(Courriels de diversion: <epaula@violentees-combinais.com> <reinvesti@amadouerait-depeigne.com> <rodailler@agrement-crachez.com> <inexpliques@versees-recensera.com> <pavanerait@peuplerions-entêterais.com> <ballets@constants-gronderais.com> <apprêterai@bricole-craindrions.com> <suffocations@bifurquerez-calligraphiant.com> <persevererions@sertissiez-bloqueront.com> <edifierez@media-financee.com> )


les versions sensibles à nimda

----------  Message transmis  ----------
Subject: Re: [suse-security] Nimda Worm - BugTraq
Date: Thu, 20 Sep 2001 08:57:41 +0200
From: "Milan Goellner" <milan.goellner@compu-shack.com>To: <suse-security@suse.com>

>** is that true ? the readme executes without being explicitly opened?
>**
>** thank
>
>yes it's true
>also it can getcha if you go tot a webpage that has been haxored by
>these guys...  all w/o your permission or even knowledge ( i.e. it
>doesn't ask it just does it )

Only when using IE5.x without SP2 for any of the IE5.x Versions though.
IE5.x's with their respective SP2s, IE4 and IE6 ask the user whether he/she
 would like to open or execute the javascript which gets you your personal
 copy of Nimda. The same principal applies to your readme.exe in your mail
 ... IE5.x without SP2 simply executes, all other IE's ask. If the user now
 hits YES ... you'll end up with some major extra hours cleaning your
 systems.


Mit freundlichen Grüßen / Kind Regards

Milan Goellner
Network Technician

----------------------------------------------------------------
Compu-Shack Electronic GmbH
Ringstrasse 56-58
56564 Neuwied
Germany

Telefon             +49/(0) 26 31-9 83-962
Email                 milan.goellner@compu-shack.com                         http://www.compu-shack.com


--
To unsubscribe, e-mail: suse-security-unsubscribe@suse.comFor additional commands, e-mail: suse-security-help@suse.com
-------------------------------------------------------

-- 
<http://www.dodin.net> <mailto:jdanield@dodin.net>WHO'S THAT GUY ? Help me found it
Russia & South america help needed
http://www.dodin.net/serge/index.html


---------------------------------------------------------------------
Aide sur la liste: <URL:mailto:linux-31-help@CULTe.org>Le CULTe sur le web: <URL:http://www.CULTe.org/>