Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > Mac OS X > OS X is vulnerable to the Nachi (Welchia) worm?

OS X is vulnerable to the Nachi (Welchia) worm?
Thread Tools
Junior Member
Join Date: Aug 2002
Status: Offline
Reply With Quote
Aug 29, 2003, 01:12 PM
 
Today I received an e-mail from our computer lab:

Dear XXX,

Our database shows that your computer is or was recently vulnerable to the Nachi (Welchia). We need to be sure your computer has been patched and our records updated.

FAILURE TO TAKE THE NEEDED STEPS TO RESOLVE THIS PROBLEM AND CONTACT US MAY CAUSE YOUR ACCOUNT TO BE TEMPORARILY DISABLED ON SEPTEMBER 1ST AFTER 8AM.

..........

I can not believe this!!! From Symantec, this worm only affects Windows
     
Mac Elite
Join Date: Dec 1999
Location: NYC
Status: Offline
Reply With Quote
Aug 29, 2003, 01:30 PM
 
Reply and tell them you have a Mac. If OSX were vulnerable, it would have been a big deal in the (mac) news. You know, being the first virus/worm for OSX and all.
     
Addicted to MacNN
Join Date: Apr 2001
Location: europe
Status: Offline
Reply With Quote
Aug 29, 2003, 01:42 PM
 
http://www.symantec.com/avcenter/ven...chia.worm.html

Systems Not Affected:
Linux, Macintosh, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows Me, Windows NT
Nasrudin sat on a river bank when someone shouted to him from the opposite side: "Hey! how do I get across?" "You are across!" Nasrudin shouted back.
     
Professional Poster
Join Date: Nov 2000
Location: Tasmania, Australia
Status: Offline
Reply With Quote
Aug 31, 2003, 10:09 PM
 
They probably are using an "affected systems" detection tool that tests for open ports that the virus uses, but then doesn't go the rest of the way and test for what OS has that port open.

Tell them to fix their detection tool!
     
Senior User
Join Date: Jul 2002
Location: Arizona Wasteland
Status: Offline
Reply With Quote
Aug 31, 2003, 10:15 PM
 
Also report them to their supervisor. System administrators like this shouldn't be working.
     
Mac Elite
Join Date: Apr 2002
Location: Illinois
Status: Offline
Reply With Quote
Sep 1, 2003, 12:37 AM
 
This worm like many of the others lately, it pretends it's sending from your computer. It's not actually you sending it but the scripts that check for worms don't know any better.
     
Mac Elite
Join Date: Feb 2001
Location: Washington, DC
Status: Offline
Reply With Quote
Sep 1, 2003, 04:26 AM
 
Originally posted by King Bob On The Cob:
This worm like many of the others lately, it pretends it's sending from your computer. It's not actually you sending it but the scripts that check for worms don't know any better.
Wrong worm. You're thinking of mass mailers. This worm is different, it self-propagates over a LAN using a buffer overrun vulnerability in Windows 2K and XP and, optionally, IIS 5.0.

They probably just scanned the network to see who had port 135 and/or 80 open.

Would you, by chance, have web sharing or windows file sharing turned on (and if web sharing is turned on is mod_webdav enabled)?
/Earth\ Mk\.\ I{2}/
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 10:15 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2