TT (Mk1) Discussion Discussion forum for the Mk1 Audi TT Coupe & Roadster produced from 2000-2006

OT: Code Red Worm....

Thread Tools
 
Search this Thread
 
Old Jul 19, 2001 | 08:20 PM
  #1  
geiswiz's Avatar
Thread Starter
Junior Member
 
Joined: Dec 2000
Posts: 684
Likes: 0
Default OT: Code Red Worm....

Here's some info on this that I just got, looks like it could be pretty serious. Only affects WinNT and 2K boxes running IIS without MS01-033 patch applied:

This should be interesting.....

-----Original Message-----

Thanks to Eric from Symantec for tossing us a note about the worm being
Date
based and not Time based.

We made an error in our last analysis and said the worm would start
attacking whitehouse.gov based on a certain time. In reality its based
on a
date (the 20th UTC) which is tomorrow.

If the worm infects your system between the 1st and the 19th it will
attempt
to deface the infected servers web page or try to propogate itself to
other
systems. On the 20th all infected threads will attempt to attack
www.whitehouse.gov. This seems to continue until the worm is removed
from
the infected system.

Any new infection that happens between the 20th and 28th will most
likely be
someone "hand infecting" your system as all other worms should be
attacking
whitehouse.gov. If for some reason you are infected between the 20th and
the
28th then the worm will begin attacking whitehouse.gov without trying to
infect other systems. This attack will continue indefinitly.

The following are rough numbers, but we felt that it was important to
illustrate the affects this worm can _possibly_ have.

The worm has a timeline like this:

day of the month:
1-19: infect other hosts using the worm
20-27: attack whitehouse.gov forever
28-end of month: eternal sleep

Presumably, this could restart at any point in a new month again.

Also, some stats for the attack:

Each infection has 100 threads
Each thread is going to send about 100k, a byte at a time, which means
you
have a (40 for ip + 1 for each byte) which means you have 4.1 megs of
data
per thread
100 threads * 4.1megs = 410 Megabytes
This will be repeated again every 4.5 hours or so

Remember, each host can be infected multiple times, meaning that a
single
host can send 410MB * # of infections.

We have had reports between 15 thousand and 196 thousand unique hosts
infected with the "Code Red" worm. However, there has been cross
infection
and we have heard reports of at least 300+ thousand infections/instances
(machines with multiple infections etc..) of this worm.

If there are 300 thousand infections then that means you have (300,000 *
410
megabytes) that is going to be attempted to be flooded against
whitehouse.gov every 4 and a half hours. If this is true and the worm
"works
as advertised" then the fact that whitehouse.gov goes offline is only
the
begining of what _can_ possibly happen...

----

I am actually writing this part of the eMail about 45 minutes after the
first part because our Internet connection here in california has been
going
up and down. We have also heard reports of internet connectivity going
down
in parts of northern california and new york.
Reply
Old Jul 19, 2001 | 08:50 PM
  #2  
Bracketracer's Avatar
AudiWorld Super User
 
Joined: Mar 2000
Posts: 15,505
Likes: 1
Default

Damn....and I thought the GRC DoS story was wild.....this is unreal
Reply
Old Jul 19, 2001 | 08:56 PM
  #3  
NexxTT's Avatar
Senior Member
 
Joined: May 2000
Posts: 6,178
Likes: 0
Default

TTN's server was choked today by a "chinese" worm....same?
Reply
Old Jul 19, 2001 | 09:08 PM
  #4  
OzChris's Avatar
Junior Member
 
Joined: Jul 2000
Posts: 984
Likes: 0
Default This is the info. I received on the worm this morning.

<ul><li><a href="http://it.mycareer.com.au/breaking/2001/07/20/FFXJM0IUCPC.html">http://it.mycareer.com.au/breaking/2001/07/20/FFXJM0IUCPC.html</a</li></ul>
Reply
Old Jul 20, 2001 | 06:17 AM
  #5  
Gnowknayme's Avatar
AudiWorld Super User
 
Joined: May 2000
Posts: 4,514
Likes: 0
Default I think we were getting hit by that yesterday.

I've got tons of hits in all of our logs that match the worm (GET /default.ida?NNNNNNNN.... or something like that) and they started right about the same time one of our NT web servers just started shutting down for no apparent reason. The machine would stay up, but IIS would just stop all the web and FTP servers so I would have to start them all back up again. Rebooted a few times and it still kept on doing it. After looking around for a while, I figured out that was the one server that apparently got skipped when I was applying patches last time...Oops. Patch applied, reboot, no more problems.

Supposedly, the worm does some sort of defacement after it has been installed for 2 hours, so luckily, I got the machine patched and rebooted before that happened. BTW, if you have a Windows 2000 server running IIS 5, you can download an application from MS that will check for hotfixes periodically...I highly recommend it. If you need more info on that, just ask and I can probably track it down.
Reply
Old Jul 20, 2001 | 06:20 AM
  #6  
225TTR's Avatar
Senior Member
 
Joined: Apr 2000
Posts: 9,428
Likes: 0
Default

Sounds like it from the story in the Washington Post this morning.
Reply
Old Jul 20, 2001 | 07:16 AM
  #7  
EloqnTT's Avatar
AudiWorld Member
 
Joined: Aug 2000
Posts: 506
Likes: 0
Default Mostly affecting ISPs and backbone providers...

the worm is also IP address-based. whitehouse.gov changed its IP address, and some major backbone providers filtered the old IP addresses. My ISP had been hit by 33,000 distinct infected hosts as of yesterday afternoon, but since they're not MS-based, no infection occurred at the ISP.
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
MADD2.0T
Rocky Mountain Discussion
2
Jul 11, 2007 03:53 PM
Jon G
A4 (B5 Platform) Discussion
4
Apr 3, 2002 05:06 AM
225TTR
TT (Mk1) Discussion
6
Jul 30, 2001 01:27 PM
got_root?
A4 (B5 Platform) Discussion
1
Jul 20, 2001 01:26 AM




All times are GMT -8. The time now is 03:08 AM.

story-0
10 Strangest Audi Designs That Actually Made Production

Slideshow: 10 strangest Audi designs that actually made production

By Joe Kucinski | 2026-06-10 16:32:29


VIEW MORE
story-1
2027 Audi Q7 and SQ7: Audi Upgraded EVERYTHING!

Slideshow: Everything you need to know about the 2027 Audi Q7 and SQ7

By Michael S. Palmer | 2026-06-09 06:02:56


VIEW MORE
story-2
Audi Unveils Absurdly Cool New Supercar: 10 Things You Need to Know!

Slideshow: Limited to just 499 units, the 987-horsepower halo car signals a new chapter for Audi performance.

By Verdad Gallardo | 2026-06-04 17:37:15


VIEW MORE
story-3
The Highs & Lows of Every Audi C-Class Generation

Slideshow: The highs and lows of every Audi C-Class generation.

By Joe Kucinski | 2026-05-27 16:05:50


VIEW MORE
story-4
Top 10 Most Expensive Audis Ever Sold on Bring-A-Trailer

People were more than happy to shell out big bucks for these cars.

By Brett Foote | 2026-05-27 15:32:23


VIEW MORE
story-5
10 Audi Features & Options We Miss the Most!

Slideshow: 10 Audi features and options we miss the most.

By Joe Kucinski | 2026-05-12 19:33:47


VIEW MORE
story-6
Audi Recreates Crazy-Looking Speed Record Breaker From 1935

Slideshow: Audi has recreated one of the wildest machines of the pre-war speed-record era, reviving a streamlined V16 racer that originally exceeded 200 mph in 1935.

By Verdad Gallardo | 2026-05-11 09:49:34


VIEW MORE
story-7
Coachbuilder Recreates the 1995 Audi TTS Concept

Slideshow: A Dutch coachbuilder has reimagined the original Audi TT by finishing what the 1995 concept only hinted at.

By Verdad Gallardo | 2026-05-05 15:17:58


VIEW MORE
story-8
Every Audi V10 Car Ranked!

Slideshow: Ranking every Audi V10 road car

By Joe Kucinski | 2026-04-29 16:11:56


VIEW MORE
story-9
9 Audi Designs That Aged Like Fine Wine

Slideshow: A look back at the Audis that didn't just survive changing tastes, they quietly outgrew them.

By Verdad Gallardo | 2026-04-28 19:38:27


VIEW MORE