[Esd-l] Fw: New Virus/Worm email

John D. Hardin jhardin at impsec.org
Tue Sep 18 21:14:01 PDT 2001

On Tue, 18 Sep 2001, Jeffrey S. Gavin wrote:

> I've read that this particular worm (W32.Nimda.A at mm) will try to
> download itself when a user visits a compromised web server.  More info
> can be found at:
> http://securityresponse.symantec.com/avcenter/venc/data/w32.nimda.a@mm.html

I posted this to the dshield mailing list. Here it is if anyone finds it useful...

Squid ACLs to hopefully prevent this attack on your users:

In /etc/squid.conf:

   acl POISONEDURL  url_regex -i "/etc/squid/URL-Blacklist"
   http_access deny POISONEDURL

In /etc/squid/URL-Blacklist:


Whenever URL-Blacklist changes, poke squid with "squid -k reconfigure"

NB: The firewall protecting my company's Class C was logging three to
five attacks *per second* this afternoon. It's not logging them any
longer, as the system load was simply too much for that little box.

