| Index: > A B C D E F G H I J K L M N O P Q R S T U V W X Y Z |
|
|||||
| First Prev [ 1 2 ] Next Last |
Sites monitoring the traffic of the Internet such as Internet Storm Center reported significant slowdowns globally, resembling the impact of the Code Red worm in the summer of 2001.
Yonhap news agency in South Korea reported on the Internet services had been shut down for hours on Saturday, January 25, 2003 nationwide. The impact was mitigated by the fact that it occurred over the weekend.The same attack was reported throughout most of Asia, Europe, and North America. Anti-virus software maker SymantecSymantec Corporation , founded in 1982, is an information security company headquartered in Cupertino, California that specializes in computer security and antivirus software. Symantec has been primarily known for its Norton brand of antivirus and utility estimated that at least 22,000 systems were affected worldwide. Though some reports indicated that the root nameserverA root nameserver is a DNS server that answers requests for the root namespace domain, and redirects requests for a particular top-level domain to that TLD's nameservers. All domain names on the Internet actually end in a . period) character that is, techs had been brought down, this was not true.
The worm continuously sends traffic to randomly generated IP addresses, attempting to send itself to hosts that are running the Microsoft SQL Server Resolution Service, causing them to spray the Internet with more copies of the worm program.
Home PCs are generally not vulnerable to this worm, as they are usually not running SQL Server. The worm stays only in memory and not in disk space, so it is easy to remove. For example, Symantec provides a free removal utility (see external link below).
The worm was made possible by a software security vulnerabilityIn computer software a security vulnerability is a software bug that can be used deliberately to violate security. Well known vulnerabilities include (but are not limited to) stack smashing and other buffer overflows format string bugs SQL Injection Cross in SQL Server first reported by Microsoft on July 24July 24 is the 205th day (206th in leap years) of the year in the Gregorian Calendar, with 160 days remaining. Events 1567 Mary Queen of Scots is deposed. 1701 Detroit, Michigan founded. 1814 War of 1812: General Phineas Riall advances toward Niagara to h, 20022002 is a common year starting on Tuesday (see link for calendar). 2002 was the first palindromic year since 1991 and the last until 2112. 2002 was also designated: International Year of Ecotourism and Mountains National Science Year in the United Kingdom. A patch has been available from Microsoft for the past six months, but many installations had not been patched -- including some at Microsoft.
The slowdown was caused by the fact that several routerThis article describes the computer networking device. A wood router is also a kind of rotating cutting tool. NAT Router, popular for home and small office networks A router is a computer networking device that forwards data packets toward their destinatis collapsed under the burden of extremely high bombardment traffic from infected servers. Normally, when this happens, the routers are supposed to slow down traffic. Instead, some routers crashed, and as the routers used some variant of the link-state routing protocolA Link-state routing protocol is a protocol concept used in routing of packet-switched networks in computer communications, as in for example the OSPF for Internet traffic. The ARPANET was the first network to use a link-state routing protocol, after the, the notice that these routers had stopped and should be removed from the routing tables of all other routers started to propagate througout the Internet (flooding). When the routers eventually came back to the network after being restarted the routing tables had to be updated again in the same fashion. Soon a significant portion of Internet bandwidth was consumed by routers communicating with each other to update their routing tables, and ordinary data traffic slowed down or in some cases stopped altogether.
SQL Slammer was the first observed example of a " Warhol worm" -- a fast-propagating Internet infection of the sort first hypothesized in 2002 in a paper by Nicholas Weaver.