January 25, 2003
The little packet that could

The internet has been heavily disturbed this weekend due to a worm that has been spreading via unsafe MS SQL Server machines allover the internet. This has generated enough traffic to shut down or block 5 of 13 root name servers according to some reports and that certainly counts as hurricane strength as 'internet weather' goes. The slashdot thread on the issue is interesting and in particular it is interesting to learn that the worm has been able to spread inside one (1) UDP packet exploiting a buffer overflow. That's 376 bytes of very malicious code! (analyzed here).

Posted by Claus at January 25, 2003 10:47 PM
