Will ANYONE hold Micro$oft
(sellers of the pitifully authored "IIS Web Server" software)
liable for the cost to us all for the atrocities
of the CodeRed/nimda vulnerabilities!???
("IIS" means "It Isn't Secure" to most in the 'know')
A little perspective at the end of November, 2002...
CodeRed shocked us into the reality of cyber attacks, BUT,
nimda is DAILY running about as rampant as CodeRed did at its peak!!
(About 40,000 FORTY THOUSAND cracking attempts per DAY!
Many web site businesses wish they could have that many hits per month!!!)
It has gotten so bad that
"Gartner recommends that enterprises hit by both Code Red and NIMDA immediately
investigate alternatives to IIS ... from other vendors, such as iPlanet and Apache"!
Steve Gibson says, "The last serious remote-code execution vulnerability
to hit the Apache Web server was back in 1997. But IIS has them monthly."
On March 11, 2003, 20 months after its start, Code Red hits again!
(Not that it ever really stopped!)
You may say, but it only affects Internet businesses... NOT SO!!!
ANYONE who has access to ANY webserver log is being 'spoon fed' a 100% accurate stream of web sites that are CURRENTLY COMPROMISED and are therefore 'sitting ducks' waiting to have their data files stolen by simple download!
Any and every file on such a compromised server can have any, or even every, data file captured! What if your credit card number is in one of those data files? Or PERSONAL INFORMATION of you or your family members? And after a 'cracker' captures that data, they can change or delete any log data that may have traced their actions!!
Can we even speculate the severe costs to us all (Yes, YOU the INDIVIDUAL!) due to even a single factor such as hijacked credit cards!!! And what about Identity theft from stolen Social Security numbers!??? (Privacy Rights Clearinghouse says 400,000 people have had their lives disrupted in year 2001 by Identity Theft and states "More than a half million people will become victims of identity theft this year alone" and " is the fastest growing crime in our nation today"!)
Steve Gibson states:
"Ultimately, the security of your personal information is YOUR responsibility."
And he provides ID Serve to help.
And as of Sep. 18, 2001, we have another atrocity called NIMDA ("admin" spelled backwards) which started attacking here Sep. 18 09:02 EDT that exploites the 'back-doors' left by CodeRed II! And this worm appears about 40 times more severe than CodeRed II at its peak!!!
The following statistics show the number of Code Red intrusion attempts
directed toward a fraction of the hundreds of IP addresses we host: