KB 132

From SWCP Support Wiki
Jump to navigationJump to search

What should I do about the Nimda worm?

Article:132
Created:2001-09-19 00:04:43
Categories:
  E-mail
  Security

Question or Symptom

I've heard about this worm running rampant on the Internet. Is there anything I can do to protect myself from it?


Resolution

Nimda is a worm that uses an exploit of MS Internet Explorer, version 5.5 or below. The exploit causes a binary attachment to be opened and run without your permission or knowledge. This exploit can be triggered by visiting a rogue web page or by receiving an HTML email message containing the worm. Although the flaw is with Internet Explorer you are vulnerable when using MS Outlook and Outlook Express because these programs use Internet Explorer to interpret the HTML email message. If you use Outlook, Outlook Express or Internet Explorer (versions 5.5 or lower) you should get the MS01-020 Security patch from Microsoft and apply it to your version of Internet Explorer. (Note, if you've applied Internet Explorer Service Pack 2 you should already be safe from this exploit). The URL below links to the MS01-020 Microsoft Security Bulletin.

http://www.microsoft.com/technet/security/bulletin/MS01-020.asp

Once you're patched IE you still must refrain from opening attachments that you weren't expecting. This worm, like so many others uses address books to send email to unsuspecting folks. This email will appear to come from someone you know. Especially don't open any attachments with .exe or .vbs extensions. This worm is known to send an attachment named readme.exe.

Other strategies: Another approach to protect from this problem is to use non-Microsoft email or and web browsing software which tends to be less vulnerable to these types of problems. Some available alternatives are:

Netscape, web browser and email, download from www.netscape.com or contact help@swcp.com to have it sent to you on CDROM ($5).

Opera, web browser and email, download from www.opera.com. (You can download a free version which displays advertising, or pay $40 for the regular version).

Eudora, for email, download from www.eudora.com.

Nimda is a fairly sophisticated worm that exploits a number of different security flaws. If you're running a MS web server you should take a look at http://www.cert.org/advisories/CA-2001-26.html for more information on how the worm propagates and what you need to patch to avoid being used as a place for the worm to propagate.


 http://www.microsoft.com/technet/security/bulletin/MS01-020.asp
 http://www.mcafee.com/anti-virus/viruses/nimda/default.asp?cid=2444
 http://www.sarc.com/avcenter/venc/data/w32.nimda.a@mm.html
 http://www.cert.org/advisories/CA-2001-26.html