Advertisement
Promo

Industry watch Toolkit

Code Red variant causes little alarm

David Becker CNET News

Published: 13 Mar 2003 09:36 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security experts said Wednesday there was little cause for alarm from a minor new variant of the destructive Code Red worm that began circulating this week.

Code Red.F, which differs from the original Code Red by only two bytes, began spreading on Tuesday, according to reports from security software makers Symantec, McAfee and F-Secure. The new variant is detected by existing virus signatures for Code Red, according to the companies, and is blocked by patches for Microsoft's Internet Information Server (IIS), which most administrators installed before or during the original Code Red outbreak.

The original Code Red wreaked widespread havoc during the summer of 2001, infecting more than 350,000 Web servers running IIS. The infected servers were used to spread the worm and to launch a denial-of-service attack on the main Web site for the White House.

The first sequel to Code Red also caused widespread damage, but subsequent variations on the worm packed only a minor punch, largely because the IIS hole the worm exploits had already been patched.

According to a security bulletin from Symantec, the main difference in Code Red.F is that it removes the expiration date that prevented the original worm from activating if the year was later than 2001.

Most security firms classified the new variant as a moderate threat, with negligible infections reported so far.

Kevin Haley, group product manager with Symantec Security Response, said the company saw a brief surge of infections in Europe on Tuesday night, but activity has been minimal since then.

"It looks like people learned a lesson with the first Code Red," he said. "They've updated their patches for IIS and kept their (antivirus) definitions current."


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
18 out of 66 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Discussions

CA CA

Spin the colour wheel

Friday 11 December 2009, 10:25 AM

1 comment
CA CA

Beware of keeping your head in the clo...

Friday 11 December 2009, 12:53 AM

1 comment
CA CA

UK internet hit by LINX router failure

Friday 11 December 2009, 12:30 AM

1 comment
CA CA

McKinnon lawyers seek judicial review

Friday 11 December 2009, 12:27 AM

1 comment
Video icon

Video

Featured Talkback

In association with Network Liberation Movement
When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters