internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / Tips & Tutorials

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Opera
Internet Explorer 7
QuickTime for Windows
Winamp
Mozilla Firefox 3
Ad-Aware 2008 Free
Adobe Flash Player
Paint Shop Pro
Adobe Shockwave Player
AVG Anti-Virus Free
7-Zip

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Handling Nimda
How Nimda Works
D. E. Levine

Although there's no evidence that Nimda actually destroys data, the major problem is that it is a very aggressive worm that generates a large volume of Internet and network activity that winds up clogging both and slowing them down. Nimda can spread in four different major ways.

Perhaps the most common way that Nimda can be spread is through e-mail. An infected message can have any kind of return address. Generally the subject is nonsensical or looks like it's in another language. (If you're not familiar with other languages you won't want the message anyway.) The body of the message usually lacks any text while an attachment will appear to be a WAV or readme.exe file. The reason that Nimda is particularly nasty is that you needn't open the message in order to activate the worm. Generally just by looking at the information in the preview pane will activate Nimda. The worm will then send e-mail to every address listed in the address book and in the browser cache.

A second way that a PC or server can get infected is by viewing and infected Web page on the Internet. When the page is infected it's generally "rigged" to ask the viewer if they want to download and Outlook Express e-mail (. eml) file. When that file is downloaded it infects the machine. With this infection, as well as the infection through e-mail, the worm appends itself to Word document files, .exe files, and .eml files. In some cases it will replace applications with copies that execute the worm and the worm always executes if a program uses Richard20.dll.

The third method of infection is by exploiting a previous system compromise. If a system running IIS software has already been compromised by either the Code Red or Code Red II worms, Nimda copies itself as an "admin.dll" file. For those IIS systems that haven't been compromised, the worm attempts to use the previously discovered "Web server folder traversal" vulnerability in order to copy the admin.dll file to the server.

Finally, the fourth major method of infection is by using shared drives on corporate networks. Network sharing allows the Nimda worm to spread very quickly, and because of its nature, to be especially pervasive in reappearing and infecting systems.

Next: Tips for Dealing with Nimda »

« Previous Page| Next Page »

Contents:
1. Explaining Nimda
2. How Nimda Works
3. Tips for Dealing with Nimda




internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info

Legal Notices, Licensing, Reprints, Permissions, Privacy Policy.
Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Whitepapers and eBooks

Symantec Whitepaper: Converging System and Data Protection for Complete Disaster Recovery
Intel Whitepaper: Comparing Two- and Four-Socket Platforms for Server Virtualization
IBM Solutions Brief: Go Green With IBM System xTM And Intel
HP eBook: Simplifying SQL Server Management
IBM Contest: Are You the Next Superstar? Join the "Search for the XML Superstar" Contest to Find Out
Intel PDF: Quad-Core Impacts More Than the Data Center
Intel PDF: Virtualization Delivers Data Center Efficiency
Go Parallel Article: PDC 2008 in Review
Avaya Article: Communication-Enabled Mashups: Empowering Both Business Owners and IT
Intel Whitepaper: Building a Real-World Model to Assess Virtualization Platforms
PDF: Intel Centrino Duo Processor Technology with Intel Core2 Duo Processor
Microsoft Article: Build and Run Virtual Machines with Hyper-V Server 2008
  Go Parallel Article: Q&A with a TBB Junkie
IBM Whitepaper: Innovative Collaboration to Advance Your Business
Internet.com eBook: Real Life Rails
IBM eBook: The Pros and Cons of Outsourcing
Internet.com eBook: Best Practices for Developing a Web Site
IBM CXO Whitepaper: The 2008 Global CEO Study "The Enterprise of the Future"
Avaya Article: Call Control XML in Action - A CCXML Auto Attendant
IBM CXO Whitepaper: Unlocking the DNA of the Adaptable Workforce--The Global Human Capital Study 2008
Adobe Acrobat Connect Pro: Web Conferencing and eLearning Whitepapers
Symantec Whitepaper: Comprehensive Backup and Recovery of VMware Virtual Infrastructure
MORE WHITEPAPERS, EBOOKS, AND ARTICLES