Re: Slammer Worm/SQL Server 7

From: Jasper Smith (jasper_smith9@hotmail.com)
Date: 02/20/03


From: "Jasper Smith" <jasper_smith9@hotmail.com>
Date: Thu, 20 Feb 2003 17:51:24 -0000


No risk from Slammer as SQL7 does not support named
instances and thus does not use the SQL Server Resolution
Service in which the buffer overflow exploited by Slammer
resided. However you should think about applying the latest
security hotfixes/service pack as SQL 7 SP3 has it's own
vulnerabilities :-)

-- 
HTH
Jasper Smith (SQL Server MVP)
I support PASS - the definitive, global
community for SQL Server professionals -
http://www.sqlpass.org
"Kevin Cullinan" <kevin.cullinan@fhr.com> wrote in message
news:062801c2d8ea$46cfde10$a401280a@phx.gbl...
> We are using SQL Server 7.0 , Service Pack 3.  Is there
> any risk from the Slammer Worm that we need to be worried
> about?  I saw a remark on the PASS website that SQL Server
> 7.0 was not at risk from the Slammer Worm but appears to
> be subject to the same vulnerability?
>
> Thanks.


Relevant Pages

  • Re: Win32/SQLSlammer.virus
    ... The best tools for determining if you are vulernable to the Slammer worm are ... That page also includes a link to the "SQL Server Critical Update Wizard", ... clicking on the "CPU" column twice to sort the display by the amount of CPU ...
    (microsoft.public.sqlserver.security)
  • Slammer Worm/SQL Server 7
    ... SQL Server 7 is not affected by the Slammer worm because ... it uses 1434 for some sort of named instance resolution. ... >7.0 was not at risk from the Slammer Worm but appears to ...
    (microsoft.public.sqlserver.security)
  • Slammer Worm/SQL Server 7
    ... SQL Server 7 is not affected by the Slammer worm because ... it uses 1434 for some sort of named instance resolution. ... >7.0 was not at risk from the Slammer Worm but appears to ...
    (microsoft.public.sqlserver.security)
  • Slammer Worm/SQL Server 7
    ... any risk from the Slammer Worm that we need to be worried ... I saw a remark on the PASS website that SQL Server ...
    (microsoft.public.sqlserver.security)
  • Re: MicroMonopoly aids Terrorism?
    ... >> Not if the patch makes it so you can't use SQL server. ... >> the multitudes of MS patches that get released. ... > No one is disputing that MS was hit by Slammer. ...
    (microsoft.public.security)