Code Red plague on the rampage

Code Red is spreading like wildfire and is attacking more than just the server.

James Middleton

The Code Red worm, which began its trail of destruction earlier this week, is spreading fast and this morning defaced Microsoft's Windows update site.

The knock-on effects from this fast-spreading IISS server worm are causing more problems to network kit because it attacks anything that uses HTTP, including Linux servers and printers.

Advertisement

Earlier this morning [Friday], windowsupdate.microsoft.com was defaced with the worm's characteristic statement: "Hello! Welcome to http://www.worm.com! Hacked by Chinese!"

Microsoft has since fixed the hack, but suffered the embarrassment of revealing that it did not update its own servers with the latest security patches.

The Code Red worm exploits a known buffer overflow vulnerability in the ISAPI extension in the Index Server of Windows 2000 and XP beta, for which Microsoft released a patch in June.

Paul Rogers, network security analyst at MIS, suggested that if the Windows update server had been open to this vulnerability for a month now, "who's to say someone didn't break in without doing anything so obvious as defacing the site, and Trojan some of the Windows update files."

He said that knock-on effects from the worm, which is programmed to break into Port 80 and deface a site, were causing other network problems.

Cisco has released an advisory warning that it may affect some of its kit, "and print servers are crashing too," said Rogers. "Basically anything accepting HTTP requests is getting DoS'ed," he added.

The White House, which was the original target for the worm's built-in denial of service command, managed to sidestep the torrent of data by shifting whitehouse.gov to a different IP address.

But Rogers said that as more info is gleaned about the worm, "it seems that it is programmed to lie dormant for some period after this weekend, and that means it could attack again."

The required patch to protect your IIS servers from this worm can be found here.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Mutant CodeRed II worm on the loose

CodeRed.F preys on vulnerable Microsoft IIS 4.0 and 5.0 web servers

BA ditches MS servers after virus threat

Airline removes 100 'unauthorised' web servers

Code Blue may be about to bite

Code Red variant is on rampage in the Far East, apparently

Linux users warned of new Trojan danger

Remote Shell worm could cause more damage than Code Red

Related whitepapers

Related jobs

Most watched

Views from the Valley: 17 November 2009

Legal issues take centre stage this week

Schwarzenegger applauds California tech firms - part 1

Local firms recognised for tech contributions

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

t-mobile logo

V3.co.uk weekly debrief, 20 Nov 09

This week we round up the major vendor conference events,...

Apple iPhone apps

Top 10 articles, 20 Nov 2009

An App Store upset for Apple, and a scandal at...

Biz Stone

Twitter founder details commercial account plans

Biz Stone says paid-for accounts will give users access to...

Cloud computing

Enisa launches comprehensive cloud security report

EU security agency provides checklist for firms looking to vet...

Primary Navigation