Nimda

Nimda
Nimda
Type Multiple
Operating system(s) affected Windows 95XP

Nimda is a computer worm, and is also a file infector. It quickly spreads, eclipsing the economic damage caused by past outbreaks such as Code Red. Multiple propagation vectors allowed Nimda to become the Internet’s most widespread virus/worm within 22 minutes.

The worm was released on September 18, 2001.[1] Due to the release date, exactly one week after the attacks on the World Trade Center and Pentagon, some media quickly began speculating a link between the virus and Al Qaeda, though this theory ended up proving unfounded.

Nimda affected both user workstations (clients) running Windows 95, 98, Me, NT, 2000 or XP and servers running Windows NT and 2000.

The worm's name origin comes from the reversed spelling of it, which is "admin".

F-Secure found the text[2] "Concept Virus(CV) V.5, Copyright(C)2001 R.P.China" in the Nimda code.

Contents

Methods of infection

Nimda was so effective partially because it—unlike other infamous malware like the Morris worm or Code Red—uses five different infection vectors:

  • via email
  • via open network shares
  • via browsing of compromised web sites
  • exploitation of various Microsoft IIS 4.0 / 5.0 directory traversal vulnerabilities. (Both Code Red, and Nimda were hugely successful exploiting well known and long solved vulnerabilities in the Microsoft IIS server.[3])
  • via back doors left behind by the "Code Red II" and "sadmind/IIS" worms.

See also

References

  1. ^ http://www.cert.org/advisories/CA-2001-26.html CERT first released an advisory on the worm on September 18, 2001
  2. ^ http://www.f-secure.com/v-descs/nimda.shtml
  3. ^ http://seifried.org/lasg/introduction-to-security/

External links



Wikimedia Foundation. 2010.

Игры ⚽ Нужно сделать НИР?

Look at other dictionaries:

  • Nimda —   [nach der rückwärts gelesenen Abkürzung Admin für Administrator »Netzwerkverwalter«], eigentlich W32.nimda, ein erstmals im September 2001 aufgetretener Computervirus, der Merkmale eines Virus und eines Wurms vereint. Er befällt Rechner mit dem …   Universal-Lexikon

  • Nimda — Le ver Nimda (anglais : Nimda Worm) est un logiciel malveillant résident. Le nom Nimda est un jeu de mots : c est le nom Admin (administrateur) renversé. Sommaire 1 Propagation 1.1 Caractéristiques du fichier 1.2 Ports utilisés …   Wikipédia en Français

  • Nimda (computer worm) — Nimda is a computer worm, isolated in September 2001. It is also a file infector. It quickly spread, eclipsing the economic damage caused by past outbreaks such as Code Red. Multiple propagation vectors allowed Nimda to become the Internet’s most …   Wikipedia

  • Nimda Shoet — Shoet in Yad la Shiryon museum, Israel. Shoet is a 6 by 6 wheeled armored personnel carrier developed by Nimda Group, Israel as a private venture, along the concept lines of the Soviet BTR 152. The vehicle successfully passed tests with the… …   Wikipedia

  • Ver Nimda — Nimda Cet article fait partie de la série Programmes malveillants Virus Cabir MyDoom.A Tchernobyl Yaman …   Wikipédia en Français

  • Многовекторный червь — Многовекторный червь  сетевой червь, применяющий для своего распространения несколько разных механизмов (векторов атаки), например, электронную почту и эксплойт ошибки в операционной системе.Черви повреждают файлы и негативно влияют на… …   Википедия

  • Achzarit — IFV[1] Achzarit IFV en una Exhibición. Tipo Transporte blindado de personal …   Wikipedia Español

  • Хронология компьютерных вирусов и червей — Здесь приведён хронологический список появления некоторых известных компьютерных вирусов и червей, а также событий, оказавших серьёзное влияние на их развитие. Содержание 1 2012 2 2011 3 2010 4 2009 …   Википедия

  • Windows 2000 — Part of the Microsoft Windows family Screenshot of Windows 2000 Professional …   Wikipedia

  • PT-76 — Infobox Weapon|is vehicle=yes name=PT 76 caption=PT 76 on display near the Museum of the Great Patriotic War, Kiev. type=Amphibious Light Tank origin=flagcountry|Soviet Union service=16 August 1952 present used by=See Operators wars=See Combat… …   Wikipedia

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”