ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Help & HowTo: Slammer

Staff for CNET Asia CNet Asia

Published: 27 Jan 2003 11:18 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The havoc wreaked by the Sapphire worm, also known as Slammer and SQLExp, could have been avoided if a patch issued by Microsoft last July was administered.

As loopholes are found in products on a weekly basis, experts stressed that IT managers should keep abreast with the latest warnings and patches. One way is to subscribe to vulnerability mailing lists such as Microsoft's security bulletin.

"Companies need to take applying patches against new security threats seriously," said Graham Cluley, senior technology consultant at Sophos. "If you don't, then stopping new worms and viruses is as easy as catching smoke in a butterfly net."

"It takes companies anywhere from four to 12 months to apply patches -- the exposure window is far too big," said Viren Mantri, regional engineering manager, Network Associates.

Slammer causes increased traffic on UDP port 1434 and spreads via an exploit in Microsoft SQL 2000 Web servers, which in turn scans the Internet for other SQL servers to infect, according to Avert, the antivirus research division of security software maker Network Associates.

"The exploit uses a buffer overflow to gain control of a target server," Avert said.

To prevent external attacks from exploiting this vulnerability, administrators should block UDP port 1434 by downloading and applying Service Pack 3 from Microsoft.

After the server is restarted, the virus will be cleared from memory and reinfection can be deterred, said Network Associates' Mantri.

Cleaning up
Several antivirus firms have released advisories on next steps.

For Avert (Network Associates) users:

  • Stinger will be able to locate the worm (in memory) on infected SQL servers and shut down the SQL processes.

Stinger is a standalone utility used to detect and remove specific viruses. It is not a substitute for full antivirus protection, but a tool to assist administrators and users when dealing with an infected system. Stinger utilises next generation scan engine technology, including process scanning, digitally signed DAT files, and scan performance optimisations.

Stinger must be run with administrator privileges to shut down SQL Server. Existing Sniffer users can use Sniffer filter to detect W32/SQLSlammer.worm traffic.

  • A McAfee ThreatScan signature update is available to locate unpatched Microsoft SQL 2000 servers.

To effect the update, run the console auto update utility on the ePO server (not ePO console). Next, push out update tasks to all ThreatScan agents. After updating the ThreatScan installation, create a new ThreatScan task of type "Threat Scan".

Select the "Remote Vulnerability Detection" category and the "SQL Slammer Worm Vulnerability Check" on the scan options tab.

When this task is executed, all computers running Microsoft SQL Server 2000 that do not have service pack 3 will be reported.

  • For users who have McAfee Desktop Firewall running on their SQL servers, simply create a rule that blocks incoming UDP port 1434.

Meanwhile, Trend Micro users can download its System Cleaner patch from its Web site.

Securing SQL Server 2000 On Jan. 15, Microsoft released a checklist of ways to improve the security of SQL Server installation:


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
58 out of 121 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Senior SQL Server DBA Oxfordshire - 40-45k + Bens

A fantastic opportunity has come about for a Senior SQL Server Database Administrator to join a global provider of Supplier Management Software ...

Senior Support Analyst - Leeds - 30,000

Ideally you will have experience with Microsoft Exchange 2003 Installation, Configuration, and Administration, and some experience of Microsoft ...

Network Security Administrator Level 2 (CCNA, CCNP)

Job Title: Network Security Administrator Level 2 (CCNA, CCNP) Company Description: Rackspace Hosting is the worlds leading hosting company. To ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment