White Papers

CERTŪ Advisory CA-2001-26 Nimda Worm

Overview Original release date: September 18, 2001
Revised: September 25, 2001

The CERT/CC has received reports of new malicious code known as the W32/Nimda worm or the Concept Virus (CV) v.5. This new worm appears to spread by multiple mechanisms:

- from client to client via email - from client to client via open network shares
- from web server to client via browsing of compromised web sites
- from client to web server via active scanning for and exploitation of various Microsoft IIS 4.0 / 5.0 directory traversal vulnerabilities (VU#111677 and CA-2001-12) - from client to web server via scanning for the back doors left behind by the "Code Red II" (IN-2001-09), and "sadmind/IIS" (CA-2001-11) worms

The worm modifies web documents (e.g., .htm, .html, and .asp files) and certain executable files found on the systems it infects, and creates numerous copies of itself under various file names.

We have also received reports of denial of service as a result of network scanning and email propagation.

Further White Paper Details
PublisherCERT Coordination Center File FormatHTML
Date PublishedSeptember 2001
FormatWhite Papers   
Topics
    N/A
Thin clients switch on digitally excluded

Thin clients switch on digitally excluded

Case study: Digital inclusion project tackles social exclusion in Liverpool more

Renault goes multilingual

Renault goes multilingual

Case study: Translation tech turns docs into 23 languages… more


Quick Sitemap Links: