ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Companies 'not liable' for Code Red attacks

Wendy McAuliffe ZDNet.co.uk

Published: 02 Aug 2001 14:18 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Companies that inadvertently spread the Code Red worm to other corporate servers cannot be held liable for causing an Internet attack, say British legal experts.

The self-propagating worm, which resurfaced on Wednesday, had raised concerns that companies could face legal action for unleashing Code Red on other servers. Some companies have expressed fears that they could be found negligent for not installing the Microsoft patch that would protect their systems from re-infection, and prevent them from attacking other servers.

But according to IT legal experts, it would be ridiculous to imply that all companies should invest time and money into protecting other servers from malicious worms such as Code Red.

The Computer Misuse Act makes the "unauthorised modification of computer material" illegal -- but in the case of Code Red, there would be no evidence to prove criminal intent. "The Act could apply to someone that had deliberately targeted a virus to someone else's computer, but when you can't show that the attack was deliberate, you are moving back to the general realms of negligence," said Peter Stevens, partner in IT at city law firm Manches.

A company could technically be accused of negligence if it has failed to "act reasonably to prevent the loss of material on another company server," explained Stevens. But the duty of care that surrounds issues of negligence typically exists within specific human or business relationships. In the case of Code Red, the time-sensitive worm that is pseudo-random, it is programmed to generate IP addresses for servers using Microsoft's Internet Information Server (IIS) software that it intends to attack. Once executed, the worm will start to create copies of itself in the memory, in order to attack even more IIS servers at the same time.

Mark Read, systems security analyst for computer security company MIS Corporate Defence Solutions, admits that the issue of indirect negligence is a grey area for technology companies. "They are effectively starting an attack on someone else, but it is not deliberate," he said. "It is more likely that system administrators for compromised servers will be red-faced for not installing the Microsoft patches and doing their job properly."

The legal picture for ISPs (Internet Service Providers) and Web hosting companies is more contractual, and will depend on whether they have accepted the additional responsibility of ensuring the security of their clients' Web sites. Richard Kirby at server management company NPSL is fearful of the increasing liability issues which viruses are creating for service providers.

"Many viruses are copycat ones, and I can see the same sort of thing happening with Code Red. With core software changing (like the transition to Windows XP), the patch issue is only going to get worse," added Kirby.

Is your PC safe? Find out in ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
33 out of 54 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

Systems Administrators/ Linux/ Windows/ Unix/ Networking/ W.London

Systems Administrators/ Linux/ Windows/ Unix/ Networking/ 24/7/ W.London Do you want a new challenge ? Do you want a role to develop you existing ...

Hyperion Administrators - Reading - 30,000-40,000

Hyperion Administrators are required to join a global data integration companies based in the UK. My client, based near Reading is looking for an ...

Unix/Linux/ Systems Administrators/ Surrey/ West London/ 40k/

Unix/Linux/ Systems Administrators/ Surrey/ West London/ 40k/ Scripting/ MySQL/ Oracle/ Networking My client is the worlds leading organisation for ...

Discussions

Moley Moley

welcome to www.007trader.com

Saturday 17 May 2008, 11:37 PM

3 posts
Tallin Tallin

welcome to www.007trader.com

Saturday 17 May 2008, 11:11 PM

3 posts
Moley Moley

Pride

Saturday 17 May 2008, 10:10 PM

6 comments

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal