Re: weird Windows 2000/XP bug

From: Blue Boar (BlueBoar@thievco.com)
Date: 10/30/01


Date: Tue, 30 Oct 2001 09:45:02 -0800
From: Blue Boar <BlueBoar@thievco.com>
Subject: Re: weird Windows 2000/XP bug
To: Rodrigo Goya <lucent@securenet.com.mx>
Message-id: <3BDEE71E.972AC997@thievco.com>

Rodrigo Goya wrote:
>
> What if something like this would be used in a worm like Nimda or CodeRed,
> would it crash all the infected servers? Bet that'd really call the admin's
> attention. Though it'd make the propagation a little difficult...
>
> Maybe by infecting mail clients (like Nimda) and make them scan for web
> servers and crash them?

I *think* Nimda and CodeRed end up with enough privilege to simply
issue a reboot command if they want. As I recall, CodeRed II
does reboot after a while, which gets rid of any CodeRed I running.

                                                BB