Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register
SECURITY ADVISER  

Say it ain't so!

Slammer worm exploits an old vulnerability: too many patches, too little time

By Wayne Rash
February 07, 2003
 

No doubt you're expecting me to be (virtually) wagging my index finger at you and saying over and over, "Shame, shame, shame." Well, I'm not.

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

Yes, the Slammer/Sapphire worm that emerged a couple of weekends ago was a great hindrance to the Internet, and yes, a patch for it already existed, but sometimes it's just hard to keep up.

The Slammer/Sapphire worm exploited a weakness in Microsoft SQL Server 2000 that allowed the worm to flood the server with requests until it suffered a buffer overflow. Then things would stop. Fortunately, this was a worm with no payload, so all it did was interfere with SQL Server ?it didn't also deliver a load of viruses or other malicious code.

Also, fortunately, the patch already existed, so all affected companies had to do was download and install the patch from Microsoft. When that was done, the worm was gone. The sad thing is that the patch has been available since July 2002. By now, you'd think that everyone with a copy of SQL Server would have patched it.

But you'd have thought wrong. Applying updates to your enterprise database servers isn't the same as downloading the latest fix using Windows Update. The fact that you'll have to take the server offline to apply the patch means that you'll be out of business for a while, and if something goes wrong during the process, then you'll be out of business for a while longer. So you wait until a time when you'll be taking the server down for some other reason and plan to apply all your patches then.

And, of course, all of this assumes that you have a good handle on what's installed on all your servers and what their current patch status is. If you have a lot of servers, this is a tall order all by itself. Given today's vastly understaffed IT departments, it could be more than the staff can do. After all, can you spare an individual's hours to account for each server, its operating system, applications, and current patches on each, not to mention the status of all planned maintenance? I didn't think so.

So what can you do? One solution is to find a good means of scanning your network for vulnerabilities. We mentioned eEye’s Retina recently, and that's precisely what this product does. It even offers to download patches and fix other problems for you.

But knowing about the vulnerabilities is only part of the problem. You'll still have to take the server offline to apply patches, and that will still take you out of business. So maybe the answer is to invest in a few backup servers; that way, if you plan your downtime right, you can add patches while incurring little interruption to your business.

Or even better ?maybe periodic patching sessions would be a great time to test your continuity of operations plan. Put your enterprise into its emergency operations mode, and while that's being tested, upgrade those servers. Then you'll have accomplished two goals at once.

Of course, that assumes you have a continuity of operations plan. You do have one, don't you?

?/span>





 


 
Wayne Rash is an InfoWorld senior contributing editor.
 

TOP NEWS:


»  Parts of San Francisco network still locked out
Administrators are still locked out of the city's VoIP system and LANs within the Sheriff's Department and the Recreation & Park Department

»  Intel says Moblin update coming soon
Open-source effort set for mobile Linux should have an alpha-level release in a few weeks

»  Are virtual firewalls a solution for VM security?
Virtual firewalls can be a useful security tool, but their efficacy depends heavily on how you have set up your networks

»  Ubuntu to unveil new version of Launchpad next week
Ubuntu's beta community still has a long way to go to achieve the popularity of competitors such as SourceForge.net

»  Oracle unveils access management suite
Oracle's suite includes a new server that provides controls to fine-tune user privileges

»  5 ways the iPhone 3G still lags in enterprise
Despite Apple's improvements, its iPhone 2.0 software remain less competent and less tested than its BlackBerry and Windows Mobile counterparts




What Every Enterprise Needs to Know About VDI
Today's enterprise IT environment is already complex, and replete with heterogeneous technologies. Attend this informative webcast to understand the key components for deploying and managing virtual desktop infrastructure in your environment. Sponsor: VDIworks

»  Click here to view this Webcast
  Zombie PCs Are Attacking Your LAN
A recent study showed that malware-infected zombie PCs are now a bigger threat to ISPs and Web infrastructure than DoS attacks. As this brand new IT Strategy Guide explains, an increased use of peer-to-peer techniques by the attackers has made it harder to fight back. Download now, compliments of Verio:

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist