What Was Code Red? The Worm They Beat by Changing an Address

The worm knew exactly one address, and it was not a name.

Code Red's denial-of-service payload targeted 198.137.240.91, hardcoded. Not whitehouse.gov — the number. The worm never performed a DNS lookup, because it never needed to, because the author had written the address in directly.

So the White House changed the address, and 359,000 machines spent a week attacking an IP that no longer served anything.

What was Code Red?

Code Red appeared on 13 July 2001 and exploited a buffer overflow in the indexing service extension of Microsoft IIS, reached through a long request to a .ida URL. Microsoft had shipped the patch, MS01-033, on 18 June 2001 — twenty-five days earlier.

The first version had a flaw in its random number generator that made every copy probe the same sequence of addresses, which limited it badly. A corrected variant appeared on 19 July with proper seeding, and that one infected over 359,000 hosts in about fourteen hours.

It ran on a calendar. Days 1 to 19 of the month: spread. Days 20 to 27: flood the hardcoded address. Days 28 to the end of the month: dormant. Then repeat.

Infected servers with English-language systems also had their pages replaced with a message reading HELLO! Welcome to http://www.worm.com! Hacked By Chinese!

The name

Two researchers at eEye Digital Security, Marc Maiffret and Ryan Permeh, analysed it through the night of 15 July. The only thing in the office to drink was Code Red Mountain Dew.

That is the whole etymology. There is no deeper meaning, and it set the tone for two decades of vulnerability naming.

Correcting the record, twice

"Hacked By Chinese!" was not attribution. It was a string in a defacement, written in English, in a worm whose author has never been identified. It was reported at the time as though it were evidence of origin. There has never been anything to support that, and a string an attacker chose to display is close to the weakest signal available — misdirection costs nothing.

Code Red II was a different worm. It appeared in August 2001, shared the same IIS vulnerability and a similar name, and was otherwise unrelated: no defacement, no calendar, no White House. It installed a backdoor giving full remote access, which made it considerably more dangerous and considerably less famous. The two are routinely merged into one story.

The part worth keeping

Hardcoding the target was not laziness — it removed a dependency. A worm that resolves a hostname needs working DNS, and DNS is a thing defenders control.

But it also removed the author's own ability to adapt. Once released, the worm's target was fixed forever in every copy. There was no command channel, no configuration, no way to redirect. The moment the defenders moved the destination, the entire distributed attack became a very large number of machines shouting into a void.

This is a genuinely instructive trade-off, and it is why every serious piece of malware since has a command-and-control channel. Flexibility costs you a detectable dependency. Rigidity costs you the ability to respond. Code Red chose rigidity and was beaten by a DNS record change that took minutes.

The other thing worth keeping is the timeline. The patch was twenty-five days old. Not months, not years — twenty-five days, in an era when a public exploit for an internet-facing service still took weeks to weaponise. That gap has since closed to hours, and Code Red is where the industry started arguing seriously about how long you actually have.

What is still true

Code Red is the reason the phrase "patch window" entered ordinary operational language, and the reason Microsoft's Trustworthy Computing memo arrived six months later. IIS was rebuilt substantially in response.

The worm lived only in memory. A reboot removed it. Machines were reinfected almost immediately, because the underlying server was still unpatched — the same pattern Mirai would repeat fifteen years later with default passwords instead of a buffer overflow.

Further reading

  • eEye Digital Security — the original Code Red advisory and disassembly, July 2001.
  • CAIDA — Analysis of Code-Red, for the propagation measurements and the 19 July curve.
  • Microsoft Security Bulletin MS01-033.
  • CERT Advisory CA-2001-19.

EXHIBIT 0013 — CODE RED

We put it on a shirt. A brass address plate coming off a wall, two screws already falling, the pale rectangle behind it exposed — and a dense fan of arrows still converging on the spot where it used to be.

Most people will read it as a sign being taken down. A smaller number will read the numbers on it.

That's the whole idea.

View the Code Red shirt — EXHIBIT 0013

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.