July 18, 2001 1:35 PM PDT

"Code Red" worm claims 12,000 servers

Related Stories

Microsoft reveals Web server hole

June 18, 2001

Year of the Worm

March 15, 2001
Almost 12,000 Web servers have been infected by a new Internet worm that takes advantage of a security flaw in Microsoft software to deface sites, security experts said Wednesday. The worm could also help attackers identify infected computers and gain control of them.

Known as the "Code Red" worm because of evidence that it may have been launched from China, the self-spreading program infects servers using unpatched versions of Microsoft's Internet Information Server software and defaces the Web sites hosted by the servers.

The code is still being analyzed to see if it does any further damage. But the way the worm is written, it could allow online vandals to build a list of infected systems and later take control of them, said Marc Maiffret, chief hacking officer with eEye Digital Security.

"It is a very slick worm," Maiffret said. "Until all these people go out and patch their systems, it will keep going."

eEye found the vulnerability in Microsoft's software--the so-called index-server flaw--last month and reported it to the software giant, which acknowledged the flaw June 18 and posted a downloadable fix on its Web site. Microsoft urged people to patch the hole before the Internet underground could produce tools to take advantage of the estimated 6 million vulnerable systems.

"Obviously, not a lot of people patched it," Maiffret said. "Even with the press, a lot of people didn't hear about it."

System administrators first detected the Code Red worm this past Friday.

Code Red worm sounds off The worm spreads by selecting 100 IP addresses, scanning the computers associated with them for the hole, and spreading to the vulnerable machines. The worm then defaces any Web site hosted by the server with the text:

Welcome to http://www.worm.com!
Hacked by Chinese!

Code Red seems to deface only English-language servers, going into hibernation on non-English versions of Microsoft's IIS software.

Believing that Worm.com acted as a collection point for information sent from compromised servers, Microsoft has successfully requested that Worm.com's Internet service provider pull the plug on the site. If Worm.com had built such a list, it could have allowed online vandals to target computers known to be vulnerable.

"That site was a collection point for data about what sites had been compromised," said Scott Culp, security program manager for Microsoft's security response center. "By taking it down, it prevents the malicious individual that created the worm from getting that information. It doesn't prevent the worm from spreading."

But according to eEye's Maiffret, removing Worm.com from the Web will probably have no effect, because the way Code Red is programmed can allow anyone--including an online vandal or malicious hacker--to make a list of every system that has been compromised.

That's because each instance of the worm will attack the same computers in the same order, according to eEye's analysis. Maiffret said that while the addresses of the computers attacked by the worm seem to be random, because the worm uses the same starting point, or "seed," to generate the list, the "random" lists that any two worms generate are identical. Like identical genes, which produce a clone, identical seed numbers produce attack lists that are the same.

see special report: Year of the Worm That means any computer on the "randomized" list will be attacked by every newly infected computer. By monitoring who attacks a target machine, a list of attacking--thus infected--computers can be made.

One eEye client has done just that, said Maiffret, and found that almost 11,900 servers had been infected as of 7 a.m. PDT Wednesday. Unlike other worm attacks, where the actual number of infections can only be estimated, these numbers correspond to the actual infections, he said.

Unfortunately, if attackers have access to a machine on the target list, they, too, can make a list of compromised machines. Later, an attacker can use the list to take control of the servers.

For system administrators who have not patched their systems, now would be a good time, said Microsoft's Culp.

"We are going back out to customers and telling them that if they didn't put the patch on before, this is all the reason they need to put the patch on now," he said.

Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
What you need in business class email.
Mailtrust

Click Here!
Never worry about email again. From mobility and shared calendaring to virus and spam protection starting at only $3 per mailbox. more>

Rackspace Mailtrust
Total Email Relief

We'll take care of your email so you can take care of your business.

14 Day Free Trial

With expert support 24x7x365 we guarentee 100% uptime. Try us for free for 14 days. Never worry about your email again.

Just $3 per mailbox

Choose the plan that is right for your company and only pay for what you need.

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement
Rackspace

Inside CNET News

Scroll Left Scroll Right
  • Nanotech: The Circuits Blog

    SanDisk stock surges on buyout rumors

    Stock for flash memory maker SanDisk is up on rumors that a buyout by Samsung is in the works.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • The Open Road

    Analysts as a lagging indicator of success

    Gartner, Forrester, and other analyst firms tend to be great predictors of the past, probably because that's where they get their money.

  • Outside the Lines

    EIC Squared: Chrome, iPods, and a Dell-Salesforce union

    On this week's EIC Squared podcast CNET's Dan Farber and ZDNet's Larry Dignan discuss Google's latest rocket launch--the Chrome browser--as well as Apple's iPod event next week and a Dell-Salesforce.com union.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Wireless

    Start-up launches spectrum marketplace

    A new company called Spectrum Bridge has launched a Web site for buying and selling wireless spectrum licenses.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Photos: Future Combat Systems, here and now

    The U.S. Army has ambitious plans for a widespread high-tech refresh of its vehicles and other soldier gear. It's also finding a way to make some parts happen sooner rather than later.

  • Crave

    Leaked specifications of the LG Prada II

    Leaked specifications of the LG Prada II.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.