Low End P C

Affiliates: Office Depot | Amazon.com

Other Cobweb sites: Low End Mac | Low End Living | Reformed.net

Nimda came out of nowhere on September 18, 2001. It targets Windows computers, using individual networked PCs to infect NT-base servers running IIS. A Windows PC can become infected by opening or previewing an infected email, visiting a site on an infected server, or simply being on the same network as another infected Windows machine.

Windows servers can be infected by another server or PC on the same network or connecting over the Internet. Once a computer is infected, it will scan for other machines to infect. Once a server is infected, it will serve infected pages to visitors.

It may also be spreading via IRC and FTP.

Although Nimda can only infect Windows PCs, it can cripple servers running any operating system by hitting them persistently. As of 9:00 p.m. on Sept. 18, the Web log showed Low End Mac's (our sister site) Linux-based server had been hit almost 8,000 times:

989: /scripts/..%255c../winnt/system32/cmd.exe
988: /scripts/..%5c../winnt/system32/cmd.exe
500: /scripts/root.exe
499: /msadc/root.exe
498: /c/winnt/system32/cmd.exe
498: /d/winnt/system32/cmd.exe
497: /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe
496: /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe
495: /scripts/winnt/system32/cmd.exe
495: /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe
495: /scripts/..%c1%1c../winnt/system32/cmd.exe
494: /scripts/..%c0%af../winnt/system32/cmd.exe
493: /scripts/..%252f../winnt/system32/cmd.exe
493: /scripts/..%c1%9c../winnt/system32/cmd.exe

We received out first email with Nimda at 11:18 a.m. Here's the opening part of that message:

--====_ABC1234567890DEF_====
Content-Type: multipart/alternative;
	boundary="====_ABC0987654321DEF_===="
         
--====_ABC0987654321DEF_====
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
         
         
<HTML><HEAD></HEAD><BODY bgColor=3D#ffffff>
<iframe src=3Dcid:EA4DMGBP9p height=3D0 width=3D0>
</iframe></BODY></HTML>
--====_ABC0987654321DEF_====--
         
--====_ABC1234567890DEF_====
Content-Type: audio/x-wav;
	name="readme.exe"
Content-Transfer-Encoding: base64
Content-ID: <EA4DMGBP9p>

If you're setting up a filter, have it look for name="readme.exe" as a good place to start in separating Nimda from other incoming email.

The Nimda worm seeks out Windows servers running IIS. As the log indicates, Nimda is looking for cmd.exe and/or root.exe.

Links

<The Virus Page>

Low End P C The Virus Page

The Nimda Worm

Low End Mac Reader Specials

Memory To Go Special: MacPro 8 Core 8GB kit $232 / 4GB kit $116 / 2GB kit $72. New Macbook 2GB DDR3-$65. HARD DRIVES available -- Free shipping / LIfetime warranty.

Download Typestyler, still the Ultimate Styling Tool for Internet, Print and Video Graphics. Works great in Classic with a Native OS X Version on the way. Free Tryout: www.typestyler.com

LA Computer Company: Specials on AppleCare, iMac's, Apple Batteries and Apple A/C Adapters. Also Great prices on Used Apple Computers. Call 1-800-941-7654 Click Here.

Mac users can finally play Party Poker for Mac. Not only that, they can also learn how to play PokerStars for Mac.

Laptop Hardware Provided by TechRestore - Overnight Mac & iPod Repairs.

Compare products like desktop computers, laptops, and LCD TVs side by side! All the information and reviews to make the best purchasing decision for a new cell phone GPS products or MP3 players. The Ciao network makes searching products easy for you.

Dan Knight - 2001:09:18

Resources
 Editorial Index
 Editorial Archive
 Online Tech Journal
 The Virus Page
 PC History
 About Low End PC

Favorite Sites

 - Living Without Microsoft
 - The Register
 - Slashdot

Support LEPC

iTunes Store
eBay
Amazon.com
PayPal
PC Zone
Crucial Memory

Open Link

Viewable With Any Browser