Funny Nimda story

calpha

Golden Member
Mar 7, 2001
1,287
0
0
For those that don't know....Nimda was and is one of the worst viruses to hit. I actually got infected w/ it by going to a site that supposedly tested for if you were vulnerable to Nimda. The site itself was infected. And to make matters worse, even though my Norton was updated to the current date of my test--the virus def's hadn't yet included Nimda yet. So about a week later, I got some corrupt files, and I went to Panda's testing website, adn found out I had been killed. Not only that but my server, and all my installation scripts were fubarred. Can you say----no backup. I ought a tape backup the next day. I also quit using Norton for good based on that, and went w/ Panda ever since.

Well, about a month later ( I used to have a static IP and host a support website at home)....I noticed my IIS Server was getting hammered by an IP in the same subnet as my ISPs. I mean getting rocked. And when I checked the logs, I could tell it was a Nimda attack. (all the _vti_prvt calls....). After finding the ISP of the guy was my isp (road runner)...>I emailed road runner to inform them. A few days later, the ppl I support started complaining that they couldn't access my website---and again I found out it was the same IP that was hammering me. So, by this time, I had read up on nimda, and knew that it gave admin privelages to the Guest account.

So---as a guess---I figured the os was w2k----I just browsed to the IP Address/C$---and used guest as the login and it worked. So---I just left a note (.txt) for him on his desktop explaining his computer was unknowingly attacking me----and that he had Nimda. I also included a link for the latest online scanners to detect it, as well as a link for the Nimda fix from Panda. 2 days later the attacks from his IP was over.

I didn't browse his computer-----I merely went straight for the all users/desktop folder and left the text file in there. But can you imagine waking up one morning to find a text document that you hadn't created with the words--'YOU HAVE A VIRUS.txt". I even left him my hotmail account but he never emailed me. Anyway---it still makes me laugh----but also, I use it as a constant reminder just how f'd up you can get if you don't update Winders, Patch your servers---and make sure you have the latest virus definitions. I was and am still blown away that that virus opened up your computer that bad.

Anyway---jsut thought I'd share. A few days later, I was getting hammered again by a diff't IP, and it made me drop my static ip and move my support web site to a host.....I'm glad I don't work on servers---especially M$ft servers---but Linux servers as well. It's got to be a tough job to keep a big site up and runing right----especially with som many infected computers just hammering your IP looking for exploits.
 

Spyro

Diamond Member
Dec 4, 2001
3,366
0
0
Nice story :)

Interesting that he never emailed you back to complained about your intrusion =)
 

chiwawa626

Lifer
Aug 15, 2000
12,013
0
0
I havent got a virus in over 5 years. I dont use a virus protector/scan on a regular basis either.
 

SarcasticDwarf

Diamond Member
Jun 8, 2001
9,574
2
76
Originally posted by: chiwawa626
I havent got a virus in over 5 years. I dont use a virus protector/scan on a regular basis either.

ditto, I have never once gotten a virus


*crosses fingers*
 

yoda291

Diamond Member
Aug 11, 2001
5,079
0
0
I always thought it strange that if you talk to most competent network admins about nimda and code red, they say "yeah, that was rough" or the equivalent. The second you mention the dancing baby, they go into convulsions.
 

MrHappyMonkey

Diamond Member
Mar 15, 2001
3,091
0
0
speaking of nimba, I have a machine that is infected with it. What is the easiest/safest way to remove it? Norton says it can't fix it.
 

NewSc2

Diamond Member
Apr 21, 2002
3,325
2
0
Originally posted by: DeathByAnts
Originally posted by: chiwawa626
I havent got a virus in over 5 years. I dont use a virus protector/scan on a regular basis either.

ditto, I have never once gotten a virus


*crosses fingers*

got one once, and I don't know how. Norton cleaned it up fine.
 

Barnaby W. Füi

Elite Member
Aug 14, 2001
12,343
0
0
Never used virus software, never got a virus. Honestly, IMO, if you get a virus, it's your own dumbass fault. It's easy to avoid them.

Not meant as an insult, that's just how I feel about it.
 

calpha

Golden Member
Mar 7, 2001
1,287
0
0
Originally posted by: BingBongWongFooey
Never used virus software, never got a virus. Honestly, IMO, if you get a virus, it's your own dumbass fault. It's easy to avoid them.

Not meant as an insult, that's just how I feel about it.

When Code Red first hit---- there were a lot of non-patched servers that were the culprit. I dont' remember if the Nimda virus was just a Code Red Exploit, nor do I remember the timing of Code Red vs Microsoft's release of the patch to fix it for IIS. I can't say for sure whether or not a major virus attack has occurred before m$ft released a major patch to fix a whole...but I know that some of them have come at the same time. Not long after Code Red, there was Code Red II.

Nimda taught me an important lesson. Previously---I had never installed virus software since I was always behind a firewall---and only port 80 was open to a IIS Server. But, when I got Nimda---it got every machine I had...becaus I was simply unaware of how Nimda would propagate. I downloaded symantec's tool---and a few days later, I had it again. Then I blew all machines away and went to backup.

The important lesson I learned is that a large majority of the need for virus software can be avoided by intelligent use and patching----however---if in the case that you do get hit with something, have a lan wide virus solution will greatly reduce the impact of it (of course that's based on the effectiveness of your virus software---why I use panda now)....

But anyway---needless to say, I don't go to websites taht check your vulnerabilities anymore. I just do a scheduled task for hfnetchk every day, and read it's output when I first log on.