Slashdot Mirror


Hotmail Servers Shut Down by Code Red

An Anonymous Coward writes: "SF Gate has this story about Code Red taking down some of Microsoft's Hotmail servers. That's funny." So is Code Red a problem yet? Meanwhile my sircams have stopped, except for 2 people who mail me a hundred or more a day. Thank god for filters, but if I had a monthly bandwidth cap, I'd be pissed.

29 of 460 comments (clear)

  1. This reminds me of Dilbert by balls001 · · Score: 4, Funny

    Did anyone read the Dilbert comic where MS had mis-spelled a word in MS Word? I can imagine the Admin(s) in question to be put into a similar situation

    MS Admin: We got the virus we've been teaching people to prevent.
    Bill: Great, so what are you going to do about it?
    MS Admin: Kill myself as an example to others?
    Bill: .. At our Comdex booth

  2. I'm incredulous by wirefarm · · Score: 5, Interesting

    I find it amazing that they didn't take every precaution to protect what might be their highest-profile property. If MSDN went down, they could cover it - Most of their other servers, too. But Hotmail? That's so closely associated with Passport and, by association, dot-net, that I think they would do absolutely everything in their power to keep it spotless in the minds of the users.
    Good luck to them. They'll need it.
    I got two unsolicited calls asking how to set up Apache on a Windows 2000 server. These were people who had never seen a need to switch before. If I convert their servers for them, I'll probably set up a Linux box or two, 'just for backup purposes'.
    Heh heh.
    Cheers,
    Jim in Tokyo

    --
    -- My Weblog.
  3. Definitive answer to Hotmail front-end OS by doctor_oktagon · · Score: 4, Insightful

    I just queried Netcraft What's That Site Running and it answers:

    The site www.hotmail.com is running Microsoft-IIS/5.0 on Windows 2000

    I also tried the SSL Port 443 and it's also hosted on IIS5/Win2K. Hope this clears up any confusion *grin*

    One thing to consider here folks: this is a classic case of Security Process falling down. It just so happens it's an Win2K hole in this instance. If Hotmail still ran BSD and there was a root exploit discovered, someone still needs to follow the process and plug the hole.

    NB: I'm not excusing MS here ... I'm laughing as much as everyone!

  4. Here's a great plan by BillyGoatThree · · Score: 5, Funny

    Make a modified version of CodeRed called, say, CodeNap. Include in the payload an MP3 by Metallica. Wait 48 hours until it's everywhere. Now sue Microsoft because they are making money of a system that is being used to make illegal copies of copyrighted works!

    --
    324006
  5. BSD by Crewd · · Score: 5, Informative

    I bet Microsoft is wishing they left those hotmail servers on BSD. If I remember correctly, they started moving from BSD to Windows 2000 just about this time last year...of course that was after an unsuccessful try in about the 97/98 time frame....

    Crewd

    1. Re:BSD by bmajik · · Score: 4, Informative

      No.

      The "back end" is a bunch of Sun E4500's.

      The vast majority of freebsd machines are now running w2k.

      --
      My opinions are my own, and do not necessarily represent those of my employer.
    2. Re:BSD by Balinares · · Score: 4, Interesting
      I bet Microsoft is wishing they left those hotmail servers on BSD.

      The sad part is, they probably don't. More likely, they're wishing it was illegal to be a programmer outside a regular, certified company. That way, those damn hackers couldn't exist, and only companies would produce software, for the only good reason there is to produce software, money.

      And the worse is, I'm barely being satirical here. It's really what they corporate culture seems to promote, as has been proved too many times... Maybe I'm just being an overreacting idiot, but they've given me that impression so many times...
      --

      -- B.
      This sig does in fact not have the property it claims not to have.
  6. Probably... by briggsb · · Score: 5, Funny

    Microsoft is using a Beta version of the new IIS software for their hotmail servers that come with the worm already bundled with it.

    1. Re:Probably... by Waffle+Iron · · Score: 5, Funny
      Microsoft is using a Beta version of the new IIS software for their hotmail servers that come with the worm already bundled with it.

      This is another monopolistic outrage!!! Just where will the bundling stop? Now Bill Gates wants to take away the livelyhoods of the virus witers! Is anybody safe?

  7. Windows NT servers by tringstad · · Score: 5, Informative

    I submitted this as an article this morning, but as it is still pending, and both my home and work servers are still under constant annoyance, I figured I'd pass it on here as well. If you are running a Windows NT server, kindly do us all a favor and just turn it off for a few months.

    According to yesterday's Handler's Diary on www.incidents.org, "Microsoft has confirmed that if an IIS 4.0 webserver is using URL redirection, it is still vulnerable to Code Red even if the Microsoft patch is installed". The only known solution is to remove all URL redirections from NT servers running IIS 4.0.

    -Tommy

    --
    "I got a half gallon of Jack, and 2 dozen Ant Traps. I'm about to get wild." -me
  8. Great way to spread sotfware. by Lussarn · · Score: 4, Funny

    Can anyone write a new napster using this "protocol". Then we just have to set up NT servers and wait for the files to arive. First it spread itself to any boxes on the net then start transfering files on off Your HD. Everyday when you come home from work you got 2gb of fresh pron. Should keep you busy for the rest of the evening.

  9. Re:Hotmail running Windows again? by Jucius+Maximus · · Score: 4, Informative
    "I thought Hotmail was not running Windows. Correct me if I am wrong, but I thought it was running Solaris."

    Back when MS bought out Hotmail, they were running on BSD software (Apache, I think,) and then a lot of people started to make fund of them because they didn't even use their own software on their own servers.

    So they moved it over to an MS platform. According to my scanner, it's running IIS 5.0.

    [64.4.53.7:80] World Wide Web HTTP
    HTTP/1.1 302 Redirected..Server: Microsoft-IIS/5.0..Date: Thu, 09 Aug 2001 14:48:33 GMT..Location: http://lc2.law5.hotmail.passport.com

  10. Re:Microsoft to be the target of (more) lawsuits? by Shotgun · · Score: 4, Interesting

    Except that the EULA, any EULA, is absolute and total bullshit, except in Maryland and Virginia(?) who think UCITA makes sense.

    You can't make addendums to a contract after the sale without agreement from both sides. Clicking a button or hitting a key does not constitute proof of agreement. That requires a signature. Please help spread the news that EULA's are bullshit until they are upheld in a court of law or supported by legislation. At the present, they are just some grandstanding bullshit from rich software companies with nothing more than threats from lawyers standing behind them.

    BTW, did I mention that EULAs are BULLSHIT mumbo-jumbo legalese that don't have the force of spit.

    --
    Aah, change is good. -- Rafiki
    Yeah, but it ain't easy. -- Simba
  11. All part of the new design by Nick+Number · · Score: 5, Funny

    MSN Hotmail has a new look!
    MSN Hotmail has a brand new face...and it's easier to use. You'll find it easier to create and manage your folders, see which of your Messenger buddies has been hacked by chinese, and quickly choose names from your Address Book when send document for to ask advice.

    --
    Promote proofreading. Don't mod up sloppy posts.
  12. Re:Microsoft to be the target of (more) lawsuits? by slimme · · Score: 4, Insightful

    Who has losses that arise from code red?

    ISP's and individuals/companies paying for bandwith used.

    Who causes this mess?

    People who haven't patched their software (gross negligence).

    Who can sue who?

    People who have losses because of gross negligence.

    Micorosoft is shielded by a EULA that limits (or denies)liability (although this EULA might not be fully apllicable worldwide).

  13. Microsoft to be the target of (more) lawsuits? by DG · · Score: 5, Insightful

    Back in the Dark Ages of corporate acceptance of Free Software (circa '97 or so) a common pointy-haired manager complaint was "Who do we sue?"

    IE, if the software contained some fatal flaw that resulted in Actual Money being lost, the corporation could go after a commercial software house in the courts in an attempt to recover costs.

    Free Software, being provided as a community service with no sue-able corporation behind it, lacked this perceived accountability.

    Well, here we have a gold-plated example of a fatal flaw in a piece of commercial software, coupled to a lax attitude towards fixing it, that has without question resulted in the loss of Actual Money by a great deal of people. One would think then, that IS Managers across the world would be queuing up to sue Microsoft and recover their costs.

    Anybody seeing any evidence of this happening?

    --
    Want to learn about race cars? Read my Book
  14. Not just MS Hotmail server with the bug by jmoo · · Score: 5, Informative

    I work for a small company that handles license production for a number of the software companies, most of the stuff for OEMs - one of them is Microsoft. (You know that little piece of paper with the cool hologram and bunch of numbers? We make them)

    Now Microsoft is very critical about who gets access to the serial numbers and databases. They have there own servers, VLAN, and firewall at our plants for distribution of licenses. Think it would be pretty secure, right?

    Well not really, they all got Code Red when it first came out. Now we were cleaning Code Red up on our own webserver (Yeah, I know, should have patched) Noticed that the MS server were infected, called up MS and told them what was up. They didn't believe us and told us the servers were already patched. Took a number of calls and yelling to get their boxes fixed.

    I don't know if its really funny or really sad.

    --
    The world isn't run by weapons anymore, or energy, or money. It's run by little ones and zeroes, little bits of data.
  15. Irony? by rnturn · · Score: 4, Interesting

    And this the company whose software that the vast majority of ISPs insist that you use if you want to connect to the internet using their lines.

    I think I'll have some new ammunition the next time I get into an argument with an ISP over what software I'm allowed to run.

    --
    CUR ALLOC 20195.....5804M
  16. "Just patch your servers" by Havokmon · · Score: 5, Funny
    Wasn't it Craig Mundie who said that, in refrence to WHOSE problem the virus was?

    (twas a ZDNet story I can't seem to locate)

    --
    "I can't give you a brain, so I'll give you a diploma" - The Great Oz (blatently stolen sig)
  17. Load Balanced by waldoj · · Score: 4, Interesting

    We discussed this one year ago this week. It was concluded that they were running a round-robin DNS, and you'd sometimes get Apache (~20% of the time) and sometimes get IIS 5.0 (~80% of the time.) To run your own experiment, try the script that I included at the time.

    #!/bin/bash
    i=1
    while [ "$i" -lt 253 ]
    do
    lynx -head -dump http://lw7fd.law7.hotmail.msn.com/ |grep Server >> /var/tmp/hotmail
    let i="$i"+1
    done


    -Waldo

  18. I think you meant: by flimflam · · Score: 5, Funny

    GET /default.ida?heheheheheheheheheheheh.....heheheh.m uahahahahahahahahaaaaaaaaaaaaaaaaaaaahahahahaHAHAH AHAHAHAAAAAAAAAAAAAAAAAAAAa%u9090%u6858%ucbd3%u780 1%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801% u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0 078%u0000%u00=a HTTP/1.0

    ;-)

    --
    -- It only takes 20 minutes for a liberal to become a conservative thanks to our new outpatient surgical procedure!
  19. Okay so... by UberOogie · · Score: 5, Funny

    ...Code Red is taking down Hotmail so that people can't get to their accounts that are filled up with SirCam?

    --
    "Enough of this wretched, whining monkey life." -- Marcus Aurelius, _Meditations_, Book 9, 37
    1. Re:Okay so... by cworley · · Score: 5, Informative

      >people can't get to their accounts that are filled up with SirCam

      I was out of town for a week (two weeks ago), when I returned, the Hotmail Janitor had deleted all my saved mail in all my folders, and all I had left was that weeks spam/sircam.

      In complaining to Hotmail support, they replied, to my Hotmail account, asking what the name of my Hotmail account was. I'm not joking -- they're that stupid.

      In further correspondence, they have said that they can't recover anything deleted by their "auto janitor".

      They have said that Hotmail should not be trusted to store valuable mail (and that I should use outlook instead -- the damn software responsible for SirCam in the first place).

      They think this is my problem, and I should upgrade my anti-virus software (I've repeatedly assured them that I've been WinDoh's free for four years -- I can't find McAfee's Linux download site).

      They say their anti-virus protection is sufficient -- yet I rec'd two more SirCam laced spams today. They won't let me download the contents (even though it won't hurt my Linux system).

      I've told them that their anti-virus protection kicks in too late -- they need to not stick any email into the Inbox that has the SirCam virus (they don't let you download the attachment anyway -- why bother letting it fill up your quota).

      I've told them they should shut down their Janitor and make backups until this problem is resolved, or more Hotmail customer's are going to get their accounts wiped out without backup.

      I've also told them that the correct solution is to bounce new incoming emails headed for an over-quota user, rather than allowing the incoming email and deleting the existing, saved, mail.

      They don't get it. They don't understand.

      And, if any Microsoft troll cares to say I'm a liar about this (like they did the last time I reported this in Slashdot)... I have the email transcripts to proove that this is Hotmail's behavior.

      I have found two solutions:

      www.mail.com
      www.graffiti.net

      Both provide free email excellent (and web hosting) service, and are smart enough to not run Microsoft products.

      --
      When I die, please cast my ashes upon Bill Gates -- for once, make him clean up after me!
  20. .Net by Marcus+Erroneous · · Score: 5, Funny

    Sign me up for Hailstorm right now! Do you need my credit card number now or later? When do you want my ssn, drivers license, home address and other personal information? Boy, I sure am glad I've got a big responsible company to handle my sensitive data instead of a bunch of foreign nobodies. If MicroSoft can't protect my information, who can we trust? ;)

    --
    You must be the change you wish to see in the world - Ghandi
  21. I dunno! by pallex · · Score: 5, Funny

    "Sucks to be them"

    I can think of worse jobs than being paid by Microsoft to watch their servers being brought down by their own software!

  22. What the hell. by scott1853 · · Score: 5, Interesting

    Ok, I know it's a lot of servers, but the company that runs Hotmail, also wrote the OS that is insecure. This company release a warning, what, like 6 months ago, and also released a patch at the same time. They have been claiming that this is a major security hole since then and strongly encourages everybody to install the patch, yet they themselves don't.

    Somehow, when I picture a server farm, I see this clean, organized room with nice neat racks. With everything that happens with MS's servers, all I can envision is a building reminiscent of a level from Diablo. Something dark & gloomy with servers just sitting on workbenches with their hard drives just hanging out of the side of the case and the motherboard coated in 1/2" of dust.

    How can you forget a bunch of servers. I work for a small ISP so we're not the most organized place, but hell, all we have is two racks for modems & routers, and a dozen boxes sitting on the floor for servers. But we at least have pieces of paper tacked to the wall with a list of IP addresses, server names, functions and OS. We install the patches on all of our machines just fine.

    All you need is a list of all the servers. Then take that list around with you and after you install the patch, put a little "X" next to the server on the list. Not really complex guys. Of course this is Microsoft, they're probably running little handhelds with WinCE, connecting wirelessly to a MSSQL server that seems to simply misplace records for the hell of it.

  23. code red, sircam, taco, and real business by Anonymous Coward · · Score: 4, Informative

    first off, cmdrtaco, please keep moaning about getting too much mail all the time from these viruses. it really adds to the discussion to hear every 5 posts or so, 'wah, i am getting megs of virus mail.' okay, we get it. but... what is really weird is the reaction of 'real businesses' to these viruses. IBM for one (and this is why i'm posting anonymously...) SHUT DOWN their entire internal access to all port 80 traffic to stop the spread of code red -- this is a big deal, as this is affecting entire companies' modes of operation and costing millions in lost productivity (no access to even internal web docs, let alone external web resources, etc).

  24. Re:Why not serve your own? by alexburke · · Score: 4, Funny

    Is it true that I can get my FREE download of MSN Explorer at http://explorer.msn.com/intl.asp?

    Nope, but you can at:

    http://explorer.msn.com/default.ida?NNNNNNNNNNNN NN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNN%u9090%u6858%ucbd3%u7801%u9090%u6858%ucb d3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190 %u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a

  25. Re:What the hell, The patch doesn't work by Whiplash42 · · Score: 4, Funny

    Actually, the MS provided patch doesn't work against Code Red if you have URL forwarding on your server. I bet they have it enabled, and so they were left open...