ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Application development Toolkit

Code Red remains a major threat

Published: 07 May 2002 09:04 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security researchers presented data on Friday indicating that Code Red version 2, a 9-month-old worm, continues to spread slowly across the Internet, compromising computers and leaving them easily accessible to malicious attackers.

At present, more than 18,000 systems appear to be infected and, with a simple command, could be co-opted into an attack that could take down any Web site, said Dug Song, a hacker and security architect for network protection firm Arbor Networks. Song was speaking at the CanSecWest security conference in Vancouver, British Columbia.

"We are mostly concerned with the potential for a major distributed denial-of-service (DDoS) attack using the Code Red servers," Song said. A DDoS attack uses many computers to send a flood of data at a single target, overwhelming the victim's connection, effectively cutting the victim off from the Internet.

Song presented the results of Arbor Networks' seven months of monitoring a large portion of the Internet. Code Red version 2 -- a variant of the original Code Red worm that fixed a bug in the program's infection routines -- has infected more than 18,000 computers as of April, up from around 14,000 computers in December, Song said.

Code Red and its two variants use a security hole in Microsoft's flagship Web server -- the Internet Information Server -- to spread to computers that don't have the vulnerability patched. As servers are infected with Code Red, the worm then scans the Internet using specially formatted data, searching for more vulnerable servers.

The original Code Red had spread slowly -- until the modification -- and then flooded the Internet, reaching more than 350,000 servers in less than 24 hours, according to data collected by the Cooperative Association of Internet Data Analysis.

Computer security response teams succeeded in stemming the tide, but weren't able to eradicate the worm, Song said. In total, Arbor has found more than 5 million unique Internet addresses that appear to have been infected with Code Red in the past six months and another 1.7 million that have been infected with Nimda.

Today, Arbor's monitoring system still receives nearly 30 probes by infected Code Red servers every minute, Song said. Nimda, a worm that struck a month after Code Red and borrowed several of its tricks, has also stuck around but appears to be slowly disappearing. The original Code Red, and the third variant known confusingly as Code Red II, have both seemingly died off.

Alfred Huger, vice president of engineering at vulnerability information firm SecurityFocus, said the company's own monitoring system also continues to detect both Nimda and Code Red.

Huger shares Song's concern that the infected machines can be used as a made-to-order attack network for malicious hackers.

"Having that many compromised machines... They are just begging to be used in an attack," Huger said.

Online vandals, even those without much technical knowledge, could listen to the "noise" on the Internet, collecting a list of infected machines attempting to send data to their computers. Then attackers would use that list and send a simple command to each Code Red-infected computer, and the security-compromised system would do their bidding.

Solving the problem is not easy, Song said.

"If we try to shut down the systems, when they are turned on, they will just start spreading the worm all over," Song said.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
30 out of 93 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Production Services Analyst- North West

Production Services Analyst - St Davids Park, North West RESPONSIBLE FOR: The Production Services Analyst (PSA) is primarily responsible for ...

Senior Technician (Web Developer) - Warwick

Job Title: Senior Technician (Web Developer - SoftGrid, SMS, SCCM, DNS, SharePoint 2007, SCOM, Internet Filtering & Monitoring) Salary Scale: 18,907 ...

Service Delivery Manager - Information Management & Regional Information Office (IM & RIO)- IT Manager - Various Locations

Excellent understanding of service delivery and setting of service levels Flexibility to adjust to changing business requirements Command of ...

Discussions

harpless harpless

SAP goes big business

Friday 25 July 2008, 6:17 PM

1 comment
pjc158 pjc158

Will Drizzle rain on Sun's MySql

Friday 25 July 2008, 5:30 PM

1 comment
pjc158 pjc158

Show me the money!

Friday 25 July 2008, 5:18 PM

5 comments

Featured Talkback

The fact is: Software developers today are really designers and not coders. The reason that business anlaysts exist today to model solutions is because they understand the value of designing software before writing it. All too often developers create code that has little value because they do not understand that business classes interact with other classes within the confines of a working model or pattern.

By: 1000165269

Read full story:
Making sense of agile modelling