Code Red hits DSL routers, cable-modem networks

By Ellen Messmer, Network World Fusion |  Security Add a new comment

The Code Red worm in all its variants continues its destructive spread, not only worming its way into hundreds of thousands of Microsoft Corp. Web servers, but also having a newly noticed impact on a broad range of Cisco Systems Inc. equipment, including DSL (digital subscriber line) routers within the Qwest Communications International Inc. network.

In addition, cable Internet providers, including Time Warner Cable Inc., AT&T Broadband Inc., Cox Communications Inc. and Excite@Home Inc., have experienced network slowdowns as the new, rewritten version of Code Red discovered last weekend continues to spread.

Cox spokeswoman Laura Oberhelman said: "We're monitoring the network for Code Red. Because of the high volume of traffic that the Code Red worm generates, we are having a traffic slowdown, particularly with e-mail."

When Cox technical staff identifies an infected Microsoft Web server on the Cox Internet cable service, the Cox personnel contacts the subscriber in order to temporarily disconnect them from the Cox network and assist the subscriber in eliminating the Code Red worm from the infected machine.

Cox would not say exactly how many of its subscribers were affected in this way, but said it was only a small percentage.

Dubbed Code Red II, the new computer worm, which includes a dangerous backdoor Trojan, has bogged down their networks by infecting Internet-connected machines where the Microsoft Web server is running.

Many enterprises were thrown into disarray this week by Code Red II.

The global news agency Associated Press found its Internet communications curtailed a few days last week as its IT staff "scrubbed clean" the array of Microsoft IIS Web servers used internally and for news distribution, said spokesman Jack Stokes. Code Red II delayed updates on AP's Web site and affected a photo service used by smaller newspapers. Unaffected were AP's satellite communications.

Motorola found Code Red II invading its global corporate intranet, forcing the company to shut it down to disinfect its Microsoft Web servers. Motorola employees switched to fax, phone and pager in place of e-mail.

Ironically, Microsoft's own MSN Hotmail servers were infected by the Code Red II worm because Microsoft had failed to patch its own servers.

Time-Warner's RoadRunner service issued an advisory to its customers this week, acknowledging that customers "may experience slow network response, flashing connectivity lights on the cable modem, and other activity, such as unusual port scan log activity or increased firewall activity." Time-Warner urged its customers to install the software patch Microsoft has made available to prevent Code Red from infecting Microsoft Windows NT or the Microsoft Windows operating system.

Other cable services also had problems.

"The day before yesterday, I couldn't even use my cable-modem service, AT&T Broadband," said Dennis Treece, director of the special operations group at vendor Internet Security Systems (ISS). As Code Red II worms its way into Web servers on the cable networks, it's having a particularly strong impact because the second version of Code Red "favors the neighborhood," says Treece.

The first version of Code Red, spotted in July, used a randomizer that looked for IP (Internet Protocol) addresses in a random way, often searching for addresses that weren't actually available. Code Red II scans more efficiently for IP blocks, which is probably the reason the cable-modem networks are becoming clogged.

The second version of Code Red also includes a dangerous back-door Trojan that can be used to totally commandeer a victim's machine.

The analysis ISS has done on Code Red II leads the company to believe that Code Red II may turn itself off in October. But if machine clocks in Microsoft Web servers are incorrectly set, the worm may re-awaken, as was the case with the earlier versions of Code Red.

As Code Red in its approximately four variations has spread, it has also impacted Qwest DSL customers, which saw their Cisco DSL routers knocked off-line.

The DSL routers appear to be have been knocked off-line due to a large Internet Control Messaging Protocol echo ping that can cause the router to lock up. Code Red is getting the blame for much of the damage.

Brian Allen, director of network services and operations at Streaming Media Systems, a division of Broadcast Media Systems, said he has experienced problems for about a month, but it has grown worse since Code Red II started spreading this week.

According to Allen, Qwest has attributed the Cisco DSL router problem to "older" Cisco gear, but Allen noted that his company got its Cisco DSL router just last May to provide Qwest DSL service and Internet access for a dozen employees in Seattle.

    Add a comment

    Post a comment using one of these accounts
    Or join now
    At least 6 characters

    Note: Comment will appear soon after you have activated your account.
    Obscene/spam comments will be removed and accounts suspended.
    The information you submit is subject to our Privacy Policy and Terms of Service.

    ITworld LIVE

    SecurityWhite Papers & Webcasts

    White Paper

    Overcome Top 7 Admin Challenges of Active Directory

    As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

    White Paper

    Insiders Can Ruin Your Company. Take Action.

    Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

    White Paper

    Top Solutions and Tools to Prevent Devastating Malware

    Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

    White Paper

    Streamline Compliance and Increase ROI

    Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

    White Paper

    X-Ray of the PCI Process-4 Proactive Steps

    This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

    See more White Papers | Webcasts

    Ask a question

    Ask a Question