-
August 12th, 2005, 03:46 PM
#1
SQL Slammer hits
Is anyone else seeing a spike in SQL Slammer worm hits on their perimeter?
I have 124 uniques hosts hitting me with 533 events. This is particularly high and my guess is that it might be tied to a worm we discovered in the wild earlier this week.
--Th13
Our scars have the power to remind us that our past was real. -- Hannibal Lecter.
Talent is God given. Be humble. Fame is man-given. Be grateful. Conceit is self-given. Be careful. -- John Wooden
-
August 12th, 2005, 03:53 PM
#2
I've been getting 300+ MS-SQL worm attempts for a week or two now. Don't know or care if it's Slammer or not since I don't have the ports open to the world. I've had 290 in the last 24 hours.
Don\'t SYN us.... We\'ll SYN you.....
\"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides
-
August 12th, 2005, 03:58 PM
#3
Re: SQL Slammer hits
Originally posted here by thehorse13
Is anyone else seeing a spike in SQL Slammer worm hits on their perimeter?
I have 124 uniques hosts hitting me with 533 events. This is particularly high and my guess is that it might be tied to a worm we discovered in the wild earlier this week.
--Th13
I hear ya Horse, I have seen A LOT of activity for well over a week now.
Now excuse me while I go hug my firewall.
Cheers:
-
August 12th, 2005, 04:26 PM
#4
Thanks fellas,
My firewall is tighter than a frog's ass in water. I was just curious if others were getting fired at by this. It was more to satisfy my curiousity than anything else. There is no way it's gettin in here!
Our scars have the power to remind us that our past was real. -- Hannibal Lecter.
Talent is God given. Be humble. Fame is man-given. Be grateful. Conceit is self-given. Be careful. -- John Wooden
-
August 12th, 2005, 04:33 PM
#5
There is no way it's gettin in here!
Yep.... and pride cometh before a fall..... You don't have that admin writing any other scripts do you.... or changing firewalls......
Don\'t SYN us.... We\'ll SYN you.....
\"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides
-
August 12th, 2005, 05:08 PM
#6
My Snort logs show...
Yesterday: 49 unique hosts, 80 hits
Past 7 days: 249 unique hosts, 536 hits with about 10 hosts hitting 10-15 times.
Mostly normal
-
August 12th, 2005, 06:24 PM
#7
Hahahah, no sir. He is not part of our operation, thus, the world is a safer place.
Our scars have the power to remind us that our past was real. -- Hannibal Lecter.
Talent is God given. Be humble. Fame is man-given. Be grateful. Conceit is self-given. Be careful. -- John Wooden
-
August 14th, 2005, 01:59 AM
#8
Firewalls can do some good even if you don't think it would
-
August 14th, 2005, 05:53 AM
#9
Sorry, don't have access to current stats... but I can tell you that the last 3 days of July, the corporate HQ dmz sensor triggered 1394 events (tcp1434) from 300 unique hosts. It's up a little bit, but we see it all the time at this client's site.
"Data is not necessarily information. Information does not necessarily lead to knowledge. And knowledge is not always sufficient to discover truth and breed wisdom." --Spaf
Anyone who is capable of getting themselves made president should on no account be allowed to do the job. --Douglas Adams (1952-2001)
"...people find it far easier to forgive others for being wrong than being right." - Albus Percival Wulfric Brian Dumbledore
-
August 14th, 2005, 06:48 AM
#10
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|