Re: New SQL Server worm - UDP Port 1434

From: \ (dvader@deathstar.mil)
Date: 01/25/03


From: "\"Crash\" Dummy" <dvader@deathstar.mil>
Date: Sat, 25 Jan 2003 16:58:32 -0500


>Looking at the disassembled code there briefly, it doesn't look like it is
>just using an ordinary socket, and so would indeed not be able to fake the
>source IP address.

Okay, I'll take your word for it. If that's true, then it simultaneously
infected thousands of people and began immediately propagating. I've never seen
a worm spread that fast.

--
Dave "Crash" Dummy
Certified Dilettante
crash@gpick.com
http://lists.gpick.com

Quantcast