We have relaunched: What's new at ZDNet Asia?

Code Red slows, but danger still lurks

Summary

The rate of infection from the dreaded Code Red worm and related mutations is slowing, but security experts say some computers may still be at risk.

Events

The 2nd InfoSecurity Summit HK 2010
17 Mar 2010

Hong Kong Convention and Exhibition Centre, Hong Kong

IT Architect Regional Conference Singapore 2010
20 - 21 Apr 2010

Singapore Management University, Singapore

The Internet Show 2010
21-22 Apr 2010

Suntec Singapore

The rate of infection from the dreaded Code Red worm and related mutations is slowing, but security experts say some computers may still be at risk.

The worm had infected servers responsible for more than 280,000 Web sites as of 10 a.m. PDT Thursday, according to security trackers at the SANS Institute. But the number of computers that the worm infects each hour appeared to be declining steadily after an initial burst on Tuesday, according to SANS.

By Thursday morning, the rate of infection had slowed to such an extent that the National Infrastructure Protection Center (NIPC) had issued a news release stating that agents were "cautiously optimistic" about the worm's demise. They said the impact of the worm's second attack on computer servers worldwide "has been minimized."

Despite the worm's seeming sluggishness, virus experts warn that it could still wreak havoc on vulnerable servers. The worm works on a monthly cycle and will not go back into hibernation for several weeks.

As originally reported by CNET News.com, the Code Red worm takes advantage of a hole in Microsoft's Internet Information Server (IIS) Web server software running on Windows NT and Windows 2000 systems. Code Red was thought to have infected as many as 359,000 systems within about six days during its original attack in July, making it one of the fastest-spreading worms ever.

The worm remains active between the first of the month and the 28th, when it goes into hibernation. While the worm does not reactivate itself automatically, any computer vandal sending a copy of the worm once the active period begins--most recently at midnight GMT August 1--would start a new round of infections. On the 20th of the month, the worm is set to switch to attack mode and barrage an Internet address originally associated with the White House Web site with large packets of data.

Experts credited massive downloading of a security patch that fixes the IIS vulnerability for hampering the worm's spread this time. The worm only infects computers running the Windows NT and Windows 2000 operating systems and Microsoft's Internet Information Server (IIS) Web server software, meaning few home PCs are vulnerable to the attack.

"The large number of machines that are now patched (has) changed the playing field, but we still anticipate increasingly rapid growth worldwide in the coming days," according to a statement on the Web site of security services company Internet Security Systems (ISS).

"We anticipate remaining at (high alert) through early August but will watch the situation closely and adjust the threat level accordingly."

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment
Transform your business interactions with real-time voice, video and telepresence solutions.
Tech Vendor: Cisco

ZDNet Asia Live

[TECH] URL Shorteners slow Web redirection. - http://bit.ly/bySnWK @zdnetasia

URL shorteners are great but they can slow web redirection & you pray it would never go down http://bit.ly/bySnWK via @zdnetasia

Indian IT to clock double-digit growth in 2010 - Interview with Som Mittal http://bit.ly/bN6JXY

1 hour 42 minutes ago by nasscom on topsy

RT @zdnetasia: URL shorteners slow Web redirection. http://bit.ly/bySnWK

1 hour 42 minutes ago by stannie on topsy

Temasek Holdings eyeing tech stocks, indicating optimistic outlook on IT sector. http://bit.ly/aM7VwU

URL shorteners slow Web redirection. http://bit.ly/bySnWK

Chinese agencies cry foul over Google. http://bit.ly/by6rwV

Philippine antipiracy drive focuses on enterprises. http://bit.ly/aWryDC

story: Gartner: China to become world's fastest-growing enterprise software market. http://bit.ly/bqJTtb

2 hours 13 minutes ago by yqliauzdnetasia on topsy

all of sg's isps have been practising compulsory invisible proxy for all home subscribers at their backend since many years back alre...

5 hours 8 minutes ago by melvinchia on Web filters mean bad news for business

#Cloud #News Aussie university joins Cisco cloud - Zd Net Asia.com: Australia's Curtin University of Technolog... http://bit.ly/bnsSsA #TCN

7 hours 2 minutes ago by thetechgang on topsy

it is not to good for china.
Proactol

7 hours 53 minutes ago by nathonastle on Chinese ad partners beg Google for information

RT @zdnetasia: HP touts new products and management and productivity tools to address business computing pain points. http://bit.ly/dudgA6

For those with a computer science background, or interested in the high performance computing scene: http://bit.ly/9vFC3i

HP touts new products and management and productivity tools to address business computing pain points. http://bit.ly/dudgA6

** S'pore govt launches traffic Web app. http://www.zdnetasia.com/s-pore-...

the new look site is very nice @zdnetasia @zdnetaustralia

Big up to my peeps at www.ZDNet.com.au (and www.ZDNetasia.com and www.ZDNet.com.uk). Loving the redesign!

McAfee steps up cloud assurance - Zd Net Asia.com
http://www.zdnetasia.com/mcafee-...

Interesting take on social analystics. http://www.zdnetasia.com/blogs/w...

Very good explanation of JMX

1 day 58 minutes ago by Babith B on Managing applications with JMX

The reaction to a report issued Tuesday by Flurry Analytics managed to completely overlook some interesting news--the Android-based Motorola Droid outsold the original iPhone over the same period of time following their respective launches--to focus instead on the sales numbers for the Nexus One.

1 day 2 minutes ago by lonemavericks on diggs

Another ZTE story....

1 day 4 minutes ago by Moderate Your Greed on Philippines opens bid for final 3G license

We at www.fifosys.com have also seen a growth in IT outsourcing and anticipate it as a growing field.

1 day 37 minutes ago by sarah Jane on Companies' outsourcing spend to increase

I agree with you. The iSiVaL is super portable and TVs can't expand their image size. I recorded a video that might bring some ideas to...

1 day 8 minutes ago by Jesse B Andersen on Buying a projector? Try an LED TV instead

hermm... he deserved it.. he shud not talk abt sensitive things like tat, well, he shud think twice before saying all those things, event...

1 day 46 minutes ago by ... on Facebook user charged in Malaysia

Password manager tools are potential security threat. Criminals who hack into the computer can use the password manager to log onto any s...

2 days 46 minutes ago by ohanae on What defaults should random password generators use?

I've found the cross platform utility unetbootin to be rather handy for this kind of thing as well.

2 days 20 minutes ago by Jim on Use Live USB Creator to install Fedora 12 from a USB stick

Thanks for the article. I think the debug command has an "\" after "C:" it should say w32tm /debug /enable /file:C:\l...

2 days 20 minutes ago by Roger Biefer on Manage time accuracy with W32Tm

available in singapore now
http://www.portablemall.com.sg/goods-71-Microsoft+Zune+HD+32GB+-+Platinum.html

2 days 57 minutes ago by steve on Microsoft coy on apps for Zune HD

How about just using http://www.random.org/strings/? It is very configurable, satisfies all of the flexibility requirements you have ment...

2 days 3 minutes ago by Varun V Nair on What defaults should random password generators use?

Wi-Fi as the "Rodney Dangerfield of wireless", is a catchy metaphor, but it's already been used. In fact, it was the title of a...

2 days 2 minutes ago by Martin Suter on Selina Lo: Wired up for Wi-Fi in Asia

Dear Sir/Madam, I am Narasimha Rao.L. From bangalore India , i searching job in abroad , in electronics field, i have 6+ years exp....

3 days 4 minutes ago by Anonymous on Hot tech jobs in Singapore

Good article, computational aspect of acquired knowledge from the social platform is really questionable, given that there are a lot of p...

3 days 10 minutes ago by JN on What will social analytics say about your company?