What is the worm's impact? The ISS alert warns, "Although the Spida worm is not destructive to the infected host, it may generate a damaging level of network traffic when it scans for additional targets. The scanner bundled with the worm is multi-threaded and is capable of scanning with 100 threads. A large amount of network traffic is created by the worm, which scans both internal and external IP addresses for vulnerable servers."
I know that many of our readers may be running Microsoft SQL servers, and it is very important that you protect your systems and your networks and keep from getting infected by this worm. For more information on how the worm works, and what to look for, I've provided you with several links:
Microsoft SQL Spida Worm Propagation
Product Support Services Informational Alert on SQL Server (Microsoft.com, May 21, 2002)
SQLSnake Code Analysis (Incidents.org, report by George Bakos and Guofei Jiang, Institute for Security Technology Studies, Dartmouth College)