July 19, 2001

Code Red worm targets IIS web servers

The Code Red wormSelf-replicating malware that spreads across networks without needing a host file. peaked on July 19, 2001 — exploiting a buffer overflow in MicrosoftThe software giant behind Windows, Office, Azure, and Xbox — founded by Bill Gates and Paul Allen. IIS to deface websites and launch DDoS attacks against the White House.

What it was for

Code Red (computer worm)Code Red scanned the entire IPv4Internet Protocol version 4 — the 32-bit address scheme still widely used on the internet. space for vulnerable IIS installs — hundreds of thousands of servers compromised in hours. It was named after Mountain Dew flavor at eEye Digital Security and forced emergency patching of Windows NT and 2000 web farms. Developers learned that internet-facing services could be weaponized into botnets overnight.

Companies

  • Microsoft

Why it's here

Code Red showed how one IIS bug could infect the public web in a single day.

Why it mattered

It accelerated automated patching and incident-response teams for internet services.

What it solved

Nothing initially — it exploited unpatched buffer overflows faster than admins could deploy fixes.

Media

  • Code Red (computer worm)
    ImageCode Red (computer worm)

    Unknown author, Public domain, via Wikimedia Commons

Related