Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

Welchia

From Wikipedia, the free encyclopedia
(Redirected fromNachi worm)
Computer worm
Welchia
AliasNachi worm
TypeComputer worm
Origin2003
Technical details
PlatformMicrosoft Windows

Welchia, also known as the "Nachi worm", is acomputer worm that exploits a vulnerability in theMicrosoftremote procedure call (RPC) service similar to theBlaster worm. However, unlike Blaster, it first searches for and deletes Blaster if it exists, then tries to download and installsecuritypatches fromMicrosoft that would prevent further infection by Blaster, so it is classified as ahelpful worm. Welchia was successful in deleting Blaster, but Microsoft claimed that it was not always successful in applying their security patch.[1]

This worm infected systems by exploiting vulnerabilities in Microsoft Windows system code (TFTPD.EXE and TCP on ports 666–765, and a buffer overflow of the RPC on port 135). Its method of infection is to create a remote shell and instruct the system to download the worm using TFTP.EXE. Specifically, the Welchia worm targeted machines running Windows XP. The worm usedICMP, and in some instances flooded networks with enough ICMP traffic to cause problems.[2]

Once on the system, the worm patches the vulnerability it used to gain access (thereby actually securing the system against other attempts to exploit the same method of intrusion) and run its payload, a series of Microsoft patches. It then attempts to remove theBlaster Worm by deleting MSBLAST.EXE. If still in the system, the worm is programmed to self-remove on January 1, 2004, or after 120 days of processing, whichever comes first.

In September 2003, the worm was discovered on the US State Department's computer network, causing them to shut down their network for 9 hours for remediation.[3]

See also

[edit]

References

[edit]
  1. ^Bransford, Gene (2003-12-18)."The Welchia Worm".Global Information Assurance Certification.SANS Institute. Retrieved2018-11-03.
  2. ^Naraine, Ryan (2003-08-19)."'Friendly' Welchia Worm Wreaking Havoc". InternetNews.com. Retrieved2022-10-21.
  3. ^Labott, Elise (2003-09-24)."'Welchia worm' hits U.S. State Dept. network".CNN. Retrieved2022-04-09.

External links

[edit]
Hacking in the 2000s
Incidents
2004
2005
2007
2008
2009
Groups
Individuals
Darknets
Hacking forums
Vulnerabilities
discovered
Malware
2000
2001
2002
2003
2004
2005
2006
2007
2008
2009
Retrieved from "https://en.wikipedia.org/w/index.php?title=Welchia&oldid=1273457630"
Category:
Hidden categories:

[8]ページ先頭

©2009-2025 Movatter.jp