Friday, July 20th, 2001

happy to be running apache

I am stunned by the speed with which the Code Red worm propagated across the web.

I do not run any Microsoft server products, so my systems are not vulnerable to this particular attack, and yet the worm hit all my sites repeatedly in an attempt to replicate itself. was hit from 16 different infected hosts. was hit by 26. An unnamed, unpublished, empty website that I use only for testing purposes got hit 18 times.

This is a good reminder to everyone who runs a server to keep up-to-date with vendor patches and bug reports. Subscribe to CERT and BugTraq. That’s the minimum sane level of paranoia; you’d be much better off actually becoming well-versed at server security, or hiring someone who is, to make sure your servers are at least difficult to hack.

