<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.swcp.com/w/index.php?action=history&amp;feed=atom&amp;title=KB_132</id>
	<title>KB 132 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.swcp.com/w/index.php?action=history&amp;feed=atom&amp;title=KB_132"/>
	<link rel="alternate" type="text/html" href="https://wiki.swcp.com/w/index.php?title=KB_132&amp;action=history"/>
	<updated>2026-10-06T22:38:59Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.45.1</generator>
	<entry>
		<id>https://wiki.swcp.com/w/index.php?title=KB_132&amp;diff=393&amp;oldid=prev</id>
		<title>Jamii: New page: ===What should I do about the Nimda worm?===  Article:132  Created:2001-09-19 00:04:43  Categories:    E-mail    Security  ====Question or Symptom==== I&#039;ve heard about this worm running ra...</title>
		<link rel="alternate" type="text/html" href="https://wiki.swcp.com/w/index.php?title=KB_132&amp;diff=393&amp;oldid=prev"/>
		<updated>2008-06-04T22:50:29Z</updated>

		<summary type="html">&lt;p&gt;New page: ===What should I do about the Nimda worm?===  Article:132  Created:2001-09-19 00:04:43  Categories:    E-mail    Security  ====Question or Symptom==== I&amp;#039;ve heard about this worm running ra...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;===What should I do about the Nimda worm?===&lt;br /&gt;
 Article:132&lt;br /&gt;
 Created:2001-09-19 00:04:43&lt;br /&gt;
 Categories:&lt;br /&gt;
   E-mail&lt;br /&gt;
   Security&lt;br /&gt;
&lt;br /&gt;
====Question or Symptom====&lt;br /&gt;
I&amp;#039;ve heard about this worm running rampant on the Internet. Is there&lt;br /&gt;
anything I can do to protect myself from it?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
====Resolution====&lt;br /&gt;
Nimda is a worm that uses an exploit of MS Internet Explorer, version&lt;br /&gt;
5.5 or below. The exploit causes a binary attachment to be opened&lt;br /&gt;
and run without your permission or knowledge. This exploit can be&lt;br /&gt;
triggered by visiting a rogue web page or by receiving an HTML email&lt;br /&gt;
message containing the worm. Although the flaw is with Internet Explorer&lt;br /&gt;
you are vulnerable when using MS Outlook and Outlook Express because&lt;br /&gt;
these programs use Internet Explorer to interpret the HTML email&lt;br /&gt;
message. If you use Outlook, Outlook Express or Internet Explorer&lt;br /&gt;
(versions 5.5 or lower) you should get the MS01-020 Security patch from&lt;br /&gt;
Microsoft and apply it to your version of Internet Explorer. (Note,&lt;br /&gt;
if you&amp;#039;ve applied Internet Explorer Service Pack 2 you should already&lt;br /&gt;
be safe from this exploit). The URL below links to the MS01-020 Microsoft &lt;br /&gt;
Security Bulletin.&lt;br /&gt;
  &lt;br /&gt;
http://www.microsoft.com/technet/security/bulletin/MS01-020.asp&lt;br /&gt;
  &lt;br /&gt;
Once you&amp;#039;re patched IE you still must refrain from opening attachments&lt;br /&gt;
that you weren&amp;#039;t expecting. This worm, like so many others uses address&lt;br /&gt;
books to send email to unsuspecting folks. This email will appear to come&lt;br /&gt;
from someone you know. Especially don&amp;#039;t open any attachments with .exe&lt;br /&gt;
or .vbs extensions. This worm is known to send an attachment named&lt;br /&gt;
readme.exe.&lt;br /&gt;
  &lt;br /&gt;
Other strategies: Another approach to protect from this problem is to&lt;br /&gt;
use non-Microsoft email or and web browsing software which tends to be&lt;br /&gt;
less vulnerable to these types of problems.  Some available alternatives&lt;br /&gt;
are:&lt;br /&gt;
  &lt;br /&gt;
Netscape, web browser and email, download from www.netscape.com or&lt;br /&gt;
contact help@swcp.com to have it sent to you on CDROM ($5).&lt;br /&gt;
  &lt;br /&gt;
Opera, web browser and email, download from www.opera.com.  (You can&lt;br /&gt;
download a free version which displays advertising, or pay $40 for the&lt;br /&gt;
regular version).&lt;br /&gt;
  &lt;br /&gt;
Eudora, for email, download from www.eudora.com.&lt;br /&gt;
  &lt;br /&gt;
Nimda is a fairly sophisticated worm that exploits a number of different&lt;br /&gt;
security flaws. If you&amp;#039;re running a MS web server you should take a look&lt;br /&gt;
at http://www.cert.org/advisories/CA-2001-26.html for more information on&lt;br /&gt;
how the worm propagates and what you need to patch to avoid being used&lt;br /&gt;
as a place for the worm to propagate.&lt;br /&gt;
  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
====Related URLS====&lt;br /&gt;
  http://www.microsoft.com/technet/security/bulletin/MS01-020.asp&lt;br /&gt;
  http://www.mcafee.com/anti-virus/viruses/nimda/default.asp?cid=2444&lt;br /&gt;
  http://www.sarc.com/avcenter/venc/data/w32.nimda.a@mm.html&lt;br /&gt;
  http://www.cert.org/advisories/CA-2001-26.html&lt;/div&gt;</summary>
		<author><name>Jamii</name></author>
	</entry>
</feed>