SQL slammer analysed
16th February 2003
Robert Graham’s analysis of SQL Slammer cleared up quite a few things I had been wondering about the worm. It confirms that the majority of the infections were caused not by SQL Server (as reported widely by the press) but by the embedded MSDE component, which is far less likely to be patched (or firewalled off from the public internet) than SQL Server.
Incidentally, Curious Yellow is a fascinating explanation of a theoretical “co-ordinated super-worm” capable of adapting to attempts to combat it using advanced peeer to peer techniques. It is an extension of the Warhol worm concept where a worm that pre-scans the internet for targets could infect all susceptile hots world-wide in less than 30 seconds. Scary stuff.
More recent articles
- First impressions of Claude Cowork, Anthropic's general agent - 12th January 2026
- My answers to the questions I posed about porting open source code with LLMs - 11th January 2026
- Fly's new Sprites.dev addresses both developer sandboxes and API sandboxes at the same time - 9th January 2026