Re: [VulnDiscuss] Sapphire SQL Worm Analysis Complete
Ieong Sze Chung Ricci <[email protected]>
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general,gmane.comp.security.bugtraq |
|---|---|
| Message-ID | <[email protected]> |
Hello All, Do you know where can we find the network packet payload of the Sapphire SQL worm? I would like to analyze the payload information of the SQL worm. Can you point me to the link if you have that payload. Thanks. Ricci > I've completed an analysis of the 'Sapphire' SQL worm targeting MS-SQL > servers. Some have reported massive slowdowns. An interesting part of > this worm results from its use of UDP. Attacked hosts/networks may > generate ICMP Host/Port Unreachable messages in response to a Sapphire > attack, amplifying the attack's strength. One reason that this attack > is worse for users of home systems, etc. that don't run any servers, is > because Sapphire sends the entire 400 bytes or so in the initial packet, > where scans from Code Red and bretheren only prompted a 26 byte TCP SYN > packet. > > The full analysis is available at: > http://www.techie.hopto.org/sqlworm.html