Security Incidents mailing list archives
RE: nimda tries to send mail after reboot
From: "Lists" <lists () acros si>
Date: Wed, 19 Sep 2001 21:40:38 +0200
Brett,
Sadly, the copies of the worm we're receiving are coming from companies whose employees we'd expect to know better than to leave machines unprotected -- such as V-One and SCO.
It was noted before by someone, and witnessed by myself, that Nimda employs spoofing of sender's address. Yesterday I received a Nimda copy that was *sent by myself* (which of course raised my suspicion). A few minutes later I got a reply from McAfee ASAP Support which is an auto-replying mailbox - apparently Nimda sent itself to at least two addresses (but I'll assume there were more), pretending to be me. So let's not assume someone has a badly secured machine just because he/she is the apparent sender - more likely it means that someone with the apparent sender's address in address book is a little behind on security. Regards, Mitja Kolsek ACROS, d.o.o. Stantetova 4, SI - 2000 Maribor, Slovenia web: http://www.acros.si e-mail: mitja.kolsek () acros si ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
Current thread:
- nimda tries to send mail after reboot John Q. Public (Sep 18)
- Re: nimda tries to send mail after reboot John Q. Public (Sep 18)
- Re: nimda tries to send mail after reboot Paul Seaman (Sep 18)
- Message not available
- Re: nimda tries to send mail after reboot Brett Glass (Sep 18)
- Re: nimda tries to send mail after reboot John Q. Public (Sep 18)
- RE: nimda tries to send mail after reboot Don Weber (Sep 18)
- RE: nimda tries to send mail after reboot Jim Forster (Sep 18)
- Re: nimda tries to send mail after reboot Brett Glass (Sep 18)
- Re: nimda tries to send mail after reboot John Q. Public (Sep 18)
- <Possible follow-ups>
- Re: nimda tries to send mail after reboot Brett Glass (Sep 19)
- RE: nimda tries to send mail after reboot Lists (Sep 19)
- Re: nimda tries to send mail after reboot Michael H. Warfield (Sep 19)
- RE: nimda tries to send mail after reboot Andrew Mulholland (Sep 19)
