FW: Help with Nimda.E?

From: Matt Beck (Mbeck@GiantStep.com)
Date: 11/01/01


Message-ID: <E57972EDA0D5D311BE2F00508B6FC48004CF1E5E@GSMAIL>
From: Matt Beck <Mbeck@GiantStep.com>
To: "'incidents@securityfocus.com'" <incidents@securityfocus.com>
Subject: FW: Help with Nimda.E?
Date: Thu, 1 Nov 2001 10:56:29 -0600 

Hello list,

Sorry to reply to my own message but I wanted to publicly thank all of you
that gave me advice and add an interesting note. You were very helpful.

Also, I located the source of the breach. It turns out that the first
system hit had Code Red II on it. (Apparently it was not properly cleaned
when we went through that problem.) It then got compromised by the new
Nimda and, well...

So once again, my thanks to those of you that replied with help. I'm very
appreciative.

Good luck,
        Matt

-----Original Message-----
From: Matt Beck [mailto:Mbeck@GiantStep.com]
Sent: Wednesday, October 31, 2001 1:30 PM
To: 'incidents@securityfocus.com'
Subject: Help with Nimda.E?

Hello all,

I haven't determined how yet, but one system on my dmz was unpatched. Of
course, it got hit by Nimda.e. This new variant is now propagating like mad
through the shares.

Given the nature of the environment, I am having trouble containing and
removing it. Any suggestions? I have 50+ NT/2k servers on the dmz LAN.
There is a master domain that all other domains trust. Servers in each
domain require shares to function. Permissions are highly entangled. All
servers (but one apparently) are patched against the IIS vulnerability, but
the shares remain open.

I have tried Symantec's new scanner and the web A/V tool at antivirus.com,
but neither seem to get it all. As soon as someone logs in to the "clean"
box, snort detects outbound attacks. I am shutting down all non-essential
systems, but some are going to have to keep running.

Please contact me off list for more details or on list with solutions.

Thanks,
        Matt

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: New version of Code Red?
    ... web logs on our apache servers showed a single similar entry on ... each of those servers e.g.. ... > For more information on this free incident handling, management ... > and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • Re: Help with Nimda.E?
    ... I have 50+ NT/2k servers on the dmz LAN. ... > domain require shares to function. ... > For more information on this free incident handling, management ... > and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • RE: <victim>server formmail.pl exploit in the wild
    ... In the past 2 weeks I've had several of my web hosting servers hit with this ... For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • Re: Increased activity on UDP/1434
    ... It is an MsSql Worm spreading very fast. ... Blocking UDP/1434 and patching Sql2000 servers that have public IP's ... For more information on this free incident handling, management ... and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • RE: Betr.: Re: MS Patches Management software: SUS vs 3rd party
    ... We are also currently looking at a solution for updating our clients and servers. ... The major drawback is that if a new unpatched client connects to it, it retrieves all patches at once. ... There is no management in SUS, ... >The Presidio integrates PGP data encryption and XML Web Services security to ...
    (Security-Basics)

Loading