ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

FBI criticised for ignoring early Code Red warnings

Wendy McAuliffe ZDNet.co.uk

Published: 06 Sep 2001 13:18 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The security firm that discovered the destructive Code Red worm has launched an attack on the FBI for its reluctance to publicise the Microsoft vulnerability exploited by the worm.

The self-propagating worm infected an estimated 975,000 servers in July and August 2001, but the security company eEye Digital, who posted the first Code Red alert on 12 July, claims that the FBI should have been more proactive in warning people about a "test" version of the worm to which it was alerted in April.

"Had the FBI been more vigilant in its warnings, Code Red would have had less of an impact than it did," said Mark Jones, UK manager of eEye Digital.

The FBI's National Infrastructure Protection Centre (NIPC) had received earlier reports of a Code Red-like worm that affected a buffer overflow vulnerability in the .htr files of Microsoft IIS 4. It is now thought that this was a test version, as the more virulent Code Red was adapted to target a similar hole in the more widely used IIS 5 servers. The earlier worm also propagated in a manner similar to Code Red, by infecting a random list of IP addresses, and then resetting itself to attack the same machines again.

"The mechanism that the initial worm used to spread was exactly the same mechanism that was used by Code Red," said Jones. "If we had have had access to the methodology used in the previous worm, we would have been able to decode Code Red sooner," he added. According to eEye, six days were lost investigating Code Red as a result of the delay.

A US Department of Energy security research lab, known as Sandia National Laboratories, spotted the initial worm on its systems in February, March and May 2001. It handed over complete logs of the worm's activity as well as a copy of the malicious code to the NIPC in April, but the FBI ignored the warnings. It decided against publicising the .htr worm on the basis that the Computer Emergency Response Team at Carnegie Mellon University had posted a report of the .htr vulnerability when it was first detected in June 1999.

"It is key that the NIPC didn't publicise how the worm's methods were proliferating across machines," said Jones.

It is suspected that the two worms were written by the same person, but eEye is refusing to confirm this without a full investigation into the matter.

See the Viruses and Hacking News Section for the latest headlines.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
46 out of 66 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:











Sentry Posts Blog

Facebook Bans Firefox 3

Ok this is the issue. Because I dared to try and access facebook with firefox 3, and all the cookies disabled, it won't let me back on there with firefox ever again, even though... More

1 comment

GoDaddy suspends travel-getaways.com d...

I'm very pleased to say that GoDaddy has suspended the travel-getaways.com domain. I blogged in June that to my surprise I had found I was the site administrator for travel-getaways.com,... More

1 comment

Hello, I知 a PC. I知 a Handheld.

Hello, I知 a PC. I知 a Handheld. Author: Eric Everson, Founder MyMobiSafe.com I have said it before and I am sure I値l say it again, mobile devices are simply replacing computers.... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains