Code Red2 computer virus comes with an added punch

What is classified by many to be a new strain of the Code Red virus — quickly dubbed “Code Red II” — was detected just two weeks after the virus’ initial outbreak, and is affecting computers worldwide.

The CERT Coordination Center (CERT/CC) began receiving notifications of Code Red II infections on Saturday, August 4, according to the organization’s Web site.

Seifert Systems Invests in Energy Efficiency to Strengthen Operations

For manufacturers, energy is more than just another operating expense. It plays a critical role…

Learn More

CERT/CC studies issues of Internet security and vulnerability, and is located at the Software Engineering Institute, a federally funded research and development center located at Carnegie Mellon University.

CERT/CC estimates that 150,000 servers have been compromised by Code Red I and that in nine hours on July 19 alone, the worm infected more than 250,000 systems.

- Advertisement -

The total number of systems affected by Code Red is not known.

The Code Red virus was deployed from an unknown site to exploit a flaw in Microsoft’s Internet Information Server (IIS) to spread from server to server.

Once the Code Red worm infects a server (making it a “zombie”), it scans for other vulnerable servers and infects them (more zombies). During a certain period of time the worm only spreads, then on the 20th day of each month the zombies initiate a Denial-of-Service (DoS) attack against www1.whitehouse.gov to attempt to crash the site.

The White House has since moved its Web site.

The virus changes the home page of sites that it attacks to read, “Welcome to http://www.worm.com !, Hacked By Chinese!”

The scanning activity initiated by the worm slows the Internet.

The new strain of the virus is similar to Code Red I, but with an added punch: Code Red II installs a “backdoor” into the systems it infects by copying the standard Windows NT/2000 command interpreter “cmd.exe” into Web servers’ “scripts” directory.

While the Code Red II worm uses the same injection vector (vulnerability) as the first Code Red, according to the virus analysis on Internet security company eEye Digital Security’s Web site (www.eeye.com), because of the new worm’s “backdoor,” eEye does not consider it to be a variant.

Code Red is named by the eEye Digital Security team for the new flavor of Mountain Dew soda. eEye issued an early dissection of the worm. The company maintains a U.S. headquarters in Aliso Viejo, California.

“We’ve really encouraged people to apply the patches so they won’t be part of this,” said Steve Gottwals, director of product marketing for Espoo, Finland-based Internet security firm F-Secure (with a North American headquarters in San Jose, California).

The company maintains a detailed archive of computer viruses on its Web site www.europe.datafellows.com.

Gottwals said he wasn’t surprised by the latest outbreak and doesn’t think Code Red II will be as severe.

“It’s really common to see a massive infection right off the bat and then the word gets out,” he said. “The variants are really easy to write and people get infected again, but I’ve never seen a variant surpass the original infection.”

Users who have already applied the patch for the Code Red virus are not vulnerable to the new strain, Gottwals said.

According to the National Infrastructure Protection Center (NIPC) in Washington, D.C., more than one million individual software patches were applied during the first week the Code Red virus was deployed. The number of machines now protected is actually greater than that, as the software can be downloaded and installed on any number of machines.

But, according to the NIPC’s Web site, “we are still not out of the woods — it (Code Red) will be in infection mode until late August 19, 2001, when it switches to ‘attack’ mode. At that time, we will be better prepared to assess how well these efforts paid off.”

Orbidex, Inc. Chief Operations Officer Erik Petersen, who has been following Code Red developments, likened Code Red II to “finding out that somebody robbed your house, so you get a new lock — and a new door, even — not knowing that they have cracked the basement window downstairs.”

Once the cmd.exe file is there, Petersen said, “if you know how to use that program, you can do anything you want.”

Petersen agreed with Gottwals that Code Red won’t infect as many computers this time around, but said that because of the added backdoor, those hit with the new strain stand to sustain more site damage because of the administrative capabilities the worm enables.

In monitoring his network’s traffic, Petersen said he’s noticed particular scanning activity — many several times a day — on sites hit by the previous incarnation of Code Red.

“You better do more than just patch, because you’re going to get a lot of attention,” he said. “(Those infected in Code Red’s first outbreak) were hacked and therefore they must be hackable. It’s almost always reducible to a human element. They’re (hackers) always looking for the bad administrator.”

Petersen said that monitoring the company’s local network of computers revealed Code Red II scans every 20 minutes. The bottom line: “If you are vulnerable, you will be found,” he said.

Orbidex, Inc. continues to offer help, information and even humor on its Code Red the Web page, www.orbidex.org/codered.

No posts to display