SQL Slammer, also known as Sapphire and SQL-Hell, was a fast-spreading network worm that emerged in January 2003 and targeted vulnerable Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 systems. It exploited a buffer overrun in the SQL Server Resolution Service associated with Microsoft bulletin MS02-039, using a single UDP-based exploit path to achieve extremely rapid self-propagation without requiring a file to be written to disk. Once active, the worm continuously generated scan traffic to locate and infect additional vulnerable hosts, causing severe network congestion and widespread disruption across the public internet and enterprise networks.
SQL Slammer is notable for having no conventional destructive payload beyond propagation. Its operational effect came from overwhelming bandwidth and infrastructure with massive volumes of scanning traffic, which degraded connectivity and availability at global scale within minutes. Contemporary reporting and later retrospectives consistently characterize the outbreak as one of the most disruptive early internet worm events, with very high infection velocity and broad collateral impact.
The worm targeted Windows-based deployments of Microsoft SQL Server and MSDE. It has also been repeatedly cited in industrial control system security discussions as an example of how broadly disruptive commodity worms can affect operational environments when vulnerable systems are exposed or insufficiently segmented. SQL Slammer remains a canonical case study in vulnerability-driven mass exploitation, patch latency, and the systemic risk posed by homogeneous, internet-reachable software flaws.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
By sending a carefully crafted packet to the Resolution Service, an attacker could cause portions of system memory (the heap in one case, the stack in the other) to be overwritten. Overwriting it with carefully selected data could allow the attacker to run code in the security context of the SQL Server service.
A second kind of covert channel, aimed at subverting firewall–based filtering, uses standard ports for passing non-standard traffic. Firewalls that enforce a “block-all-but-necessary” approach to regulating traffic are the typical targets of standard port abuse. A recent (25 Jan 2003) case of standard port abuse involved a Denial of Service (DOS) attack that was variously known as the ‘SQL Slammer’ worm, ‘Sapphire’ and “SQL-Hell’.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Internet worm that rapidly spread by scanning vulnerable systems at massive scale, causing widespread network disruption rather than delivering a traditional malicious payload.
A fast-spreading Internet worm cited as an example of flash-worm-style propagation, infecting 90% of its hosts in less than 10 minutes.
A notorious internet worm mentioned as part of the sequence of disruptive malware incidents that forced changes in defensive strategy.
Malware 2003 SQL Slammer
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.