Slammer damage could spread

Commercial software built around Microsoft's SQL Server could be as vulnerable to the Slammer worm as the database itself

Written by Madeline Bennett, IT Week

The recent Slammer worm could infect non-Microsoft products, including security tools, according to a security advisory site. This may put businesses at risk from further infections if they fail to patch all vulnerable software.

According to SQLSecurity.com, products from companies such as security tools provider Internet Security Systems (ISS) and storage firm Veritas use the vulnerable SQL Server database software. Veritas told its customers last week that its Backup Exec 9.0 for Windows and ExecView 3.1 servers could be open to infection by Slammer. ISS said its products were configured to minimise the risk.

IT managers need to assess their software products and ensure they apply any necessary patches. This may be especially important in light of a poll that shows the majority of computer users blame administrators for recent Slammer infections.

In a poll of more than 200 business PC users carried out by antivirus firm Sophos, almost two-thirds said that systems administrators should be blamed because they had failed to keep systems updated with the most recent patches. Twenty-four percent indicated that Microsoft was at fault because it had released flawed software.

Ben Claridge, technical manager at antivirus firm Panda Software, agreed that failure to apply patches contributed to the spread of the worm, which exploits a buffer overflow found in Microsoft SQL Server databases. "The main reason why SQL Slammer has infected so many servers with ease is due to the fact that network administrators typically do not upgrade their systems with enough frequency," he said.

Companies had plenty of warning about the availability of the fix, according to Adam Newby, IT manager at an online publisher. "The patch to SQL Server that prevents this from spreading has been available since last July," he said. "Even if network managers were worried about potential instability to their systems caused by installing the patch, they've had six months to test it."

Newby pointed out that in addition to applying fixes more quickly to protect systems, firms could also divide up their networks into segments and place firewalls between them. This would contain worms within one segment of a network if an infection occurs.

The Slammer worm has already caused more than $1bn of damage around the world, according to the Intelligence Unit at security solutions firm Mi2g. This is more than the damage caused by previous viruses such as Goner and Love Letter.

Have your say: reply to IT Week

Tags:

reader comments

related articles

Panda completes indirect move

Completes year-long transition to channel-only sales 14 Sep 2003

 

IT giants improve patching

Microsoft and Oracle are changing the way they issue patches, following criticism of their practices 24 Feb 2003

Comment: Buffers cause heaps of problems

Hackers have exploited buffer overflow weaknesses in stacks since the 1980s. Now a new variation involving memory heaps could catch many firms unawares, says Neil Barrett 10 Feb 2003

SQL Slammer used British code

'Straight cut-and-paste job', says original author 03 Feb 2003

Comment: Culprits or scapegoats?

The extent of the Slammer worm outbreak suggests many companies are failing to fix well-known vulnerabilities. But are IT staff solely to blame for this, asks Neil Barrett 03 Feb 2003

SQL Slammer hits Microsoft

Redmond 'didn't get around to' updating its own servers 28 Jan 2003

SQL Slammer slows the internet

Unpatched systems contribute to havoc on servers as worm spreads 27 Jan 2003

Microsoft warns of new Office attack

Attackers take aim at database component 25 Mar 2008

Apple patches critical Safari holes

Four flaws addressed in latest update 17 Apr 2008

RealPlayer flaw raises security flags

Be wary of unknown files, say experts 07 Jan 2008

related whitepapers

today's top stories

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

IT leaders must stand by India

A sense of perspective is the most important response from IT leaders to the attacks in Mumbai 04 Dec 2008

Case study: Clifford Chance

Law firm implements Sun platform and reduces datacentres to gain efficiency and cost synergies 03 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Colin McDonaldComment

Web 2.0 has potential to transform staff training

Employees can sharpen their IT skills through using the latest interactive training tools, writes Colin McDonald 04 Dec 2008

Advertisement

Primary Navigation