[unisog] udp port 1434 worm?

Gene Rackow rackow at mcs.anl.gov
Sat Jan 25 14:55:50 GMT 2003


It appears to be a MS-SQL attack.  See

        http://www.kb.cert.org/vuls/id/370308
        http://www.kb.cert.org/vuls/id/399260
        http://www.kb.cert.org/vuls/id/484891

Or see the MS security announcement and fix at
http://www.microsoft.com/technet/security/bulletin/MS02-039.asp

This is an old problem that people should have fixed some time ago.
Numda, CodeRed, now MSSQL-Hell.
--Gene

Rich Graves made the following keystrokes:
 >anyone isolated it yet? we've yanked a half dozen machines in the last 2
 >hours. all seem to be windoze, possibly related to ms-sql server.
 >
 >given the unusual lag we're seeing on internet2 i'm assuming this is a
 >shared experience.
 >-- 
 >Rich Graves <rcgraves at brandeis.edu>
 >UNet Systems Administrator
 >



More information about the unisog mailing list