maps*index*directories*


 
   
 
  Network

OIT

Computing Services

Organization Chart

Backbone

Novell

Microsoft

Unix

Phone

 

Information on the "Nimda" Worm


Summary: A new worm, officially called W32/Nimda@MM, is circulating on the Internet and affecting large numbers of people.  If you haven’t already installed the appropriate updates and/or patches, your computer can become infected.

 

Actions You Should Take


 

End Users


If you do not have Norton Anti Virus loaded on your computer, please load it now.

http://library.boisestate.edu/authenticate/virus/

 

To prevent infection from email, update Internet Explorer with one of the following:

bulletThe patch provided in Microsoft Security Bulletin MS01-020
bulletInternet Explorer 5.01 Service Pack 2.
bulletInternet Explorer 5.5 Service Pack 2.
bullet Internet Explorer 6

For Netscape users


 

System Administrators

1.   Prevent the Code Red Worm II from infecting your system and use a Microsoft tool to repair systems that have been infected. (Code Red Worm II leaves a “back door” that Nimda exploits.)

2.   Block the ”Web Server Folder Traversal” vulnerability by applying or installing any of the following:

bulletApplying the patch provided in Microsoft Security Bulletin MS00-057
bulletApplying the patch provided in Microsoft Security Bulletin MS00-078
bulletApplying the patch provided in Microsoft Security Bulletin MS00-086
bulletApplying the patch provided in Microsoft Security Bulletin MS00-026
bulletApplying the patch provided in Microsoft Security Bulletin MS01-044
bulletInstalling Windows 2000 Service Pack 2
bulletInstalling the Windows NT 4.0 Security Roll-up Package
bulletRunning the IIS Lockdown Tool in its default mode
bulletInstalling the URLScan tool with its default ruleset.

3.   Prevent spread through file shares by locking down permissions on all computers.

 

Additional Information

The official name of the worm is W32/Nimda@MM, but it is generally referred to as the "Nimda" worm. It attempts to spread via three different means:

bulletEmail: Infected machines attempt to spread the infection to other users by sending copies of the worm via email.
bulletWeb servers: Infected machines attempt to pass the infection to web servers by either locating an already compromised server, or by exploiting a known security vulnerability in Internet Information Server.
bulletFile shares: Infected machines will search for systems that have been configured to allow anyone to add files to them and, upon finding such a machine, will insert infected files onto it.

Email

The worm spreads via email by sending a copy of itself within a mail that exploits the security vulnerability discussed in Microsoft Security Bulletin MS01-020. As the bulletin describes, the vulnerability lies in Internet Explorer, but is exploited via email. Simply opening the email itself would be sufficient to infect the machine – it would not be necessary to open an attachment.

Anti-virus vendors are currently developing updated scanning tools that will detect and disarm mails sent by the virus. But even in the absence of these tools, patches and updated versions of IE have been available for some time to eliminate the vulnerability. Customers who have installed any of the updates listed earlier would be at no risk of infection by email.

 

Web Servers

When the worm attacks IIS 4.0 and 5.0 web servers, it does so through either of two means. First, it checks to see if the machine was previously compromised by the Code Red II worm, which creates a "back door" that any malicious user can use later to gain control of the system. If the Nimda worm finds such a machine, it simply uses the back door created by Code Red II to infect the system. Second, the worm attempts to exploit the "Web Server Folder Traversal" vulnerability. If it succeeds in exploiting this vulnerability, the worm uses it to infect the system.

A tool is available to remove the back door created by the Code Red II worm. However, the best course of action is to prevent the Code Red II worm altogether, as instructed in step 1 above.

 

File shares

The final means by which the worm tries to spread is through file shares. Windows systems can be configured to allow other users to read files from them or write files to them. It is generally poor security practice to allow anyone to have access to your files and, by default, Windows systems only allow the authorized user of the system to access the files on it. However, if the worm finds a system that has been configured to allow other users to create files on it, it adds files that spread the infection. The Microsoft Personal Security Advisor can be used to determine whether you have any incorrectly configured shares on your system.

 

More Resources

Microsoft is continuing to investigate this worm, and will provide updated information as we learn it. In the meantime, additional information is available from the following sources:

bulletCERT Coordination Center
bullet Symantec Security Response
bulletNetwork Associates

 

News Site

Boise State University had contracted with Micron Internet Services to provide Usenet News feed for the University. Micron Internet Services no longer provides a Usenet News feed.  Because of the low number of users of News, the University will no longer provide a site license for news.  There are news feeds available from a number of Internet sites.

A small sample of sites that provide news are;

http://www.help.com

http://www.topica.com

http://groups.google.com

http://www.yahoo.com

 

Usenet News
Usenet News is the equivalent of a discussion group or "bulletin board system" (BBS). With Usenet News you can keep track of the latest gossip about your favorite TV sitcom, discuss your sports heroes with other fans or find out what printer you should buy for your home PC. Newsgroups cover every imaginable topic (and some you can't imagine) -- some will help you with your work and others are simply for entertainment.

bulletNetscape News Handbook
Everything you need to know about Netscape News reader.
bulletList of Usenet FAQs
A complete listing of ALL Usenet FAQs....all in one place.
bulletNewsgroup Finder
Type in a keyword and find out what newsgroups fit your interests.
bulletDejaNews Research Service
A search engine for Usenet News.
bulletWhere is the archive for newsgroup X?
Find the archives for almost all newsgroups here.
 

1910 University Drive, Boise Idaho  83725   ©2002 Boise State University...