Code Red: Alive again and kicking

NEWS The Code Red worm made a quiet comeback Wednesday, with no signs yet of a predicted traffic surge that could affect the functioning of the Internet. As of 9 pm BST on Wednesday, Code Red had infected servers responsible for at least 127,000 Web sites, according to the SANS Institute, a computer security think-tank. New infections were happening at the rate of more than 50,000 per hour, although the rate of growth had slowed markedly. Network administrators and security experts originally braced for a slowdown shortly after 1 am BST on Wednesday, when the worm was set to emerge from an inactive state and flood the Internet as it searched for new servers to infect. Most Web sites were functioning normally late Tuesday and early Wednesday. But exactly how many servers the worm will send itself to -- and therefore how fast it spreads -- was still being debated by security experts. The Computer Emergency Response Team (CERT), a Carnegie Mellon University organisation that tracks security issues, said in a statement issued Wednesday morning that it has "begun receiving reports of increasing Code Red scanning activity". The FBI's National Infrastructure Protection Center (NIPC) also projected the worm to be spreading at a rapid clip. "Based on our preliminary analysis, we expect to see the activity of this particular worm to compare to the 19 July infection," said Deborah Weierman, a spokeswoman for government's National Infrastructure Protection Centre. "At the time, it resulted in over 250,000 infections on systems. Today, we believe that should be achieved by this afternoon." The FBI was expected to make a statement late Wednesday about whether the worm has continued to spread or had any impact in slowing down the Internet. The agency said early Wednesday that its initial impact has been minimal. "Early reports of activity spanning the entire globe, including the United States, indicate that the worm has gone active and is presently spreading throughout the Internet," the FBI said in a statement issued Wednesday morning. "We are hopeful that the many precautions taken by the public, the government and private industry will have some effect on its ability to propagate." The Code Red worm -- named after a hypercaffeinated, cherry-flavored Mountain Dew drink popular with computer programmers -- infected servers around the world last month and launched a massive denial-of-service attack against the White House's Web site. The worm only infects computers running the Windows NT and Windows 2000 operating systems and Microsoft's Internet Information Server (IIS) Web server software, meaning few home PCs are vulnerable to the attack. But the worm could disable some e-commerce sites or slow down the overall speed of the Internet by bombarding sites with data. As originally reported by CNET News.com, the Code Red worm takes advantage of a hole in IIS. Code Red was thought to have infected as many as 359,000 systems within about six days during its original attack in July, making it one of the fastest-spreading worms ever. While Microsoft quickly released a widely distributed patch for the IIS hole, it's unclear how many system administrators have downloaded and installed the fix. Microsoft has estimated that servers responsible for some 6 million Web pages have the vulnerability. The worm remains active between the first of the month and the 28th, when it goes into hibernation. While the worm does not reactivate itself automatically, any computer vandal sending a copy of the worm once the active period begins -- most recently at midnight GMT 1 August, or 1 am BST on Wednesday -- would start a new round of infections. On the 20th of the month, the worm is set to switch to attack mode and barrage an Internet address originally associated with the White House Web site with large packets of data. While many security experts warned of potential Internet outages due to the revived worm, others maintained the worm is not spreading as quickly as once feared. Instead of an exponential or logarithmic spreading method, some say the worm is spreading at a slower, geometric rate. Rob Rosenberger, editor of the Vmyths.com news service, said the alarm surrounding Code Red is largely undeserved, but he acknowledged that the Internet is not quite "out of the woods" in terms of the danger that Code Red could inflict on it. He says the next 12 to 24 hours will be key because it appears as though the worm is spreading geometrically, infecting two computers, then four, then eight. "What's been lost in the mix here is that Code Red is a geometric rise," said Rosenberger, who has been one of the most outspoken critics of the FBI, Microsoft and conventional security companies in their response to the worm. "I still believe that I'm right and this never should have reached the level of hysteria it did. But I won't be right for 24 hours." Worms have become the tool of choice among malicious vandals on the Internet, but the Code Red strain has proven especially fast and effective. Unlike other worms that hide in email attachments, such as Love Letter and SirCam, Code Red does not require fooling an unwitting recipient into opening an email document. Several experts said Code Red was the most nefarious worm they've seen since the Cornell Internet Worm, which overloaded an estimated 3,000 to 4,000 servers, or about 5 percent of those connected to the early Internet, in November 1988. The worm, which exploited flaws in Unix systems, was written and released by Robert T. Morris, a Cornell University graduate student, and is also called the Morris worm. A new version of Code Red could mean it will be more virulent its second time around, launching a data flood that could potentially overwhelm many servers over the next few days. The original worm looked for servers to infect by targeting a single Internet Protocol (IP) address, the unique string of numbers that identifies computers on the Internet. But a second version may have a so-called "random seed" that could hunt down Web sites even after they've changed IP addresses, making it harder to avoid attack. Despite its more virulent nature, it's unclear exactly how many unpatched servers are still vulnerable to the worm. Douglas Conorich, global solutions manager for IBM's managed security services in Dallas, said that about half of IBM's corporate customers were vulnerable to the original attack. But IBM quickly alerted its customers of the patch and no customers were infected, Conorich said. He also said they've installed a patch that will guard against several new vulnerabilities likely in a second outbreak. "They skated through, luckily," Conorich said of his customers. "But the danger was there. This was a very unusual one in that it only took the hackers a month from the time the vulnerability was discovered until they did something. Usually it takes six to seven months before a hacker comes out with an attack against a vulnerability, and that gives people some time." Although IBM's customers are reportedly safe, small businesses and those that don't have contracts with large computer consulting companies may have more to fear. John B. Butler Jr., president of LiveVault, estimated that 3 million Windows servers in the United States -- mainly at small businesses and remote branch offices -- do not have professional IT support. It's likely that a large percentage of these "stranded" servers are vulnerable, Butler said. Code Red also can damage smaller networks by calling attention to a vulnerability in Cisco System's 600 series DSL routers. The worm could cause the router to stop forwarding traffic. Although many small businesses may be in danger of attack, home computer users have little to fear. The worm does not connect to individual PCs running Windows 95, 98 or Me. Only Windows NT and Windows 2000 Web servers running IIS can be infected with this worm. Although it won't infect home computers, users may experience extreme delays or malfunctioning of their favourite Web sites because of traffic generated by the worm. attacks. Because of that and the danger it poses to Microsoft Web servers, Microsoft, federal security agencies and trade groups hosted a globally televised press conference Monday to urge businesses to install a software patch that prevents infection. It's unlikely that the worm will do permanent damage. The worm doesn't destroy data, though future generations of it could be modified to do so. Only computers set to use the English language have had their Web pages defaced, typically with the message, "Hacked by Chinese". (The first Net address from which attacks emanated in the July episode was determined apparently to be from Foshan University in China, although a Chinese network safety official denied those allegations on Tuesday.) It's also unclear how long the worm will live. Guarding against the worm is a relatively straightforward matter of installing a Microsoft software patch that prevents any malicious program from taking advantage of the IIS hole. Because Code Red is memory-resident -- it lives in the server's volatile physical memory rather than on a hard drive or other permanent storage -- rebooting wipes out the infection. The software patch prevents re-infection. In theory, if every server were patched, the worm would die. Otherwise, it could continue its monthly cycle of hibernation and attack. The most recent statistics from Microsoft show that more than 1 million people have downloaded the patch. The idea of installing a patch is simple, but many companies do not do so -- sometimes because the patch ends up causing other problems to the corporate system. Conorich said it's not uncommon for servers to lose credit card or other personal data immediately after receiving a patch, causing e-commerce transactions to be erased. Microsoft last month released two faulty patches for a flaw in its Exchange email server software. See also: ZDNet UK's Code Red News Roundup. Is your PC safe? Find out in ZDNet UK's Viruses and Hacking News Section. See the Internet News Section for full coverage. Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum. Let the editors know what you think in the Mailroom. And read other letters.

Post your comment

In order to post a comment you need to be registered and logged in

Log in or create your ZDNet UK account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Membership FAQ

ZDNet UK Live

sgardia

You are quite right. HDS has not been marketing their products well. USPV is miles ahead in terms of ease of use and technology on enterprise...

4 hours ago by sgardia on Will the SUN set on Hitachi Data Systems OEM relationship?
apexwm

Fedora is the same way as well. The yum update system uses "presto" which shrinks the amount of data needed for download. It's a great system....

15 hours ago by apexwm on Can you believe it - 2765 kB will be freed?
cybfor

Updated ID cards considered for 2012: [zdnet.co.uk] The government is considering introducing a new generation of ID... http://dlvr.it/KpBZ

cybfor

Google, Viacom trade blows in YouTube copyright spat: [zdnet.co.uk] Google and the US media giant Viacom have issued... http://dlvr.it/Knht

CIMITL

Be sure to include an audio option - eg. a beep tone - to intensify and reiterate the action. This will greatly benefit some consumers and give...

16 hours ago by CIMITL
DataSecurityUK

Data disposal is really important to get right. There are standards set by UK and US federal governments to ensure that data is kept secure. If...

17 hours ago by DataSecurityUK
chaycon1

Online Fiber Optic Certification Join a talented group of professionals, who are dedicated to Fiber Optic Networking technology. The online course...

19 hours ago by chaycon1 on BT launches 40Mbps fibre-based broadband
chaycon1

Online Fiber Optic Certification Join a talented group of professionals, who are dedicated to Fiber Optic Networking technology. The online course...

19 hours ago by chaycon1 on Google to build gigabit broadband to the home
J.A. Watson

Hi Dava, I'm glad to hear from you, and glad that you see things from the other side. I think that is the most important point of the whole...

19 hours ago by J.A. Watson on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

please please please please please please kill that spam bot.

20 hours ago by dava4444 on ZDNet UK: faster, smarter, still IT all the way
253chelisa253

hi

20 hours ago by 253chelisa253 on How security will look in 10 years
lezlow

it is only greedy[microsoft]?

22 hours ago by lezlow on Researchers break into BitLocker
dava4444

it didn't post the link it's 'Ubuntu 10.04 Lucid Lynx Beta-1 First Look' on youtube :) Dava

23 hours ago by dava4444 on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

Hi James I disagree, Ubuntu needs a GUI update and this one IMO is quite good. your pics show a low res. here's a high res. on YouTube* The...

23 hours ago by dava4444 on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

Hi any news on the comment bot? knocking me back from my own blog is a bit cheeky lol *Mulder to Scully* "I think it has an agenda.." I know, I...

24 hours ago by dava4444 on ZDNet UK: faster, smarter, still IT all the way
benny boy

if you look at the Brentwood exchange on samknows it servers 21,000 residential propertiesm, Lowestoft serves 31,000! Come on BT sort yourselves...

1 day ago by benny boy on BT fibre broadband coming to 69 more towns
pbreddit

[programming] H.264 - a sting in the tail http://reddit.com/bfu4q [zdnet.co.uk]

reddit

H.264 - a sting in the tail [programming] 13 points, submitted by zigzag [zdnet.co.uk] http://reddit.com/bfu4q

cybfor

Malware infects second Vodafone HTC phone: [zdnet.co.uk] A second Android-based HTC Magic from Vodafone has been... http://dlvr.it/KhKx

miyabi81

Chatter preview http://www.zdnet.co.uk/news/application-development/2010/03/17/salesforce-opens-up-chatter-developer-preview-40088348/

Featured white papers

Achieving PCI Compliance for:Privileged Password Management & Remote Vendor Access

For multi-store outlets, including retail, banking, grocery, gas, hospitality, convenience stores and others, reducing (or avoiding) the cost of in-store system support and maintenance while maintaining compliance with PCI and other requirements has become a strategic challenge.

Download now

Web 2.0 Security Threats: How to Protect Your Enterprise Network

Speaker: Dr. Chenxi Wang, Principal Analyst, Security and Risk Management, Forrester Research, Inc. As Enterprises are increasingly connected to the Internet and as hard organizational boundaries are fast disappearing, security professionals are facing fresh challenges in Enterprise computing.

Download now

MindManager - Tutorial for New Users - Short

This tutorial is for new MindManager users and teaches you how to get started, by creating maps, reading maps and organizing your information.

Download now