BugTraq
MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434! Jan 25 2003 07:11AM
Michael Bacarella (mbac netgraft com) (4 replies)
Re: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434! Jan 25 2003 12:07PM
cstone (cstone pobox com)
On Sat, Jan 25, 2003 at 02:11:41AM -0500, Michael Bacarella wrote:
> I'm getting massive packet loss to various points on the globe.
> I am seeing a lot of these in my tcpdump output on each
> host.
>
> It looks like there's a worm affecting MS SQL Server which is
> pingflooding addresses at some random sequence.

yeah. i guess it's an old vulnerability, but i don't keep up on
this stuff.

however, i have disassembled the code inside; all it does is send
itself to pseudorandomly generated hosts.

there is an annotated disassembly at
http://www.boredom.org/~cstone/worm-annotated.txt

--cstone (at) pobox (dot) com [email concealed]

[ reply ]
Re: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434! Jan 25 2003 10:04AM
Tom Kyle (tom eos umsl edu)
Re: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434! Jan 25 2003 10:01AM
Ed Blanchfield (Ed E-Things Org)
Re: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434! Jan 25 2003 09:17AM
Geoff Shively (gshively pivx com)


 

Privacy Statement
Copyright 2010, SecurityFocus