Re: New worm / port 1434?'

2003-01-25 Thread David G. Andersen
On Sat, Jan 25, 2003 at 10:49:01AM -0500, Eric Gauthier mooed: > > Ok, > > I'm not sure if this helps at all. Our campus has two primary connections - > the main Internet and something called Internet2. Internet2 has a routing > table of order 10,000 routes and includes most top-tier research

Re: New worm / port 1434?

2003-01-25 Thread Curtis Maurand
]> Sent: Saturday, January 25, 2003 3:48 AM Subject: Re: New worm / port 1434? > > On Sat Jan 25, 2003 at 02:19:04AM -0500, Mike Tancsa wrote: > > Yes, I am seeing this big time. Are you sure its SQL server ? Thats > > normally 1433 no ? Are there any other details so

Re: New worm / port 1434?

2003-01-25 Thread Adam \"Tauvix\" Debus
rator, ReachONE Internet [EMAIL PROTECTED] - Original Message - From: "Jack Bates" <[EMAIL PROTECTED]> To: "Eric Gauthier" <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]> Sent: Saturday, January 25, 2003 9:35 AM Subject: Re: New worm / port 1434? > > From

RE: New worm / port 1434?

2003-01-25 Thread Marc Maiffret
| To: Eric Gauthier; [EMAIL PROTECTED] | Subject: Re: New worm / port 1434? | | | | From: "Eric Gauthier" | | > Woot! | > | > We made the front page of CNN.com: | > | > Electronic attack slows Internet | > http://www.cnn.com/2003/TECH/internet/01/25/internet.attack/in

Re: New worm / port 1434?

2003-01-25 Thread Jack Bates
From: "Eric Gauthier" > Woot! > > We made the front page of CNN.com: > > Electronic attack slows Internet > http://www.cnn.com/2003/TECH/internet/01/25/internet.attack/index.html > > Guess that USD10 goes to some unnamed reporter at CNN > And please tell me how CodeRed was worse? I'm sorry, this

Re: New worm / port 1434?

2003-01-25 Thread Len Rose
http://lists.netsys.com/pipermail/full-disclosure/2003-January/003718.html

Re: New worm / port 1434?

2003-01-25 Thread Marshall Eubanks
Dear Eric; On Saturday, January 25, 2003, at 10:49 AM, Eric Gauthier wrote: Ok, I'm not sure if this helps at all. Our campus has two primary connections - the main Internet and something called Internet2. Internet2 has a routing table of order 10,000 routes and includes most top-tier re

Re: New worm / port 1434?

2003-01-25 Thread Marshall Eubanks
Can you give me any information about which multicast group addresses were being attacked ? I have seen very little sign of this worm in interdomain multicast; it does not seem to be causing MSDP havoc the way that the RAMEN worm did. Regards

Re: New worm / port 1434?

2003-01-25 Thread Eric Gauthier
Woot! We made the front page of CNN.com: Electronic attack slows Internet http://www.cnn.com/2003/TECH/internet/01/25/internet.attack/index.html Guess that USD10 goes to some unnamed reporter at CNN Eric :)

Re: New worm / port 1434?

2003-01-25 Thread Stephen J. Wilcox
On Sat, 25 Jan 2003, Eric Gauthier wrote: > > Ok, > > I'm not sure if this helps at all. Our campus has two primary connections - > the main Internet and something called Internet2. Internet2 has a routing > table of order 10,000 routes and includes most top-tier research instituations > in

Re: New worm / port 1434?

2003-01-25 Thread Stephen J. Wilcox
Dont panic, its all ok "Howard Schmidt, one of President George W Bush's top cyber-security advisers, said the FBI's National Infrastructure Protection Center and private experts at the CERT Co-ordination Center were monitoring the attacks. " ;) I'm monitoring too, hope you all feel better! St

RE: New worm / port 1434?

2003-01-25 Thread Marcos R. Della
-Original Message- From: Peter van Dijk [mailto:[EMAIL PROTECTED]] Sent: Saturday, January 25, 2003 3:35 AM To: Avleen Vig; [EMAIL PROTECTED] Subject: Re: New worm / port 1434? On Sat, Jan 25, 2003 at 08:05:33AM +, Gary Coates wrote: > > Duplicated info.. But this is an o

Re: New worm / port 1434?

2003-01-25 Thread lost
On Sat, 25 Jan 2003, Marshall Eubanks wrote: > Can you give me any information about which multicast group addresses > were being attacked ? I didn't have any logging turned on at the time so I don't have the addresses laying around. I just remember I had a storm of traffic trying to go to addre

Re: New worm / port 1434?

2003-01-25 Thread Stephen J. Wilcox
On Sat, 25 Jan 2003, Avleen Vig wrote: > > On Sat, Jan 25, 2003 at 12:12:37AM -0800, Mike Leber wrote: > > > > We are seeing this too. > > We are seeing the gige interfaces on multiple customer aggregation > > switches at multiple locations add several hundred Mbps each. All the > > traffic i

Re: New worm / port 1434?

2003-01-25 Thread Eric Gauthier
Ok, I'm not sure if this helps at all. Our campus has two primary connections - the main Internet and something called Internet2. Internet2 has a routing table of order 10,000 routes and includes most top-tier research instituations in the US (and a few other places). By 1am this morning (Eas

Re: New worm / port 1434?

2003-01-25 Thread Neil J. McRae
> Anyone else dealing with this tonight? Its kind of nasty Its very nasty, and it happened at the worse time after 17:00 GMT so contacting customers hasn't been easy. We've deployed filters on systems that are under attack and continue to monitor the sitation, its caused lots of DNS issues with

Re: New worm / port 1434?

2003-01-25 Thread Peter van Dijk
On Sat, Jan 25, 2003 at 08:05:33AM +, Gary Coates wrote: > > Duplicated info.. But this is an old worm ;-( > > http://www.cert.org/advisories/CA-1996-01.html This is not the worm that's spreading now. Greetz, Peter -- [EMAIL PROTECTED] | http://www.dataloss.nl/ | Undernet:#clue

Re: New worm / port 1434?

2003-01-25 Thread lost
This one seemed to be particularly nasty as it was generating traffic to multicast addresses too. It caused a nice flood on the switched ethernet segment I had a vulnerable box on. (And took out a router in the process. Great fun.) William Astle finger [EMAIL PROTECTED] for further information

Re: New worm / port 1434?

2003-01-25 Thread Josh Richards
Note, further analysis makes me believe that the ICMP we saw immediately beforehand was a coincidence and unrelated. The origin of the ICMP has been traced to a customer application. -jr * Josh Richards <[EMAIL PROTECTED]> [20030125 00:21]: > > A preliminary look at some of our NetFlow data sh

Re: New worm / port 1434?

2003-01-25 Thread Scott Call
I'm seeing obscene amounts of 1434/udp traffic at my transit and peering points. I've filtered it out in both directions everywhere my network touches the outside world. It's almost 20% of my traffic at this point. I think I've calmed the internal storm so far, but we'll see. I saw refence to

Re: New worm / port 1434?

2003-01-25 Thread Dr. Mosh
We had to go through each VLAN to determine which boxes were compromised, looks like W2K SQL. This thing is spreading fast. -D 0. Pete Ashdown <[EMAIL PROTECTED]> farted: > > * Avleen Vig ([EMAIL PROTECTED]) [030124 23:50] writeth: > > > >It seems we have a new worm hitting Microsoft SQL ser

Re: New worm / port 1434?

2003-01-25 Thread Jack Bates
From: "Mike Tancsa" > > > Yes, I am seeing this big time. Are you sure its SQL server ? Thats > normally 1433 no ? Are there any other details somewhere about this ? > All MS SQL servers listen to 1434 reguardless of the other ports they listen on. Depending on configuration depends on what

Re: New worm / port 1434?

2003-01-25 Thread Mike Leber
We are seeing this too. We are seeing the gige interfaces on multiple customer aggregation switches at multiple locations add several hundred Mbps each. All the traffic is destined for udp port 1434 with a randomized source address. We are doing "ip verify unicast source reachable-via any" whic

Re: New worm / port 1434?

2003-01-25 Thread Adam \"Tauvix\" Debus
- From: "Mike Tancsa" <[EMAIL PROTECTED]> To: "Avleen Vig" <[EMAIL PROTECTED]> Cc: <[EMAIL PROTECTED]> Sent: Friday, January 24, 2003 11:19 PM Subject: Re: New worm / port 1434? > > > Yes, I am seeing this big time. Are you sure its SQL serv

Re: New worm / port 1434?

2003-01-25 Thread Avleen Vig
On Sat, Jan 25, 2003 at 12:12:37AM -0800, Mike Leber wrote: > > We are seeing this too. > We are seeing the gige interfaces on multiple customer aggregation > switches at multiple locations add several hundred Mbps each. All the > traffic is destined for udp port 1434 with a randomized source ad

Re: New worm / port 1434?

2003-01-25 Thread K. Scott Bethke
Anyone else dealing with this tonight? Its kind of nasty -Scotty - Original Message - From: "Avleen Vig" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Saturday, January 25, 2003 1:32 AM Subject: New worm / port 1434? > > It seems we have a new worm

Re: New worm / port 1434?

2003-01-25 Thread Simon Lockhart
On Sat Jan 25, 2003 at 02:19:04AM -0500, Mike Tancsa wrote: > Yes, I am seeing this big time. Are you sure its SQL server ? Thats > normally 1433 no ? Are there any other details somewhere about this ? This URL seems to explain the exploit: http://www.nextgenss.com/advisories/mssql-u

Re: New worm / port 1434?

2003-01-25 Thread Jake Khuon
### On Fri, 24 Jan 2003 22:59:17 -0800, Josh Richards <[EMAIL PROTECTED]> ### casually decided to expound upon [EMAIL PROTECTED] the following thoughts ### about "Re: New worm / port 1434?": JR> * Avleen Vig <[EMAIL PROTECTED]> [20030124 22:44]: JR> > JR> >

Re: New worm / port 1434?

2003-01-25 Thread Gary Coates
Duplicated info.. But this is an old worm ;-( http://www.cert.org/advisories/CA-1996-01.html Pete Ashdown wrote: * Avleen Vig ([EMAIL PROTECTED]) [030124 23:50] writeth: It seems we have a new worm hitting Microsoft SQL server servers on port 1434. Affirmative. Be sure to block 1434 UDP o

Re: New worm / port 1434?

2003-01-25 Thread Mike Tancsa
At 02:45 AM 1/25/2003 -0600, Jack Bates wrote: From: "Mike Tancsa" > > > Yes, I am seeing this big time. Are you sure its SQL server ? Thats > normally 1433 no ? Are there any other details somewhere about this ? > All MS SQL servers listen to 1434 reguardless of the other ports they listen

Re: New worm / port 1434?

2003-01-25 Thread Adam \"Tauvix\" Debus
t; <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Friday, January 24, 2003 10:32 PM Subject: New worm / port 1434? > > It seems we have a new worm hitting Microsoft SQL server servers on port > 1434. >

Re: New worm / port 1434?

2003-01-25 Thread Mark Radabaugh
Yep - we are seeing 3 compromised SQL boxes right now. Mark Radabaugh Amplex (419) 720-3635 - Original Message - From: "Avleen Vig" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Saturday, January 25, 2003 1:32 AM Subject: New worm / port 1434? > >

Re: New worm / port 1434?

2003-01-25 Thread Lloyd Taylor
This may well be the exploit being used: http://www.nextgenss.com/advisories/mssql-udp.txt --Lloyd On Sat, 25 Jan 2003, Dave Stewart wrote: > Date: Sat, 25 Jan 2003 01:50:03 -0500 > From: Dave Stewart <[EMAIL PROTECTED]> > To: [EMAIL PROTECTED] > Subject: Re: New worm / por

Re: New worm / port 1434?

2003-01-25 Thread Josh Richards
* Avleen Vig <[EMAIL PROTECTED]> [20030124 22:44]: > > It seems we have a new worm hitting Microsoft SQL server servers on port > 1434. A preliminary look at some of our NetFlow data shows a suspect ICMP payload delivered to one of our downstream colo customer boxes followed by a 70 Mbit/s burst

Re: New worm / port 1434?

2003-01-24 Thread Pete Ashdown
* Avleen Vig ([EMAIL PROTECTED]) [030124 23:50] writeth: > >It seems we have a new worm hitting Microsoft SQL server servers on port >1434. Affirmative. Be sure to block 1434 UDP on both the inbound and the outbound. Infected servers are VERY NOISY.

Re: New worm / port 1434?

2003-01-24 Thread Dave Stewart
At 01:32 AM 1/25/2003, you wrote: It seems we have a new worm hitting Microsoft SQL server servers on port 1434. Agreed... shutting down MSSQL stopped the flood here now to find it and remove it

New worm / port 1434?

2003-01-24 Thread Avleen Vig
It seems we have a new worm hitting Microsoft SQL server servers on port 1434.