Simple clear advice in plain English

A worm with many tricks and turns

Nimda gains the run of local networks

Nimda is 'admin' spelt backwards, which is apt as one of its tricks is to grant itself administrative privileges to gain the run of local networks.

It spread initially by scanning the web and local networks for servers with two vulnerabilities: a back door used by the Code Red virus, and a 'web server folder traversal', which allows an intruder to gain access to folders on a web server using a particular form of malformed URL.

Once Nimda has found a compliant server, it installs itself as a file called Admin.dll, which is executed to create a guest account granting full access privileges.

It also tries to infect other local servers and makes the boot drive public. Finally it appends a script to key HTML and ASP files, which can infect PCs accessing the site.

Unpatched versions of Explorer 5.5 or earlier are vulnerable to this attack. Users of other browsers can still be infected if they have JavaScript enabled, but the code will ask permission before activation.

Yet another transmission route is provided by email. Nimda runs its own email routine, sending itself to addresses in the Outlook address book.

In older versions of Outlook and Outlook Express, these emails can self-activate from the viewing pane without being opened.

Reader Comments

   

Add your comment

All fields must be completed. Your email address will not be displayed or used to send marketing messages.

All messages will be checked by moderators before appearing on the site.

See our Privacy Policy for more information.

Related articles

Security shield illustration

How to use the Command Prompt

Lurking under Windows is the little-known world of the command line. We explain how to use this to fix faults and make your PC much more secure

VLC screenshot

20 free alternatives to Windows built-in utilities

You might think Windows has all the utilities you want, but we've found 20 that are free and do a better job. We tell you what they do and where to download them

f-341-pc-slip-ups

How to avoid common PC mistakes

Everyone makes mistakes, but some can be averted if you follow our advice

Question & Answer

Q.How do I store musician and other information about...

> Read the answer

Q.Why can't my browser find the website address I typed...

> Read the answer

Q.All updates have been downloaded, so why won't Windows...

> Read the answer

Best deals on the web

img

Apple MacBook Pro (MC724LL/A)

£999.99- Buy it now

img

Sony Vaio VPCF23P1E/B

£679.98- Buy it now

img

Samsung 300E5A-A01DX

£449.99- Buy it now

Great benefits for subscribers!

Poll

Which is your preferred web browser

Jargon Buster

Computing terms explained in plain English

Router

A device used to connect more than one computer or other device to the internet.

Great shopping deals from Computeractive