# Code Red Worm-what the hell?

**URL:** <https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283>\
**Category:** Factual Questions\
**Created:** [July 30, 2001, 11:26pm UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283 "2001-07-30T23:26:15Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Guinastasia](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guinastasia/32/5751_2.png) [@Guinastasia](https://boards.straightdope.com/u/Guinastasia)\
**Post date:** [July 30, 2001, 11:26pm UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/1 "2001-07-30T23:26:15Z")

</div>

> **[Developer tools, technical documentation and coding examples](https://docs.microsoft.com/en-us/?url=%2Ftechnet%2Fitsolutions%2Fsecurity%2Ftopics%2Fcodealrt.asp)**
>
> The home for Microsoft documentation and learning for developers and technology professionals.

Normally, I wouldn’t ask this, but I’m extremely confused…

First off, I want to know-is Windows ME the same as Windows 2000?

2nd-does reboot mean restart my computer, or reformat my harddrive?

3rd-is this all a stupid hoax?

(sorry, my mother is telling me about it, and I’m very frightened at the idea of ANYTHING happening to my precious computer…)

---

<div class="post-metadata">

**Author:** ![Shiva](https://avatars.discourse-cdn.com/v4/letter/s/85e7bf/32.png) [@Shiva](https://boards.straightdope.com/u/Shiva)\
**Post date:** [July 30, 2001, 11:49pm UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/2 "2001-07-30T23:49:20Z")

</div>

1. ME, 2000, close enough.

2. Reboot means to restart.

3. It’s no hoax. Here’s a good article from **Wired** : [http://www.wired.com/news/technology/0,1282,45681,00.html](http://www.wired.com/news/technology/0,1282,45681,00.html)  
Note that only some machines are vulnerable, and that it’s aimed at servers, not Bob’s laptop.

---

<div class="post-metadata">

**Author:** ![Tranquilis](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tranquilis/32/3639_2.png) [@Tranquilis](https://boards.straightdope.com/u/Tranquilis)\
**Post date:** [July 30, 2001, 11:49pm UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/3 "2001-07-30T23:49:20Z")

</div>

1. No. Win’98 is based upon Win’95, which is based upon MS-DOS. Win2000 is based upon WinNT.

2. Restart. Two choices: “Warm boot” (“Soft Boot”); select {Start | Shut Down | restart} -or- “Cold Boot” (“Hard Boot”); Shut down, power-off, then power-on.

3. No hoax, but unless you’re running an Internet Information Server on WinNT or Win2000, or own a Cisco router, you’ve got little to worry about.

[Link](http://www.sophos.com/support/news/#codered)

BTW, TechNet has moved the page you linked to.

---

<div class="post-metadata">

**Author:** ![Tranquilis](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tranquilis/32/3639_2.png) [@Tranquilis](https://boards.straightdope.com/u/Tranquilis)\
**Post date:** [July 30, 2001, 11:56pm UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/4 "2001-07-30T23:56:36Z")

</div>

Not as clear as I intended: ME is Win’98 Millenium Edition, which comes from the DOS branch of the MS family. Win2000 Is based upon Windows New Technology, written by a bunch of OpenVMS programmers hired by M$.

---

<div class="post-metadata">

**Author:** ![black\_rabbit](https://avatars.discourse-cdn.com/v4/letter/b/f19dbf/32.png) [@black\_rabbit](https://boards.straightdope.com/u/black_rabbit)\
**Post date:** [July 31, 2001, 12:05am UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/5 "2001-07-31T00:05:04Z")

</div>

ME is probably even more safe than 98… it doesn’t include Personal Web Server.

Until about a week ago, that pissed me off.

Thanks to Red Alert, though, having an OS that doesn’t do diddly suddenly has its advantages.

---

<div class="post-metadata">

**Author:** ![Guinastasia](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guinastasia/32/5751_2.png) [@Guinastasia](https://boards.straightdope.com/u/Guinastasia)\
**Post date:** [July 31, 2001, 1:06am UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/6 "2001-07-31T01:06:25Z")

</div>

Whew. Thanks.

Sorry to clog up GQ, it’s just that despite the fact that I spend 99.9% of my time on this thing, I know little about it’s inner workings, and I’m EXTREMELY overprotective of my beautiful computer.

---

<div class="post-metadata">

**Author:** ![Guinastasia](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guinastasia/32/5751_2.png) [@Guinastasia](https://boards.straightdope.com/u/Guinastasia)\
**Post date:** [July 31, 2001, 1:13am UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/7 "2001-07-31T01:13:35Z")

</div>

Forgot to add-Manny, feel free to close this.

---

<div class="post-metadata">

**Author:** ![Sultan\_Kinkari](https://avatars.discourse-cdn.com/v4/letter/s/7bcc69/32.png) [@Sultan\_Kinkari](https://boards.straightdope.com/u/Sultan_Kinkari)\
**Post date:** [July 31, 2001, 1:39am UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/8 "2001-07-31T01:39:09Z")

</div>

No hoax whatsoever.

I’ve been down for the past three+ weeks courtesy of the Code Red Worm as you will read about [here](http://boards.straightdope.com/sdmb/showthread.php?threadid=79464).

I want to be pissed a Qwest, my ISP, but they really are just a bunch of clueless wackoffs. It’s not their fault that they have a multi-million-dollar contract with Cisco that they are undoubtedly dreading as of late.  
[list]  
[li]I own a Cisco router.[/li]  
[li] I am using ME/2000[/li]  
[li] I have been up sh_t creek for three weeks and Qwest is still running me in circles whenever I call tech support, now trying to convince me that **I** have done something wrong. :rolleyes:[/li]  
Thanks for reminding me how f_cked I am right now. 😃

---

<div class="post-metadata">

**Author:** ![JoltSucker](https://avatars.discourse-cdn.com/v4/letter/j/d2c977/32.png) [@JoltSucker](https://boards.straightdope.com/u/JoltSucker)\
**Post date:** [July 31, 2001, 1:45am UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/9 "2001-07-31T01:45:19Z")

</div>

The Code Red worm is targeted to M$ IIS servers that don’t have the latest security patches. One area of vulnerability that (almost) no one thought of is the Cisco gear: that easy-to-use HTML interface is actually a firmware copy of IIS. Cisco has a security bulletin on it, but I don’t have the URL here at home.

Another oxymoron: Microsoft security.

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [July 31, 2001, 2:30am UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/10 "2001-07-31T02:30:56Z")

</div>

The home user has nothing to worry about. It only affects people running web servers (and Microsoft’s Personal Web Server doesn’t count).

While the virus is not a hoax, the hysteria is **way** out of line. This virus is only of a concern to people who run websites. It’s also an easy fix (add the patch and reboot). The media has been disgustingly irresponsible on this one.

It’s sort of like having doctors warn people about a major outbreak of Ick (a disease of tropical fish).

---

<div class="post-metadata">

**Author:** ![Sultan\_Kinkari](https://avatars.discourse-cdn.com/v4/letter/s/7bcc69/32.png) [@Sultan\_Kinkari](https://boards.straightdope.com/u/Sultan_Kinkari)\
**Post date:** [July 31, 2001, 6:59am UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/11 "2001-07-31T06:59:14Z")

</div>

> [@](#):
>
> \*Originally posted by RealityChuck \*  
> **The home user has nothing to worry about. It only affects people running web servers (and Microsoft’s Personal Web Server doesn’t count).**

I am currently not running a web server and I have been without my high-speed DSL service for the past three weeks. Any ideas?

> [@](#):
>
> \*Originally posted by RealityChuck \*  
> \*\*While the virus is not a hoax, the hysteria is **way** out of line. This virus is only of a concern to people who run websites. It’s also an easy fix (add the patch and reboot). The media has been disgustingly irresponsible on this one. \*\*

How hysterical would you be if you were forced to use a 56k with a dial-up every Goddamn day for three weeks straight, after having a 600+ kbs at your disposal for the past three years? Hey pal, any links to the website with the patch?

> [@](#):
>
> \*Originally posted by RealityChuck \*  
> \*\*It’s sort of like having doctors warn people about a major outbreak of Ick (a disease of tropical fish). \*\*

It’s a little bit different than that, and a remedy/panacea is not quite as readily available as you have described. Trust me, I have spoken with the tech support for my ISP, conducted multiple ping tests, and results conclude that my ISP(I cannot speak for the others) is definitely experiencing internal difficulties. My router consistently sends positive pings to the intermediary routers and shows that all is well at my terminal. Now I am simply waiting for the dumbasses at Qwest to discover that there is nothing wrong with my setup and to get their shit into working order.

---

<div class="post-metadata">

**Author:** ![Spiny\_Norman](https://avatars.discourse-cdn.com/v4/letter/s/9de0a6/32.png) [@Spiny\_Norman](https://boards.straightdope.com/u/Spiny_Norman)\
**Post date:** [July 31, 2001, 9:34am UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/12 "2001-07-31T09:34:58Z")

</div>

FWIW, it’s certainly not every Cisco router that’s vulnerable to the Red Worm - the only vulnerable systems are (unpatched) DSL routers in the Cisco 600 series.

And it’s not as if they propagate the worm, it’s simply an old and well-known bug in the 600 router’s configuration interface that coincidentally gets triggered by the Red Worm scanning. But 600 routers are odd birds anyway, they’re not part of the general Cisco lineup (800-12000 routers) - specifically, they don’t run the IOS operating system.

The other affected Cisco products are software products (mainly management software) running on MS IIS or modified versions thereof.

Yeah, I know, noone asked.

S. Norman

---

<div class="post-metadata">

**Author:** ![techchick68](https://avatars.discourse-cdn.com/v4/letter/t/ea5d25/32.png) [@techchick68](https://boards.straightdope.com/u/techchick68)\
**Post date:** [July 31, 2001, 10:43am UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/13 "2001-07-31T10:43:16Z")

</div>

wishbone, I think you need to lighten up a bit…yeesh, that kind of attitude will pop a blood vessel in your eye or in your neck.

Here’s the official email from Microsoft that I received this evening:

> [@](#):
>
> The following is a Security Bulletin from the Microsoft Product Security  
> Notification Service.
> 
> Please do not reply to this message, as it was sent from an unattended  
> mailbox.  
> \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*
> 
> -----BEGIN PGP SIGNED MESSAGE-----
> 
> * * *
> 
> The Microsoft Security Response Center, along with other  
> organizations listed below, is jointly publishing this alert that  
> ALL IIS ADMINISTRATORS ARE ASKED TO READ
> 
> A Very Real and Present Threat to the Internet:  
> July 31 Deadline For Action
> 
> Summary:
> 
> The Code Red Worm and mutations of the worm pose a  
> continued and serious threat to Internet users. Immediate action  
> is required to combat this threat. Users who have deployed  
> software that is vulnerable to the worm (Microsoft IIS  
> Versions 4.0 and 5.0) must install, if they have not done so  
> already, a vital security patch.
> 
> How Big Is The Problem?
> 
> On July 19, the Code Red worm infected more than 250,000 systems in just 9 hours. The worm scans the Internet, identifies vulnerable systems, and infects these systems by installing itself. Each newly installed worm joins all the others causing the rate of scanning to grow rapidly. This uncontrolled growth in scanning directly decreases the speed of the Internet and can cause sporadic but widespread outages among all types of systems. Code Red is likely to start spreading again on July 31st, 2001 8:00 PM EDT and has mutated so that it may be even more dangerous. This spread has the potential to disrupt business and personal use of the Internet for applications such as electronic commerce, email and entertainment.
> 
> Who Must Act?
> 
> Every organization or person who has Windows NT or Windows 2000 systems **AND** the IIS web server software may be vulnerable. IIS is installed automatically for many applications. If you are not certain, follow the instructions attached to determine whether you are running IIS 4.0 or 5.0. If you are using Windows 95, Windows 98, or Windows Me, there is no action that you need to take in response to this alert.
> 
> What To Do If You Are Vulnerable?
> 
> a. To rid your machine of the current worm, reboot your computer.  
> b. To protect your system from re-infection:  
> Install Microsoft’s patch for the Code Red vulnerability problem:
> 
> - 
> - Windows NT version 4.0:  
> [http://www.microsoft.com/Downloads/Release.asp?ReleaseID=30833](http://www.microsoft.com/Downloads/Release.asp?ReleaseID=30833)
> 
> - 
> - Windows 2000 Professional, Server and Advanced Server:  
> [http://www.microsoft.com/Downloads/Release.asp?ReleaseID=30800](http://www.microsoft.com/Downloads/Release.asp?ReleaseID=30800)
> 
> Step-by-step instructions for these actions are posted at  
> [http://www.microsoft.com/technet/treeview/default.asp](http://www.microsoft.com/technet/treeview/default.asp)?  
> url=/technet/itsolutions/security/topics/codeptch.asp
> 
> Microsoft’s description of the patch and its installation,  
> and the vulnerability it addresses is posted at:  
> [http://www.microsoft.com/technet/treeview/default.asp](http://www.microsoft.com/technet/treeview/default.asp)?  
> url=/technet/security/bulletin/MS01-033.asp
> 
> Because of the importance of this threat, this alert is  
> being made jointly by:
> 
> Microsoft  
> The National Infrastructure Protection Center  
> Federal Computer Incident Response Center (FedCIRC)  
> Information Technology Association of America (ITAA)  
> CERT Coordination Center  
> SANS Institute  
> Internet Security Systems  
> Internet Security Alliance
> 
> -----BEGIN PGP SIGNATURE-----  
> Version: PGP Personal Privacy 6.5.3
> 
> iQEVAwUBO2Wpgo0ZSRQxA/UrAQFQeQgAgmva53MJdjGF4u4oFXcAJICgf+1YTd1n  
> IJ7XIPPjTFkc5/8Fqe0lbFY7ZeBNAvGGI276RPkebmTz1WAJ08MNe9uvMJAuyULw  
> nOU8sMIO7S0Z5Z65/UYow0ui2qLVdmioqf809RAydHPdj1GINU0yDNS1HwwfjZia  
> 0wBN+GjyjbdMU6bgMadoMdRgvCwdx2Jzr8ExAnFeNtLxRjwct3mv23bCrln1h80I  
> 4awW0GPPd5iFzLIZX+QVh9/qkPdYm3SD1e8rs8GK69dub1AsVoKdXea+EHb3YckO  
> 9XfuZdhxy6I+PnZJ8woSSNqtuZ2zKuS+q4kdPt0Abh0ToCbR4jK91A==  
> =a2a5  
> -----END PGP SIGNATURE-----
> 
> * * *
> 
> You have received this e-mail bulletin as a result of your registration  
> to the Microsoft Product Security Notification Service. You may  
> unsubscribe from this e-mail notification service at any time by sending  
> an e-mail to [MICROSOFT\_SECURITY-SIGNOFF-REQUEST@ANNOUNCE.MICROSOFT.COM](mailto:MICROSOFT_SECURITY-SIGNOFF-REQUEST@ANNOUNCE.MICROSOFT.COM)  
> The subject line and message body are not used in processing the request,  
> and can be anything you like.
> 
> To verify the digital signature on this bulletin, please download our PGP  
> key at [http://www.microsoft.com/technet/security/notify.asp](http://www.microsoft.com/technet/security/notify.asp).
> 
> For more information on the Microsoft Security Notification Service  
> please visit [http://www.microsoft.com/technet/security/notify.asp](http://www.microsoft.com/technet/security/notify.asp). For  
> security-related information about Microsoft products, please visit the  
> Microsoft Security Advisor web site at [http://www.microsoft.com/security](http://www.microsoft.com/security).

BTW I added the information that is not really needed to show that’s it’s an official email and I added a bolding to emphasis that **YOUR** problem with Qwest is most likely not due to this but problems that you have not divuldged to a degree that many of the well informed techs on this board can help you with.

I have a problem with people that automatically blame their ISP or Microsoft for their problems without considering that it’s possible there are other fixes to your problem.

If you so choose, then post another thread to detail, yes great detail, the problem you are having. Qwest may be the problem but in this case, from the little bit of information you gave us, it’s NOT the problem of this current virus outbreak.

Oh and I kind of feel that this virus/worm is pretty harmless…there’s an easy fix, there’s little damage so it’s pretty mild compared to some of the other viruses I have had to deal with in the past.

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [July 31, 2001, 11:23am UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/14 "2001-07-31T11:23:07Z")

</div>

[bold]wishbone[/bold], even assuming your trouble was caused by the worm (and it may have nothing to do with it), my advice still stands. Your computer isn’t affected. It’s your ISP’s. Now, maybe they don’t have their act together and are total incompetents, but they’d be that way even if the virus doesn’t exist.

BTW, if you’ve been having this problem for three weeks straight – as you say – it can’t be the virus. Code Red was discovered on July 16th – only _two_ weeks ago.

> [@](#):
>
> How hysterical would you be if you were forced to use a 56k with a dial-up every Goddamn day for three weeks straight, after having a 600+ kbs at your disposal for the past three years?

\<unison\> Awww. Poor Baby.\</unison\> I do use at 56k dial-up.

---

<div class="post-metadata">

**Author:** ![bernse](https://avatars.discourse-cdn.com/v4/letter/b/a9a28c/32.png) [@bernse](https://boards.straightdope.com/u/bernse)\
**Post date:** [July 31, 2001, 1:31pm UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/15 "2001-07-31T13:31:34Z")

</div>

> [@](#):
>
> \*Originally posted by wishbone \*  
> \*\*No hoax whatsoever.
> 
> [li] I am using ME/2000[/li] \*\*

Once again, windows ME (Millenium) is **NOT** 2000 based. It is more or less immune to this virus, just as 95/98/98SE are.

I am curious if XP is immune though.

That being said, it is a very real threat from everything I have read and has some real potential to screw up the net for the next while. The SDMB may be “speedy” in comparison to some other sites. 🙂

---

<div class="post-metadata">

**Author:** ![Tranquilis](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tranquilis/32/3639_2.png) [@Tranquilis](https://boards.straightdope.com/u/Tranquilis)\
**Post date:** [July 31, 2001, 3:47pm UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/16 "2001-07-31T15:47:33Z")

</div>

> [@](#):
>
> I am curious if XP is immune though.

WinXP-based servers running IIS should also be vulnerable.

---

<div class="post-metadata">

**Author:** ![Seraphim](https://avatars.discourse-cdn.com/v4/letter/s/ad7895/32.png) [@Seraphim](https://boards.straightdope.com/u/Seraphim)\
**Post date:** [July 31, 2001, 4:23pm UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/17 "2001-07-31T16:23:49Z")

</div>

> [@](#):
>
> \*Originally posted by Tranquilis \*  
> \*\*
> 
> > [@](#):
> >
> > I am curious if XP is immune though.
> 
> WinXP-based servers running IIS should also be vulnerable. \*\*

I dunno…I’m using WinXP build 2505 and IIS, and I don’t see any critical updates to address this worm. I take that to mean that M$ has already compiled that patch into their beta builds.

---

<div class="post-metadata">

**Author:** ![Tranquilis](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tranquilis/32/3639_2.png) [@Tranquilis](https://boards.straightdope.com/u/Tranquilis)\
**Post date:** [July 31, 2001, 4:46pm UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/18 "2001-07-31T16:46:17Z")

</div>

> [@](#):
>
> I take that to mean that M$ has already compiled that patch into their beta builds.

From Sophos:

> [@](#):
>
> Microsoft has released a patch that reportedly eliminates this security vulnerability. The vulnerability exists in the Indexing Services used by Microsoft IIS 4.0 and IIS 5.0 running on Windows NT, Windows 2000, and beta versions of Windows XP. This vulnerability may allow a remote intruder to run arbitrary code on the victim machine.

From Microsoft:

> [@](#):
>
> Note: Indexing Service in Windows XP beta is also affected by the vulnerability. As discussed in the FAQ, Microsoft is working directly with the small number of customers who are using the beta in production environments to provide remediation for them.

---

<div class="post-metadata">

**Author:** ![SDP](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@SDP](https://boards.straightdope.com/u/SDP)\
**Post date:** [July 31, 2001, 6:04pm UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/19 "2001-07-31T18:04:33Z")

</div>

> [@](#):
>
> _Reality Chuck wrote:_
> 
> **wishbone, even assuming your trouble was caused by the worm (and it may have nothing to do with it), my advice still stands. Your computer isn’t affected. It’s your ISP’s. Now, maybe they don’t have their act together and are total incompetents, but they’d be that way even if the virus doesn’t exist.**

and

> [@](#):
>
> _Techchick68 wrote:_
> 
> **BTW I added the information that is not really needed to show that’s it’s an official email and I added a bolding to emphasis that YOUR problem with Qwest is most likely not due to this but problems that you have not divuldged to a degree that many of the well informed techs on this board can help you with.**

There is some significant misinformation in this thread. As **Spiny Norman** already pointed out, select Cisco routers are affected by the worm. Affected != infected. They are simply knocked offline. The problem is with the router. Don’t believe me? Believe the folks at Cisco (by way of [Security Focus](http://www.securityfocus.com) [Sorry, can’t link directly to the article – go to vulnerabilities, Cisco, 2001]):

> [@](#):
>
> \*\* Cisco 600 series of DSL routers that have not been patched per the Cisco Security Advisory,
> 
> [Cisco - Networking, Cloud, and Cybersecurity Solutions](http://www.cisco.com/warp/public/707/CBOS-multiple.shtml) , will stop forwarding traffic when scanned by a system infected by the “Code Red” worm. The power must be cycled to restore normal service.\*\*

The whole Code Red debacle is really quite interesting. The buffer overrun vulnerability was pointed out on Bugtraq, and a patch was quickly enacted. The problem was, too few people applied the patch. They had several weeks. So first it was widespread stupidity by sysadmins. But then, the worm’s coder had some stupidity issues too. The worm’s scan of other computers was random, but it used the same seed, and thus (since it can’t be truly random), it began to repeat scans. Furthermore, he hardcoded the IP address of the target of his attack ([whitehouse.gov](http://whitehouse.gov)), and the White House folks very slickly changed their IP, thus dodging the entire attack.

There is a wealth of information on the virus, ranging from analysis of disassembled code to basic information to analysis of the virus’s spread. (Parenthetical note: Don’t believe a word from Steve Gibson’s mouth about this virus.) Have some links:

[Code Red Spread Analysis](http://www.caida.org/analysis/security/code-red)

> **[Code Red Worm Spreading, Set To Flood Whitehouse - Slashdot](https://slashdot.org/story/01/07/19/2230246/code-red-worm-spreading-set-to-flood-whitehouse)**
>
> altek writes: "CNET has an article describing a worm that has taken down over 12,000 MS IIS webservers." Bill Kendrick points to another CNET story, which reports that the worm will "cause every infected computer to flood the Whitehouse.gov address...

(older)

> **[CAIDA Released Code-Red Worm Post Mortem - Slashdot](https://slashdot.org/story/01/07/25/1222229/caida-released-code-red-worm-post-mortem)**
>
> davidu writes "David Moore at CAIDA (The Cooperative Association for Internet Data Analysis) was monitoring an entire /8 network while the code-red worm traversed the net. His findings are really interesting and show just how swiftly code-red moved...

(newer)  
[More Articles Than You Could Ever Possibly Want](http://www.eeye.com/html/News/index.html)

---

<div class="post-metadata">

**Author:** ![Sultan\_Kinkari](https://avatars.discourse-cdn.com/v4/letter/s/7bcc69/32.png) [@Sultan\_Kinkari](https://boards.straightdope.com/u/Sultan_Kinkari)\
**Post date:** [July 31, 2001, 6:50pm UTC](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283/20 "2001-07-31T18:50:46Z")

</div>

> [@](#):
>
> \*Originally posted by RealityChuck \*  
> **[bold]wishbone[/bold], even assuming your trouble was caused by the worm (and it may have nothing to do with it), my advice still stands. Your computer isn’t affected. It’s your ISP’s. Now, maybe they don’t have their act together and are total incompetents, but they’d be that way even if the virus doesn’t exist.**

Au contraire, mon frere. The quality of service I received from Qwest was outstanding from day one. They were perfectly competent in every way. It was only three weeks ago TODAY that my computer started buggin’ out.

> [@](#):
>
> \*Originally posted by RealityChuck \*  
> **[bold]wishbone[/bold], BTW, if you’ve been having this problem for three weeks straight – as you say – it can’t be the virus. Code Red was discovered on July 16th – only _two_ weeks ago…**

I don’t know whether the Red Worm was the official reason that my DSL quit working exactly three weeks ago today, but I think it would be foolish to think it was something else, considering that it(my DSL) has run perfectly 24-7 for the past three years.

> [@](#):
>
> How hysterical would you be if you were forced to use a 56k with a dial-up every Goddamn day for three weeks straight, after having a 600+ kbs at your disposal for the past three years?

\<unison\> Awww. Poor Baby.\</unison\> I do use at 56k dial-up. \*\*  
[/QUOTE]

Then you understand what a pain in the ass inconvenience. It’s like being stuck in rush hour traffic.

[Next page](https://boards.straightdope.com/t/code-red-worm-what-the-hell/74283.md?page=2)
