Code Red is here to stay

By Wendy McAuliffe, ZDNet UK
27 August 2001 08:32 AM
Tags: code red, thompson, worm, variant, machine
Code Red will be around 'forever', warns the security expert who has detected a new variation of the Code Red II worm.

A new permutation of the Code Red II worm was discovered on Friday, and experts say that Code Red is now unlikely ever to disappear.

The new variant has been dubbed CodeRed.d, and exploits the same Index Server flaw in Microsoft's Internet Information Server (IIS) software as the initial Code Red. According to Roger Thompson, technical director of malicious code research at anti-virus firm TruSecure, who detected the variant, the appearance of a new worm indicates that we are stuck with the Code Red problem "forever".

"This is pretty much noise level for Code Red II and CodeRed.d -- it's not going to get any better or worse, and will stay like this forever," said Thompson. "Those machines that have not yet been patched never will be, meaning that the worm is here to stay."

CodeRed.d is nearly identical to its predecessor, except for two minor pieces of code that make it slightly more malicious. Code Red II used a self-recognition string of code that prevented it from re-infecting the same machine -- but in the new variant, the string of code is replaced with underscore characters, meaning that both Code Red II and CodeRed.d can re-infect the same machine at once. "People won't notice, but it will be banging out twice as many attempts to attack other PCs," said Thompson. "It randomly selects a range of addresses to attack other machines -- each worm will be churning out 300 threads to try and infect 300 different addresses at any one time."

And CodeRed.d can target a greater spread of IP addresses than could earlier versions of Code Red, said, added Thompson. "But this is mitigated by those who have patched their machines."

Thompson discovered CodeRed.d after writing his WormCatcher programme, which monitors for traffic on a Web server's port 80, and immediately detects any unknown worm variants. The first report of the new Code Red II permutation came from New Zealand, followed by a second from the US. "I am now getting 10 hits an hour of reported catches -- but I suspect that this figure would have been much higher last month when few people has installed the Microsoft patch," said Thompson.

According to Thompson, four to five new worms are created by accident on the Internet every day -- but CodeRed.d was intentional. "This didn't happen by accident -- someone was trying to get Code Red to go again, and we will be seeing more variations of this worm," Thompson warned.

Advertisement

Talkback 2 comments

    I have a solution to the code ...Anonymous -- 30/08/01

    I have a solution to the code red virus. Call it an antivirus. Why doesn't someone write a virus that behaves just like code red, but instead of being malicious, it displays a friendly warning to the infected web server's administrator about the problem and how to fix it. Or maybe even just automatically install the fix itself. In order for this to work, there would have to be a waiting infection period of about a month to allow the worm enough time to propogate to other vunerable systems. If a worm can identify a security hole and use it for bad, why can't a worm be developed to identify a security hole and use it for good - auto-repair?

    I'm a Unix Admin. If I had pu ...Anonymous -- 03/09/01

    I'm a Unix Admin.
    If I had public servers then I'd be keeping an eye on them and patching the servers myself. it is the ONLY way servers become secure [apart from pulling the plug, etc...!] Its just part of the daily routine. So if I found that I had a security hole that is being used for "good" or "evil" then this isn't curing the problem - more like putting an Elastoplast over it.
    What if the spread of CodeRed.d (or whatever variant) is greater than the patch version then you aren't solving the problem - just slowing it down.

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured