IDS mailing list archives

RE: Did IDSes detect the SQL worm?


From: <Cathleen_M_Brackin () bankone com>
Date: Wed, 29 Jan 2003 13:04:52 -0500

We saw it on both our Dragon (MS-SQL:REG-STACK--before Enterasys put out one specific to the worm) and Real Secure 
sensors (SQL_SSRP_StackBo).

-----Original Message-----
From: Todd Heberlein [mailto:todd_heberlein () mac com]
Sent: Tuesday, January 28, 2003 6:42 PM
To: focus-ids () securityfocus com
Subject: Did IDSes detect the SQL worm?


Much has been made about the fact that the vulnerability exploited by 
the MS-SQL worm has been known about for six months.  So not only 
should users have been aware of it, but IDS vendors should have been 
aware of it.

Here is my question: Other than an IDS reporting an unusual amount of 
traffic to port 1434, did any report the specific nature of the attack?

In other words, did any IDS report that the packet appears to attack a 
vulnerability identified by CAN-2002-0649?

Thanks,

Todd



**********************************************************************
This transmission may contain information that is privileged, confidential and/or exempt from disclosure under 
applicable law. If you are not the intended recipient, you are hereby notified that any disclosure, copying, 
distribution, or use of the information contained herein (including any reliance thereon) is STRICTLY PROHIBITED. If 
you received this transmission in error, please immediately contact the sender and destroy the material in its 
entirety, whether in electronic or hard copy format. Thank you
**********************************************************************


Current thread: