ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Slammer worm claims victim Down Under

Munir Kotadia ZDNet Australia

Published: 17 Jan 2005 09:50 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Macquarie Telecom has admitted that a variant of the Slammer worm was responsible for a serious disruption to its co-location customers last week.

Following an upgrade to its firewall and intrusion detection systems, many of Macquarie's Sydney-based co-location customers found their Web sites and intranet systems either completely inaccessible or painfully slow.

At the time, Macquarie admitted that the problem was caused by an avalanche of malicious traffic.

Subsequently Macquarie has admitted that it was forced to roll back to the old security system in order to find the problem. Engineers eventually discovered that the traffic was being generated by some of its customers that had been infected by a variant of the Slammer worm.

"The massive traffic loads were caused by virus-related broadcasts from Macquarie Telecom customers. As part of our troubleshooting process we rolled back to the old firewall to eliminate the new firewall architecture and policies as being a variable".

Slammer, which exploits a vulnerability in un-patched versions of Microsoft SQL Server 2000, was first detected almost two years ago. According to antivirus firm Symantec, Slammer has the "unintended payload of performing a denial of service attack due to the large number of packets it sends".

Neil Campbell, national security manager of IT services company Dimension Data, said that there is no excuse for a company to become infected with the Slammer worm – almost two years after it first appeared.

"If you are in any way vigilant with security there is no excuse and no reason to get infected by Slammer. It has been out for more than a year and there has been enough visibility and there are enough tools out there [to avoid infection]," said Campbell.

Although Campbell would not comment specifically on Macquarie, he explained that with co-location services, the provider is unlikely to be responsible for any virus outbreak.

"My understanding in a co-location scenario is that the provider does not have any control over the machines. There is nothing the hosting provider can do to ensure that the customers are managing their systems,"

However, Campbell did say that co-location providers should protect customers from each other.

"Co-location providers should protect each customer from the others so you can minimise the disruption to one customer caused by another customer not being up to date with patching," said Campbell.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
45 out of 113 people found this useful


Full Talkback thread

1 comment

  1. So, how much is the estimated COST of this problem... Scott Marlowe

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Network Security Lead

The successful candidate will be responsible for the Network and Firewall areas across all projects and the local environment within the site. Job ...

Firewalls Engineer Lead

Ensure all firewall related break/fix SLA timescales are met and all associated reporting is completed in a full and timely fashion. Activities and ...

NHS - Performance Analyst - Contract - Healthcare - Midlands - Apply!

Experience: Sourcing and managing health information Managing informatics and analytical services in health context Working with a variety of ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment

Trades Unions against ID Cards

The Trades Union Congress (TUC) has backed up airport workers protesting against ID cards, the Financial Times reports. In a letter to Home Secretary Jacqui Smith, the TUC said it... More

Post a comment