[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-287226-105":53,"doc-detail-287226-en":126},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":119,"head_meta":121,"extra_data":123,"updated_unix":125},105,"en","a-netware-nightmare-how-a-windows-based-virus-can-effect-novell-netware-giac-incident-handling-certification-part-1-the-exploit","A NetWare Nightmare - How a Windows Based Virus Can Effect Novell NetWare - GIAC Incident Handling Certification - Part 1 - The Exploit","","A NetWare Nightmare explains how the ILOVEYOU email worm spread across networks by exploiting weaknesses in Microsoft Outlook and Internet Explorer. It describes the initial love-letter lure, execution through Windows scripting and VBScript attachments, rapid Internet-wide propagation via address books, and follow-on variants that reused the same malicious payload. The paper details impacted Windows platforms, how Windows Scripting Host is enabled by default, and the organizational consequences of widespread address-book sharing.",{"@graph":63,"@context":118},[64,80,101],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":11,"@type":70,"position":76},"https://docshare.wps.com/template/presentations/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/a-netware-nightmare-how-a-windows-based-virus-can-effect-novell-netware-giac-incident-handling-certification-part-1-the-exploit/287226/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/a-netware-nightmare-how-a-windows-based-virus-can-effect-novell-netware-giac-incident-handling-certification-part-1-the-exploit/287226.png","ImageObject",442,249,{"name":88,"@type":89},"Theodora","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/pdf","2026-09-24","2026-09-17",true,{"@type":98,"interactionType":99,"userInteractionCount":79},"InteractionCounter",{"@type":100},"ViewAction",{"@type":102,"mainEntity":103},"FAQPage",[104,110,114],{"name":105,"@type":106,"acceptedAnswer":107},"How did the ILOVEYOU worm convince users to activate the attachment?","Question",{"text":108,"@type":109},"It arrived as an email framed like a love letter with the subject ILOVEYOU. The message instructed recipients to open an attachment to view the letter, and the attachment activated the worm.","Answer",{"name":111,"@type":106,"acceptedAnswer":112},"How did the worm spread across an organization and the Internet?",{"text":113,"@type":109},"After execution, it resent itself to users listed in the recipient’s Outlook address book. Because address books were commonly shared within organizations, it could infect many accounts quickly.",{"name":115,"@type":106,"acceptedAnswer":116},"Which Windows capability enabled the worm’s execution and why was it widespread?",{"text":117,"@type":109},"The worm relied on Windows Scripting Host and VBScript execution via Outlook and Internet Explorer. Windows Scripting Host was installed by default on many Windows platforms, making infection easier.","https://schema.org",{"og:url":78,"og:type":120,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":122,"canonical":78},"index,follow",{"doc_id":124,"site_id":56},287226,1789632040,{"code":4,"msg":5,"data":127},{"doc_id":124,"user_id":128,"nickname":88,"user_avatar":129,"doc_module":9,"category_id":8,"category_name":11,"doc_title":59,"doc_description":61,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":79,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":135,"language":136,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":137,"faqs":138,"seo_title":139,"seo_description":61,"update_tm":125,"read_time":140},687197207919,"https://ap-avatar.wpscdn.com/avatar/a000253d6f5f7c60be?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779446848396160552","Global Information Assurance Certification Paper  \nCopyright SANS InstituteAuthor Retains Full Rights  \nThis paper is taken from the GIAC directory of certified professionals.Reposting is not permited without express writen permission.  \nInterested in learning more?  \nCheck out the list of upcoming events offering  \n\"Hacker Tools,Techniques,and Incident Handling (Security 504)\"  \nat http://www.giac.org/registration/gcih  \n# A NetWare Nightmare:\n\nHow a Windows Based Virus CanEffect Novell NetWare  \nGIAC Incident Handling Certification  \nJames Manion  \n## Background:\n\nWhile working at a local college an attack was invoked upon the college's network.Theattack infected mail servers including clients using POP3 mail programs.Web servers andvarious subnets throughout the campus were brought to their knees.The sad part is that thiseasily preventable attack was kicked off by an unknowing user and was later restarted onpurpose by another user.The attack did not target the college specifically.The purpose of theworm was to invoke havoc on as many unsuspecting users as possible across the entire Internet.  \nThe attack came in the form of an innocuous email claiming to be a love letter with thesubject ILOVEYOU.Since the worm used the address book of the user,the recipient wouldprobably recognize the sender and assume the email and attachment to be legitimate.The bodyof the email instructed the reader to open the attachment to view the love letter.The body read:“kindly check the attached LOVELETTER coming from me”.When the attachment was opened,the worm was activated and the email was resent to all users within the recipient's Outlookaddress book.  \nThe worm spread throughout the Internet in just a few hours.Since most places shareaddress books within the organization and there are usually accounts like “ALL'or “ALL USERS”it was very easy to infect an entire organization,as wellas infect everyone who was listed in eachindividual's personal address book.Soon organizations all over the Internet were infected.TheUnited States Congress,the U.S.Air Force,the British Parliament and many other govemment,education and business entities were infected.Just as network administrators were getting ahandle on this worm,new worms that were just cheap imitations of the ILOVEYOU worm startedto show up.A Mother's Day variant soon was spreading across the Internet and reinfecting thesame users.Anti-virus vendors were quick to create a fix and most had a fix in place and newvirus definitions on their websites within a day.However,this led to a new variant,which claimedto be an email from the Anti-virus vendors with the fix attached to the email.Unfortunately,thiswas just a hacked version of the original ILOVEYOU worm with basically the same maliciouspayload.  \nAll of these variations took advantage of exploits within Microsof's Outlook and InternetExplorer.The worm used capabilities within windows scripting which is installed when InternetExplorer is installed.This type of scripting permitted Visual Basic Scripts to be sent asattachments and executed.If not configured properly,Outlook would automatically execute thescripts when the email was read.When the wom was executed,it not only emailed itself to otherusers it would also delete and modify certain multimedia files,as wellas alter the user's IntemetExplorer settings and try to send it self to chat rooms via Internet Relay Chat.  \nThe worm used a unique way of social engineering to help propagate itself and infectother users.Most users could not resist the urge to open an ILOVEYOU message from someonethey knew.And for this reason the worm continued to spread.Here are the details about theILOVEYOU worm.  \n## Part 1-The Exploit\n\nName:  \nThe ILOVEYOU worm is commonly known by the following names.VBS.LoveLetter.A(Symantec naming convention),Lovebug,IwWorm.LoveLetter,VBS/LoveLetter.A,VBS/LoveLet-A  \n## Operating System:\n\nAll Microsoft Windows platforms that have the Windows Scripting Host enginesinstalled can be","cbCaiguUo5xhZHeC","https://ap.wps.com/l/cbCaiguUo5xhZHeC","pdf",664494,62,"English","# A NetWare Nightmare\n## Background\n## Part 1-The Exploit\n### Name and variants\n### Operating System (Windows scripting host)","[{\"question\":\"How did the ILOVEYOU worm convince users to activate the attachment?\",\"answer\":\"It arrived as an email framed like a love letter with the subject ILOVEYOU. The message instructed recipients to open an attachment to view the letter, and the attachment activated the worm.\"},{\"question\":\"How did the worm spread across an organization and the Internet?\",\"answer\":\"After execution, it resent itself to users listed in the recipient’s Outlook address book. Because address books were commonly shared within organizations, it could infect many accounts quickly.\"},{\"question\":\"Which Windows capability enabled the worm’s execution and why was it widespread?\",\"answer\":\"The worm relied on Windows Scripting Host and VBScript execution via Outlook and Internet Explorer. Windows Scripting Host was installed by default on many Windows platforms, making infection easier.\"}]","A NetWare Nightmare - How a Windows Based Virus Can Effect Novell NetWare - GIAC Incident Handling Certification - Part 1 - The Exploit | PDF",22]