<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>SQL Slammer</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/SQL_Slammer"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-SQL_Slammer rootpage-SQL_Slammer skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">SQL Slammer</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<style data-mw-deduplicate="TemplateStyles:r1295905060">
/* start https://en.wikipedia.org/ */
.mw-parser-output .infobox-subbox{padding:0;border:none;margin:-3px;width:auto;min-width:100%;font-size:100%;clear:none;float:none;background-color:transparent}.mw-parser-output .infobox-3cols-child{margin:auto}.mw-parser-output .infobox .navbar{font-size:100%}@media screen{html.skin-theme-clientpref-night .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media(min-width:640px){body.skin--responsive .mw-parser-output .infobox-table{display:table!important}body.skin--responsive .mw-parser-output .infobox-table>caption{display:table-caption!important}body.skin--responsive .mw-parser-output .infobox-table>tbody{display:table-row-group}body.skin--responsive .mw-parser-output .infobox-table th,body.skin--responsive .mw-parser-output .infobox-table td{padding-left:inherit;padding-right:inherit}}
/* end https://en.wikipedia.org/ */
</style><table class="infobox"><tbody><tr><th colspan="2" class="infobox-above" style="background-color:#FFADAD;text-align:center;vertical-align:middle;font-size:110%;">SQL Slammer</th></tr><tr><th scope="row" class="infobox-label">Type</th><td class="infobox-data"><a href="Computer_worm" title="Computer worm">Computer worm</a></td></tr><tr><th scope="row" class="infobox-label">Origin</th><td class="infobox-data">2003</td></tr><tr><th colspan="2" class="infobox-header" style="background-color:#ffdcd7;">Technical details</th></tr><tr><th scope="row" class="infobox-label">Platform</th><td class="infobox-data"><a href="Microsoft_Windows" title="Microsoft Windows">Microsoft Windows</a></td></tr></tbody></table>
<p><b>SQL Slammer</b><sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>a<span class="cite-bracket">]</span></a></sup> is a 2003 <a href="Computer_worm" title="Computer worm">computer worm</a> that caused a <a href="Denial_of_service" class="mw-redirect" title="Denial of service">denial of service</a> on some <a href="Internet" title="Internet">Internet</a> hosts and dramatically slowed general <a href="Internet_traffic" title="Internet traffic">Internet traffic</a>. It also crashed routers around the world, causing even more slowdowns. It spread rapidly, infecting most of its 75,000 victims within 10 minutes.
</p><p>The program exploited a <a href="Buffer_overflow" title="Buffer overflow">buffer overflow</a> bug in Microsoft's <a href="Microsoft_SQL_Server" title="Microsoft SQL Server">SQL Server</a> and <a href="MSDE" title="MSDE">Desktop Engine</a> database products. Although the <a rel="nofollow" class="external text" href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-039">MS02-039</a> (CVE-2002-0649)<sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> patch had been released six months earlier, many organizations had not yet applied it.
</p><p>The most infected regions were Europe, North America, and Asia (including East Asia and India).<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup>
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Technical_details">Technical details</h2></div>
<p>The worm was based on proof of concept code demonstrated at the <a href="Black_Hat_Briefings" title="Black Hat Briefings">Black Hat Briefings</a> by <a href="David_Litchfield" title="David Litchfield">David Litchfield</a>, who had initially discovered the buffer overflow vulnerability that the worm exploited.<sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> It is a small piece of code that does little other than generate random IP addresses and send itself out to those addresses. If a selected address happens to belong to a host that is running an unpatched copy of <a href="Microsoft_SQL_Server" title="Microsoft SQL Server">Microsoft SQL Server</a> Resolution Service listening on UDP port 1434, the host immediately becomes infected and begins spraying the Internet with more copies of the worm program.
</p><p>Home <a href="Personal_Computer" class="mw-redirect" title="Personal Computer">PCs</a> are generally not vulnerable to this worm unless they have MSDE installed. The worm is so small that it does not contain code to write itself to disk, so it only stays in memory, and it is easy to remove. For example, Symantec provides a free of charge removal utility, or it can even be removed by restarting SQL Server (although the machine would likely be reinfected immediately).
</p><p>The worm was made possible by a <a href="Software_security_vulnerability" class="mw-redirect" title="Software security vulnerability">software security vulnerability</a> in SQL Server first reported by Microsoft on 24 July 2002. A patch had been available from Microsoft for six months prior to the worm's launch, but many installations had not been patched – including many at Microsoft.<sup id="cite_ref-6" class="reference"><a href="#cite_note-6"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>
</p><p>The worm began to be noticed early on 25 January 2003<sup id="cite_ref-11" class="reference"><a href="#cite_note-11"><span class="cite-bracket">[</span>b<span class="cite-bracket">]</span></a></sup> as it slowed systems worldwide. The slowdown was caused by the collapse of numerous <a href="Router_(computing)" title="Router (computing)">routers</a> under the burden of extremely high bombardment traffic from infected servers. Normally, when traffic is too high for routers to handle, the routers are supposed to delay or temporarily stop network traffic. Instead, some routers <i>crashed</i> (became unusable), and the "neighbour" routers would notice that these routers had stopped and should not be contacted (aka "removed from the <a href="Routing_table" title="Routing table">routing table</a>"). Routers started sending notices to this effect to other routers they knew about. The flood of routing table update notices caused some additional routers to fail, compounding the problem. Eventually the crashed routers' maintainers restarted them, causing them to announce their status, leading to another wave of routing table updates. Soon a significant portion of Internet bandwidth was consumed by routers communicating with each other to update their routing tables, and ordinary data traffic slowed or in some cases stopped altogether. Because the SQL Slammer worm was so small in size, sometimes it was able to get through when legitimate traffic was not.
</p><p>Two key aspects contributed to SQL Slammer's rapid propagation. The worm infected new hosts over the <a href="Session_(computer_science)" title="Session (computer science)">sessionless</a> <a href="User_Datagram_Protocol" title="User Datagram Protocol">UDP</a> protocol, and the entire worm (only 376 bytes) fits inside a single packet.<sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-13" class="reference"><a href="#cite_note-13"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup> As a result, each infected host could simply "fire and forget" packets as rapidly as possible.
</p>
<div class="mw-heading mw-heading2"><h2 id="Notes">Notes</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */
.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}
/* end https://en.wikipedia.org/ */
</style><div class="reflist reflist-lower-alpha">
<div class="mw-references-wrap"><ol class="references">
<li id="cite_note-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-2">^</a></b></span> <span class="reference-text">Other names include W32.SQLExp.Worm, DDOS.SQLP1434.A, the Sapphire Worm, SQL_HEL, W32/SQLSlammer and Helkern.<sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup></span>
</li>
<li id="cite_note-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-11">^</a></b></span> <span class="reference-text">Public disclosure began with Michael Bacarella posting a message to the <a href="Bugtraq" title="Bugtraq">Bugtraq</a> security mailing list entitled "MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434!"<sup id="cite_ref-7" class="reference"><a href="#cite_note-7"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> at 07:11:41 UTC on 25 January 2003. Similar reports were posted by Robert Boyle at 08:35 UTC<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> and Ben Koshy at 10:28 UTC<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup> An early analysis released by Symantec is timestamped 07:45 GMT.<sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup></span>
</li>
</ol></div></div>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<div class="reflist">
<div class="mw-references-wrap mw-references-columns"><ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-1">^</a></b></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */
.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}
/* end https://en.wikipedia.org/ */
</style><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20061110180054/http://www.symantec.com/security_response/writeup.jsp?docid=2003-012502-3306-99">"Symantec W32.SQLExp.Worm"</a>. Archived from <a rel="nofollow" class="external text" href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-012502-3306-99">the original</a> on 10 November 2006.</cite></span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-3">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0649">"CVE - CVE-2002-0649"</a>. <i>cve.mitre.org</i><span class="reference-accessdate">. Retrieved <span class="nowrap">7 September</span> 2023</span>.</cite></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text"><cite id="CITEREFMezquita2020" class="citation web cs1">Mezquita, Ty (12 February 2020). <a rel="nofollow" class="external text" href="https://cyberhoot.com/cybrary/sql-slammer-virus/">"SQL Slammer Virus (Harbinger of things to come)"</a>. <i>CyberHoot</i>.</cite></span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-5">^</a></b></span> <span class="reference-text"><cite id="CITEREFLeyden2003" class="citation news cs1">Leyden, John (6 February 2003). <a rel="nofollow" class="external text" href="https://www.theregister.co.uk/2003/02/06/slammer_why_security_benefits/">"Slammer: Why security benefits from proof of concept code"</a>. Register<span class="reference-accessdate">. Retrieved <span class="nowrap">29 November</span> 2008</span>.</cite></span>
</li>
<li id="cite_note-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-6">^</a></b></span> <span class="reference-text"><cite class="citation magazine cs1"><a rel="nofollow" class="external text" href="https://www.wired.com/2003/01/microsoft-attacked-by-worm-too/">"Microsoft Attacked By Worm, Too"</a>. <i>Wired</i>.</cite></span>
</li>
<li id="cite_note-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-7">^</a></b></span> <span class="reference-text"><cite id="CITEREFBacarella2003" class="citation web cs1">Bacarella, Michael (25 January 2003). <a rel="nofollow" class="external text" href="http://seclists.org/bugtraq/2003/Jan/221">"MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434!"</a>. Bugtraq<span class="reference-accessdate">. Retrieved <span class="nowrap">29 November</span> 2012</span>.</cite></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-8">^</a></b></span> <span class="reference-text"><cite id="CITEREFBoyle2003" class="citation web cs1">Boyle, Robert (25 January 2003). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20090219072838/http://archives.neohapsis.com/archives/ntbugtraq/2003-q1/0011.html">"Peace of Mind Through Integrity and Insight"</a>. Neohapsis Archives. Archived from <a rel="nofollow" class="external text" href="http://archives.neohapsis.com/archives/ntbugtraq/2003-q1/0011.html">the original</a> on 19 February 2009<span class="reference-accessdate">. Retrieved <span class="nowrap">29 November</span> 2008</span>.</cite></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-9">^</a></b></span> <span class="reference-text"><cite id="CITEREFKoshy2003" class="citation web cs1">Koshy, Ben (25 January 2003). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20090219072809/http://archives.neohapsis.com/archives/ntbugtraq/2003-q1/0010.html">"Peace of Mind Through Integrity and Insight"</a>. Neohapsis Archives. Archived from <a rel="nofollow" class="external text" href="http://archives.neohapsis.com/archives/ntbugtraq/2003-q1/0010.html">the original</a> on 19 February 2009<span class="reference-accessdate">. Retrieved <span class="nowrap">29 November</span> 2008</span>.</cite></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-10">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20030307233701/http://securityresponse.symantec.com/avcenter/Analysis-SQLExp.pdf">"SQLExp SQL Server Worm Analysis"</a> <span class="cs1-format">(PDF)</span>. DeepSight™ Threat Management System Threat Analysis. 28 January 2003. Archived from <a rel="nofollow" class="external text" href="http://securityresponse.symantec.com/avcenter/Analysis-SQLExp.pdf">the original</a> <span class="cs1-format">(PDF)</span> on 7 March 2003.</cite></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-12">^</a></b></span> <span class="reference-text"><cite id="CITEREFMoore,_David" class="citation web cs1">Moore, David; et al. <a rel="nofollow" class="external text" href="https://www.caida.org/catalog/papers/2003_sapphire/">"The Spread of the Sapphire/Slammer Worm"</a>. <i>CAIDA (Cooperative Association for Internet Data Analysis)</i>.</cite></span>
</li>
<li id="cite_note-13"><span class="mw-cite-backlink"><b><a href="#cite_ref-13">^</a></b></span> <span class="reference-text"><cite id="CITEREFSerazzi,_GiuseppeZanero,_Stefano2004" class="citation book cs1">Serazzi, Giuseppe; Zanero, Stefano (2004). <a rel="nofollow" class="external text" href="http://home.deib.polimi.it/zanero/papers/zanero-serazzi-virus.pdf">"Computer Virus Propagation Models"</a> <span class="cs1-format">(PDF)</span>. In Calzarossa, Maria Carla; Gelenbe, Erol (eds.). <i>Performance Tools and Applications to Networked Systems</i>. Lecture Notes in Computer Science. Vol. 2965. pp. <span class="nowrap">26–</span>50.</cite></span>
</li>
</ol></div></div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<dl><dt>News</dt></dl>
<ul><li><a rel="nofollow" class="external text" href="http://news.bbc.co.uk/2/hi/technology/2693925.stm">BBC NEWS Technology Virus-like attack hits web traffic</a></li>
<li><a rel="nofollow" class="external text" href="http://slashdot.org/article.pl?sid=03/01/25/1245206&mode=flat&tid=109">MS SQL Server Worm Wreaking Havoc</a></li>
<li><a rel="nofollow" class="external text" href="https://www.wired.com/wired/archive/11.07/slammer.html">Wired 11.07: Slammed!</a> A layman's explanation of the Slammer code.</li></ul>
<dl><dt>Announcement</dt></dl>
<ul><li><a rel="nofollow" class="external text" href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-039">Microsoft Security Bulletin MS02-039 and Patch</a></li>
<li><cite class="citation web cs1 cs1-prop-unfit"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20030201230443/http://www.cert.org/advisories/CA-2003-04.html">"CERT Advisory CA-2003-04: MS-SQL Server Worm"</a>. <i>Carnegie Mellon University Software Engineering Institute</i>. Archived from the original on 1 February 2003<span class="reference-accessdate">. Retrieved <span class="nowrap">22 September</span> 2019</span>.</cite></li>
<li><a rel="nofollow" class="external text" href="https://web.archive.org/web/20060105050228/http://securityresponse.symantec.com/avcenter/venc/data/w32.sqlexp.worm.html">Symantec Security Response - W32.SQLExp.Worm</a></li></ul>
<dl><dt>Analysis</dt></dl>
<ul><li><a rel="nofollow" class="external text" href="http://www.cs.ucsd.edu/~savage/papers/IEEESP03.pdf">Inside the Slammer Worm</a> IEEE Security and Privacy Magazine, David Moore, Vern Paxson, Stefan Savage, Colleen Shannon, Stuart Staniford, and Nicholas Weaver</li></ul>
<dl><dt>Technical details</dt></dl>
<ul><li><a rel="nofollow" class="external text" href="https://web.archive.org/web/20110722191923/http://www.eeye.com/html/Research/Flash/sapphire.txt">Worm code disassembled</a> at the <a href="Wayback_Machine" title="Wayback Machine">Wayback Machine</a> (archived 22 July 2011)</li>
<li><a rel="nofollow" class="external text" href="http://www.cert.org/advisories/CA-2002-22.html">Multiple Vulnerabilities in Microsoft SQL Server</a> - Carnegie-Mellon Software Engineering Institute</li></ul>
<p class="mw-empty-elt">
</p>
<div class="navbox-styles"><style data-mw-deduplicate="TemplateStyles:r1129693374">
/* start https://en.wikipedia.org/ */
.mw-parser-output .hlist dl,.mw-parser-output .hlist ol,.mw-parser-output .hlist ul{margin:0;padding:0}.mw-parser-output .hlist dd,.mw-parser-output .hlist dt,.mw-parser-output .hlist li{margin:0;display:inline}.mw-parser-output .hlist.inline,.mw-parser-output .hlist.inline dl,.mw-parser-output .hlist.inline ol,.mw-parser-output .hlist.inline ul,.mw-parser-output .hlist dl dl,.mw-parser-output .hlist dl ol,.mw-parser-output .hlist dl ul,.mw-parser-output .hlist ol dl,.mw-parser-output .hlist ol ol,.mw-parser-output .hlist ol ul,.mw-parser-output .hlist ul dl,.mw-parser-output .hlist ul ol,.mw-parser-output .hlist ul ul{display:inline}.mw-parser-output .hlist .mw-empty-li{display:none}.mw-parser-output .hlist dt::after{content:": "}.mw-parser-output .hlist dd::after,.mw-parser-output .hlist li::after{content:" · ";font-weight:bold}.mw-parser-output .hlist dd:last-child::after,.mw-parser-output .hlist dt:last-child::after,.mw-parser-output .hlist li:last-child::after{content:none}.mw-parser-output .hlist dd dd:first-child::before,.mw-parser-output .hlist dd dt:first-child::before,.mw-parser-output .hlist dd li:first-child::before,.mw-parser-output .hlist dt dd:first-child::before,.mw-parser-output .hlist dt dt:first-child::before,.mw-parser-output .hlist dt li:first-child::before,.mw-parser-output .hlist li dd:first-child::before,.mw-parser-output .hlist li dt:first-child::before,.mw-parser-output .hlist li li:first-child::before{content:" (";font-weight:normal}.mw-parser-output .hlist dd dd:last-child::after,.mw-parser-output .hlist dd dt:last-child::after,.mw-parser-output .hlist dd li:last-child::after,.mw-parser-output .hlist dt dd:last-child::after,.mw-parser-output .hlist dt dt:last-child::after,.mw-parser-output .hlist dt li:last-child::after,.mw-parser-output .hlist li dd:last-child::after,.mw-parser-output .hlist li dt:last-child::after,.mw-parser-output .hlist li li:last-child::after{content:")";font-weight:normal}.mw-parser-output .hlist ol{counter-reset:listitem}.mw-parser-output .hlist ol>li{counter-increment:listitem}.mw-parser-output .hlist ol>li::before{content:" "counter(listitem)"\a0 "}.mw-parser-output .hlist dd ol>li:first-child::before,.mw-parser-output .hlist dt ol>li:first-child::before,.mw-parser-output .hlist li ol>li:first-child::before{content:" ("counter(listitem)"\a0 "}
/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1236075235">
/* start https://en.wikipedia.org/ */
.mw-parser-output .navbox{box-sizing:border-box;border:1px solid #a2a9b1;width:100%;clear:both;font-size:88%;text-align:center;padding:1px;margin:1em auto 0}.mw-parser-output .navbox .navbox{margin-top:0}.mw-parser-output .navbox+.navbox,.mw-parser-output .navbox+.navbox-styles+.navbox{margin-top:-1px}.mw-parser-output .navbox-inner,.mw-parser-output .navbox-subgroup{width:100%}.mw-parser-output .navbox-group,.mw-parser-output .navbox-title,.mw-parser-output .navbox-abovebelow{padding:0.25em 1em;line-height:1.5em;text-align:center}.mw-parser-output .navbox-group{white-space:nowrap;text-align:right}.mw-parser-output .navbox,.mw-parser-output .navbox-subgroup{background-color:#fdfdfd}.mw-parser-output .navbox-list{line-height:1.5em;border-color:#fdfdfd}.mw-parser-output .navbox-list-with-group{text-align:left;border-left-width:2px;border-left-style:solid}.mw-parser-output tr+tr>.navbox-abovebelow,.mw-parser-output tr+tr>.navbox-group,.mw-parser-output tr+tr>.navbox-image,.mw-parser-output tr+tr>.navbox-list{border-top:2px solid #fdfdfd}.mw-parser-output .navbox-title{background-color:#ccf}.mw-parser-output .navbox-abovebelow,.mw-parser-output .navbox-group,.mw-parser-output .navbox-subgroup .navbox-title{background-color:#ddf}.mw-parser-output .navbox-subgroup .navbox-group,.mw-parser-output .navbox-subgroup .navbox-abovebelow{background-color:#e6e6ff}.mw-parser-output .navbox-even{background-color:#f7f7f7}.mw-parser-output .navbox-odd{background-color:transparent}.mw-parser-output .navbox .hlist td dl,.mw-parser-output .navbox .hlist td ol,.mw-parser-output .navbox .hlist td ul,.mw-parser-output .navbox td.hlist dl,.mw-parser-output .navbox td.hlist ol,.mw-parser-output .navbox td.hlist ul{padding:0.125em 0}.mw-parser-output .navbox .navbar{display:block;font-size:100%}.mw-parser-output .navbox-title .navbar{float:left;text-align:left;margin-right:0.5em}body.skin--responsive .mw-parser-output .navbox-image img{max-width:none!important}@media print{body.ns-0 .mw-parser-output .navbox{display:none!important}}
/* end https://en.wikipedia.org/ */
</style></div><div role="navigation" class="navbox" aria-labelledby="Hacking_in_the_2000s685" style="padding:3px"><table class="nowraplinks hlist mw-collapsible autocollapse navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="2"><style data-mw-deduplicate="TemplateStyles:r1239400231">
/* start https://en.wikipedia.org/ */
.mw-parser-output .navbar{display:inline;font-size:88%;font-weight:normal}.mw-parser-output .navbar-collapse{float:left;text-align:left}.mw-parser-output .navbar-boxtext{word-spacing:0}.mw-parser-output .navbar ul{display:inline-block;white-space:nowrap;line-height:inherit}.mw-parser-output .navbar-brackets::before{margin-right:-0.125em;content:"[ "}.mw-parser-output .navbar-brackets::after{margin-left:-0.125em;content:" ]"}.mw-parser-output .navbar li{word-spacing:-0.125em}.mw-parser-output .navbar a>span,.mw-parser-output .navbar a>abbr{text-decoration:inherit}.mw-parser-output .navbar-mini abbr{font-variant:small-caps;border-bottom:none;text-decoration:none;cursor:inherit}.mw-parser-output .navbar-ct-full{font-size:114%;margin:0 7em}.mw-parser-output .navbar-ct-mini{font-size:114%;margin:0 4em}html.skin-theme-clientpref-night .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}@media(prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}}@media print{.mw-parser-output .navbar{display:none!important}}
/* end https://en.wikipedia.org/ */
</style><div id="Hacking_in_the_2000s685" style="font-size:114%;margin:0 4em">Hacking in the 2000s</div></th></tr><tr><td class="navbox-abovebelow" colspan="2"><div><table style="width:100%; margin:1px; display:inline-table;"><tbody><tr>
<td style="text-align:center; vertical-align:middle; padding:0 1px;" class=""><a href="Timeline_of_computer_security_hacker_history" class="mw-redirect" title="Timeline of computer security hacker history">Timeline</a></td>
</tr></tbody></table></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Incidents</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"></div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th scope="row" class="navbox-group" style="width:1%">2004</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Titan_Rain" title="Titan Rain">Titan Rain</a> (2003–2006)</li>
<li><a href="Operation_Firewall" class="mw-redirect" title="Operation Firewall">Operation Firewall</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2005</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Sony_BMG_copy_protection_rootkit_scandal" title="Sony BMG copy protection rootkit scandal">Sony BMG copy protection rootkit scandal</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2007</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="2007_cyberattacks_on_Estonia" title="2007 cyberattacks on Estonia">Cyberattacks on Estonia</a></li>
<li><a href="Operation%3A_Bot_Roast" title="Operation: Bot Roast">Operation: Bot Roast</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2008</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Project_Chanology" title="Project Chanology">Project Chanology</a></li>
<li><a href="Cyberattacks_during_the_Russo-Georgian_War" title="Cyberattacks during the Russo-Georgian War">Cyberattacks on Georgia</a></li>
<li><a href="Sarah_Palin_email_hack" title="Sarah Palin email hack">Sarah Palin email hack</a></li>
<li><a href="2008_cyberattack_on_United_States" class="mw-redirect" title="2008 cyberattack on United States">US military cyberattack</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2009</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="July_2009_cyberattacks" class="mw-redirect" title="July 2009 cyberattacks">Operation Troy</a></li>
<li><a href="Operation_Aurora" title="Operation Aurora">Operation Aurora</a> (findings published in 2010)</li>
<li><a href="WebcamGate" class="mw-redirect" title="WebcamGate">WebcamGate</a> (2008–2010)</li></ul>
</div></td></tr></tbody></table><div></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Hacker_group" title="Hacker group">Groups</a></th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Anonymous_(group)" class="mw-redirect" title="Anonymous (group)">Anonymous</a>
<ul><li><a href="Timeline_of_events_associated_with_Anonymous" title="Timeline of events associated with Anonymous">associated events</a></li></ul></li>
<li><a href="Avalanche_(phishing_group)" title="Avalanche (phishing group)">Avalanche</a></li>
<li><a href="Gay_Nigger_Association_of_America" title="Gay Nigger Association of America">GNAA</a>
<ul><li><a href="Goatse_Security" title="Goatse Security">Goatse Security</a></li></ul></li>
<li>0x1fe</li>
<li><a href="GhostNet" title="GhostNet">GhostNet</a></li>
<li><a href="Level_Seven_(hacker_group)" title="Level Seven (hacker group)">Level Seven</a></li>
<li>Lordz of Kaos</li>
<li><a href="PLA_Unit_61398" title="PLA Unit 61398">PLA Unit 61398</a></li>
<li><a href="Russian_Business_Network" title="Russian Business Network">RBN</a></li>
<li><a href="ShadowCrew" title="ShadowCrew">ShadowCrew</a></li>
<li><a href="World_of_Hell" title="World of Hell">World of Hell</a></li>
<li><a href="Sandworm_(hacker_group)" title="Sandworm (hacker group)"> Sandworm</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Hacker" title="Hacker">Individuals</a></th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Owen_Walker" title="Owen Walker">AKill</a></li>
<li><a href="Jeanson_James_Ancheta" title="Jeanson James Ancheta">Jeanson James Ancheta</a></li>
<li>SilenZ</li>
<li>Dshocker</li>
<li>Digerati</li>
<li>str0ke (milw0rm)</li>
<li><a href="Matthew_Weigman" title="Matthew Weigman">Lil Hacker</a></li>
<li><a href="Vladislav_Horohorin" title="Vladislav Horohorin">BadB</a></li>
<li><a href="Cameron_Lacroix" class="mw-redirect" title="Cameron Lacroix">camZero</a></li>
<li><a href="Dennis_Moran_(computer_criminal)" title="Dennis Moran (computer criminal)">Coolio</a></li>
<li><a href="Cyxymu" title="Cyxymu">Cyxymu</a></li>
<li><a href="Farid_Essebar" class="mw-redirect" title="Farid Essebar">diabl0</a></li>
<li><a href="Albert_Gonzalez" title="Albert Gonzalez">Albert Gonzalez</a></li>
<li><a href="Sam_Hocevar" title="Sam Hocevar">Sam Hocevar</a></li>
<li><a href="Sven_Jaschan" title="Sven Jaschan">Sven Jaschan</a></li>
<li><a href="Dan_Kaminsky" title="Dan Kaminsky">Dan Kaminsky</a></li>
<li><a href="Samy_Kamkar" title="Samy Kamkar">Samy Kamkar</a></li>
<li><a href="Dmitry_Sklyarov" class="mw-redirect" title="Dmitry Sklyarov">Dmitry Sklyarov</a></li>
<li><a href="Stakkato" title="Stakkato">Stakkato</a></li>
<li><a href="Weev" title="Weev">weev</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Darknets</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li>Bluehell IRC</li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Hacking forums</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li>ryan1918</li>
<li>unkn0wn.eu</li>
<li>darksun.ws</li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Vulnerability_(computing)" class="mw-redirect" title="Vulnerability (computing)">Vulnerabilities</a><br>discovered</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Shatter_attack" title="Shatter attack">Shatter attack</a> (2002)</li>
<li><a href="Dan_Kaminsky#Flaw_in_DNS" title="Dan Kaminsky">Kaminsky DNS cache poisoning</a> (2008)</li>
<li><a href="Moxie_Marlinspike#SSL_stripping" title="Moxie Marlinspike">sslstrip</a> (2009)</li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Malware" title="Malware">Malware</a></th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"></div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th scope="row" class="navbox-group" style="width:1%">2000</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="ILOVEYOU" title="ILOVEYOU">ILOVEYOU</a></li>
<li><a href="Pikachu_virus" title="Pikachu virus">Pikachu</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2001</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Anna_Kournikova_(computer_virus)" title="Anna Kournikova (computer virus)">Anna Kournikova</a></li>
<li><a href="Code_Red_(computer_worm)" title="Code Red (computer worm)">Code Red</a></li>
<li><a href="Nimda" title="Nimda">Nimda</a></li>
<li><a href="Klez" title="Klez">Klez</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2002</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Simile_(computer_virus)" title="Simile (computer virus)">Simile</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2003</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul>
<li><a href="Welchia" title="Welchia">Welchia</a></li>
<li><a href="Sobig" title="Sobig">Sobig</a></li>
<li><a href="Gruel_(computer_worm)" title="Gruel (computer worm)">Gruel</a></li>
<li><a href="Graybird" title="Graybird">Graybird</a></li>
<li><a href="Blaster_(computer_worm)" title="Blaster (computer worm)">Blaster</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2004</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Bagle_(computer_worm)" title="Bagle (computer worm)">Bagle</a></li>
<li><a href="Netsky_(computer_worm)" title="Netsky (computer worm)">NetSky</a></li>
<li><a href="Sasser_(computer_worm)" title="Sasser (computer worm)">Sasser</a></li>
<li><a href="Mydoom" title="Mydoom">Mydoom</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2005</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="PGPCoder" title="PGPCoder">PGPCoder</a></li>
<li><a href="Samy_(computer_worm)" title="Samy (computer worm)">Samy</a></li>
<li><a href="Sony_BMG_copy_protection_rootkit_scandal" title="Sony BMG copy protection rootkit scandal">Sony rootkit</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2006</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Rustock_botnet" title="Rustock botnet">Rustock</a></li>
<li><a href="Zlob_trojan" title="Zlob trojan">ZLOB</a></li>
<li><a href="Clickbot.A" title="Clickbot.A">Clickbot</a></li>
<li><a href="Stration" title="Stration">Stration</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2007</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Storm_botnet" title="Storm botnet">Storm</a></li>
<li><a href="Zeus_(malware)" title="Zeus (malware)">ZeuS</a></li>
<li><a href="BlackEnergy#BlackEnergy_1_(BE1)" title="BlackEnergy"> Black Energy 1</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2008</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Asprox_botnet" title="Asprox botnet">Asprox</a></li>
<li><a href="Agent.BTZ" title="Agent.BTZ">Agent.BTZ</a></li>
<li><a href="Mariposa_botnet" title="Mariposa botnet">Mariposa</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2009</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Conficker" title="Conficker">Conficker</a></li>
<li><a href="Koobface" title="Koobface">Koobface</a></li>
<li><a href="Waledac_botnet" title="Waledac botnet">Waledac</a></li></ul>
</div></td></tr></tbody></table><div></div></td></tr></tbody></table></div></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2024-10-19" href="https://en.wikipedia.org/wiki/?title=SQL_Slammer&oldid=1252078763">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
</body></html>