<?xml version="1.0" encoding="UTF-8"?>
<essay xml:lang="en" version="pto" xmlns="http://docbook.org/ns/docbook" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:dcterms="http://purl.org/dc/terms/" xmlns:gal="http://norman.walsh.name/rdf/gallery#">
<info>
    
    
    
    
    
    
    
    
    
    
    
<title>Crack This!</title><biblioid class="uri">http://norman.walsh.name/2003/05/18/crackthis</biblioid>
<volumenum>6</volumenum>
<issuenum>17</issuenum>
<pubdate>2003-05-18</pubdate>
<date>$Date: 2005-09-11 10:27:02 -0400 (Sun, 11 Sep 2005) $</date>
<author>
      <personname>
<firstname>Norman</firstname>
	<surname>Walsh</surname>
</personname>
    </author>
<copyright>
      <year>2003</year>
      <holder>Norman Walsh</holder>
    </copyright>
<abstract>
<para>You can run, but I guess you can't hide.</para>
</abstract>
<dc:subject rdf:resource="http://norman.walsh.name/knows/taxonomy#SelfReference"/>
<dc:subject rdf:resource="http://norman.walsh.name/knows/taxonomy#TheWeb"/>
</info>
<epigraph>
<attribution>Joseph Conrad</attribution>
<para xml:id="p1"><indexterm>
	<primary>Conrad</primary>
<secondary>Joseph</secondary>
      </indexterm>The belief in a
supernatural source of evil is not necessary; men alone are
quite capable of every wickedness.</para>
</epigraph>

<para xml:id="p2">This site has been online for less than two weeks; to the best
of my knowledge, it isn't publically advertised anywhere.</para>

<para xml:id="p3">You can imagine that I was a little bit surprised to discover
entries like the following in my server log:
</para>

<programlisting>GET /default.ida?XXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
X%u9090%u6858%ucbd3%u7801%u9090%u6858%uc
bd3%u7801%u9090%u6858%ucbd3%u7801%u9090%
u9090%u8190%u00c3%u0003%u8b00%u531b%u53f
f%u0078%u0000%u00=a</programlisting>

<para xml:id="p4">They're coming from all over, at a rate of a little more than
one an hour.</para>

<para xml:id="p5">It didn't take Google very long to tell me that this is some
variant of the
<emphasis>CodeRed</emphasis><indexterm>
      <primary>Virus</primary>
<secondary>CodeRed</secondary>
    </indexterm> virus. I knew it existed,
of course, but I'd never paid it any mind. There's no Windows software
around here for it to infect. I'll admit a mild curiosity<indexterm>
<primary>Curiosity</primary>
    </indexterm> about why a
GET of the form above should spread a virus, but not enough curiosity
to go and find out.</para>

<para xml:id="p6">Malicious bastards.</para>

</essay>

