Nimda (computer worm)

Nimda (computer worm)

Nimda is a computer worm, isolated in September 2001. It is also a file infector. It quickly spread, eclipsing the economic damage caused by past outbreaks such as Code Red. Multiple propagation vectors allowed Nimda to become the Internet’s most widespread virus/worm within 22 minutes. Due to the release date, some media quickly began speculating a link between the virus and Al Qaeda, though this relationship ended up being untrue.

Nimda affected both user workstations (clients) running Windows 95, 98, Me, NT, or 2000 and servers running Windows NT and 2000.

The worm's name spelled backwards is "admin".

Methods of infection

Nimda was so effective partially because it—unlike other famous malware like the Morris worm or Code Red—uses five different infection vectors:
* via email
* via open network shares
* via browsing of compromised web sites
* exploitation of various Microsoft IIS 4.0 / 5.0 directory traversal vulnerabilities. (Both Code Red, and Nimda were hugely successful exploiting well known and long solved vulnerabilities in the Microsoft IIS server. [http://seifried.org/lasg/introduction-to-security/] )
* via back doors left behind by the "Code Red II" and "sadmind/IIS" worms.

ee also

* Timeline of notable computer viruses and worms

External links

* [http://www.cert.org/advisories/CA-2001-26.html Cert advisory on Nimda]
* [http://www.f-secure.com/v-descs/nimda.shtml Antivirus vendor F-Secure's info on Nimda]


Wikimedia Foundation. 2010.

Игры ⚽ Нужно сделать НИР?

Look at other dictionaries:

  • Computer worm — Morris Worm source code disk at the Computer History Museum …   Wikipedia

  • Code Red (computer worm) — Code Red Type Server Jamming Worm The Code Red worm was a computer worm observed on the Internet on July 13, 2001. It attacked computers running Microsoft s IIS web server. The Code Red worm was first discovered and researched by eEye Digital… …   Wikipedia

  • Nimda — Type Multiple Operating system(s) affected Windows 95–XP Nimda is a computer worm, and is also a file infector. It quickly spreads, eclipsing the economic damage caused by past outbreaks such as Code Red. Multiple propagation vectors allowed… …   Wikipedia

  • Timeline of computer viruses and worms — Contents 1 1960–1969 1.1 1966 2 1970–1979 2.1 1 …   Wikipedia

  • Timeline of notable computer viruses and worms — This is a timeline of noteworthy computer viruses and worms.1970 1979Early 1970s* Creeper virus was detected on ARPANET infecting the Tenex operating system. Creeper gained access independently through a modem and copied itself to the remote… …   Wikipedia

  • Хронология компьютерных вирусов и червей — Здесь приведён хронологический список появления некоторых известных компьютерных вирусов и червей, а также событий, оказавших серьёзное влияние на их развитие. Содержание 1 2012 2 2011 3 2010 4 2009 …   Википедия

  • Computers and Information Systems — ▪ 2009 Introduction Smartphone: The New Computer.       The market for the smartphone in reality a handheld computer for Web browsing, e mail, music, and video that was integrated with a cellular telephone continued to grow in 2008. According to… …   Universalium

  • ILOVEYOU — Common name Love Letter Type Computer worm Operating system(s) affected Microsoft Windows …   Wikipedia

  • Code Red II — Type Server Jamming Worm Code Red II is a computer worm similar to the Code Red worm. Released two weeks after Code Red on August 4, 2001, although similar in behavior to the original, analysis showed it to be a new worm instead of a variant. The …   Wikipedia

  • Многовекторный червь — Многовекторный червь  сетевой червь, применяющий для своего распространения несколько разных механизмов (векторов атаки), например, электронную почту и эксплойт ошибки в операционной системе.Черви повреждают файлы и негативно влияют на… …   Википедия

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”