sos5.1.0
high
This signature detects the V variant of the NetSky worm.
The V variant encodes a malicious HTML script in the body
of an e-mail sent to the target host. Due to a known
vulnerability, Microsoft Outlook and Outlook Express process
the encoded script when the e-mail appears in the preview
pane (the e-mail does not need to be opened). The script
downloads the NetSky worm from known Internet sites and
installs the worm on the target host.
WORM:NETSKY:V-SMTP-PROP
sos5.0.0,
sos5.1.0
medium
This signature detects attempts to infect a Microsoft IIS Web
server with the Nimda worm. Nimda may infect other Web
servers by obtaining e-mail addresses and sending a copy
of itself in infected messages using its own SMTP or POP3
server; adding files to a system configured to allow Windows
file shares; or posting an infected HTML e-mail to the Web
server where it can be accessed via HTTP.
WORM:NIMDA:BIN-255-CMD
sos5.0.0,
sos5.1.0
medium
This signature detects attempts to infect a Microsoft IIS Web
server with the Nimda worm. Nimda may infect other Web
servers by obtaining e-mail addresses and sending a copy
of itself in infected messages using its own SMTP or POP3
server; adding files to a system configured to allow Windows
file shares; or posting an infected HTML e-mail to the Web
server where it can be accessed via HTTP.
WORM:NIMDA:MSADC-ROOT
sos5.1.0
medium
This signature detects attempts to create .EML files on the
system, a common sign of the NIMDA worm. The worm
browses remote directories and creates .EML files (the
worm's multi-part messages containing a MIME-encoded
worm) with the same names as existing documents or Web
page files.
WORM:NIMDA:NIMDA-EML
sos5.1.0
medium
This signature detects attempts to create a .NWS file on the
system, a common sign of the NIMDA worm. The worm
browses remote directories and creates .NWS files (the
worm's multi-part messages containing a MIME-encoded
worm) with the same names as existing documents or Web
page files.
WORM:NIMDA:NIMDA-NWS
sos5.1.0
high
This signature detects attempts to create the file
RICHED20.DLL on the system, a common sign of the NIMDA
worm. The worm may overwrite the original RICHED20.DLL
in the Windows systems folder with a binary copy of itself,
and place additional copies in all folders containing .DOC or
.EML files.
WORM:NIMDA:NIMDA-RICHED20
sos5.0.0,
sos5.1.0
medium
This signature detects attempts to infect a Microsoft IIS Web
server with the Nimda worm. Nimda may infect other Web
servers by obtaining e-mail addresses and sending a copy
of itself in infected messages using its own SMTP or POP3
server; adding files to a system configured to allow Windows
file shares; or posting an infected HTML e-mail to the Web
server where it can be accessed via HTTP.
WORM:NIMDA:SCRIPTS-C11C-CMD
Copyright © 2010, Juniper Networks, Inc.
938
Network and Security Manager Administration Guide
Содержание NETWORK AND SECURITY MANAGER 2010.3
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Страница 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Страница 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 94 Network and Security Manager Administration Guide...
Страница 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Страница 234: ...Copyright 2010 Juniper Networks Inc 184 Network and Security Manager Administration Guide...
Страница 310: ...Copyright 2010 Juniper Networks Inc 260 Network and Security Manager Administration Guide...
Страница 364: ...Copyright 2010 Juniper Networks Inc 314 Network and Security Manager Administration Guide...
Страница 366: ...Copyright 2010 Juniper Networks Inc 316 Network and Security Manager Administration Guide...
Страница 478: ...Copyright 2010 Juniper Networks Inc 428 Network and Security Manager Administration Guide...
Страница 576: ...Copyright 2010 Juniper Networks Inc 526 Network and Security Manager Administration Guide...
Страница 580: ...Copyright 2010 Juniper Networks Inc 530 Network and Security Manager Administration Guide...
Страница 592: ...Copyright 2010 Juniper Networks Inc 542 Network and Security Manager Administration Guide...
Страница 684: ...Copyright 2010 Juniper Networks Inc 634 Network and Security Manager Administration Guide...
Страница 690: ...Copyright 2010 Juniper Networks Inc 640 Network and Security Manager Administration Guide...
Страница 696: ...Copyright 2010 Juniper Networks Inc 646 Network and Security Manager Administration Guide...
Страница 698: ...Copyright 2010 Juniper Networks Inc 648 Network and Security Manager Administration Guide...
Страница 748: ...Copyright 2010 Juniper Networks Inc 698 Network and Security Manager Administration Guide...
Страница 778: ...Copyright 2010 Juniper Networks Inc 728 Network and Security Manager Administration Guide...
Страница 870: ...Copyright 2010 Juniper Networks Inc 820 Network and Security Manager Administration Guide...
Страница 872: ...Copyright 2010 Juniper Networks Inc 822 Network and Security Manager Administration Guide...
Страница 898: ...Copyright 2010 Juniper Networks Inc 848 Network and Security Manager Administration Guide...
Страница 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Страница 910: ...Copyright 2010 Juniper Networks Inc 860 Network and Security Manager Administration Guide...
Страница 995: ...PART 6 Index Index on page 947 945 Copyright 2010 Juniper Networks Inc...
Страница 996: ...Copyright 2010 Juniper Networks Inc 946 Network and Security Manager Administration Guide...