Short Name |
TFTP:FILE:ADMIN-DLL |
---|---|
Severity |
Medium |
Recommended |
No |
Category |
TFTP |
Keywords |
nimda IIS |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to uses TFTP to access the admin.dll file in the root directory. This can indicate the presence of the Nimda worm on the system.
The Nimda worm enables file sharing and creates an administrative account on and infected machine.