[55896] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: The minutes seem like hours (was Re: Symantec detected Slammer

daemon@ATHENA.MIT.EDU (Mike Lewinski)
Sat Feb 15 11:05:38 2003

Date: Sat, 15 Feb 2003 09:02:02 -0700
From: Mike Lewinski <mike@rockynet.com>
To: nanog@merit.edu
In-Reply-To: <Pine.GSO.4.44.0302141703080.22169-100000@clifden.donelan.com>
Errors-To: owner-nanog-outgoing@merit.edu


Sean Donelan wrote:

 > According to Wired, Symantec is now saying they sent out an alert to
 > their paying customers about 30 minutes (9pm PST) before the SQL
 > slammer worm was detected by anyone else around 9:30pm PST.
 >
 > I have not seen a copy of the Symantec message.

OK, if there really was a private alert... one would expect that after 
news hit NANOG, BUGTRAQ et al, a public advisory would have been 
released by Symantec as well.

There was no information about Slammer available on Symantec's public 
web site for more than four hours after it reached criticality (3AM 
MST). I kept a close eye on Symantec, McAffee, dshield.org, 
incidents.org and other usual suspects, none of them had information 
available until the next morning.

Mike



home help back first fref pref prev next nref lref last post