19 Sep 2001
Millions of internet surfers are in danger from a virus currently spreading much more rapidly than Code Red, security experts warned today.
The self propagating worm, known as Nimda, which spells admin backwards, is particularly virulent as it can spread through email attachments, shared hard disks inside networks, or across HTTP.
It is doubly dangerous as it attacks both PCs and servers running Microsoft software.
An alert by TruSecure, which discovered the worm, said the rate of growth and spread is exceedingly rapid, significantly faster than any worm to date and significantly faster than any variant of Code Red.
TruSecure pointed out that Nimda sends itself by e-mail, as SirCam does, and also scans for and infects web servers like Code Red does.
When Nimda, which is known to affect all 32-bit Window systems including Windows 98, 2000, ME and NT, arrives in email, it appears as an attachment named readme.exe.
"This worm bites you right on the nose, you can get stung by browsing the internet or by opening an infected email," said Graham Cluley, senior technology consultant, Sophos Anti-Virus. An FBI representative said the agency was "assessing the incident", but so far it found no relationship between the online attack and last week's US terrorist attacks.
Security firm Panda software said: "W32/Nimda.A@mm (alias Nimda) is a dangerous mass-mailing worm that runs automatically when the message that contains it is viewed through the preview pane.
It spreads by e-mail by means of a vulnerability in Internet Explorer 5 and the email clients Outlook and Outlook Express.
According to Panda the vulnerability has two main characteristics: it uses HTML code to generate a frame together with an attachment coded in Base64, marked as audio/x-wav. Both actions trick the Internet Explorer component which offers browser services to Microsoft's e-mail clients.
Antivirus specialist, McAfee said the worm attacks 16 known vulnerabilities in Internet Information Services (IIS) servers, including the security hole left by the recent Code Red II worm.
Experts at McAfee added that, using the vulnerability in Microsoft's IIS web server software, the worm corrupts websites with malicious code.
The worm then forwards itself by email to all addresses found on the user's computer.
Infected Web sites may also display a Web page prompting users to download an Outlook file containing the Nimda worm.
Experts said Nimda had appeared in Europe, Latin America and the US and was likely to spread to additional regions.
Have your say on this article
Newsletters
Latest stories from Hacking
Latest videos
You may also like
Hacking jobs
Technology Patent Wars
Case studies from large organisations across all sectors
... And rich media, and flexible working, and peaks in traffic ...
Upcoming Events
Join us for this Computing web seminar, in which the Head of BI at the Co-operative Group Nick Colebourn will be explaining just how he reigned in the Group’s sprawling database estate and how significant savings were realised and data quality improved as a result.
Date: 31 May 2012
Time: 11:00 AM
Live June 13th 11:00am: Register now. During this web seminar we will be looking at the sorts of incidents that can bring data centres grinding to a halt and what can be done about them.
Date: 13 Jun 2012
Time: 11:00 am
Receive the latest jobs direct to your inbox
Are you being paid what you are worth?