SQL Slammer, also known as Sapphire, was a rapidly propagating network worm that emerged in January 2003. It exploited a buffer-overrun vulnerability in the Microsoft SQL Server 2000 Resolution Service, affecting SQL Server 2000 and Microsoft Desktop Engine 2000 systems that exposed UDP port 1434. The worm used randomized scanning to find and infect further vulnerable hosts, doubling its infected population approximately every 8.5 seconds and reaching most vulnerable systems within roughly 10 minutes. SQL Slammer did not deploy a destructive payload; its exceptionally high-volume scanning saturated networks and caused widespread denial-of-service conditions and major Internet disruption. It targeted Microsoft SQL Server deployments on Windows systems. A patch addressing the exploited vulnerability had been available before the outbreak.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
By sending a carefully crafted packet to the Resolution Service, an attacker could cause portions of system memory (the heap in one case, the stack in the other) to be overwritten. Overwriting it with carefully selected data could allow the attacker to run code in the security context of the SQL Server service.
A second kind of covert channel, aimed at subverting firewall–based filtering, uses standard ports for passing non-standard traffic. Firewalls that enforce a “block-all-but-necessary” approach to regulating traffic are the typical targets of standard port abuse. A recent (25 Jan 2003) case of standard port abuse involved a Denial of Service (DOS) attack that was variously known as the ‘SQL Slammer’ worm, ‘Sapphire’ and “SQL-Hell’.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rapidly propagating worm cited as having doubled infected hosts every 8.5 seconds and infected nearly every vulnerable system in under 10 minutes.
Internet worm that rapidly spread by scanning vulnerable systems at massive scale, causing widespread network disruption rather than delivering a traditional malicious payload.
A fast-spreading Internet worm cited as an example of flash-worm-style propagation, infecting 90% of its hosts in less than 10 minutes.
A notorious internet worm mentioned as part of the sequence of disruptive malware incidents that forced changes in defensive strategy.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.