Solution: Only systems that allow access to port 1434/udp can be infected by this worm.
Other Microsoft SQL ports:
ms-sql-s 1433/tcp #Microsoft-SQL-Server
ms-sql-s 1433/udp #Microsoft-SQL-Server
ms-sql-m 1434/tcp #Microsoft-SQL-Monitor
ms-sql-m 1434/udp #Microsoft-SQL-Monitor
The vulnerability was closed by Microsoft in July 2002: http://www.microsoft.com/technet/security/bulletin/ms02-039.asp
We recommend that you use MS02-061 instead as it is newer and closes other issues too: http://www.microsoft.com/technet/security/bulletin/MS02-061.asp
The updates are also included in Microsoft SQL Server 2000 Servicepack 3.
NOTE: that if you have applied hotfix Q317748, which is a bug fix from Microsoft, after the above patches, then your system will still be vulnerable, as this hotfix introduce an old version of ssnetlib.dll
The worm does not harm the system it affects and can be removed by rebooting the system as it only resides in memory.
Any system that has been infected by this worm should be considered compromised as it has been exposed to a known vulnerability for so long. We recommend that you reinstall.
Changelog: 26/01-2003 Added information about MSDE 2000 and other software using MSDE 2000.
27/01-2003 Added link to official Microsoft advisory regarding slammer
01/04-2004 Added CVE reference
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.