Sorry, I've been reading more about the virus (having seen one of our computers outside the firewall attacked, hopefully contained!) and feel compelled to post yet another warning... (and thanks to the original post to this list that warned me of what was going on.. I spent the latter half of today making sure our network is secure) Anyway, the scariest bit IMHO is that it takes advantage of the auto-execute vulnerability in IE 5.0.. even if you follow all normal warnings about not running attachments or running the .eml file you might encounter on an infected web site, you might still find yourself an unwitting propagator... If you have ie 5.0 on your desktop, you need to make sure you're computer has this update (or ie 5.0 sp2) installed... http://www.microsoft.com/windows/ie/downloads/critical/q290108/default.asp best, Eric P.S. I gather from my reading this virus is attributed/named internally as "Concept Virus(CV) V.5, Copyright(C)2001 R.P.China" I'm going out a limb here perhaps depending on what payload may be discovered in this nasty worm, but: Not that this can at all be attributed to anyone in China, but as I was assuring a Chinese friend earlier, though these clever hacks/attacks by smart Chinese/Taiwanese/US and other young people are costing us money and time, it may even perhaps doing us a favor alerting us of vulnerabilities someone might exploit who is really wanting to do us harm might do and really doing us a favor making us harden our systems... I think I can say that as a (I think pretty good I hope) network administrator working for a small company.. Anyway, this is obviously nothing like an attack that kills people.. I could even envision this as a release by an enlightened 'friendly' (or even our own gov't?) who is just warning us.. let's heed the warning (and hope this present worm is not carrying a destructive payload.) Anyway, thanks Dmitiri.... ----- Original Message ----- From: "Dimitri Rotow" <[EMAIL PROTECTED]> To: "manifold-l" <[EMAIL PROTECTED]> Sent: Tuesday, September 18, 2001 7:43 PM Subject: [Manifold] "nimda" worm/ attacks on servers Hello everyone, This morning a new worm/virus, "nimda", struck the net. It spreads by a variety of means, including sending an attachment called "readme.exe" by email. It also attempts direct attacks on Windows IIS servers. If you have installed the latest Microsoft SPs and hotfixes and are otherwise running a safe and sane IIS web server it will withstand the attacks. This thing is a really nasty beast that all people running web servers should be aware of. See http://www.fsecure.com/v-descs/nimda.shtml for technical details. Following are a) Microsoft's post on this and b) sample text from some as yet unpublished material from the 5.00 user manual topics on the map server. Note that the recommended IIS security measures work fine with Manifold IMS. Cheers, Dimitri --------------------------------------- >From Microsoft: Click this link to read more information about this new worm: http://www.trusecure.com/html/tspub/hypeorhot/rxalerts/tsa01024_cid177.shtml or http:[EMAIL PROTECTED] If you have been infected, please read the following: http://www.cert.org/tech_tips/win-UNIX-system_compromise.html As posted earlier: if you think you may have been infected: 1. remove the Guest account from their local Admins group 2. rename the local admins group 3. make sure Q301625 is installed. You can get this patch here: http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/ bulletin/MS01-044.asp 4. install URLScan (http://www.microsoft.com/technet/security/URLScan.asp) 5. keep checking with your anti-virus manufacturer for an updated signature that will detect and clean the email virus All customers we have worked with so far have not had hotfix Q301625 installed. Having the hotfix installed should have protected you from this virus. More to come soon... --------------------------------------- >From the 5.00 user manual: Security Tips Microsoft IIS is a secure and highly reliable web server when correctly configured by the system administrator. Nonetheless, the many options made available within IIS to support the needs of experts can result in security problems if administered improperly. Because an IIS web server connected to Internet can be attacked by any Internet user from anywhere in the world, a few general IIS security measures should be applied to any web server connected to the Internet. These measures are not specific to Manifold IMS: they should be applied to every web server. We recommend the following elementary steps: � Use Windows 2000 or XP. � Do not allow anyone to work interactively, to read mail or to browse web sites on the machine that hosts your web site. If you must use the same machine interactively, make sure that users do not have Administrator privileges. If a user with Administrator privileges just once opens a malevolent email attachment the web server itself could be infected with a wide variety of "backdoor" viruses or Trojan Horse attacks. Never read email or browse the web when logged in as Administrator. � Install the latest Service Pack for Windows. Service packs include many security patches. � Install any supplemental security patches published by Microsoft after the last Windows Service Pack. Microsoft now has tools that can scan your system to determine if there are security patches published that have not yet been installed. Visit Microsoft TechNet at http://www.microsoft.com/technet/default.asp and drill down to their Security pages for information on the latest security tools and patches. � Install anti-virus software. Keep your anti-virus software updated with regular downloads from your vendor. � Install Microsoft URLScan (a free download from Microsoft TechNet) or similar tool. URLScan is a ISAPI filtering tool for IIS that rejects a wide variety of malformed URL requests before they can hit IIS. It is very easy to use. It was published by Microsoft in 2001 and is an absolutely essential tool to prevent many different types of Denial of Service attacks. No doubt the functions provided by URLScan will continue to be offered by Microsoft either as independent tools or built into IIS. Manifold IMS works perfectly with URLScan. � Apply Microsoft's IIS Lockdown Tool (a free download from Microsoft TechNet) using Advanced Lockdown. Uncheck the box that disables support for Active Server Pages (.asp) and otherwise accept all of the defaults suggested by Advanced Lockdown. Manifold IMS works perfectly with Advanced Lockdown settings so long as Active Server Pages are still enabled. This tool is also very easy to use. � Do not run unnecessary services. If your server runs a web site only, do not install or enable additional services such as FTP, NNTP or others. If such services are already installed, use Internet Services Manager to stop them. Do not install any accessory software or Windows components that are not required. � Learn to use Advanced TCP/IP settings for the Internet Protocol in your Network properties for your network card. If your web site is intended only for specific machines (such as those on an Intranet), use IP security to deny access to any unauthorized machines (IP addresses). If you are connected to Internet, use TCP/IP filtering to permit only those TCP ports absolutely required to service your web site (typically, port 80 for HTTP and port 443 for HTTPS). � If you can afford it, install a firewall and learn to use it. Use a hardware firewall and/or software solution such as Microsoft's Internet Security and Acceleration Server. Hardware firewalls now cost well under $200. � Install the latest updates for Manifold System from manifold.net. � Get a good book on Windows and IIS security. Read it carefully and apply the recommendations. Very important: Although Manifold IMS can work with Microsoft security tools for IIS such as URLScan and the IIS Lockdown Tool, it is possible that other IIS applications installed on your system cannot work with these tools or require modifications to the default settings of these tools. It is critically important to read the documentation for these security tools. _______________________________________________________________________ List hosting provided by Directions Magazine | www.directionsmag.com | To unsubscribe, send e-mail to [EMAIL PROTECTED] and put "unsubscribe MapInfo-L" in the message body.
