Home Up Contact Contents Search


W32/SQL Slammer

 

EVRT™ Virus Warning issued for  W32/SQLSlammer

Complete description can be read online by clicking here

Details:

Name:
W32/SQLSlammer
Alias: SQL.Slammer
Type: Worm
Discovered: January 25, 2003
Home users: LOW RISK
Corporate users: HIGH RISK

Description:

W32/SQLSlammer is a fileless worm that targets Microsoft SQL 2000 servers. If a vulnerable server is found, W32/Slammer installs itself into memory and does not write a file to the hard disk. An exploited server will then create traffic on UDP port 1434. To correct and fix an affected server an administrator will have to apply the necessary patch to avoid re-infection and reboot the server.

This worm can generate massive IP traffic to effect the quality of service of the network.

Microsoft has issued a patch which protects users against this vulnerability. It can be downloaded from here:

Microsoft patch and information