午夜福利1000集合

“Nimda” computer worm deploys many weapons

The worm attacks web servers, desktop computers and networks and is causing serious slow down in performance

A new hybrid computer worm combines a range of tricks to attack web servers, desktop computers and computer networks.

The worm has already infected hundreds of machines in the US and Asia. Although it does not cause damage to its host, IT consultants say it could significantly slow down computer networks.

The worm is called Nimda, which backwards reads 鈥淎dmin鈥, the nickname for a system administrator. But it has also been dubbed the Swiss army knife of computer worm鈥檚 because it combines 16 different techniques in order to spread.

鈥淲e haven鈥檛 seen a widespread virus that combines all these things before,鈥 says Graham Cluley, senior security consultant for anti-virus company Sophos. 鈥淚t鈥檚 a pretty nasty combination, and I think that鈥檚 why it has spread so fast.鈥

Its worst side effect could be that it creates new accounts on a machine with full administrative permissions, says Cluley. This could open the door to intruders who could cause more damage, he says.

Box of tricks

Nimda relies on known software vulnerabilities in software manufactured by Microsoft. It relies on four main methods.

The worm automatically searches the internet for web servers running Microsoft Internet Information Server with a known security bug. Once installed on an unguarded machine, it also tries to infect desktop machines through the local network. It does this by copying itself to shared network drives.

Nimda also performs the familiar trick of sending itself on to any email addresses it can find. It uses another bug in Microsoft software to execute automatically when it lands in a victim鈥檚 in-box. The worm is reported to use the same trick to infect those who visit pages hosted on an infected web server by automatically downloading itself.

Alex Shipp, chief anti-virus technologist for virus detection firm MessageLabs, says that the complexity of the worm will escalate the cost of recovery. 鈥淚t鈥檚 going to be quite difficult to make sure you have cleaned everything, 鈥 Shipp told New Scientist.

Despite the worm鈥檚 lack of a destructive payload, many web servers running IIS have been bombarded with levels of traffic that could block out regular visitors, according to US monitoring company Matrix.net. The worm performs ten-times as many network searches as the Code Red worm, which received unprecedented attention from US law enforcement agencies in August.

More from New Scientist

Explore the latest news, articles and features