Risk rating: TREND MICRO is escalating this to RED ALERT (High Risk) status
Virus action: Denial of service (using port 1434)
Description: This DDOS (Distributed Denial of Service Attack) happens to systems using Microsoft SQL Server 2000. The vulnerability allows remote attackers to create a denial-of-service condition between two Microsoft SQL servers.
This DDOS worm uses the buffer overflow method of invoking vulnerability.
It comes as a program that ask for parameters. The parameters ask are the target host, port and version of the SQL service pack.
It uses shellcode and commands to trigger and execute a return address to the code of the DDOS.
When an attack happens, it will consume server and network resources resulting in a restart of the SQL Server, a reboot of the server host, or a network failure.
Service Pack version 1 are tested to be vulnerable.
For additional information about the vulnerability, you can refer to the URL below:
http://www.kb.cert.org/vuls/id/370308
http://www.microsoft.com/technet/security/bulletin/MS02-039.asp
Recommendation from Trend Micro:
Apply patches
This malware exploits known vulnerabilities in Microsoft SQL Server 2000. Please download and install the
http://www.microsoft.com/sql/downloads/2000/sp3.asp
fix patch supplied by Microsoft. Refrain from using this product until the appropriate patch has been installed.
Block UDP port 1434
As a workaround, system administrators can block UDP port 1434, thus preventing external attackers from exploiting this vulnerability.