SQL spida has no bite Down Under

Symantec has downplayed the threat of a new worm attacking SQL servers, saying it's unlikely to spread much more.

-It's actually a fairly low threat," John Donovan, managing director of Symantec Asia Pacific told ZDNet Australia. -We've graded it a level 2, with the highest threat being level 5. By contrast, Code Red was a level 4."

-The number of SQL servers is very low, and it's fairly easy to fix, you just have to change the administrator's password so it's not blank," Donovan said. -It's got a fairly limited number of attack points, it's unlikely to spread."

Symantec's site shows less than 50 cases of infections, in stark contrast to the 6,600 being touted in other reports.

The worm infects computers running Microsoft SQL Servers that do not have a patch released by Microsoft in April. In addition, the server must be running under administrative access, but with no password on the administrator account.

The worm then deletes file "%SystemRoot%\system32\msver241.srq" and sends the compromised server IP address to the hacker's e-mail account. It also changes the SQL administrator's password to a set of four random characters and scans for vulnerable servers on port 1433.

-It illustrates that it's important to have good antivirus software, and to ensure that you keep passwords changed regularly," Donovan said.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured