The minutes seem like hours (was Re: Symantec detected Slammer worm "hours" before)

Mike Lewinski mike at rockynet.com
Sat Feb 15 16:02:02 UTC 2003


Sean Donelan wrote:

 > According to Wired, Symantec is now saying they sent out an alert to
 > their paying customers about 30 minutes (9pm PST) before the SQL
 > slammer worm was detected by anyone else around 9:30pm PST.
 >
 > I have not seen a copy of the Symantec message.

OK, if there really was a private alert... one would expect that after 
news hit NANOG, BUGTRAQ et al, a public advisory would have been 
released by Symantec as well.

There was no information about Slammer available on Symantec's public 
web site for more than four hours after it reached criticality (3AM 
MST). I kept a close eye on Symantec, McAffee, dshield.org, 
incidents.org and other usual suspects, none of them had information 
available until the next morning.

Mike





More information about the NANOG mailing list