Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

New SQL Worm Spreading Rapidly

Status
Not open for further replies.

browolf

Programmer
Dec 18, 2001
442
GB
Internet Security systems Security Alert
January 25, 2003

Microsoft SQL Slammer Worm Propagation

Synopsis:
ISS X-Force has learned of a worm that is spreading via Microsoft SQL
servers. The worm is responsible for large amounts of Internet traffic as
well as millions of UDP/IP probes at the time of this alert's publication.
This worm attempts to exploit MS/SQL servers vulnerable to the SQL Server
Resolution service buffer overflow (CVE CAN-2002-0649). Once a vulnerable
computer is compromised, the worm will infect that target, randomly select a
new target, and resend the exploit and propagation code to that host.


ISS X-Force recommends blocking UDP port 1433 and 1434 traffic to protect SQL Server databases with a firewall or packet filter.

more info:

===============
Security Forums
 
also

“It is so good at replicating that it generates massive amounts of traffic that will slow down networks,” Hypponen said. “The end user never sees it. They only experience the slowdown on the Net.”

Security experts blamed the worm for crashing almost all Internet services in South Korea.

from:
===============
Security Forums
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top