INFO

SQL Server worm "Slammer" is no risk for SwyxWare (kb2318)

Le informazioni contenute nel presente articolo riguardano i seguenti prodotti:

  • Microsoft Database Engine 2000
  • Microsoft Database Engine 1.0
  • Microsoft SQL Server 2000
  • Microsoft SQL Server 7.0
  • SwyxWare all versions

[ Riepilogo | Informazioni | Referenze ]


Riepilogo

Last week the SQL Server worm Slammer filled the topics of all news. This articles describes the worm and why it is no risk for the SwyxWare.

Informazioni

The SQL Server worm "Slammer"

"Slammer" uses a security gap within Microsofts SQL Server 2000. This gap has been addressed by Micrososft by a security update in October 2002. The worm generates a huge data load via UDP port 1434 which slows down an SQL Server machine and produce high costs for data transfer. The worm searches and infects other SQL Servers and spreads therefore quite fast.

The worm gains control over the SQL Server by creating a Buffer Overflow. Microsoft SQL Server 2000 installations with Service Pack 3 installed are immune against "Slammer". "Slammer" itself has a size of 376 bytes.

SwyxWare and "Slammer"

SwyxWare uses the Microsoft Database Engine (MSDE) Version 7.0 which is an MS SQL Server 7.0 without administrative tools to store configuration and user settings. "Slammer" only infects MS SQL Server 2000 machines and is therefore no harm for a standard SwyxWare installation.

If SwyxWare is being used with an MS SQL Server 2000, which is of course possible, Swyx assumes the database administrator to install all Security Updates and Service Packs as they become available from Microsoft.

MS SQL Server 7.0 Service Pack 4

The Service Pack 4 can be found on the SwyxWare CD, the Swyx FTP Server or directly on the Microsoft Webpages. Swyx recommends the installation of the Service Pack allthough it is not necessary for the usage of SwyxWare.


Referenze

As far as software supplied or used by us, includes open source elements the additional terms under https://www.swyx.com/open-source apply in addition. An overview which products from the Swyx portfolio include open source elements and which open source license is relevant can be found under https://www.swyx.com/open-source.

Informazioni di altri produttori proposte in questo articolo hanno il compito di appoggiare la ricerca di informazioni tecniche. I contenuti potrebbero essere modificati senza preavviso. Swyx non garantisce per la veridicità dei contenuti di articoli di terzi e declina ogni responsabilità per essi.


Commento

L'articolo è stato utile? Lasci un commento all'articolo



Come possiamo contattarLa se dal Suo commento dovessero nascere altri quesiti?

Indirizzo e-mail Adresse (facoltativo)


Nota

Il campo destinato ai commenti non è ammesso per richieste all'assistenza. Per quesiti inerenti l'assistenza rivolgersi esclusivamente al proprio rivenditore di fiducia o al distributore competente.