ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Emerging tech Toolkit

FAQ: The Code Red threat

ZDNet UK CNet

Published: 01 Aug 2001 09:08 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

ZDNet UK answers common questions about the Code Red worm:

When will the Code Red worm strike?
The worm became active at 1 am BST on Wednesday, potentially launching a new round of infections that could slow parts of the Internet.

What is Code Red?
Named after a caffeine drink favoured by computer programmers, the Code Red worm takes advantage of a hole in Microsoft's Internet Information Server (IIS) Web server software. Starting on 13 July it may have infected more than 350,000 servers worldwide, launching a massive denial-of-service (DoS) attack against the White House's official Web site.

The most recent version of the worm fixes a flaw in the way it searches for and records addresses of vulnerable servers. That means the worm could be more virulent as it returns to action Tuesday, launching a data flood that could potentially overwhelm many servers and slow large swatches of the Internet.

Should everyone be worried about an infection?
No. If you are a home computer user running Windows 95, Windows 98 or Windows Me -- or any non-Microsoft operating system -- the worm cannot infect your system. Only computers running Windows NT or Windows 2000 and IIS can be infected with this worm. The worm doesn't destroy data, but it could be modified to do so. Only computers set to use the English language will have their Web pages defaced.

Code Red also can damage smaller networks by calling attention to a vulnerability in Cisco System's 600 series DSL routers. The worm could cause the router to stop forwarding traffic.

Although it won't infect home computers, users may experience delays or malfunctioning of their favourite Web sites because of worm-generated surges in Internet traffic. Because of that and the danger it poses to Microsoft Web servers, Microsoft, federal security agencies and trade groups hosted a globally televised press conference Monday to urge businesses to install a software patch that prevents infection.

Is there a particular target of the DoS attacks?
Yes. From the 20th of every month to the 28th, the worm targets an IP address formerly associated with the White House Web site, flooding it with data in an attempt to knock it offline.

The White House took precautions against it, changing its numerical Internet address to dodge the attack. Last week, the Pentagon shut down public access to all of its Web sites temporarily to purge and protect them. But security experts say virus writers could easily alter the worm so it could attack another address.

If most people are safe, why are the media, Microsoft and the government making such a big deal of it?
Rob Rosenberger, editor of the Vmyths.com news service, said the FBI's new National Infrastructure Protection Center has over-hyped the worm to boost its public profile, in the process prompting many people unaffected by the worm to waste time trying to download and install patches.

"Vmyths.com believes they launched a 'Code Red publicity tour' largely to improve their image," Rosenberger said of the FBI. "They suffered intense humiliation last week when (NIPC) Director Ron Dick faced an irate Senate subcommittee."

Why is the worm coming back?
Code Red remains active between the first of the month and the 28th, when it goes into hibernation. While the worm does not reactivate itself automatically, anyone sending a copy of the worm once the active period begins -- in this case at midnight GMT 1 August, or 1 am BST on Wednesday -- would start a new round of infections to attack mode and barrage the whitehouse.gov Internet domain with large packets of data.

Who created the worm?
It's unclear. At first, officials suspected that the worm originated in China because some infected Web sites were defaced with the message, "Hacked by Chinese." But a Chinese network safety official denied those allegations on Tuesday.

Who's fault is it?
Many people blame Microsoft, whose server software contains a vulnerability that enables Code Red to infect servers. Microsoft has also been criticised for allowing other worms, such as those that have spread through the Outlook email software by taking advantage of Microsoft's support for Visual Basic scripts. Microsoft last month botched and apologised for two patches for a flaw in its Exchange email server software.

Can anyone stop the worm?
Maybe. Security experts could create an automated patching worm, which would spread around the Net and infect vulnerable machines to install the patch. Another idea is an automated program that -- when attacked by a server infected with the worm -- would attack back, hacking the server, deleting the worm and closing the hole. Such code is called "hack-back".

But the ethics of the hack-back approach are murky. Security expert and hacker Max Butler, also known as Max Vision, started an 18-month prison term last month for creating a worm that essentially closed security holes on vulnerable servers. The worm also left an open back door into the servers, casting doubt on Butler's altruistic intentions.

The FBI has dismissed using any hack-back tactic as well. "It is not something that we could consider," said spokeswoman Debbie Weierman. "It would basically be viewed as an unauthorised intrusion."

What has the tech industry learned from this worm and several other high-profile worms in recent months?
Many security experts are questioning the whole approach of expecting software customers to download and install fixes to prevent a particular issue -- also known as the "patch and pray" technique.

Instead of fixing buggy software, the focus should be on locking down computer systems to prevent activity that could be compromising, said Randy Sandone, chief executive of security software maker Argus Systems Group.

Christopher W. Klaus, founder of software and services company Internet Security Systems, advocates an approach called "vulnerability scanning" that routinely examines computer systems for possible security threats.

For full coverage, see ZDNet UK's Code Red News Roundup

Is your PC safe? Find out in ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
37 out of 59 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Security Consultant Ethical Hacking / Penetration Testing - London

Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...

Testing consultant-vba/visual basic- West Midlands.

Testing consultant/VBA/VISUAL BASIC. Testing consultant required to join a global IT company based in the West Midlands. As Testing consultant you ...

Implementation Consultant - Calypso or Murex experts required !!

Leading Investment banking consultancy is currently looking for a specialist implementation consultant to join their growing specialist department. ...

Discussions

harpless harpless

SAP goes big business

Friday 25 July 2008, 6:17 PM

1 comment
pjc158 pjc158

Will Drizzle rain on Sun's MySql

Friday 25 July 2008, 5:30 PM

1 comment

Featured Talkback

While full medical records may be of (dubious) value at rear/base medical facilities, these could be provided much simpler by either physical disk or electronic transfer to an "in theatre" database for individuals posted in. That £80m (and it's associated running costs) could have been far better employed in resuscitating a disbanded infantry battalion or providing a big boost in equipment quality and quantity.

By: 1000215420

Read full story:
Photos: MoD unveils £80m IT health programme