Micron Document
<!DOCTYPE html>
<html class="client-nojs vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-0 vector-toc-not-available vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-0 vector-feature-night-mode-enabled skin-theme-clientpref-os vector-sticky-header-enabled" lang="fr" dir="ltr"><head>
<meta charset="UTF-8">
<title>SQL Slammer</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="icon" type="image/png" href="./_res_/favicon.png">
<link rel="canonical" href="https://fr.wikipedia.org/wiki/SQL_Slammer"> <link href="./_mw_/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.wikimediamessages.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./_mw_/site.styles.css">
<link rel="stylesheet" type="text/css" href="./_mw_/noscript.css">
<link rel="stylesheet" type="text/css" href="./_res_/footer.css">
<link rel="stylesheet" type="text/css" href="./_res_/vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-SQL_Slammer rootpage-SQL_Slammer skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading"><span class="mw-page-title-main">SQL Slammer</span></h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="contentSub">
<div id="mw-content-subtitle"></div>
</div>
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="fr" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="fr" dir="ltr">
<p><b>SQL Slammer</b> (aussi connu sous le nom de <b>Sapphire</b>) est un <a href="Ver_informatique" title="Ver informatique">ver informatique</a> qui a provoqué le <time class="nowrap" datetime="2003-01-25" data-sort-value="2003-01-25">25 janvier 2003</time> un <a href="Attaque_par_d%C3%A9ni_de_service" title="Attaque par déni de service">déni de service</a> sur certains <a href="Ordinateur_h%C3%B4te" class="mw-redirect" title="Ordinateur hôte">ordinateurs hôtes</a> d'<a href="Internet" title="Internet">Internet</a> et un ralentissement grave du <a href="Trafic_Internet" title="Trafic Internet">trafic Internet</a>. Sa propagation fut foudroyante. Michael Bacarella fut le premier à en faire l'annonce, mais c'est Christopher J. Rouland, CTO de ISS, qui le nomma Slammer (voir les <a href="#Notes">notes</a> ci-dessous). Bien qu'il fût appelé «&nbsp;SQL slammer worm&nbsp;», le programme n'utilisait pas le langage <a href="Structured_Query_Language" title="Structured Query Language">SQL</a>&nbsp;; il se propageait plutôt grâce à une <a href="Vuln%C3%A9rabilit%C3%A9_(informatique)" title="Vulnérabilité (informatique)">faille</a> du type <a href="D%C3%A9passement_de_tampon" title="Dépassement de tampon">dépassement de tampon</a> des <a href="Serveur_informatique" title="Serveur informatique">serveurs</a> de bases de données <a href="Microsoft_SQL_Server" title="Microsoft SQL Server">Microsoft SQL Server</a> et <a href="Microsoft_SQL_Server_Desktop_Engine" title="Microsoft SQL Server Desktop Engine">MSDE</a>, pour laquelle un <a href="Patch_(informatique)" title="Patch (informatique)">correctif</a> existait déjà.
</p>

<div class="mw-heading mw-heading2"><h2 id="Historique">Historique</h2></div>
<p>Le <time class="nowrap" datetime="2003-01-25" data-sort-value="2003-01-25">25 janvier 2003</time> à partir de 05 h 30 <a href="Temps_universel_coordonn%C3%A9" title="Temps universel coordonné">UTC</a>, le ver informatique SQL Slammer a entamé sa propagation<sup id="cite_ref-zdnet_1-0" class="reference"><a href="#cite_note-zdnet-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup><sup class="reference cite_virgule">,</sup><sup id="cite_ref-CAIDA_1_2-0" class="reference"><a href="#cite_note-CAIDA_1-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>. Il se répandit si rapidement qu'il infecta la plupart de ses victimes durant les dix premières minutes de l'attaque<sup id="cite_ref-CAIDA_1_2-1" class="reference"><a href="#cite_note-CAIDA_1-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>.
</p><p>C'est une <a href="Vuln%C3%A9rabilit%C3%A9_(informatique)" title="Vulnérabilité (informatique)">vulnérabilité</a> de <a href="Microsoft_SQL_Server" title="Microsoft SQL Server">Microsoft SQL Server</a> rapportée par <a href="Microsoft" title="Microsoft">Microsoft</a> le <time class="nowrap" datetime="2002-07-24" data-sort-value="2002-07-24">24 juillet 2002</time><sup id="cite_ref-Symantec_4_3-0" class="reference"><a href="#cite_note-Symantec_4-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup><sup class="reference cite_virgule">,</sup><sup id="cite_ref-viruslist_4-0" class="reference"><a href="#cite_note-viruslist-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> qui a permis la mise en œuvre du ver. En même temps que cette annonce, Microsoft avait aussi publié un <a href="Patch_(informatique)" title="Patch (informatique)">correctif</a> à cette <a href="Vuln%C3%A9rabilit%C3%A9_(informatique)" title="Vulnérabilité (informatique)">faille</a>, soit six mois avant le lancement de l'attaque<sup id="cite_ref-CERT_5-0" class="reference"><a href="#cite_note-CERT-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>.
</p><p>SQL Slammer a révélé que certains administrateurs de réseaux, y compris chez Microsoft, n'avaient pas appliqué les <a href="Patch_(informatique)" title="Patch (informatique)">correctifs</a> nécessaires aux logiciels qu'ils utilisent<sup id="cite_ref-cnn_1_6-0" class="reference"><a href="#cite_note-cnn_1-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup><sup class="reference cite_virgule">,</sup><sup id="cite_ref-cnet_1_7-0" class="reference"><a href="#cite_note-cnet_1-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>, et ce même si le <a href="Patch_(informatique)" title="Patch (informatique)">correctif</a> à cette faille avait été publié 6 mois, jour pour jour, avant la diffusion du ver. Il est également possible de corriger cette faille en installant le <a href="Service_pack" title="Service pack">Service Pack</a> 3 pour SQL Server<sup id="cite_ref-secuser_8-0" class="reference"><a href="#cite_note-secuser-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup>.
</p><p>Le ver est aussi connu sous les noms&nbsp;: W32.SQLExp.Worm, DDOS.SQLP1434.A, SQL_HEL, W32/SQLSlammer et Helkern<sup id="cite_ref-viruslist_4-1" class="reference"><a href="#cite_note-viruslist-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup><sup class="reference cite_virgule">,</sup><sup id="cite_ref-Symantec_1_9-0" class="reference"><a href="#cite_note-Symantec_1-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup>.
</p>
<div class="mw-heading mw-heading2"><h2 id="Détails_techniques"><span id="D.C3.A9tails_techniques"></span>Détails techniques</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Fonctionnement">Fonctionnement</h3></div>
<p>La conception du ver repose sur une démonstration de faisabilité, exposée à une <a href="Conf%C3%A9rences_Black_Hat" title="Conférences Black Hat">Conférence Black Hat</a> par David Litchfield&nbsp;<a href="https://en.wikipedia.org/wiki/David_Litchfield" class="extiw external" title="en:David Litchfield"><span class="indicateur-langue" title="Article en anglais&nbsp;: «&nbsp;David Litchfield&nbsp;»">(en)</span></a>, exploitant une <a href="Vuln%C3%A9rabilit%C3%A9_(informatique)" title="Vulnérabilité (informatique)">vulnérabilité</a> de type <a href="D%C3%A9passement_de_tampon" title="Dépassement de tampon">dépassement de tampon</a> qu'il avait auparavant découvert<sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup>. Ce ver est un petit code qui ne fait rien d'autre que générer des <a href="Adresse_IP" title="Adresse IP">adresses IP</a> de façon aléatoire et envoyer des copies de lui-même à ces adresses<sup id="cite_ref-viruslist_4-2" class="reference"><a href="#cite_note-viruslist-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup><sup class="reference cite_virgule">,</sup><sup id="cite_ref-Symantec_2_11-0" class="reference"><a href="#cite_note-Symantec_2-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup>. Si, à une de ces adresses, il y a un ordinateur exécutant une version de <a href="Microsoft_SQL_Server" title="Microsoft SQL Server">Microsoft SQL Server</a> auquel on n'a pas appliqué le <a href="Patch_(informatique)" title="Patch (informatique)">correctif</a> publié dans le bulletin <a rel="nofollow" class="external text" href="http://www.microsoft.com/technet/security/bulletin/MS02-039.mspx">MS02-039</a> celui-ci devient immédiatement infecté et commence à son tour à envoyer <i>via</i> <a href="Internet" title="Internet">Internet</a> de nouvelles copies du ver<sup id="cite_ref-viruslist_4-3" class="reference"><a href="#cite_note-viruslist-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup><sup class="reference cite_virgule">,</sup><sup id="cite_ref-Symantec_1_9-1" class="reference"><a href="#cite_note-Symantec_1-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup><sup class="reference cite_virgule">,</sup><sup id="cite_ref-Symantec_2_11-1" class="reference"><a href="#cite_note-Symantec_2-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup>.
</p><p>Le <a href="Payload" class="mw-redirect mw-disambig" title="Payload">code</a> du ver, très court (306 <a href="Octet" title="Octet">octets</a>)<sup id="cite_ref-viruslist_4-4" class="reference"><a href="#cite_note-viruslist-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup><sup class="reference cite_virgule">,</sup><sup id="cite_ref-Symantec_2_11-2" class="reference"><a href="#cite_note-Symantec_2-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup> ne contient aucune instruction pour se copier sur le disque, il réside donc uniquement en mémoire<sup id="cite_ref-Symantec_1_9-2" class="reference"><a href="#cite_note-Symantec_1-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup><sup class="reference cite_virgule">,</sup><sup id="cite_ref-viruslist_4-5" class="reference"><a href="#cite_note-viruslist-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> ce qui le rend très facile à supprimer. Pour ce faire, on peut utiliser un utilitaire de suppression comme celui fourni gratuitement par Symantec (voir le lien externe plus bas) ou tout simplement redémarrer le serveur<sup id="cite_ref-Symantec_3_12-0" class="reference"><a href="#cite_note-Symantec_3-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup>, mais la machine sera probablement réinfectée presque immédiatement<sup id="cite_ref-xforce_1_13-0" class="reference"><a href="#cite_note-xforce_1-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup>.
</p><p>Deux caractéristiques clés ont contribué à la propagation rapide du ver SQL Slammer&nbsp;: l'utilisation du protocole <a href="User_Datagram_Protocol" title="User Datagram Protocol">UDP</a> pour infecter de nouveaux <a href="Ordinateur_h%C3%B4te" class="mw-redirect" title="Ordinateur hôte">hôtes</a><sup id="cite_ref-viruslist_4-6" class="reference"><a href="#cite_note-viruslist-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup><sup class="reference cite_virgule">,</sup><sup id="cite_ref-Symantec_2_11-3" class="reference"><a href="#cite_note-Symantec_2-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup> et la possibilité de faire tenir le code du ver dans un seul paquet <a href="User_Datagram_Protocol" title="User Datagram Protocol">UDP</a><sup id="cite_ref-CAIDA_2_14-0" class="reference"><a href="#cite_note-CAIDA_2-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup>. Libéré par l'utilisation d'<a href="User_Datagram_Protocol" title="User Datagram Protocol">UDP</a> de la nécessité d'établir une connexion comme en TCP<sup id="cite_ref-Symantec_3_12-1" class="reference"><a href="#cite_note-Symantec_3-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup>, l'hôte infecté pouvait employer une stratégie dite de «&nbsp;tir et oubli&nbsp;» pour transmettre son paquet aussi souvent que possible (habituellement plusieurs centaines par seconde)<sup id="cite_ref-CAIDA_2_14-1" class="reference"><a href="#cite_note-CAIDA_2-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup>.
</p><p>Les <a href="Ordinateur_personnel" title="Ordinateur personnel">ordinateurs personnels (PC)</a> ne sont pas touchés par ce ver sauf si <a href="Microsoft_SQL_Server_Desktop_Engine" title="Microsoft SQL Server Desktop Engine">MSDE</a> y est installé<sup id="cite_ref-f-secure_15-0" class="reference"><a href="#cite_note-f-secure-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup>.
</p>
<div class="mw-heading mw-heading3"><h3 id="Effets[16],[17]"><span id="Effets.5B16.5D.2C.5B17.5D"></span>Effets<sup id="cite_ref-IEEE_paper_16-0" class="reference"><a href="#cite_note-IEEE_paper-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup><sup class="reference cite_virgule">,</sup><sup id="cite_ref-Symante_5_17-0" class="reference"><a href="#cite_note-Symante_5-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup></h3></div>
<p>L'effondrement de nombreux <a href="Routeur" title="Routeur">routeurs</a>, en réaction à la très grande augmentation de trafic engendrée par l'envoi massif de copies du ver par les <a href="Serveur_informatique" title="Serveur informatique">serveurs</a> infectés, a causé un ralentissement significatif sur <a href="Internet" title="Internet">Internet</a> en raison du trafic massif sur le port 1434. En règle générale, si le trafic devient trop important pour que le routeur le prenne en charge, ce dernier est censé retarder ou arrêter temporairement le trafic. La surcharge de <a href="Bande_passante" title="Bande passante">bande passante</a> a engendré un dysfonctionnement de certains routeurs, directement «&nbsp;déconnectés&nbsp;» du réseau Internet par les routeurs voisins (par retrait de la <a href="Table_de_routage" title="Table de routage">table de routage</a>). Finalement, les multiples notifications de mise à jour de routes, soit pour enlever des routeurs éteints du réseau, soit pour en ajouter de nouveaux qui ont redémarré, ont très vite monopolisé une part importante de la bande passante d'Internet. Le trafic ordinaire a conséquemment ralenti, allant même jusqu'à s'arrêter complètement dans certains cas. Il est ironique toutefois de constater qu'à cause de sa très petite taille le ver SQL Slammer pouvait parfois être transmis alors que le trafic légitime ne le pouvait pas.
</p>
<div class="mw-heading mw-heading2"><h2 id="Notes">Notes</h2></div>
<p>Il existe une polémique quant à savoir qui a trouvé Slammer en premier, bien qu'il soit pratiquement impossible de le déterminer. On peut toutefois attribuer la première alerte publique à Michael Bacarella qui a envoyé un message sur la liste de diffusion <a href="Bugtraq" title="Bugtraq">Bugtraq</a>, le <time class="nowrap" datetime="2003-01-25" data-sort-value="2003-01-25">25 janvier 2003</time> à 07:11:41 UTC&nbsp;: «&nbsp;Le ver MS SQL est en train de détruire Internet - Bloquez le port 1434&nbsp;!&nbsp;» («&nbsp;<i>MS SQL WORM IS DESTROYING INTERNET - BLOCK PORT 1434!</i>&nbsp;»)<sup id="cite_ref-18" class="reference"><a href="#cite_note-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup>.
</p><p>Cependant la première annonce est souvent attribuée à Ben Koshy. En effet, la société W3Media, pour laquelle il travaille alors, a émis un communiqué à cet effet<sup id="cite_ref-19" class="reference"><a href="#cite_note-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup>. Toutefois, son avertissement au public ne fut envoyé à la <a href="Liste_de_diffusion" title="Liste de diffusion">liste de diffusion</a> NTBugtraq qu'à 10:28 UTC<sup id="cite_ref-20" class="reference"><a href="#cite_note-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup>. Robert Boyle envoya une alerte à NTBugtraq à 08:35 UTC<sup id="cite_ref-21" class="reference"><a href="#cite_note-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup>, donc avant Koshy mais après Bacarella.
</p><p>ISS, par l'entremise de Chris Rouland, envoie des alertes à 11:54 UTC<sup id="cite_ref-22" class="reference"><a href="#cite_note-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup> et à 11:56 UTC<sup id="cite_ref-23" class="reference"><a href="#cite_note-23"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup> sur les listes de diffusion ISSForum et Vulnwatch respectivement.
</p>
<div class="mw-heading mw-heading2"><h2 id="Références"><span id="R.C3.A9f.C3.A9rences"></span>Références</h2></div>
<div class="references-small decimal" style=""><div class="mw-references-wrap mw-references-columns"><ol class="references">
<li id="cite_note-zdnet-1"><span class="mw-cite-backlink"><a href="#cite_ref-zdnet_1-0">↑</a> </span><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> «&nbsp;<a rel="nofollow" class="external text" href="https://www.zdnet.com/sql-slammer-worm-wreaks-havoc-on-internet-3002129330/"><cite style="font-style:normal;" lang="en">SQL Slammer worm wreaks havoc on Internet</cite></a>&nbsp;»</span></span>
</li>
<li id="cite_note-CAIDA_1-2"><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> «&nbsp;<a rel="nofollow" class="external text" href="http://www.caida.org/research/security/sapphire/"><cite style="font-style:normal;" lang="en">Analysis of the Sapphire Worm - A joint effort of CAIDA, ICSI, Silicon Defense, UC Berkeley EECS and UC San Diego CSE</cite></a>&nbsp;»</span></span>
</li>
<li id="cite_note-Symantec_4-3"><span class="mw-cite-backlink"><a href="#cite_ref-Symantec_4_3-0">↑</a> </span><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> «&nbsp;<a rel="nofollow" class="external text" href="http://securityresponse.symantec.com/avcenter/security/Content/2270.html"><cite style="font-style:normal;" lang="en">"Microsoft SQL Server Resolution Service buffer overflows allow arbitrary code execution"</cite></a>&nbsp;»</span></span>
</li>
<li id="cite_note-viruslist-4"><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> «&nbsp;<a rel="nofollow" class="external text" href="http://www.viruslist.com/fr/viruses/encyclopedia?virusid=23889"><cite style="font-style:normal;" lang="en">Net-Worm.Win32.Slammer</cite></a>&nbsp;»</span></span>
</li>
<li id="cite_note-CERT-5"><span class="mw-cite-backlink"><a href="#cite_ref-CERT_5-0">↑</a> </span><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> «&nbsp;<a rel="nofollow" class="external text" href="http://www.cert.org/advisories/CA-2002-22.html"><cite style="font-style:normal;" lang="en">"CERT Advisory CA-2002-22 Multiple Vulnerabilities in Microsoft SQL Server"</cite></a>&nbsp;»</span></span>
</li>
<li id="cite_note-cnn_1-6"><span class="mw-cite-backlink"><a href="#cite_ref-cnn_1_6-0">↑</a> </span><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> «&nbsp;<a rel="nofollow" class="external text" href="http://www.cnn.com/2003/TECH/biztech/02/01/microsoft.security.reut/"><cite style="font-style:normal;" lang="en">Experts: Microsoft security gets an 'F'</cite></a>&nbsp;»</span></span>
</li>
<li id="cite_note-cnet_1-7"><span class="mw-cite-backlink"><a href="#cite_ref-cnet_1_7-0">↑</a> </span><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> «&nbsp;<a rel="nofollow" class="external text" href="http://news.cnet.com/Worm-exposes-apathy%2C-Microsoft-flaws/2100-1002_3-982135.html"><cite style="font-style:normal;" lang="en">Worm exposes apathy, Microsoft flaws</cite></a>&nbsp;»</span></span>
</li>
<li id="cite_note-secuser-8"><span class="mw-cite-backlink"><a href="#cite_ref-secuser_8-0">↑</a> </span><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> «&nbsp;<a rel="nofollow" class="external text" href="http://www.secuser.com/alertes/2003/sqlslammer.htm"><cite style="font-style:normal;" lang="en">Virus SQL Slammer</cite></a>&nbsp;»</span></span>
</li>
<li id="cite_note-Symantec_1-9"><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> «&nbsp;<a rel="nofollow" class="external text" href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-012502-3306-99"><cite style="font-style:normal;" lang="en">Symantec W32.SQLExp.Worm - Summary</cite></a>&nbsp;»</span></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><a href="#cite_ref-10">↑</a> </span><span class="reference-text"><span class="ouvrage" id="Leyden2003"><span class="ouvrage" id="John_Leyden2003">John <span class="nom_auteur">Leyden</span>, «&nbsp;<cite style="font-style:normal">Slammer: Why security benefits from proof of concept code</cite>&nbsp;», <i>Register</i>,‎ <time class="nowrap" datetime="2003-02-06" data-sort-value="2003-02-06">6 février 2003</time> <small style="line-height:1em;">(<a rel="nofollow" class="external text" href="https://www.theregister.co.uk/2003/02/06/slammer_why_security_benefits/">lire en ligne</a>, consulté le <time class="nowrap" datetime="2008-11-29" data-sort-value="2008-11-29">29 novembre 2008</time>)</small><span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&amp;rft.genre=article&amp;rft.atitle=Slammer%3A+Why+security+benefits+from+proof+of+concept+code&amp;rft.jtitle=Register&amp;rft.aulast=Leyden&amp;rft.aufirst=John&amp;rft.date=2003-02-06&amp;rft_id=https%3A%2F%2Fwww.theregister.co.uk%2F2003%2F02%2F06%2Fslammer_why_security_benefits%2F&amp;rfr_id=info%3Asid%2Ffr.wikipedia.org%3ASQL+Slammer"></span></span></span></span>
</li>
<li id="cite_note-Symantec_2-11"><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> «&nbsp;<a rel="nofollow" class="external text" href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-012502-3306-99&amp;tabid=2"><cite style="font-style:normal;" lang="en">Symantec W32.SQLExp.Worm - Technical details</cite></a>&nbsp;»</span></span>
</li>
<li id="cite_note-Symantec_3-12"><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> «&nbsp;<a rel="nofollow" class="external text" href="http://securityresponse.symantec.com/avcenter/Analysis-SQLExp.pdf"><cite style="font-style:normal;" lang="en">DeepSight Threat Management System Threat Analysis: SQLExp SQL Server Worm Analysis</cite></a>&nbsp;»</span></span>
</li>
<li id="cite_note-xforce_1-13"><span class="mw-cite-backlink"><a href="#cite_ref-xforce_1_13-0">↑</a> </span><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> «&nbsp;<a rel="nofollow" class="external text" href="http://xforce.iss.net/xforce/xfdb/37236"><cite style="font-style:normal;" lang="en">SQL Worm Propagation</cite></a>&nbsp;»</span></span>
</li>
<li id="cite_note-CAIDA_2-14"><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> «&nbsp;<a rel="nofollow" class="external text" href="http://www.caida.org/publications/papers/2003/sapphire/sapphire.html"><cite style="font-style:normal;" lang="en">The Spread of the Sapphire/Slammer Worm</cite></a>&nbsp;»</span></span>
</li>
<li id="cite_note-f-secure-15"><span class="mw-cite-backlink"><a href="#cite_ref-f-secure_15-0">↑</a> </span><span class="reference-text"><span class="ouvrage">«&nbsp;<a rel="nofollow" class="external text" href="http://www.f-secure.com/v-descs/mssqlm.shtml"><cite style="font-style:normal;">Worm:W32/Slammer</cite></a>&nbsp;»</span></span>
</li>
<li id="cite_note-IEEE_paper-16"><span class="mw-cite-backlink"><a href="#cite_ref-IEEE_paper_16-0">↑</a> </span><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> «&nbsp;<a rel="nofollow" class="external text" href="http://cseweb.ucsd.edu/~savage/papers/IEEESP03.pdf"><cite style="font-style:normal;" lang="en">Inside the Slammer Worm</cite></a>&nbsp;»</span></span>
</li>
<li id="cite_note-Symante_5-17"><span class="mw-cite-backlink"><a href="#cite_ref-Symante_5_17-0">↑</a> </span><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> «&nbsp;<a rel="nofollow" class="external text" href="http://www.symantec.com/connect/articles/effects-worms-internet-routing-stability"><cite style="font-style:normal;" lang="en">Effects of Worms on Internet Routing Stability</cite></a>&nbsp;»</span></span>
</li>
<li id="cite_note-18"><span class="mw-cite-backlink"><a href="#cite_ref-18">↑</a> </span><span class="reference-text"><span class="ouvrage" id="Bacarella2003"><span class="ouvrage" id="Michael_Bacarella2003"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> Michael <span class="nom_auteur">Bacarella</span>, «&nbsp;<a rel="nofollow" class="external text" href="http://seclists.org/bugtraq/2003/Jan/221"><cite style="font-style:normal;" lang="en">MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434!</cite></a>&nbsp;», Bugtraq, <time class="nowrap" datetime="2003-01-25" data-sort-value="2003-01-25">25 janvier 2003</time> <small style="line-height:1em;">(consulté le <time class="nowrap" datetime="2012-11-29" data-sort-value="2012-11-29">29 novembre 2012</time>)</small></span></span></span>
</li>
<li id="cite_note-19"><span class="mw-cite-backlink"><a href="#cite_ref-19">↑</a> </span><span class="reference-text"><span class="ouvrage" id="2003"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> «&nbsp;<a rel="nofollow" class="external text" href="http://www.w3media.com/images/news/W3_Identify_Slammer_Virus.pdf"><cite style="font-style:normal;" lang="en">W3 Media's Ben Koshy first to identify Internet 'Slammer' Virus</cite></a>&nbsp;», <span class="italique">Press Release</span>, W3 Media, <time class="nowrap" datetime="2003-01-24" data-sort-value="2003-01-24">24 janvier 2003</time> <small style="line-height:1em;">(consulté le <time class="nowrap" datetime="2008-11-29" data-sort-value="2008-11-29">29 novembre 2008</time>)</small></span></span>
</li>
<li id="cite_note-20"><span class="mw-cite-backlink"><a href="#cite_ref-20">↑</a> </span><span class="reference-text"><span class="ouvrage" id="Koshy2003"><span class="ouvrage" id="Ben_Koshy2003"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> Ben <span class="nom_auteur">Koshy</span>, <span class="noarchive">«&nbsp;<a rel="nofollow" class="external text" href="http://archives.neohapsis.com/archives/ntbugtraq/2003-q1/0010.html"><cite style="font-style:normal;" lang="en">Peace of Mind Through Integrity and Insight</cite></a>&nbsp;» <small class=" cachelinks">[<a rel="nofollow" class="external text" href="https://web.archive.org/web/20090219072809/http://archives.neohapsis.com/archives/ntbugtraq/2003-q1/0010.html">archive du <time class="nowrap" datetime="2009-02-19" data-sort-value="2009-02-19">19 février 2009</time></a>]</small></span>, Neohapsis Archives, <time class="nowrap" datetime="2003-01-25" data-sort-value="2003-01-25">25 janvier 2003</time> <small style="line-height:1em;">(consulté le <time class="nowrap" datetime="2008-11-29" data-sort-value="2008-11-29">29 novembre 2008</time>)</small></span></span></span>
</li>
<li id="cite_note-21"><span class="mw-cite-backlink"><a href="#cite_ref-21">↑</a> </span><span class="reference-text"><span class="ouvrage" id="Boyle2003"><span class="ouvrage" id="Robert_Boyle2003"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> Robert <span class="nom_auteur">Boyle</span>, <span class="noarchive">«&nbsp;<a rel="nofollow" class="external text" href="http://archives.neohapsis.com/archives/ntbugtraq/2003-q1/0011.html"><cite style="font-style:normal;" lang="en">Peace of Mind Through Integrity and Insight</cite></a>&nbsp;» <small class=" cachelinks">[<a rel="nofollow" class="external text" href="https://web.archive.org/web/20090219072838/http://archives.neohapsis.com/archives/ntbugtraq/2003-q1/0011.html">archive du <time class="nowrap" datetime="2009-02-19" data-sort-value="2009-02-19">19 février 2009</time></a>]</small></span>, Neohapsis Archives, <time class="nowrap" datetime="2003-01-25" data-sort-value="2003-01-25">25 janvier 2003</time> <small style="line-height:1em;">(consulté le <time class="nowrap" datetime="2008-11-29" data-sort-value="2008-11-29">29 novembre 2008</time>)</small></span></span></span>
</li>
<li id="cite_note-22"><span class="mw-cite-backlink"><a href="#cite_ref-22">↑</a> </span><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> «&nbsp;<a rel="nofollow" class="external text" href="http://archive.cert.uni-stuttgart.de/issforum/2003/01/msg00099.html"><cite style="font-style:normal;" lang="en">[ISSForum] ISS Security Brief: Microsoft SQL Slammer Worm Propagation</cite></a>&nbsp;» <small style="line-height:1em;">(consulté le <time class="nowrap" datetime="2013-01-18" data-sort-value="2013-01-18">18 janvier 2013</time>)</small></span></span>
</li>
<li id="cite_note-23"><span class="mw-cite-backlink"><a href="#cite_ref-23">↑</a> </span><span class="reference-text"><span class="ouvrage" id="X-Force2003"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> X-Force, <span class="noarchive">«&nbsp;<a rel="nofollow" class="external text" href="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0038.html"><cite style="font-style:normal;" lang="en">Peace of Mind Through Integrity and Insight</cite></a>&nbsp;» <small class=" cachelinks">[<a rel="nofollow" class="external text" href="https://web.archive.org/web/20090219072755/http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0038.html">archive du <time class="nowrap" datetime="2009-02-19" data-sort-value="2009-02-19">19 février 2009</time></a>]</small></span>, Neohapsis Archives, <time class="nowrap" datetime="2003-01-25" data-sort-value="2003-01-25">25 janvier 2003</time> <small style="line-height:1em;">(consulté le <time class="nowrap" datetime="2008-11-29" data-sort-value="2008-11-29">29 novembre 2008</time>)</small></span></span>
</li>
</ol></div>
</div>
<div class="mw-heading mw-heading2"><h2 id="Liens_externes">Liens externes</h2></div>
<ul><li><a rel="nofollow" class="external text" href="http://support.microsoft.com/kb/323875/fr">CORRIGER&nbsp;: MS02-039&nbsp;: des dépassements de mémoire tampon dans le Service de résolution de 2000 de SQL Server peuvent permettre l'exécution de Code</a>. Article Q323875</li>
<li><a rel="nofollow" class="external text" href="http://www.microsoft.com/technet/security/bulletin/MS02-039.mspx">Microsoft Security Bulletin MS02-039</a> Bulletin rapportant la faille exploités par SQL Slammer</li>
<li><a rel="nofollow" class="external text" href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-012520-2612-99">Outils de désinfection de Symantec (en)</a></li>
<li><a rel="nofollow" class="external text" href="http://www.01net.com/article/200441.html">Sapphire fait une peur bleue au Web</a> sur 01Net</li>
<li><a rel="nofollow" class="external text" href="http://www.microsoft.com/downloads/details.aspx?displaylang=fr&amp;FamilyID=9552D43B-04EB-4AF9-9E24-6CDE4D933600">Outils de sécurité SQL Server 2000</a> sur le site de Microsoft</li></ul>
<p><br>
</p>
<ul><li><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> Cet article est partiellement ou en totalité issu de l’article de Wikipédia en anglais intitulé <span class="">«&nbsp;<a class="external text" href="https://en.wikipedia.org/wiki/SQL_Slamer?oldid=525625662">SQL Slamer</a>&nbsp;» <small>(<a class="external text" href="https://en.wikipedia.org/wiki/SQL_Slamer?action=history">voir la liste des auteurs</a>)</small></span>.</li></ul>
<div class="navbox-container" style="clear:both;">

</div>
<ul id="bandeau-portail" class="bandeau-portail"><li><span class="bandeau-portail-element"><span class="bandeau-portail-icone"><span class="noviewer" typeof="mw:File"></span></span> <span class="bandeau-portail-texte">Portail de la sécurité des systèmes d'information</span> </span></li> </ul></div><!--htdig_noindex--><div><div class="zim-footer">
Cet article est issu de <a class="external text" title="Dernière modification le 2025-04-25" href="https://fr.wikipedia.org/wiki/?title=SQL_Slammer&amp;oldid=225111964">Wikipédia</a>. Sauf mention contraire, le texte est disponible sous <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.fr">Creative Commons Attribution-Share Alike 4.0</a>. Des conditions supplémentaires peuvent s’appliquer aux fichiers multimédias.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
<script src="./_webp_/webpHandler.js"></script>

</body></html>