Type | Server Jamming Worm |
---|
Code Red II is a computer worm similar to the Code Red worm. Released two weeks after Code Red on August 4, 2001, although similar in behavior to the original, analysis showed it to be a new worm instead of a variant. Different from the first the second has no attacking function, but a backdoor to allow attacks. The worm was designed to exploit a security hole in the indexing software included as part of Microsoft's Internet Information Server (IIS) web server software.
A typical signature of the Code Red II worm would appear in a web server log as:
When the original worm tried to infect other computers at random, Code Red II tried to infect machines on the same subnet as the infected machine.
Microsoft had already released a security patch for IIS that fixed the security hole on June 18, 2001, however not everyone had patched their servers, including Microsoft themselves.