📄 1290.txt
字号:
Rule: --Sid:1290--Summary:This event is generated when an attempt is made to load and runreadme.eml, which is used as an infection vector for the nimda worm.--Impact:The source address is likely infected with the Nimda worm. Thedestination, without adequate AntiVirus protection and the properpatches, may now be infected and may attempt to infect other hosts usingthis or any of the other infection vectors that the Nimda worm uses.--Detailed Information:The nimda worm affects Microsoft Windows systems and attempts to spreadvia email, network shares and Microsoft IIS servers. A compromisedserver will attempt to spread and infect other vulnerable hosts.--Affected Systems: Microsoft Windows 95, 98, ME, NT and 2000 --Attack Scenarios:This is worm activity.--Ease of Attack:Simple. Nimda is a worm, so the attack is automated. Exposure of unprotectedsystems to the internet has been know to result in an infection within15 minutes.--False Positives:None KnownWeb pages containing the Javascript as text in a web page may activatethis alert. Web-sites detailing Nimda infection vectors may also trigger this event.--False Negatives:Nimda has multiple infection vectors. This rule alone will only detecta particular type.--Corrective Action:Ensure all servers within your domain are protected to the appropriatepatch-levels to mitigate infection and spread of the Nimda worm.Ensure network clients in your domain are also appropriately patched and arerunning up to date AntiVirus software.--Contributors:Original rule writer unknownSnort documentation contributed by Giles Coochey and Josh GraySourcefire Vulnerability Research TeamNigel Houghton <nigel.houghton@sourcefire.com>-- Additional References:CERT:http://www.cert.org/advisories/CA-2001-26.htmlCisco:http://www.cisco.com/warp/public/cc/so/cuso/epso/sqfr/snam_wp.htmMicrosoft:http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/topics/Nimda.asphttp://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/topics/NimdaIE6.aspSecurityFocushttp://online.securityfocus.com/archive/75/215118--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -