![]() |
||||||
|
CERT-In Monthly Security Bulletin
April 2008 | ||||||
|
Cyber Intrusion Trends |
||||||
| In this month 61 security incidents were reported to CERT-In from various National/ International agencies. As shown in the figure 34% phishing incidents were reported in this month. 25% unauthorized scanning , 28% incidents related to virus/worm under the Malicious code category and 13% incidents related to technical help under the Others category were reported in this month. As compared to previous month the number of phishing incidents, scanning incidents and incidents related to virus/worm under the Malicious code category have incresaed while incidents related to technical help under the Others category have decreased. In this month CERT-In tracked 14 C&C (Command & Control) servers and 8,580 bot-infected computers existing in India.The concerned ISPs were intimated to dis-infect the bot infected systems and C&C servers to mitigate botnets. |
Cyber Intrusion during April 2008 |
|||||
|
Indian Websites Defacement |
||||||
In total 682 Indian websites were defaced during April 2008. A chart depicting Top Level Domain(TLD) wise defacements is shown in the figure. The vulnerabilities which might have been exploited for the defacements are: 1. Apache-SSL Authentication Bypass Vulnerability CIVN-2008-36
|
Statistics of Defaced Indian Websites in April 2008
| |||||
|
Open proxy servers |
||||||
Any proxy server that doesn't restrict its client base to its own set of clients and allows any other client to connect to it, is known as an open proxy server. An open proxy server will accept client connections from any IP address and make connections to any Internet resource. CERT-In tracked 35 open proxy servers functioning in India during April 2008. All the concerned ISPs were alerted immediately to shut down the open proxy servers. A bar chart of open proxy servers tracked during this year is shown in the figure. |
Statistics of Open Proxy Servers tracked during Jan - April 2008
|
|||||
|
Security Alerts |
||||||
|
The critical and medium vulnerabilities in various Operating Systems, Application software and Network devices discovered during April 2008 and their countermeasures alongwith wide-spreading malicious code like virus/ worm/Trojan are given below: | ||||||
|
High Vulnerabilities | ||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||
| Microsoft | Multiple Vulnerabilities in Microsoft Windows and Office Components: Microsoft Project, Microsoft Visio, Internet Explorer, Windows DNS Client, Windows Kernel, VBScript and JScript | April 10, 2008 |
||||
| Microsoft | Microsoft Project Memory Validation Vulnerability | April 10, 2008 |
||||
| Microsoft | Microsoft windows GDI Files Remote Code Execution Vulnerability | April 10, 2008 |
||||
| Microsoft | Microsoft Windows VBScript and JScript Remote Code Execution Vulnerability | April 10, 2008 |
||||
| Microsoft Internet Explorer | Microsoft Internet Explorer 'hxvz.dll' ActiveX Control Memory Corruption Vulnerability | April 10, 2008 |
||||
| Microsoft | Microsoft Data Stream Handling Memory Corruption Vulnerability | April 10, 2008 |
||||
| Microsoft Internet Explorer | Microsoft Internet Explorer Popup Window Address Bar URI spoofing vulnerability | April 11, 2008 |
||||
|
Database |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Oracle | Multiple Vulnerabilities in various Oracle products | April 23, 2008 |
||||
|
Cisco |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Cisco | Cisco Unified Communications Disaster Recovery Framework Command Execution Vulnerability | April 04, 2008 |
||||
| Cisco | Multiple vulnerabilities in Cisco IOS | April 04, 2008 |
||||
| Cisco | Cisco Network Admission Control Shared Secret Disclosure Vulnerability | April 29, 2008 |
||||
|
Miscellaneous |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Wireshark | Multiple Vulnerabilities in Wireshark | April 04, 2008 |
||||
| Apple QuickTime | Multiple vulnerabilities in Apple QuickTime |
April 11, 2008 |
||||
| Mozilla Products | JavaScript Garbage Collector Vulnerability in Mozilla Products | April 23, 2008 |
||||
| Adobe Flash player | Multiple Remote code Execution Vulnerabilities in Adobe Flash player | April 25, 2008 |
||||
|
Medium Vulnerabilities |
||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Microsoft | Microsoft Crypto API X.509 Certificate Validation Remote Information Disclosure Vulnerability | April 04, 2008 |
||||
| Microsoft | Microsoft Visio Object Header and Memory Validation Vulnerabilities | April 10, 2008 |
||||
| Microsoft | Microsoft DNS stub resolver Spoofing Vulnerability | April 10, 2008 |
||||
| Windows Kernel | Windows Kernel Elevation of Privilege Vulnerability | April 10, 2008 |
||||
| Microsoft Windows | Microsoft Windows SeImpersonatePrivilege Local Privilege Escalation Vulnerability | April 19, 2008 |
||||
|
Unix |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| OpenSSH | OpenSSH Forwarded X11 Connection Information Disclosure Vulnerability | April 07, 2008
|
||||
| Apache | Apache-SSL Authentication Bypass Vulnerability | April 09, 2008 |
||||
| phpMyAdmin | phpMyAdmin HTTP POST Request File Disclosure Vulnerability | April 23, 2008 |
||||
Malicious Code Threats |
||||||
|
Title of Malicious Code |
Type |
Overview |
Aliases |
Discovery Date |
References | |
| Bancorkut Worm |
Worm |
It has been observed that a mass mailing worm named Bancorkut is spreading widely.It spreads when a user clicks upon the malicious link embedded within the email message body.The worm collects the confidential information such as username and passwords from the infected system and some websites to send the collected information to a remote server under attacker's control. These credentials are further used for performing illegal banking activities. | No Alias |
April 08, 2008 |
||
| Goldun Trojan | Trojan |
It has been observed that an information stealing Trojan called Goldun is spreading via email. It comes as an email attachment or as a malicious link inside the email body which pretends to appear from E-Gold online bank or from Yahoo Shopping. The “subject line” of the email entices users to open the attachment or visit the malicious link and install the trojan on their system.Upon successful installation the Trojan opens a backdoor and steals confidential information such as usernames and passwords for financial accounts from the infected system and sends this information to the remote server which is under the control of the attacker. |
Trojan.Goldun.G [Symantec] |
April 15, 2008 |
||
| Trojan Vundo | Trojan |
It has been observed that a trojan named Vundo is circulating widely. It is dropped by some dropper as a DLL component on user's system. It installs itself as browser helper object ( BHO ) and gets injected into Explorer DOT exe . After successful installation it generates popup ads for rogue antispyware installation on the infected system which may appear as visible or hidden window. |
Win32/Vundo!generic [CA], W32/Virtumonde.TY [ Norman ], Adware.VirtuMonde [Symantec] |
April 25, 2008 |
http://www.cert-in.org.in/virus/Trojan_Vundo.htm | |
| W32.Zatyudi.A |
Worm | It has been observed that a Worm named Zatyudi is spreading widely. It spreads by copying itself to network shares and removable drives with the file name SETUP.exe which is kept in an achieve with .zip extension..After successful infection the worm collects email addresses from the compromised computer and attempts to connect to certain websites to send a notification of the infection. It also attempts to terminate certain processes and services whose name or description contains the strings such as: SysMech, PDFIND, avtask, mav, process. |
No Alias |
April 30 , 2008 |
http://www.symantec.com/business/security_response /writeup.jsp?docid=2008-043015-2430-99&tabid=1 |
|
|
Security News |
||||||
India assists Mauritius to fight cyber crime 28th April , 2008 Department of Homeland Security website hacked! 25th April 2008 U.S. reveals plans to hit back at cyberthreats 04 April , 2008 "Terrorists and criminals are doing the same thing. We depend so heavily as a military on the use of cyber, we have to be cautious about it," Elder said. "Cyber gives us a huge advantage, but adversaries look at our capabilities and see areas they can undermine. We need to protect our asymmetric advantage--on the one hand by having people further exploit cyber, and on the other by having mission assurance." New attack technique threatens databases Huge Web hack attack infects 500,000 pages Web infection attacks more than 100,000 pages 24th April, 2008
Microsoft Botnet-hunting Tool Helps Bust Hackers 29th April , 2008 The software vendor is giving law enforcers access to a special tool that keeps tabs on botnets, using data compiled from the 450 million computer users who have installed the Malicious Software Removal tool that ships with Windows.Although Microsoft is reluctant to give out details on its botnet buster -- the company said that even revealing its name could give cyber criminals a clue on how to thwart it -- company executives discussed it at a closed door conference held for law enforcement professionals Monday. The tool includes data and software that helps law enforcers get a better picture of the data being provided by Microsoft's users, said Tim Cranton, associate general counsel with Microsoft's World Wide Internet Safety Programs. "I think of it ... as botnet intelligence," he said.Microsoft security experts analyze samples of malicious code to capture a snapshot of what is happening on the botnet network, which can then be used by law enforcers, Cranton said. "They can actually get into the software code and say, 'Here's information on how it's being controlled.'"Botnets are networks of hacked computers that can be used, almost like a supercomputer, to send spam or attack servers on the Internet. They have been on Microsoft's radar for about four years, ever since the company identified them as a significant emerging threat. In fact, the software vendor has held seven closed-door botnet conferences for law enforcement officials over the years, including an inaugural event in Lyon, France, hosted by Interpol, Cranton said.Microsoft had not previously talked about its botnet tool, but it turns out that it was used by police in Canada to make a high-profile bust earlier this year.In February, the Sûreté du Québec used Microsoft's botnet-buster to break up a network that had infected nearly 500,000 computers in 110 countries, according to Captain Frederick Gaudreau, who heads up the provincial police force's cybercrime unit.The case illustrates how useful Microsoft's software and data can be.
Cyber criminals to target mobiles
Phishers offer credit card discounts to prospective marks 10th April 2008
'Long-Term' Phishing Attack Underway 28th April , 2008 The danger of the so-called Zeus Trojan is that it can execute what Yaneza calls a "long-term" phishing attack on the victim. "It can stay there and log credentials, personal information, and steal personal information. Basically anything you type," he says. The version Trend has been studying has the ability to receive downloaded updates to itself, he says. Move over Storm - there's a bigger, stealthier botnet in town 7th April , 2008
Kraken stripped of World's Largest Botnet crown (maybe)
Spam filtering services throttle Gmail to fight spammers 10th April 2008
Google to open suspect Orkut albums to Brazil police 12th April 2008 Chinese spammers target 1,200 US , UK firms 11th April 2008
Symantec internet security threat report thirteenth version released 08 April 2008
Yahoo! pimping malware from banner ads 28th April 2008 The ads pitch women's deodorant, but behind the scenes, they contact servers that have been used by previous rogue ads targeting high-traffic websites. Typically, the ads produce a pop up that looks strikingly similar to official Windows dialog pop-ups that urge the end user to download software to fix problems. Expedia, Rhapsody, MySpace, Excite, Blick, and CNN.com have all served up similar malicious ads in the past.
|
||||||