Security Incidents mailing list archives

RE: MSDE contained in...


From: "Mark E. Donaldson" <markee () ridgecrest ca us>
Date: Tue, 28 Jan 2003 18:25:17 -0800

MSDE "comes available" and "optional" with all these programs.  However, in
most cases it is not part of the normal install, and must be installed
separately and explicitly.  Heck, I've got Visio too, and Visual Studio .NET
installed on my primary machine.  But I do not have MSDE installed.

-----Original Message-----
From: Tina Bird [mailto:tbird () precision-guesswork com]
Sent: Monday, January 27, 2003 8:12 PM
To: incidents () securityfocus com; intrusions () incidents org; Ced Bennett;
tmd () Stanford edu; David Hoffman; eric.nakagawa () Stanford edu;
mnewton () Stanford edu; tsg () shmoo com; tbird65 () Stanford edu;
list-ni () counterpane com
Subject: MSDE contained in...


Chalk this all up to "things I wish I didn't know":  I've been amused and
skeptical at the list of applications people have claimed include MSDE,
that are therefore vulnerable to SQL Slammer.  In particular, I had a hard
time believing that Visio used it.  Heck, I've got Visio, and I'm pretty
sure it doesn't open any network connections.

So I prowled around the Web, and found this:
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/prodtechn
ol/visio/Visio2002/maintain/vis_msde.asp

MSDE is integrated with these Microsoft applications:

Microsoft Visio 2000 Enterprise Edition AutoDiscovery & Layout (AD&L)
solution
AD&L solution from Microsoft Visio Enterprise Network Tools 2002
Microsoft SharePoint Team Services (a Microsoft FrontPage Server
Extensions 2002 companion product)
Microsoft Project Central (a Microsoft Project 2000 companion product)
Microsoft Application Center

The following products ship MSDE on their product CD and can use MSDE as a
database:

Microsoft Access
Microsoft Office 2000
Microsoft Visual Studio 6.0

--> Bleh.  I stand corrected.

tbird

--
I, on the other hand, do not work. I enjoy the slothful life of an artist,
and while away the hours in meaningless aesthetic pursuits punctuated by
bouts of hedonistic debauchery and an occasional nap.
                                              -- David Rinehart

http://www.shmoo.com/~tbird
Log Analysis http://www.loganalysis.org
VPN http://vpn.shmoo.com



----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: