1 Year Anniversary of Nimda Outbreak
dots and loops writes "Today marks one year to the date that the nimda
worm began making its way across the Internet." Hey, speaking of hilarious worms, I'm still getting 5-10 klez virus's a day! Yay Security!
If anybody is interested, I've developed WormScan last year, which is a Java-based program (GPL) which can analyze your Apache log files for pretty much anything you want (just plug in your regular expressions). It detects Nimda and CR1+2 out of the box. It's easy to add your own entries to scan for.
According to my logs (please be gentle), I've been hit 650 times yesterday.
Shameless plug, yes. But it does the job and the users of WormScan seem to be pretty happy with it, judging from the emails I've gotten so far.
You can accomplish anything you set your mind to. The impossible just takes a little longer.
Where did I put my hard hard? I think I might be needing it.
Never email donotemail@WeAreSpammers.com
No doubt in celebration of the birthday, I got a number of nimda hits this morning.
//xx.xx.xx.xx/C$ /mnt/dork /mnt/dork/boot.ini
/mnt/dork
mount -t smbfs password=
vi
Change the boot delay to some huge number and the boot message to "Run a virus scanner, asshole".
umount
-- Will program for bandwidth
Here's one I just got;
Do you think this was sent by webmaster@msn.com? (I hear the jokes now!). In this case, the Return-path actually contained the victim's full mail address, which I've mercifully blankedAlison
"It is a miracle that curiosity survives formal education." - Albert Einstein