Internet Hack Attack on Old Earth
by jdb_educator for CVN/VNN
Symantec, maker of Norton and McAfee Anti-viral products, estimates 22, 000 systems may have been affected by the latest hack effort which is described similar to Code Red. According to Microsoft and Netscape.
Both Web browsing and emails are affected according to the report. Netscape posted this as their lead story, MSN did not have it on their news front page ( http://msnmember.msn.com/ ) as seen by this writer, until top MSNBC headlines were expanded to more. jdb_educator, CVN Editor, told CVN "Well it is nice to know why I am not getting email. It will be interesting to see how long it takes Microsoft to fix their system. I logged on at 7:30 AM. CyT and continue to receive MSN's popup for authorization, and no email."
Microsoft has called this a critical situation and has provided a free patch for their SQL Server 2000. F-Secure has named the SQL worm "Sapphire" and is looking for samples. http://www.F-Secure.com/v-descs/mssqlm.shtml
McAfee calls it the SQL Slammer and calls it a high risk worm for businesses http://vil.mcafee.com/newVirus.asp
Norton appears to have been the first to report the worm and calls it the W32.SQLExp.Worm. There is an excellent detailed description on their site: http://securityresponse.symantec.com/avcenter/venc/data/w32.sqlexp.worm.html
Netscape reports: "The virus-like attack, which began about 12:30 a.m. EST, sought out vulnerable computers on the Internet to infect using a known flaw in popular database software from Microsoft Corp., called "SQL Server 2000." But the attacking software code was scanning for victim computers so randomly and so aggressively - sending out thousands of probes each second - that it overwhelmed many Internet data pipelines."
http://my.netscape.com/corewidgets/news/story.psp?cat=51180&id=200301250719000199457
Microsoft's report, patch, and further information can be found at http://www.microsoft.com/technet/security/bulletin/ms02-039.asp
