Nimda worm yet to strike Down Under

Australians are safe for the time being from being infected by the latest worm, which is spreading fast throughout the world just five hours after being released.

The "Nimda" worm, which appears as an email with the attachment "readme.exe", spreads to both servers and PCs running Microsoft software and propagates itself by email, mailing itself to everyone in your address book. It also spreads through network shares - infecting file and print servers via anyone who has -write" access to them.

-She's a nasty little one," Trend Micro's Ian Bigwood told ZDNet Australia. -Some people are going to get infected [in Australia] for sure."

According to Bigwood, as most people these days are blocking executables, the spread of the worm should be controlled, However, for a worm that's not much more than five hours old, -It's still very early days," he said.

Nimda utilises Microsoft's Internet Information Server (IIS) directory, the same one utilised by the recent Code Red worm and launches an attack on other people's Web servers from your computer. -Those folks who haven't leveraged off the Microsoft security patch really need to do so," Bigwood said. -Hopefully a lot of people learnt from Code Red, especially on the Web server side."

Servers that are attacked will have Web pages modified so that additional JavaScript runs when you browse them. This script downloads a specially-encoded version of the virus onto your PC. According to anti-virus vendor Sophos, some versions of Microsoft Internet Explorer have a vulnerability which allows this file to run automatically -- as if you had received it in an email and launched it yourself.

For information on Microsoft security patches: www.microsoft.com/technet/itsolutions/security/current.asp

Advertisement

Talkback 11 comments

    What a load... This article sa ...Anonymous -- 19/09/01

    What a load...

    This article says the worm isn't here at all

    I admin a network and have been receiving scans since last night at about 11pm EST (sydney)

    I'll admit I have seen no infections but the fact that it isn't here is a load... the way this worm spreads doesn't limit it an IP range or a geographical area.

    I suggect the editor of this site takes a little more care before publishing stories such as this

    my $0.02

    What a load alright. we know o ...Nimda Victim -- 19/09/01

    What a load alright.
    we know of two already.
    and it DOES wreak havoc.

    This is the biggest risk virus ...Damon Wynne -- 19/09/01

    This is the biggest risk virus I have ever seen. Ever.

    Intranet servers that no one bothered to patch are falling down all over the place. I'm talking government, small business.. everything.

    In the space that some servers took in their hourly download schedules for pattern updates, I estimate at least a dozen companies in SA were infected by this mongrel.

    Nasty.

    Don't you guys read your webse ...Anonymous -- 19/09/01

    Don't you guys read your webserver transfer (access) logs - the worms been virulent since at least Midnight AEST 19.09.2001.

    I have a Windows ME PC running ...Anonymous -- 19/09/01

    I have a Windows ME PC running Savant web server and started receiving messages like

    "GET :/scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir"

    from around 23:00 last night. After looking it up in Google found out what it was.

    I assume I am not infected (?), but obviously others in Aus are because the IP address was similar to mine.

    So finally we've got a virus t ...Bruce Rivendell -- 19/09/01

    So finally we've got a virus that respects international borders! I think not. Such a story should be written by someone who understands the issue.

    It also contains an outragous example of wankerspeak. Now one doesn't need to install a patch, you just 'leverage off' it.

    I despair!

    Nimda is quite active in Oz. I ...David Readman -- 19/09/01

    Nimda is quite active in Oz. I went through my Web server logs and I'm experiencing faily constant hits from Nimda even as I type. Perhaps this will act as a final wake-up call to any who haven't bothered with server patches

    Two of our sites are already i ...STEPHEN KLIMECK -- 19/09/01

    Two of our sites are already infected with this worm. MS Word out of memory errors were the first noticable error for the customers along with the blank email messages. We are still attempting manual repair of these computers. We are finding it hard to get AV software to detect or remove the virus.

    Has not hit australia! Rubbish ...Anonymous -- 19/09/01

    Has not hit australia! Rubbish. We've had hits since 8am this morning. Wake up Zdnet and get your facts straight!

    You didn't ask me... I've got ...Anonymous -- 20/09/01

    You didn't ask me... I've got all my bloody network infected!!!!

    Our Intranet server did not have the latest patches! (NT)

    It is definatley here in austr ...Anonymous -- 20/09/01

    It is definatley here in australia.
    We were struck hard on tuesday night around 11.30.
    It is now thursday and we are still trying to get rid of it.

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

Tags

Back to top

Featured