Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


March 11, 2003

Behind the Scenes of the SQL Slammer Worm Virus: Readers Respond

RSS
Subscribe to Windows IT Pro | See More SQL Server and Database Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

In my last commentary ( http://www.windowswebsolutions.com/articles/index.cfm?articleid=38138 ), I covered Slammer or Sapphire, a worm that targets systems running either Microsoft SQL Server 2000 or Microsoft SQL Server Desktop Engine (MSDE). Slammer crippled the Web for a long time and affected all Internet users in some way. I also focused on what happened behind the scenes at Microsoft after the worm appeared and the black eye that Slammer gave to the already battered Microsoft security effort. I boldly predicted that as a result of Slammer, every Microsoft product will become a part of Windows Update within the next 6 months. Time will tell how that prediction shakes out, but since my commentary, I've talked to numerous Microsoft employees who have validated my prediction as a good idea--and one that Microsoft is discussing.

I asked you to email me your comments, and I received many interesting and intelligent responses. I stated that many administrators don't install patches and, because of that, IIS 6.0 in Windows Server 2003 is shipping completely locked down with automatic patching enabled. The patch that eliminated the security vulnerability that Slammer exploited was available 6 months before the worm appeared.

I also stated some reasons why administrators don't patch, but I was remiss because I failed to identify one major reason why they don't: the lack of resources to be able to effectively set up a patch-testing environment. Many administrators are afraid of the side effects they often suffer after blindly installing patches without first testing the patches in the proper environment. But testing requires much time and effort--too much, for many overworked administrators. Some administrators have also had a service pack or a patch break something and wreak havoc on their servers and applications. Another factor that causes some administrators not to patch as often as they should is the economy: Downsized support staffs mean that many tasks aren't handled, leaving networks vulnerable to attacks.

Windows Web Solutions UPDATE reader Tariq Hamirani pointed out that another reason administrators don't patch is for fear of Microsoft taking on the role of Big Brother. Hamirani told me about administors' fear of automatic updates sending information to vendors about the machines being updated and their configuration. Hamirani said, "Microsoft may collect information on installed software that might simply have a common key or is flat-out illegal." I don't believe in this particular fear--Microsoft is forthright about what information it collects and when it's collected. Further, I think that companies that run unlicensed software don't have any right to complain about that software.

Anthony Paulina, a network systems architect for CherryRoad Technologies, said, "If your prediction turns out to be true that 6 months from now, all Microsoft products can be updated via Windows Update, my humble opinion is this: It is about bloody time! Currently, Microsoft is underutilizing a really good method of providing fixes for their software. If they provided checks for the other product lines that would be great. Ideally I'd like to see it as a one-stop Web site, unlike today, where you have to go to Office Update for Office and Windows Update for Windows." Richard Rosenheim, CEO of Intelligence Research Systems, agrees: "The idea of having Windows Update handle all the Microsoft updates and patches sounds good to me. In the same vein, I would also like to see SUS [Software Update Services] handle everything (not just critical updates)."

Of course, the Windows Update route might not be as easy as it sounds. Andrew Brust, president and founder of Progressive Systems Consulting, wrote, "One issue with Windows Update is that using it from servers may be tough. Microsoft may need to create a remote console that allows monitoring of pending updates on a collection of servers and applying them via some RPC [remote procedure call]. Otherwise, you have to Terminal Service into each box, log in as an administrator, and click Update. This will just result in more patches not getting applied."

Clearly, Microsoft intends to fix the process problem. Mike Nash, who is vice president of the security business unit at Microsoft and has responsibility for the security component of Trustworthy Computing, said, "The key lesson of Slammer--maybe it's a re-lesson of Slammer--is our work is not done when the patch is available. Our work is done when the patch is installed on the majority of customers' systems." We can glean from his statement that Microsoft acknowledges it's just not there yet. One can only hope it gets there soon.

End of Article



Reader Comments
There appears to be a dilemma for systems administrators here. They are behind on their patching because of shortage of time and equipment for adequate testing. Your solution to this problem is to promote a method for semi-automatically applying patches without any testing at all. Hmmm...

Jim Eckford March 12, 2003


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...

Escape From Yesterworld

Kevin points you to the funniest SQL Server website ever! ...

PsExec

This freeware utility lets you execute processes on a remote system and redirect output to the local system. ...


SQL Server and Database Whitepapers StoreVault SnapManagers for Microsoft Exchange and SQL Server

Related Events Microsoft BI Unleashed | Online Conference

Storage Consolidation for Your Microsoft Applications: Reducing Cost and Complexity

Check out our list of Free Email Newsletters!

SQL Server and Database eBooks Safeguarding Your Windows Servers

SQL Server Administration for Oracle DBAs

Taking Control: Monitoring the Windows Platform Proactively

Related SQL Server and Database Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing