Another Microsoft SQL Worm On the loose

Kr0m

OSNN Veteran Addict
Joined
4 Dec 2001
Messages
1,392
I found out about this when I noticed a LARGE number of probes to port 1434/33 to my PC lastnight. Why users or admins don't keep their Servers patched(especially these days) is mind boggling. They need to be slapped!

Internet Security Systems

Quoting their site:

"Synopsis:

ISS X-Force has learned of a worm that is spreading via Microsoft SQL servers. The worm is responsible for
large amounts of Internet traffic as well as millions of UDP/IP probes at the time of this alert's publication.
This worm attempts to exploit MS/SQL servers vulnerable to the SQL Server Resolution service buffer overflow
(CVE CAN-2002-0649). Once a vulnerable computer is compromised, the worm will infect that target, randomly
select a new target, and resend the exploit and propagation code to that host.

Impact:

Although the Slammer worm is not destructive to the infected host, it does generate a damaging level of
network traffic when it scans for additional targets. A large amount of network traffic is created by the
worm, which scans random IP addresses for vulnerable servers."
 
Thanks to Pseudokiller to bringing this to my attention that this worm is causing havoc on the internet right now as stated from CNN...

"Traffic on the many parts of the Internet slowed dramatically early Saturday, the apparent effects of a fast-spreading, virus-like infection overwhelming the world's digital pipelines and interfering with Web browsing and delivery of e-mail."


CNN
 
Seems an old exploit is being targeted. SQL server are the current target but the worm is probing everything on the net. As it stands all major and even minor isp's are being affected. UUnet is especially being hit. Their pipe is full and no one knows when it will stop.
Its not going to be a good day on the net ...
 
not good at all, I cannot even sign into windows messenger because of this..
 
Only a few sites I can't get to. Lost my cable connection for about 3 - 5 mins. Other then that nothing is different for me. All chat programs are working fine on this end.
 

Members online

No members online now.

Latest profile posts

Also Hi EP and people. I found this place again while looking through a oooollllllldddd backup. I have filled over 10TB and was looking at my collection of antiques. Any bids on the 500Mhz Win 95 fix?
Any of the SP crew still out there?
Xie wrote on Electronic Punk's profile.
Impressed you have kept this alive this long EP! So many sites have come and gone. :(

Just did some crude math and I apparently joined almost 18yrs ago, how is that possible???
hello peeps... is been some time since i last came here.
Electronic Punk wrote on Sazar's profile.
Rest in peace my friend, been trying to find you and finally did in the worst way imaginable.

Forum statistics

Threads
62,015
Messages
673,495
Members
5,625
Latest member
vinit
Back