RIYADH, 1 August — The Internet Services Unit of King Abdul Aziz City for Science and Technology (KACST) has advised Internet users in the Kingdom to install an appropriate software patch to protect their systems against “Code Red” worm, which is threatening to become widespread by tomorrow in a second wave of infection.
In an advisory, Dr. Eyas Al-Hajery, head of Information Security Center at KACST’s Internet Services Unit, said the worm is a self-replicating malicious code that exploits a known vulnerability in a major Microsoft product (IIS server) operated on both Windows NT and Windows 2000. It is expected to hit nearly all vulnerable systems by identifying and installing itself in them.
Al-Hajery said more than 250,000 systems had been infected on July 19 in less than nine hours. “This has caused a very noticeable performance degradation in the Internet, as indicated in the CERT Coordination Center Advisory, a major reporting center for Internet security problems. Other major security centers have issued similar warnings.”
According to Al-Hajery, the US National Infrastructure Protection Center (NIPC), a task force that works under the FBI and the US Justice Department, considered the worm a “significant threat”.
The Code Red worm, first reported by eEye Digital Security, was expected to unleash a second wave by tomorrow, when it will become widespread. “The solution is to install an appropriate Microsoft patch software, which can be downloaded from the Microsoft site,” the KACST executive said.
Yaqub Snobar, general manager of Nesma Internet, said the problem was caused by a hole in the Microsoft IIS through which the Code Red worm was able to sneak in and infect the system. “We have blocked the hole thereby denying access to the worm,” Snobar said, adding that all their clients have been protected against the bug.
Speaking on behalf of Ofoq Information Systems and Communications Co. (arab.net), Anwar A. Helmi, maintenance and operations manager, said all ArabNet servers had the Microsoft patch installed late Monday night right after Microsoft released it.
Helmi advised Internet users never to open an unknown or weird message. They should also learn not to expect any file from a chatter or e-mail from an unknown source. They should secure their data and create back-up files. Moreover, they should not store confidential files in the system, he added.
The Ofoq executive urged Internet users to protect their files with the free download of Microsoft patch via the following link:http://www.microsoft.com/downloads/release.asp?ReleaseID=30833 for Windows NT 4.0 platforms. Helmi said the size of the patch was only 270KB and could be simply downloaded over a dial-up connection. “Immediate action must be taken as the worm might start affecting servers early today.”
He pointed out that the worm infects Windows NT and Windows 2000 but not Windows 95,98 and the Millennium edition.



