Nimda
Home > Security Definitions - Nimda
SearchSecurity.com Definitions (Powered by WhatIs.com)
EMAIL THIS
LOOK UP TECH TERMS Powered by: WhatIs.com
Search listings for thousands of IT terms:
Browse tech terms alphabetically:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #

Nimda


Show me everything on Malware, Viruses, Trojans and Spyware

DEFINITION - First appearing on September 18, 2001, Nimda is a computer virus that caused traffic slowdowns as it rippled across the Internet, spreading through four different methods, infecting computers containing Microsoft's Web server, Internet Information Server (IIS), and computer users who opened an e-mail attachment. Like a number of predecessor viruses, Nimda's payload appears to be the traffic slowdown itself - that is, it does not appear to destroy files or cause harm other than the considerable time that may be lost to the slowing or loss of traffic known as denial-of-service and the restoring of infected systems. With its multi-pronged attack, Nimda appears to be the most troublesome virus of its type that has yet appeared. Its name (backwards for "admin") apparently refers to an "admin.DLL" file that, when run, continues to propagate the virus.

To briefly summarize what Nimda does:

  • It probes each IP address within a randomly-selected range of IP addresses, attempting to exploit weaknesses that, unless already patched, are known to exist in computers with Microsoft's Internet Information Server. A system with an exposed IIS Web server will read a Web page containing an embedded JavaScript that automatically executes, causing the same JavaScript code to propagate to all Web pages on that server.
  • As people (those with Microsoft Internet Explorer browsers at the 5.01 or earlier level) visit sites at the infected Web server, they unwittingly download pages with the JavaScript that automatically executes, causing the virus to be sent to other computers on the Internet in a somewhat random fashion.
  • Nimda also can infect users within the Web server's own internal network that have been given a network share (a portion of file space).
  • Finally, one of the things that Nimda has an infected system do is to send an e-mail with a "readme.exe" attachment to the addresses in the local Windows address book. A user who opens or previews this attachment (which is a Web page with the JavaScript) propagates the virus further.

To summarize preventive action:

  • Server adminstrators should get and apply the cumulative IIS patch that Microsoft has provided for previous viruses and ensure that no one at the server opens e-mail.
  • PC users should never open a "readme.exe" attachment sent by e-mail. They should also update their Internet Explorer version to IE 5.5 SP2 or IE 6.0.

To summarize corrective action (if your server is infected):

  • Here we quote TruSecure's Surgeon General Russ Cooper: "If you need to keep it up and running, disconnect it from infection vectors, restore it from tape or reformat and install fresh, then patch it. Restore the data (even if it's infected), run the currently available cleanser, and scan it again with your anti-virus software product. If it passes, reconnect it to the Net and carry on."
  • More ideally, Cooper believes that the server should remain down until a comprehensive cleanser arrives within a few days from one of the anti-virus software vendors such as McAfee or Symantec. He recommends using more than one cleanser to be on the safe side.

To summarize corrective action (for end users):

  • Scan and cleanse your system with anti-virus software.
  • Download the Internet Explorer upgrade.

For details on how the virus behaves and more information about corrective and preventive actions, consult any of the major anti-virus software vendor sites.

Learn more about Malware, Viruses, Trojans and Spyware
Built-in Windows commands to determine if a system has been hacked: Ed Skoudis identifies five useful Windows command-line tools for machine analysis and discusses how they can assist administrators in determining if a machine has been hacked.
More built-in Windows commands for system analysis: Ed Skoudis defines five more useful Windows commands that can provide new insight into the realm of Windows analysis.
Information security book excerpts and reviews: Visit the Information Security Bookshelf for book reviews and free chapter downloads.
Mini guide: How to remove and prevent Trojans, malware and spyware: Organizations need to learn how to implement proper protections and understand best practices for malware defense in order to keep their network environments secure. In this mini guide you will learn ...
Hacker attack techniques and tactics: Understanding hacking strategies: This guide provides you with a plethora of tips, expert advice and Web resources that offer more in-depth information about hacker techniques and various tactics you can employ to protect your ...
Spyware Protection and Removal Tutorial: This spyware protection and removal tutorial is a compilation of free resources that explain what spyware is, how it attacks and what you can to do to win the war on spyware.
Googling Security: How Much Does Google Know About You?: In an excerpt from Googling Security: How Much Does Google Know About You?, author Greg Conti explains how attackers exploit advertising networks to compromise end-user machines.

LAST UPDATED: 20 Sep 2001

Do you have something to add to this definition? Let us know.
Send your comments to techterms@whatis.com

More resources from around the web:
- The official advisory from CERT offers details.
- SearchSecurity.com provides an interview with Jim Reavis, a security expert.
- In "Nimda moving fast, slams brakes on Net," Michael Mimoso interviews TruSecure's Surgeon General Russ Cooper.





FILE EXTENSION AND FILE FORMAT LIST
File Extension and File Format List:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #


RELATED CONTENT
Malware in Google attacks uses spaghetti code
Coding technique designed to tie up reverse engineers has been used in the past, Symantec says.
Preparing for future security threats, evolving malware
Security expert Nick Lewis predicts how infosec threats will evolve in 2010. Luckily, enterprise defenses will evolve, too.
Facebook attacks prompt investments in social networking security
Social networks are opening their wallets in a big way to bolster security teams and install new security technologies to combat attacks.

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bot worm  (SearchSecurity.com)
A bot worm is a self-replicating malware program that resides in current memory, turns infected computers into zombies (or bots) and transmits itself...
directory traversal  (SearchSecurity.com)
Directory traversal is a form of HTTP exploit in which a hacker uses the software on a Web server to access data in a directory other than the...




Get More Nimda Answers
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts