[Fwd: Update on "Slammer" Worm]

George Toft plug-discuss@lists.plug.phoenix.az.us
Sat, 01 Feb 2003 18:07:39 -0500


Derek Neighbors wrote:
[snip]
> previously been made available, and (b) there was no data corruption on
> customers' systems. The release of this worm is a criminal act, and we

So riddle me this: What if the next slammer (call it the Grand Slam),
were to spread using the same mechanism, and use the "feature" of no
password on the admin port to run a "drop table" command followed by a
"drop database" followed by a "commit"???  

Scary.

George