Advertisement
Promo

Security threats Toolkit

Slammer 'could have originated from Asia'

Winston Chai CNet Asia

Published: 27 Jan 2003 14:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Some security experts are pointing to the Far East as the birthplace of the worm that wreaked havoc over the weekend on Internet servers worldwide.

The Slammer worm -- also known as Sapphire and SQLExp -- exploits vulnerabilities in Microsoft SQL 2000 Web servers and causes increased traffic between servers. The worm started spreading at about 9:30 p.m. PST on Friday.

"The worm could have originated from Asia," Roy Ko, centre manager for the Hong Kong Computer Emergency Response Team, said in a email interview.

Slammer's spread over the weekend was the largest such incident since the Code Red and Nimda worms swamped servers in 2001. The attack served as a wake-up call for anyone who thought the Internet had become a safer place following increased attention by corporate and government leaders.

"We started to notice heavy Internet traffic in Asia on Saturday afternoon before other parts of the world reported it," said Ko.

A company is claiming that the worm first appeared in Hong Kong, Ko said, but that's still under investigation.

Security software makers such as Trend Micro and Network Associates have not ascertained Slammer's origins but media reports do lend some weight to Ko's deduction.

According to The Washington Post, security experts who studied the worm have found references in its code to the Chinese hacking group, the Honkers Union of China.

In April 2001, the faction defaced more than 80 US Web sites including those belonging to the Navy, Labor Department and the California Department of Energy.

While the culprits behind this online assault remain unclear, the damage in Asia is far more concrete.

South Korea appears to have taken the brunt of the damage as the region's most wired nation. Almost all of Korea Telecom's--the nation's largest Internet service provider (ISP) -- customerslost their connections during the attack.

In China, the Web sites of China Telecom, the China Science and Technology Network and the Education and Research Network came to a halt, and Japanese Internet firms reported a network slowdown, said Viren Mantri, regional engineering manager of Network Associates.

Chunghwa Telecom, Taiwan's largest ISP, said millions of Net users were unable to access its portal during the virus onslaught.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
49 out of 96 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters