Sorry, I've been reading more about the virus (having seen
one of our computers outside the firewall attacked, hopefully
contained!) and feel compelled to post yet another warning...

(and thanks to the original post to this list that warned me of
what was going on.. I spent the latter half of today making sure
our network is secure)

Anyway, the scariest bit IMHO is that it takes advantage of
the auto-execute vulnerability in IE 5.0.. even if you follow
all normal warnings about not running attachments or running
the .eml file you might encounter on an infected web site, you
might still find yourself an unwitting propagator...

If you have ie 5.0 on your desktop, you need to make sure
you're computer has this update (or ie 5.0 sp2) installed...
http://www.microsoft.com/windows/ie/downloads/critical/q290108/default.asp

best,
Eric

P.S. I gather from my reading this virus is attributed/named internally
as "Concept Virus(CV) V.5, Copyright(C)2001  R.P.China"

I'm going out a limb here perhaps depending on what payload may be
discovered in this nasty worm, but:

Not that this can at all be attributed to anyone in China, but as I was assuring
a Chinese friend earlier, though these clever hacks/attacks by smart
Chinese/Taiwanese/US and other young people are costing us money and
time, it may even perhaps doing us a favor alerting us of vulnerabilities
someone might exploit who is really wanting to do us harm might do and
really doing us a favor making us harden our systems... I think I can say
that as a (I think pretty good I hope) network administrator working for a
small company..

Anyway, this is obviously nothing like an attack that kills people.. I
could even envision this as a release by an enlightened 'friendly' (or
even our own gov't?) who is just warning us.. let's heed the warning
(and hope this present worm is not carrying a destructive payload.)
Anyway, thanks Dmitiri....

----- Original Message -----
From: "Dimitri Rotow" <[EMAIL PROTECTED]>
To: "manifold-l" <[EMAIL PROTECTED]>
Sent: Tuesday, September 18, 2001 7:43 PM
Subject: [Manifold] "nimda" worm/ attacks on servers


Hello everyone,

This morning a new worm/virus, "nimda", struck the net. It spreads by a
variety of means, including sending an attachment called "readme.exe" by
email.  It also attempts direct attacks on Windows IIS servers.  If you have
installed the latest Microsoft SPs and hotfixes and are otherwise running a
safe and sane IIS web server it will withstand the attacks.

This thing is a really nasty beast that all people running web servers
should be aware of.  See http://www.fsecure.com/v-descs/nimda.shtml for
technical details.

Following are a) Microsoft's post on this and b) sample text from some as
yet unpublished material from the 5.00 user manual topics on the map server.
Note that the recommended IIS security measures work fine with Manifold IMS.

Cheers,

Dimitri


---------------------------------------

>From Microsoft:

Click this link to read more information about this new worm:

http://www.trusecure.com/html/tspub/hypeorhot/rxalerts/tsa01024_cid177.shtml
or
http:[EMAIL PROTECTED]

If you have been infected, please read the following:

http://www.cert.org/tech_tips/win-UNIX-system_compromise.html

As posted earlier:
if you think you may have been

infected:

1. remove the Guest account from their local Admins group

2. rename the local admins group

3. make sure Q301625 is installed. You can get this patch here:


http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/

bulletin/MS01-044.asp

4. install URLScan (http://www.microsoft.com/technet/security/URLScan.asp)

5. keep checking with your anti-virus manufacturer for an updated

signature that will detect and clean the email virus

All customers we have worked with so far have not had hotfix Q301625

installed. Having the hotfix installed should have protected you from this

virus.

More to come soon...

---------------------------------------

>From the 5.00 user manual:

Security Tips

Microsoft IIS is a secure and highly reliable web server when correctly
configured by the system administrator.  Nonetheless, the many options made
available within IIS to support the needs of experts can result in security
problems if administered improperly.  Because an IIS web server connected to
Internet can be attacked by any Internet user from anywhere in the world, a
few general IIS security measures should be applied to any web server
connected to the Internet.   These measures are not specific to Manifold
IMS: they should be applied to every web server.

We recommend the following elementary steps:

� Use Windows 2000 or XP.
� Do not allow anyone to work interactively, to read mail or to browse web
sites on the machine that hosts your web site.  If you must use the same
machine interactively, make sure that users do not have Administrator
privileges.  If a user with Administrator privileges just once opens a
malevolent email attachment the web server itself could be infected with a
wide variety of "backdoor" viruses or Trojan Horse attacks.  Never read
email or browse the web when logged in as Administrator.
� Install the latest Service Pack for Windows.  Service packs include many
security patches.
� Install any supplemental security patches published by Microsoft after the
last Windows Service Pack.  Microsoft now has tools that can scan your
system to determine if there are security patches published that have not
yet been installed.  Visit Microsoft TechNet at
http://www.microsoft.com/technet/default.asp and drill down to their
Security pages for information on the latest security tools and patches.
� Install anti-virus software.  Keep your anti-virus software updated with
regular downloads from your vendor.
� Install Microsoft URLScan (a free download from Microsoft TechNet) or
similar tool.  URLScan is a ISAPI filtering tool for IIS that rejects a wide
variety of malformed URL requests before they can hit IIS. It is very easy
to use.  It was published by Microsoft in 2001 and is an absolutely
essential tool to prevent many different types of Denial of Service attacks.
No doubt the functions provided by URLScan will continue to be offered by
Microsoft either as independent tools or built into IIS.  Manifold IMS works
perfectly with URLScan.
� Apply Microsoft's IIS Lockdown Tool (a free download from Microsoft
TechNet) using Advanced Lockdown.  Uncheck the box that disables support for
Active Server Pages (.asp) and otherwise accept all of the defaults
suggested by Advanced Lockdown.   Manifold IMS works perfectly with Advanced
Lockdown settings so long as Active Server Pages are still enabled.  This
tool is also very easy to use.
� Do not run unnecessary services.  If your server runs a web site only, do
not install or enable additional services such as FTP, NNTP or others.  If
such services are already installed, use Internet Services Manager to stop
them.  Do not install any accessory software or Windows components that are
not required.
� Learn to use Advanced TCP/IP settings for the Internet Protocol in your
Network properties for your network card.   If your web site is intended
only for specific machines (such as those on an Intranet), use IP security
to deny access to any unauthorized machines (IP addresses).  If you are
connected to Internet, use TCP/IP filtering to permit only those TCP ports
absolutely required to service your web site (typically, port 80 for HTTP
and port 443 for HTTPS).
� If you can afford it, install a firewall and learn to use it.  Use a
hardware firewall and/or software solution such as Microsoft's Internet
Security and Acceleration Server.  Hardware firewalls now cost well under
$200.
� Install the latest updates for Manifold System from manifold.net.
� Get a good book on Windows and IIS security.  Read it carefully and apply
the recommendations.

Very important: Although Manifold IMS can work with Microsoft security tools
for IIS such as URLScan and the IIS Lockdown Tool, it is possible that other
IIS applications installed on your system cannot work with these tools or
require modifications to the default settings of these tools.   It is
critically important to read the documentation for these security tools.





_______________________________________________________________________
List hosting provided by Directions Magazine | www.directionsmag.com |
To unsubscribe, send e-mail to [EMAIL PROTECTED] and
put "unsubscribe MapInfo-L" in the message body.

Reply via email to