Re: [Full-Disclosure] SQL Slammer - lessons learned

From: David Howe (DaveHowe@cmn.sharp-uk.co.uk)
Date: 02/03/03

  • Next message: rm-rf@hushmail.com: "Re: [Full-Disclosure] Lance Spitzner bustin some rhymes and popping some caps."
    From: "David Howe" <DaveHowe@cmn.sharp-uk.co.uk>
    To: "Email List: Full Disclosure" <full-disclosure@lists.netsys.com>
    Date: Mon, 3 Feb 2003 12:40:12 -0000
    

    All good points - but missing the essential point that, even if the
    internet ports were redivided into "server" at (say) 1-10240 and "user"
    at 10241+ (like the current division at 1024) this worm would *still*
    have spread like wildfire. the service exploited is a legitimate
    service, so would be expected to run on a server port. Filtering would
    allow you to block certain services at the expense of blocking anyone
    being able to run those servers legitimately ( which may be borderline
    acceptable to filter dialup/home users and protect all those insecure
    MSDE owners out there) but would still not have slowed the infection of
    legitimate servers; The only place to close ports to inbound traffic is
    at the server running that service in the first place.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



    Relevant Pages

    • Re: Access Workgroup File
      ... >> There is no legitimate use for such a ... for setting up Access security. ... secured Access database being cracked, Rebecca R was the only one who ... > using a good server database, and using the server OS and server DB ...
      (microsoft.public.access.modulesdaovba)
    • Already Activated
      ... I have a new client who had a server installed for them. ... the .bak file did not exist. ... The client has a legitimate License and CD key. ...
      (microsoft.public.windows.server.general)
    • Already Activated
      ... I have a new client who had a server installed for them. ... the .bak file did not exist. ... The client has a legitimate License and CD key. ...
      (microsoft.public.win2000.setup)
    • Windows 2003 Enterprise Server - Online update Validation error
      ... I have purchased a Server with Windows 2003 Enterprise Server already ... The Validation report states that the ActiveX control encountered an error. ... legitimate version of the OS already installed. ...
      (microsoft.public.windowsupdate)
    • Explorer question
      ... Every time I turn on my computer, ZA Pro asks if I want Windows Explorer to ... act as a server. ... I checked and it is the legitimate explorer.exe ...
      (alt.computer.security)