![]() |
||||||
|
CERT-In Monthly Security Bulletin
August 2007 | ||||||
|
Cyber Intrusion Trends |
||||||
| In this month 37 security incidents were reported to CERT-In from various
National/ International agencies. As shown in the figure 62%
phishing incidents were reported in the month. 24% unauthorized scanning , 11% incidents related to virus/worm under the malicious code category and 3% incidents from others category were reported in this month.As compared to previous month the number of
virus/worm incidents have increased. In this month CERT-In tracked 4 C&C (Command & Control) servers and 4934 bot-infected computers existing in India.The concerned ISPs were intimated to dis-infect the bot infected systems and C&C servers to mitigate botnets. |
Cyber Intrusion during August 2007
| |||||
|
Indian Websites Defacement |
||||||
In total 345 Indian websites were defaced during August 2007. A chart depicting Top Level Domain(TLD) wise defacements is shown in the figure. The vulnerabilities which might have been exploited for the defacements are: 1. PHP msql_connect() Buffer Overflow and PHP-Nuke Multiple Cross-Site Scripting (XSS) Vulnerabilities CIAD-2007-43 2. PHP Win32std Extension Local Buffer Overflow Vulnerability CVE-2007-4441 3. PHP 5.2.3 php_ntuser ntuser_getuserlist() Local Buffer Overflow vulnerability 4. Apache Tomcat Error Message Reporting Cross Site Scripting Vulnerability CVE-2007-3384 5. Multiple Vulnerabilities in Apache Tomcat CIAD-2007-44
|
Statistics of Defaced Indian Websites in August 2007
| |||||
|
Open proxy servers |
||||||
|
Any proxy server that doesn't restrict its client base to its own set of clients and allows any other client to connect to it, is known as an open proxy server. An open proxy server will accept client connections from any IP address and make connections to any Internet resource. CERT-In tracked 55 open proxy servers functioning in India during August 2007. All the concerned ISPs were alerted immediately to shut down the open proxy servers. A bar chart of open proxy servers tracked during this year is shown in the figure. |
Statistics of Open Proxy Servers tracked during Jan - Aug 2007
| |||||
|
Security Alerts |
||||||
|
The critical and medium vulnerabilities in various Operating Systems, Application software and Network devices discovered during August 2007 and their countermeasures alongwith wide-spreading malicious code like virus/ worm/Trojan are given below: | ||||||
|
High Vulnerabilities | ||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||
| Microsoft XML | Remote Code Execution Vulnerability in Microsoft XML Core Services | August 16, 2007 |
||||
| Microsoft Windows | Microsoft Windows OLE Automation Remote Code Execution vulnerability | August 16, 2007 |
||||
| Microsoft Excel | Microsoft Excel Remote Code Execution Vulnerability | August 16, 2007 |
||||
| Microsoft Internet Explorer | Microsoft Internet Explorer Multiple Vulnerabilities | August 16, 2007 |
||||
| Microsoft | Microsoft GDI Remote Code Execution Vulnerability | August 16, 2007 |
||||
| Microsoft Windows | Microsoft Windows Media Player Remote Code Execution Vulnerability | August 16, 2007 |
||||
| Microsoft Window | Microsoft Windows Vector Markup Language Remote Code Execution Vulnerability | August 16, 2007 |
||||
| Microsoft | Microsoft DirectX Media SDK DXTLIPI.DLL FlashPix ActiveX Control Buffer Overflow Vulnerability | August 16, 2007 |
||||
| Microsoft | Multiple Vulnerabilities in various components of Microsoft Windows, XML Core Services, Visual Basic, Microsoft Office for Mac, Internet Explorer, Windows Vista and Virtual PC/Virtual Server | August 16, 2007 |
||||
|
Unix |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||
| Apache Tomcat | Apache Tomcat Error Message Reporting Cross Site Scripting Vulnerability | August 02, 2007 |
||||
| Opera Web Browser | Opera JavaScript Invalid Pointer Vulnerabilit | August 15, 2007 |
||||
| PHP | PHP msql_connect() Buffer Overflow and PHP-Nuke Multiple Cross-Site Scripting (XSS) Vulnerabilities | August 17, 2007 |
||||
| Apache Tomcat | Multiple Vulnerabilities in Apache Tomcat | August 22, 2007 |
||||
| PHP | PHP php_iisfunc.dll buffer overflow vulnerability | August 29, 2007 |
||||
|
Cisco |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Cisco | Vulnerabilities in Cisco IOS and Cisco Unified Communications Manager | August 14, 2007 |
||||
| Cisco | Cisco IOS Next Hop Resolution Protocol Vulnerability | August 14, 2007 |
||||
| Cisco | Cisco IOS Information Leakage Using IPv6 Routing Header | August 14, 2007 |
||||
| Cisco | Cisco IOS Secure Copy Authorization Bypass Vulnerability | August 14, 2007 |
||||
| Cisco | Multiple vulnerabilities in Cisco IOS | August 14, 2007 |
||||
| Cisco | SIP Vulnerability in the Cisco 7960 IP Phones | August 24, 2007 |
||||
| Cisco | Local Privilege Escalation Vulnerabilities in Cisco VPN Client | August 24, 2007 |
||||
|
Miscellaneous |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| xpdf, gpdf, kpdf, CUPS | xpdf, gpdf, kpdf, CUPS, Poppler StreamPredictor::StreamPredictor() Integer Overflow Vulnerability | August 02, 2007 |
||||
| Mozilla | Mozilla Products Privilege Escalation and Unescaped URI's Handling Vulnerabilities | August 02, 2007 |
||||
| IBM AIX | Multiple Buffer Overflow Vulnerabilities in IBM AIX |
August 10, 2007 |
||||
| Symantec | Symantec ActiveX Control Vulnerabilities | August 10, 2007 |
||||
| OpenSSL | OpenSSL RSA Encryption Algorithm Implementation Vulnerability |
August 10, 2007 |
||||
| Trend Micro | Multiple Buffer Overflow Vulnerabilities in Trend Micro ServerProtect | August 24, 2007 |
||||
|
Medium Vulnerabilities |
||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Microsoft Windows Vista Gadgets | Multiple Vulnerabilities in Microsoft Windows Vista Gadgets | August 16, 2007 |
||||
| Microsoft Windows | Microsoft Windows Virtual PC and Virtual Server Privilege Escalation Vulnerability | August 16, 2007 |
||||
|
Unix |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Apache Tomcat | Apache Tomcat SendMailServlet Cross Site Scripting Vulnerability | August 06, 2007 |
||||
| phpMyAdmin | phpMyAdmin Multiple Cross-Site Scripting Vulnerabilities | August 10, 2007 |
||||
| Linux Kernel | Linux Kernel CIFS Secure Signing Vulnerability | August 17, 2007 |
||||
| PHP | PHP Win32std Extension Local Buffer Overflow Vulnerability | August 22, 2007 |
||||
| PHP | PHP 5.2.3 php_ntuser ntuser_getuserlist() Local Buffer Overflow vulnerability | August 23, 2007 |
||||
| Apache | Apache mod_proxy "date" Denial of Service Vulnerability | August 30, 2007 |
||||
Malicious Code Threats |
||||||
|
Title of Malicious Code |
Type |
Overview |
Aliases |
Discovery Date |
References | |
| W32.Mimbot Worm |
Bot |
The worm propagates by sending a zipped copy of itself through MSN Instant Messenger with some attractive message which tricks a user to open the attachment named as PictureAlbum2007.zip |
W32.Mimbot [Symantec] , W32/Delf-EXR [Sophos] |
August 17, 2007
|
http://www.cert-in.org.in/virus/W32_Mimbot.htm | |
| Trojan.Randsom | Trojan |
This Trojan compromises users system and encrypt important data found on the compromised system. Further perpetrators asks for the ransoms to make the valuable data to its original form. | TR/Gpcode.H (Avira) |
August 17, 2007 |
http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-081705-2952-99 | |
| W32.Scrimge!gen | Worm |
This worm spread through MSN instant messenger.This worm placed itslf in a zipped file and then send this zipped file to all the contacts listed in MSN messenger with attractive messages which entice user to open the zipped file.Upon opening of the zipped file the system gets compromises and opens a backdoor and gets connected to an IRC server to listen further commands from a remote attacker | W32/Generic.Delphi.a(McAfee) |
August 17, 2007 |
http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-081716-1758-99&tabid=2 | |
| Tspy_Mamaw | Trojan |
The Trojan compromises the database of monster.com and steals personal information from the compromised system. Further send this stealed information to a remote server for performing malicious activities. |
No Alias |
August 22, 2007 |
http://blog.trendmicro.com/here-there-be-28monsters29-trojans/ | |
| Storm Variants | Worm |
Storm worm, also known as Zhelatin started spreading in January 2007 through email attachments with subject lines related to European storm video. |
Trojan.Peacomm (Symantec), CME-711 |
August 23 , 2007 | http://www.cert-in.org.in/currentacts/currentact07.htm#RPSW | |
| Nuwar Variant | Worm |
It arrives in spammed e-mail messages which contain a malicious link to You Tube video. As user clicks upon that link, it gets redirected to an IP address which contains HTML script tags instead of You Tube video. | WORM_ZHELATI.MAB |
August 29, 2007 |
http://blog.trendmicro.com/page/6/ | |
|
Security News |
||||||
|
DoS Attack Feared As Storm Worm Siege Escalates August 2, 2007 Storm Botnet Behind Canadian DoS Attack August 13, 2007 Storm Worm using YouTube August 26, 2007 Storm Worm of a thousand faces August 21, 2007 Universities warned of Storm Worm attacks August 17, 2007 Storm Worm Attack Shifts To Malicious Web Pages August 09, 2007 Spammers debut FDF spam Latest Nuwar Spamming Uses YouTube Lure Old worm threat returns August 24, 2007 e-Passports get hacked in new security threat August 06, 2007 Monster data theft also hit U.S. job site August 31, 2007 German gov't PCs hacked, China offers to investigate Sony pleads innocent in latest rootkit fiasco August 31, 2007 NIST Draft Special Publication August 02, 2007
How to neutralize today's worst Web attacks August 22, 2007 300,000 malicious items approaching fast August 01, 2007
|
||||||