Researcher: Half a Million Database Servers Have No Firewall
According to an upcoming report by security researcher David Litchfield, nearly half a million database servers lack firewall protection. What's worse, many aren't even patched properly.
About 82 percent of the SQL Servers were running older SQL Server 2000 software, and less than half of those had the product's latest Service Pack updates installed. On the Oracle side, 13 percent of the servers were running older versions of the database that no longer receive patches. These Oracle 9.0 and earlier databases are known to have security vulnerabilities, Litchfield said.
Litchfield, who wrote the proof of concept code that was eventually used by Slammer, said that this many unsecured databases is enough to sustain another worm outbreak. "There's certainly potential there," he said. "So the question is, what's the likelihood? [That's] much more difficult to answer."
firewall



