NEWS MSN has admitted its website was infected by the Code Red virus last week, despite the fact that Microsoft has had a patch available to plug the security vulnerability for over a month. MSN, Microsoft's internet business, said a "small number of servers" were infected by the malicious code on the night of 19 July. This follows Microsoft's own update site being hit by the bug earlier the same day. A Microsoft spokeswoman said all affected servers have been removed from service and it is conducting a full investigation. It was unable to say exactly how many servers were affected but insisted the attack did not affect the MSN service or any Microsoft customers. The Code Red worm attacks a vulnerability in Microsoft web servers called internet information servers, or IISs. This leads websites to display the messages http://www.worm.com and "Hacked by Chinese!". The worm then randomly generates an IP address from a pre-set list of domains and propagates itself to other web servers. By Friday, an estimated 225,000 servers had been affected, leading some to describe the worm as the most damaging web server virus ever. Microsoft first published a patch for the vulnerability on 18 June. However, it appears MSN didn't take its own medicine and allowed the holes to go unplugged. Spokespeople for MSN and Microsoft today were unable to explain why servers hadn't been updated with the patch. Microsoft said "operational procedures were being reviewed in the light of a full investigation". A full patch to plug the flaw is available at http://www.microsoft.com/technet/ That's presuming, of course, the site is still up.
Microsoft red-faced over sloppy security
We have a patch, we simply choose not to use it...
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Keeping flash drives secure with biometric authentication
People and organisations hand over their most valuable and vital personal information to government agencies. It is...
-
Detection systems guard against network intrusion
How do the different types of intrusion prevention system (IPS) work? Inline systems sit on the network like layer-two...
-
How malware threats have changed
These days, cybercriminals have four core weapons: targeted attacks, infecting websites, social networking and mobile...
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters




