[[email protected]: [linux-elitists] Re: Robert Graham's SQL Slammer analysis (was Re: [linux-elitists] MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434!)]
Phil Hughes <[email protected]> Fri, 31 Jan 2003 09:33:44 -0600
| Newsgroups | gmane.linux.usage.government |
|---|---|
| Message-ID | <[email protected]> |
This was posted to the linux-elitists mailing list. Reading Graham's
advisory is well worth your time. It has graphs and a good explanation
of what happened.
Why do we (gov-list readers) care? Besides the obvious concerns of
preventing something like this from infecting existing systems, there is
a lot of FUD-busting information here. Two points are:
* While all the press talked about unpatched SQL Server 2000 systems,
it turns out that the real problem was Microsoft software that
was embedded in applications. How was this missed by the press?
Based on other political situations covered/not-covered by the
press, I would guess that the "news" was constructed by asking
Microsoft for the answer.
* It seems that having something listening on port 1433 open on
desktop systems is an example of a "back door". As far as I
know, there was nothing telling users of Visio or McAffee Virus
Manager that this was happening on their system. At the very
least this is a good argument for why Open Source software is
more secure--you can see that things like this exist.
This is also a good argument for making sure there is "something"
between an office full of computers and the Internet. At least some sort
of firewall where to block ports that make more sense.
----- Forwarded message from Aaron Sherman <[email protected]> -----
On Wed, 2003-01-29 at 21:36, Karsten M. Self wrote:
> *VERY* strongly recommended reading:
>
> Advisory: SQL slammer
> Robert Graham
> http://www.robertgraham.com/journal/030126-sqlslammer.html
>
As a friend of mine would say, oh my freakin' head! I did not realize
just how truly MS had porked the universe here! To quote from the
article:
If 100% of SQL Server 2000 systems had been patched by system
administrators, the situation would not have changed one bit. I
probed port 1433/tcp on attacking hosts and got a lot more RSTs
than SYNACKs. This means that most hosts were infected by MSDE,
not MSSQL. MSDE is "Microsoft Database Embedded", and is
embedded within desktop products like Visio, network
infrastructure systems from companies like Cisco, and in server
applications such as McAffee's virus manager. These aren't
unusual: MSDE is being included in thousands of desktop,
infrastructure, and server software packages.
...
McAffee's Virus manager, for Pete's sake! The virus manager was
listening on a random port for database queries from mind-control
lasers!
----- End forwarded message -----
--
Phil Hughes, [email protected] Phone/FAX: 506-483-1265
Aptdo. 89-4060, Alajuela, Costa Rica
This Linux in Government list is sponsored by Linux Journal.