All the latest UK technology news, reviews and analysis

Code Red plague on the rampage

by James Middleton

20 Jul 2001

Be the first to comment

  • Tweet this

The Code Red worm, which began its trail of destruction earlier this week, is spreading fast and this morning defaced Microsoft's Windows update site.

The knock-on effects from this fast-spreading IISS server worm are causing more problems to network kit because it attacks anything that uses HTTP, including Linux servers and printers.

Earlier this morning [Friday], windowsupdate.microsoft.com was defaced with the worm's characteristic statement: "Hello! Welcome to http://www.worm.com! Hacked by Chinese!"

Microsoft has since fixed the hack, but suffered the embarrassment of revealing that it did not update its own servers with the latest security patches.

The Code Red worm exploits a known buffer overflow vulnerability in the ISAPI extension in the Index Server of Windows 2000 and XP beta, for which Microsoft released a patch in June.

Paul Rogers, network security analyst at MIS, suggested that if the Windows update server had been open to this vulnerability for a month now, "who's to say someone didn't break in without doing anything so obvious as defacing the site, and Trojan some of the Windows update files."

He said that knock-on effects from the worm, which is programmed to break into Port 80 and deface a site, were causing other network problems.

Cisco has released an advisory warning that it may affect some of its kit, "and print servers are crashing too," said Rogers. "Basically anything accepting HTTP requests is getting DoS'ed," he added.

The White House, which was the original target for the worm's built-in denial of service command, managed to sidestep the torrent of data by shifting whitehouse.gov to a different IP address.

But Rogers said that as more info is gleaned about the worm, "it seems that it is programmed to lie dormant for some period after this weekend, and that means it could attack again."

The required patch to protect your IIS servers from this worm can be found here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Information Security Manager

My client is a well established, non profit organisation;...

PHP Web Developer

PHP Web Developer – £30,000 - £35,000 PHP, MySQL, HTML...

HEAD OF DIGITAL - London - £80-95K+

HEAD OF DIGITAL - London - £80-95K + Excellent Bens...

Agile C# Developer - (North London)

Agile C# Developer - (North London) £55,000 - £65,000...

To send to more than one email address, simply separate each address with a comma.