Help & HowTo: Slammer

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
The havoc wreaked by the Sapphire worm, also known as Slammer and SQLExp, could have been avoided if a patch issued by Microsoft last July was administered. As loopholes are found in products on a weekly basis, experts stressed that IT managers should keep abreast with the latest warnings and patches. One way is to subscribe to vulnerability mailing lists such as Microsoft's security bulletin. "Companies need to take applying patches against new security threats seriously," said Graham Cluley, senior technology consultant at Sophos. "If you don't, then stopping new worms and viruses is as easy as catching smoke in a butterfly net." "It takes companies anywhere from four to 12 months to apply patches -- the exposure window is far too big," said Viren Mantri, regional engineering manager, Network Associates. Slammer causes increased traffic on UDP port 1434 and spreads via an exploit in Microsoft SQL 2000 Web servers, which in turn scans the Internet for other SQL servers to infect, according to Avert, the antivirus research division of security software maker Network Associates. "The exploit uses a buffer overflow to gain control of a target server," Avert said. To prevent external attacks from exploiting this vulnerability, administrators should block UDP port 1434 by downloading and applying Service Pack 3 from Microsoft. After the server is restarted, the virus will be cleared from memory and reinfection can be deterred, said Network Associates' Mantri. Cleaning up
Several antivirus firms have released advisories on next steps. For Avert (Network Associates) users:
  • Stinger will be able to locate the worm (in memory) on infected SQL servers and shut down the SQL processes.
Stinger is a standalone utility used to detect and remove specific viruses. It is not a substitute for full antivirus protection, but a tool to assist administrators and users when dealing with an infected system. Stinger utilises next generation scan engine technology, including process scanning, digitally signed DAT files, and scan performance optimisations. Stinger must be run with administrator privileges to shut down SQL Server. Existing Sniffer users can use Sniffer filter to detect W32/SQLSlammer.worm traffic.
  • A McAfee ThreatScan signature update is available to locate unpatched Microsoft SQL 2000 servers.
To effect the update, run the console auto update utility on the ePO server (not ePO console). Next, push out update tasks to all ThreatScan agents. After updating the ThreatScan installation, create a new ThreatScan task of type "Threat Scan". Select the "Remote Vulnerability Detection" category and the "SQL Slammer Worm Vulnerability Check" on the scan options tab. When this task is executed, all computers running Microsoft SQL Server 2000 that do not have service pack 3 will be reported.
  • For users who have McAfee Desktop Firewall running on their SQL servers, simply create a rule that blocks incoming UDP port 1434.
Meanwhile, Trend Micro users can download its System Cleaner patch from its Web site. Securing SQL Server 2000 On Jan. 15, Microsoft released a checklist of ways to improve the security of SQL Server installation:
For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section. Let the editors know what you think in the Mailroom.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Lonnie

those conformation letters are hard to figure out what is which letters it is a pain in the back side. Please make it more Ledge-able being better...

3 hours ago by Lonnie on Screenshots: Photoshop CS6 Beta
BrownieBoy

"cites" even. Ouch!

10 hours ago by BrownieBoy on Using Windows XP is a waste of money, says IDC
Horace Ontalhold

...... and PDP11s too

10 hours ago by Horace Ontalhold on Fusion-io lays minefield with a billion IOPS
BrownieBoy

I had a quick skim through the PDF. It seems to be that many of these so-called cost savings would be down to a hardware refresh. Although...

11 hours ago by BrownieBoy on Using Windows XP is a waste of money, says IDC
bobandroid

496,999 BT Fon Hotspots lovingly situated in your next door neighbours garden, no matter how you dress that up its still a pup... Not where I need...

13 hours ago by bobandroid on London Olympics: BT needs 25,000 more Wi-Fi hotspots
apexwm

Jack : I was hoping you could provide us a summary since you are familiar with this report. I am not yet sure how much of my time I'd like to...

15 hours ago by apexwm on Using Windows XP is a waste of money, says IDC
Smilig Eddie

2 – 4 more weeks of waiting: how many buyers are going to decide instead to see what the iPhone 5 offers? Consumer trust in the brand has also...

15 hours ago by Smilig Eddie on Samsung Galaxy 'S3' delayed by special paint
SRist

So it looks like this was a complete red herring - Adobe are allowing upgrades from Photoshop CS3, CS4 and CS5 at the same price. When did this...

16 hours ago by SRist on Photoshop users attack Adobe upgrade policy change
Jack Schofield

@apexwm Have you considered either (a) reading the story above or (b) reading the PDF? There are answers in both.

18 hours ago by Jack Schofield on Using Windows XP is a waste of money, says IDC
apexwm

I would love to hear why Microsoft believes that "upgrading from Windows XP to Windows 7 pays for itself in a year, in increased productivity and...

18 hours ago by apexwm on Using Windows XP is a waste of money, says IDC
debsmk

I have just changed mine to white they said 3 to 5 days

19 hours ago by debsmk on Samsung Galaxy 'S3' delayed by special paint
Atangana

I would like a job for me and do good to their tackiness vellent my help I will do my best to help you mercie for all

20 hours ago by Atangana on UK's 15-year-old World Excel champion offered £100k job
BrownieBoy

Well done to IDC for producing a report that says using XP is a waste of money. Only 11 years too late with it is all....

21 hours ago by BrownieBoy on Using Windows XP is a waste of money, says IDC
Jack Schofield

@Burn-IT ...which doesn't mean it isn't true ;-) I'll be interested if you can find any properly-researched, independent data from any of the...

22 hours ago by Jack Schofield on Using Windows XP is a waste of money, says IDC
Burn-IT

As said, sponsored by Microsoft........

23 hours ago by Burn-IT on Using Windows XP is a waste of money, says IDC
mrbigdong

@620W, I mine 1 BTC/daily for cost of 1.7eur, they naysayers regurgitate the rubbish they read as usual

23 hours ago by mrbigdong on A minor Bitcoin miner injury?
Mike Denton

If the link to the next section existed that would be awesome.... Guess I have to ask uncle google where it is

1 day ago by Mike Denton via Facebook on Security on the farm: Accounts and permissions
minzhu

Don't blame CEO, they want RIM win. RIM has strange culture and self distruct political environment. In RIM if a new hired person figure out...

1 day ago by minzhu on RIM CEO: Time to squash BlackBerry myths
Thomas Gellhaus

I've been very pleased with Mageia 2. My review went up on Sunday. My only issue is that my particular wireless printer hasn't been detected on...

1 day ago by Thomas Gellhaus via Facebook on Scorecard - Linux Mint 13 and Mageia 2
knapper

That we have :-) Retailers don't buy stuff to lie around in warehouses, particularly with fast moving technology products. If they didn't think...

2 days ago by knapper on Windows Phone, Android take bite out of BlackBerry