SQL Server CAN-2002-0649 exploit v1.34

Vulnerability exploited: CAN-2002-0649 - BID-5311

Category: Exploits/Remote

This module exploits a buffer overflow in MS SQL Server and installs a level0 agent into the target host.
This module exploits a vulnerability in the Microsoft SQL Server. After successful exploitation a level0 agent will be installed. If the attack was not successful, the server might stop responding (one-shot-exploit).

Supported Systems:
    Windows 2000 Server - sp0 (i386)
    Windows 2000 Server - sp1 (i386)
    Windows 2000 Server - sp2 (i386)
    Microsoft SQL Server 2000 SP0 running under Microsoft Windows 2000 Server
    Microsoft SQL Server 2000 SP0 running under Microsoft Windows 2000 Server SP1
    Microsoft SQL Server 2000 SP0 running under Microsoft Windows 2000 Server SP2


This module is included in the latest version of CORE IMPACT, the first automated comprehensive penetration testing product for accurately identifying information security risks. Click here to learn more about the product.