Re: [Full-Disclosure] SQL Slammer - lessons learned

From: David Howe (DaveHowe@cmn.sharp-uk.co.uk)
Date: 02/03/03

  • Next message: rm-rf@hushmail.com: "Re: [Full-Disclosure] Lance Spitzner bustin some rhymes and popping some caps."
    From: "David Howe" <DaveHowe@cmn.sharp-uk.co.uk>
    To: "Email List: Full Disclosure" <full-disclosure@lists.netsys.com>
    Date: Mon, 3 Feb 2003 12:40:12 -0000
    

    All good points - but missing the essential point that, even if the
    internet ports were redivided into "server" at (say) 1-10240 and "user"
    at 10241+ (like the current division at 1024) this worm would *still*
    have spread like wildfire. the service exploited is a legitimate
    service, so would be expected to run on a server port. Filtering would
    allow you to block certain services at the expense of blocking anyone
    being able to run those servers legitimately ( which may be borderline
    acceptable to filter dialup/home users and protect all those insecure
    MSDE owners out there) but would still not have slowed the infection of
    legitimate servers; The only place to close ports to inbound traffic is
    at the server running that service in the first place.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



    Relevant Pages

    • Re: A interesting way to detect spam based on the proximity of the sender with the receiver
      ... spam, the trick is to do this ... machine is clearly flawed (any legitimate, ... have the SMTP port open to the world). ... server to check for any other thing like white list, ...
      (Security-Basics)
    • Re: Access Workgroup File
      ... >> There is no legitimate use for such a ... for setting up Access security. ... secured Access database being cracked, Rebecca R was the only one who ... > using a good server database, and using the server OS and server DB ...
      (microsoft.public.access.modulesdaovba)
    • Already Activated
      ... I have a new client who had a server installed for them. ... the .bak file did not exist. ... The client has a legitimate License and CD key. ...
      (microsoft.public.win2000.setup)
    • Already Activated
      ... I have a new client who had a server installed for them. ... the .bak file did not exist. ... The client has a legitimate License and CD key. ...
      (microsoft.public.windows.server.general)