Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


February 25, 2003

Behind the Scenes of the SQL Slammer Worm Virus

RSS
Subscribe to Windows IT Pro | See More SQL Server and Database Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

On Friday, January 24, at 9:30 P.M. Pacific time, an Internet attack began causing a dramatic increase in network traffic worldwide. Microsoft identified a worm virus called Sapphire or Slammer, which targets systems running either Microsoft SQL Server 2000 or Microsoft SQL Server Desktop Engine (MSDE). The Slammer virus is similar to a Denial of Service (DoS) attack in that it generates enough network traffic to bring the Internet to a standstill. Slammer doesn't attack SQL Server systems' data. Home users' machines typically aren't affected because their MSDEs aren't exposed to the Internet, but more than a million MSDEs are in production systems that are exposed to the Internet.

The irony of the Slammer crisis is that the vulnerability that the Slammer exploited was first corrected almost 7 months earlier by Microsoft Security Bulletin MS02-039 (Buffer Overruns in SQL Server 2000 Resolution Service Could Enable Code Execution) and in the subsequent cumulative Microsoft Security Bulletin MS02-061 (Elevation of Privilege in SQL Server Web Tasks). In addition, these fixes were also included in SQL Server 2000 Service Pack 3 (SP3) and MSDE 2000 SP3. What does this tell us? Systems and Web administrators don't apply available security patches. Microsoft Internet Information Services (IIS) 6.0 in Windows Server 2003 will ship completely locked down with automatic patching enabled because administrators don't patch systems for reasons that include ignorance and being "too busy." The heavy traffic on the TechNet SQL Server security sites demonstrates the value of online communities in helping systems administrators respond quickly and effectively to threats.

Slammer was another black eye to the already battered Microsoft security effort. Most industry experts agree that security vulnerabilities on other platforms are high, but Microsoft still receives the brunt of attacks. Microsoft is an irresistible target for the type of person who spends his or her time trying to maliciously exploit security weaknesses and who wants bring the world's productivity to a screeching halt.

Behind the scenes at Microsoft on January 24, a response team worked to make sure its customers had the information and resources to get secure. When SQL Server and MSDE customers returned to work on Monday, January 27, they were able to receive customer support from Microsoft Product Support Services (PSS) in a short amount of time. Microsoft also swiftly assembled a development team to issue a rerelease of MS02-061 for SQL Server with automatic installation functionality. As of noon on Monday, Microsoft received about 21,000 download requests per hour for SQL Server-related patches, which included 14,000 requests per hour for SQL Server SP3 and 6800 requests per hour for the rerelease of MS02-061. Microsoft provides access to IT professional-focused public newsgroups through the TechNet site ( http://www.microsoft.com/technet ). The public newsgroups on the TechNet site immediately had helpful information about what was happening with Slammer and how to fix the problem.

I depend on Windows Update to keep my client systems secure. You can get the Windows Update software by selecting Windows Update on the Tools menu in Microsoft Internet Explorer (IE), or you can go directly to the Windows Update site at http://windowsupdate.microsoft.com . Andrew Brust, security expert and founder of Progressive Systems Consulting, said, "Patching is clearly a suboptimal solution for addressing security vulnerabilities, but it's the best way we have of protecting the current installed base of products." So why isn't SQL Server part of Windows Update? And, why isn't every Microsoft product part of Windows Update? Here's my bold prediction: The result of Slammer will be that every Microsoft product will become a part of Windows Update within the next 6 months. What are your thoughts about my prediction and the mechanics of how we might help to reduce the security vulnerabilities that continue to bite us? Email me and tell me your thoughts.

End of Article



Reader Comments
A million MSDE's exposed to the Internet? I wonder how many were "stealth" installs from the thirty or so Microsoft products that install this as part of their setup. Not to mention the hundreds of third-party programs that use MSDE. We use one called POS (seriously!) for authorizing credit card transactions. It installed and enabled MSDE for use as its data store. We have technical people on staff who noticed and remembered that it was there and required patching but I bet the vast majority of apps deployed this way are juicy targets.

Yes, all apps need to at least be analyzed by Windows Update. Even if automatic patching from Update is impractical in the short term, users should at least be warned that there is a problem and referred to the correct site for information.

David Arndt February 26, 2003


I believe if you use HFNETCHK or the MSBA - it will tell you of SQL patches that need applied.

Chad Buser February 26, 2003


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Battery Life Issues Almost Certainly Not Windows 7's Fault

While Microsoft is still investigating a notebook battery life issue that was supposedly caused by Windows 7, some interesting trends have emerged. ...

Confirmed: Battery Life Issues Not Windows 7's Fault

Microsoft on Monday issued a lengthy statement about the recent Windows 7 battery controversy, echoing my assessment from earlier in the day, but backing it up with hard, cold evidence. ...

Getting your iPhone to Sync with Exchange 2003

Follow these steps to use an iPhone with Exchange. ...


Related Events Improving Your Data Integration Performance

SQL Server Consolidation, eLearning Series

Protecting SQL Server Data

Check out our list of Free Email Newsletters!

SQL Server and Database eBooks Safeguarding Your Windows Servers

SQL Server Administration for Oracle DBAs

Taking Control: Monitoring the Windows Platform Proactively

Related SQL Server and Database Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2010 Penton Media, Inc. Terms of Use | Privacy Statement