RE: New worm? 'readme.eml'
From: JKruser (jkruser@adelphia.net)Date: 09/18/01
- Previous message: JKruser: "RE: New worm? 'readme.eml'"
- Maybe in reply to: JKruser: "RE: New worm? 'readme.eml'"
- Next in thread: Guillaume TARRARE: "RE: New worm? 'readme.eml'"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "JKruser" <jkruser@adelphia.net> To: "Pedro Miller Rabinovitch" <pedro@cipher.com.br>, <forensics@securityfocus.com> Subject: RE: New worm? 'readme.eml' Date: Tue, 18 Sep 2001 13:07:14 -0400 Message-ID: <NDBBJDPCMMJOCGOGCHPHCEKMEGAA.jkruser@adelphia.net>
I also see a very serious possibility of this work interacting with the
still prevalent sircam virus. Nimda, when it infects, opens share drives on
the infected PC...Sircam will scan for open shares on an internal network or
cable subnet and infect the remote PC without user interaction. This could
effectively increase the spread of sircam exponentially and, due to the
remailing capability of sircam, could shut down mail servers in a short
period of time.
I have not verified this possibility but it sounds feasible.
Claymore
the unprofound
- Previous message: JKruser: "RE: New worm? 'readme.eml'"
- Maybe in reply to: JKruser: "RE: New worm? 'readme.eml'"
- Next in thread: Guillaume TARRARE: "RE: New worm? 'readme.eml'"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|