Re: [VulnDiscuss] Sapphire SQL Worm Analysis Complete

Ieong Sze Chung Ricci <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.general,gmane.comp.security.bugtraq
Message-ID <[email protected]>
Hello All,

Do you know where can we find the network packet payload of the Sapphire
SQL worm? I would like to analyze the payload information of the SQL worm.

Can you point me to the link if you have that payload.

Thanks.

Ricci


> I've completed an analysis of the 'Sapphire' SQL worm targeting MS-SQL
> servers.  Some have reported massive slowdowns.  An interesting part of
> this worm results from its use of UDP.  Attacked hosts/networks may
> generate ICMP Host/Port Unreachable messages in response to a Sapphire
> attack, amplifying the attack's strength.  One reason that this attack
> is worse for users of home systems, etc. that don't run any servers, is
> because Sapphire sends the entire 400 bytes or so in the initial packet,
> where scans from Code Red and bretheren only prompted a 26 byte TCP SYN
> packet.
>
> The full analysis is available at:
> http://www.techie.hopto.org/sqlworm.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.