Steps againt Nimba Worm

TAKAHASHI Motonobu monyo at samba.gr.jp
Sat Sep 22 10:07:45 GMT 2001


Hello,

SUGJ(Samba Users Group Japan) offers such information
  at http://www.samba.gr.jp/project/kb/J0/1/09.html

This is the English version of it,

Is it usefull?

-----
Steps againt Nimba Worm for Samba

Last Updated: 2001/09/22
Author: HASEGAWA Yohsuke
Translator: TAKAHASHI Motonobu

The information in this article applies to 
    Samba 2.0.x
    Samba 2.2.x
    Windows 95/98/Me/NT/2000

SYMPTOMS
  This article has described the measure against Nimba Worm for Samba
  server.

DESCRIPTION
  Nimba Worm is infected through the shared disk on a network besides 
  Microsoft IIS, Internet Explorer and mailer of Outlook series.

  At this time, the worm copies itself by the name *.nws and *.eml on
  the shared disk, moreover, by the name of Riched20.dll in the folder
  where *.doc file is included.

  To prevent infection through the shared disk offered by Samba, set
  up as follows:

-----
[global]
  ...
  veto files = /*.eml/*.nws/riched20.dll/
-----

  Setting up "veto files" parameter, the matched files on the Samba
  server are completely hidden from the clients and become impossible
  to access them at all.

  In addition to it, the following setting are also pointed out by the
  samba-jp:09448 thread: when the
  "readme.txt.{3050F4D8-98B5-11CF-BB82-00AA00BDCE0B}" file exists on
  a Samba server, it is visible only with "readme.txt" and a dangerous
  code may be performed when this file is double-clicked.

  Setting the following, 
-----
  veto files = /*.{*}/
-----
  no files having CLSID in its file extension can be accessed from any
  clients.

This technical article is created based on the discussion of
samba-jp:09448 and samba-jp:10900 threads.

-----
TAKAHASHI, Motonobu(monyo)         monyo at samba.gr.jp
Personal - http://home.monyo.com/
Samba Team - http://samba.org/     Samba-JP - http://www.samba.gr.jp/  
JWNTUG - http://www.jwntug.or.jp/  Analog-JP - http://www.jp.analog.cx/
MCSE+I, SCNA, CCNA, Turbo-CI





More information about the samba-docs mailing list