Web worm targets White House

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
Administrators for the Web site of president George W Bush dodged an Internet worm's denial-of-service attack by moving the site to an alternate Internet address, security experts said on Thursday. As previously reported, servers infected by the so-called Code Red worm -- estimated to be about 200,000 computers -- were scheduled to flood a specific Internet address representing the White House Web site with a deluge of data starting at 5pm PDT. However, administrators for Whitehouse.gov apparently moved the site to an alternate address. In addition, a flaw in the worm's design caused the tactic to fool the program into sending a much-reduced amount of data. White House spokesman Jimmy Orr said the White House took precautions, but would not confirm whether Internet addresses were switched. "We have taken preventative measures aimed at minimising the impact of any computer virus," he said Thursday night. Marc Maiffret, chief hacking officer for eEye Digital Security, said Whitehouse.gov administrators "blackholed" the original address -- meaning that any data sent to the address would disappear into the Internet. EEye originally found the flaw that the worm exploits. Computer worms are programs that have the ability to spread across Internet and execute instructions. In this case, the worm sought out vulnerable Web servers using Microsoft software. As for the instructions, the Code Red worm was written to flood the Whitehouse.gov site with a massive amount of data, overwhelming it to the point where it could not be accessed. Before Thursday, anyone who tried to view Whitehouse.gov in a browser would be directed to a specific numeric address, 198.137.240.91. Because of Thursday's change, however, people who went to Whitehouse.gov were automatically redirected to a new address, 198.137.240.92. Computers infected with the worm -- hard-wired to spam the original address with data -- weren't redirected to the new location. Maiffret, who warned earlier on Thursday that the White House site was the target of the worm, also noted that the flood of data flowing across the Internet during the attack could degrade the overall performance of the Net. However, the data flood never occurred because the worm checked for a valid connection before sending data -- what could be considered a design flaw on the part of the author. Because the site's address was switched, the worm never established a connection and therefore did not begin sending data. "You might have overload on the local networks where the worm was trying to get out, but the actual Web site looks okay," Maiffret said. Others besides Maiffret warned of the potential for worm problems Thursday as well. The Computer Emergency Response Team (CERT) Coordination Centre issued an advisory predicting that the worm could cause performance problems on the Net. "In addition to Web site defacement, infected systems may experience performance degradation as a result of the scanning activity of this worm," CERT stated in its advisory. "Non-compromised systems and networks that are being scanned by other hosts infected by the 'Code Red' worm may experience severe denial of service." Belatedly, the National Infrastructure Protection Center -- the FBI agency responsible for protecting critical components of the US intrastructure, such as the Internet -- released an advisory warning companies of the worm Thursday evening, after the incident at Whitehouse.gov. After slowing down earlier in the week, the Code Red worm spread wildly on Thursday, possibly due to someone modifying the code. In addition to making the code spread faster, the person who changed the code may have made another important modification. The original creator of Code Red apparently created the worm to stop spreading at midnight Friday morning coordinated universal time (UTC), or 5pm PDT Thursday, and to attack the Whitehouse.gov site with a distributed denial-of-service attack. At that time the worm would stop spreading. Yet Thursday evening, some early reports indicated that some infected machines continued to spread the worm. Even Microsoft, which recently issued a patch to prevent the worm from infecting servers using its software, failed to protect all its servers. On Thursday, the company acknowledged that a "small number of servers" were infected by Code Red. "We have investigations going on to look at other reports," said Scott Culp, security program manager for Microsoft's security response centre. Culp stressed that although their may be a lull in probes from the worm, customers still need to patch the servers. "Our recommendation now is the same as our recommendation a month ago," he said. "If you haven't patched your software, do so now." Until 20 July, the worm is programmed to spread to new servers, according to eEye's analysis. From 20 July to 28 July, the worm will attack the now-outdated address for the White House Web site. If system administrators don't patch their systems on 1 August, they could be re-infected with the worm, starting the whole process over again. Is your PC safe? Find out in ZDNet UK's Viruses and Hacking News Section. Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum. Let the editors know what you think in the Mailroom. And read other letters.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

bootlegger

Make that 13 people now - I got refused today at Manchester airport. I thought I was up to date on this legislation - I knew of the EU ruling from...

2 hours ago by bootlegger on UK airport body scans will not be opt out
tinycg

Don't forget to check out apps like GoodReader or SlideShark either, they're indispensible for people on the go in presentation situations. Best...

5 hours ago by tinycg on Four top iPad apps for people on the move
TerryRK

Well it seems there is something a number of us agree on. Why is the Ubuntu Unity launcher so ugly? I thought perhaps it was something to do with...

9 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

19 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

1 day ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

1 day ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

1 day ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

1 day ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

1 day ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

2 days ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

2 days ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

2 days ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

2 days ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

2 days ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

2 days ago by bdantas on A tale of two distros: Ubuntu and Linux Mint