As of March 22, 2004, due to an increase in submission rate, Symantec Security Response has upgraded W32.Netsky.P@mm (also known as W32.Netsky.Q@mm) to a Category 3 level threat from a Category 2 threat.
a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses it finds when scanning the hard drives and mapped drives. The worm also tries to spread through various file-sharing programs by copying itself into various shared folders.
The From line of the email is spoofed, and its Subject line and message body of the email vary. The attachment name varies with the .exe, .pif, .scr, or .zip file extension.
This worm also uses the Incorrect MIME Header Can Cause IE to Execute E-mail Attachment vulnerability to cause unpatched systems to auto-execute the worm when reading or previewing an infected message. Type: Worm Infection Length: 29,568 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 3.x CVE References: CVE-2001-0154
Asta e ce zice Symatec cand ii intrebi despre ce e vorba. Pe scurt e un mass mailer. Nu stie decat sa se replice si sa omoare banda de net. Nu cred sa stie si altceva.Paate versiunile mai noi Cat de curand ar trebui sa primeasca toti cei care au cont pe crims asa ceva. Sper totusi ca adresele de mail sa fie stocate criptat pentru ca altfel jucarioara asta ajunge la lvl 4 ca amenintare.
Oricum asta arata ca oameni nu prea stiu sa isi intretina serverele si ca au servere pe windows. Pentru ca in momentul in care a ajuns pe linux engine-ul de smtp al worm-ului este omorat automat
_______________________________________ Invata sa visezi si sa iti aperi visele pentru ca fara vise esti ca si mort...