BillSoo
09-18-2001, 01:36 PM
Yet another CODERED style worm (W32.Nimda) has appeared and is tying up the net. This may impact access to the forum...
"I have a plan so cunning you could put a tail on it and call it a weasel!" - Edmund Blackadder
dcl3500
09-18-2001, 05:29 PM
Any word on a fix for it yet?
Don
Time is the best teacher; unfortunately it kills all its students.
BillSoo
09-18-2001, 05:36 PM
It uses the same IIS vulnerabilities as CodeRed plus a bunch more previously documented NT vulnerabilities. It sends itself via e-mail as ReadMe.Exe as well as doing the worm thing.
It also puts itself on websites of infected servers for download, which is something I've never heard of before...
Basically, if you've patched your NT/IIS system or if you don't use NT (and don't open any unexpected attachments) you should be ok.
For more info, <a href="http://www.datafellows.com/v-descs/nimda.shtml"> look here </a>
"I have a plan so cunning you could put a tail on it and call it a weasel!" - Edmund Blackadder