mailing list archives
MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434!
From: Michael Bacarella <mbac () netgraft com>
Date: Sat, 25 Jan 2003 02:11:41 -0500
I'm getting massive packet loss to various points on the globe.
I am seeing a lot of these in my tcpdump output on each
02:06:31.017088 18.104.22.168.3047 > 22.214.171.124.ms-sql-m: udp 376
02:06:31.017244 126.96.36.199 > 188.8.131.52: icmp: 184.108.40.206 udp port ms-sql-m unreachable [tos 0xc0
It looks like there's a worm affecting MS SQL Server which is
pingflooding addresses at some random sequence.
All admins with access to routers should block port 1434 (ms-sql-m)!
Everyone running MS SQL Server shut it the hell down or make
sure it can't access the internet proper!
I make no guarantees that this information is correct, test it
out for yourself!
Michael Bacarella 24/7 phone: 646 641-8662
Netgraft Corporation http://netgraft.com/
"unique technologies to empower your business"
Finger email address for public key. Key fingerprint:
C40C CB1E D2F6 7628 6308 F554 7A68 A5CF 0BD8 C055
- MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434! Michael Bacarella (Jan 25)