New MS SQL Server Worm

From: H D Moore (sflist@digitaloffense.net)
Date: 01/25/03

  • Next message: Christian Vogel: "Re: SNMP Weirdness"
    From: H D Moore <sflist@digitaloffense.net>
    To: incidents@securityfocus.com
    Date: Sat, 25 Jan 2003 03:15:40 -0600
    
    

    A worm which exploits a (new?) vulnerability in SQL Server is bringing the
    core routers to a grinding halt. The speed of the propagation can be
    attributed to the attack method and simplicity of the code. The worm
    sends a 376-byte UDP packet to port 1434 of each random target, each
    vulnerable system will immediately start propagating itself. Since UDP is
    connection-less, the worm is able to spread much more quickly than those
    using your standard TCP-based attack vectors (no connect timeouts).

    Some random screen shots, a copy of the worm as a perl script, and a
    disassembly (sorry, no comments) can be found online at:

    http://www.digitaloffense.net/worms/mssql_udp_worm/

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management
    and tracking system please see: http://aris.securityfocus.com



    Relevant Pages

    • Re: CodeGreen beta release (idq-patcher/antiCodeRed/etc.) (fwd)
      ... It attacks vulnerable machines and uses them as a platform to scan ... >> so does this worm. ... starts 50 propagation threads ...
      (Vuln-Dev)
    • Re: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434!
      ... A worm which exploits a vulnerability in SQL Server is bringing ... the core routers to a grinding halt. ... The speed of the propagation can be ...
      (Bugtraq)
    • Nimda Worm Alert
      ... A new worm named W32/Nimda-A (known aliases are Nimda, Minda, Concept ... It utilizes multiple IIS ... Microsoft IIS 4.0/5.0 File Permission Canonicalization Vulnerability ...
      (Incidents)
    • Nimda Worm Alert
      ... A new worm named W32/Nimda-A (known aliases are Nimda, Minda, Concept ... It utilizes multiple IIS ... Microsoft IIS 4.0/5.0 File Permission Canonicalization Vulnerability ...
      (Focus-IDS)
    • CERT Advisory CA-2001-23
      ... We believe the worm will begin propagating again on ... susceptible to the vulnerability described in CA-2001-13 Buffer ... time required to infect all vulnerable IIS servers with this worm ... and egress filtering should be implemented at the network edge. ...
      (Cert)