[28650] in bugtraq

home help back first fref pref prev next nref lref last post

Sapphire SQL Worm Analysis Complete

daemon@ATHENA.MIT.EDU (Matthew Murphy)
Sat Jan 25 20:17:36 2003

Message-ID: <004601c2c4cc$c2b799a0$e62d1c41@basement>
From: "Matthew Murphy" <mattmurphy@kc.rr.com>
To: <vulnwatch@vulnwatch.org>, <vulndiscuss@vulnwatch.org>,
        "SecurITeam News" <news@securiteam.com>, <bugtraq@securityfocus.com>,
        <ms-focus@securityfocus.com>
Date: Sat, 25 Jan 2003 17:52:03 -0600
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit

I've completed an analysis of the 'Sapphire' SQL worm targeting MS-SQL
servers.  Some have reported massive slowdowns.  An interesting part of this
worm results from its use of UDP.  Attacked hosts/networks may generate ICMP
Host/Port Unreachable messages in response to a Sapphire attack, amplifying
the attack's strength.  One reason that this attack is worse for users of
home systems, etc. that don't run any servers, is because Sapphire sends the
entire 400 bytes or so in the initial packet, where scans from Code Red and
bretheren only prompted a 26 byte TCP SYN packet.

The full analysis is available at:
http://www.techie.hopto.org/sqlworm.html


home help back first fref pref prev next nref lref last post