RE: Did IDSes detect the SQL worm?

From: Gonzalez, Albert (albert.gonzalez@eds.com)
Date: 01/29/03

  • Next message: Thierry Evangelista: "RE: SQLSlammer Worm & IDSs"
    From: "Gonzalez, Albert" <albert.gonzalez@eds.com>
    To: focus-ids@securityfocus.com
    Date: Wed, 29 Jan 2003 14:15:14 -0500
    
    

    RealSecure did pick up the worms activity. Snort didn't
    because there was no signature at the time of the worm started
    spreading. Though they did respond very quickly. Our Dragon
    sensors aren't correctly running, so I can't verify them

    Cheers!

            Alberto Gonzalez

    -----Original Message-----
    From: Todd Heberlein [mailto:todd_heberlein@mac.com]
    Sent: Tuesday, January 28, 2003 6:42 PM
    To: focus-ids@securityfocus.com
    Subject: Did IDSes detect the SQL worm?

    Much has been made about the fact that the vulnerability exploited by
    the MS-SQL worm has been known about for six months. So not only
    should users have been aware of it, but IDS vendors should have been
    aware of it.

    Here is my question: Other than an IDS reporting an unusual amount of
    traffic to port 1434, did any report the specific nature of the attack?

    In other words, did any IDS report that the packet appears to attack a
    vulnerability identified by CAN-2002-0649?

    Thanks,

    Todd



    Relevant Pages

    • Massive Internet Worm Attack Timed to Match Terrorist Bombing One Week Ago
      ... Massive Internet Worm Attack Timed to Match Terrorist Bombing One Week Ago ... corroborated on CERT and other security sites. ...
      (Incidents)
    • Linux Users Running Apache - Slapper Worm Spreading Rapidly
      ... CERTŪ Advisory CA-2002-27 Apache/mod_ssl Worm ... OpenSSL 0.9.6d or earlier on Intel x86 ... During the infection process, ... information on other infected systems as well as attack instructions. ...
      (comp.security.firewalls)
    • RE: help - can someone explain this to me?
      ... > every network that has Wintendo boxes in it. ... This worm cannot do any harm to your Linux box. ... >> perhaps a machine that the ISP hosts is infected with something ... Can anyone identify what sort of attack it was? ...
      (Security-Basics)
    • Re: help - can someone explain this to me?
      ... > every network that has Wintendo boxes in it. ... This worm cannot do any harm to your Linux box. ... >> perhaps a machine that the ISP hosts is infected with something ... Can anyone identify what sort of attack it was? ...
      (Security-Basics)
    • Re: Whats up with Zone Alarm?
      ... I was told and have to agree that anti virus software would not have stopped ... the Red Worm attack and it did not stop it. ... necessary measures to protect the machines with the security patches with MS ...
      (comp.security.firewalls)

  • Quantcast