Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Big Trouble on the Net Today

Thread Tools
 
Search this Thread
 
Old 25 January 2003, 12:22 PM
  #1  
P1Fanatic
Scooby Regular
Thread Starter
 
P1Fanatic's Avatar
 
Join Date: Dec 2001
Location: Arborfield, Berkshire
Posts: 12,387
Likes: 0
Received 0 Likes on 0 Posts
Post

If youve noticed the Net being slow today it looks like yet another worm has been released causing chaos on internet links worldwide. Looks like its something to do with SQL on Port 1434.

No reports on the register etc as yet but believe me this is big!

Simon.
Old 25 January 2003, 12:31 PM
  #2  
P1Fanatic
Scooby Regular
Thread Starter
 
P1Fanatic's Avatar
 
Join Date: Dec 2001
Location: Arborfield, Berkshire
Posts: 12,387
Likes: 0
Received 0 Likes on 0 Posts
Post

It looks like everyone is suffering from a Distributed Denial of
Service attack. It seems to be related to MS SQL servers that suddenly start sending loads of UDP traffic to random IP addressess on port 1434. This keeps on increasing, eventually maxing out links.

Simon.
Old 25 January 2003, 12:34 PM
  #3  
super_si
Scooby Regular
 
super_si's Avatar
 
Join Date: Feb 2002
Location: Lurkin Somewhere
Posts: 7,951
Likes: 0
Received 0 Likes on 0 Posts
Post

Culprit
Old 25 January 2003, 12:47 PM
  #4  
P1Fanatic
Scooby Regular
Thread Starter
 
P1Fanatic's Avatar
 
Join Date: Dec 2001
Location: Arborfield, Berkshire
Posts: 12,387
Likes: 0
Received 0 Likes on 0 Posts
Post

This makes code red look like a **** in the park. So I wouldnt be posting on a public BBS that you were involved
Old 25 January 2003, 12:53 PM
  #5  
pslewis
Scooby Regular
 
pslewis's Avatar
 
Join Date: Jun 2000
Location: Old Codgers Home
Posts: 32,398
Likes: 0
Received 1 Like on 1 Post
Post

I havent noticed any difference?? its faster than yesterday!! So I say - release the worm!!

Pete
Old 25 January 2003, 01:02 PM
  #6  
P1Fanatic
Scooby Regular
Thread Starter
 
P1Fanatic's Avatar
 
Join Date: Dec 2001
Location: Arborfield, Berkshire
Posts: 12,387
Likes: 0
Received 0 Likes on 0 Posts
Post

Thats because by the time old farts like you get up from your slumber, its impact has been reduced
Old 25 January 2003, 01:05 PM
  #7  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

http://vil.nai.com/vil/content/v_99992.htm

Saturday!!! Working on notification now.

Old 25 January 2003, 02:06 PM
  #8  
P1Fanatic
Scooby Regular
Thread Starter
 
P1Fanatic's Avatar
 
Join Date: Dec 2001
Location: Arborfield, Berkshire
Posts: 12,387
Likes: 0
Received 0 Likes on 0 Posts
Post

Good link Jack!
Old 25 January 2003, 02:26 PM
  #9  
RichB
Scooby Regular
 
RichB's Avatar
 
Join Date: Apr 1999
Location: Bore Knee Muff
Posts: 3,666
Likes: 0
Received 0 Likes on 0 Posts
Red face

Our Mac servers seem to be running fine
...but only cos all the SQL servers are off

Oh what fun it is to work in an ISP! *yawn*
Old 25 January 2003, 02:59 PM
  #10  
P1Fanatic
Scooby Regular
Thread Starter
 
P1Fanatic's Avatar
 
Join Date: Dec 2001
Location: Arborfield, Berkshire
Posts: 12,387
Likes: 0
Received 0 Likes on 0 Posts
Post

We have loads of customers shutting their routers off due to the problems its causing them. Doesnt seem thay many customers are aware as yet. Im off for 5 days on monday so Ill miss the aftermath - ah joy!
Old 25 January 2003, 03:14 PM
  #11  
stevem2k
Scooby Regular
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Post

One of our rotating banner providers has been down since 05:30 this morning ~ had to come into the office to put in some workarounds .. grrrrrr



Steve
Old 25 January 2003, 05:34 PM
  #12  
Houlbt
Scooby Regular
 
Houlbt's Avatar
 
Join Date: Sep 2001
Posts: 748
Likes: 0
Received 0 Likes on 0 Posts
Post

Where do you work P1Fan...

We got totally fcuked today, costs a lot of cash in my game.

But me not being IT I just get to sit here looking stoopid whilst IT runs round pulling wires out of stuff

oh well....at least someone left a copy of evo lying around
Old 25 January 2003, 05:39 PM
  #13  
P1Fanatic
Scooby Regular
Thread Starter
 
P1Fanatic's Avatar
 
Join Date: Dec 2001
Location: Arborfield, Berkshire
Posts: 12,387
Likes: 0
Received 0 Likes on 0 Posts
Post

I work for WorldCom mate. We knew about it just after midnight. Didnt impact our network that much as we got filters up to reduce traffic.

Simon.
Old 25 January 2003, 05:59 PM
  #14  
Houlbt
Scooby Regular
 
Houlbt's Avatar
 
Join Date: Sep 2001
Posts: 748
Likes: 0
Received 0 Likes on 0 Posts
Post

Dunno.... but it is causing real trouble here, think we have a load of people from Siemens here sorting stuff.

Apparently BT lost a lot of systems... but I don't really know what I am talking about
Old 25 January 2003, 06:00 PM
  #15  
Houlbt
Scooby Regular
 
Houlbt's Avatar
 
Join Date: Sep 2001
Posts: 748
Likes: 0
Received 0 Likes on 0 Posts
Post

UDP broadcast....ehhhh! what is that all about, me dunno
Old 25 January 2003, 06:28 PM
  #16  
Gordon Brown
Scooby Newbie
 
Gordon Brown's Avatar
 
Join Date: Jan 2003
Posts: 5
Likes: 0
Received 0 Likes on 0 Posts
Post

.

[Edited by Gordon Brown - 25/01/2003 18:29:41]
Old 25 January 2003, 07:13 PM
  #17  
P1Fanatic
Scooby Regular
Thread Starter
 
P1Fanatic's Avatar
 
Join Date: Dec 2001
Location: Arborfield, Berkshire
Posts: 12,387
Likes: 0
Received 0 Likes on 0 Posts
Post

Heres another good link:

http://www.cert.org/advisories/CA-2003-04.html

Simon.
Old 25 January 2003, 07:17 PM
  #18  
mega_stream
Scooby Regular
 
mega_stream's Avatar
 
Join Date: May 2001
Location: Scotland
Posts: 4,580
Likes: 0
Received 0 Likes on 0 Posts
Talking

Have UUNET sorted that DNS problem yet?

What happened?

Old 25 January 2003, 07:39 PM
  #19  
P1Fanatic
Scooby Regular
Thread Starter
 
P1Fanatic's Avatar
 
Join Date: Dec 2001
Location: Arborfield, Berkshire
Posts: 12,387
Likes: 0
Received 0 Likes on 0 Posts
Post

Its looking ok at the moment. I cant say exactly what happened as its more than my jobs worth posting that sort of stuff on a public bbs. If you look on the register it should give you the lowdown.

Simon.

[Edited by P1Fanatic - 25/01/2003 19:40:17]
Old 25 January 2003, 08:58 PM
  #20  
P1Fanatic
Scooby Regular
Thread Starter
 
P1Fanatic's Avatar
 
Join Date: Dec 2001
Location: Arborfield, Berkshire
Posts: 12,387
Likes: 0
Received 0 Likes on 0 Posts
Post

Has made it to the Beeb:

http://news.bbc.co.uk/1/hi/technology/2693925.stm
Old 25 January 2003, 10:25 PM
  #21  
super_si
Scooby Regular
 
super_si's Avatar
 
Join Date: Feb 2002
Location: Lurkin Somewhere
Posts: 7,951
Likes: 0
Received 0 Likes on 0 Posts
Post

Nestle feel foul to it aswell.

Old man told us.

Si
Old 25 January 2003, 10:29 PM
  #22  
Houlbt
Scooby Regular
 
Houlbt's Avatar
 
Join Date: Sep 2001
Posts: 748
Likes: 0
Received 0 Likes on 0 Posts
Post

And Barclaycard, Commerzbank, Citibank, EdF, London Electricity, Transco.....they're just a few! **** and they are only some of the 24/7 places that have weekend people to pick up on it.

Monday will be chaos in London.... no central line and all the computers hacked.

Old 25 January 2003, 10:32 PM
  #23  
Puff The Magic Wagon!
Moderator
Support Scoobynet!
iTrader: (2)
 
Puff The Magic Wagon!'s Avatar
 
Join Date: May 2000
Location: From far, far away...
Posts: 16,978
Received 15 Likes on 9 Posts
Post


This threat has a special Risk Assessment - it is "High" only for unpatched systems (only affects SQL servers not running SP3):
Phew

After the week I've just had & now being on holiday, I'm sure as hell glad I've got SP3 running - that & lots of other protection...

Phew...
Old 25 January 2003, 11:41 PM
  #24  
Houlbt
Scooby Regular
 
Houlbt's Avatar
 
Join Date: Sep 2001
Posts: 748
Likes: 0
Received 0 Likes on 0 Posts
Post

We were supposed to be patched though.... Que???? We spend fecking loads (I mean really lots) on IT, what a pi55 take!

Dunno...think there were some computers running SQL analytics type jobs (I'm no IT honcho in case you couldn't tell) and they got it in the data they were downloading (weather data i think???)

[Flame Suit Donned] I find it fascinating though... you know in the same way you can find those master criminal roberies...even though you cannot condone the action or the cost to innocent people etc etc

Night people.... H

[Edited by Houlbt - 1/25/2003 11:42:27 PM]
Old 26 January 2003, 12:33 AM
  #25  
dsmith
Scooby Regular
 
dsmith's Avatar
 
Join Date: Mar 1999
Posts: 4,518
Likes: 0
Received 0 Likes on 0 Posts
Post

.
Old 26 January 2003, 10:45 PM
  #26  
Soulgirl
Scooby Regular
 
Soulgirl's Avatar
 
Join Date: Dec 2002
Location: Here!
Posts: 5,145
Likes: 0
Received 0 Likes on 0 Posts
Post

Its ok guys... they caught the culprit!
CNN NEWS
Old 26 January 2003, 11:21 PM
  #27  
Miles
Scooby Regular
 
Miles's Avatar
 
Join Date: Oct 1998
Location: The Granite City/Dallas, Tx.
Posts: 2,519
Likes: 0
Received 0 Likes on 0 Posts
Post

The story from The Register.....
Old 26 January 2003, 11:45 PM
  #28  
Huxley
Scooby Regular
 
Huxley's Avatar
 
Join Date: Sep 1999
Location: In the garage or in bed
Posts: 7,278
Likes: 0
Received 0 Likes on 0 Posts
Post

Miles

[img]images/smilies/mad.gif[/img]That fookin site has the habbit filling your screen with **** knows how many popups[img]images/smilies/mad.gif[/img] I wish i could **** there servers up somehow as that sort of thing realy gets on my t1ts and it's almost as bad as junk mail through the post[img]images/smilies/mad.gif[/img]

Huxley
Old 27 January 2003, 10:26 AM
  #29  
stevem2k
Scooby Regular
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Post

We're over the moon ... internally the only thing it affected was the timesheet system

Steve
Old 27 January 2003, 11:11 AM
  #30  
Foot_Tapper
Scooby Regular
 
Foot_Tapper's Avatar
 
Join Date: Aug 2002
Posts: 1,977
Likes: 0
Received 0 Likes on 0 Posts
Post

LOL very good Soulgirl, the popups you have are very helpful as well.


Quick Reply: Big Trouble on the Net Today



All times are GMT +1. The time now is 09:22 PM.