at Thursday, January 30, 2003 12:01 AM, [EMAIL PROTECTED] <[EMAIL PROTECTED]> was seen to say: >> But this worm required external access to an internal server (SQL >> Servers are not front-end ones); even with a bad or no patch >> management system, this simply wouldn't happen on a properly >> configured network. Whoever got slammered, has more problems than >> just this worm. Even with no firewall or screening router, use of >> RFC1918 private IP address on the SQL Server would have prevented >> this worm attack > > RFC1918 addresses would not have prevented this worm attack. > RFC1918 != security Indeed. More accurately though "don't have an SQL server port exposed to the general internet you bloody fools" might be closer to the correct advice to customers :) I have been trying *hard* but can't think of a single decent reason a random visitor to a site needs SQL Server access from the outside.
- Re: What could have been done differently? Alex Bligh
- Re: What could have been done differently? Andy Putnins
- Re: What could have been done differently? Alex Bligh
- Re: What could have been done differently? Mike Lewinski
- Re: What could have been done differently? E.B. Dreger
- Re: What could have been done differently? E.B. Dreger
- Re: What could have been done differently? Eliot Lear
- Re: What could have been done differently? Rubens Kuhl Jr.
- Re: What could have been done differently? Ted Fischer
- Re: What could have been done differently? bdragon
- Re: What could have been done differently? David Howe
- Re: What could have been done differently? Scott Francis
- Re: What could have been done differently? Leo Bicknell
- RE: What could have been done differently? Eric Germann
- Re: What could have been done differently? Jack Bates
- RE: What could have been done differently? Eric Germann
- Re: What could have been done differen... Scott Francis
- Re: What could have been done differen... Valdis . Kletnieks
- Re: What could have been done differently? Leo Bicknell
- Re: What could have been done differently? Scott Francis
- WANAL (Re: What could have been done different... Paul Vixie
