Code Blue strikes

Of course it is something to do with Code Red...

By Joey Gardiner, 12 September 2001 17:30

NEWS A new internet worm, called Code Blue, is infecting Chinese and Australian servers fast with a payload set to deliver a denial of service attack against targets in China. In what could be a perverse attempt at retribution for Code Red, thought to be the work of Chinese virus writers, the worm infects servers already hit by Code Red and eradicates both the worm and the vulnerability. However, according to security firm Kaspersky Labs it then reproduces itself 100 times - to servers infected and non-infected by Code Red alike - with the ultimate aim of producing a DDoS on the website of Chinese security firm Network Security Focus. The worm exploits a well-known security flaw in Microsoft's IIS web server software for which a patch has been available for a year. According to security testing firm VIGILANTe, the rapidity of the virus's spread in Asia shows how many firms have failed to heed expert advice. A patch for the vulnerability is available here: http://www.microsoft.com/technet/treeview/default.asp?url=/technet/Security/Bulletin/ms00-078.asp

Post your comment

In order to post a comment you need to be registered and logged in.

Log in or create your silicon.com account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ