View Full Forums : EQ, the SQL Slammer worm and port closings


Seriena
06-17-2003, 04:52 PM
From Monkly-Business and this thread (http://pub147.ezboard.com/fmonklybusiness43508frm1.showMessage?topicID=39844 .topic):

<blockquote><strong><em>Quote:</em></strong><hr>Some people have been getting locked out of Plane of Tactics.

Plane of Tactics can use UDP port 1434 for connections (apparently, zone servers chooes semi-random port upon startup).

That is the same port by MS SQL Server (and related software like MSDE). A worm, called "SQL Slammer", propogated via a SQL Server vulnerability and cause quite a mess on the internet. Some ISPs chose to close UDP 1434 in response.

I called Verizon support and verified they have blocked this port. Further, they have no plans or timetable for reopening it.

PoTactics is now 100% inaccessible to some players, and will remain so as long as Microsoft, the ISPs, and SoE keep pointing fingers at each other instead of fixing the problem.

Edit: also other zones, if you zone and suddenly get disconnected--- that is EQ chosing port 1433 or 1434....[/quote]

Scott responded,

<blockquote><strong><em>Quote:</em></strong><hr>We do already know about the port issues. There are actually many more than 1434 that are blocked.

The problem is that whenever we pick a new port range, we end up with a bigger problem. As an example, when we moved to 9000-9100 where no known problems exist, a couple weeks ago, we ended up with 5% of the test players not being able to connect.

We'll be moving to a different static range sometime in the near future, that's hopefully compatible with everyone's provider. Finding that range has been quite the challenge.

Thanks,

- Scott [/quote]

So, if you're getting disconnected when you enter certain zones, this may be the reason.

FyyrLuStorm
06-17-2003, 05:27 PM
I still would like to know the reasons for the 1017 errors endemic of BB.(and what appears to be isolated to BB).

KubianVOIDTANK
06-18-2003, 08:28 AM
Raid down.. 1017 wins.

We /random loots now...

1(Person) 2 (Rot) 3(Person) 4(1017). WHO WILL WIN?
<hr />

And Fyyr (Get on more btw)

Check out HERE (http://crimsonblade.hopto.org/)

And see my new mantle of happiness.

ccLothar
06-18-2003, 01:17 PM
Quick Story on Slammer
whirlpool.net.au/article....ow=replies (http://whirlpool.net.au/article.cfm/1064?show=replies)

The irony is that Microsoft released the patch that closed the hole that the Slammer Worm exploited about six months before Slammer hit. Now I've heard that some agencies claimed to still be hit with Slammer even on patched systems, but I never saw or looked for anything to confirm this. After Slammer hit Microsoft rebuffed with these two bulitens…

www.microsoft.com/technet...02-039.asp (http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS02-039.asp)
And
www.microsoft.com/technet...02-061.asp (http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS02-061.asp)

So, how did Slammer screw up EQ? The ISP response to all of the Bank ATM machines getting shut down by the buffer overflow errors Slammer was causing was was, "Nobody has a use for UDP port 1434, so we are closing it down". In affect, they stopped routing anything to and from that port number. Well, EQ uses it, eh? Oops!

Now, legally, I doubt they can close it, and in practice it's lunacy but we are talking banks here and money talks and…walks. Had all those bank IT managers done their job and patched their ATMs you'd still be able to zone into PoT if you drew that port number. :)

This is a great developing story. It looks like SoE tried to adjust their UDP ranges only to run up against other port roadblocks. Should be fun to see Sony throw their muscle around in an attempt get the necessary UDP ports freed up again. :)

*edit* Here is Symantecs Security Response "strongly recommends" that you "Configure perimeter devices to block the ingress UDP traffic to port 1434 from untrusted hosts"

This would be the ISPs and their routers!

securityresponse.symantec....worm.html (http://securityresponse.symantec.com/avcenter/venc/data/w32.sqlexp.worm.html)

Selldor
06-18-2003, 02:01 PM
We do already know about the port issues. There are actually many more than 1434 that are blocked.

Well this explains alot. Why certain zones over the past while have dumped me out on zone in and kept me from getting on a certain character that I zone in there, unless I went to my alternate ISP. In which case I never had a problem.

This zone and get dumped issue happened even as recent as today to myself and a friend of mine for Cobalt Scar zone. We both use the same provider. Only on my alteranate provider could I get us both out of CS.