Slashdot Mirror


Code Red! All Hands to Battle Stations!

We had thought we were done with Code Red last week, but CERT is sending out warnings that the entire internet will cease to exist if the Code Red MSTD [?] isn't stopped in its tracks. Even Scientific American has a story about it. Cringely tells us that the true threat is servers with mis-set clocks.

445 comments

  1. Sue Microsoft by Anonymous Coward · · Score: 1

    Right, I'm not a laywer.

    But, 5 million (who cares, it's lots) IIS servers installed world wide (according to one of those articles). Now, those Terms and Conditions (EULA) says that Microsoft still 'owns' the software, even more so with their new licensing policy (with XP etc), so if they still own and control the software, surely they are responsible that on one day in the not too distant future /our/ Internet (parts of) will become saturated (for perhaps only a limited time) but the overall effect will strike all (thru degraded service), especially those who don't even run Microsoft software, and those who ensure their networks aren't open to this worm (the attack's a little harder to combat since it saturates your lines).

    IIS is a kind of polution. It's ruining the Internet for the rest of us.

    And it's Microsofts fault (be its engineers, or more likely its massive marketing force)

    Join with me! Lets Embrace and Extend Microsoft dodgy wares off the face of the internet and make the world a nicer place to be :)

    OK enough of that. But surely this is somewhere near the mark, if some legal types where to look into it.

    I work tech support, and get shit loads of moans when some little thing goes work, I get moans of "I'm loosing X thousand every hour" or some other zero tollerance bullshit. What's the net worth of loss that this little baby is going to unleash... and you bet, not one person will say anything (except the *nix zellots) and currently, Microsoft abandons all responsibility.

    Am I right, or what ?

  2. We're Missing the Point Here... by Anonymous Coward · · Score: 1
    I think the big issue is:

    Is the Code Red Worm under the GPL?

    I want access to the code, dammit!

  3. Re:Oooo..... let's bash Microsoft! Yeah! by Anonymous Coward · · Score: 1
    remove any that are unnecessary, including the one for Index Server.

    Unless you need to use Index Server of course!

  4. Re:Why can't MS be held responsible? by Anonymous Coward · · Score: 1
    In my opinion, someone should force MS to take responability for issuing a product recall...just like in any other industry. That means they much contact their dealers and their dealers must contact their customers and get it patched. Obviously this is serious enough to warrant that kind of attention and MS can surely afford it.

    Such a proposal would lead to the death of free software.

    A big proprietary software corporation like Microsoft, with billions of dollars of cash on hand, could easily afford to carry out such a recall. But any time such a recall was ordered for a security flaw in a free software project (which typically doesn't have as much cash on hand as Microsoft), it would probably be the end of the project. In fact, it's unlikely that anyone would bother starting a free software project in the first place, with the enormous risks of an expensive recall.

    Be careful what you ask for -- you might just receive it.

  5. Re:Best IIS Patch by Anonymous Coward · · Score: 1

    I just checked my home server today and I was hit 20 times by the worm on the 19th, but it doesn't matter because I run linux and apache. Just shows that we were right all along, M$ sucks, linux and apache rocks!

  6. CERT and Code Red by Anonymous Coward · · Score: 1

    I thought it might be useful to clarify a few things.

    -- The CERT/CC has issued 3 advisories on the general area of Code Red
    and the related vulnerability in IIS.

    http://www.cert.org/advisories/CA-2001-13.html
    http://www.cert.org/advisories/CA-2001-19.html
    http://www.cert.org/advisories/CA-2001-23.html

    CA-2001-13 describes the vulnerability, and was issued shortly after
    Microsoft's bulletin on the problem.

    CA-2001-19 describes the first appearance of Code Red, and CA-2001-23
    describes the expected impact of Code Red in August.

    In our original advisory (13) we said

    "Imapct: Anyone who can reach a vulnerable web server can execute
    arbitrary code in the Local System security context. This results in
    the intruder gaining complete control of the system. Note that this
    may be significantly more serious than a simple "web defacement."

    In the first description of "Code Red," (19) we said:

    "The "Code Red" worm is self-replicating malicious code that exploits
    a known vulnerability in Microsoft IIS servers (CA-2001-13).

    "The "Code Red" worm attack proceeds as follows:

    "The CERT/CC encourages all Internet sites to review CERT advisory
    CA-2001-13 and ensure workarounds or patches have been applied on all
    affected hosts on your network.

    "If you believe a host under your control has been compromised, you
    may wish to refer to

    Steps for Recovering from a UNIX or NT System Compromise"

    In the third advisory (23) we said:

    "Our analysis estimates that starting with a single infected host, the
    time required to infect all vulnerable IIS servers with this worm
    could be less than 18 hours. Since the worm is programmed to continue
    propagating for the first 19 days of the month, widespread denial of
    service may result due to heavy scan traffic.

    "As reported in CA-2001-19, infected systems may experience web site
    defacement as well as performance degradation as a result of the
    propagating activity of this worm. This degradation can become quite
    severe, and in fact may cause some services to stop entirely, since it
    is possible for a machine to be infected with multiple copies of the
    worm simultaneously.

    "Furthermore, it is important to note that the IIS indexing
    vulnerability that the "Code Red" worm exploits can be used to execute
    arbitrary code in the Local System security context. This level of
    privilege effectively gives an attacker complete control of the
    infected system."

    I feel confident that I haven't overlooked the phrase : "the internet
    will cease to exist." Indeed, I'm rather confident the Internet will
    continue to exist through August. September is another matter
    entirely. :-)

    At this point in time (7:02 PM EDT, 7/31/2001), I personally
    anticipate that the worm will begin spreading again within a few
    hours, and that we'll reach saturation (all vulnerable, reachble
    servers compromised) within 96 hours. I further expect that the number
    of vulnerable machines will be substantially smaller this round. The
    question is, by how much.

    Shawn Hernan
    Vulnerability Handling Team Leader
    CERT/CC

  7. Re:The Entire Internet Will cease to exist... by Anonymous Coward · · Score: 1

    Are you kidding? IIS runs less than 25% of the net's web servers, and what percentage of those do you think have the time mis-set? This sounds like the percentages in a *BSD is Dying troll.

  8. Re:Microsoft can fix this! by phil+reed · · Score: 1

    Uh, it does. On Windows Update it's referred to as the Indexing Service patch, but it's there and automatically installed as part of the Critical Updates section.


    ...phil

    --

    ...phil
    "For a list of the ways which technology has failed to improve our quality of life, press 3."
  9. Re:And the REALLY sad thing. . . by echo · · Score: 1

    The /REALLY/ sad thing is that patching a web server APPLICATION requires you to REBOOT the OPERATING SYSTEM!

  10. Re:And the REALLY sad thing. . . by echo · · Score: 1

    I was basing my comment on what the previous poster said about rebooting, I haven't used the Code Red patch, because I don't run Windows.

    So don't complain at me, I'm not the one scheduling reboots of servers.

  11. The Story's a Troll by Threed · · Score: 1

    USENET old timers are used to people claiming the net will die. "Emminent death of the internet predicted!" But it keeps not happening.

    But it makes Slashdot because 1) it has to do with Microsoft 2) it's a followup story 3) someone in a tie wrote it so it must be true. But that suit just trolled you better than theElectron.

    The real Threed's /. ID is lower than the real Bruce Perens'.

    --Threed

  12. Coca Cola by Threed · · Score: 1

    From the company reps lips: "Cocaine has never been an added ingredient in any Coca Cola product."

    Technically, they're right. It wasn't an /added/ ingredient, though it certainly tagged along as part of their coca leaf flavoring. It was later replaced with caffeine, but Coca Cola still has a grandfather clause allowing them to import "denatured" coca leaf extract.

    Anyway, that's where "Coke" as dual use street slang came from.

    The real Threed's /. ID is lower than the real Bruce Perens'.

    --Threed

  13. Re:Worms and market share by SJS · · Score: 1
    ...and nobody bothers writing a virus for an OS like Linux.
    Huh?

    What about the Lion (Linux BIND) worm?

    --
    Pick One: http://www-rohan.sdsu.edu/~stremler/sigs/sigs.html (Note - disable Javascript first!)
  14. How come.... by talks_to_birds · · Score: 1
    ...you seem to be talking about Internet Information Server, but Micro$oft's own security bulletin seems to be talking about Internet Indexing Service?

    Just wondering...

    t_t_b
    --
    I think not; therefore I ain't®

    --
    I'm on PJ's "enemies" list! Are you?
    1. Re:How come.... by Strangely+Unbiased · · Score: 1

      You're right. But Indexing Service works in conjunction with IIS.Not exactly a part of IIS, but kind of.If you do not have IIS enabled, you are not vulnerable to the attack. And since most of the times it's the IIS's fault, I'm talking about that.

      --


      There is no such thing as 'world peace'.
  15. Re:Code Red Sci-Am article by Exocet · · Score: 1

    Carolyn Meinel is, in a nutshell, a flaming idiot. It's a credit to her social engineering skills that she managed to get Scientific American to publish her nasty fluff - and a discredit to SA.

    http://www.dis.org/shipley/cpm/
    http://www.shmoo.com/mail/cypherpunks/may99/msg001 41.html
    http://www.landfield.com/isn/mail-archive/1998/Nov /0040.html

    Wooo! Just do the following search on google: "Carolyn Meinel" site:attrition.org

    ...She's made about as many friends in the security community as Bill Gates would at a LUG meeting.

    --
    Exocet Industries - Taking over the world, one computer at a
  16. Re:Apache problem by laertes · · Score: 1
    To be honest, apache may be vulnderable; however, it's not quite as simple as that. In linux, you could theoretically do wacky things, like disable outgoing connections on port 80. If linux had finer grained security, you could even do this without interfering with mozilla's attempts to connect out on port 80. The beautiful thing is, as linux is open source, you can make said modifications. See the NSA modifications.

    Also, you could limit the outgoing bandwidth, or disable outgoing pings. You could even write an anti worm program, which gets updated worm attack patterns from some website, and looks at every outgoing web request for possible matches. Further, apache and linux run on different hardware, and apache runs on non-linux operating systems too, making apache much less homgenous an entity than IIS. And finally, the average linux user is much more likely to upgrade their operating system for security reasons that your average windows user.

    By the way, Apache is free as in speech, too, which is why I like it (well, that and the fact that I can pronounce "apache" easily; it's not a tounge twister like "IIS").

    --

    Yes, I'm still a junky. Are you still a bitch?
  17. Re:Mis-set clocks? by unitron · · Score: 1

    A Windows machine running forever? Please.

    --

    I see even classic Slashdot is now pretty much unusable on dial up anymore.

  18. No shiiiiiiiitt! by KlomDark · · Score: 1
    This has been getting really stupid lately. K5 and .5e are really doing a lot better than this lately.

    It's pretty much a balance of quantity vs quality- ./ has a new (but quite often lame and stupid) article to read every hour or so, while K5 and .5e the articles are much better, but less quantity. I can't stop but keep checking ./ every couple hours, but the others are something I only check once or twice a day.

    Just waiting for something to get better. Either here or them, some reason to keep or stop going here.

  19. Spoon? by KlomDark · · Score: 1
    I thought it was "There is no spoon"... :)

    Don't worry about the Internet...

    What Internet?

    *CRASH*

    That Internet... It's OK, have a cookie. (Or maybe "Have a Code Red Mountain Dew")

  20. Re:The Entire Internet Will cease to exist... by Bob+McCown · · Score: 1

    You forgot to include your ... tags....

  21. Re:CNN this morning by kurowski · · Score: 1
    ...they call the owner of the companie's kid, who doesn't know anything at all about security, he manages to know a few simple things about computer hardware, but not that a motherboard with an AGP1x does not work well with AGPPro cards

    and that is relevant to system administration in general, or security specifically, how?

  22. Re:a taste of what's to come by kurowski · · Score: 1
    Every PC, PDA, cell phone, and dog collar will be running a Microsoft OS and accessing its data over .NET.

    *cough*Mono*cough*

    What happens when the .NET version of Code Red comes out? What then? All my data is wrapped up in .NET. Everything I do is on a server somewhere but the wireless .NET is too bottlenecked for me to get to it.

    *cough*DotGNU*cough*

    When are people going to get the hint that despite all their propoganda, Microsoft is not good for anyone.

    People will only get the hint when compelling alternatives are produced.

  23. I dont belive that 40% of the world could kill by johnjones · · Score: 1

    right

    apart from the network traffic which the isp should regualte anyway what does this do ?

    infects IIS servers but they run under 40% thats right UNDER now if apache had a whole like this then the world would be in for a shock !!

    but I dont belive that this could do anything except give credance to the admins who pull plugs out of walls when they are labeled

    "MIS webserver (win2000)"

    fankly fools damn fools and microsoft IIS administrators

    sorry but how can this bring the world to an end ?

    "life finds a way " -> "randomness protects the internet"

    regards

    john jones

    1. Re:I dont belive that 40% of the world could kill by StueyB2U · · Score: 1

      Just a few points:

      1. I agree that admins who dont patch servers are pretty stupid !!!
      2. Some of us dont know enough unix to competantly administer such box if things do really go wrong.

      Surely it is a better idea to have a well patched and secured IIS Server that behaves and is robust and hacker resistant (not hacker proof you note, no system can be totally secure) than a dodgy Apache installation.

      I'd love to be able to run Apache on our web server, its faster, more robust and doesnt crash all the time, but you need to know what you are doing !! I have a lot of knowledge (no I aint an MCSE - dont want to be !! all paper and no tech knowledge) but if I where to implement a RedHat/Apache solution, it wouldnt be as secure (due to me not bieng up on *nix systems)and it would be harder for me to maintain when you get things like kernel panics (wouldnt know what to do)

    2. Re:I dont belive that 40% of the world could kill by Tassach · · Score: 2
      Applying patches willy-nilly can be just as bad as NOT applying them. Applying a patch can break dependencies or expose bugs that were previously overlooked. Patches can introduce new bugs too -- just ask anyone who was misfortunate enough to install NT Service pack 6 the first few days it was available.

      When you are administering a critical production server, you don't make ANY change to the system without a good reason, and if you do you damn well make sure you test the patch on non-critical systems first.

      --
      Why is it that the proponents of "one nation under God" are so eager to get rid of "liberty and justice for all"?
    3. Re:I dont belive that 40% of the world could kill by einhverfr · · Score: 2
      Too many IIS admins I have spoken with say the following things:
      "Security patch? Yeah, I just downloaded it from Norton!" and
      "Backup? What if I don't have a backup?"

      The problem, IMO, is that servers should be administrator friendly and transparent. They should make the administrator part of the process. In this way, I think that UNIX is a better OS for servers than NT.

      Contributing factor: how many questions on the NT4 MCSE covered security or disaster recovery?

      Sig: Tell all your friends NOT to download the Advanced Ebook Processor:

      --

      LedgerSMB: Open source Accounting/ERP
  24. Fire with fire by bkocik · · Score: 1
    I had this idea earlier. It'd most certainly be illegal (even though you could convincingly argue that it shouldn't be), but it would still be fun, and probably effective if enough people used it.


    I thought, why not write a servlet/JSP/cgi/whatever that detected an inbound hit from a Code Red infected server, and responded by using the same vulnerability to turn around and turn off the worm on the offending box?


    Like I said, probably illegal...but a cool concept, I think. If I had the time I might put a servlet together, but I don't, and it's probably too late for today's attack anyways.

    Regards,

  25. Re:Worms and market share by Mike+Schiraldi · · Score: 1

    It's "viruses", not virii.

  26. Re:And the REALLY sad thing. . . by Salgak1 · · Score: 1

    Except all of my IIS boxen use Indexing Services. Wierd. . .

  27. And the REALLY sad thing. . . by Salgak1 · · Score: 1
    is that people still haven't patched. I have several managed webservers at a co-lo site, and to play it safe, asked them it they'd installed it yet.

    And was asked when they could re-boot the boxen, a fairly strong indication that they hadn't installed a routine security patch until I asked about it. . .

    Luckily, Cringely gave me an idea for a quick fix: since our Maintenance Window on the boxen is 0-dark-early in the morning, and the worm hits at 0000 GMT tonight (8 Eastern, 4 Pacific), TURN YOUR NT/2000 boxes back a day, and then reboot early tomorrow morning, and re-set your date to the correct one...

    Of course, if they'd listened to me and used Apache, we wouldn't be having this problem...

    1. Re:And the REALLY sad thing. . . by Salgak1 · · Score: 1

      They're all development variants of our production servers. I built them all with the same install script. I can only assume developer tweaks have diverged the boxen enough over the 8 months I've been here. . .

    2. Re:And the REALLY sad thing. . . by Salgak1 · · Score: 1

      Most of my local IIS boxen did not require a reboot, 2 did. Damned if I know why, either. . .ya gotta LOVE Windows (NOT!)

    3. Re:And the REALLY sad thing. . . by LinuxHam · · Score: 1

      The exploit works even if the Indexing Service is not running. The key is to remove the dll mapping for .ida. What's worse is that just about any action in modifying your IIS configuration will reenable the offending mapping if you have disabled it.

      The patch from Microsoft allows that mapping to remain permanently removed.
      --
      Steve Jackson

      --
      Intelligent Life on Earth
    4. Re:And the REALLY sad thing. . . by SuiteSisterMary · · Score: 1

      Yes, but had they used it recently? It's an ISAPI dll, and should get unloaded if it's not used for a while.

      --
      Vintage computer games and RPG books available. Email me if you're interested.
    5. Re:And the REALLY sad thing. . . by bpellin · · Score: 1
      I would venture to say that linux has reached critical mass on the internet. Afterall, we are talking about servers here. Maybe everything implemented now isn't linux, but I wouldn't be surprised if linux was growing fastest in the server market. You just don't go out and buy SCO Unix, or HPUX to serve webpages these days, and speaking for the standpoint of an ISP, we only have enough Windows webservers to placate the users who demand them. Anyone have links to statistics?

    6. Re:And the REALLY sad thing. . . by LordKariya · · Score: 1

      Reboot system = remove worm from memory

      Why not have everyone reboot at midnight (adjusted to your time zone) August 1st ? Seems simple, but it would work.

      --
      I alternate between posting +5 and -1 Comments. Karma: +53 -47 = 6
    7. Re:And the REALLY sad thing. . . by kiwimate · · Score: 1

      Do they? Or is it just *installed*? Indexing Services gets installed as part of the default installation, but a lot of boxes don't actually *use* its functionality.

      A bit like documentation and geeks, really.

    8. Re:And the REALLY sad thing. . . by SuiteSisterMary · · Score: 2
      However, unless the admins have the time and the knowledge to turn this service off, it will continue to be a problem.
      And the first line of any 'how to secure a network operating system' text is 'turn off things you don't need.' The 'How to secure IIS' checklists and docs that Microsoft puts out all list several aspects of IIS that should be shut off; sample apps, admin pages, stuff that makes sense on an Intranet but not on the Internet. A lazy admin can install NT2K and have a bunch of security holes because they put it on the network and walk away. Guess what happens if they install everybody's golden OS, Linux? Same shit. Why do you think there are projects like Bastille? If Linux ever achieves critical mass on the Internet, it'll be targeted, and compromised, by just as many of these things as NT/IIS has ever been.
      --
      Vintage computer games and RPG books available. Email me if you're interested.
    9. Re:And the REALLY sad thing. . . by SuiteSisterMary · · Score: 2

      The exploit, and the patch, affect Indexing Service. Most sites aren't actually using Indexing Service. Hence, no reboot required.

      --
      Vintage computer games and RPG books available. Email me if you're interested.
    10. Re:And the REALLY sad thing. . . by Saint+Aardvark · · Score: 2
      Mmm...IIRC, the worm is memory-resident -- so while installing the patch doesn't require a reboot, you do need to take it down if you *have* been infected in order to clear it out of memory.

      But I could be wrong. Hell, I remember the last time that happened. I believe it was a Thursday...

    11. Re:And the REALLY sad thing. . . by MrBogus · · Score: 2

      The 'How to secure IIS' checklists and docs that Microsoft puts out all list several aspects of IIS that should be shut off; sample apps, admin pages, stuff that makes sense on an Intranet but not on the Internet.

      True, but it's still irresponsible for Microsoft to ship a webserver (or any 'Internet' software) that come out of box with an inherently insecure configuration. Given the rate of IIS bugs that affect non-core components, Code Red is just the beginning of the iceberg until admins figure out how to turn this stuff off.

      --

      When I hear the word 'innovation', I reach for my pistol.
  28. Re:Microsoft should just give up on IIS by CerebusUS · · Score: 1

    My boss has just told our head of technical support to download the patches.
    I said to our head of technical support "We don't need no steenkin' patches!"
    Running Apache on Linux has turned out to be the right choice!


    riiiight. Apache needs no patches

    The tooth fairy will protect you.

  29. A virus that patches M$ exploits by chryptic · · Score: 1

    I was thinking that since the hole this virus exploits allows it to exicute any code it wants why not alter the virus to install the patch from M$?

    The way I see it any system that is still vunerable will always be. The people running those systems are not paying attention and will never install the patch themselves. But since this worm is so good at finding those systems why not use it to force an update?

    --
    The two most common things in the Universe are hydrogen and stupidity. -- Harlan Ellison
  30. Re:From cringely's article by Azghoul · · Score: 1

    I thought he was just going to point out Apache.
    Or well, what the hell, ANY web server that is not IIS.

    All kinds of people will see that as being just as bad, because replacing IIS would force them to use non-MS software, require some training (I'm available!), roll out new/updated servers, etc etc...

  31. Re:Beter yet - the reboot virus by hrm · · Score: 1

    Better do rigorous bug testing before releasing such a "benevolent worm". I hear Morris originally planned something else for his worm, too :-)

    Seriously, it won't be a proper solution anyway because any future mutations are bound to be disk-resident (and thus immune to reboots). They might even rely on a reboot to do serious damage, given Window's unwillingness to write to files (like, say, MSVCRT.DLL) while they're in use.

  32. Re:The Internet will "cease to exist" ? by odaiwai · · Score: 1

    Capitalizing occasional words like that always reminds me of Robert McElwaine. "FULL and COMPLETE dissemination is ENCOURAGED..."

    dave

  33. Talk Show hosts by spudnic · · Score: 1

    I've heard several talk show hosts over the last couple of days read the press releases about code red infecting all these MS servers.

    They invariably follow it up by saying, "Yeah, I got about 200 copies of code red in my inbox yesterday asking for my advice, but I was smart enough not to open them."

    Geez.

    --
    load "linux",8,1
  34. blah... by zook · · Score: 1
    I have a hard time getting too excited or upset about this. In fact, I have a hard time feeling that whoever wrote this is all that evil.

    Let's look at it this way, someone took a bug that existed in a product and exploited it in a way that made it very clear that it was being exploited. Result: MS publishes a patch. If they were really mallicious they'd make a much more subtle attack that MS wouldn't be so quick to recognize and fix.

    As for the horrible things that this will do to us, let me ask you all this: would you rather have an attack like this one that will slow things down, and maybe even shut down a few web sites, or would you like to have someone exploit web servers to get your credit card number?

    As a consumer I'd rather do without [insert favorite e-commerce site here] for a while than have to deal with someone stealing my information off of a web site.

    Both happen, both get some publicity, but the one that industry cares about is the one that everyone is up in arms about.

    1. Re:blah... by zook · · Score: 1
      I love the intelligent tone of the commentary on Slashdot.

      I don't care too much whether MS posted the patch before or after the worm came out, though you're almost certainly right on this point. I'm not trying to bash MS here, and I'm definately not trying to get into the whole "linux rules, down with M$" garbage. Were this an Apache bug the same situation might arise.

      Rather, it's obvious that many system administrators have not patched this bug, but certainly with a high profile attack like this one many will. If, instead, there was a more sneaky attack, people might be slower to recognize it as a problem, and hence slower to respond. The end result might not be so spectacular, but might cause more real harm.

  35. Late warning by perrin5 · · Score: 1

    Dear Slashdot moderators:

    Thank you for warning us of such a problematic issue THE DAY IT"S SCHEDULED TO GO OFF!!!!! Not to poke any sarcasm your way or anything.

    I'm sure I'm not the first one to have pointed out the IIS second-wave yesterday:
    2001-07-30 19:28:56 'Code Red' Worm might be coming back (articles,microsoft) (rejected)

    But, don't you think that putting out the word yesterday, when we already had stories out, would have reminded those sysadmins lax enough to "worry about it later" to get on the ball and patch their servers?

    Just curious

    --
    hmmmm?
  36. Much Ado About Nothing by drfalken · · Score: 1

    I don't think much will come of this. Cringley is an idiot. His comments that as long as there's one server with a broken clock the worm will always be with us is stupid. There are loads of viruses in the wild that continually spread but are harmless because the software they infect has been patched and/or anti-virus software continues to keep them at bay.

    I have been getting calls from people all day asking why I haven't sent out a warning about this worm. The problem here is that the media has hyped this up and the average joe doesn't understand that it can't infect their Win9x desktop so everyone is freaking out.

    I doubt that much will happen. I lived through Y2K and the Internet gold-rush. Things online are rarely what they seem.
    ----------------------------

  37. Cringely by Monte · · Score: 1

    Along the same lines, am I the only person who has a problem with Cringley? After watching his PBS show about building an airplane in thirty days, I was convinced the guy has more money than brains, and that his infamy is due more to who he knows than what he knows.

    To get a good idea of just what he does know you might want to read his book "Accidental Empires", which IMHO is a pretty good look at the history of the microcomputer revolution.

    You should be able to get a copy cheap from half.com.

  38. Re:Fatal Infections by T3kno · · Score: 1

    A worm like Code Red doesn't care if the final host is "destroyed" because it launches all of the attacks from cracked Sun boxen. This way you always have a staging area from which to launch the attack

    --
    (B) + (D) + (B) + (D) = (K) + (&)
  39. Re:Are there any non-microsoft viruses anymore? by LinuxHam · · Score: 1

    Back before I knew what I was doing, a Linux host I had up on the net got hacked by the Ramen worm. BIND has got to be the closest open source product to IIS with respect to massive numbers of vulnerabilities that give "immediate root access" to quote SANS.

    I feel UNIX/Linux will always beat Microsoft hands down because of chroot jails. If you chroot Apache or BIND running as a non-privileged user and they get cracked, the cracker will have nothing more to fark with than the individual service they cracked. Not to downplay the severity of that situation, but at least they won't get root access on your box. Furthermore, if you script nightly overwrites of the directories hosting those services from protected locations, the hack won't be long lived.

    Add to that web programming that uses protected connections to Java servlet engines (i.e. Tomcat listens on localhost-only), and you can easily and frequently rebuild your websites the moment Tripwire detects that something has changed.

    And so long as Linux and UNIX run neck-and-neck in vulnerabilities, I have no interest in running a commercial UNIX. And no, BSD is not an option for me so long as I wish to run commercial (or even current) apps. I found out last night that FreeBSD is just now getting Java **1.2** in Beta. Forget about Jakarta Tomcat and Cocoon. Gimme a break. Looks like BSD is best for static HTML or perl CGI.
    --
    Steve Jackson

    --
    Intelligent Life on Earth
  40. Re:The Internet will "cease to exist" ? by LinuxHam · · Score: 1

    There's a difference between web servers and web sites.. I've been searching and searching but I can't find the article right now.. I recall reading a recent /. article linking to Netcraft, but I can't seem to locate it.. anyway, here's the gist of it.. now follow me here..

    1/4th of the world's web SITES run under IIS on 2/3ds of the world's web SERVERS. And the opposite is true for Apache.. 2/3ds of the world's web SITES (the 62% you always hear about) run on just 1/4th of the world's web SERVERS. In short, IIS (or its admins) are not very good at virtual hosting (running more than one totally independent website on one box), while one beefy Apache box can host 50 or 100 different web sites.

    Again, TONS of vulnerable servers host a small portion of the Internet's web sites (and can cripple the net with traffic), while the VAST MAJORITY of the world's web sites run on far fewer servers running non-vulnerable Apache servers.

    Imagine if Sourceforge ran on IIS? That would be one way to get a free co-lo! Open a project, get a free server all to yourself! At least until they figure out how to add a second virtual domain to the server they gave you.
    --
    Steve Jackson

    --
    Intelligent Life on Earth
  41. Re:Are there any non-microsoft viruses anymore? by LinuxHam · · Score: 1

    Perhaps I should have said BIND and Sendmail together give IIS a run for the money in the vulnerability list. :)

    At least there are viable secure alternatives to Sendmail in Qmail and Postfix. With BIND, you can reduce the privileges, but you really need to chroot jail it. I didn't want to go TOO long on the post, so I chose to bash BIND the hardest :)

    And just a reminder: click here for the ten worst and most abused vulnerabilities.. lisitng BIND *and* Sendmail holes.
    --
    Steve Jackson

    --
    Intelligent Life on Earth
  42. My God don't remind me... by LinuxHam · · Score: 1

    Service Pack 6 knocked out email for 5,000 users of NTWS at my company because MS decided to ship out a patch that forced the logged in user to have **Admin** privileges just to use TCP/IP. Lotus Notes? Dead in the water. IE? Shot. Logins? Nope. Drive mappings? Forget it.

    Didn't we test it? Of course we did. Unfortunately our "user" accounts were also domain admins, so it didn't appear in our extensive testing.

    That was a bad day at the office. We definitely regretted finally getting software delivery working under CA TNG (another pain in the ass software manufacturer).
    --
    Steve Jackson

    --
    Intelligent Life on Earth
  43. Not from China? by Palshife · · Score: 1

    News.com says:

    Despite Web site postings that said "Hacked by Chinese," a Chinese network safety official says that the fast-spreading Code Red Internet worm was probably not made in China.

    I'm inclined to agree. This is simply someone who wants to forcibly make their political views known through a worm. Probably the best way of going about it these days, but I certainly dont condone the method.

    You CAN use Pine for windows, you know...

    --
    Attention deficit disorder is a complicated issue, spanning several major... HEY LET'S GO RIDE BIKES!
  44. Devils Advocate by pipeb0mb · · Score: 1

    OK...so we agree that MS' IIS is at fault for this worm. A bug in the software is a 'bad thing'.
    However, ALL software is buggy. Repeat, ALL.
    How many patches have been made for Apache or Perl or ProFTPD or ftpd?
    Dozens...

    Microsoft has done what they have to do, take the public beating and made a patch available.
    If Apache were a company, would there be the same outcry if this worm affected it? Probably not, because, outside of the Redmond campus, Apache is not reviled and hated.

    Calls for a class action suit and legal recourse are totally opposite of what should be advocated on this forum...since when is litigation the answer? (Ask Dmitri...)Why not contact the companies affected and offer your services in promoting a BSD or Linux?
    Like Taco implied a few weeks ago, bashing is out; promotion is IN!


  45. Re:LINUX SUCKS ASS by daveman_1 · · Score: 1

    Learn

    To

    Use

    The

    Break

    Tag

    Troll.

    --
    Russian Russian Russian RussianDollSig DollSig DollSig DollSig
  46. Re:So why doesn't someone release a counter-virus? by daveman_1 · · Score: 1

    This was covered in Cringely's article. They don't want to start acting like the bad guys.

    --
    Russian Russian Russian RussianDollSig DollSig DollSig DollSig
  47. Overblown media hype by jfp51 · · Score: 1

    Please... According to various security lists that I receive, once the worm goes into its dormant stage it does NOT wake up again. However, the risk is from new variants of the worm, or crackers finding a way to reactivate the dormant worm. Anyways, if people haven't patched their boxes by now (and they should have done it at least one month before Code Red erupted when MS released the security bulletin, even longer if you follow their IIS security checklist), I don't know what we should do with these people. If you don't patch your boxes, they will get compromised. How much time did it take to compromise the Honeynet project's Red Hat default install, 13 minutes or something? Not just an MS problem folks, it's a stupidity problem

  48. Re:Microsoft should just give up on IIS by jfp51 · · Score: 1

    We run IIS servers. We keep said IIS servers patched. We have had no probs with code red. Keeping our boxes current has turned out to be the right choice

  49. Re:Code Red Sci-Am article by Shanep · · Score: 1

    Thanks for wasting heaps of my time Exocet! I found this Carolyn Meinel bitch very morbidly fascinating. : ) Kinda like when people come out to see traffic accidents, hoping to see some guts on the road, etc.

    Some of the stuff at http://www.attrition.org/shame/index.html was really funny.

    --
    War crimes, torture, lies, illegal spying... Would someone give Bush a blowjob, already, so he can be impeached?
  50. Very Scary Quote by medcalf · · Score: 1
    The government relies on Microsoft ... to secure everything from defence networks to financial systems.
    Because, after all, their proven security record is a real inducement to trusting them with security.
    --
    -- Two men say they're Jesus. One of them must be wrong. - Dire Straits
  51. Re:New ways to patch MS holes by Lew+Pitcher · · Score: 1

    My point is that if people don't use the tools already availible, why would the take the time to opt-in to this program?

    Because they could 'opt-in' once, and let the holes take care of themselves, rather than opting in seperately for each hole found.

    With the number of holes in MS products, it's easier for a typical, poorly educated NT Administrator to opt-in once and have the problems fixed automagically, then to keep reading BugTraq, locating, downloading, and applying fixes, and justifying his salary (and the server downtime) to his boss.

    ;-)

    --

    "values of beta will give rise to dom!"

  52. New ways to patch MS holes by Lew+Pitcher · · Score: 1

    According to one of the articles, Microsoft is looking for new/improved ways to distribute security fixes to broken systems. My suggestion, with some qualifications, would be to distribute fixes through the identified security holes.

    Just as attacks like "Code Red" take advantage of security holes to place priveledged code on vunerable systems, Microsoft could package hole-fixes into packages that prowl the internet looking for exposed systems. If the package (call it a 'worm') discovers a system with the appropriate hole, it enters the system, and replaces the faulty software with a patch.

    Now, lest Microsoft be accused of unleashing attacks against exposed systems (beneficial attacks to be sure, but attacks none the less), the worms would only approach systems that have subscribed to this as a service. Additionally, each worm would inform the Administrator of the system (through email, or some other messaging service available in MS products) that an exposure has been discovered and a patch has been applied.

    Of course, there would be an element of trust necessary here. The worm must also give the Administrator some sort of assurance that its changes are beneficial (we don't want attacks masquerading as patches), so there has to be some sort of confirmation/activation/deactivation process available to the Administrator, but I'm sure that, if Microsoft is serious about it's commitments (and it's revenues), this can be adequately worked out and implemented.

    --

    "values of beta will give rise to dom!"

    1. Re:New ways to patch MS holes by Zack · · Score: 2

      would only approach systems that have subscribed to this as a service.

      inform the Administrator of the system (through email

      some sort of confirmation/activation/deactivation process available to the Administrator

      I've got an idea too! How about an "opt in system" where system administrators get emailed a location to where the "patch" is! That way they would:
      1) Be informed of the problem.
      2) Told where to get the fix
      3) Have some sort of confirmation/activation/deactivation process available to the Administrator

      Or how about a web page where users could find updates?

      Or maybe a site that tracks bugs in software?

      And all that without having to have microsoft send out more stupid worms.

      My point is that if people don't use the tools already availible, why would the take the time to opt-in to this program?


      -- Zack

  53. It's time to clean the Internet! by Stonehand · · Score: 1

    An old April Fools joke come true?

    *** Attention ***

    It's that time again!

    As many of you know, each leap year the Internet must be shut down for
    24 hours in order to allow us to clean it. The cleaning process, which
    eliminates dead email and inactive ftp, www and gopher sites, allows
    for a better-working and faster Internet.

    This year, the cleaning process will take place from 12:01 a.m. GMT on
    Feb. 29 until 12:01 a.m. GMT on March 1. During that 24-hour period,
    five powerful Internet-crawling robots situated around the world will
    search the Internet and delete any data that they find.

    In order to protect your valuable data from deletion we ask that you do
    the following:

    1. Disconnect all terminals and local area networks from their
    Internet connections.

    2. Shut down all Internet servers, or disconnect them from the
    Internet.

    3. Disconnect all disks and hardrives from any connections to the
    Internet.

    4. Refrain from connecting any computer to the Internet in any way.

    We understand the inconvenience that this may cause some Internet
    users, and we apologize. However, we are certain that any inconveniences
    will be more than made up for by the increased speed and efficiency of
    the Internet, once it has been cleared of electronic flotsam and
    jetsam.

    We thank you for your cooperation.
    Kim Dereksen
    Interconnected Network Maintenance staff
    Main branch, Massachusetts Institute of Technology

    Sysops and others: Since the last Internet cleaning, the number of
    Internet users has grown dramatically. Please assist us in alerting
    the public of the upcoming Internet cleaning by posting this message
    where your users will be able to read it. Please pass this message on
    to other sysops and Internet users as well. Thank you.

    --
    Only the dead have seen the end of war.
  54. A IIS Patch Worm... by Jace+of+Fuse! · · Score: 1

    What would really amuse the hell out of me is if someone were to write a Worm that went out to IIS servers and patched them for the idiots who are too damned stupid to do it themselves.

    Alternatively, someone should write a Worm that takes down the machine entirely and leaves a helpful note to the admin explaining to them how to take his or her head out of their arse (i.e. patch the system or run less exploitable software).

    "Everything you know is wrong. (And stupid.)"

    --

    "Everything you know is wrong. (And stupid.)"

    Moderation Totals: Wrong=2, Stupid=3, Total=5.
  55. OT - Ford / Firestone by Ender+Ryan · · Score: 1
    Actually, isn't the Ford Explorer supposedly and offroad vehicle? Tires for an offroad vehicle should be semi-deflated(or at least be able to be).


    Any offroad tire should (and do) handle that just fine. Either Ford uses crappy road tires(probably) or Firestone tires are shit(probably true also).


    Either way, it looks to me like they're both to blame.


    (ok, now mod me offtopic)

    --
    Sticking feathers up your butt does not make you a chicken - Tyler Durden
    1. Re:OT - Ford / Firestone by Ender+Ryan · · Score: 1

      Yeah, that's about what you'd figure these days.

      Damn, I friggin hate all these new SUVs, what crap. They're worthless! WTF is the point, take a truck frame, put car tires on it, leather, flashy paint, flashy rims, flashy chrome shit all over the place, which makes it.... A glorified mini-van.

      I've been a Jeep owner for 5 years, I love them. I just got rid of my Wrangler a few months ago, but I still have a Cherokee. When I have the money, I plan to get another Wrangler or CJ to play with.

      --
      Sticking feathers up your butt does not make you a chicken - Tyler Durden
    2. Re:OT - Ford / Firestone by NewOrder · · Score: 1

      Yeah, When I take my jeep offroading or even in 6 or more inches of snow on the ground I defalte my tires from 40PSI to 20PSI (in extream cases 10PSI). makes one hell of a differnece in traction. But I do not dare go above 60MPH (20psi, 30mph @ 10psi) in those defalted conditions for long periods of time. That creats extream amounts of heat and is just terminally stupid.

      But the ford SUV is no off road machine at all. it's a POS luxury SUV ppl by to feel "safe" and to make it over speed bumps.

      --
      -- Jason...
  56. Woohoo! by Ratchet · · Score: 1

    First good thing to come from an internet-wide virus attack, the company I "work" for has <I>finally</I> decided to switch from NT/IIS to Linux/Apache!
    WOOHOO!!

  57. Re:Gibson may be extreme, but he does have a point by kootch · · Score: 1

    sorry to nitpick, but you statement about companies attempting to keep their computer systems up to date was just a bit too much.

    I know of way too many large companies that are just now upgrading from Win95 to Win2000 (they skipped NT4 and Win98).

    Large companies don't like to upgrade, and when they upgrade, lots of machines at a time are left unmaintained by the systems people because they're busy configuring the new machines and fielding requests by the new users who can't find their bookmarks and such.

  58. Re:Microsoft should just give up on IIS by jhines · · Score: 1

    Or take a clue from the OpenBSD project, and audit their code, and fix all of the buffer overruns, and other problems that have plagued them in the past, and are usually repeated the same way throughout the code base.

  59. Re:Best-case scenario by DebtAngel · · Score: 1

    Your friend does know he can get CF for Linux, right?

    Now, while he might as well take the time to learn PHP anyway, it's not like Allaire/Macromedia has been ignoring the Linux market.

    --

    Is this post not nifty? Sluggy Freelance. Worshi

  60. Facts all up the wazoo by kimihia · · Score: 1
    it's just because they don't have much market share and nobody bothers writing a virus for an OS like Linux

    Buddy, have you read the most recent Netcraft Web Server Survey, released barely two days ago?

    And another thing, the reason why Linux is not infected is because it didn't have that silly buffer overflow.

  61. Re:They seem to be making a real publicity effort by mrogers · · Score: 1
    a. To rid your machine of the current worm, reboot your computer.
    b. To protect your system from re-infection:
    Install Microsoft's patch for the Code Red vulnerability problem:

    Surely that should be:

    a. Take your machine offline
    b. To rid your machine of the current worm, reboot your computer.
    c. To protect your system from re-infection:
    Install Microsoft's patch for the Code Red vulnerability problem:
    d. Take your machine back online

    Otherwise there's a chance you'll be reinfected between rebooting and upgrading.

    --

  62. Re:Best IIS Patch by John3 · · Score: 1

    I also patched my IIS system years ago by upgrading to Website Pro (formerly O'Reilly, now Deerfield) from Bob Denny.
    www.big-box.com - Covering the world, one community at a time

    --
    "We make our world significant by the courage of our questions and by the depth of our answers." Carl Sagan
  63. Who modded the parent up? by dave-fu · · Score: 1

    To quote Marc Maiffret, "We've designated this the .ida "Code Red" worm, because part of the worm is
    designed to deface web pages with the text "Hacked by Chinese" and also
    because code red mountain dew was the only thing that kept us awake all last
    night to be able to disassemble this exploit even further.
    "
    If you want to blame someone, blame eEye; for once, a journalist isn't to blame. I'll content myself with wagging an accusatory finger at the braindead moderators who dumped points in your lap.
    Easy does it!

    --
    Easy does it!
    This comment has been submitted already, 276865 hours , 59 minutes ago. No need to try again.
  64. No difference. by dave-fu · · Score: 1

    Best practices dictates that you uninstall any unneeded services: you install a vanilla (OS of your choice) server and point it to the internet, it's gonna get rooted in no time; the Honeynet Project has shown this to be (perhaps not statistically) true.
    The service may have been exploitable, but the VAST majority of websites weren't even using it and as such should have removed the script mappings (and DLLs, for the truly paranoid).
    Of course, IIS patches do a fine job of restoring script mappings behind your back, so maybe you have a point after all?
    Easy does it!

    --
    Easy does it!
    This comment has been submitted already, 276865 hours , 59 minutes ago. No need to try again.
  65. It was discussed on Bugtraq. by dave-fu · · Score: 1

    File it under bad idea: you release it, you're liable. Unless you can test every NT/Win9X installation and every piece of hardware it talks to between here and the ends of the earth and verify that it's OK and verify that the operators have OK'd your entry to their systems, you're hanging yourself out to dry.
    Which is to say it's a dumb idea, but not a horrible one, so if someone else wants to, uh. Go ahead or something.
    Easy does it!

    --
    Easy does it!
    This comment has been submitted already, 276865 hours , 59 minutes ago. No need to try again.
  66. Good riddance. by dmoen · · Score: 1
    CERT is sending out warnings that the entire internet will cease to exist if the Code Red MSTD isn't stopped in its tracks.

    Not the entire internet. Only 25% of the web uses IIS servers. The rest is mostly Apache.

    Frankly, if all of the IIS servers disappeared off the web tomorrow, I wouldn't shed a tear. None of the sites I care about would be affected.

    --
    I have written a truly remarkable program which this sig is too small to contain.
    1. Re:Good riddance. by Legion303 · · Score: 1
      Not the entire internet. Only 25% of the web uses IIS servers. The rest is mostly Apache.

      <sarcasm>
      Yeah, and CERT obviously forgot that the Code Red worm only sends its bandwidth-sucking attacks to the white house over IIS servers. Damn, they're clueless.
      </sarcasm>

      -Legion

  67. Re:From cringely's article by Hell+O'World · · Score: 1

    Or perhaps he means... (horrors!) .NET!

    Subscription software would mean that the latest versions/patches would automatically be sent out to everyone. Grandma's web server will have sparkly clean software.

  68. Re:People still don't know by kindbud · · Score: 1

    The line for the license exam starts to the right. Put down that keyboard and get in it.

    --
    Edith Keeler Must Die
  69. Re:Why can't MS be held responsible? by JoeShmoe · · Score: 1

    When there was a problem with the gas gauge on my car, I got a call from the dealer that sold it to me. The manufacture had issued the advisory because they didn't want customers stranded without gas due to faulty readings. They told the dealers and the dealers told their customers. That's usually how a recall works, although for serious ones the media usually gets involved.

    So then why can't MS contact the VARs who sold/installed NT/2000 server and have them run through their customer list and advise them of this recall in the same fashion? Really, the only systems at risk should be the ones that are pirated.

    At every company I have worked at, there is no one single person responsible for "all things NT" and so as a result, it is very difficult to make sure that everyone is on top of the latest update and that it is pushed down to all the servers without interrupting production systems. So patches are basically a "when time permits" activity for whoever remembers to do it. I don't say that's right, but that's reality and I wouldn't be surprised if patches are forgotten because sysadmins are busy getting some users e-mail recovered.

    Now, if some IT manager got a call warning them that their servers were vulnerable, he or she would issue the order and it would get done. If you leave it up to the sysadmins, you are really counting on them being through and I've known people who are MSCE and know they should patch systems but simply don't have the time becasue they can't make their bosses see its a Sev1 issue when compared to the MQSeries rollout.

    - JoeShmoe

    --
    -- I wonder which will go down in history as the bigger failure: the War on Drugs or the War on Filesharing
  70. Re:Why can't MS be held responsible? by JoeShmoe · · Score: 1

    With one key difference...with open source software people are capable of theoretically fixing it themselves. Which means it is much easier for end users to accept responability.

    MS is closed source so when a problem is discovered, you can't just alert everyone and be done with it. You have to go to MS, get them to fix it, then issue the alert.

    One solution to the Firestone mess was to remove the Firestone tires and replace it with some other brand, a brand that could then be used in the quasi-inflated state Ford recommended. But what if only Firestone tires worked on Fords? Then you would HAVE to wait for Ford to re-engineer and re-distribute tires, during which time you would either have to drive around in an unsafe condition or not use their Explorer (ha, that analogy is closer than I thought).

    - JoeShmoe

    --
    -- I wonder which will go down in history as the bigger failure: the War on Drugs or the War on Filesharing
  71. Re:OT: Firestone vs. Ford FUD by JoeShmoe · · Score: 1

    Firestone argues that the cut-rate crappy tires would have been fine if they hadn't been deflated to 25psi from the factory-spec 32psi...they still maintain that it was this deflation that caused the tread separation, not the manufacturing.

    In all likelihood it was probably a combination of both but how much? 80/20? 70/30?

    -JoeShmoe

    --
    -- I wonder which will go down in history as the bigger failure: the War on Drugs or the War on Filesharing
  72. Why can't MS be held responsible? by JoeShmoe · · Score: 1

    Seriously. Compare this diaster to the Ford/Firestone mess:

    A) Ford decides to ship vehicles with partially deflated tires.

    B) MS decides to ship products in their least-secure state with every service running.

    A) When this causes problems, Ford blames Firestone for not making tires that can handle it.

    B) When this causes problems, MS blames system administrators for not being smart enough to patch their system.

    A) The end result is that many people died because Ford passes the buck to Firestone and Firestone passed it right back to Ford.

    B) The end result is that many servers are going to be knocked offline because MS passes the buck to sysadmins and sysadmins pass it right back to MS.

    In my opinion, someone should force MS to take responability for issuing a product recall...just like in any other industry. That means they much contact their dealers and their dealers must contact their customers and get it patched. Obviously this is serious enough to warrant that kind of attention and MS can surely afford it.

    - JoeShmoe

    --
    -- I wonder which will go down in history as the bigger failure: the War on Drugs or the War on Filesharing
    1. Re:Why can't MS be held responsible? by skuenzli · · Score: 1

      I don't have an MS EULA (or any other company, but they're more or less all the same), but EULAs typically disclaim all warranty for fitness of purpose. So, you when you install IIS, you have to agree that even though you're installing this super-duper software, it may not be able to handle a GET request.

      Of course, the GPL does the same thing with point 11 (with the explanation that there's no warranty because you received it freely):

      11. BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION.

      So, when somebody says they can't use Free software because there's no one to sue or get support, you should tell them that the EULA that came with their commercial software probably specifically removed those options from them and they'll have to make other arrangements anyway.

      So, I think the 'no one to sue' argument is a bit of a red herring when used against free software.

      Regards,
      Stephen

    2. Re:Why can't MS be held responsible? by LoudMusic · · Score: 1

      All your points are correct ...

      Plus: Free and/or open sourced software is generally issued as 'Use at your own risk, we offer no support/help/advice/patches unless we want to. Best of luck to you, see you in Hell.' Whereas Microsoft touts their products as secure and easy to maintain (load of crap).

      What is true about MS software is that it is highly integratable and works well together, which is the exact problem of most of the security holes.

      Oh well, I guess you could say that Microsoft killed the Internet, or at least opened the door for someone else to.

      I like your analogies, they're right on (:

      ~LoudMusic

      --
      No sig for you. YOU GET NO SIG!
    3. Re:Why can't MS be held responsible? by LoudMusic · · Score: 1

      That I can agree with. I didn't think that Microsoft would have left themselves wide open on a license like that. I guess it's "buyer beware", or maybe "user beware" would be more appropriate here.

      Thanks for the copy/paste (:

      ~LoudMusic

      --
      No sig for you. YOU GET NO SIG!
    4. Re:Why can't MS be held responsible? by the_tsi · · Score: 2

      Don't you ever read that EULA before you install?

      MS (and every other software company) have you agree not to hold them responsible for any loss of any kind (and due to any cause... even negligence). If I were a computer company, I'd have you agree to the same thing.

      Now, the question for the lawyers is if the negligence is to the point that they are in breach of their portion of the EULA, which would put the users in a position to demand something in return (service, patches, upgrades, money, bill's head on a platter, etc).

      -Chris
      ...More Powerful than Otto Preminger...

    5. Re:Why can't MS be held responsible? by StevenMaurer · · Score: 2

      The reason why MS can't be held responsible is that manufacturers are not responsible for deliberate illegal misuse of their products.

      Ford and Firestone got into trouble because people attempting emergency maneuvers, or just driving on a hot day, could have a tire blow leading to a rollover. They wouldn't have been in trouble if the failures only occurred when a crook deliberately targeted the tires with a gun.

      Manufacturers are not legally responsible for making their products "bullet proof" - unless they specifically contractually agree to do so. It's the criminal himself who is liable.

      This, by the way is also true for firearms, which is why you can't generally sue a gun manufacturer when someone murders a family member with their product. Only if they knowingly sold the product to someone who was likely to commit a crime (a felon or violent paranoic) do you have a prayer of a chance against them in American courts.

    6. Re:Why can't MS be held responsible? by Reality+Master+101 · · Score: 2

      In my opinion, someone should force MS to take responability for issuing a product recall...just like in any other industry.

      What do you think a security advisory and a patch is?


      --

      --
      Sometimes it's best to just let stupid people be stupid.
    7. Re:Why can't MS be held responsible? by tswinzig · · Score: 2

      In my opinion, someone should force MS to take responability for issuing a product recall...just like in any other industry. That means they much contact their dealers and their dealers must contact their customers and get it patched. Obviously this is serious enough to warrant that kind of attention and MS can surely afford it.

      If your aim is really to stop this worm, and not to "punish Microsoft," then you're way off base.

      How exactly would Microsoft be able to contact the sysadmins? They don't have everyone's number. (They don't have ours, and we run servers with NT4 and IIS4 at work.)

      Instead, Microsoft has issued not only the original patch to their security alert list (which every real sysadmin is already subscribed to), but also another warning yesterday about the problem and how severe it is. They've also placed notices on their websites.

      This is far more effective, and will reach far more sysadmin people, than trying to call all the companies that have registered NT/2000.

      --

      "And like that ... he's gone."
    8. Re:Why can't MS be held responsible? by tswinzig · · Score: 2

      So then why can't MS contact the VARs who sold/installed NT/2000 server and have them run through their customer list and advise them of this recall in the same fashion? Really, the only systems at risk should be the ones that are pirated.

      Are you kidding? Yeah, pirated systems and every IIS system in use by a small business who does not buy "from a dealer." We bought our copies from places like Fry's. They don't know we have the software. How exactly would we be notified?

      At every company I have worked at, there is no one single person responsible for "all things NT" and so as a result, it is very difficult to make sure that everyone is on top of the latest update and that it is pushed down to all the servers without interrupting production systems.

      This is exactly why the current system is the best. The person that is in charge of keeping the NT systems secured would be on the Microsoft security alert list. That is the best way to reach the correct person.

      The main problem is with people who don't have anyone maintaining their security. Chances are, though, that they too did not buy from a software dealer, but instead, from a regular software store.

      Now, if some IT manager got a call warning them that their servers were vulnerable, he or she would issue the order and it would get done.

      Where do you draw the line, then? Should Microsoft have to do these calls for EVERY patch or potential security problem that is found in Windows? What about if this flaw infected all versions of Windows, with or without IIS installed. Would it be plausible to call every person in the world that owns Windows, and let them know to patch their machine?

      They are doing all that can reasonably be done on this one. Realize that 75% of all people have averate to below-average intelect. Worms take advantage of this fact.

      --

      "And like that ... he's gone."
    9. Re:Why can't MS be held responsible? by tmark · · Score: 2
      In my opinion, someone should force MS to take responability for issuing a product recall...just like in any other industry.

      And what would you suggest happen if someone installed a stock (say) RedHat box that (say) had telnet open, and someone worked their way in there and brought it down ? Would you hold RedHat liable ? What about if there was some bug in the kernel which brought down some number of machines - would you hold Linus Torvalds liable, and should he be responsible for contacting all Linux users for a 'recall'? If not, why not ? Who do you think we should hold liable for the sendmail worm of yore ? When you install an OS you accept a certain amount of responsibility for taking reasonable steps to assure its security. AFAIK, there were alerts and patches put out some time ago, so Microsoft's culpability is mitigated greatly, but even if there were not, it is too much to expect companies to accept liability for bugs in there software. Now, if MS had known about the bugs but kept that information quiet, that would be different.

    10. Re:Why can't MS be held responsible? by OpCode42 · · Score: 2
      Don't you ever read that EULA before you install?

      Sorry, its been about 5 years since I had any MS software in my possesion.

      the question for the lawyers is if the negligence is to the point that they are in breach of their portion of the EULA

      Yeah, Under the trade descriptions act (in the UK anyway) a product has to be fit for the purpose sold. IIS is not fit for serving web pages, due to the huge security holes. Yeah, patches can fix this, but the purchased product is not fit for the purpose it was bought for. Plus, I have seen a few systems where patches for the CGI Decode bug are not effective. A full refund would then definately be in order. It would be interesting to see what happens if a case is ever brought to court.

    11. Re:Why can't MS be held responsible? by OpCode42 · · Score: 2


      This is an interesting point. Can MS be held responsible for holes and bugs in their software that cost businesses money?

      MS Could say that part of running a machine connected to the internet is checking for bug fixes and applying them, and that it is the users responsiblity.

      However, companies pay a lot of money for MS software, which is marketed as secure and easy to maintain.

      Can anyone with an MS licence agreement tell me if they have a disclaimer absolving them from any responsiblity if their software goes wrong and costs you money, either due to downtime or data loss?

  73. It's just one way but ....... by chrisdb · · Score: 1

    In the Netherlands my university (Technical University of Delft) is actually scanning ALL their IP# themself for the vulnerability and will filter all hosts who are vulnerable.

    The owners offcourse will be informed they are vulnerable and should fix their system(s).

    I know it's a lowsy job, but I think it's a good start !

    ( one could say they are probably generating more network traffic during this scan than the worm would do but okay ;-) )

  74. Re:Idiots in journalism by RedHat+Rocky · · Score: 1
    Was that before or after a call to Pepsi and Coke and a small bidding war which ended with 5 million USD transferred to a numbered account in the Caman Islands?

    --
    Anything is possible given time and money.
  75. The sky is falling... by gordzilla · · Score: 1

    Jesus, You'd think the world is going to end the way all three major newspapers in my home town have "CODE RED" splashed across their front pages.

    Correct me if I'm wrong here, but as of 00:00 utc, Code Red goes into "propogation" mode, the real trouble won't start until the 20th of next month when it starts hammering the world wide web.

    Typical media, blowing things out of proportion (again)

  76. My site was 'Hacked by Chinese' about 5 weeks ago. by sideshow · · Score: 1
    Our phone system is run by a router. My boss was trying to show his boss how to configure his phone over the browser based interface. Well insted we got a 'Hacked by Chinese' page. I think all the anti-virus guys said to do was reboot the machine, which I did.

    This happened over a month ago. This sounds like Code Red but everybody keeps saying it was created on 7/17. Did I get it early? Or is this something else?

    --

    Hollow words will burn and hollow men will burn.

  77. Another Company Suffers for Misinformation by sideshow · · Score: 1
    First, Cold Fusion has absolutly nothing to do with windows. To tell the truth most people I know that use Cold Fusion use it because they aren't using IIS and therefore can't use ASP.

    Second, In less then three days he got his Linux system running? Didn't he tell you had his NT/ISS system up before lunch the first day?

    --

    Hollow words will burn and hollow men will burn.

  78. Re:Magic Bullet (was Re:die, monster devil, die!) by DeePCedure · · Score: 1

    Don't think that just because you're running a Linux distribution that you're safe from worms.

    I would really like to see this sentiment taken to heart by admins of any OS. All holy wars aside, no system is 100% secure unless it's disconnected from the internet, WAN/LANs, modems, or any other communications device... including drives that can use shared disks.

    Whatever happened to the paranoia that drove the development of tighter security in Linux? Do all the alpha-geeks, gurus, and wizards truly feel this safe when they know that other alpha-geeks, gurus, and wizards with the same knowledge have turned to the dark side of the force?

    I know MS bashing is a blast, and it furthers the cause of the Jihad, but at what cost? Every single person who tangled with Lion, Ramen, or even the Internet Worm of '88; then proceeded to denigrate MS here today makes the community look exponentially more idiotic.

    We should be discussing ways to resolve and prevent this, and similar instances of, malware. I haven't seen one suggestion to contact admins of infected machines. It's simple enough to do. Look up the owner of the offending IP and send an email or make a phone call. The way MS bundles all of their products, if an inexperienced user (not admin) has installed WinNT 4 server by themselves, they may very well have IIS installed and not even know it. A phone call to their admin could get the problem fixed, which is a damn sight better than whining about how Truly Evil ol' Bill really is.

  79. Re:60 % Apache is not all unix by JimR · · Score: 1
    you dont have to run unix to run apache the win32 port is dreadfully easy and comes with lots of docs

    Ah, but anyone with the intelligence to download and install Apache for win32 and read the necessary documentation, is also intelligent enough to download and install a decent operating system to run non-win32 Apache on.

    --
    #exclude <ms/windows.h>
  80. Re:Mis-set clocks? by JimR · · Score: 1
    IIRC, the worm is memory-resident-only and therefore can't survive a reboot.

    So all that needs to be done is make sure that every machine running a Microsoft Operating System is powered off, and the world is safe.

    (And maybe once people realise that the world is safe when there are no MS boxes running they won't bother to power them back on ;-)

    --
    #exclude <ms/windows.h>
  81. Re:Steve Gibson Made this Worse by T.Hobbes · · Score: 1

    I saw that series too.. I was struck more by how much of an ass he is than his relative intelligence. More of a Steve Jobs than a Gibson.

    Linus has,in fact,grown,and explosively-JonKatz

  82. Re:Why all the public hullaballoo by DJStealth · · Score: 1

    The problem is that every patch that Microsoft makes, installs DLLs that breaks something else.

    I've worked as a SysAdmin for government before, they usually want to do about 2 weeks to a month of testing on a test machine before they'll actually install it on a production server.

  83. I can't wait! by DJStealth · · Score: 1

    I can't wait until 7pm when all the MS servers go down, and companies start making decisions to migrate to *nix based OS's running Apache!

    Maybe then MS will decide to put some quality into their work

  84. Re:CNN this morning by BradleyUffner · · Score: 1

    #1=turn off unused services even iff you turn off index server you can still be infected.
    =\=\=\=\=\=\=\=\=\=\=\=\=\=\=\=\=\=\=\= \=\=\=\=\=\

  85. Windoze Versions by twitter · · Score: 1

    Let's see. Here at work we are up to NT service pack six and IE 5. If you factor in all the other programs that change dlls and what not, MS junk has lots of variants. (That's why software does not always work on MS platforms. Hell, I've never had an MS box that acutally did everything it was usupposed to, but that's another story.) The only thing thats been consistent is low quality and poor security. Why fix bugs when there is a competitor to trip up?

    --

    Friends don't help friends install M$ junk.

  86. FUD kill. by twitter · · Score: 1
    there are undoubtedly subtle and potentially dangerous bugs in the Windows code which will be obvious to anyone who can steal the source from the servers.

    The flaws will be more obvious to poor users. Who needs source code to break machines? You find responses faster by sending ugly junk to a running machine. Source code is better for fixing things.

    Oh that subtle and complicated peice of work that is MS. More complicated than the space shuttle, able to deliver Active Desktops, Adverts and other trash to you by clever scripting language that has full root access right from your word processor. Bloaaaty 500MB footprint of MSIE, cool!

    --

    Friends don't help friends install M$ junk.

  87. Re:MS == Internet by Simon+Garlick · · Score: 1

    Yeah, you never hear the real truth - that Cisco runs the Internet.

  88. The word from Microsoft in Australia by Simon+Garlick · · Score: 1

    In today's Sydney Morning Herald:

    Microsoft Australia product marketing manager Mr Calum Russell said it was highly likely that " people out there with malicious intent" would kick the worm - which runs on a monthly cycle of self-propagation and attack - off again.

    Microsoft today defended itself against criticism that it was partly to blame for the spread of the worm and the threat it posed to the Internet by clogging traffic.

    "With over 50 per cent of Websites run on Microsoft servers it makes us a natural target. It means if someone is going to do something malicious, who will they target? Microsoft," said Mr Russell.

    Microsoft spent "hundreds of hours" testing its products, but security vulnerablities were constantly found because of the advances of technology and hackers, he said.

    Hey, nice to know that Microsoft http servers are now running over half of the Web. I guess the stats at Netcraft which put MS at less than 26% are just wrong, huh?

  89. Re:Idiots in journalism by Caspuh · · Score: 1

    Yes, we should stop reverse engineering bugs that can clog up the net and focus all of our energies on "WindowsKnockOff v. 0.237".

  90. Re:The Entire Internet Will cease to exist... by Enzondio · · Score: 1

    Someone to feed my family for me.

  91. I can see it now... by Raymond+Luxury+Yacht · · Score: 1

    Web Surfer: What happen?

    ISP: Someone set up us the Code Red worm.

    Tech Support: We get signal.

    Web Surfer: What!

    Tech Support: Main screen turn on.

    Web Surfer: It's you!

    Code Red: How are you gentlmen!! All your IIS server are hacked by Chinese. You are on the way to destruction.

    Web Surfer: What you say!!

    Code Red: You have no chance to survive make your time. Ha ha ha ha....

    --

    Ceci n'est pas une sig.
  92. Deja vu? by razablade · · Score: 1

    Anyone else remember all the hype about Y2K that never ammounted to anything?

    --
    The expression is "I could NOT care less." Think about it.
  93. Cringley: Brush up on your clock skills! by rjune · · Score: 1

    Mr. Cringley states in his article that 7:00 pm Eastern time is Midnight (or 2400) Greenwich Mean Time. We are are on Daylight Savings Time so it is actually 8:00 pm Eastern and 5:00 pm Pacific time before the fun begins. Use your extra hour wisely!

  94. Re:Apache problem by friscolr · · Score: 1
    It seems to me that this is a potentially larger problem with most distros of Linux.

    Linux distros ship with a lot of other services active which are often vulnerable to remote root exploits - lpd, wuftp, samba - but the apache vulerabilities are few and far between, and generally only allow something silly like a directory listing. Products using Apache such as the notorious Matt's Scripts are more likely to be vulnerable and might be widely distributed enough to be a problem.

    But if you're talking solely about linux boxen being problematic, they already are with those non-apache vulnerabilities, and every time someone at my work brings up a redhat box, within 24 hours it's been hacked and 24 hours later we're getting email from people complaining about port scans from that box.

    The best solution is to disable servers and include firewalling by default. I was delightfully surprised that RedHat 7.1 asks to set up firewalling during the install. Finally!

    -f

  95. Re:Can't They... by ~Socrates · · Score: 1

    Euhm, sorry, but you're wrong

    Really, once it hits /dev/null it's gone to the heavens, bye bye packet, holding a ceremony with flours and a coffin, things like that.

    If /dev/null would have been linked to the internet, people would get some really weird packets from me :)

    -- Socrates

  96. Re:Can't They... by ~Socrates · · Score: 1

    Yeah, and next thing is that the backbones will do routing if you try to use an encrypted link to www..com I like my internet non-contaminated. traffic shaping is _not_ an option --Socrates

  97. Re:Worms and market share by Dahan · · Score: 1
    More than 10 years ago, and back then, most machines on the Internet were either Vaxes running BSD or 68K Suns running SunOS.

    The Internet is much more diverse these days.

  98. uhg. bunch of lazy sysadmins... by yzquxnet · · Score: 1

    Come on, if you get a hit again, or even if it's your first time getting hit with the virus, You really deserve it. For starters, there has been so much media coverage on this worm that I hardley know anyone who hasn't heard about it. And secondly, if it's your job to admin these servers, WHY THE HELL HAVN'T YOU PATCHED IT YET!!! My servers were correctly patched before even the first wave came through. Someone must not being doing what they are being paid to do. Come on people, it only takes a few minutes a day to go to microsofts website and check for updates.

  99. Why are worm writers plain stupid ? by kaltan · · Score: 1
    I don't know how this comes, but if one is technical/intellectual able to write a worm, why then :

    Use they pseudo random number generation (all infected servers check exactly the same IP addresses) -->with less effort you could just run all the IP addresses sequentially.

    Encode the target IP statically

    don't they just simply use one of the many DDOS BOTS available if the only purpose is flooding.

    Wasn't the hackers code : "Do it once, do it good" ?

    It just looks to me like a 'gotten out of hand' toy, prematurely released on the internet...

  100. Re:Maybe we should send Al Gore a wreath.... by Milalwi · · Score: 1
    ... and a card with our Condolences to mark the death of his "child".
    I won't believe it until I see the "film at 11"!

    Milalwi

  101. Re:Worms and market share by krogoth · · Score: 1

    The biggest security problems are the "install everything" idea and the "default password idea". If, for example, my desktop machine was cracked and all my mp3s erased because I was running bind (no, i'm not), I would feel pretty stupid. We need the users to take the time to read the documentation (which has to be there) to be able to only install what they need.

    Also, default passwords on anything that can be a gateway to system access - such as the default password on certain Red Hat servers that cause a problem a while ago - have to go. Even Mandrake Linux, which is made for new users, asks for passwords instead of saying "you root password is wordpass. If you ever find the time, you just might want to think about changing it, but it's ok if you don't".

    Another thing computers need in their default install is more security. Why don't consumer operating systems come with firewall installed by default? Zone Alarm is an excellent firewall that I used on Windows that stealths the system (in fact, unless you specifically allow a program to act as a server, it will not even respond to incoming packets attempting to open a connection). It also asks you for permission to allow each application to access the internet, and uses checksums to make sure it's still the same program. The users also need to know more - yesterday my dad got asked to allow "scam32.exe" to access the Internet, and said yes. Although frequent updates (for those who can do it) would allow the program to detect known viruses and slow the infection rate, it's very hard to set up an automatic security system (of course, there is always the option of default-denying based on a list of known safe applications, but that would have to be a well-maintained and large list to satisfy all the users).
    ---
    btw, sorry for the bad paragraph spacing. Slash doesn't seem to understand that I want two line-breaks!
    ---

    --

    They that quote Benjamin Franklin on liberty and safety deserve neither.
  102. Re:Gibson may be extreme, but he does have a point by krogoth · · Score: 1

    I agree with you that he does actually say some useful things (I wouldn't run a firewall if it weren't for the GRC), but after reading some things against him I have come to agree with them at least a little - for example, from vmyths, "Translation: antivirus software could no longer save the world from evildoers as of 1992.". Also, they go on to say ""Nearly impossible to detect." "Alarming capabilities." "The game is forever changed." "Amazing and staggering." "Completely incapable." "Fundamentally a dead end." Gibson mastered the art of trigger phrases at least nine years ago.". This is something that is very obvious if you read something he's written - the first time I went to GRC, I wasn't sure it was real because his writing style looks like it's stolen straight from spam. He is doing everything possible to get his readers' attention, and it seems to be working, which is a bad thing if he starts spreading delusions.
    ---

    --

    They that quote Benjamin Franklin on liberty and safety deserve neither.
  103. Re:Worms and market share by ogre2112 · · Score: 1

    This isn't flamebait, it's truth and understanding. I would've mod'd this interesting, myself.

    Ahh, Only if I hadn't used all those mod points on the Xena story... Sigh.

  104. Re:No IP telephony for Robert X. Cringely by Doomdark · · Score: 1
    While it is true that one shouldn't just assume VoIP uses 'stock' internet backbone connections, it may well be more cost-effective for carriers to mix traffic at some level. And if the mixing is done dynamically (ie. no hard-coded fixed bw allocation for different traffic types, or QoS), excessive IP traffic might cause problems to VoIP calls too. And that would include virus-generated traffic amongst 'valid' overloads.

    Of course this doesn't (like the original author claimed) make VoIP impractical or too suspectible to fluctuations on general Internet traffic rates, but perhaps it could cause some problems. But... that's something companies have to deal with whether viruses exist or not.
    --

    --
    I like paying taxes. With them I buy civilization -- Oliver Wendell Holmes
  105. Re:Are there any non-microsoft viruses anymore? by Doomdark · · Score: 1
    BIND has got to be the closest open source product to IIS with respect to massive numbers of vulnerabilities that give "immediate root access" to quote SANS.

    Wonder if sendmail has lost its position as number one Intruder Service, then? :-)
    --

    --
    I like paying taxes. With them I buy civilization -- Oliver Wendell Holmes
  106. Re:Gibson may be extreme, but he does have a point by Doomdark · · Score: 1
    ... Think about this for a minute. It is easy to conceive of ways in which much more damage could be done to the internet than has already been done. If I recall correctly, the ILOVEYOU virus deleted jpgs from hard drives. The worst results I am aware of from this is a commerical image database being wiped out.

    Commercial companies make backup copies of their databases on regular basis. This means that while financially losses are big (big bucks DB admins get paged to restore stuff from backups), the content losses are likely to be at most as severe as results of hardware failures (which do happen... even with sophisticated raid systems etc).

    Also, unlike ignorant end users, companies (their admins) usually try to keep their systems up-to-date, and are likely to be less vulnerable to attacks. Even though as targets they are more visible, and probably more lucrative, too, they are much better prepared against threats than your regular Joe Sixpack.

    Up until now, we have delt mainly with simple scripts whose workings are obvious.

    I don't want to flame you here (you did say you are not a security expert), but usually worms are not just simple scripts (nor even non-word viruses); on unix-systems they may (and have) been scripts to be more portable, but there isn't anything simple in them either.

    As to email being required... for decades (since first worms were created, early 80s?) worms have been able to use other network connections than email. That's the case with CR; variety is good for viruses and worms. Spreading using attachments is easy (some might say lame...) way to spread, but bit too obvious. Easy to implement, though, which is why it has been a popular approach.

    I guess I just disagree with doomsday prophecies like this. Even though I don't want to appear like a MS-bashing zealot, I must say that Microsoft is now paying for putting security related issues on rather low priority for years. There's a lot that have been done by other companies and organizations (Java-security model by Sun, xBSD code inspections to build reasonably secure server OSes, etc. etc); Microsoft just didn't think potential risks were big enough. They have been proven wrong... and hopefully have started paying more attention.
    --

    --
    I like paying taxes. With them I buy civilization -- Oliver Wendell Holmes
  107. Re:Gibson may be extreme, but he does have a point by Doomdark · · Score: 1

    Well, I probably should have clarified that I mean security patch - type upgrades. And yes, on work station - side, things get pretty obsolete. But for servers, although (large) companies dislike upgrading to new versions, they do usually apply the patches as required. Or perhaps that's only for the ones that are more mission critical than others, my view may be bit distorted. I'm sure mom and pop - ISPs are different from Fortune 500 dinosaurs.
    --

    --
    I like paying taxes. With them I buy civilization -- Oliver Wendell Holmes
  108. Re:Magic Bullet (was Re:die, monster devil, die!) by pyite · · Score: 1

    You know, I'd love to tell someone there's a vulnerability in their system, but I'm truly afraid of the consequences. You know, if you own a store and someone walks by to window shop while your closed, and just happens to move the door to the point of realizing it's not locked, and then they inform the police or yourself, you're grateful. You're grateful someone decent enough to tell you noticed it before someone with malicious intent did. Yet, whenever someone does the internet equivilent, FUD explodes all over the place. For some reason on the internet, if you have knowledge of something evil, then you are pre-determined to use such knowledge in a bad away. And like I said, I agree with your opinions 100%.

    --

    "Nature doesn't care how smart you are. You can still be wrong." - Richard Feynman

  109. Re:Gibson may be extreme, but he does have a point by starseeker · · Score: 1

    Bingo.

    --
    "I object to doing things that computers can do." -- Olin Shivers, lispers.org
  110. Re:IIS Explained by Dr.+Spork · · Score: 1
    How about:

    I Infect Servers
    Internet Immobile Soon

  111. Time Zones? by tubs · · Score: 1
    From the Cringely article ...

    For those readers in the United States, that is 7:00 PM Eastern and 4:00 PM Pacific time on Tuesday, July 31.

    Does that mean readers in the United States wouldn't have been able to work the time out and everyone else could? Or Cringely thinks there are only 3 timezones - Eastern, Pacific and GMT?

    --

    try to make ends meet, you're a slave to money, then you die

  112. Re:Code Red Sci-Am article by Dr.+A.+van+Code · · Score: 1
    This isn't the first time Meinel has socially engineered her way into Sci Am. They had an issue devoted to security a couple of years ago, and in addition to people like (if memory serves) Matt Blaze and Bruce Schneier, they had an article filled with her drivel.

    You would think Scientific American would have learned from that experience (I imagine they got a fair amount of negative feedback from it), but apparently they didn't.


    Well a friend of a friend of a friend told me

    --
    Good mfences make good neighbors.
  113. Just RBL infected machines by Captain+Kirk · · Score: 1

    It seems they have the IP addresses of the infected machines. So the routing tables of backbone providers could be updated to block those IP addresses. I think that might prompt the owners to patch their machines, disable IIS or whatever.

    So what's the problem here...its just like rbl-ing a spam host.

  114. Microsoft should just give up on IIS by JimPooley · · Score: 1

    Maybe they could buy Apache instead. Or perhaps just licence the Windows version for bundling purposes. This has just got to be bad publicity. "The web server that ate the internet."
    My boss has just told our head of technical support to download the patches.
    I said to our head of technical support "We don't need no steenkin' patches!"
    Running Apache on Linux has turned out to be the right choice!

    Hacker: A criminal who breaks into computer systems

    --

    "Information wants to be paid"
    1. Re:Microsoft should just give up on IIS by b0r1s · · Score: 1
      Doesnt that seem logical to you? If you rebuild something, starting from scratch, yes, you'll have to re-apply the patch, because the source you're using to rebuild the stack is UNPATCHED. Same as if you apply service packs that might not incorporate all of the fixes: remaining fixes must be re-applied.

      More interesting to me, though, is this comment in one of the articles:

      A second proposal was to simply send an e-mail to the registered administrator of every infected IP address saying "Hey, your server is infected, patch it!" This, too, was rejected, because the authorities didn't want to scare poor sysadmins by asking them to do their jobs. That they didn't at least try the e-mail route astounds me. They have a list of all the IP addresses. It would have taken an hour, but it didn't happen, according to sources who were present at the meeting.

      I work on the Unix staff at a small private college. Many students on the dorm network choose to run win2k/IIS to serve personal webpages. We received an email from "codered@securityfocus.com" informing me of two boxes on the school network that were compromised. Interesting. A portion of that email is below:


      Hello,

      This mail is from the ARIS Analyzer Service (Attack Registry and Intelligence
      Service) from SecurityFocus. It has come to our attention that your system(s),
      listed below have been identified as being compromised by the Code Red Worm.
      The Code Red Worm is rapidly spreading across the Internet, compromising
      vulnerable Windows NT IIS servers.

      The addresses identified as belonging to you are as follows:

      134.xxx.xxx.xxx xxx.eng.xxx.Edu
      134.xxx.xxx.xxx xxx.st.xxx.Edu

      You can find up to date information on the Code Red Worm at:

      http://aris.securityfocus.com/alerts/codered

      On June 18, 2001, eEye Digital Security released an advisory regarding a new
      security hole in IIS. You can find its advisory at:

      http://www.eeye.com/html/Research/Advisories/AD2 00 10618.html.

      In short this worm is propagated by a recently released buffer overflow
      attack in Microsoft's IIS Index Server and Indexing Service ISAPI Extension.
      The worm exploits this buffer overflow in the code handles .ida requests.
      An as-yet unknown source has created an exploit and turned it into a worm.
      The worm attempts to deface the Web site of the victim host with the
      following HTML code:

      Odd, but good. I was able to forward the email on to those responsible, and they have both since been patched.
      --
      Mooniacs for iOS and Android
    2. Re:Microsoft should just give up on IIS by bodhimindspirit · · Score: 1

      Hey, some of our machines are running IIS. I keep them patched, too -- in fact, I'd applied the patch when it was released. Our systems were still compromised. When I re-applied the patch I noticed this caveat in the dialog box after applying the patch: "If you change or add any components to your system, you will need to reapply the hotfix." Hmmm, so if I rebuild the TCP/IP stack, or make any other system changes, I have to remember to apply the patch again...

  115. Odd quote... by chinton · · Score: 1
    I found this quote a little odd in light of the current relationship between the government and Microsoft:

    The government relies on Microsoft and other technology companies to secure everything from defence networks to financial systems. "The protection of the Internet requires a partnership with the government, private companies and the public as a whole," Dick said.

    Kinka like letting the wolf guard the henhouse, don't 'cha think? What's next -- Gotti running the Secret Service?

  116. Re:Why all the public hullaballoo by Joao · · Score: 1

    > The general public, for the most part
    > can do nothing to stop this. It is sysadmins
    > and those running servers who need to pay
    > attention.

    Actually, one of the problems is that it is indeed "Joe General Public" who's running many of these servers. They do a full install of NT or W2K on their home or office PCs, or got their machine with the full OS pre-installed, and don't realize that IIS is included and running.

  117. Conspiracy Theory by Oliver+Wendell+Jones · · Score: 1

    Steve Lipner, head of Microsoft's security response centre, said the company was looking for new ways to distribute patches more efficiently.

    Has anyone considered that maybe Microsoft released this worm in an effort to convince everyone to go to their .NET platform that would allow Microsoft to automatically download these kinds of patches to you?

    --
    A computer once beat me at chess, but it was no match for me at kick boxing -- Emo Phillips
    1. Re:Conspiracy Theory by Oliver+Wendell+Jones · · Score: 1

      How stupid can you be?

      Not as stupid as you, I hope. If you re-read my message, you'll see that I said it's a *theory*, I did not say I had any proof, or that I even actually believed it. If you can think of a better theory, feel free to offer it up for speculation, otherwise, keep your asinine opinions to yourself.

      Thanks for playing, though, we have some lovely parting gifts for you.

      --
      A computer once beat me at chess, but it was no match for me at kick boxing -- Emo Phillips
    2. Re:Conspiracy Theory by thetman · · Score: 1

      How stupid can you be?

    3. Re:Conspiracy Theory by SuiteSisterMary · · Score: 3

      If you go here: http://www.microsoft.com/technet/security/search/b ulletins.xml you'll find a lovely XML doc which lists hotfixes going back, I believe, to 1998, what they apply to, what they're superceeded by, and so on. If you look for 'hfcheck' on the ms sites you'll find a lovely little WSH script that grabs this bulletin, and uses WMI to check servers and tell you what needs to be installed. It defaults to only checking for IIS patches, but that is easily fixable.

      --
      Vintage computer games and RPG books available. Email me if you're interested.
  118. Take a hint from bio systems by Stultsinator · · Score: 1

    I wonder how long before MS et. al. start distributing their virus fixes in the form of self-replicating antiviruses. That seems the quickest way to defeat this sort of thing.

    1. Re:Take a hint from bio systems by Nihilanth · · Score: 1

      I wonder how long before MS (or the government for that matter) starts releasing their own malicious Worms to increase antivirus revenue, spy on users, or scare the lUser population into making uninformed purchasing decisions?

      who's to say this hasnt already happened?

  119. Re:Why all the public hullaballoo by gotih · · Score: 1

    The problem I see is that so many sysadmins are programmers who can't hack code or worse. Take the 'sysadmin' where i work, he's the best friend of the ceo (no previous experience) and spent hours trying to get code red off 4 servers. it's that sort of incompetence that lets these virii propigate in the first place.

    --

    fear is the mind killer
  120. Re:Idiots in journalism by Random_Eyes · · Score: 1
    During the Bush Dynasty, the Empire has once again turned it's attention to the Red Menace.

    Everything from asthma to zymotic diseases will be blamed on them.

    Ready the missle defenses! Beware the commie horde!

  121. Tax Code Red by Aloekak · · Score: 1

    Hey, it's very popular, and is illegal. Why don't we confront this like some countries confront drugs. Make them legal and tax the hell out of them.

    The government should tax the people that are "using" code red to "access" whitehouse.gov. We all know that, like the lottery is a tax on people bad at math, this will be a tax on stupid admins.

    :)

    1. Re:Tax Code Red by ethereal · · Score: 3

      I thought there already was a Microsoft tax on stupid admins?

      --

      Your right to not believe: Americans United for Separation of Church and

  122. Re:CNN this morning by MrBogus · · Score: 1

    Free consulting since you are too stupid to RTFM -- Remove the extention mappings for all DLLs that you aren't using.

    --

    When I hear the word 'innovation', I reach for my pistol.
  123. Re:CNN this morning by MrBogus · · Score: 1

    See recommendation #1 above. :)

    --

    When I hear the word 'innovation', I reach for my pistol.
  124. Re:That's not the case by MrBogus · · Score: 1

    Maybe you should check that the survey you link to counts *domains* and not *servers*. For example, www.microsoft.com has 50 webservers but is only counted once, while local yokel ISP hosts 50 lightly trafficked customer domains on an old Sun and is counted 50 times.

    The only reason that Microsoft has such a large share is that it takes a few Windows servers to do the work of one Linux server

    IIS has had a history of reliablity problems and is more likely to be used in corporate sites and in loadbalanced configurations. But that means that the *server* count is more like 50/50 (although Netcraft charges for per-IP data.)

    --

    When I hear the word 'innovation', I reach for my pistol.
  125. Re:Why all the public hullaballoo by Suppafly · · Score: 1

    yeh or choose to install a 'kde workstation' and unselect any gnome related items.. then when its all done, type startx and low and behold you end up in gnome.. why in the world would you want your kde workstation to start in gnome..

  126. The Register is wrong by thechink · · Score: 1

    I don't always agree with Gibson, I think he's off-base concerning raw sockets, but the Register is way out of line in saying that he predicted severe consequences for the Internet. In reading Gibson's advisory I see no such thing. In fact at the end of the the advisory Gibson says:

    "Please note that neither in the above communique, nor elsewhere, have I ever made any dire predictions for the worm's effect on the Internet. Others have, but I am skeptical. I believe that the Internet can easily handle the "replication probing traffic" generated even by millions of simultaneously searching and reproducing IIS worms."

    The rest of the advisory is here.

    The Register has lost my respect, but then it never had much of it to begin with.

  127. Re:Quarantine... by OpenSourceRulez · · Score: 1

    I agree with you wholey on this. If some threatens the US way the govt should be able to say fix it or you won't be able to use it. However I have to say this about the worm: If MS knew what they were doing in the first place these security holes would not exist. This is like what the third or fourth IIs buffer overrun hole. You would have thought after the first one was found MS would have seen if others existed. I am just wondering, might these "holes" be intentionally left there as back doors to systems so that MS can get into them. Just some food for thought.

    --
    "Success is not the result of spontaneous combustion. You must first set yourself on fire." -- Fred Shero
  128. Why not rewrite the worm to propogate the fix? by totalslacker · · Score: 1

    Given that the security hole is a known problem, why not write a worm which finds unpatched servers and patches them? Yes, you would want to be sure that you're not unleashing some new death, but it would seem to be a simple way to catch all the lame admins who don't bother to install the update...

  129. Re:The Entire Internet Will cease to exist... by mikenb · · Score: 1

    Yeah, unless you work for a company that is gung-ho M$, then you don't really have a choice other than quit your job.

    --
    "Sometimes the most intelligent statement is the one that is left unsaid"
  130. This is nothing new by Chundra · · Score: 1

    I was talking to a professor who was a theoretical conspiratist back in the 70s. He claims that the Coca-Cola company was paying kickbacks to the Columbians and to street dealers to push the name "coke". It had the same degree of edginess at the time.
    --

  131. Google groups is gone! taken over by worm? by MrDingDong · · Score: 1

    Try to go to Google groups and you'll see. It's gone

  132. Re:self-defense by overturf · · Score: 1

    Lovely conclusion, but your premise is quite flawed. It's called vigilante justice, and it's rarely defensible.
    Fight the bastard off, but don't kill him unless you want legal trouble.

  133. Use a Worm to Distribute a Patch by ras_b · · Score: 1

    I have seen this idea before, but it's worth mentioning again. Wouldn't it be possible to write a variation on the code red worm that goes around patching IIS servers instead of infecting them? If this thing infected 250,000 computers in a day (or whatever it was), why not distribute the patch the same way?

    1. Re:Use a Worm to Distribute a Patch by nrx · · Score: 1

      Right! Leaving the legal aspects aside, you'll have twice as much traffic, generated by two worms instead of one.

      This is a problem of education (I leave it to the others to discuss Micro$oft's approach to security).
      On one hand you tell people not to open attached documents from strangers and on the other you tell them to open them - they may be nice.

      I can't wait for the first worm made by some script kiddie to resemble an auto-patcher. ;)

  134. ISS DEATH by rsd · · Score: 1

    At least IIS servers would shrink its market share.

    I know some IIS ISPs which are down with the web servers.

  135. Or that... by brer_rabbit · · Score: 1

    Jon Katz will go off on it....then die.

    1. Re:Or that... by scott1853 · · Score: 2

      Can't he just die, do we really have to read another one of his 4 day late analysis'.

  136. A cliffhanger from Cringely! by Mtgman · · Score: 1
    From Cringely's article
    This is very, very bad news, but there is a solution that will shortly be presented that will be claimed to save the day. This miracle solution will be the subject of my regular column this week, which will appear, as usual, on Thursday. Please come back then. Because while there is a solution, I believe that many people will see the cure as being nearly as bad as the disease.


    Doh! What is the answer! Enquiring minds want to know! And how could the cure possibly be worse than the disease(which he says could "bring the internet to a complete standstill and we all go back to watching TV")? What could possibly be worse than DoSing the entire net to the point of unusability? Damn you! Tell us!

    Steven
    --
    -- I have marked myself unwilling to moderate-- I don't have other accounts to artificially inflate the karma of
  137. Blame Canada by davonds · · Score: 1

    Just another reason not to use Microsoft, and of course keep up to date on your patches.

  138. L0pht... by datawar · · Score: 1

    At one point The L0pht (now @stake - www.atstake.com) said to a Congress Committee that they could take down the Internet in half an hour. Maybe this is what they meant.

    Those silly hackers.

  139. Re:Worms and market share by MeNeXT · · Score: 1
    Part of the reason Windows is so widespread is because Windows is stable (in an API sense, and in a reliability sense as far as W2K is concerned), and easy to write for.

    It's so stable that the same errors / bug / problems keep on comming back again and again.

    It's a question of puttung out a product prior to it being ready just to get market share and fixing the problems after the fact.

    --
    DRM? No thanks, I'll just get it somewhere else...
  140. Have you patched your server today? by Lechter · · Score: 1
    Some handy links to MS:

    You know, I just happened to think, how screwed with this be if the worm also targeted MS so that people wouldn't be able to get at the patches...

    Meanwhile I'll stick with OpenBSD...

    --
    credo quia absurdum
  141. The internet is like a woman... by Lechter · · Score: 1

    So, I guess what Cringely is telling us is that, once a month the interent is going to start flying off the handle without reason, and be incapable of being worked with... so, in otherwords, the 'Net has reached puberty and is going to have be "pms-ing" at the end of every month. (Until everyone gives up on IIS that is.) I guess this is what they mean when they talk about worms being "biological" in their spread!

    --
    credo quia absurdum
  142. Re:CNN this morning by Lechter · · Score: 1
    I think that, to a certain extent, we'll be talking about this for quite a while. Like Cringely said, the problem is with people who don't realize that they're running IIS. I'm sure there are quite a few very small companies out there who have something like an NT box attached on their network to provide a NAS. They installed NT a while ago and put IIS on just in case they wanted to put up a web-site later, left it turned on, and forgot about it. As long as their NT box keeps serving up their files, and internal e-mail the people with these servers don't realize they have a problem.

    It's the downside of the increasing accessability of servers. On the up side, pretty much anyone with a tiny bit of knowledge can put up a server for the small business LAN. So they benefit from the network without having to pay a sys-admin. On the downside, they don't have a sys-admin to keep their system worm-free.

    I don't think we'll see the total end of this problem until MS sends out a snail-mail CD to everyone with an NT license that says in big bold letters Put this CD in all your servers and let it patch them!

    --
    credo quia absurdum
  143. dunno 'bout you by Gehenna_Gehenna · · Score: 1

    but I'm unable to get my yahoo email account to work. Other than that, no big problem. from my understanding only nt/2000 is at risk, the fixes are readily available, and all you have to do to stop it is reboot your server/pc. Is this really as bad as they are saying?

    --

    1. Re:dunno 'bout you by shaunak · · Score: 1

      "and all you have to do to stop it is reboot your server/pc. Is this really as bad as they are saying?"

      Well, yes.
      You could reboot to stop it, but once you're online, its highly probable that you're machine will get infected again.
      So it isn't that easy.
      Besides, n number of servers (as n-> infected IIS server numbers) sending packets out to an IP addy at a given time is enough to make sure /. doesn't load quickly enough for you to check you're KARMA every m seconds (shudder).

      --
      -Shaunak.
  144. patent by Planesdragon · · Score: 1

    You can patent the possition, not "copyright."

    :)

  145. What ?!? AGAIN??? by gully42 · · Score: 1

    is this just too-late media hype, or is there another variant out there now? I though the origional Code Red was timed to go off last week?
    Best Regards, Nick
    Patch IIS with Apache guys!

    --
    fortune: You die cold and alone
  146. Still the biggest thrill of all by T1girl · · Score: 1

    I didn't know there was a soft drink called White Lightnin'. I was thinking about the beverage Merle Haggard sang about in Okie from Muskogee, the same kind Robert Mitchum ran in Thunder Road. I think Mitchum sang the Ballad, too. I just remember white lighnin' and mountain dew being euphemisms for moonshine whiskey. There's a silly song about mountain dew that's innocuous enough for kids to sing as a campfire song. I thought the hillbilly ad campaign was pretty corny; it's remarkable that they've been able to reposition it as something that people who consider themselves cool would even consider drinking. (It's not too bad with Cruzan's Pineapple Rum)

  147. Yahooo, Mountain Dew! by T1girl · · Score: 1

    Man, you must be older'n God if you can remember when Mountain Dew had the hillbilly ad campaign, positioning itself as some kind of White Lightnin'. When I tried to describe it to my friends, they thought I was hallucinating. Maybe they'll bring it back with some kind of tie-in with that other Yahoo. Haven't had a chance to try Code Red yet. I judge most liquids on how well they mix with rum.

  148. Open source by vinnythenose · · Score: 1
    Make Code Red Opensourced!! It should be free for all.

    All kidding aside, 'tis a shame that half of the Windows side of the Internet shall be beaten down for a while.

    Sarcasm aside, I have nothing to say.

    --
    --- I used to moderate, then I read the -1 articles and decided having to filter through them was not worth it.
  149. Re:Yikes! by mr_exit · · Score: 1

    the internet is made to route arround troubble, and if this includes every unpatched iis box on the planet then thats ok.

    Every internet user has had outages at some point, but this just makes it a outage for everybody at the same time, it might take a day or two to get over the slowdown but no biggie.

    i've used a 28.8 modem before and it isn't THAT slow really.

    -------
    Drink Coffee - Do Stupid Things Faster And With More Energy!

    --

    -------
    Drink Coffee - Do Stupid Things Faster And With More Energy!
  150. Re:Microsoft software: threat to national security by Weh · · Score: 1

    can they be sued for that ?

  151. Problems of closed source by AlXtreme · · Score: 1
    Okay, its probly said more than once every second on /. but hey, let me troll, its my karma :)

    Closed source software has once more proved that the user (customer) gets the bill, in more way than one. W32+NT software is full of holes and bugs, with a lot of them being exploitable by l4m3 viri-kiddies, but in my opinion this worm is just the beginning. Holes in open-source software are easilly discoverd during beta-testing and, thanks to the community, these are quickly dealt with, giving a strong and sturdy product/project.
    Closed-source projects will always have problems, if only because two people see more than one, and 5000 people see more than 10.

    In my (not so humble) opinon, closed-source servers should be banned from the net, not legally (that would limit freedom), but by word of mouth. Products like IIS will create millions in damages (although it may be exagerated), and Microsoft should be sued for damages. Let them take responsibility for their flawed product, and be an example for all porely created closed-source software, hyped for profit. Make Microsoft pay for their problem, as getting hard cash back is the only way to hurt a capitalistic company.

    Sue 'em for damages, make them learn the hard way...

    --
    This sig is intentionally left blank
  152. Re:Why all the public hullaballoo by quantum+bit · · Score: 1

    Actually, one of the problems is that it is indeed "Joe General Public" who's running many of these servers. They do a full install of NT or W2K on their home or office PCs, or got their machine with the full OS pre-installed, and don't realize that IIS is included and running.

    Who buys a new PC with an OEM version of NT or 2k Server preinstalled? Last I checked, IIS wasn't even available for Workstation/Professional.

    Oh yeah, and PWS (personal web server) doesn't use the index server so Code Red can't hit it.

  153. MS == Internet by Bugmaster · · Score: 1

    What really scares me about all this is not Code Red itself. Ok, so it reproduces like "I Love You" on PMS, big deal. What really scares me is that most media reports state, "The virus infects Microsoft IIS, and therefore the Internet is doomed". Thus, in the public eye, Microsoft IS the Internet.

    You may rant and rave about how Apache is better than IIS, but the battle has already been lost. Most people cannot even concieve the very idea that anything other than Microsoft could be running the Internet. Thus, it is quite probable that eventually Microsoft will in fact run every computer on the Net - since the alternatives will dwindle into complete obscurity.

    --
    >|<*:=
    1. Re:MS == Internet by Bugmaster · · Score: 1

      Regrettable, yet true... Still, the actual software is somewhat more diversified.

      --
      >|<*:=
  154. I looked at the animation... by canning · · Score: 1
    and it looks as if all of the zero computers in greenland have been infected. brrrr, that's scary. Is anyone safe??

    --
    I love the smell of Karma in the morning
  155. A short article in New Scientist by Big+Nothing · · Score: 1

    is here.

    --
    SIG: TAKE OFF EVERY 'CAPTAIN'!!
  156. Microsoft PR Machine by CygnusTM · · Score: 1

    And through all of this, Microsoft comes of looking like the poor victim, instead of the purveyor of swiss cheese software.

    1. Re:Microsoft PR Machine by Genoaschild · · Score: 1

      It's not just the fact that Microsoft writes "swiss cheese software(although they do)" it is the fact that people hate Microsoft so much that they write software in order to destroy Microsoft. When is the last time you seen a virus that targeted Apache Web server. Fewer people hate Unix or Apache then they do hate Microsoft so more people are likely to target their software and OS. It's like, who is more likely to get assasinated, Adolf Hitler or Theodore Roosevelt? Who do you think has more of a love-hate relationship.
      ----

      --
      Just because a bunch of people believe or do something stupid, doesn't make it any less stupid.
  157. Von Nueumann Virus Patch by vodoolady · · Score: 1

    A virus that infects a computer and installs the patch for itself.

  158. Re:The Entire Internet Will cease to exist... by MarkLR · · Score: 1

    This of course assumes that all of the IIS machines do not yet have the patch to fix the vulnerability. Its MS's fault that there is a problem in the first place but the people running these servers should have applied the patch by now (maybe they should bill the time to MS). All of this is hype.

  159. Pots and black kettles by necrognome · · Score: 1
    "Open Source is a threat to the American way of life."

    -- residents of the glass house

    --


    Let's get drunk and delete production data!
  160. Which is more likely? by necrognome · · Score: 1
    1. Evil, nefarious, satanic, Chinese hackers are enacting their plan of revenge on the United States for its global hegemonic practices.
    2. Yet another "feature" has been discovered in IIS, due to the tendency of Microsoft to leave "easter eggs" in its products.

    Remember to use Occam's Razor.

    --


    Let's get drunk and delete production data!
  161. Don't do it! by rppp01 · · Score: 1
    No no, don't turn back your clocks. They guy on pbs.org says that those IIS servers are causing all this problem! No, for the love of all that is good journalism, don't turn back your clocks!

    --
    They stuck me in an institution, said it was the only solution, to...protect me from the enemy, myself
  162. Re:60 % Apache is not all unix by br0ck · · Score: 1

    Check out Apache::ASP, Sun Chili!Soft ASP or even better move on over to PHP using ASP2PHP.

  163. Re:Or not... [Re:ITS BAAAAAAAACK!!!!~] by m45 · · Score: 1

    Hm, well, our server logged 22 attempts since 1 Aug 2001 19:48 UTC, with a noticable ramp at 2 Aug 2001 05h UTC. No attempts in the last 2 hour though (2 Aug 2001 10:30h UTC). Compared to the 30 attempts 19-20 Jul, it is at least something to make you think. Besides all attempts were coming from different IP addresses. Most of the logged IP addresses run IIS, so I don't think it is the eEye stuff.

  164. Code Red vs The Backhoe by Red_Winestain · · Score: 1
    Around 1:30 EST (we don't do daylight savings), Purdue University's connectivity disappeared (all Internet, Internet2, regional campus, IHETS, and other wide-area links went down).

    Due to publicity, everyone thought, "Oh no, Code Red!"

    It turns out a contractor dug through one of Verizon's major fiber optic cables. Surprisingly, some cell phone connectivity was also out (along with Sprint and AT&T long distance).

    Low tech beats high tech yet again!

  165. So why doesn't someone release a counter-virus? by patmandu · · Score: 1

    I mean, we already know that all these systems are vulnerable to that attack, so just send out a white-hat virus to remove the Code Red virus, patch the security hole, propagate itself to "N" other infected systems, and then quietly go away. Problem solved. Now get busy and start coding...

  166. soft drink conspiracy? by kriemar · · Score: 1

    Methinks the soft drink companies paid the programmers to develop the worm and name it Code Red.

    I always thought internet advertising would bring down the net, but I didn't expect something of this magnitude.

  167. Re:Mis-set clocks? by tanpiover2 · · Score: 1
    IIRC, the worm is memory-resident-only and therefore can't survive a reboot. It's not picking up where it left off, it's starting over infecting the internet almost from scratch, so it should be the same thing as last time. Except that this time everyone's forewarned.

    IIRC, everyone was forewarned (see here and here) last time!

    --

    But masters, remember that I am an ass: though it be not written down, yet forget not that I am an ass.
  168. Duhh by mcgrof · · Score: 1
    Ok, is it me or is it just that some government people cannot think right when it comes to "viruses"?. Not just the government, but M$ themselves.

    I just read an article on somewhere.excite.com that says "For infected computers, turning the machine off and then on gets rid of the worm but does not provide immunity from future infection".

    There's so much hype about the "National security concerns" over this virus, and how it may "melt down the internet" (cough cough, BS)... Well duhh... How about organizing a group of potential worm feeders and shutting them all down @ once? Obviously this is not the best solution, but I don't see any sites recommending this as a group-effort.

    Actually if the "1337" government people are trying really hard to get common folks to get the patch so that the virus won't spread more, and if they can't do it, this is at least a humble shot that they can give at stopping the spraed.

    --

    mcgrof

  169. Best IIS Patch by bahtama · · Score: 1
    I recently patched all of our company's servers with a great patch that seemed to have fixed all IIS related problems. It's called Apache.

    But seriously I did and now I can sit back and laugh at these silly MS Security Bulletins. Just another event that will cause Microsoft alternatives to gain popularity and notice. :)

    =-=-=-=-=

    --

    =-=-=-=-=-=-=-=-=
    Oh bother.

  170. Microsoft software: threat to national security by clone22 · · Score: 1

    "The Internet has become indispensable to our national security and economic well-being," said Ron Dick, head of the National Infrastructure Protection Centre, an arm of the FBI. "Worms like Code Red pose a distinct threat to the Internet." Duck and cover.

    --
    Ask me about my vow of silence!
    1. Re:Microsoft software: threat to national security by clone22 · · Score: 1

      They really know how to put the class in class action...

      --
      Ask me about my vow of silence!
  171. Re:Idiots in journalism by Anonymvs+Cowardvs · · Score: 1


    Or maybe they read the part in the original advisory where the eeye folks mention that they took the name from the bottle o' Dew in the room:

    Greetings:
    The guy at Del Taco that sold us food at 3am to allow us to perform this research. The guy who left the warm "Code Red" Mountain Dew in the eEye lab.
  172. Re:The Entire Internet Will cease to exist... by imipak · · Score: 1
    Yeah, people like Cisco who embedded it in some of their lower end routers. Smart move huh? It also crashes HP JetDirect cards, not sure whether they have IIS embedded or it's just a fluke.

    The degree of schadenfreude amongst the Linux zealots here today is really rather nauseating. No doubt you patch your Linux boxen every time there's a new buffer overflow in something that comes with every distro? (yeah yeah, only people who DO patch will reply... the point is, lots of others WON'T be patched & up to date.)

    Running a box is a fulltime job. Outlaw hobbiuest computers, I say ;)
    --

  173. Re:Steve Gibson Made this Worse by Seeka · · Score: 1

    No -- I read Cringely every time it comes out. Why? Because he knows what he's talking about. Even if most of his stuff is stretched theory, I believe that he has some very good points, and that sometimes it's not the mainstream "guru's" who are right. As for Steve Gibson, I listen to him too. He learned to use IRC from a god damn RFC, which just makes me laugh forever, but in an age where 1% of the computer population even knows what an RFC is, I think I'll stick with him.

    Seeka

  174. Re:Are there any non-microsoft viruses anymore? by morcego · · Score: 1

    I agree M$ is not the problem "pre se".
    The point is that non-MS admins tend to keep their systems upgraded with more frenquence then MS one's.
    It's all about culture. MS seems (IMHO) to cultivate the "Do it couse it's easy, even if you don't know anything about it" posture. THAT is the base of our programs.
    Of course, some may say that rWin interface is Virus oriented, but thats another matter entirely, if we conside that a patch that would have stopped CodeRed was avaliable 2 months or so before the worm started spreading...
    What we really need is to patch the admins ...

    ---

    --
    morcego
  175. MSNBC by ImaLamer · · Score: 1

    Their spin is this: we'll show the MS name 100 times a minute, and act like every computer in the f world is running microsoft software.

    Maybe it's just something that Brian Williams character came up with.

  176. IIS? What's that? by Proud+Geek · · Score: 1
    Cringely says the other big threat, and the reason they didn't simply email the administrators of all the infected servers, is that most of them are simply run as services by people who don't even suspect they have a web server. I hope every one of you reading this knows whether Apache is running on your box!

    Sometimes the cluelessness of people writing software at Microsoft astounds me, but then I look at the cluelessness of the users, and it's even worse. With a combination like that, we're lucky the Internet exists at all anymore.

    --

    Even Slashdot wants to hide some things

  177. Re:Microsoft can fix this! by zerofoo · · Score: 1

    When did they start supporting IIS in windows update? Was it recent? I checked a couple of months ago and I still had to manually download the patches. -ted

  178. Re:Microsoft can fix this! by zerofoo · · Score: 1

    It seems you can only get IIS 5 patches on windows update. IIS 4 is comming though.

  179. Microsoft can fix this! by zerofoo · · Score: 1

    Microsoft could actually fix all this crap by having windows update support IIS patches! Why MS would go through the effort of developing windows update and have it not support IIS baffles me!

  180. nipc worried about its job. by zaphod750 · · Score: 1

    seems to me i remember reading somthing about the nipc being in trouble, so it wouldnt really surprise me if they were to do a lot of hollering just to get themselves noticed and keep their jobs.

  181. What? by shaunak · · Score: 1

    "Steve Lipner, head of Microsoft's security response centre, said the company was looking for new ways to distribute patches more efficiently."

    So they're going to provide upgrades^H^H^H^H^H^H^H^H patches at more locations?

    "The government relies on Microsoft and other technology companies to secure everything from defence networks to financial systems. "

    Defence networks secured by MS (and others ...)?
    Well, the FBI might as well give up counter-intelligence, 'cause the 'farners' already have easier access. Who needs cumbersome Dead Letter Boxes when you have MS.
    Hmmmm.

    --
    -Shaunak.
    1. Re:What? by thetman · · Score: 1

      Ha ha ha, you wrote patches, but you actually meant upgrades!!! Very clever!!

  182. Re:Can't They... by shaunak · · Score: 1

    "Really, once it hits /dev/null it's gone to the heavens"

    Actually, when I said they don't cease to exist, I was referring to his/her idea of re-routing them to servers in China, not /dev/null(duh).

    --
    -Shaunak.
  183. Re:Can't They... by shaunak · · Score: 1

    "Can't the backbones do some routing thing and reroute traffic to the targetted address to /dev/null (Or better yet, someplace in China?)"

    Well, yes. They can (I hope I'm right), but then the data packets DO NOT CEASE TO EXIST. They still move around, and EAT BANDWIDTH. Besides, getting enough backbones to do this is logistically painful.

    --
    -Shaunak.
  184. So all you have to do is reboot... by BeneathTheVeil · · Score: 1

    and the worm is no longer effective?

    Well, uh... that wasn't smart on the part of the virus creator(s). This is Windows we're talking about here. How many of these machines aren't rebooted daily anyway?

    Perhaps, the virus should attack when one of these boxen crash, instead. That would cause quite a bit of action, no?

    Insert obligatory Microsoft joke here.

  185. Re:The Entire Internet Will cease to exist... by antek9 · · Score: 1

    The way I see it, since a patched IIS server is no longer vulnerable, ...

    [I'll spare all ye a comment.]

    --
    A World in a Grain of Sand / Heaven in a Wild Flower,
    Infinity in the Palm of your Hand / And Eternity in an Hour.
  186. Re:Idiots in journalism by antek9 · · Score: 1

    Then don't send 'em, you - ermh - raging idiot.

    --
    A World in a Grain of Sand / Heaven in a Wild Flower,
    Infinity in the Palm of your Hand / And Eternity in an Hour.
  187. Sure, Gibson may sound like a nut at times... by BillX · · Score: 1
    ...but I think he has exposed a possibility that, if not Destined To Come True, we should at least be taking seriously. Think of it in terms of the big Y2K non-event: every computer person and media pundit imaginable was foretelling the end of the world as we know it. Sensationalized, overblown, improbable? Absolutely. But it sure got people to take the possibility of massive trouble seriously, seriously enough to pour money and time into fixing systems and making sure it was, indeed, a non-event.

    As for code-red reinfecting everything at the crack of August, nobody honestly knows. It may happen, it may not. But without someone like Gibson with the foresight to explore the (admittedly farfetched) possibility of what may happen if we don't secure these systems, chances are much higher they WON'T be secured, and we may be totally unprepared for what, if much/anything, does happen. Stitches in time, and all that.

    --

    --
    Caveat Emptor is not a business model.
    1. Re:Sure, Gibson may sound like a nut at times... by SlashDottie · · Score: 1

      Gibson is a nut. Dangerous too...

      Here's another nutty idea. Let's say that Code Red fizzles. The original creator goes back to the drawing board, and thinks up the next worm variant. This one uses the new "exploit X" to get around.

      This time, though, the target is not centralized. It's geographically distributed, and hardened to withstand attack. It's withstood many DoS in the past, and remains a juicy, coveted target. If only there were half a million or so DoS agents out there, all working together...

      Unfortunately (for the target), the IP addresses are fixed, and it takes a long time to change them, not like the Whitehouse.

      DNS root servers, anyone?

      (I'm glad I still remember where the Internet's "off" button is)

      ---
      SlashDottie

  188. Isn't that one of Steve's references? by BillX · · Score: 1
    What, did you think he just pulled the 'logorithmic graphs' out of hi^H^H thin air? The numbers come from competent analysis by people who know what the heck they're talking about. (If he was reporting his *own* numbers, in his typical paranoid-guy-wearing-tinfoil-beanie writing style, I would be a bit more suspicious :)

    --

    --
    Caveat Emptor is not a business model.
  189. How about an anti-virus? by superposed · · Score: 1

    This suggestion may be either dorky or rash: Could someone engineer an "anti-virus" to patch all the unpatched IIS servers in the world? It could spread itself like the Code Red virus, but then it could unload the Code Red virus and/or install a patch on the affected server to close the hole. This should be possible in theory, because the security hole allows full access to the computer.

  190. Re:The Entire Internet Will cease to exist... by soloport · · Score: 1

    You forgot your ... tags. (Look it up on-line at Webster's).

  191. Re:Magic Bullet (was Re:die, monster devil, die!) by soloport · · Score: 1

    Ah. But with Unix/Linux, it's just that much easier.

  192. Re:Are there any non-microsoft viruses anymore? by soloport · · Score: 1

    Warning: Your ignorance is showing. I'm pretty sure Apache "owns" the biggest share of the pie...

  193. Re:Oooo..... let's bash Microsoft! Yeah! by mikewhittaker · · Score: 1
    Why do so many of the posts seem to almost presume that MS intentionally sells defective s/w?

    Anyone who has read (eg.) the Maguire/McConnell books should realise that MS probably makes as much or more effort than other s/w companies to write software well (unless disproved by some inside information ...?!)

    While stopping short of saying "let those without sin cast the first stone", I wonder how many of those rubbing their hands in glee at this latest MS problem actually follow best practice themselves in design, coding, peer-review and test of their own applications ? or open-source ones ?

    Come on guys (m/f) - let's get professional. Hate the bugs, certainly, but LEARN from experience - as I hope MS does.

  194. Chinese or not? by Haxx · · Score: 1



    So where does this virus say Code Red?
    Because if the coder named it Code Red than it's
    not from China. Code Red is that yummy American
    caffiene booster drink stuff that kids are drinking these days.

    ~ If I were a missionary I would copywrite the position

    1. Re:Chinese or not? by ph8ts2l · · Score: 1

      if you read one or two related stories about this thing, the people at eEye who first analyzed it named it for a version of Mountain Dew (seems like a test market thing) called "Code Red" Mountain Dew, which they aparrently drank a lot of while back-engineering.

      That, plus it makes an appropo reference to the worm's Chinese origin (according to the defacement it leaves on an infected server).

  195. Immunity through obsolescence by Faust7 · · Score: 1

    I have splendiferous net access at work. Consequently, my home machine is an Apple II+ on which I run an old terminal program to access my Unix shell account. Now then, what's all this Code Red business? :-)

  196. Re:Down with the internet! by misnoma · · Score: 1

    To infect your computer with code red, please contact your local Microsoft Representative who can assist you with what licensing you require to legally operate code red on your server. It operates on a NCDL license (numbers of coffees drunk license).

    --
    -- Stop listening to that rock. http://www.nuenergy.co.uk
  197. Yikes! by misnoma · · Score: 1

    I guess it's a hell of a worry in some ways... but to be realistic... The internet's not gonna cease to exist... maybe for a wee ehile would it be slowed.. but no...

    --
    -- Stop listening to that rock. http://www.nuenergy.co.uk
    1. Re:Yikes! by misnoma · · Score: 2

      Will the internet route arround trouble like this Virus may cause... That's debatable. I'm sure there's enough Cisco gear out there to cause some major issues... However, people may be (sic) stupid enough not to patch their IIS boxes (let alone run them at all!) but watch how fast ISP's kick customers that are causing mayhem by being infected. It's a similar situation to open relays, there are plenty of ISP's out there (at least here in New Zealand) who actively disconnect permanently connected customers with open relays. The internet as we know it has become almost a self supporting entity, the people (us) involved in any way will not stand for it to be out of service or degraded for long. Sure, we may lose a few websites in the process, but the internet as it stands will always exist. How long do you really think someone's gonna sit looking at an IIS box or Cisco router that's malfunctioning before they actually decide to remove it from the network or fix it. (or someone decides it shouldn't be part of this global network for them!). -- Stop listening to that rock! http://www.nuenergy.co.uk

      --
      -- Stop listening to that rock. http://www.nuenergy.co.uk
  198. Re:Mis-set clocks? by jjjpinkojjj · · Score: 1

    This is the funniest thing I've read on /. for a long time. Mod this up, please!!!

    --
    I'd like to dip my balls in that.
  199. Re:The Entire Internet Will cease to exist... by thanq · · Score: 1
    From the site:

    "Estimates by Netcraft, an Internet consultancy based in Bath, England (http://netcraft.com), indicate that some 20 percent of all Internet Web servers run on IIS. As that site tracks some 28 million Web sites, the implication is that there are at least four million vulnerable IIS servers out there. "

    That's twenty percent, and it's just an estimate, but goood enough just to get an idea.
  200. Re:The Entire Internet Will cease to exist... by vegetarian+towel · · Score: 1

    So, what are you waiting for?

  201. Apache problem by s20451 · · Score: 1
    From Cringely's article:

    Many of the infected servers aren't really being used at all. They are still showing their default Microsoft homepages and are simply running as a service under Windows NT. In those cases, the people on whose computers IIS is running probably don't even know they have a web server.

    It seems to me that this is a potentially larger problem with most distros of Linux. Quite often a default installation package will include Apache, which is happily installed and activated without the user being actively informed how to care for it. I know for a fact that this was true for RedHat 6.2, though more recent distributions of RedHat have fixed this. Since Apache is free (as in beer), while IIS is not, more Linux users generally have Apache than Windows users have IIS.

    How vulnerable is Apache to an attack of this sort? And, furthermore, could there be a more prudent way to distribute Apache? (Such as with a disclaimer? Or only by specific request?)

    --
    Toronto-area transit rider? Rate your ride.
    1. Re:Apache problem by nevets · · Score: 2

      I also know that RedHat was criticized for having Apache and several other services running as the default behavior. So the later versions (7.x) don't default as web servers, and the users need to configure them to get them started.

      I also believe that this is true for the other distros. Now with XP coming with sockets, I can just imagine the new impact that will have.


      Steven Rostedt

      --
      Steven Rostedt
      -- Nevermind
  202. Re:Worms and market share by gupta · · Score: 1

    Windows is stable... and easy to write for. Apparently, you love writing junks everyday.

  203. Ha! by Publicus · · Score: 1

    The government relies on Microsoft and other technology companies to secure everything from defence networks to financial systems.

    Maybe that's the problem.


    Stick it to The Man!

    --

    My Karma was at 49, then they switched to words. All that work for nothing!

  204. Are there any non-microsoft viruses anymore? by Dan+Ost · · Score: 1

    It seems that all the recent viruses require
    you to be running outlook or IIS.

    When will virus writers turn their efforts
    towards open source OS's?


    --

    *sigh* back to work...
    1. Re:Are there any non-microsoft viruses anymore? by 4mn0t1337 · · Score: 1
      Uh, that might be of "official" servers (ie, commercial sites that are run by IT staff), but what about all of the personal sites/servers out there?

      IIRC, doesn't win2k do a default instal of IIS with the service on? (Thought I read that some where, but I don't run Win2k, so I can't verify.) This means that there are plenty of machines that are vunerable and their owners don't know it.

      According to stats collected by CAIDA, the top 4 identifiable infected domains, with over 7% of the infections, are home.com (cable), rr.com (cable),t-dialin.net (? dial-up?), and pacbell.net (dial-up and DSL). Add in a few more to the list and you are above 10%.

      The way I read this, most of those companies are geared to home and individual users (or fairly small businesses). These people are *NOT* Apache customers (otherwise they wouldn't be infected) but nor would they be the kind to purchase Apache. They are small businesses (home business) or home users that either have a cute web site up for their friends, or don't even know they have IIS running.

      These people are the ones that don't know about the updates and couldn't care (but can't figure out why their Quake latency is so high).

      So, I am a little afraid about this "slice of the pie." Not only is it potentially bigger than the "official server" base, but also is it less informed, and more of a potential threat.

      [What happens if Steve Gibson's WinXP concerns are correct and insecure software is being put in the hands of every Joe/Jane User that allows for/facilitates massive global attacks? (I realize that Steve's issue is slightly different, but I bring it up here as it illustrates that the nature of the "pie" is shifting.)]

      ______

      --

      ______
      Once: you're a philosopher. Twice: a pervert.

    2. Re:Are there any non-microsoft viruses anymore? by banshee2000 · · Score: 1

      Yes there are other o/s's that are vulnerable to exploits. Check out Bugtraq and click on Linux. Just because Macrosquish is getting most of the attention, doesn't mean us linux users aren't getting any. :P

    3. Re:Are there any non-microsoft viruses anymore? by SuiteSisterMary · · Score: 2

      No, it's because you go after the biggest share of the pie. Ramen.worm I think was the most recent example of Linux being just as vulnerable to this sort of thing.

      --
      Vintage computer games and RPG books available. Email me if you're interested.
    4. Re:Are there any non-microsoft viruses anymore? by whopis · · Score: 2

      Don't you remember 1i0n, butcher, ramen, etc... that were running around a little while ago? Those were not MS worms

  205. Re:Gibson may be extreme, but he does have a point by Big+Yak · · Score: 1

    our network Internet Protection Office has a very apt saying: Convienience is never sacrificed for security...

    --
    -Hell hath no fury like that of a woman scorned for /.
  206. Re:Quarantine... by powerlinekid · · Score: 1

    I suppose you'll never know when only around 50-100 people have ever seen the source code. M$ takes alot of shit for its mistakes which I disagree with... we shouldn't chastise M$ for buffer overruns (linux has alot too) but rather for the fact that they take forever getting a patch out there. Part of the blame also lies on windows "users", because unlike the linux community they're not exactly all about fixing something that doesn't necessarily look broken.

    --

    can't sleep slashdot will eat me
  207. Quarantine... by powerlinekid · · Score: 1

    It would seem to me that if the govt is allowed to quarantine a small town due to some disease, etc... then they should be able to tell some dumb sysadmin to either A)Get rid of the worm or B)Disconnect the machine from the network. I understand that certain privacy, rights groups would throw a fit but this is important. The internet is way too important to how we live now (although I don't believe this worm is nearly as crippling as the media has been portraying), and we need to protect it. Seriously folks, think about it... say Bob has ebola and the govt tells him he not only can't leave his house, but has to go live in a bubble. Do you think the Human Rights organizations would bitch??? So why should it be different with a sick computer... ps- I, too, have some issues with the govt telling me whether my computer could be on or not... however I would never have the worm long enough to do any damage, and would be responsible enough to accept the fact that I was a fuck up. Interesting question: If this thing does start to rack up damage $$$, who is responsible: the virus writer, or the virus users???

    --

    can't sleep slashdot will eat me
  208. Re:The Entire Internet Will cease to exist... by masoncooper · · Score: 1

    Obviously I was referring to vulnerability to the Code Red Worm. I think we've all established that IIS has more holes than pumice.

    And regarding the other reply, I again was only referring to the exploit that Code Red was taking advantage of. Wasn't that what the topic of the thread about anyways?

  209. Isn't this illegal? by sup4hleet · · Score: 1

    I thought pointing out the shoddy design in some one's Intellectual Property was illegal according to the DMCA. Is Washington breaking their own law?

    ---===[end sarcasm]===---

  210. William Burroughs by columbus · · Score: 1
    Greetings: The guy at Del Taco that sold us food at 3am to allow us to perform this research. The guy who left the warm "Code Red" Mountain Dew in the eEye lab.

    William Burroughs:" Word is Image. Image is Virus".

    Code Red is actually a mind virus. Because of it's physical components, it is now on the brains and tongues of the computer literate, the government and the media. It was designed by the Pepsi Corporation to embed the idea of Mountain Dew into minds, and thereby increase sales. I refuse to buy Code Red Mountain Dew. I will not be brain hacked.

    --
    friends don't let friends teleport drunk
  211. Re:Why all the public hullaballoo by columbus · · Score: 1
    They're FUDing the Net!

    If this is a FUD campaign, it could be a part of the old political strategem - "Create the problem. Let people suffer. Attack a scapegoat, and offer a solution that happens to fortify your postion." Who who would better know how to exploit an M$ security hole . . .M$!

    --
    friends don't let friends teleport drunk
  212. Re:The Internet will "cease to exist" ? by archen · · Score: 1

    sort of like how a computer becomes unusable if you move the start bar to the top and on autohide? har har.

  213. This is stupid. by The+Panther! · · Score: 1

    In the 'cease to exist' linked article, there's a quote:

    "Steve Lipner, head of Microsoft's security response centre, said the company was looking for new ways to distribute patches more efficiently."

    Obviously they can't write software that doesn't have security holes big enough for the Hindenburg to fly through... so why not write a PATCH that exploits the same HOLE and repairs it, and destroys the worm, then deactivates itself after a month? At least that way, it catches and repairs the hole on all the machines whose sysadmins aren't paying attention.

    JH

    --
    Any connection between your reality and mine is purely coincidental.
  214. ...or Y2K all over again by Samer · · Score: 1
    I just watched my local news, and boy are they clueless. On this issue, it is not really their fault, after all they only have a minute or two in order to be come experts on the subject.

    Unfortunately, by over hyping this, the FBI and all the powers that be have created a really serious situation where - when nothing happens *today* - people will just dismiss it as another Y2K.

    One of the anchors said as much. It does not matter that Code Red will not have the full impact until the 20th, and it does not matter that most of the facts in the story that was aired were plain wrong. What matters is that most of those watching are going to think that nothing major happened, that it was over hyped and will stop beliving the warnings.

    The over-reaction of the Feds and everybody else is going to be another case of the boy who cried wolf.

    Samer

  215. Re:Why all the public hullaballoo by banshee2000 · · Score: 1

    The logic is simple. Business wants a new manageable internet. First, prove to the world that end-to-end is broken. Then, advance proposals to fix it. Waiting for the other shoe to drop. . . No need to wait ... http://www.g7.utoronto.ca/g7/summit/2001genoa/dotf orce1.html

    Annoy a politician today - THINK! In part reads: the DOT Force has examined in depth the challenge of bridging the digital divide and harnessing the power of information and communications technologies (ICT) and global networks to assure opportunity, empowerment and inclusion for all. The DOT Force has analyzed the underlying causes of the digital divide, the poverty-reducing and empowering potential of new technologies, and the complex mix of strategies, policies, investments, and actions required to create digital opportunities for all while addressing key development imperatives.

  216. Re:Microsoft should be held responsible for this by lordlod · · Score: 1

    I agree I have seen lots of mainstream media attention about this worm that kills the internet and ends the world I have not seen one article about how poor quality products leave themselves over to exploitation and that prehaps, maybe the large company that has made millions of dollars off this product (and others) should be held responsible for thier mess. When somebody builds a substandard bridge and it falls over and kills 20 people they get in trouble... A substandard webserver isn't worth a mention?

  217. Okay, I'll bite... by kiwimate · · Score: 1

    Name an MS application which installs and configures IIS and doesn't warn you about it in one of those screens which administrators would *never* not read completely (after all, that's what users do, right? They complain their PC is broken and, yes, there was some sort of ominous-looking warning message, but they don't have time to read that stuff.).

    1. Re:Okay, I'll bite... by kiwimate · · Score: 1

      No. The legal messages *usually* (more often than not these days) come at the beginning, and then the warning messages about possible implications appear as you're going through the setup. Specifically, you pick an option or turn something off or give a certain reply, and either as soon as you pick it or when you click next you'll get a pop-up message or a dialog screen warning you of the implications.

      If it's NT4, in any case, it'd have to give you some warning because IIS is installed from the Option Pack CD, not from the NT CD. In Win2K it's part of the install, but MS are pretty careful nowadays about warning admins that certain options require other components to support them and making sure they've covered themselves in informing you that IF you do this THEN such-and-such must be installed/turned on/turned off, and are you sure?

      You'll find that, frighteningly, MS have actually realised they're not well-regarded in certain areas and have tried to do something about it. By all means, let's hold them accountable for security holes, bugs, poor practise, or whatever; but let's be honest about it.

    2. Re:Okay, I'll bite... by RedX · · Score: 2

      Was that one of those pop-up messages that was interspersed with all of the licensing legal-ease pop-up messages?

  218. Re:60 % Apache is not all unix by StueyB2U · · Score: 1

    I agree there. (use it to play with PHP) But even Apache themselves discourage Win32 on the "open net" due to it not being as mature. The only other prob is the ASP extensions - is there an Apache mod to do this ?

  219. Y2K-2 by nailchipper · · Score: 1

    Think somebody is making money out of all this hysteria? This sounds like another apocolypse prediction.. first, Y2k... this was for sure going to end life as we knew it.. now this...we have new situation at hand... smaller in scale but just as important...

    With all this hype its bound to be a disapointment. The internet will "not cease to exist" and makes you wonder who actually benifits from all this....

    we dont even have time to breathe before our next apocolypse prediction anymore, they are coming one after another...

    --


    what is nailchipper?
    1. Re:Y2K-2 by beanerspace · · Score: 2

      Yeah, see my earlier comment about blowing a chance to make millions.

  220. Nice idea, I like it. :) -NT by NinjaWorm · · Score: 1

    NT

  221. Thank you by ph8ts2l · · Score: 1

    though i wouldn't say trying to start a panic--unless it's a rush to purchase a subscription or visit their advertisers.

    i've already commented here on the assertion in /.'s summary that the web as we know it will 'cease to exist,' so what if M$ and people who stake all their data on it have to learn something new!?.

  222. Calling BS on some of this by ph8ts2l · · Score: 1

    Cease to exist?

    this sounds like the kind of sensationalist teasing for which most cities' local TV news productions are known and despised, and most /.ers i've known can see past it. This problem has an elegantly Darwinian element to it, no? Only the most stable servers and subnets will survive, if worse comes to worst.

  223. Re:Worms and market share by p_trinli · · Score: 1

    You mispelt "Part of the reason Windows virii are so widespread...." Ahem, misspelled. Since IIS has LESS marketshare then Apache one would expect... than, not then.

    --
    Aaron J. Shaver
    http://aaronshaver.com/

  224. CNN wonderful graphic design team by Rkane · · Score: 1

    Anyone seen CNN's story about all this? They have a nice rendition of the virus: An evil sperm trying to break through the monitor to infect the innocent virgin IIS system. Beautiful. Personification at its best.

  225. serious problem by theantix · · Score: 1
    The truth is though that Microsoft only accounts for 20% of the servers out there

    Nope, infact the number is much higher in this case. You are probably close on the number of "normal" web servers, but the problem pointed out in the article was not with administered corporate/personal sites. Instead the problem is with people who are using WinNT /Win2K and have IIS installed running as a service but may not even know it.

    Check back next month to see Apache hit >70% on the Web Server Survey.

    I doubt it will have that much impact, as much of the damage comes from domains such as rr.net and home.com.

    --
    501 Not Implemented
  226. Re:I always knew... by Pliable+Manic · · Score: 1

    "The government relies on Microsoft and other technology companies to secure everything from defence networks to financial systems." Now, there's a nice cheery thought!

  227. Re:What would be incredibly funny... by Schrodinger's+Mouse · · Score: 1
    The "7 Dwarves" virus [check the Symantec write-up on W95.Hybris.gen] does, in fact, check for new functionality on a particular newsgroup - it isn't just rumor. Those plug-ins are a sneaky idea.

    If anything, I'm surprised the media isn't paying more attention to SirCam - they could sound all serious and say "It's a violation of your privacy because it sends all your personal crap all over the Internet", then follow that story with an ad for MSN Internet Service.

    --

    *****

    There are many people in this country who, through no fault of their own, are sane.

  228. Down with the internet! by OverDrive33 · · Score: 1

    Does anyone know how/where I can get my computer infected with Code red? I mean I think it'd be cool to throw my small amount of bandwidth in with the DESTRUCTION OF THE INTERNET!! (Does this sound like a really bad movie to anyone?)

    Somehow I have my doubts that the internet will "cease to exist"... then again...

    1. Re:Down with the internet! by Chundra · · Score: 2
      Somehow I have my doubts that the internet will "cease to exist".

      You must understand that there is no internet. This is a zen thing, so stick with me. To help you understand this, you need to meditate very deeply and free your mind of all you know. Sometimes to achieve this state, it helps to imagine yourself in an empty room. The room is painted pure white. The walls are white, the ceiling is white, the floor is white. There are no visible light fixtures, but the room is incredibly bright. There are no Windows.

      *rimshot*
      --

    2. Re:Down with the internet! by b1t+r0t · · Score: 5
      Does anyone know how/where I can get my computer infected with Code red?

      All you have to do is:

      1. Sell your soul to Microsoft
      2. Install a copy of IIS
      3. Connect to the Internet without a firewall
      4. Wait. It will be automatically delivered to you within 24 hours. Or it's free.

      --

      --
      "Open source is good." - Steve Jobs
      "Open source is evil." - Microsoft
  229. what about.. by MyMomIsALinuxHacker · · Score: 1

    ..guess the name/contents of the first Code Red worm variation and win a prize (you did something close to this for Dmitry, come on!)

    My guesses:

    Code Pink worm:
    -Infects IIS servers that have females for sysadmins
    -Displays the message: Welcome to http://www.pinkyandbrain.com ! Hacked by perverts!
    -Solution: take the windozer machine and put it on the fridge

    Code Green worm:
    -Infects IIS servers that have nature-friendly sysadmins
    -Displays the message: Welcome to http://www.TreesWithWorms.com ! Hacked by trees!
    -Solution: Pouring water on the machine that as the IIS server

    Code "1m 50 313373 th4t 1 3v3n d0nt kn0w c0l0rX" worm:
    -Infects IIS servers that have sysadmins that were once skript kiddies
    -Displays the message: Welcome to http://WankWankWank.313373rTh4nJ00.aol ! Hacked by chinese! (skripts kiddies are too leet for changing the msg Hacked by chinese)
    -Solution: never play with yourself EVER again.

    And so on and so on..

    A witty saying proves nothing. -- Voltaire

    (nevermind the previous post, I forgot to log in..)

  230. Re:The Entire Internet Will cease to exist... by ihawk · · Score: 1

    Actually, when you look at this coverage, it's pretty scary. Not Code Red, but the FUD and scare tactics that are coming out of "official" sources. The FBI clearly needs something to bolster its severely tarnished credibility re tachnical issues, the White House always needs something dire to distract the public away from what it's really doing and Microsoft stands to lose more credibility if it gets identified as the weakest link(tm). That line about the Internet being crucial to national security is the kicker - that could be the excuse that the government needs to reinforce DMCA as a means of restricting and re-structuring the net to make it "secure", meaning to make it a tool for propogating the party line and Microsoft software. Like I said, scary.

  231. The fuss... by Runt-Abu · · Score: 1

    From my point of view all this fuss appears to be beacuase the intial attack targeted US govermental web sites, it ain't no W32.Sircam.Worm@mm after all...

    --

    GCM d+ s+:+ a- c++ U? P! L E-- W++ NM+ V PS- PE+ Y+ PGP- t 5+ X?+ R+++$ tv+ b+ DI++++ D---- G e
  232. Re:I always knew... by FreeDmitry · · Score: 1

    You forgot one! They might do it by .. hm, incompetence...

    Free Dmitry

  233. Re:Worms and market share by Mike+Hicks · · Score: 2
    apart from 127.xxx.xxx.xxx and 224.xxx.xxx.xxx


    Eh? You're getting queries for your web server from multicast addresses? Interesting.
    --
  234. Re:Steve Gibson Made this Worse by Have+Blue · · Score: 2

    And you know what? He's right. The fact that 13-year-old kid with "off-the-shelf" script-kiddying tools can cultivate an army of bots and anonymously attack any site he wants is a very large flaw in the world of computing and deserves a lot of attention. Scare tactics, while somewhat repugnant, are effective, and Gibson sometimes uses his powers for good as well as evil.

  235. Why is nobody using this as a propaganda tool? by Ami+Ganguli · · Score: 2

    All the articles I've read about Code Red seem to be carefully avoiding pointing the finger at Microsoft.

    A statement like "Microsoft IIS servers run less than 25% of the Web, but the congestion created by the attack could affect all servers" would be accurate, informative, and make it clear that the problem is caused by a minority of systems. It would also make PHBs think twice about implementing IIS.

    How do we get this message out to PHBs everywhere?

    --
    It is tempting, if the only tool you have is a hammer, to treat everything as if it were a nail. - Abraham Maslow
  236. Magic Bullet (was Re:die, monster devil, die!) by Craig+Maloney · · Score: 2

    Don't think that just because you're running a Linux distribution that you're safe from worms. Anybody running portsentry or snort can tell you about how many times per day they get a portscan on their system looking at port 111 (rpc.statd). Linux is not a magic bullet; it takes discipline to keep up with the exploits no matter what operating system you use to connecto to the net.

  237. Re:The Entire Internet Will cease to exist... by jd · · Score: 2

    Hey! No need to be sorry for speaking the truth.

    --
    It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
  238. Hey! Cool! by jd · · Score: 2
    If the Internet crashes badly enough, then the tech monstrosities that run(?) it might be forced to install modern (ie: > 18th century) technology.

    The string & tin-cans currently used on the backbones and trans-atlantic link might be a cool hack, but they are a little short on bandwidth for serious use. It's got to the point where those who built the Internet in the first place have had to jump ship, and start from scratch, just to get the necessary bandwidth.

    I -hope- that the failures are major enough that QoS technology is deployed, not just decorated. I -hope- that delays become bad enough that terabit pipes become the norm, not just a pipe-dream. I -hope- that this scares ISPs and corporations into enabling ECN, IPSec and possibly even IPv6.

    It is only in times of adversity that technology really changes. We have an adversary, we HAVE to defeat it, and that means we HAVE to change.

    IMHO, viruses, trojans, etc, are evil. But in destroying their evil, we have the opportunity to rid ourselves of some of our own.

    This probably sounds a sick way of looking at things, but the fact is, we HAVE the means to prevent Code Red. We have, for many years. It's because system admins have always argued that it's not worth dealing with threats -before- they happen, that we're in the situation we're in.

    Inertia is mankind's second-greatest enemy. (Jerry Springer narrowly beats it.) Damned is the person who does nothing, because they couldn't do everything. This entire fiasco could well give the impetus needed to overcome that inertia.

    On the other hand, I'm inclined to think that everyone'll just panic, but do nothing, and actually be over-run. Needlessly and stupidly. But, then, that's people for you.

    --
    It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
  239. Re:The Entire Internet Will cease to exist... by jd · · Score: 2
    I collect patches. (I even make the collection available, online. It's running at 17th or so on the 20 most active Sourceforge projects.)

    Mind you, I collect all sorts of odd things. One time, I was into collecting comms software. I had over 30 for the PC.

    Another time, it was MUDs. I had practically every MU* server on the planet. (LP, MudOS, Pernmush, Tinymud, Tinymush, Pennmush, Ubermud*, Tinymuck, Abermud, Circle, LambdaMOO, etc)

    *Ubermud was the first truly distributed MUD system. Processes could migrate between the Uber servers freely, provided the necessary database entries existed. It was truly ingenious for it's time, and nothing more recent really compares.

    Of course, *Trek games were great for collecting, too. XTrek, Netrek (Bronco, Vanilla, KSU, et al), the briefly-lived Paradise development line, etc.

    Compilers and interpreters are cool, too. That's one reason I'm fluent in something like 10 computer languages, and am OK in about 7-8 more.

    Of course, collecting has its down-side. You need a LOT of disk space, a LOT of time, and a LOT of bandwidth. The stuff will never be worth the tens of thousands of dollars that stamps, or other "physical" collectables, will fetch in time. And they require active steps to preserve. A teddy bear, if stuffed in a box in the attic, will usually do ok for 40-50 years. Netrek, on a 3.5" floppy, would be lucky to last a tenth of that time. Even if there was still anything that would read it.

    --
    It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
  240. Re:The Entire Internet Will cease to exist... by jd · · Score: 2

    Anyone with the naivety to run IIS is, IMHO, automatically suspect when it comes to doing anything technical, such as setting a clock.

    --
    It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
  241. Re-infection? What about continued infection? by iabervon · · Score: 2

    Considering the nature of this thing, when it went dormant, probably most people just forgot about it. It doesn't really need to spread again, since it's still out there all over the place.

    This is not really all that different from an average virus-- it spreads for a while, activates, causing a lot of damage and panic and such, people panic for a while, it deactivates and spreads some more.

    The people who are all worried about it coming back repeatedly should be at most disappointed that it doesn't just kill itself after a month. But there's no reason they should expect it to.

    In fact, this is still less of a problem than an old-style virus: it order to stop those, you had to get a clever program to catch and disable this code. With Code Red you merely have to patch or replace IIS and it stops being an issue.

  242. People don't patch... by Jeremy+Erwin · · Score: 2

    I'm still getting

    "Hi! How are you?
    I send you this file in order to have your advice
    See you later. Thanks"

    spam in my mailbox...

  243. My favorite bit of misinformation: China denial by Brian+Stretch · · Score: 2

    This newswire article quotes various people in China claiming that obviously the worm didn't come from there because Chinese servers aren't getting infected, and besides, the worm is just too complicated for an individual to create. The reporter bought it. Had he bothered to do some research, he'd have known that the worm is coded to only infect English (US) language servers, and in all likelyhood it was coded by a (Chinese?) teenager with too much time on his hands.

    (Well, okay, it does run on the non-English servers, but it doesn't deface them...)

  244. Re:My favorite bit of misinformation: China denial by Brian+Stretch · · Score: 2

    Perhaps the fact that this guy got modded to 3 with such baseless "logic" is an indication that there are some xenophobic moderators around? Guys, mod this misguided moron down!

    My point, had you bothered to think about it, was that the reasons given for why the worm couldn't have originated in China were obviously wrong, and had the reporter been competent enough to do a modest amount of research he'd have seen that.

    Sometimes the obvious answer, namely that the worm really was written by a lone cracker in China, really is the right one, no matter how un-politically-correct it is. However, we don't really know, as I indicated with "(Chinese?)". I'm just curious why the reporter's mainland Chinese sources felt it necessary to dispense obvious misinformation. It's probably just a reflex action from a lifetime in one of the more brutal Communist dictatorships.

  245. Re:The Lazarus Worm by unitron · · Score: 2
    "The Lazarus Worm"

    Great title. If you'll hurry up with that screenplay maybe we can get Robert Urich as the title character and it can be the "Tron" sequel.

    --

    I see even classic Slashdot is now pretty much unusable on dial up anymore.

  246. Re:This is pretty sad by unitron · · Score: 2

    Actually MSNBC (the cable channel, haven't looked at the web site) just had someone on explaining this who didn't do too badly considering the audience he was trying to explain it to, and they even put up a graphic showing which *Microsoft* products were vulnerable. They forgot the "We're a joint venture of..." disclaimer, though.

    --

    I see even classic Slashdot is now pretty much unusable on dial up anymore.

  247. Re:Yahooo, Mountain Dew! by unitron · · Score: 2
    I'm pretty sure that White Lightnin' was a Mountain Dew wannabe. I never saw one until several years after Mountain Dew came along.

    Here's a link to the story of its creation (Mountain Dew) in Knoxville, Tennessee (I'd always heard that it was started in western North Carolina) from an AC's reply to another post of mine.

    http://metropulse.com/dir_zine/dir_2000/1039/t_sec ret.html

    --

    I see even classic Slashdot is now pretty much unusable on dial up anymore.

  248. Re:Idiots in journalism by unitron · · Score: 2

    Being a Mountain Dew drinker since they had a hillbilly on the bottle, I tried Code Red out of curiosity and don't see how anyone could stand to drink an entire bottle, much less copious quantites of it, and wouldn't trust any work done by anyone who did. It's that bad.

    --

    I see even classic Slashdot is now pretty much unusable on dial up anymore.

  249. Re:Please cut the sensationalist crap. by garcia · · Score: 2

    another story to add to the mounting piles of crap that /. editors have been posting lately.

    I have found that by going to other sites I am getting better coverage than /.

    I have been an advocate (and even annoyed that people were complaining about the journalism here) but this is getting ridiculous.

    Repeat posts, The Onion like garbage, etc is all getting to me.

    Clean up the act boys.

  250. Instant partial solution by leonbrooks · · Score: 2
    The problem with security is not that we don't know what to do. The problem is that so many of us don't do anything. That is what alarms Gibson, and in that he is correct. There are so many machines not being properly managed that damage is inevitable.

    Given that at least four components are necessary for a crack to be effective, removing any one of them will prevent the problem. These components are: malicious code, vulnerable service or device, access to same, lack of fixes or unwillingness to apply available fixes.

    Evolution suffers the same type of problems. Hypermutation was recently discovered in components of an immune system and many hands were waved about what this proved. What was not explored was the nature of the mutations. They are almost deliberately allowed to ``go wild'' within very strict bounds, and the result (which would be disastrous outside the immune system) is that a large set of possibly useful responses are produced and tried as antigens in a very short time. However, if any one of a large set of very specific conditions were not met, hypermutation would be lethal. And you can safely bet that any retractions of the previous headlines will be four lines of fine print on page twenty.

    So, given that convenience will tend to be chosen over better security (and partly becuase if an administrator goes for a more secure but less convenient solution they may actually suffer a greater security problem by encouraging (for example) undocumented sharing of passwords), a solution such as replacing Windows plus IIS with Linux/*BSD/whatever plus Apache will actually work, and much better than telling users and administrators that they're idiots. They either know that and have to live with it, or don't know it, never will, and will be annoyed every time someone tries to point this out.

    ASP2PHP exists, and works, so there's no really sound reasons left for running IIS. It's also (especially in the name of avoiding monoculture) worthwhile checking out alternatives like Zope. The combination of an inherently more reliable service, and automated updates (I know that Debian, Mandrake and RedHat - at least - have these) will remove a vital section from the crackers' stairway to heaven.

    Where Mr Gibson does score is in that not everyone needs to be running vulnerable servers to swamp and drown the Internet. Just enough twits to do the job. I'm currently wondering what social effect would drive IIS market penetration up 4% at the very instant this it's been shown to be a public menace. Again. Remember that it's been copping buffer overflows for the best part of a decade now, and doesn't look like stopping.

    --
    Got time? Spend some of it coding or testing
  251. Not as unthinkable as first glance might suggest by leonbrooks · · Score: 2

    ...after all, they've given up on Microsoft DNS for themselves, and MSN's outsourced web hosting includes Apache. There's nothing to stop them from telling Apache to lie about who it is, and use something like ChilliSoft for their own web services, and after that it's not such a big step (remember Apache's licencing) to MS-Apache. Then they can explain that they outsourced development in order to be able to focus on .NET, can't they? (-:

    --
    Got time? Spend some of it coding or testing
  252. Don't forget the scripting by leonbrooks · · Score: 2
    ASP2PHP will pretty much solve that little issue for you. And remember to set up your new Apache-on-Linux installation for automated security updates. We work while you sleep. (-:

    --
    Got time? Spend some of it coding or testing
  253. IIS overflowing for ages: petition MS to open it! by leonbrooks · · Score: 2
    Go back and have a look at the old security alerts. Buffer overflow in IIS. Buffer overflow in IIS. Buffer overflow in IIS. Buffer overflow in IIS. Buffer overflow in IIS. Buffer overflow in IIS. Buffer overflow in IIS. Buffer overflow in IIS. Buffer overflow in IIS. Buffer overflow in IIS. I'm sure you get the idea. And every one of those means, effectively, root access on that box. The only saving grace is that Windows systems generally don't have the full spectrum of interesting network tools available that Unix boxes routinely do. I'm not sure how to call that an advantage, but I do know a number of people (think Mundie) who probably could.

    We should petition Microsoft to Open Source IIS, purely as a matter of self defence.

    --
    Got time? Spend some of it coding or testing
  254. Re:Worms and market share by Cato · · Score: 2

    I agree about stability of Win2000 - it's a lot better on my laptop, but I still manage to crash it occasionally (most recently when launching Outlook). I don't remember ever managing to crash a Linux or Solaris box.

  255. Re:From cringely's article by bughunter · · Score: 2
    No, I suspect that the cure Cringely is teasing us with is a countervirus.

    If these putzadmins can't or won't patch the holes, then a "white hat" virus can use the same holes to apply the patches.

    I'm not endorsing it, just making a prediction. (But it does have its elegance.)

    --

    --
    I can see the fnords!
  256. 60 % Apache is not all unix by johnjones · · Score: 2

    you dont have to run unix to run apache the win32 port is dreadfully easy and comes with lots of docs

    I run it when I want to be quick and dirty on an NT box with the win32 port of perl for CGI so that webfools can get to grips with things rather than screw up my systems

    regards

    john jones

  257. Is W2K really stable though? by Medievalist · · Score: 2

    /.
    When NT came out, it was supposed to be based on code stolen from the VMS system, which has truly phenomenal stability - equaled only by a few linux kernels. The advertising, and the legions of MS-shills in userland (who at that time were gunning for OS/2) gleefully proclaimed that NT was stable enough for the enterprise.
    I tested NT extensively and found that 3.51 was basically stable enough for user desktops - it crashed about as often as a Macintosh. But the computer press behaved exactly as they do today in regards to W2K - "It's uncrashable! Rock-solid! No more BSOD!" ranted the pundits.
    When 4.0 shipped, suddenly the previously "rock solid" NT 3.51 was not a stable platform - you had to upgrade to 4.0 to get the exact same empty promises and gleeful raving. My tests showed no phenomenal improvement, however.
    So, perhaps W2K is really stable and wonderful and all that nice warm fuzzy stuff. But, fool me once, shame on you; fool me twice - shame on me. I won't be buying W2K because I have known working alternatives from sources that have not abused my trust.
    --Charlie

    PS - HP (vendors of the unbelievably horrible HP-UX) were advertising Windows NT using the word uncrashable only a year ago. Just now a quick search on Google turned up numerous instances of this egregiously fraudulent claim... are W2k's promises likely to be any different?
    --CTB

  258. Re:Why all the public hullaballoo by GregWebb · · Score: 2

    I'm getting irritated on this one, too. My userbase is only just into double figures, but I've had something like 20% of them ask me if they have to do anything to their machines to guard against this. On this scale it's only an irritation - but it's daft.

    If they'd only prefixed the bulletins with a simple rider that this only affects website operators (to word it for the users, remember) and that home PCs are fine, this would be better. Users wouldn't be panicking for no good reason, we'd all have a more peaceful world.

    Why can't people think harder?

    --

    Greg

    (Inside a nuclear plant)
    Aaaarrrggh! Run! The canary has mutated!

  259. Re:From cringely's article by gmhowell · · Score: 2

    I suspect this is the cure.

    --
    Jesus was all right but his disciples were thick and ordinary. -John Lennon
  260. Re:Mis-set clocks? by handorf · · Score: 2

    No, he really goes off on the off-clock machines.


    As long as even one of these clockless machines remains up and running, Code Red will start over on the first of every month. Forever.


    I don't know WHERE he gets that idea. As long as ANY machines still have the work and ANY machines remaine unhardened, we'll still have this problem.

    BAD JOURNALIST! NO BISCUIT!

    --
    -- IANAEG - I am not an elder god.
  261. IIS Explained by macsforever2001 · · Score: 2

    I just cracked the advanced *32-bit* encryption scheme used on Microsoft IIS with my hi-tech Pentium processor - even with the logic bug. Boy did it heat up my apartment doing all those calculations - I have the AC on and it's the dead of Winter here in Siberia! I found out this *top secret* information from the source code about what IIS stands for:

    • Is It Serving?
    • Idiotic Information Server
    • I Ignore Standards
    • I'd Invest in Sun
    • It Is Stupid
    • It Irritates Sysadmins
    • It Irritates Surfers
    • Information Is Stopped
  262. Re:Mis-set clocks? by gorilla · · Score: 2

    No, he's a proponent of promoting Steve Gibson. One year it might be polymorphic viruses are going to kill all our computers, the next Linux is going to kill the internet.

  263. Re:Mis-set clocks? by gorilla · · Score: 2
    And Cringely is just reposting Gibson's alert, and Gibson has shown himself to be clueless.

    As The register pointed out, if the clock is misset so that it's in infection mode, then it's just going to find that the servers it infects AREN'T in infection mode, so the whole mis-set clock thing is a red herring.

  264. Re:My favorite bit of misinformation: China denial by Xenna · · Score: 2

    Come on, I wouldn't believe anything Chinese officials say, but I definitely wouldn't believe anything any Worm-author would like me to believe either.

    If I were a nerdy Slashdot-reading Worm-writer I would probably think it a good idea to frame the Chinese. And start my infection spree by attacking some Chinese servers first. Next time he'll try Saddam or Milosevic (I heard those stupid Dutch gave him a computer in his cell).

    Why the White House? Simply because it makes for a more visible target, publicity is what these guys are after.

    Of course it could be the (a?) Chinese, but it could be anyone else on the planet with the necessary skills.

    Regards,
    Xenna

    Disclaimer: The fact that I have a Chinese girlfriend does not influence my opninion in the least. And, no, it wasn't me.

  265. People still don't know by macdaddy · · Score: 2
    What really gets me is that many people (read: Admins) still don't know about this worm. With all the publicity it's gotten they still don't know. Never mind the fact that the problem is known to the point that a patch has been officially released (for about a month and a half now) and that these people still haven't gotten around to installing it yet. That's incompetent if you ask me. IMHO every person should be accountable for any machine they put on the Internet. They should be responsible for at lesat the basic security practices. I had a friend who had his car stolen a few years back. The insurance company wouldn't honor his claim because in the police report he told the cops that he didn't lock the doors. The insurance company had a clause that stated that the owner was responsible for the basic security precautions and they gave a short list of no brainers. Locking the doors was one of them. Not leaving the keys in the ignition or in plain site through a window was another. I think similar things should be applied to publicly accessible machines. I just don't know how something like this would be enforced. Any ideas?

    --

    1. Re:People still don't know by macdaddy · · Score: 2
      What in the world are you talking about?

      --

  266. Re:Worms and market share by prizog · · Score: 2

    OTOH, almost every Unix box on the net has Perl these days, so, except for some bootstrapping code, it could be network independant. Also, compilers (and cross-compilers) are more prevalent.

  267. Re:Worms and market share by prizog · · Score: 2

    "Why don't you try writing a virus or worm that knows enough about each of the various *nix OSes, and the versions of Apache they are running, to infect them all. "

    s/Apache/Sendmail and Robert T. Morris did it over 10 years ago.

  268. Re:What would be incredibly funny... by cr0sh · · Score: 2

    You know it and I know it, and I am certain that most people here on /. know it, too.

    I tend to wonder if these "viruses" we have been seeing are merely "shots across the bow", so to speak. I mean - why hasn't a virus as you described come out yet?

    Most of the source code to these viruses is available for free, if you know where to search.

    It is obvious that MS products are buggy, full of holes to exploit, and rarely patched - not to mention that users of the systems tend to be lazy and ingnorant about security precautions - constantly clicking to see the next naked Brittany Spears image - so why haven't we seen true chaos yet?

    Worldcom - Generation Duh!

    --
    Reason is the Path to God - Anon
  269. Re:What would be incredibly funny... by cr0sh · · Score: 2

    Actually, I probably am good enough to do this under Windows - but I hate M$'s business practices, and their software is shit.

    I am a Linux "convert" - I run SuSE Linux 7.2 at home, currently learning Perl. At work I do VB and Java coding. I have seen the code of the ILoveYou virus - it is dead simple. I am certain these other "viruses" are similar in scope. I am aware of various virus coding sites, and I keep up from time to time on the "underground" - side hobby of mine.

    I could probably patch together such a "virus" as described, and even release it without leaving behind a "trail". The only thing keeping me from doing anything like this is that I know ultimately it wouldn't benefit anybody, not even myself - and would be unlikely to affect Microsoft, either. All it would cause would be anger, lost time, and money. So why do it? Of course, all of these other viruses out there do the same thing - so someone either is really fucked up in the head, or there must be some kind of motive.

    Boggles me...

    Worldcom - Generation Duh!

    --
    Reason is the Path to God - Anon
  270. This is not new by wiredog · · Score: 2

    When the Morris worm hit, around 10 years ago (IIRC), it was on all the major newscasts, and on the front page of many papers.

  271. Not that serious by alteridem · · Score: 2
    Hey, this isn't as serious as they make it out to be. The government is just concerned because they were stupid and choose Microsoft servers and probably think that's what most people use. The truth is though that Microsoft only accounts for 20% of the servers out there, but Apache runs on 63% (see Netcraft Web Survey)

    With any luck, this will just wipe Microsoft servers off the map. Check back next month to see Apache hit >70% on the Web Server Survey.

    1. Re:Not that serious by MrBogus · · Score: 3

      Netcraft's numbers do not apply to this situation -- they tally *public* webservers *by domain*, which means it ignores virtual hosts and load balanced configurations. Since the worm attacks on the IP address level, I think you'd find there's significantly more IIS _servers_ out there than the 20% of IIS _domains_ number indicates.

      Second, Microsoft has a large market of intranet servers and client machines running IIS for some reason or another. That's a significant amount of mayhem that doesn't show up in Netcraft's reports at all.

      --

      When I hear the word 'innovation', I reach for my pistol.
  272. Maybe it will change peoples minds about Microsoft by alteridem · · Score: 2
    Funny, another highly visible vulnerability in a Microsoft operating system. You think that sometime soon, people would start waking up and choose a more secure and efficient OS for important servers (like BSD or Linux of course.) There is an old adage that 'nobody can get fired for buying 'Microsoft' (used to be IBM). Well, maybe it's time that changed.

    When people make statements like this;

    The government relies on Microsoft and other technology companies to secure everything from defence networks to financial systems.

    and then call this worm,

    the largest ever dangers to the Internet.

    and then go on to state

    Code Red exploits a flaw discovered in June in Microsoft's Internet Information Services software used on Internet servers. It is found in Windows' NT and 2000 operating systems.

    When are people going to put the pieces together and start holding the people that choose Microsoft and maybe even Microsoft responsible for these things?

    Of course this is only a pipe dream. There are too many people out there willing to believe Microsofts propoganda.

  273. That's not the case by alteridem · · Score: 2

    Maybe you should check out the figures at Netcraft's Survey. Apache runs on over 63% of the web servers out there and MS IIS is only on 20%. I would bet that most of those Apache servers are running BSD, Linux or Solaris. The only reason that Microsoft has such a large share is that it takes a few Windows servers to do the work of one Linux server, so companies deploy more of them for their websites. Look at Microsoft's own attempts

  274. Deadline, Cringely!! by anticypher · · Score: 2

    [EDITOR] "Cringely, you useless fuckhead! Its deadline! Just make something up, 90% of your readership is so clueless, they won't know the difference. Ignore the 10% who have a clue, they won't bother reading our site for much longer."

    Although he mostly misses the point, especially about how any single unpatched server will somehow relaunch CodeRed every month, I'll agree that port 25 probes are on the increase here. But as more and more machines are patched, the problems and reinfections from this particular worm will eventually become lost in the noise. I am looking forward to new, better written nasty IIS worms over the next few months.

    It can be retargetted from whitehouse.gov to ... cringely.com in an instant.

    Thanks for the idea. Now, which bit is it that makes CodeRed attack forever? And which bits to change the target? :-)

    the AC
    [too much karma interferes with your tantric energy, time to troll]

    --
    Hemos is like...sci-fi fans;he thinks technology is cool, but he hasn't bothered to understand the science it's based on
  275. Use the Preview Button! by anticypher · · Score: 2

    (Use the Preview Button! Check those URLs! Don't forget the http://!)

    Doh! Port 80. Self-LART applied.

    [obPitifulExcuse: was working on sendmail/procmail/qmail/postfix/dns interaction on one screen, watching port 80 probe counts coming in on another screen, and reading /. on another screen.]

    the AC

    --
    Hemos is like...sci-fi fans;he thinks technology is cool, but he hasn't bothered to understand the science it's based on
  276. shut down the internet? by British · · Score: 2

    Shut down the internet?

    No more X-10 popup ads!

    No more AOL kiddies!

    This just might be the Internet Clean Up day we have been needing for a while.

  277. Re:Not a surprise to everyone by LinuxHam · · Score: 2

    Patrick,

    I *really* appreciate your recognition of my post. Unfortunately, my thoughts were discredited yesterday when I first got the ISS alert stating that several security firms have tried the clock-forwarding test, and they were *never* able to get the worm to reawaken. I guess I didn't deserve the "5; Insightful" after all :)

    I never did think that it could be rereleased tonight at 8ET to get started again, but even with the 2,000 hosts with the misconfigured clocks still trying to spread the worm, the first few hours won't be as devastating as the image I painted -- a hundred thousand hosts or more kicking it into high gear all within a few minutes of each other.

    I'm excited, so I'll be up late tonight to see how it's going. Thanks again for the recognition. Most appreciated! :)
    --
    Steve Jackson

    --
    Intelligent Life on Earth
  278. The Internet will "cease to exist" ? by theEd · · Score: 2
    As of July 2001 IIS only represented ~25% of the web servers on the Internet. So even if Code Red achieved 100% infection (highly unlikely), about 3/4 of the web would be untouched. Explain to me how this would cause the Internet to cease to exist.

    Besides, don't think of it as a virus, but rather "natural selection" in the digital world :)

    --
    "And now you shall learn the secret of boot to the head"
    1. Re:The Internet will "cease to exist" ? by SuiteSisterMary · · Score: 3

      Think about 25 percent of the servers on the internet constantly sending out a stream of crap against random websites, not to mention clogging up the wires as they search in vain for more servers to infect. In other words, imagine if 25 percent of the servers on the internet were suddening acting like SlashDot... Don't forget also that the attack affects various web-enabled machines, such as certain Cisco routers, HP LaserJets, and the like.

      --
      Vintage computer games and RPG books available. Email me if you're interested.
  279. die, monster devil, die! by nobody/incognito · · Score: 2

    i am really looking forward to midnight uct tonight -- it's a code red party!

    we'll have all our packet sniffers running full tilt and plan to laugh and laugh at all the losers running iis! die! die! die!

    nobody

    --
    parturiunt montes, nascetur ridiculus mus
  280. Vigilante style? by Marasmus · · Score: 2

    The government has turned down the prospects of creating a counter-worm, but any decently-experienced assembly programmer with sockets experience could just disassemble the current worm, make a number of changes, and release the worm on a time-skewed box. A really crafty assembly programmer could even keep the binary size of the worm the same, so in case the worm has some self-check mechanism, it won't notice any difference. I personally wouldn't mind seeing this fire fought with fire - Let the anti-worm run its course for a month, and then have it destroy itself. That would wipe out the vast majority of the code-red virus.

    It is a really rash and dangerous tactic, but considering the scenario that a number of people are expecting from this worm, are there really any other effective options?

    --
    .... um, i lost you after "0110100001101001".
  281. No email to infected owners? by SirSlud · · Score: 2

    .. where in, Sir Slud's suspicion that humans are dumber than rocks is confirmed: They decided NOT to email the owners of infected webservers. I'm guessing they felt that those server admins have far more important emails to read, like "MAKE $$$ IN A WEEK - TRUE STORIES FROM PEOPLE LIKE YOU"?

    --
    "Old man yells at systemd"
  282. What would be incredibly funny... by BlueUnderwear · · Score: 2
    ... would be a chimera made of "Code Red", "Seven Dwarves", and of course our friend "Sircam":
    • It would spread like Code Red by exploiting the hole in IIS
    • Like "7 Dwarves" it would be field-upgradable. Indeed, rumors are that the "7 Dwarves" virus has code in it to check certain newsgroups for messages signed with a certain cryptographic key. If it finds any, it can download them to patch itself to add new "functionality". This new functionality could be new payload, new exploits, new boilerplate text for the e-mails, whatever...
    • And, last but not least, from the infected IIS servers, it would send a barrage of e-mails to addresses harvested from Usenet or wherever, which would carry a Sircam-like payload...
    --
    Say no to software patents.
    1. Re:What would be incredibly funny... by BlueUnderwear · · Score: 2
      > so why haven't we seen true chaos yet?

      Probably because the people having the motivation to do so, don't necessarily have the skills... Hey, if you were good enough at Windows programming that you could do such a beast (even by piecing it together from existing parts...), would you want to rush the demise of that platform that you're so good at?

      --
      Say no to software patents.
    2. Re:What would be incredibly funny... by BlueUnderwear · · Score: 2

      Very interesting... I especially love the irony of using alt.comp.virus for this... However, from this page, it looks as if the virus itself can upload those plugins too... which would mean that the virus would actually have the private key needed for signing them. Which means that somebody could reverse engineer the virus, and then build a plugin which would disable the virus :-(

      --
      Say no to software patents.
  283. Re:The Entire Internet Will cease to exist... by EyesOfNostradamus · · Score: 2
    > Someone to feed my family for me.

    Hey, even after the dot-bomb crash of 2000, the software engineer's job market is still roaring. Just look around, I'm certain there are enough Linux-friendly employers in your area too.

  284. Re:Why all the public hullaballoo by AugstWest · · Score: 2

    This kills me -- install Redhat, choose the custom option, then DE-select "Web Server."

    Run through the rest of the install, and... tada, apache was installed anyway.

  285. Re:Oooo..... let's bash Microsoft! Yeah! by mesocyclone · · Score: 2
    This is getting to be an inadequate defense. If anybody else shipped products that required hundreds of thousands of people, including nontechnical consumers, to fix it every two weeks, they would have no business. And the consumers (as opposed to big-deal webmasters) never even get informed that *they* might have a problem. Furthermore, if the result of their inattention caused havoc on a major piece of infrastructure, the offending manufacturer would be torn to pieces by the media and government.

    The only reason that Microsoft gets away with this is the technical ignorance of the news media.

    --

    The only good weather is bad weather.

  286. Re:Worms and market share by Kishar · · Score: 2

    That's the sort of damned pedantry up with which I will not put.
    (STR)
    --

  287. Does Cringely know anything about computers? by treat · · Score: 2
    He says

    These 2,000 IIS servers are ones with broken clocks. They have no idea what the date is, so they are still in infection mode. The only good news here is that these machines never know to turn from infection to attack, either.

    If the clocks are set wrong and the machines are currently in infection mode, the machines will switch to attack mode when the clock says to. Does he really think you can have a computer with a "broken clock" that literally means it doesn't increment time within at least a few percent of the correct rate?

  288. Hmm or better yet... by Greyfox · · Score: 2

    Modify the Code Red code to install the IIS security patch and reboot the system...

    --

    I'm trying to teach myself to set people on fire with my mind... Is it hot in here?

  289. Can't They... by Greyfox · · Score: 2

    Can't the backbones do some routing thing and reroute traffic to the targetted address to /dev/null (Or better yet, someplace in China?) You can do a lot of cool stuff as a backbone provider. I remember one time when an MCI engineer accidentally routed all their traffic through one router in Mexico...

    --

    I'm trying to teach myself to set people on fire with my mind... Is it hot in here?

  290. Please cut the sensationalist crap. by TomatoMan · · Score: 2

    Michael, how on earth can you justify linking the phrase (the entire internet will) "cease to exist" to the article Washington sounds alarm over "Code Red" worm virus, when the article itself says or implies no such thing?

    You might as well link the phrase "alien attack imminent" or "Elvis seen in Redmond" - it has as much to do with the story as your title suggested. Of course, most people won't read the story, they'll just remember the catchy phrase that "the internet might cease to exist" - how exciting! - and that they read it first on slashdot.

    Code Red is a pretty serious situation as it stands; we don't need to mislead people while we talk about it.

    TomatoMan

    --
    -- http://frobnosticate.com
    1. Re:Please cut the sensationalist crap. by Anonymous Coward · · Score: 3

      I think it may have been irony?

  291. Re:I find this a bit offensive. by TomatoMan · · Score: 2

    Did you read the article, or just get offended that UNIX and NT were mentioned in the same sentence?

    Maybe you should read it before you get huffy. It contains generic steps for establishing and reviewing security policies, and then a methodical approach to recovering control. They add this useful link to all of their security advisories dealing with topics relating to the possibility of system compromises.

    TomatoMan

    --
    -- http://frobnosticate.com
  292. Re:The Entire Internet Will cease to exist... by Sc00ter · · Score: 2
    The problem isn't that everybody uses IIS, it's just that there's enough IIS server to create enough traffic to cause latency issues.


    --

  293. Variants by HunterRose · · Score: 2

    All these news agencies rave about the more effective variants out there. Does anyone actually know whats been changed other than the random number gen?

  294. Re:CNN this morning by BradleyUffner · · Score: 2

    I think you can be infected even with index server not running. The .DLLs are still used by IIS. At least I think thats what I read somewhere.
    =\=\=\=\=\=\=\=\=\=\=\=\=\=\=\=\=\=\=\ =\=\=\=\=\=\

  295. Re:FFS, doesn't anyone here... by john@iastate.edu · · Score: 2
    If this thing truly is cyclical (not just a one-month-wonder), then it seems to me that the N systems out there with mis-set clocks have been infecting other systems most of which are now sitting quiet, and on the 1st all those quietly infected systems will go into scanning mode. This will be the seed for August -- will this be a big number or a small number?

    Judging from the apparent lack of action by IIS sysadmins on this campus (or perhaps they're just procrastinating) I'd suggest a significant percentage of machines are still unpatched.

    So my guess is the curve will start faster this time, but reach a lower peak (because surely somebody has to have applied the patch).

    --
    Shut up, be happy. The conveniences you demanded are now mandatory. -- Jello Biafra
  296. Code Red Sci-Am article by mikeage · · Score: 2
    Although I'm normally somewhat of a fan of CPM's articles, I think this one was just a _little_ weird... the Chinese did it to get back at us? It might be the US government trying to frame the Chinese? I know she doesn't make these claims, just quotes others, but still... not every crackpot idea has to be covered.

    Other than that, quite an interesting article ;)... I wonder who they'll have write the "more in-depth" article referenced at the bottom of the article. Speaking of which... quick poll.. how many of y'all read that far to see that section? ;) (yes, the only way I got this so fast is by reading the article yesterday... if you subscribe to happyhacker@yahoogroups.com, you got this yesterday).

    --
    -- Is "Sig" copyrighted by www.sig.com?
  297. Beter yet - the reboot virus by Aceticon · · Score: 2
    Just do an IIS worm that spreads in exactly the same way as the Code Red worm (the same code base can be used).
    • First it has a propagation period in which it spreads using 199 threads (we got improve on the code red thing some way).
    • Next phase starts at a synchronized moment (using some web available Atomic Clock) and reboots Windows.
    Ideally all Windows machines with unpatched IIS in the whole world would be down for a couple of minutes - that should flush the little bugger...
  298. Re:Gibson may be extreme, but he does have a point by starseeker · · Score: 2

    "I don't want to flame you here (you did say you are not a security expert), but usually worms are not just simple scripts (nor even non-word viruses); on unix-systems they may (and have) been scripts to be more portable, but there isn't anything simple in them either. As to email being required... for decades (since first worms were created, early 80s?) worms have been able to use other network connections than email. That's the case with CR; variety is good for viruses and worms. Spreading using attachments is easy (some might say lame...) way to spread, but bit too obvious. Easy to implement, though, which is why it has been a popular approach. " Thanks for not flaming me, it's appreciated. I expressed myself badly - I didn't mean they were simple to code. What I ment was that once people see things like ILOVEYOU or Melissa in action, it's fairly simple to devise countermeasures and alert people what to watch for. What I'm afraid of is something that isn't so easy to watch for or warn people to be on the lookout for. Despite the obviousness of the attachment viri and the repeated warnings, a lot of damage was done. My school had to shut down email for a while during a couple of the outbreaks. Something more subtle yet just as universal would be scary. "I guess I just disagree with doomsday prophecies like this. Even though I don't want to appear like a MS-bashing zealot, I must say that Microsoft is now paying for putting security related issues on rather low priority for years. There's a lot that have been done by other companies and organizations (Java-security model by Sun, xBSD code inspections to build reasonably secure server OSes, etc. etc); Microsoft just didn't think potential risks were big enough. They have been proven wrong... and hopefully have started paying more attention." I didn't really mean to sound like a doomsday prophet - I don't actually think what I described will come to pass. What I am saying is that there appears to be no fundamental reason it can't happen, if some nut takes the time and effort. That means we have to think more carefully about how we impliment the next generations of network and computer technology. We don't even want a remote chance for something like this to exist. Sort of like nuclear bombs - I don't think anyone would actually launch one, but you still want to make sure you can respond if they do. As for Microsoft, I'm quite sure they are going to pay more attention, but at this point I'm not sure what they are going to do about it. There are already so many computers out there that have to be fixed and maintained, fixing their new stuff won't do a whole lot for quite a while. People use what works, and whatever it's faults Windows 95/98/Me does work for a lot of people. So they will be reluctant to fix bugs, because there is always the chance that it will break something. Also, Microsoft only keeps selling new version of their OS by adding more features. That is often at odds with security, but they need to make money. It's a problem.

    --
    "I object to doing things that computers can do." -- Olin Shivers, lispers.org
  299. Reminds me of my '94 NANOG T-Shirt by Prof_Dagoski · · Score: 2

    Which sez "Repent, the Internet Will Collapse in 8(crossed out) 7 Days". So, CodeRed is the Internet's crisis dujour. Has anyone noticed that the Net seems beat the odds makers every time? Meanwhile, the SciAM article is unreal. Talk about paranoic speculation and exagaration. "The only remedy is total isolation". C'mon. It's the same as always, don't use outlook, and don't open unknown attachments. And, don't use windows unless you have no better choice. In terms of net traffic, yeah, that's a bummer, but hardly a show stopper. The Internet will be bogged down as thing waxes, but it'll go away. There is one point the SciAM article makes that is worth paying attention to: the need to get ready for the next one. So far, no one has written a worm designed to launch denial of service attacks against backbone routers. This type of attack could be very dangerous. However, it would require a lot knowledge about the current architecture of the Internet, and a good understanding of the TCP/IP protocols. Luckily most of the script kiddies out there haven't read David Comer's series on TCP/IP, but it's only a matter of time before we get someone knowledgeable and malicous.

  300. Media Hysteria?!?! by ayjay29 · · Score: 2

    This cracks me up!

    The BBC had their ActionMan Nick Bryant on the scene at the RipTech Computer Center in Washington with a camera crew and a live saterlite link up. They are T+ 4 hours, and the conversation goes a bit like this:

    Nick: Well, computer expert, whats happning?
    Expert: Well, actually, nothing.
    Nick: Do you think it's over-hyped by the media
    Expery: Um, well... Yes...

    Check the article or the RealVideo

    --
    Offtopic, Inflammatory, Inappropriate, Illegal, or Offensive comments might be moderated up.
  301. Re:CNN this morning by demo9orgon · · Score: 2
    Think CNN performed a disservice?

    At least they had the balls to mention the evil M$ empire and their flaky server/services. ABC was a gelded wonder this morning and didn't mention any of the following words in their "the sky is falling because of the Code Red worm" hysteria:

    • Microsoft
    • Internet Information Server (IIS)
    • Windows NT
    • Windows 2000
    Any layperson who was hearing about this issue for the first time would think that there was something malicious out there just disrupting the Internet in general, but they wouldn't have a clue about how, or why. And listening to spoo-brained dullards muse about who was responsible or where the worm came from was a joke.

    What really made me want to shift into Nordic Stormgod Mode and beat the assholes within inches of their ignorant lives was the line

    • "Just reboot the machine and the worm will go away."
    I watch both the "Free" as in "through the air" and "Pay" as in "Holy crap they raised my cable bill again!? Damn Icehole sucking bastiges!" news services, and the lies of ommision coming from the free side are shameful.

    And what really sucked was listening to the newsreader/MC lie repeatedly about how he broke his wrist (hey, that isn't news!).

    It all just goes to prove that it's not about news, it's about entertainment...and dodging the pit of lawyers large corporations have while giving Joe Public his morning brainwashing. Ahhh...lemony freshness.

    Personally, I think the worm was the right thing to do. It exposed a closed-software tendency to create backdoors into a long-duration service which would permit government/M$/and anyone who knew about the weakness to exploit it.

    Sysadmins are supposed to be smart people. What M$ has done is screw a couple hundred, maybe even tens of thousands of them. What I'm waiting for is an even bigger backlash at the Sysadmin level, where the words,

    • "We're not going to deploy on Internet Information Server because it has no security and there's no accountability for it from the vendor."
    will be commonplace and more and more server farms will silently shift to *nix and Apache, and all those M$ developer subscriptions (useless firehoses of CD's and nifty binders to hold them) will silently wither away, and M$ zelots will not have their marketing mail answered and will endure mono-syllabic responses to their phone calls from smart people who have a right to be royally pissed. If there's no accountability, then why bother with a pay-to-play solution?

    I look forward to the day when M$ server products are reviled for the exploits they are. Sure it may take a while, but somewhere out there right now several clever people are enjoying themselves, having made at least a partially successful run with this last worm, and will probably have the code for an inline resolver to use with the next worm.

    --
    Every new form of media has it's own Requirimento
  302. self-defense by peccary · · Score: 2

    I think that Bush should just sign an executive order making it legal to take out any machine trying to infect you with CodeRed, on the grounds that it's self-defense (of other innocent standers-by, obviously). Just like if I see a rapist attacking a lady at the bus-stop, I can probably legally kill him. We should be able to do the same thing re: CodeRed.

    It wouldn't last too long, in that case.

  303. Re:CNN this morning by MrBogus · · Score: 2

    What really made me want to shift into Nordic Stormgod Mode and beat the assholes within inches of their ignorant lives was the line "Just reboot the machine and the worm will go away."

    Well, the worst thing about all of this hype is that it's not being directed towards fixing the root problem -- the fact that IIS ships with WAY WAY too much stuff turned on by default.

    My guess is that 99% of the people infected by Code Red didn't need Index Server running in the first place. So, they'll patch (or worse, reboot) and go on their merry way. Until the next bi-monthly (not much of an exaggeration) Index Server bug is found in which case they are screwed again.

    Repeat for FrontPage, Internet Printing, Remote Data, and all of the other mostly unused crap that out-of-box IIS has. The correct security advice should be:

    1) Turn all of this stuff off if you aren't using it. (And if you can't figure out how, turn the web server off and get the hell away from it.)
    2) Patch only if you need the affected software.

    --

    When I hear the word 'innovation', I reach for my pistol.
  304. Re:No IP telephony for Robert X. Cringely by wishus · · Score: 2

    IP telephony doesn't need the internet - just an IP network.

    Carriers build their own IP networks so they can control / monitor traffic and guarantee QoS.


    ---

  305. Re:No IP telephony for Robert X. Cringely by wishus · · Score: 2

    Yes, you are correct.

    And let us not forget those fly-by-night operations that use the internet to lob calls overseas for cheap rates meanwhile escaping regulation as a telephone carrier.
    ---

  306. Idiots in journalism by InfinityWpi · · Score: 2

    According to the Yahoo story, Code Red was named after a soft drink prefered by programmers...

    Excuse me? The Code Red drink hasn't been around long enough to be prefered by programmers... don't you think it's far more likely to say that 'Code Red' was chosen simply to make people think it's more dangeous than it really is?

    They also blame the thing on the Chinese... sure, if a virus made to doS the White House puts text saying 'Hacked By Chinese' on your screen, you're going to believe it? Just like all those guys on Counter-Strike servers a few months ago talking about Wang Wei were really Chinese, too...

    Journalists are so -gullible- when they're trying trying to start a panic...

    1. Re:Idiots in journalism by InfinityWpi · · Score: 2

      *sigh* I really need to remember to research everything before making comments about journalism... this is why I'd never make it as a reporter. I stand corrected.

      Still can't believe everyone's decided it's either the Chiense or a US frame-job, tho...

    2. Re:Idiots in journalism by 11223 · · Score: 2

      Thanks for the warning. I've been meaining to try it but neither the machines here at work or the machines at school carry it. I'll stay away.

    3. Re:Idiots in journalism by phil+reed · · Score: 3

      The fellows at eeye, who are the ones who found the IIS hole, and then found and analyzed the worm called it Code Red, because they drank copious quantities of Code Red Mountain Dew while they worked on it. Check the archives at SecurityFocus.


      ...phil

      --

      ...phil
      "For a list of the ways which technology has failed to improve our quality of life, press 3."
    4. Re:Idiots in journalism by astrosmash · · Score: 3
      Excuse me? The Code Red drink hasn't been around long enough to be prefered by programmers... don't you think it's far more likely to say that 'Code Red' was chosen simply to make people think it's more dangeous than it really is?
      No. The guys (from eEye Security) who initially reverse engineered the worm were drinking Code Red at the time, so that's what they named the worm.

      --
      ENDUT! HOCH HECH!
  307. Prayer for the Red by fishbonez · · Score: 2
    Oh Great and Mighty Keeper of the Code, we beseech thee. Save us from thy wrath. For it is the bane of our media-hyped existence. Oh to watcheth the cable news and not see thy handywork whipped into a feeding frenzy.

    And lead us not unto insecure NT boxes. For it here in the fertile ground of evil that thy demon seed takes root. We, the Children of Linux, ask only that you keep our Linux safe and secure. And that you limit thy wrath to the unfaithful heathens of NT. Amen, brethren.

    --
    Frylock: That's not a toy!
    Master Shake: You say that about everything you own. You should own toys. They're fun.
  308. Re:Mis-set clocks? by Erasmus+Darwin · · Score: 2
    It's not picking up where it left off, it's starting over infecting the internet almost from scratch, so it should be the same thing as last time.

    Except that last time, (as I understand it) the infection window was relatively short before it kicked over into attack mode. Also, due to the Cisco problem, the infection time is a bit of a DoS attack itself.

    I don't expect doom and gloom (especially with the page defacement and probes making it easier to identify compromised hosts), but I do expect it to be at least a little different from last time.

  309. Serious to a fault by SubtleNuance · · Score: 2

    "The Internet has become indispensable to our national security and economic well-being," said Ron Dick, head of the National Infrastructure Protection Centre, an arm of the FBI. "Worms like Code Red pose a distinct threat to the Internet."

    You think things are bad for hackers now, wait until all the clueless masses start seeing the Internet as a battlefield - you only have to say 'National Security' in America to get the public inspired to goto war, whatever the cost... god help us.

    "hacked by Chinese" oh brother - might as well say "hacked by the godless communist hordes out to destroy the american way of life and enslave you! Defend America from the Red Menace!"

    What laws will the Plutocrats pass now in order to defend the Internet from life outside their precious economy. I am personally not that alarmed with trojans or worms. The world can live without the internet - our desire to have zero random variations in all things (our lawns, our parks, our workplaces the internet), removing all acts of fancy/folly and chaos (in a good sense) has shaded our eyes from the important goals. So what if the Internet shuts down for a few days?

    Frankly, the world needs a little random excitement... Much in life is arbitrary, a game if you will, lets not get to serious about all this, try and think about this in a more situationist manner.

  310. InfoWorld Cringley is not PBS Cringley by satch89450 · · Score: 2

    Not that it makes much difference, but there are two Robert X. Cringley people in the world. Cram (no, I'm not going to use his real name) wrote the column for InfoWorld for years, then broke away from IW and IDG and took the name to new heights.

    Meanwhile, back at InfoWorld, another member of the staff has picked up the monikor and writes it.

    That doesn't invalidate your statement, though, that his infamy is due more to who he knows than what he knows -- but the PBS Cringe does know quite a bit on his own. (I used to work with him.)

  311. Plenty of commercialization to go around. by shokk · · Score: 2

    Remember the next time you hear about a virus and see a vendor offering a free fixit, that the link to download that fixit is on the same page with an ad for their virus protection. No free deed is done without some small ulterior motive on the net or anywhere else.

    In the case of the worm, every time MS offers a patch, you're deeper in their hooks, when you should instead be finally fed up and refuse to operate with such irresponsibly assembled solutions. Only when you've pushed MS to produce something that can be thought of as secure, or gone over to Apache will you be out of the Code Red cycle. No Apache is not free of holes, but when they appear I see a much stronger effort in that group to hunting it down and telling everyone that they had better upgrade NOW.

    Yes, it might not be a simple thing to have to go and recompile Apache vs downloading the next patch and rebooting, but think about what you buy for that convenience. Just because something is cheaper doesn't make it better, and I'm not just talking about $$$.

    --
    "Beware of he who would deny you access to information, for in his heart, he dreams himself your master."
  312. Re:The Entire Internet Will cease to exist... by Chundra · · Score: 2

    And of course we all know what this means. Unreal Tournament will be practically unplayable over dsl.
    --

  313. Dynamic View of a Webserver Log File by BigBlockMopar · · Score: 2

    For all those Slashdotters who don't have access to webserver logs and therefore can't see the Code Red worm searching for victim hosts, check out this dynamically created view of my log file. For legibility, a reverse lookup is done on the incoming visitors.

    The party should start shortly after 8:PM Eastern time tonight.

    --
    Fire and Meat. Yummy.
  314. Where's the poll? by scott1853 · · Score: 2
    Hoy many people think:

    Nothing terrible will happen.

    The Internet will die

    Cowboy Neal will die

    Please note that I said think not wish

  315. This could be bad! by quintessent · · Score: 2

    Someday, they might nickname this catastrophe, " Y2K-2! "

  316. cease to exist? Great! buletin boards here I come by Billly+Gates · · Score: 2

    I would love to see hailstorm and .net fail. I also miss the days of CompuServe and dialing bbs's. I find receiving any information that I need on the Internet difficult. It's cluttered and way too big. The search engines only look for words and key phrases and not content. The reason AOL is so popular is that everything is organized. Sure its slow and unreliable but the productivity is incredible. With the web you have to search and know where to look.

    Anyway, I highly doubt this will happen. The backbone may become saturated but UUNet definitely can deal with this. Even if the Internet pauses or even goes down, you can always reboot the routers. After the Internet connection is idle for a certain period of time the NT servers will assume its down and stop sending packets out on the web.

  317. Re:a taste of what's to come by TOTKChief · · Score: 2
    When are people going to get the hint that despite all their propoganda, Microsoft is not good for anyone.

    No, let's make that, "When are people going to get the hint that, despite the conveniences, relying on one entity for the managemente of data or other assets is not good for anyone."

  318. Is your server on 'the patch'? by tenzig_112 · · Score: 2
    My server has been eight kinds of agitated today.

    I wonder why?

    I cannot [nor do I possess the patience to] count the number of desktop users who have demanded that I install the patch on their machines before it "hax0rz the white house gibson" and gets them put in jail. They seem more worried that the virus will drown the Net and cause their multiplayer game of Hearts to be interrupted.

    Thankfully our Content-O-Matic server is in the clear. No one writes decent viruses for the DRDOS Http Daemon anymore. A shame, really.

  319. The whole internet could crash ... by Mr_Silver · · Score: 2
    Before Microsoft the web was nothing!

    Now after they've finished, there will be nothing left!

    What an accolade! :o)

    --

    --
    Avantslash - View Slashdot cleanly on your mobile phone.
  320. Just government looking for an excuse... by sdo1 · · Score: 2
    To quote the smh article...
    In an unprecedented show of force against an extremely virulent Internet attack, government and private officials will tomorrow implore worldwide organisations to protect themselves from the "Code Red" worm.

    In a not-so-unprecidented show of FUD, the government is finally getting the the boogey man they so desparately need in order to swing public opinion toward the side of deepening regulation of the internet.

    -S

    --
    --- What parts of "shall make no law", "shall not be infringed", and "shall not be violated" don't you understand?
  321. Distribute Patch via Worm by devnullkac · · Score: 2

    If there are so many web masters out there who refuse to protect themselves, perhaps someone knowledgeable could take it upon themselves to write a worm which installs the patch to close this security hole.

    Volunteers?

    --
    What do you mean they cut the power? How can they cut the power, man? They're animals!
  322. Re:Why all the public hullaballoo by Auckerman · · Score: 2
    "The general public, for the most part can do nothing to stop this. It is sysadmins and those running servers who need to pay attention."

    I was talking to someone today, and they mentioned that one their web servers (IIS) was hax0r3d and defaced, to which I replied, "I hope the sys admin looses their job for that". The guy was astonished and actually asked why! Good Lord, has it really come to that? He thought it was ridiculous to fire someone over a hack, cause "that kind of thing can't be stopped". Is it really that hard to install publically available patches? Is it really that much of a pain to keep up with security bullitens?

    The Navy (or Airforce?) actually turned off their servers to avoid this! If the sys-admins of our armed forces are so fucking stupid as to NOT apply patches immediatly, is there any hope?

    --

    Burn Hollywood Burn
  323. Oooo..... let's bash Microsoft! Yeah! by rabtech · · Score: 2


    Let me recount two very important facts before everyone starts jumping all over Microsoft.

    1) If you had followed the security checklist for IIS 4/5, you would not be vulnerable. The checklist instructs you to go over the server mappings and remove any that are unnecessary, including the one for Index Server.

    2) If you were on the Microsoft Product Security Bulletin mailing list, you would have gotten a notice back in early June about this, downloaded the patch, and installed it. Thus, you would not be vulnerable.

    This is not a case of Microsoft shipping something insecure by default (although such a case can be made for other issues in the past). This is a case of the most common programming mistake made by C++ programmers the world over: a buffer overflow. Buffer overflows have been found in every single OS currently in use, which includes Linux and *BSD. Some have even been root exploits.

    Please... go to http://www.microsoft.com/technet/security/

    There are a number of checklists, tools, and downloads that can be used to harden any IIS webserver to the point that it is virtually uncrackable. Of course I must add the virtual part, because there is ALWAYS a chance that ANY system connected to ANY network can be compromised. There is no such thing as 100% security; we can only get really close.

    I now return you to your regularly scheduled zealotry.


    -- russ

    --
    Natural != (nontoxic || beneficial)
  324. It could have been much worse.... by canning · · Score: 2
    Then, at midnight, all Code Red zombies quit searching for new victims. Instead the horde of enthralled computers all focused on flooding one of the servers that hosts Slashdot Web site with junk connections threatening its shutdown. "Slashdot essentially turned off one of its two DNS servers, saying that any requests to slashdot.org should be rerouted to the other server," says Jimmy Kuo, a Network Associates's McAfee fellow who assisted slashdot in finding a solution. Luckily, Code Red couldn't cope with the newly altered address and waged war on the inactive site. "The public didn't notice anything because any requests went to the other server," Kuo says. We feel that this is payback for the numerous servers the "Slashdot Effect" has grinded to a halt. The author of this worm has made it personal.

    --
    I love the smell of Karma in the morning
  325. No IP telephony for Robert X. Cringely by hillct · · Score: 2
    I particularly like this quote from Cringly:
    And what happens on the 20th, when the attack cycle begins? It depends on the number of infected machines and the nature of the chosen target, but the worst case says the Internet simply comes to a standstill and we go back to watching TV and talking on the phone until the 28th day of the month and potentially until every 28th day of the month thereafter.
    So we will simply stop using the internet and instead watch TV and talk on the phone huh? gee. Where does that leave IP telephony? Telecom industry analysts have criticized the major players (Nortel Networks, Cisco Systems) in this industry for sinking so much money into IP telephony too soon, and blame this for the telecom equipment market downturn. If Cringely is right, the IP telephony market may never get it's chance to prove itself... but at least we'll still be able to talk on the phone.

    --CTH
    --

    --Got Lists? | Top 95 Star Wars Line
  326. Interesting Quote: by einhverfr · · Score: 2
    "The question for security enthusiasts and professionals alike is, how do we prepare for what's around the corner?"

    IMO. DMZs with good firewalls, monitoring outbound as well as inbound... Laws mandating it. Switching to Linux is not the answer, as much as I like open source, because it too can be attacked (just not as easily, and the same user problems could exist there as well). Good firewall design is the only way, and I think that anyone with internet server of any kind should use some sort of firewall. at least for monitoring...

    Sig: Tell all your friends NOT to download the Advanced Ebook Processor:

    --

    LedgerSMB: Open source Accounting/ERP
  327. I always knew... by Lobsang · · Score: 2

    Yes, I always new Microsoft would destroy the internet one day! Either by incompetence or by... incompetence (what else?). :))

  328. If only there was this much attention... by baptiste · · Score: 2
    when the original hole was found :)

    I can't figure out all this chicken little/sky is falling media coverage (well hey its yet another SCARY Internet story, but still). CNN had an article that kinda made me chuckle. It was a story on ISS founder and "worm splattering" "worm hunter" Chris Klaus. It talked about how the 'patch may not hold' What a great thing to be telling everyone. If a new version of the worm hits and spreads liek wildfire, it will be due to a new vulnerability I'd expect. Amazing how mainstream media tries to cover situations like this.

    As for the real threat, I expect there will be a large # of infections tonight/tomorrow. Why? Just look at the analysis at CAIDA They found that the majority of servers infected were from domains used primarily by small businesses and residential users (@home, etc) While many of these will have patched themselves, I'm sure many just restarted when problems arose and the problem went away - problem solved. I mean that's standard MO with a Microsoft OS - if it starts acting strangely, reboot.

    The good news is, perhaps ISPs have been able to put plans in place to try and block the worm from spreading. Only time will tell.

    Don't get me wrong - I think publicizing this issue is a good thing. But I expect that the problem will not be as awful as the media is trying to protray (Internet slowdown, websites knocked offline, etc)

    Of course on the flip side - we know that the patch won't be applied to every IIS server out there - what will be done and by who to track down and irradicate the remaining servers that are still infected or are being re infected day after day? I'd expect hte ISPs but given the service level of many DSL and cable providers - you haev to wonder if they'll all pursue this diligently unless the courts get involved (yuck)

  329. Re:CNN this morning by cavemanf16 · · Score: 2

    What's really sad is that this kind of 30 second 'news spot' does it for the majority of people. Most could care less what the details are these days. And not just on tech related news, I'm talkin' 'bout all sorts of news: political, social, worldwide, etc. Needless to say, here's just one more reason why I'm changing all my really confidential and important stuff to Linux, and I don't give my allegiance to any one large, bloated, political party.

  330. Re:Mis-set clocks? by Rogerborg · · Score: 2
    • It isn't a bug that Windows requires rebooting every few days, it's a security feature.

    You chuckle, but it actually says in the MSDN docs that the Windows NT family suffers from the "problem" that it doesn't fall over or have to be rebooted as often as Win9x. When applications crash out and leak memory, you don't get it back, so you really should encourage users to reboot every few days.

    I put my hand on my heart and swear that this is true.

    --
    If you were blocking sigs, you wouldn't have to read this.
  331. Re:Why all the public hullaballoo by Rogerborg · · Score: 2
    • First, prove to the world that end-to-end is broken. Then, advance proposals to fix it.

    If there's one thing our media has taught us, it's that no technical problem takes more than 60 seconds of random typing on a laptop to solve, as long as there are enough A list stars, guns and blowjobs involved.

    --
    If you were blocking sigs, you wouldn't have to read this.
  332. The Entire Internet Will cease to exist... by loconet · · Score: 2

    The Entire Internet uses IIS??

    --
    [alk]
    1. Re:The Entire Internet Will cease to exist... by masoncooper · · Score: 2

      The way I see it, since a patched IIS server is no longer vulnerable, I see these infecting waves hitting a smaller and smaller amount of unpatched IIS servers due to (hopefully)the admins seeing their defaced site and getting off thier butts to patch it. Eventually the numbers will drop low enough to not effect any noticable amount. Of course by then, all the admins realize they were totally raped by M$ and move to Apache and join the rest of the world.

    2. Re:The Entire Internet Will cease to exist... by peccary · · Score: 3

      The problem was that there were just enough Cisco routers running down-rev software that crashed when you send "GET ?" to port 80. Fix those, and the Internet will be fine. The traffic is a non-issue.

    3. Re:The Entire Internet Will cease to exist... by sorinm · · Score: 4

      And then another bug will be discovered, and then another worm will start spreading and so forth. The only solution to this (IMHO) is not to shut down whatever network or to put another patch or even to switch to Apache. The solution is to stop the false ideea that using computers is easy. It is not, it requires work and study. Thos who are merely pushing buttons on screen should quit computers or pay more atention. Having a netwotked computer is a responsibility and people should learn that. "Easy use" of computers is the virus, not Code Red. Sorin M

  333. Productivity Conspiracy ! by beanerspace · · Score: 2
    GAD ! If the Internet shuts down, I'll actually have to do some real work on my computer !!!

    If I didn't know any better, I'd think Code Red and similar viri are the product of conspiracy put into place by pointy-heads of management-types to keep us from our Constitutional right to goof-off ! !

  334. blew another chance to make millions ! by beanerspace · · Score: 2

    Darn ! If I would have known this issue was going to recycle, I would have modified some old Y2K tripe with "Code Red" stuff, bought some time on some religious broadcasting network and made beacoup dollars peddling fear to survivalist-types.

  335. Re:I find this a bit offensive. by Anomynous+Cowand · · Score: 2
    I've read the article, but that's not my point. My point is one of "first impressions" -- the title simply gives one the first impression that UNIX and Windows are both similarily insecure.

    Yes, they both have some weaknesses, and yes, the aforementioned common practices apply to both. And yes, there are both good and bad system admins working on both UNIX and Windows boxes. My complaint is the simple juxtaposition of listing UNIX first in what is a uniquely IIS fault. It gives one the incorrect impression that UNIX may somehow need to be improved to make up for the Code Red attack.

    Truthfully, the article is so full of "If UNIX else if Microsoft" clauses that if were an object under my control, I'd split it into two articles: one for securing UNIX and one for securing Windows.

  336. I find this a bit offensive. by Anomynous+Cowand · · Score: 2
    CERTs page has this to say under the III Solutions section:
    If you believe a host under your control has been compromised, you may wish to refer to Steps for Recovering from a UNIX or NT System Compromise
    So, they've given UNIX first billing on a distinctly Microsoft problem? Spin! Spin!
  337. Re:Steve Gibson Made this Worse by The+Jboy · · Score: 2

    has it occurred to anyone that this guy is a closet hacker himself? like the old saying, the criminal returns to the scene of the crime...what better way of getting attention? write a virus, talk about how terrible it is on TV, watch it die, lather, rinse repeat. Jboy

  338. Re:Best-case scenario by Hallow · · Score: 3

    Umm. ColdFusion server runs on linux. Sure, you can't use studio, but the lack of a text editor's not necessarily a reason to abandon the platform. The docs are all HTML, install in windows, copy the docs over.

  339. Help from your friendly unix/linux webmaster? by hrm · · Score: 3
    I had an idea for a simple little program that can help sort out this Code red mess. I'm not aware of any existing program that does this and unfortunately lack the time to write it myself -- even though it's probably not beyond my rudimentary bash skills, it's that simple -- so I'll just present the idea here in the hope that someone will pick it up (or shoot it down in flames if it sucks :-).

    What I propose is a GPL'd shell/python/perl script that "grep"s the apache/thttpd/whatever access log for "default.ida" requests, and logs the requesting site name/ip to a file. Sort | uniq this file for good measure, then send a friendly message to the webmaster at this site, stating at least the following points:

    • an apology in case this is the 50th mail of this nature that the admin receives (possible, because I recall that an infected host contacts about 100 semi-random targets), and point out that there's no way for the sender of knowing that in advance.
    • that their host has probably been infected by the Code Red worm, or a mutation thereof (you should grep for "default.ida" only and not "www.worm.com" as well, as mutations are not likely to use that string). Also quote the access log line, to be complete.
    • briefly point out that this is not a hoax, as can be seen from these mainstream press articles (link, link, link).
    • point to the microsoft patch.
    • warn them to look into the problem in case it's a new strain of Code Red (for example, a disk-resident one that can't be flushed by a reboot).
    • put in a plug for free software :-). Make it a friendly and useful kind of microsoft bashing for a change...
    • link to the author and source of the program that was used to generate this mail, for review and troubleshooting of the program.

    Running this a few times a day, and keeping track of the sites that we've mailed already to avoid duplicates, should give semi-awake (i.e. reading mail, but not patching their system regularly) IIS admins some friendly help.

    What do you think?

  340. Not a surprise to everyone by p3d0 · · Score: 3

    Apparently this guy saw it coming.
    --

    --
    Patrick Doyle
    I mod down every jackass who puts his moderation policy in his sig. Oh, wait a sec....
  341. a taste of what's to come by Lxy · · Score: 3

    I hate to criticize .NET since I am by no means the expert on the subject. Think about if .NET actually succeeds. Every PC, PDA, cell phone, and dog collar will be running a Microsoft OS and accessing its data over .NET. What happens when the .NET version of Code Red comes out? What then? All my data is wrapped up in .NET. Everything I do is on a server somewhere but the wireless .NET is too bottlenecked for me to get to it. It's a sign of things to come. Companies put many $$ into Microsoft software and constantly have to upgrade to keep a virus from systematically destroying their entire network. When are people going to get the hint that despite all their propoganda, Microsoft is not good for anyone.

    --

    There is no reasonable defense against an idiot with an agenda
    :wq
  342. CNN this morning by iso · · Score: 3

    I saw the "special report" on CNN this morning. Pretty standard stuff for a non-technical news show but what was funny (or disturbing, depending on your take) was when the "technology expert" said that "a simple re-boot" would solve the problem in the near-term. He went on to say that regular reboots (on your servers) are a "good idea," as it's like "cleansing your system." The host agreed and said she solveds all her computer problems with a reboot :).

    They took a while to explain that only Windows NT/2000 are at risk while Windows 98/Me are not. No mention of any other alternatives besides Windows of course (I guess that's too much to ask :). Of course what I can't believe is that they're still talking about this! Are there that many admins that still haven't patched this?

    - j

    1. Re:CNN this morning by chompz · · Score: 3

      You ask about admins still not patching this? Take five seconds and ask yourself of all of the webservers you know, how many of them are on a network with a full time administrator? You think its all of them, don't you. No, it isn't. The companies which we need to really worry about are the ones like the webdesign company my girlfriend works for. They have a server, but they have no on staff administrators. ZERO! If something goes wrong with their server(s) they call the owner of the companie's kid, who doesn't know anything at all about security, he manages to know a few simple things about computer hardware, but not that a motherboard with an AGP1x does not work well with AGPPro cards.

      I alerted them to being infected by several IIS worms and security compromises, and they still haven't patched.

      They just don't have a clue.

      --
      Spring is here. Don't believe me, look outside!
  343. Code Red Sci-Am article by mikeage · · Score: 3
    Although I'm normally somewhat of a fan of CPM's articles, I think this one was just a _little_ weird... the Chinese did it to get back at us? It might be the US government trying to frame the Chinese? I know she doesn't make these claims, just quotes others, but still... not every crackpot idea has to be covered.

    Other than that, quite an interesting article ;).

    --
    -- Is "Sig" copyrighted by www.sig.com?
  344. Microsoft should be held responsible for this by Animats · · Score: 3
    It's time for companies that distribute bad software to take responsibility for it.

    A class action against Microsoft would be appropriate, in that it is a defect in a Microsoft product that made it possible. The class action should be led by non-Microsoft users impacted by the problem, so EULA issues are irrelevant.

    Where's the plaintiff's bar when you need them?

  345. Re:Steve Gibson Made this Worse by SuiteSisterMary · · Score: 3

    Don't forget, Steve Gibson is the guy who managed to make a 13 year old kid in a chat room, writing code that opens a socket, sends a few IRC commands (the hardest being the Ping/Pong set) and accepts a few commands sound like some sort of Big Black Voodoo Priest, sitting upon a throne carved from human bone, piecing together zombies from heaps of human corpses and sending them out to do his evil work.

    --
    Vintage computer games and RPG books available. Email me if you're interested.
  346. Best-case scenario by legLess · · Score: 3
    A friend of mine runs a Cold Fusion/NT website, and has IIS installed on his home box for development. I called him last week to alert him to this thing, and it was the final straw. He dragged an old P133 out of the closet and installed Mandrake, Apache and PHP on it. Now he's migrating his site away from Cold Fusion.

    There are a few points of interest here:

    • First, as we've all been saying, Microsoft's security flaws are hitting them where it hurts - market share.
    • Second, this guy had *never* used Linux before (although he'd seen me use it, and we've talked about it for a long time). In less than 3 days he started from scratch and got a running development machine. This is evidence of a huge step forward for Linux usability.
    • Third, Allaire/Macromedia just lost a customer. Microsoft is not a safe bet in many applications, and tying yourself to them will hurt in the long run.


    "We all say so, so it must be true!"
    --
    This isn't as much "normalization" as it is "don't take so many drugs when you're designing tables."
  347. They should call it "code redmond"... by iconnor · · Score: 3

    then at least I would know that it didn't apply to any of my servers. Instead, I have to read through a few paragraphs of crap before it gets to the "IIS security flaw" line.

  348. Fatal Infections by Srin+Tuar · · Score: 3

    Analogous to real virii and worms, Those that destroy their host too quickly dont spread.

    Those that dont spread die off.

    Making a system unbootable doenst destroy the data on the harddrive. But if the data on the harddrive is destroyed- the admin will reboot.

    The computer is now offline and the worm gets no more opportunities to spread.

    A common way to overcome this is to set a logic bomb: have the worm set a cutoff date after which it becomes destructive. The problem with this approach is that it allows people time to patch their systems.

    A good compromise would be to make the system unbootable immediately- with a boot loader that wipes the harddrive. Then set a logic bomb with a cutoff date after which data gets deleted.

    Its tricky though. A good twist may be to rearrange some dll's in the filesystem- to cause patches to fail. Also setting up a backdoor vector for reinfestation. Then at least 3 subtly different versions would have to be released simultaneosly.

    Its a lot harder than it sounds. And not worth it really.

  349. Maybe we should send Al Gore a wreath.... by doctor_oktagon · · Score: 3

    ... and a card with our Condolences to mark the death of his "child".

  350. Re:Worms and market share by Auckerman · · Score: 3
    "Part of the reason Microsoft has so many hackers and skr1pt k1ddi3s after them is because Windows is so wide spread."

    As the previous writer clearly stated, and you clearly missed, this is just not the case with IIS. Since IIS has LESS marketshare then Apache one would expect Apache to have this kind of problem and not IIS, but it doesn't (All of which the previous poster stated).

    Part of the reason Windows is so widespread is because Windows is stable (in an API sense, and in a reliability sense as far as W2K is concerned), and easy to write for

    You mispelt "Part of the reason Windows virii are so widespread...."

    Which you would have partially correct, but mostly wrong. W2K is MORE stable than previous Windows, yes, but no where near as stable as the traditional Unixes. Windows API could NEVER be described as stable since upgrading Windows almost always breaks something important (my CD burner, for example, which works in OS X, but not WinME). This is the reason many people are still on NT4 SP3/4. If they move up to SP6 or W2k, something important breaks. This is a big reason why Windows is taken down so much. The other part you addresses with the "easy to write for" comment. VB is easy to learn (compared to Unix scripting) and can be learned on a desktop machine before one begins coding for IIS. You can use VB for all sorts of things, including scripting the breaking into of systems, so that some 9 yr old on AOL can breaking into WIndows machines all day long...

    --

    Burn Hollywood Burn
  351. idiocy of Hong Kong's media by jsse · · Score: 3

    Media here told the public Code Red would infect all computers. They simply ignore the fact that Code Red infects only IIS 5 server.

    A local lead moron - the president of Hong Kong Computer Society, a branch of British CS, told the public that in order to protect yourself from virus, we all should update the latest virus signature and do not swith on computers. I'm sure all their members would feel shame of their president's cluelessness.

    Scott Adam is right, idiots, morons and clueless people are defining the reality.

  352. FFS, doesn't anyone here... by imipak · · Score: 3
    ...read Incidents list?? Check this out. ( http://www.securityfocus.com/templates/archive.pik e?fromthread=1&end=2001-07-21&list=75&mid=198320&s tart=2001-07-15&threads=1& ). It's a proper mathematical analysis of the spread of the worm, by someone who knows what they're talking about (unlike Steve Gibson.) Be afraid. Think about what it would be like if this was an Apache or Sendmail hole.

    Turn a non-tech hobby into your career.
    --

  353. ITS BAAAAAAAACK!!!!~ by baptiste · · Score: 3
    Sure enough - decided I'd start some log traces on my (Apache) servers and watch for anything .ida Sure enough, the scans are starting already, though this looks like a different variant, instead of default.ida, its x.ida?AAAA...

    [baptiste@surfboard httpd]$ tail -f access_log | grep .ida 136.176.193.29 - - [31/Jul/2001:17:10:49 -0400] "GET /x.ida?AAAAAAAAAAAAAAAAAAAAAAA[lame filter snip]AA=X HTTP/1.1" 404 280 136.176.193.29 - - [31/Jul/2001:17:12:42 -0400] "GET /x.ida?AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[l ame filter snip]AA=X HTTP/1.1" 404 280

    Should be an interesting evening. Intersting that I got hit twice from teh same IP a few minutes apart

  354. Or not... [Re:ITS BAAAAAAAACK!!!!~] by baptiste · · Score: 3

    Turns out that this signature is probably from the eEye CodeRed scanner to identify vulnerable hosts. Interesting that they seemed to show up after 5PM from various places.

  355. Prepare for the Stone Age! by LittleGuy · · Score: 3

    If the Internet Ceases, then society will regress to the point when you can only create pr0n from whatever scraps you can find in the dilapidated ruins of New York City.

    --
    Mod Karma -1: I sed bad wurds. If I cep my mouf shut, I wud be at riyses.
  356. Re:Steve Gibson Made this Worse by tb3 · · Score: 3
    Yep, 'journalists' seem to have forgotten how to 'consider the source' and blithely believe everything handed to them. I love the way the Reg trashes Gibson, but I wish somebody in the mainstream would pick up on the other side of the story.

    Along the same lines, am I the only person who has a problem with Cringley? After watching his PBS show about building an airplane in thirty days, I was convinced the guy has more money than brains, and that his infamy is due more to who he knows than what he knows.

    --

    www.lucernesys.comHorizon: Calendar-based personal finance

  357. IIS: Why it is Used, Why it's buggy. by Strangely+Unbiased · · Score: 3

    IIS: It Isn't Secure.

    But no, really I can tell you why IIS is still a choice as a web server, and also I'll tell you why it is so insecure.
    (WARNING: As Always, IMHO).
    IIS is still a choice because:
    a) You can teach virtually anyone to perform simple administration on an IIS server.
    b) You don't need to use a command prompt (no, it doesn't really scare people, they just tend to believe it's such a fuss to make things work.)
    c) It comes with Windows 2000/NT (if you had a choice to 'Run Your Very Own Web Server(R) while running MS Office and games, without having to boot to another OS, what would you think would be better?).The fact that It's There(r), is also extremely important;otherwise, people who had to use a Windows server would use Apache for Win32 instead.
    d) It's a breeze to install and enable (incorrectly of course;there are plenty of configing and patching you can do on IIS to make it safe/er, but no-one seems to bother:'Who whould try to hack ME?')
    e) It means that it'll be easier for you to migrate to .NET later. That one's a very good reason. If the world DOES jump on .NET bandwagon would you like to stay behind( don't think '.NET port to Linux')? Could be very bad for business. On the other hand, if .NET doesn't work out, you can always jump to Apache.

    Now, why IIS is insecure:
    a) Do you remember how long it took Microsoft to realise the Internet was going to be the next big thing? That hurt them. Sure, they did release a web server (their lamest ever --IIS 2.0), but it was behind its time.IIS 4.0 was their first proper attempt, and while it worked, Microsoft had a lot to learn about security. They had to release patches constantly to help the poor early-adopters (nobody new it was going to be so open), which unfortunately, were quite a lot.IIS continued to grow, as it fitted the bill as a method to extend businesses with a Windows/NT infrastructure to the Internet. So, now we have 20% of the Internet, running IIS.
    b) IIS is also insecure because 50% of it's sysadmins are idiots. 50%, not all of them, not none of them. 50% . Now, if you pushed a *nix sysadmin to run IIS (you would have to push real hard though), you would get a web server (being configed and patched correctly) which would totaly evade most (if not all) of the IIS hacking frenzies and DoS attacks of the past 2 years. Including Code Red (the MS patch for that buffer overflow buf was published a few months ago.The wise IIS sysadmins noticed.).
    c) Remember, IIS is young. It's about 6-7 years old, but it wasn't taken seriously since Windows NT 4.0, 4-5 years ago.As with Windows 2000, the time for IIS to become a proper,feasible solution is longer than that. And isn't Apache much older (please enlighten)?
    And how will IIS become secure?
    IIS 6.0 will be the first IIS to be reasonably secure, IMHO of course. Because it will incorporate all the fixes until now (quite a lot, shouldn't they be running out of bugs?) , but most importantly because it will patch itself (that's what I heard anyway).
    Now for your opinion: Will IIS 6.0 be a proper web server? Think about it and don't reject it: There wasn't a single reason to consider it if you were happily running the latest version of Apache, but now there is: .NET.

    Think, think, and then post. And please correct me if I'm wrong.Thank you.

    Oh and some things I'd like to point out, because some people get it wrong:
    a) When you install Windows 2000 OR WinNT 4, it won't install IIS.Not even with full install. You have to install it separately AFTER the OS installation is complete, so people know when it's installed.
    b) The Internet won't cease to exist, and this isn't a conspiracy by Microsoft (probably).

    --


    There is no such thing as 'world peace'.
  358. Mis-set clocks? by Violet+Null · · Score: 3

    Cringely tells us that the true threat is servers with mis-set clocks

    No, Cringely mentions 2,000 IIS servers that are still in "infection" mode because they have misset clocks. The real "problem" is that disassembly of the worm indicates that it might have a monthly cycle, instead of being a one shot wonder; y'know, when the other x00,000 IIS servers join in again.

    1. Re:Mis-set clocks? by RedHat+Rocky · · Score: 5

      My God, I just realized that the worm's creator was obviously a man with an ex-girlfriend. It has a monthly cycle. It spends the 2/3rds of the month putting its nose in where it doesn't belong. It then spends the remaining 1/3 of the month on a complete lashing-out, bitchfest.

      Gads. Couldn't he have just gotten drunk instead?

      --
      Anything is possible given time and money.
    2. Re:Mis-set clocks? by mike260 · · Score: 5

      The real "problem" is that disassembly of the worm indicates that it might have a monthly cycle, instead of being a one shot wonder; y'know, when the other x00,000 IIS servers join in again.

      IIRC, the worm is memory-resident-only and therefore can't survive a reboot. It's not picking up where it left off, it's starting over infecting the internet almost from scratch, so it should be the same thing as last time. Except that this time everyone's forewarned.

      Microsoft knew it all along: It isn't a bug that Windows requires rebooting every few days, it's a security feature.

  359. They seem to be making a real publicity effort by kiwimate · · Score: 3

    I got the following mail from MS yesterday. (The ironic part is I initially was suspicious because the subject line was in all caps -- how rude!)

    The following is a Security Bulletin from the Microsoft Product Security Notification Service.

    Please do not reply to this message, as it was sent from an unattended mailbox.

    -----BEGIN PGP SIGNED MESSAGE-----

    The Microsoft Security Response Center, along with other organizations listed below, is jointly publishing this alert that ALL IIS ADMINISTRATORS ARE ASKED TO READ

    A Very Real and Present Threat to the Internet: July 31 Deadline For Action

    Summary:

    The Code Red Worm and mutations of the worm pose a continued and serious threat to Internet users. Immediate action is required to combat this threat. Users who have deployed software that is vulnerable to the worm (Microsoft IIS Versions 4.0 and 5.0) must install, if they have not done so already, a vital security patch.

    How Big Is The Problem?

    On July 19, the Code Red worm infected more than 250,000 systems in just 9 hours. The worm scans the Internet, identifies vulnerable systems, and infects these systems by installing itself. Each newly installed worm joins all the others causing the rate of scanning to grow rapidly. This uncontrolled growth in scanning directly decreases the speed of the Internet and can cause sporadic but widespread outages among all types of systems. Code Red is likely to start spreading again on July 31st, 2001 8:00 PM EDT and has mutated so that it may be even more dangerous. This spread has the potential to disrupt business and personal use of the Internet for applications such as electronic commerce, email and entertainment.

    Who Must Act?

    Every organization or person who has Windows NT or Windows 2000 systems AND the IIS web server software may be vulnerable. IIS is installed automatically for many applications. If you are not certain, follow the instructions attached to determine whether you are running IIS 4.0 or 5.0. If you are using Windows 95, Windows 98, or Windows Me, there is no action that you need to take in response to this alert.

    What To Do If You Are Vulnerable?

    a. To rid your machine of the current worm, reboot your computer.
    b. To protect your system from re-infection:
    Install Microsoft's patch for the Code Red vulnerability problem:

    - - Windows NT version 4.0:

    http://www.microsoft.com/Downloads/Release.asp?Rel easeID=30833

    - - Windows 2000 Professional, Server and Advanced Server:

    http://www.microsoft.com/Downloads/Release.asp?Rel easeID=30800

    Step-by-step instructions for these actions are posted at

    http://www.microsoft.com/technet/treeview/default. asp? url=/technet/itsolutions/security/topics/codeptch. asp

    Microsoft's description of the patch and its installation, and the vulnerability it addresses is posted at:

    http://www.microsoft.com/technet/treeview/defaul t. asp? url=/technet/security/bulletin/MS01-033.asp

    Because of the importance of this threat, this alert is being made jointly by:

    Microsoft
    The National Infrastructure Protection Center
    Federal Computer Incident Response Center (FedCIRC)
    Information Technology Association of America (ITAA)
    CERT Coordination Center
    SANS Institute
    Internet Security Systems
    Internet Security Alliance


  360. Re:Why all the public hullaballoo by Tim+Doran · · Score: 4

    Talk about FUD - here's a quote, from Scientific American, no less: "Imagine a cold that kills. It spreads rapidly and indiscriminately through droplets in the air, and you think you're absolutely healthy until you begin to sneeze. Your only protection is complete, impossible isolation,"

    WOW! That sounds awful! Run for the hills!

    But wait - imagine that a vaccine for the cold has been available for months. You could get vaccinated just by logging into a website.

    Oh, and once you're infected, all you need to do is take a nap (ie. reboot) and you're healthy again.

    What a load of scare-mongering. SciAm should know better.

  361. From cringely's article by wiredog · · Score: 4
    while there is a solution ... many people will see the cure as being nearly as bad as the disease

    I suspect this is the cure.

  362. Browser feature request by First+Person · · Score: 4

    If any Mozilla developers are listening, I have a request. I'd like a version which displays a visible icon everytime I log onto a IIS server. Then, if I double click the icon, it could list a selection of 'counter measures' such as CodeRed which I might deploy. These might use a plug-in architecture and be downloadable from sites using other browsers.


    Thanks for listening.

    --
    Given one hour to live, the student replied: "I'd spend it with professor FP who can make an hour seem like a lifetime."
  363. Headline Contest? by Dr_Cheeks · · Score: 4
    So what happened with the headline contest from last time Code Red shook it's groove thing all over the net? Did I win (yeah, right)?

    Perhaps this could be a monthly competition. Assuming, of course, that anyone can get through the infection storm to post to it.

    Oh, and I'd like to propose a name for the inevitable next worm that just won't die - The Lazarus Worm. Cool, eh?

    --

  364. Why all the public hullaballoo by Random_Eyes · · Score: 4
    The general public, for the most part can do nothing to stop this. It is sysadmins and those running servers who need to pay attention.

    Why then is this threat suddenly everywhere?

    They're FUDing the Net!

    The logic is simple. Business wants a new manageable internet. First, prove to the world that end-to-end is broken. Then, advance proposals to fix it.

    Waiting for the other shoe to drop. . .

  365. Great marketing ploy by T1girl · · Score: 4

    Can you think of a better marketing ploy to make your soft drink sound hip and edgy and get the name plastered all over the media? This could be even better for free publicity and name recognition than the Verizon strike.

    Vote today for Dilbert's list of Top 869 Things Programmers Are Least Likely To Say.

  366. Re:Worms and market share by rabtech · · Score: 4

    Sorry, but Apache mostly runs on *nix systems... anything from Linux to Solaris to FreeBSD.

    Why don't you try writing a virus or worm that knows enough about each of the various *nix OSes, and the versions of Apache they are running, to infect them all.

    Part of the reason Windows is so widespread is because Windows is stable (in an API sense, and in a reliability sense as far as W2K is concerned), and easy to write for.

    Part of the reason Microsoft has so many hackers and skr1pt k1ddi3s after them is because Windows is so wide spread.
    -- russ

    --
    Natural != (nontoxic || beneficial)
  367. Steve Gibson Made this Worse by cyphon · · Score: 4
    The only reason that the media is style hyping about this is because steve gibson is wailing like a little bitch about things like: Raw sockets, and "Logaritmic Axis Graphs".

    Gimme a break.

    Stevie boy is very insane, but he generates hype, which generates headlines, which makes the media look good. So wake up you government and corperate morons. The world will not come to an end. And steve gibson is not the prophet of the internet world.

    1. Re:Steve Gibson Made this Worse by agallagh42 · · Score: 5

      The Register has a good summary of Gibson's ravings here

      --
      Carpe Cerevisi - Seize the Beer
  368. Worms and market share by jmv · · Score: 5

    It's funny that everytime a Windows worm/virus propagates and (of course) Linux and other UNIX are not affected, it's just because they don't have much market share and nobody bothers writing a virus for an OS like Linux. Now, it's IIS that's being hit. If it were only about market share, Apache would get twice as much virii/worms as IIS, right? Maybe the most important factor after all is the number of security breach in a product and not market share.

  369. Gibson may be extreme, but he does have a point by starseeker · · Score: 5

    While I'd agree that he may be overly paranoid, I do share the opinion that the internet is extremely vulnerable right now, although not necessarily for the reasons he states.

    I am not a professional security expert, but I do know my fellow computer users. They will take convenience over security every time until something Really Bad happens to their system. Then they will pay money to solve the problem, be alert for several months, and gradually relax as the problem doesn't reappear. Their knowledge of security may extend as far as knowing to update Norton Antivirus every once in a while.

    We are fortunate that most virus writers are not the most skilled programmers in the world. Or, perhaps more likely, they have restrained themselves in order to avoid completely destroying their playground.

    Think about this for a minute. It is easy to conceive of ways in which much more damage could be done to the internet than has already been done. If I recall correctly, the ILOVEYOU virus deleted jpgs from hard drives. The worst results I am aware of from this is a commerical image database being wiped out. Now, imagine what would have happened if dlls had been attacked as well. Unbootable computers, applications and system software destroyed beyond repair short of total reinstall, etc. Most Windows machines out there have no file permissions system set up. NT does, but how many DOS based systems are still out there, and still hold critical work?

    The problem with security is not that we don't know what to do. The problem is that so many of us don't do anything. That is what alarms Gibson, and in that he is correct. There are so many machines not being properly managed that damage is inevitable. And all of us are impacted by this in one way or another, unless everyone you deal with has good security. If that is true, you are lucky. For me, it is not.

    Up until now, we have delt mainly with simple scripts whose workings are obvious. However, here is some food for thought. Microsoft's servers are not invulnerable. Like any complex system, there are undoubtedly subtle and potentially dangerous bugs in the Windows code which will be obvious to anyone who can steal the source from the servers. If someone with or even without this code writes a truly powerful virus which attacks hundreds of subtle vulnerabilities simultaniously, knows how to hide the code in the depths of Windows, and destroys any system it can after reproducing itself, we are in deep S**t. Right now, most virus attacks involve the active cooperation of the email system - minimally some end user opening an attachment. So the measure of how widespread a virus becomes is often based on how many suckers read it. This is not, as it turns out, a big problem for the virus - it is easy to come up with email titles people will want to open. But if you remember the worm of 88, it didn't require the end users cooperation at all. What happens when all that is needed for a machine to die is for it to connect to the network unpatched? Imagine the chaos of half a million machines with all their work, programs, and system software gone. Gibson may have a right to be paranoid.

    --
    "I object to doing things that computers can do." -- Olin Shivers, lispers.org
  370. And boy do I love the hysteria. by taliver · · Score: 5
    I got a call.

    At 5:15 AM.

    In the morning.

    From my mother.

    She had just seen the FBI guy on TV and was worried her windows 98 machine would destroy the world over her dialp connection.

    I informed her that this was unlikely, and went back to bed.

    --

    I demand a million helicopters and a DOLLAR!