MS internal network whacked by Code Red
Boneheaded employee strikes...
Posted in Software, 10th August 2001 11:39 GMT
See what The Register's experts have to say on application security
It's not just MSN - Code Red has just ripped through Microsoft's internal network too, according to our spies in Redmond. The unleashed worm is claimed to have whacked numerous servers on the corporate network; something of an embarrassment for Microsoft this, as it can only mean we hadn't quite got our act together on the patch front before the storm broke.
How did it happen? One of Microsoft's biggest internal security problems is smart-arse techies who decide to make their lives easier by ignoring and/or shorting out all the rules, thus leaving the company vulnerable to, say, employees' infected home machines. But not this time - somebody simply brought an infected, hibernated laptop in, connected it to the corporate network and bang, Code Red was inside the perimeter chomping away.
But the infection's probably a blessing in disguise, because it'll have helped Redmond's fire-fighters identify all of the machines still vulnerable, and so long as the press doesn't hear about it, High Command will be spared massive embarrassment. So shush people, OK? ®
Related story:
Code Red worms into Hotmail servers
See what The Register's experts have to say on application security


Airport insecurity: the case of lost laptops
The business case for application security
Exchange 2007 risks and mitigation strategies
The best practices guide for application security
Google code cloud punts on-demand embarrassment
Microsoft weighs next-phase in open-source support
iTunes minus the player: hack your Apple beats
Oracle plans cloud strategy