January 27, 2003, 02:28
|
#31
|
King
Local Time: 09:06
Local Date: November 1, 2010
Join Date: May 1999
Location: Lost
Posts: 1,020
|
guys, this hit a lot of people...
Bank Of america, Dell, MSN, and quite a few more...knocked out dell globally...
__________________
"Mal nommer les choses, c'est accroître le malheur du monde" - Camus (thanks Davout)
"I thought you must be dead ..." he said simply. "So did I for a while," said Ford, "and then I decided I was a lemon for a couple of weeks. A kept myself amused all that time jumping in and out of a gin and tonic."
|
|
|
|
January 27, 2003, 02:30
|
#32
|
President of the OT
Local Time: 09:06
Local Date: November 1, 2010
Join Date: Nov 1999
Location: Calgary, Alberta
Posts: 40,843
|
It should be a wakeup call to sysadmins everywhere that patches are released for a reason...
__________________
"I'll never doubt you again when it comes to hockey, [Prince] Asher." - Guynemer
|
|
|
|
January 27, 2003, 02:32
|
#33
|
King
Local Time: 09:06
Local Date: November 1, 2010
Join Date: May 1999
Location: Lost
Posts: 1,020
|
i'm sure whom evers fault it was at dell is no longer employed by the company...i hate to guess the lost revenue...
__________________
"Mal nommer les choses, c'est accroître le malheur du monde" - Camus (thanks Davout)
"I thought you must be dead ..." he said simply. "So did I for a while," said Ford, "and then I decided I was a lemon for a couple of weeks. A kept myself amused all that time jumping in and out of a gin and tonic."
|
|
|
|
January 27, 2003, 02:36
|
#34
|
President of the OT
Local Time: 09:06
Local Date: November 1, 2010
Join Date: Nov 1999
Location: Calgary, Alberta
Posts: 40,843
|
SQL Server 2003 launches in a couple months to replace SQL Server 2000 (what was infected), and was completely overhauled in the past year in the interest of security.
It also features an auto-update feature, not unlike auto-Windows Update, to ensure critical patches are pushed through.
__________________
"I'll never doubt you again when it comes to hockey, [Prince] Asher." - Guynemer
|
|
|
|
January 27, 2003, 05:14
|
#35
|
Prince
Local Time: 18:06
Local Date: November 1, 2010
Join Date: Jun 2002
Location: Mingapulco
Posts: 688
|
I think, that people who dont want to update own the warez version of product.
Have a nice bug. Free day.
__________________
money sqrt evil;
My literacy level are appalling.
|
|
|
|
January 27, 2003, 08:03
|
#36
|
King
Local Time: 11:06
Local Date: November 1, 2010
Join Date: Dec 2001
Location: Everybody writes a book too many.
Posts: 1,259
|
This part of an email in my Inbox when i came in to work this morning:
Quote:
|
Starting at around 00:30 EST it appears that a distributed denial of service attack was launched on the Internet. Our out-bound traffic to the Internet approached 100Mbps which our 6Mbps pipe took exception to.
|
Everything seems to be OK now. We'll see.
__________________
What?
|
|
|
|
January 27, 2003, 08:36
|
#37
|
Emperor
Local Time: 17:06
Local Date: November 1, 2010
Join Date: Oct 2000
Location: MY WORDS ARE BACKED WITH BIO-CHEMICAL WEAPONS
Posts: 8,117
|
Quote:
|
Originally posted by Kaak
guys, this hit a lot of people...
Bank Of america, Dell, MSN, and quite a few more...knocked out dell globally...
|
hi ,
and then to say there are products out there that can protect them , ......
..... products that cost less then what those firms pay each month to guys who are supposed to know this , ......
its like your pin code for the ATM , ......
the technology is in place to protect each card with 8 numbers , but most banks dont want to hear about it , .....
have a nice day
|
|
|
|
January 27, 2003, 09:19
|
#38
|
King
Local Time: 18:06
Local Date: November 1, 2010
Join Date: Aug 2001
Location: the contradiction is filled with holes...
Posts: 1,398
|
Yeah, I got it 2 months ago, and I've had a bad flu since then...
No, wait... We aren't talking about virology here ?
__________________
I'm not a complete idiot: some parts are still missing.
|
|
|
|
January 27, 2003, 09:25
|
#39
|
King
Local Time: 10:06
Local Date: November 1, 2010
Join Date: Aug 1999
Location: Austin, Texas, USA
Posts: 1,794
|
--"Surely you're a bright enough man to know the patch was for a product released in late 99/early 2000,"
Yeah, but there's one problem with that. If you look at the MS TechNet notes for the issues, their first patch caused problems with SQL Server operations. They had to patch their patch later.
I also note that the original vulnerability was a buffer overflow. This problem has only been known about since, oh, the 1950s or so. Heck, MS even owns the IP on an automated buffer overflow code auditor (the fact that their buffer overflow code auditor was originally released with a buffer overflow vulernability is another matter).
--"It also features an auto-update feature,"
Yeah, I know you and MS like to push this feature, but there's a problem. Like I mentioned above, the original patch broke some things. It's not the first time a MS patch has done that. Anyone running anything mission critical simply can not afford to have their software automatically upgraded.
Wraith
"It had three holes and I really wanted one."
-- Keitaro ("Love Hina")
|
|
|
|
January 27, 2003, 10:40
|
#40
|
Prince
Local Time: 15:06
Local Date: November 1, 2010
Join Date: Jul 2000
Location: of the "I agree"
Posts: 459
|
MMm, I'm using WinMX for three days (all time computer turn on) and I registered 16 failed intrusions in my firewall, is VERY high compared to the classical 2 or 3 per day!!! It happened in sunday at morning (CET).
10 of these attacks were on my 1434 port, my computer hasn't Ms SQL, but this shows me that some computers that do random IP chekings (like the classical Ad text that appears like a messenger note by the messaging system of the net command that have the NT/XP os) have been infected.
--/--
BTW, WinMX is great for private file transfers, just add the other to hotlist and put queues and other to 1 and is perfect!!
--/--
__________________
Signature: Optional signature you may use to appear at bottom of your posts
Last edited by XarXo; January 27, 2003 at 10:50.
|
|
|
|
January 27, 2003, 11:28
|
#41
|
King
Local Time: 10:06
Local Date: November 1, 2010
Join Date: Aug 1999
Location: Austin, Texas, USA
Posts: 1,794
|
A couple new notes on this.
First, an Inquirer article about how to apply the patch.
Second, a note that this vulnerability appears in other products than just MS SQL. I've seen mention of Visio 2000 and MSDE, the desktop edition of SQL. The real problem with this is that there are probably a lot of people out there who have some version of SQL installed and don't know about it. MS programs like to silently bundle stuff like this. There are also reports on Bugtraq about MS's tools misidentifying SQL patch levels.
Still, no excuses for the corporate IT guys. There's no reason to allow SQL traffic through the firewall in the first place (not without it being VPNed anyway). But that won't help the home users who don't know they're running it in the first place.
Wraith
"Computer /nm./: a device designed to speed and automate errors."
-- From the Jargon File.
|
|
|
|
January 27, 2003, 17:26
|
#42
|
Emperor
Local Time: 17:06
Local Date: November 1, 2010
Join Date: Oct 2000
Location: MY WORDS ARE BACKED WITH BIO-CHEMICAL WEAPONS
Posts: 8,117
|
There seems to have been a slight problem with the database. Please try again by pressing the refresh button in your browser.
We apologise for the inconvenience.
Database error in vBulletin: Link-ID == false, connect failed
mysql error: Can't connect to local MySQL server through socket '/var/lib/mysql/mysql.sock' (2)
mysql error number: 2002
Date: Monday 27th of January 2003 03:50:27 PM
Script: /forums/newreply.php?s=&action=newreply&postid=1667434
Referer: http://apolyton.net/forums/showthrea...34#post1667434
hi ,
this is new , is it related ?
have a nice day
|
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is On
|
|
|
All times are GMT -4. The time now is 11:06.
|
|