The Haus

Tuesday, September 18, 2001

New Worm Spreading

Slashdot is alerting people about a new worm spreading around. It appears to be a variant/mutation/update of CodeRed. Among other things, it attaches a file called "readme.eml" to every page the infected web server serves. Thanks to some problem with Internet Explorer, the readme.eml file is automatically executed on clients. This is going to be a mess.

UPDATE! I just talked with Crawl at EZ-Net and he confirmed that their servers have been attacked by this worm but not compromised. He reported around 500 attempts since around 9:00 A.M. That's the other sickening thing about this worm: it appears that it may have been set to "go off" at 8:42 this morning, exactly a week after the first attack on the World Trade Center.

UPDATE #2! This worm has a name: Nimda. Check out TruSecure for more information. According to them, it is NOT a Code Red variant, although the means of attack it uses are similar. It only affects IIS servers. It tries several different exploits, but you should be OK if your box is patched up-to-date.

This worm can also spread by opening an email attachment called readme.exe which is sent with a WAV file mime type. DO NOT RUN IT! If you receive email with that attachment delete it immediately.

News for 09/18/2001

Recent Headlines

January 5, 2015: It Returns!
August 10, 2007: SCO SUCKS IT DOWN!
July 5, 2007: Slackware 12.0 Released
May 20, 2007: PhpBB 3.0 RC 1 Released
February 2, 2007: DOOM3 1.31 Patch

January 27, 2007: Join the World Community Grid
January 17, 2007: Flash Player 9 for Linux
December 30, 2006: Darkness over Daggerford 1.2
December 19, 2006: Pocket Tunes 4.0 Released
December 9, 2006: WRT54G 1.01.1 Firmware OK with Linux/Mac

All original information on this website is copyright © TheHaus.Net, 1999-2005. The use of original images, text, and/or code from this website without expressed written consent is prohibited. The authors of this site cannot be held responsible for any damage, real or imagined, which comes from the use of information presented on this site. All trademarks used are the properties of their respective owners. This site is not to be used as a floatation device (but if you try, I want a video tape of it).