Re: Nimda


Subject: Re: Nimda
From: Robert Brandtjen (rob@prometheusmedia.com)
Date: Fri Sep 21 2001 - 13:49:10 MDT


on 9/21/01 2:35 PM, Brian Watson at bcwatso1@uiuc.edu wrote:

> Does anyone have a good nimda script? my access log has over 14k
> lines of nimda attempts in the past two days!! :(
>
> --Brian

Use that script I gave you and change it's name to that of cmd.exe and place
it in a pseudo that the infected machine is looking for.

You will have to add cmd.exe to the .cg .pl .ida list.

It should perform the same function as when it requests the .ida file, as
the nimda machines are infected with CR.

 Robert Brandtjen
 --------------------------------------
 Web Site Creation and Hosting Services
 Hostmaster@prometheusmedia.com
 www.prometheusmedia.com



This archive was generated by hypermail 2a24 : Fri Sep 21 2001 - 12:59:06 MDT