the latest beta versions of its Code Analysis Tool and Anti-Cross Site Scripting Library for developers, a critical part of which is a tool to identify vulnerabilities to SQL injection attacks and other incursions.

Both releases come just days after a zero-day flaw impacting SQL Server 2000 and Microsoft Internet Information Services (IIS) servers emerged.

The flaw, as described by Austria-based SEC Consult advisory, makes it possible for hackers to target the vulnerability remotely on Web sites that link search boxes, customer databases or other Web apps to SQL Server. According to the advisory, the SQL vulnerability can be exploited by an authenticated user with a direct database connection, or via SQL injection in a vulnerable Web application. SEC Consult came to this conclusion after successfully executing arbitrary code on one of its lab machines.

Microsoft is still investigating the flaw, but -- unlike the recently discovered zero-day Internet Explorer bug -- as of Tuesday there were no reports of the vulnerability being exploited in the wild.

However, the release of these tools (designed to complement a previous workaround released in June) comes amid alarming growth in SQL Server injection attacks. Expert say such attacks exploit security vulnerabilities and insert malicious code into a database serving as the back-end of any Web site. While it may not be as urgent as fixing as IE, recovering from a SQL injection attack can be difficult. There are numerous cases of Web site owners cleaning up their database only to be hit again a few hours later because a replicating attack mechanism is written into the coding and can't be wiped off by rebooting or via anti-virus software, as other exploits can.

About the Author

Jabulani Leffall is an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others.

Featured

  • IBM Giving Orgs a Governance Lifeline in Agentic AI Era

    Nearly overnight, organizations are facing brand-new challenges caused by self-directed AI systems (a.k.a. agentic AI). Big Blue is extending them some help.

  • Microsoft Launches Integrated E-mail Security Ecosystem for Defender for Office 365

    Microsoft is expanding its e-mail security capabilities with the launch of a new Integrated Cloud Email Security (ICES) ecosystem for Microsoft Defender for Office 365.

  • Microsoft Joins Workday's AI Agent Partner Network

    Microsoft has become a key partner in Workday's newly launched AI Agent Partner Network, aligning with other industry leaders to integrate AI agents into enterprise workforce systems.

  • LinkedIn CEO Ryan Roslansky To Lead Microsoft's Productivity Initiatives

    In a strategic leadership realignment, Microsoft has appointed LinkedIn CEO Ryan Roslansky to oversee its consumer and small business productivity software division, encompassing Microsoft 365, Teams and AI-driven tools like Copilot.