ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Web worm targets White House

Published: 20 Jul 2001 10:16 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Administrators for the Web site of president George W Bush dodged an Internet worm's denial-of-service attack by moving the site to an alternate Internet address, security experts said on Thursday.

As previously reported, servers infected by the so-called Code Red worm -- estimated to be about 200,000 computers -- were scheduled to flood a specific Internet address representing the White House Web site with a deluge of data starting at 5pm PDT.

However, administrators for Whitehouse.gov apparently moved the site to an alternate address. In addition, a flaw in the worm's design caused the tactic to fool the program into sending a much-reduced amount of data.

White House spokesman Jimmy Orr said the White House took precautions, but would not confirm whether Internet addresses were switched.

"We have taken preventative measures aimed at minimising the impact of any computer virus," he said Thursday night.

Marc Maiffret, chief hacking officer for eEye Digital Security, said Whitehouse.gov administrators "blackholed" the original address -- meaning that any data sent to the address would disappear into the Internet. EEye originally found the flaw that the worm exploits.

Computer worms are programs that have the ability to spread across Internet and execute instructions. In this case, the worm sought out vulnerable Web servers using Microsoft software. As for the instructions, the Code Red worm was written to flood the Whitehouse.gov site with a massive amount of data, overwhelming it to the point where it could not be accessed.

Before Thursday, anyone who tried to view Whitehouse.gov in a browser would be directed to a specific numeric address, 198.137.240.91. Because of Thursday's change, however, people who went to Whitehouse.gov were automatically redirected to a new address, 198.137.240.92. Computers infected with the worm -- hard-wired to spam the original address with data -- weren't redirected to the new location.

Maiffret, who warned earlier on Thursday that the White House site was the target of the worm, also noted that the flood of data flowing across the Internet during the attack could degrade the overall performance of the Net.

However, the data flood never occurred because the worm checked for a valid connection before sending data -- what could be considered a design flaw on the part of the author. Because the site's address was switched, the worm never established a connection and therefore did not begin sending data.

"You might have overload on the local networks where the worm was trying to get out, but the actual Web site looks okay," Maiffret said.

Others besides Maiffret warned of the potential for worm problems Thursday as well.

The Computer Emergency Response Team (CERT) Coordination Centre issued an advisory predicting that the worm could cause performance problems on the Net.

"In addition to Web site defacement, infected systems may experience performance degradation as a result of the scanning activity of this worm," CERT stated in its advisory. "Non-compromised systems and networks that are being scanned by other hosts infected by the 'Code Red' worm may experience severe denial of service."

Belatedly, the National Infrastructure Protection Center -- the FBI agency responsible for protecting critical components of the US intrastructure, such as the Internet -- released an advisory warning companies of the worm Thursday evening, after the incident at Whitehouse.gov.

After slowing down earlier in the week, the Code Red worm spread wildly on Thursday, possibly due to someone modifying the code.

In addition to making the code spread faster, the person who changed the code may have made another important modification.

The original creator of Code Red apparently created the worm to stop spreading at midnight Friday morning coordinated universal time (UTC), or 5pm PDT Thursday, and to attack the Whitehouse.gov site with a distributed denial-of-service attack. At that time the worm would stop spreading.

Yet Thursday evening, some early reports indicated that some infected machines continued to spread the worm.

Even Microsoft, which recently issued a patch to prevent the worm from infecting servers using its software, failed to protect all its servers. On Thursday, the company acknowledged that a "small number of servers" were infected by Code Red.

"We have investigations going on to look at other reports," said Scott Culp, security program manager for Microsoft's security response centre.

Culp stressed that although their may be a lull in probes from the worm, customers still need to patch the servers.

"Our recommendation now is the same as our recommendation a month ago," he said. "If you haven't patched your software, do so now."

Until 20 July, the worm is programmed to spread to new servers, according to eEye's analysis. From 20 July to 28 July, the worm will attack the now-outdated address for the White House Web site.

If system administrators don't patch their systems on 1 August, they could be re-infected with the worm, starting the whole process over again.

Is your PC safe? Find out in ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
53 out of 91 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Project Manager - (Web, e-commerce)

Project Manager to work for a successful Software House. Our client has developed a unique technology platform delivering significant benefits to ...

Market Risk Analyst Energy Major (55K)

This role will give you excellent exposure to a number of markets including coal and freight, UK power, spark and dark spread, the UK-France ...

NIHR/UK Clinical Research Network

It also aims to develop and implement integrated research and development management systems that will support researchers and NHS administrators ...

Discussions

harpless harpless

SAP goes big business

Friday 25 July 2008, 6:17 PM

1 comment
pjc158 pjc158

Will Drizzle rain on Sun's MySql

Friday 25 July 2008, 5:30 PM

1 comment
pjc158 pjc158

Show me the money!

Friday 25 July 2008, 5:18 PM

5 comments

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal