SQL Slammer, also known as Sapphire and SQL-Hell, was a fast-spreading internet worm that emerged in January 2003 and targeted vulnerable Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 systems. It exploited a buffer overrun in the SQL Server Resolution Service on UDP port 1434, a flaw for which Microsoft had released a patch months earlier. The worm was notable for its extremely small size and exceptional propagation speed, infecting the vast majority of reachable vulnerable hosts within minutes.
SQL Slammer did not carry a destructive or data-theft payload. Its impact came from aggressive self-propagation: infected systems continuously generated large volumes of random scanning traffic to find and compromise additional vulnerable servers. This scanning behavior saturated networks, degraded routing and connectivity, and caused widespread denial-of-service conditions across parts of the global internet. The outbreak became a canonical example of how a single remotely exploitable vulnerability in widely deployed software could produce outsized systemic disruption.
The worm primarily affected Windows-based deployments of Microsoft SQL Server and MSDE. It has also been repeatedly cited in industrial control system security discussions as an illustration of how commodity internet worms can disrupt operational environments when control networks are exposed, weakly segmented, or dependent on vulnerable enterprise-connected systems. SQL Slammer remains one of the most significant historical examples of high-speed autonomous malware propagation and vulnerability-driven internet-scale disruption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
By sending a carefully crafted packet to the Resolution Service, an attacker could cause portions of system memory (the heap in one case, the stack in the other) to be overwritten. Overwriting it with carefully selected data could allow the attacker to run code in the security context of the SQL Server service.
A second kind of covert channel, aimed at subverting firewall–based filtering, uses standard ports for passing non-standard traffic. Firewalls that enforce a “block-all-but-necessary” approach to regulating traffic are the typical targets of standard port abuse. A recent (25 Jan 2003) case of standard port abuse involved a Denial of Service (DOS) attack that was variously known as the ‘SQL Slammer’ worm, ‘Sapphire’ and “SQL-Hell’.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Internet worm that rapidly spread by scanning vulnerable systems at massive scale, causing widespread network disruption rather than delivering a traditional malicious payload.
A fast-spreading Internet worm cited as an example of flash-worm-style propagation, infecting 90% of its hosts in less than 10 minutes.
A notorious internet worm mentioned as part of the sequence of disruptive malware incidents that forced changes in defensive strategy.
Malware 2003 SQL Slammer
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.