# Are Code Red attacks continuing?

**URL:** <https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400>\
**Category:** Factual Questions\
**Created:** [August 8, 2001, 3:16am UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400 "2001-08-08T03:16:27Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Edward\_J\_Cunningham\_1](https://avatars.discourse-cdn.com/v4/letter/e/e79b87/32.png) [@Edward\_J\_Cunningham\_1](https://boards.straightdope.com/u/Edward_J_Cunningham_1)\
**Post date:** [August 8, 2001, 3:16am UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/1 "2001-08-08T03:16:27Z")

</div>

I considered posting this under MPSIMS, but then I decided that General Questions would be better. I’m the moderator of a message board hosted by [http://www.wantsomegetsome.net](http://www.wantsomegetsome.net) . Well, due to the Code Red Virus, this server is blocking any IPs that are coming from a certain range. To quote:

> [@](#):
>
> “Because of Code Red scan repeatedly coming from the same networks we are currently blocking all incoming traffic FROM 63.xxx.xxx.xxx and 209.xxx.xxx.xxx This means that anyone trying to view your website with any computer that is connected to the Internet with an IP address that begins with 63 or 209 will not be able to view that website.”

My IP begins with 66, but for some reason it’s affecting me as well. I can’t access **any** web site hosted by this server. This started last night, and I’m getting really frustrated. Aren’t the Code Red attacks over? How long will I get shut out?

Edward J. Cunningham  
[http://www.comicboards.com/fcf](http://www.comicboards.com/fcf)

P.S. Yes, it’s good to rejoin the Teeming Millions once again!

---

<div class="post-metadata">

**Author:** ![Ringo](https://avatars.discourse-cdn.com/v4/letter/r/779978/32.png) [@Ringo](https://boards.straightdope.com/u/Ringo)\
**Post date:** [August 8, 2001, 3:33am UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/2 "2001-08-08T03:33:41Z")

</div>

FWIW to you, pal, I just got hammered by one that’s not even making the news. The **W32.Magistr.24876@mm** virus _is_ a nasty one, and it’s not a one trick pony. It’s an email worm that, of course, sends itself to everyone whose address you’ve got, deletes your hard drive, flushes your CMOS, flashes your BIOS and calls you a piece (well, to be accurate, a chunk) of s\*\*\* to boot.

Watch out!

And good luck.

---

<div class="post-metadata">

**Author:** ![SmackFu](https://avatars.discourse-cdn.com/v4/letter/s/53a042/32.png) [@SmackFu](https://boards.straightdope.com/u/SmackFu)\
**Post date:** [August 8, 2001, 4:16am UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/3 "2001-08-08T04:16:48Z")

</div>

I’m still seeing attacks on my Linux box, about 1 every 5 minutes. So it’s not over.

---

<div class="post-metadata">

**Author:** ![Chas.E](https://avatars.discourse-cdn.com/v4/letter/c/e99b99/32.png) [@Chas.E](https://boards.straightdope.com/u/Chas.E)\
**Post date:** [August 8, 2001, 10:05am UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/4 "2001-08-08T10:05:05Z")

</div>

Yes, I’m seeing several attacks per minute on the @Home cable network. Some portions of the @Home net have disabled port 80 access to slow the worm down. However, this is not the worst part of the worm’s activity. The network is bogged down with bogus ARP requests aimed at random IPs, most of which do not exist. These requests are clogging up the net a bit.

For statistics on the spread of the worm, go here:

[http://www.digitalisland.com/codered](http://www.digitalisland.com/codered)

Their graphs of the worm’s progress are quite interesting.

---

<div class="post-metadata">

**Author:** ![Chas.E](https://avatars.discourse-cdn.com/v4/letter/c/e99b99/32.png) [@Chas.E](https://boards.straightdope.com/u/Chas.E)\
**Post date:** [August 8, 2001, 10:07am UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/5 "2001-08-08T10:07:22Z")

</div>

Oh, I forgot to mention… You may find [http://www.incidents.org](http://www.incidents.org) of interest, it is tracking other aspects of the worm, such as the ARP flooding caused by the worm.

---

<div class="post-metadata">

**Author:** ![Skywatcher](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/skywatcher/32/254_2.png) [@Skywatcher](https://boards.straightdope.com/u/Skywatcher)\
**Post date:** [August 8, 2001, 12:52pm UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/6 "2001-08-08T12:52:28Z")

</div>

There’s reports that the worm has mutated but is still similar enough to the original that Microsquish’s anti-Code Red patch still works.

---

<div class="post-metadata">

**Author:** ![Bill\_H](https://avatars.discourse-cdn.com/v4/letter/b/a5b964/32.png) [@Bill\_H](https://boards.straightdope.com/u/Bill_H)\
**Post date:** [August 8, 2001, 1:04pm UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/7 "2001-08-08T13:04:34Z")

</div>

That’s right. There’s a new strain called Code Red II. This one is more malicious, since it’ll allow anybody to take control of the machine and do as they wish (download files, delete the hard disk, whatever). I work at a network security scanning company, and this Code Red thing is definitely a marketing gold mine for us.

---

<div class="post-metadata">

**Author:** ![Edward\_J\_Cunningham\_1](https://avatars.discourse-cdn.com/v4/letter/e/e79b87/32.png) [@Edward\_J\_Cunningham\_1](https://boards.straightdope.com/u/Edward_J_Cunningham_1)\
**Post date:** [August 8, 2001, 11:49pm UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/8 "2001-08-08T23:49:16Z")

</div>

Well, I’m now able to access [Comicboards.com](http://Comicboards.com) and any other site hosted by [http://www.wantsomegetsome.net](http://www.wantsomegetsome.net) , but it’s clear from your posts that these attacks are far from over. I’ll keep my eyes peeled…

Eddie

---

<div class="post-metadata">

**Author:** ![yabob](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/yabob/32/2821_2.png) [@yabob](https://boards.straightdope.com/u/yabob)\
**Post date:** [August 9, 2001, 12:23am UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/9 "2001-08-09T00:23:08Z")

</div>

As of this morning, my home machine on a residential DSL service had gotten a nice big pile of them. Haven’t been home yet to see what the error log for my webserver looks like (I’m running Xitami). I suspect there’s some more instances of “Get /default.ida?XXXXXXXX …” cluttering it up. There seems to be some using X’s to generate the buffer overflow, and some using N’s. Actually, I noticed a few of these in my logs a couple weeks ago, I think, before “Code Red” hit the news. Well, now it’s got a name, and there’s more of them.

In a way, I’m glad I’m running a webserver, or I’d have zonealarm reporting the damned things, I suppose - I’d have to turn off the little notification balloons.

---

<div class="post-metadata">

**Author:** ![black\_rabbit](https://avatars.discourse-cdn.com/v4/letter/b/f19dbf/32.png) [@black\_rabbit](https://boards.straightdope.com/u/black_rabbit)\
**Post date:** [August 9, 2001, 12:41am UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/10 "2001-08-09T00:41:15Z")

</div>

Zonealarm has been blocking port scan attempts on my home (ME, dialup) machine every 2-3 minutes for the past month, including last night. I assume that’s from CR. They do seem to be decreasing in frequency, though… last week, I was getting 15 attempts at once.

---

<div class="post-metadata">

**Author:** ![Chas.E](https://avatars.discourse-cdn.com/v4/letter/c/e99b99/32.png) [@Chas.E](https://boards.straightdope.com/u/Chas.E)\
**Post date:** [August 9, 2001, 1:03am UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/11 "2001-08-09T01:03:57Z")

</div>

I noticed that the [http://www.incidents.org](http://www.incidents.org) website upgraded the level of threat from yellow to orange, just after I posted their link. The next step is red, which means total meltdown of the inernet. Another shining moment in Microsoft history.

A minor quibble: this virus didn’t “mutate.” These viruses don’t have self-modifying code or any ability to change on their own. Someone sat down at a keyboard and rewrote it by hand. There were apparently 3 versions of Code Red, and one new variant of Code Red 2.

I read with amusement a report that nobody can update their Microsoft IIS with the patch without getting infected in the process. One person reported being attacked within 10 seconds of going online. So even a fresh install from the CDs would be infected before you could finish downloading the patch.

---

<div class="post-metadata">

**Author:** ![Bill\_H](https://avatars.discourse-cdn.com/v4/letter/b/a5b964/32.png) [@Bill\_H](https://boards.straightdope.com/u/Bill_H)\
**Post date:** [August 9, 2001, 6:14am UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/12 "2001-08-09T06:14:27Z")

</div>

**Chas.E** wrote

> [@](#):
>
> A minor quibble: this virus didn’t “mutate.” These viruses don’t have self-modifying code or any ability to change on their own. Someone sat down at a keyboard and rewrote it by hand. There were apparently 3 versions of Code Red, and one new variant of Code Red 2.

True

> [@](#):
>
> I read with amusement a report that nobody can update their Microsoft IIS with the patch without getting infected in the process. One person reported being attacked within 10 seconds of going online. So even a fresh install from the CDs would be infected before you could finish downloading the patch.

Not True.

---

<div class="post-metadata">

**Author:** ![Chas.E](https://avatars.discourse-cdn.com/v4/letter/c/e99b99/32.png) [@Chas.E](https://boards.straightdope.com/u/Chas.E)\
**Post date:** [August 9, 2001, 6:34am UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/13 "2001-08-09T06:34:20Z")

</div>

> [@](#):
>
> \*Originally posted by Bill H. \*  
> \*\*Not True. \*\*

Please explain what you meant?

The standard way to obtain the IIS patch is by downloading it from Microsoft. The only way to download it will expose you to the virus, typically in 10 seconds or less. You would have to download the patch and install it in less than 10 seconds, or else you’d have to be extremely lucky and not be attacked for the duration of the upgrade, which is extremely unlikely, almost impossibly lucky.  
Of course, you can just reboot after the patch and eliminate the virus along with activating the preventative measures, but I’m merely commenting on the irony of being forced to expose yourself to the virus in order to prevent it. This is the sort of thing that makes IT managers go crazy.

---

<div class="post-metadata">

**Author:** ![Bill\_H](https://avatars.discourse-cdn.com/v4/letter/b/a5b964/32.png) [@Bill\_H](https://boards.straightdope.com/u/Bill_H)\
**Post date:** [August 9, 2001, 7:20am UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/14 "2001-08-09T07:20:19Z")

</div>

Your quote was

> [@](#):
>
> I read with amusement a report that nobody can update their Microsoft IIS with the patch without getting infected in the process.

You specifically said that everyone who downloads the patch will get infected. That’s completely untrue, although you did back-pedal in your following post.

It’s also untrue that users are exposed to Code Red II “typically in 10 seconds or less.”

A machine that is vulnerable to **any security flaw** must connect to the Internet to download a patch.

It’s a minor nit, but Code Red II is not a virus; it’s a worm.

---

<div class="post-metadata">

**Author:** ![zedan](https://avatars.discourse-cdn.com/v4/letter/z/a88e4f/32.png) [@zedan](https://boards.straightdope.com/u/zedan)\
**Post date:** [August 9, 2001, 7:28am UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/15 "2001-08-09T07:28:46Z")

</div>

> [@](#):
>
> \*Originally posted by Chas.E \*  
> \*\*
> 
> > [@](#):
> >
> > \*Originally posted by Bill H. \*  
> > \*\*Not True. \*\*
> 
> Please explain what you meant?
> 
> The standard way to obtain the IIS patch is by downloading it from Microsoft. The only way to download it will expose you to the virus, typically in 10 seconds or less. You would have to download the patch and install it in less than 10 seconds, or else you’d have to be extremely lucky and not be attacked for the duration of the upgrade, which is extremely unlikely, almost impossibly lucky.  
> Of course, you can just reboot after the patch and eliminate the virus along with activating the preventative measures, but I’m merely commenting on the irony of being forced to expose yourself to the virus in order to prevent it. This is the sort of thing that makes IT managers go crazy. \*\*

Simple enough. Physically disconnect the computer from the network before you install the OS. After it’s installed boot the system and disable the WWW service. Reconnect the ethernet connection, set up the network, and reboot. You can then safely download the patch without fear of the virus infecting your computer (since it can only spread over port 80 which is the www service that you have already disabled).

---

<div class="post-metadata">

**Author:** ![galt](https://avatars.discourse-cdn.com/v4/letter/g/35a633/32.png) [@galt](https://boards.straightdope.com/u/galt)\
**Post date:** [August 9, 2001, 8:00am UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/16 "2001-08-09T08:00:18Z")

</div>

Well, first, “nobody can update without getting infected in the process” makes it sound as though the patching procedure actually infects you. This is not the case. I presume you mean, “if you get online long enough to download the patch, odds are you’ll get infected.” But this is wrong too. Any administrator worth a nickel is either going to a) disable IIS (or better yet, just the indexing service, which is the vulnerable piece) while he downloads the patch, or b) download the patch from a different machine.  
You don’t even need to reboot. From the command line:  
\> net stop /y iisadmin  
then download the patch and run it, then:  
\> net start w3svc

---

<div class="post-metadata">

**Author:** ![Chas.E](https://avatars.discourse-cdn.com/v4/letter/c/e99b99/32.png) [@Chas.E](https://boards.straightdope.com/u/Chas.E)\
**Post date:** [August 9, 2001, 10:39am UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/17 "2001-08-09T10:39:48Z")

</div>

> [@](#):
>
> \*Originally posted by galt \*  
> **I presume you mean, “if you get online long enough to download the patch, odds are you’ll get infected.” But this is wrong too. Any administrator worth a nickel is either going to a) disable IIS (or better yet, just the indexing service, which is the vulnerable piece) while he downloads the patch, or b) download the patch from a different machine.**

That’s precisely what I meant, but note that I said a default install from CD. Your average shmoe does not know this sort of preventative measures for blocking the virus vector, he just knows that if he reformats and installs fresh from the CD, then downloads the latest service packs and security patches, he’s supposed to be safe from all known viruses and worms. Except he isn’t. With the exceptionally high traffic of attacks, the odds of escaping the attack during the update process are almost infinitesimal. But ultimately, it doesn’t matter, except to the people whose distant machines YOU infected during the short time before your machine was patched and rebooted. Once you’re done, you are updated and safe, almost certain to get infected (briefly) during the process.

---

<div class="post-metadata">

**Author:** ![bordelond](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bordelond/32/150_2.png) [@bordelond](https://boards.straightdope.com/u/bordelond)\
**Post date:** [August 9, 2001, 2:28pm UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/18 "2001-08-09T14:28:44Z")

</div>

Is this affecting home desktop PC’s, or just web servers worldwide?

---

<div class="post-metadata">

**Author:** ![Skywatcher](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/skywatcher/32/254_2.png) [@Skywatcher](https://boards.straightdope.com/u/Skywatcher)\
**Post date:** [August 9, 2001, 2:35pm UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/19 "2001-08-09T14:35:45Z")

</div>

> [@](#):
>
> \*Originally posted by Chas.E \*  
> **A minor quibble: this virus didn’t “mutate.” These viruses don’t have self-modifying code or any ability to change on their own. Someone sat down at a keyboard and rewrote it by hand. There were apparently 3 versions of Code Red, and one new variant of Code Red 2.**

Yeah, I know. I was making a little joke. I’d give you a “whoosh” but I don’t think that quite applies here.

---

<div class="post-metadata">

**Author:** ![handy](https://avatars.discourse-cdn.com/v4/letter/h/b5a626/32.png) [@handy](https://boards.straightdope.com/u/handy)\
**Post date:** [August 9, 2001, 2:55pm UTC](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400/20 "2001-08-09T14:55:17Z")

</div>

bordelond, I would say so.

I have got about 30 emails with this worm attached or something similar in a week. The people don’t know it’s coming from their computer. One lady wrote me saying she has it on her computer & that explains the ones from her.

I use Agent for reading my email & its not affected by the worm because I can see the worm/virus/script attachment before decoding it.

I got another email today with the attachment but Im gonna email them back & let them know their computer is infected.

[Next page](https://boards.straightdope.com/t/are-code-red-attacks-continuing/75400.md?page=2)
