| Code Red: Internet Armageddon? | ||||||||||||
| Wily Worm Wallops the Web | ||||||||||||
Twenty-one percent of the servers driving the Internet are vulnerable to an insidious worm threatening an Internet meltdown when the date changes to July 20, 2001. The worm takes advantage of a serious security hole identified by eEye Digital in June, 2001. At the time of that discovery, Microsoft® released a heavily publicized patch. However, current worm activity indicates that at least twelve thousand systems failed to heed the advice and are now poised to attack www.whitehouse.gov. Security experts fear the residual fallout of such a massive DDoS (Distributed Denial of Service) attack could cripple the entire Internet. Marc Maiffret of eEye Digital Security noted that, "In testing we have calculated that the worm can attempt to infect roughly half a million IP addresses a day." Given that Netcraft estimates nearly 6 million IIS servers are in use as part of the Internet backbone, close to twenty-one percent of the Web could be affected. While the attack is targeting www.whitehouse.gov, the subsequent traffic jam could potentially result in severe disruption to the Internet. eEye Digital notes, "Chances are this worm would have not been discovered if we had not fully
disclosed details about the .ida vulnerability, allowing Intrusion Detection
System vendors to create signatures for the .ida buffer overflow attack.". Indeed, without the deliberate intrusion scanning the worm's presence would go largely undetected as IIS servers do not log requests until they have been processed.
While the worm exploits any language version of IIS, on English versions of NT/2000 servers it has an extra twist - defacing the websites to display:
Welcome to http://www.worm.com !
Hacked By Chinese!
It is not known whether the worm.com website was directly involved in any fashion, but as a precaution authorities have asked the ISP to remove the site. According to eEye Digital, "This worm only specifies www.worm.com in the initial HTTP GET request HOST: header and in the defaced page show on English (US) systems. This worm does_not_ connect to www.worm.com. This worm operates completely independent and
can spread and infect systems without having a single point of failure. What
that means is that this worm will be wild on the Internet until there is a
_VERY_ high degree of systems that go and install the .ida patch."
Interestingly, Microsoft's own web servers may have been infected. One post to the Bugtraq newsgroup indicated the Microsoft Update site was displaying the Hacked By Chinese! banner and a check of the site indicated it was no longer accessible via the Web. If true that the site was affected, it lays to rest rumors that even Microsoft® doesn't use their own software.
|
||||||||||||

