From: "Disclosure From OSSI" <disclosure@xxxxxxxxxxxxx>
From the quick analysis of this worm (retrieved from
http://isc.incidents.org/diary.html?date=2004-03-20), it seems that it bears
strange similarity with SQL Slammer for the following points:
1. It uses the same "push ascii" format as SQL Slammer, for example "push 6B636F73h" in this worm.
2. It uses hard-coded import addresses (listed below) as SQL Slammer.
3. If someone can trace the origin of this worm, it might shed light on the origin of SQL Slammer as well?
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html