Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
Microsoft details 'Windows on ARM' program
March debut of 'iPad 3' a sure bet, says analyst
FBI unbolts Steve Jobs 1991 investigation file
Cisco boosted profit, sales in Q2 while cutting costs
Macs take on the enterprise
Four crazy tech ideas from Google's Solve for X project
Obama 2012 campaign playlist revealed courtesy of Spotify
Oracle buying Taleo for US$1.9 billion in direct hit at SAP
Amazon attacks Apple: You get 3 Kindle products for price of iPad 2
Pre-rendered pages highlight latest Google Chrome release
Microsoft exec: Lync-Skype integration a 'compelling opportunity'
The future of hypervisors
/

FBI, CERT, others warn of Code Red reawakening

Related linksToday's breaking news
Send to a friendFeedback


Bracing for the reawakening of Code Red, a malicious Internet worm, a number of U.S. government and private organizations on Sunday called on Web server administrators to ensure that their server software is up to date.

Describing the worm as "a real and present threat to the Internet," the organizations said in an unprecedented joint alert that Code Red is likely to start spreading again at 8 p.m. EDT Tuesday and that it has mutated so that it "may be even more dangerous." All of the data packets that Code Red generates can clog data pipelines and slow the Internet, disrupting business. Code Red first wreaked havoc on July 19.

The U.S Federal Bureau of Investigation's National Infrastructure Protection Center, the Computer Emergency Response Team (CERT) Coordination Center, the Federal Computer Incident Response Center, the Information Technology Association of America, the SANS Institute and Microsoft are among the issuers of the alert.

A new break out of Code Red is feared because the worm operates on a time clock. The first 19 days of a month the worm is set up to scan and infect, but from day 20 until day 27 the worm floods a certain IP address - in this case, the White House Web server - with information requests causing a denial-of-service attack. The Web server has since been given a new IP address.

Code Red is a self-propagating worm. It scans the Internet for vulnerable systems and infects these systems by installing itself. Once it has nestled itself on a server, it uses that server to scan the Internet for other vulnerable servers and infects those. Web pages on compromised servers are altered. In the first nine hours of its outbreak on July 19, Code Red infected more than 250,000 systems, according to the CERT.

The worm targets servers running Microsoft's Internet Information Server (IIS) software Versions 4.0 and 5.0. It exploits a buffer overflow vulnerability in the Indexing Service DLL of the Web server software. IIS is part of Windows NT and Windows 2000. A patch for the hole has been available since June 18.

The warning is warranted, according to Simon Leech, an Amsterdam-based security engineer for Network Associates.

"When the worm was first discovered, it infected servers for a couple days. Administrators had started patching servers, but may have stopped, thinking the threat was gone," he said. "We've got to make sure everybody applies the patch. We could be facing an Internet meltdown, depending on how many unpatched servers are out there. It's going to come down to how many vigilant administrators are out there."

More information on the IIS Indexing Service DLL flaw and the software fix are available on Microsoft's TechNet Web site:

www.microsoft.com/technet/security/bulletin/MS01-033.asp

CERT, in Pittsburgh, is at www.cert.org/

The NIPC, in Washington, D.C., is at www.nipc.gov/

The IDG News Service is a Network World affiliate.

Related Links

 
NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.