PDA

View Full Version : SQL Server Configuration Manager , uncommanded run ?


aseanaero
9th May 2009, 09:01
Today I opened up my notebook and noticed that SQL Server Configuration Manager was in the list of recently used programs.

I wasn't even aware I had it on my computer

I'm running a wireless network at home and 2 or 3 computers can use it simulataneously

File sharing sharing and remote connections are disabled but I noticed that remote assistance was activated (now switched off) and McAfee anti virus and security running.

Is someone trying to hack my computer remotely or does SQL Config Mgr just decide to run on it's own sometimes ?

Jofm5
9th May 2009, 22:28
Interesting...

You may have recently installed an application that uses SQLServer Express as its database - this would then install the configuration manager to configure which instance/ip ports that the program listens on. You can check to see whether SQL Server Express edition is installed by looking in add/remove programs and also under the system services (the instance name here might reveal what installed it if they gave the instance a meaningful name).

Check you have a firewall running as it could be possible to use the extended stored procedure functionality from remotely to examine the contents of the local disks (providing someone can hack into the SQL server as an administrator).

If you are worried about this you can stop the SQL Server Express service whilst you are not using the application that requires it but this should not be necessary if you have a secure firewall.

aseanaero
10th May 2009, 05:38
I have a McAfee firewall.

What I don't have is any SQL server application that I know of !

In October 2008 my previous notebook was hacked I believe as there were some similar SQL activity then and the hard drive was destroyed a few weeks later.

I had to replace the hard drive in the old notebook and the shop was able to retrieve most of the files but didn't recommend continued use of the hard drive.

I used to run a php based industrial auction site and this was also hacked at the same time , I was able to us visual IP trace and trace these back to a single range of IP addresses in East Java which is where one of my then competitors was based. They had a small team of university IT students running their industrial auction site and I also found out they were developing a porno site.

I do direct sales now as php auction was to vulnerable to hacker attacks and the spanish developer wasn't effective in fixing the sites fast enough or bringing out patches to block these attacks.

You can see now why I'm a bit paranoid :)

aseanaero
10th May 2009, 05:45
I just checked program manager and it looks like Microsoft update was the last programs that were run on 2 May 2009 including Microsoft Office , Live add-in and Live sign in assistant

SQL error reporting to Microsoft ?

Jofm5
10th May 2009, 06:32
All just a bit odd, not sure why you would have the configuration manager without at least the express edition installed.

It could be that you just cant find the installation - there are a number of ways you can check.

SQL Server stores its data (including its configuration) within the database files - these have the extensions .mdf for data and .ldf for logging - there will at least be master.mdf and master.ldf on your system if any version of sql server is present (the master database is the sql server configuration database).

If you cant find either of those files on any of your harddisks then you dont have a SQL Server installed and therefore have nothing to worry about with regard to the configuration manager. It could be microsoft has included the configuration manager with Office as Excel, Access to name just two have options for importing data from an instance of SQL Server. I cant check on my machine(s) as they all have SQL Server installed as I do alot of database coding.

Cheers