Despite that that company *was proactively* patched to protect against the #MSDE vulnerability leveraged by Slammer months in advance.
Unfortunately because of those outliers, some still got infected.
Remediating it wasn't a fire drill at least but it was nontrivial.
Thankfully someone from the libre/free open source community created a #FreeSBIE + #snort + a #Slammer signature.
I could go around to our branches, mirror a port & sniff out offending machines, slowly but surely, cleaning them.
#msde #freesbie #snort #slammer
New blog post: Slammer 20 Years After
On this date twenty years ago the Internet came as close to a total meltdown as we’ve ever seen since the commercialization of the Internet. A tiny UDP worm payload of just 376 bytes spread to all remotely accessible and vulnerable Microsoft SQL servers listening on port 1434 within a matter of minutes. This tiny payload ultimately infected roughly 75 thousand hosts worldwide and the disruption it caused made international news. It was enough to bring many networks to a screeching halt. This blog post is a personal reflection and reconsideration of the fateful event that continues to resonate as one of my most vivid experiences in Internet availability.
https://dataplane.org/jtk/blog/2023/01/slammer20/
#Slammer #Sapphire