On mySimon: Bacon Soap
BNET Business Network:
BNET
TechRepublic
ZDNet

February 21st, 2007

As the worm squirms: Slammer still runs amok

Posted by Ryan Naraine @ 11:00 am

Categories: Botnets, Exploit code, Hackers, Microsoft, Patch Watch, Viruses and Worms, Vulnerability research

Tags: Blaster Worm, Worm, SQL Slammer, Ryan Naraine

More than four years after Slammer started exploiting holes in Microsoft’s SQL Server and Desktop Engine database products, the worm continues to squirm in machines that some believe will never be disinfected.

Over the past two days, SQL Slammer was listed as the number one threat on Arbor Network’s new ATLAS (Active Threat Level Analysis System), accounting for a whopping 25 percent of all malicious Internet activity detected by Arbor’s censors. The bulk of the Slammer attacks are coming from infected hosts in China.

Although the worm isn’t dramatically impacting network availability like that January morning in 2003 when it spread like wildfire around the world, the fact that Slammer is still slithering confirms that there some boxes that will never be dewormed.

Microsoft released a patch for the flaw in July 2002 and provided disinfection tools immediately after the attack but, for a myriad of reasons, there are infected boxes out there scanning violently for vulnerable hosts.

In fact, according to sources in the anti-malware community, a high-profile Web company brought up a SQL Slammer host by accident a few weeks ago, setting off all kinds of alarm bells. “They took it down pretty quickly, but you get the idea: everyone is vulnerable,” said a source.

According to statistics from Arbor Networks, there are more than 1300 unique SQL Slammer hosts contacting its sensors. This is just a small fraction of infected hosts and signals just how impossible it is to completely kill a virulent network worm.

It’s much of the same with the Blaster worm of the summer of 2003. According to statistics culled from Microsoft’s monthly updated MSRT (malicious software removal tool), between 500 and 800 copies of Blaster are removed from Windows machines every day. (Most of the Blaster removals came from pre-SP2 Windows machines).

Arbor’s ATLAS also shows a high rate of attacks against the ASN.1 vulnerability fixed by Microsoft since February 2004.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 14 Talkback(s)
Didn't try hard, but managing a box with an LUA is a challenge...
I used my limited user account for day-to-day purposes. I did everything with the machine while logged on interactively with this account and there was no central management. I also elevated manuall... (Read the rest)
Posted by: SecurityGeek_z Posted on: 02/28/07 You are currently: a Guest | | Terms of Use
This is good news  NonZealot | 02/21/07
Actually...  jasonp@... | 02/21/07
MS itself not immune.  UserLand | 02/21/07
Not Quite...  SecurityGeek_z | 02/22/07
Limited user browsing  toadlife | 02/22/07
Didn't try hard, but managing a box with an LUA is a challenge...  SecurityGeek_z | 02/28/07
HELLO MICRO$OFT ZEALOT  nix_hed | 02/22/07
Ditto!  ladyirol | 02/22/07
This line says it all:  slow_descent | 02/21/07
Ahhh! the classics!  Reverend MacFellow | 02/21/07
"Zero Day"?  bpolhemus@... | 02/21/07
Slammer war story  toadlife | 02/21/07
A COMPUTER VIRUS IS A BUNCH OF ZEROS AND ONES  BALTHOR | 02/22/07
Slammer W.  AB8RU | 02/26/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More