Heads Up..."code red" worm may re-emerge

River Runner

New member
Got this from Pam Mathers of the National Trappers Association Monday July 30 3:54 PM ET
~~~~~~~~~~~

'Code Red' Worm May Re-Emerge on Internet Tuesday
By Deborah Zabarenko

WASHINGTON (Reuters) - The fast-spreading ``Code Red'' Internet worm, which
disrupted U.S. government Web sites last week, is likely to start
multiplying again on Tuesday and could slow down the Internet, officials
said on Monday.

Code Red, which first surfaced on July 19, could slow down the Internet
worldwide if it re-emerges as expected at 8 p.m. EDT Tuesday, according to
the FBI's National Infrastructure Protection Center (NIPC) and other online
security watchers.

``There is reason for concern that mass traffic associated with the worm's
propagation could degrade the overall functioning of the Internet and impact
ordinary users,'' said NIPC Director Ronald Dick.

Computers running the Windows NT or Windows 2000 operating systems and
Microsoft's Internet Information Server (IIS) software version 4.0 or 5.0
are vulnerable to infection and the users should install a software patch.
Instructions for the patch are available at www.digitalisland.net/codered.

Computer users running Windows 95, Windows 98 or Windows Me are less
vulnerable, and no action was recommended for them.

The worm, named for a caffeinated soft drink favored by computer
programmers, installs itself on server computers that then are instructed to
blitz government Web sites and others with data, which can slow them down.

``What makes this one different from any other is how dramatically ... it
has been able to propagate itself and the viciousness associated with
that,'' Dick told a news conference held by government and industry security
experts.

The worm can also deface sites, Some of the affected government sites
display the message ``Hacked by Chinese.''

It scans the Internet, looking for other computers to infect, and as more
and more computers are infected the scanning gets more widespread.

``This uncontrolled growth in scanning directly decreases the speed of the
Internet and can cause sporadic but widespread outages among all types of
systems,'' the online security watchers said in a joint statement.

NEW VERSION MAY BE WORSE

The version of Code Red that could re-emerge on Tuesday ''has mutated so
that it may be even more dangerous,'' the statement warned. ``This spread
has the potential to disrupt business and personal use of the Internet for
applications such as electronic commerce, e-mail and entertainment.''

The warning was posted by Microsoft Corp., the FBI center, Carnegie Mellon
University's Computer Emergency Response Team (CERT) and other groups.

While the White House Web site managed to avoid disruption when the worm
surfaced on July 19, the Pentagon temporarily cut off public access to
hundreds of its Web sites on July 23 to guard against it. Public access was
restored to the Defense Department sites on July 24.

Dick noted that on July 19 alone the worm had infected more than 250,000
computer systems in just nine hours and it was estimated it could affect
500,000 Internet addresses in a day.

He said it was up to the users of the Internet to take the measures needed
to secure the net from such worms and viruses.

``For us to have a safe Internet the public at large has to institute
appropriate security measures, of downloading appropriate fixes to various
products, making sure that their anti-virus software is continually
updated,'' he said.

The worm enters computers when users try to access a Web page, said Roman
Danyliw, an Internet Security Analyst at CERT.

``It comes in over the same exact channel that you would use to request a
page,'' Danyliw said in a telephone interview from Pittsburgh. ``It's going
to a particular Web server, it talks the same language that your browser
would be, but this time it inserts this malicious payload, this thing that's
going to cause the particular server to be infected.''

It does this by exploiting a vulnerability in the IIS software, he said.
~~~~~~~~~~~~~~

~River Runner~


------------------
predatorlogo3jpg.gif

www.predatormasters.com
 
It has already hit the North Texas Health Sciences Center here in San Antonio. They are saying to stay away from sites that are part of a network today. It appears that unless you are running NT or Windows 2000 you are reasonably safe.

Bob C.

------------------
“No man shall ever be debarred the use of arms. The strongest reason for the people to retain the right to keep and bear arms, is as a last resort, to protect themselves against tyranny in government.”
Thomas Jefferson, June 1776
 
Back
Top