ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security management Toolkit

Help & How-To: Code Red

Robert Vamosi ZDNet US

Published: 31 Jul 2001 09:33 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft and the National Infrastructure Protection Center (NIPC) today urged all users of Microsoft's IIS 4.0 and 5.0 to install a security patch to protect against Code Red. The worm, currently in a dormant phase, will re-awaken on 1 August, 2001 at 0:00 GMT, and is thought to be more dangerous the second time around. Code Red spreads by scanning the Internet for vulnerable IIS systems, and it is this scanning activity that has the potential to degrade service across the entire Internet. A patch issued by Microsoft removes the IIS scanning vulnerability in Windows NT and 2000. Users of Microsoft Windows 95, Windows 98 or Windows Me are not affected by the Code Red worm.

The Code Red worm, named after a high-caffeine cola from Mountain Dew, exploits a known vulnerability in ida.dll, a component of the Index Server that provides support for .ida and .idq files. In Microsoft's IIS 4.0 and 5.0, ida.dll is subject to buffer overruns, allowing a malicious user to exploit rogue code and gain access to the server. Microsoft originally posted a patch for this vulnerability on 18 June, 2001.

However, not all the affected IIS systems were patched. Within a few hours on 19 July, the Code Red worm spread to more than 250,000 machines worldwide. The worm, believed to have started at a university in Guangdong, China, searches out ida.dll vulnerable systems by choosing random Internet addresses and defaces some infected Web sites with the phrase "Hacked by Chinese." The original outbreak of the worm was to have launched a denial-of-service attack upon www.whitehouse.gov, but the White House changed its numerical address and avoided the attack. Code Red continued to spread from 20 July to 27 July when it went dormant.

Variations of the worm have been seen in the wild and reported to BugTraq. In a rare move, the government is joining with Microsoft to encourage all users of Windows NT and 2000 to install the security patch. Users of the beta version of Windows XP should contact Microsoft directly for more information.

The worm can be removed by rebooting an infected system, however, that solution does not guard against infection again at a later time. Therefore, Microsoft has a created a security patch for the following systems: Windows NT version 4.0 and Windows 2000 Professional, Server and Advanced Server. In addition, Symantec has a free tool to scan your system for signs of infection.

Additional information regarding the patch can be found on Microsoft's Web site. Also, Digital Island has detailed step-by-step instructions for installing the patches and safeguarding your system.

Is your PC safe? Find out in ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
13 out of 22 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Sentry Posts Blog

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

Post a comment

Trades Unions against ID Cards

The Trades Union Congress (TUC) has backed up airport workers protesting against ID cards, the Financial Times reports. In a letter to Home Secretary Jacqui Smith, the TUC said it... More

Post a comment

Kaspersky websites hacked while being...

Russian security vendor Kaspersky's nascent Malaysian website has been hacked and defaced. According to security site Zone-H.org, Kaspersky's website and online shop, which are under... More

1 comment

Featured Talkback

It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link

DOWNLOAD

Security Essentials

Security Downloads

There are masses of security suites out there for small businesses. Here's a selection to get you started

Editor’s Rating
1 Norton 360™
2 AVG Anti-Virus Free Edition Rating: 10
3 PC Tools AntiVirus Free Edition
4 Kaspersky Internet Security

See All Software

In association with Symantec