Solved

Malformed TDS response packet on SQL Server Packets

Posted on 2008-06-19
7
11,872 Views
Last Modified: 2011-10-19
Capturing network frames behind a SQL server 2005 NIC i get 70% of them being:

TDS      Response Packet[Malformed Packet]

It seems to affect Network requesting from that SQL server.

Anyone got a clue on what's going on ?

TCP is clear, only the TDS encapsuled in seems malformed.

Regards,

ws-capture.txt
0
Comment
Question by:elbosito
  • 4
  • 2
7 Comments
 
LVL 28

Assisted Solution

by:Bill Bach
Bill Bach earned 230 total points
ID: 21826555
Are you actually getting errors or having other issues?  It could be as simple that you are using a version of the TDS protocol that your network analyzer is unable to decode.  I assume that you used Wireshark?  Are you using the current version from www.wireshork.org?
0
 

Author Comment

by:elbosito
ID: 21829217
I used the latest version. is there a decode somewhere i can get?
ws-version.pdf
0
 
LVL 28

Accepted Solution

by:
Bill Bach earned 230 total points
ID: 21831594
For decode, start here:
    http://www.freetds.org/tds.html
Note that the Docs go only through SQLServer 2005, and may have been interpretted after the fact.  The only definitive answer is the Microsoft Source code that creates the packets.  Obviously, if the decoder in WireShark is wrong, you'll need to perform a manual decode of the packet and see if it really is mangled.

I also found this in my searches:
    http://www.microsoft.com/technet/security/bulletin/ms99-059.mspx
It's old, but might be applicable.
0
Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

 

Assisted Solution

by:PeterMiska
PeterMiska earned 20 total points
ID: 21854154
I've been tracking down SQL Server Crashes for the past week.  They occured every 12 hours.  MS suggested tracing traffic to and from the server.  Wireshark reported malformed RPC packets for the TDS protocol.  What a dead end that turned out to be.

After reading  BillBachs post I checked the Wirehark bugs list, and sure enough TDS isn't parsed correctly for SQL Server 2005.  The bug wasn't addressed in version 1.0.

When we turned off replication the problems, SQL Server crashes stopped.

Anyone have a clue whay?  Yes, I'm being lazy.
0
 
LVL 28

Assisted Solution

by:Bill Bach
Bill Bach earned 230 total points
ID: 21854952
Sounds like a problem with replication.  ;-)

As a question of SQLServer replication crashing will likely field an entirely different set of experts, you may wish to post this as a separate thread.
0
 

Author Comment

by:elbosito
ID: 21855619
does the problem PeterMiska has affect my Problems?
0
 
LVL 28

Assisted Solution

by:Bill Bach
Bill Bach earned 230 total points
ID: 21855659
Sorry -- didn't look at the poster name.  Are you running replication, too?  

If Wireshark doesn't decode TDS correctly, then perhaps one of the other analyzers will, such as Observer or Wildpackets EtherPeek.
0

Featured Post

Ransomware: The New Cyber Threat & How to Stop It

This infographic explains ransomware, type of malware that blocks access to your files or your systems and holds them hostage until a ransom is paid. It also examines the different types of ransomware and explains what you can do to thwart this sinister online threat.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
how to check mis-spellings in a select SQL 2 37
How to handle time out inside the stored procedure 10 24
SSIS GUID Variable 2 30
Many to one in one row 2 35
Why is this different from all of the other step by step guides?  Because I make a living as a DBA and not as a writer and I lived through this experience. Defining the name: When I talk to people they say different names on this subject stuff l…
Ever needed a SQL 2008 Database replicated/mirrored/log shipped on another server but you can't take the downtime inflicted by initial snapshot or disconnect while T-logs are restored or mirror applied? You can use SQL Server Initialize from Backup…
Viewers will learn how the fundamental information of how to create a table.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question