How to mitigate the impact of the Slammer, Sapphire, and MS SQL worm

Document

Wed, 11/18/2009 - 18:23
Jun 22nd, 2009
User Badges:
  • Gold, 750 points or more

Core issue


The worm signature is high volumes of User Datagram Protocol (UDP) traffic to port 1434. Affected customers experience high volumes of traffic from both internal and external systems. Symptoms on Cisco devices include (but are not limited to) high CPU and traffic drops on the input interfaces.

Transmission Control Protocol (TCP) port 1433 and UDP port 1434 are used for Structured Query Language (SQL)server traffic. A new worm targets UDP port 1434. This worm attempts to exploit the buffer overflow vulnerability in Microsoft's SQL Server.


Resolution


For more information, refer to these documents:

Loading.

Actions

This Document

Related Content