How big is the Code Red thing gonna be???

Jittles

Golden Member
Apr 17, 2001
1,341
1
0
I went home for lunch and on some channel, I think CNN or CNBC or something, has a countdown clock going for it and it is like totally live coverage for it! I didn't think it was that big!
 

Viper GTS

Lifer
Oct 13, 1999
38,107
433
136
It was pretty big last time, we were beyond swamped. 2.5 hour hold time at one point.

It sucked ass.

Viper GTS
 

Scrapster

Diamond Member
Nov 27, 2000
3,746
0
0
Bring it on!!!!!!!!!!!!!!!!!

I've got my canned food stockpile and a basement that has lived through 3 nuclear explosions and a flood.

Bring on the commies!
 

Paulson

Elite Member
Feb 27, 2001
10,689
0
0
www.ifixidevices.com
I got my patch and am not worried.

But still, if people can't take the time to update their servers, it's their own damn fault. They've known about this now and should know about it. If you're in charge of a webserver, you have to keep up to date on security and other flaws that are out there that can ruin a server in a moments notice.
 

konichiwa

Lifer
Oct 9, 1999
15,077
2
0
I'm with Paulson on this one. The fix for this worm is not a hard one, and neither is the patch. With all the national media coverage on this, sysadmins should be aware of this and should be patching up their systems.

But there's always a fair share of stupid admins out there, so I predict we're gonna have quite a backlash tonight. Not as bad as last time, though.
 

Viper GTS

Lifer
Oct 13, 1999
38,107
433
136
In my case we get flooded due to the worm causing buffer under/overruns in the Cisco 67x routers. Power cycling them will clear the problem, but they're still sitting there waiting to be attacked again which was happening in a matter of minutes. So hundreds & hundreds of people were calling us with routers that would lock up every 5 minutes.

Viper GTS
 

Jittles

Golden Member
Apr 17, 2001
1,341
1
0
When I was home an hour ago it was at around 3:30 so I'm estimating about 2 and a half hours.
 

Beowolf

Senior member
May 22, 2001
212
0
0
it should help show how stupid some people are for not taking care of potential problems, but they deserve it if they didn't.
 

Viper GTS

Lifer
Oct 13, 1999
38,107
433
136
I'm off in an hour and a half. & I still have both of my 15 minute breaks left.

:D

I'll be leaving on time, I'm not sticking around to witness the carnage.

What really cracked me up is the stupid bitch who called sales to say she wanted us to pay for the tech she called out to "fix" her PCs because we "knew about it ahead of time & didn't warn (her)."

Viper GTS
 

Tripleshot

Elite Member
Jan 29, 2000
7,218
1
0
If it messes with my internet surfing habits,no big loss. I will just play some more Seriuos Sam or Max Payne with my grandchildren and children. There is much more to do than wait for some skript kiddies to have their 15 minutes of fame.

BTW,I would vote in a new york second for prosecution and manadatory sentencing of 20 to life for anyone on the globe who uses the web for malicious purposes like this. I say global because it is an international community. Send in the UN troops! :|
 

ToBeMe

Diamond Member
Jun 21, 2000
5,711
0
0
Its BAAACK! Sure enough - have log scans going on my web servers and I've already been probed by an ida worm from 3 different hosts. Looks different than the original 2 versions. Old versions were default.ida?NNN

New version is x.ida?AAAAA

136.176.193.29 - - [31/Jul/2001:16:57:45 -0400] "GET /x.ida?AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=X HTTP/1.1" 404 280 "-" "-"
136.176.193.29 - - [31/Jul/2001:16:59:39 -0400] "GET /x.ida?AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=X HTTP/1.1" 404 280 "-" "-"

Should be interesting to see what this sucker is trying to do.....

 

Fearlss1

Golden Member
Dec 28, 2000
1,044
0
0
Ok someone explain this whole thing to me. I have been in the process of moving I have missed it all.. How do you get it... I am currently running w2k and I am behind a link sys firewall with 3 other w2k machines..
Does this coem in the form of email what..
Is there any preventions I can make.. This is not a business,. this is all home use gaming systems
-=\nate
 

Emulex

Diamond Member
Jan 28, 2001
9,759
1
71
it comes in using an old buffer overflow which affects IIS servers, specifically those with indexing service enabled as well.

If you block everything from the net , you have no worries. If you run an IIS server publicly, and you are not smart enough to keep up with windows security patches, you are probably already infected, or will be shortly.

These are some really old holes, unfortunately, i see some colo's that are still running sp4 :)

 

Telemonius

Senior member
Jul 5, 2001
318
0
0
i think pepsi should pay the creator of the virus a large sum of money for all of the free advertising they've created for them.
 

Viper GTS

Lifer
Oct 13, 1999
38,107
433
136
It was named after the new Mt. Dew flavor, due to it's role in the dissection of the worm.

Viper GTS
 

Telemonius

Senior member
Jul 5, 2001
318
0
0
On Monday, several programmers at eEye began analyzing the code, working through the night on adrenalin fed by large amounts of "Code Red"-branded Mountain Dew, a highly caffeinated soft drink that has become a staple among the code warriors of Silicon Valley. The group dubbed the worm code red in honor of the drink and in wry political reference to the worm's habit of defacing Web sites with pages that read "Hacked by Chinese!"

hmmm...i wasn't aware of that. i figured it was used as a spin-off on communism.

so in other news, is that drink any good?
 

worth

Platinum Member
Feb 4, 2001
2,369
0
0
It looks good, but it really sucks. It's pretty much soda with Red #5, and that fake artificial cherry flavor that you get in Pickled Cherries. I'd rather have a Diet Coke or Diet Dr. Pepper (diet, since the normal ones have way too much sugar, doesn't quench thirst).
 

Fearlss1

Golden Member
Dec 28, 2000
1,044
0
0
Thnx for all the helpful info..
so I dotn guess i have anything to worry about..
-=\nate