[[email protected]: [linux-elitists] Re: Robert Graham's SQL Slammer analysis (was Re: [linux-elitists] MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434!)]

Phil Hughes <[email protected]> Fri, 31 Jan 2003 09:33:44 -0600
Newsgroups gmane.linux.usage.government
Message-ID <[email protected]>
This was posted to the linux-elitists mailing list. Reading Graham's
advisory is well worth your time. It has graphs and a good explanation
of what happened.

Why do we (gov-list readers) care? Besides the obvious concerns of
preventing something like this from infecting existing systems, there is
a lot of FUD-busting information here. Two points are:
  * While all the press talked about unpatched SQL Server 2000 systems,
    it turns out that the real problem was Microsoft software that
    was embedded in applications. How was this missed by the press?
    Based on other political situations covered/not-covered by the
    press, I would guess that the "news" was constructed by asking
    Microsoft for the answer.
  * It seems that having something listening on port 1433 open on
    desktop systems is an example of a "back door". As far as I
    know, there was nothing telling users of Visio or McAffee Virus
    Manager that this was happening on their system. At the very
    least this is a good argument for why Open Source software is
    more secure--you can see that things like this exist.

This is also a good argument for making sure there is "something"
between an office full of computers and the Internet. At least some sort
of firewall where to block ports that make more sense.

----- Forwarded message from Aaron Sherman <[email protected]> -----

On Wed, 2003-01-29 at 21:36, Karsten M. Self wrote:

> *VERY* strongly recommended reading:
> 
>     Advisory:  SQL slammer
>     Robert Graham
>     http://www.robertgraham.com/journal/030126-sqlslammer.html
> 

As a friend of mine would say, oh my freakin' head! I did not realize
just how truly MS had porked the universe here! To quote from the
article:

        If 100% of SQL Server 2000 systems had been patched by system
        administrators, the situation would not have changed one bit. I
        probed port 1433/tcp on attacking hosts and got a lot more RSTs
        than SYNACKs. This means that most hosts were infected by MSDE,
        not MSSQL. MSDE is "Microsoft Database Embedded", and is
        embedded within desktop products like Visio, network
        infrastructure systems from companies like Cisco, and in server
        applications such as McAffee's virus manager. These aren't
        unusual: MSDE is being included in thousands of desktop,
        infrastructure, and server software packages.

...

McAffee's Virus manager, for Pete's sake! The virus manager was
listening on a random port for database queries from mind-control
lasers!

----- End forwarded message -----

-- 
Phil Hughes, [email protected]  Phone/FAX: 506-483-1265 
Aptdo. 89-4060, Alajuela, Costa Rica

This Linux in Government list is sponsored by Linux Journal.