January 29, 2003 5:46 PM PST

Slammer may not feed on Microsoft alone

Microsoft products may not be alone in contributing to the spread of the SQL Slammer worm, security researchers said Wednesday.

Other companies also make products containing the Microsoft database software that the worm has exploited. More than 30 products, from security scanners to backup servers, use the vulnerable Microsoft SQL Server 2000 and Microsoft SQL Desktop Edition (MSDE) 2000 software, according to a list compiled by database security site SQLSecurity.com.

"In most cases, it is probably a reduced danger," said Chip Andrews, an independent security consultant and the Webmaster for SQLSecurity.com. "If you have MSDE installed on an application, it's powerful. So you have to make sure to secure it."

Last weekend, many corporate networks slowed to a crawl after a fast-spreading computer worm infected database servers running vulnerable Microsoft software. Although the Redmond, Wash.-based company had issued a patch for the flaw six months earlier, more than 200,000 computers and information appliances were still not patched at the time of the attack and became infected, according to the latest estimates from security information site Incidents.org.

The compromised machines inundated local networks and the Internet with vast quantities of data, in an attempt to infect other systems. The deluge brought down banks' ATM networks and disrupted some phone services, and the effects were felt by many companies, including those in the airline and railroad industries.

Microsoft said that only SQL Server 2000 and MSDE 2000--including the retail, service pack 1 and service pack 2 versions--are affected by the Slammer worm. It released a list of products that included MSDE 2000 by default or by explicit instruction at the time of installation.

Other companies whose products use MSDE 2000 as a software component have, for the most part, been mum. While the individual products on the SQLSecurity.com list haven't been positively identified as vulnerable, some companies have acknowledged the security risk.

Storage server maker Veritas Software is included on the list. It told its customers earlier this week that its Backup Exec 9.0 for Windows Servers and ExecView 3.1 servers "may be susceptible to infection" by the worm.

Other companies said that their products included the Microsoft software in question, but that they had taken precautions to lock down the applications. For example, software company Internet Security Systems said that although both its RealSecure 7.0 and Internet Scanner included MSDE 2000, the products were configured to minimize any risk.

"Yes, we have MSDE, but it's not vulnerable," said Peter Allor, manager of the company's threat intelligence services.

That the security of most of the products on the list remains in question has left security researchers uncomfortable. Chris Wysopal, director of research and development for digital security firm @Stake, said that the lack of details from companies regarding their products' security was not reassuring.

"If there is no vulnerability, you don't say anything--that's fine," he said. "But if there is even a small vulnerability, you should advise your customers and fix it."

Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
What you need in business class email.
Mailtrust

Click Here!
Never worry about email again. From mobility and shared calendaring to virus and spam protection starting at only $3 per mailbox. more>

Rackspace Mailtrust
Total Email Relief

We'll take care of your email so you can take care of your business.

14 Day Free Trial

With expert support 24x7x365 we guarentee 100% uptime. Try us for free for 14 days. Never worry about your email again.

Just $3 per mailbox

Choose the plan that is right for your company and only pay for what you need.

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Outside the Lines

    EIC Squared: Chrome, iPods, and a Dell-Salesforce union

    On this week's EIC Squared podcast CNET's Dan Farber and ZDNet's Larry Dignan discuss Google's latest rocket launch--the Chrome browser--as well as Apple's iPod event next week and a Dell-Salesforce.com union.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    At 10 years old, whither Google?

    Daniel Sieberg of CBS News looks at how the company grew exponentially from start-up to superstar and part of our culture, but what's ahead?

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Webware

    Mozilla releases second Firefox 3.1 alpha

    Added features include support for a new video tag element introduced with the HTML 5 standard, along with some speed enhancements.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.