Home || Feedback || FAQ || Site map
CERT-In Monthly Security Bulletin August 2007
Cyber Intrusion Trends
In this month 37 security incidents were reported to CERT-In from various National/ International agencies. As shown in the figure 62% phishing incidents were reported in the month. 24% unauthorized scanning , 11% incidents related to virus/worm under the malicious code category and 3% incidents from others category were reported in this month.As compared to previous month the number of virus/worm incidents have increased.
In this month CERT-In tracked 4 C&C (Command & Control) servers and 4934 bot-infected computers existing in India.The concerned ISPs were intimated to dis-infect the bot infected systems and C&C servers to mitigate botnets.

Cyber Intrusion during August 2007

Indian Websites Defacement

In total 345 Indian websites were defaced during August 2007. A chart depicting Top Level Domain(TLD) wise defacements is shown in the figure.

The vulnerabilities which might have been exploited for the defacements are:

1. PHP msql_connect() Buffer Overflow and PHP-Nuke Multiple Cross-Site Scripting (XSS) Vulnerabilities CIAD-2007-43

2. PHP Win32std Extension Local Buffer Overflow Vulnerability CVE-2007-4441

3. PHP 5.2.3 php_ntuser ntuser_getuserlist() Local Buffer Overflow vulnerability
CVE-2007-4507

4. Apache Tomcat Error Message Reporting Cross Site Scripting Vulnerability CVE-2007-3384

5. Multiple Vulnerabilities in Apache Tomcat CIAD-2007-44


Statistics of Defaced Indian Websites in August 2007

Open proxy servers

Any proxy server that doesn't restrict its client base to its own set of clients and allows any other client to connect to it, is known as an open proxy server. An open proxy server will accept client connections from any IP address and make connections to any Internet resource.

CERT-In tracked 55 open proxy servers functioning in India during August 2007. All the concerned ISPs were alerted immediately to shut down the open proxy servers. A bar chart of open proxy servers tracked during this year is shown in the figure.

Statistics of Open Proxy Servers tracked during Jan - Aug 2007

Security Alerts

The critical and medium vulnerabilities in various Operating Systems, Application software and Network devices discovered during August 2007 and their countermeasures alongwith wide-spreading malicious code like virus/ worm/Trojan are given below:

High Vulnerabilities
Microsoft
Title of Vulnerability
Discovery/Publish Date
CERT-In References & Patch Information
Microsoft XML Remote Code Execution Vulnerability in Microsoft XML Core Services
August 16, 2007
CIVN-2007-102
Microsoft Windows Microsoft Windows OLE Automation Remote Code Execution vulnerability
August 16, 2007
CIVN-2007-103
Microsoft Excel Microsoft Excel Remote Code Execution Vulnerability
August 16, 2007
CIVN-2007-104
Microsoft Internet Explorer Microsoft Internet Explorer Multiple Vulnerabilities
August 16, 2007
CIVN-2007-105
Microsoft Microsoft GDI Remote Code Execution Vulnerability
August 16, 2007
CIVN-2007-106
Microsoft Windows Microsoft Windows Media Player Remote Code Execution Vulnerability
August 16, 2007
CIVN-2007-107
Microsoft Window Microsoft Windows Vector Markup Language Remote Code Execution Vulnerability
August 16, 2007
CIVN-2007-110
Microsoft Microsoft DirectX Media SDK DXTLIPI.DLL FlashPix ActiveX Control Buffer Overflow Vulnerability
August 16, 2007
CIVN-2007-111
Microsoft Multiple Vulnerabilities in various components of Microsoft Windows, XML Core Services, Visual Basic, Microsoft Office for Mac, Internet Explorer, Windows Vista and Virtual PC/Virtual Server
August 16, 2007
CIAD-2007-42
Unix
Title of Vulnerability
Discovery/Publish Date
CERT-In References & Patch Information
Apache Tomcat Apache Tomcat Error Message Reporting Cross Site Scripting Vulnerability
August 02, 2007
CVE-2007-3384
Opera Web Browser Opera JavaScript Invalid Pointer Vulnerabilit
August 15, 2007
CVE-2007-4367
PHP PHP msql_connect() Buffer Overflow and PHP-Nuke Multiple Cross-Site Scripting (XSS) Vulnerabilities
August 17, 2007
CIAD-2007-43
Apache Tomcat Multiple Vulnerabilities in Apache Tomcat
August 22, 2007
CIAD-2007-44
PHP PHP php_iisfunc.dll buffer overflow vulnerability
August 29, 2007
CVE-2007-4586
Cisco
Title of Vulnerability
Discovery/Publish Date
CERT-In References & Patch Information
Cisco Vulnerabilities in Cisco IOS and Cisco Unified Communications Manager
August 14, 2007
CIVN-2007-98
Cisco Cisco IOS Next Hop Resolution Protocol Vulnerability
August 14, 2007
CIVN-2007-99
Cisco Cisco IOS Information Leakage Using IPv6 Routing Header
August 14, 2007
CIVN-2007-100
Cisco Cisco IOS Secure Copy Authorization Bypass Vulnerability
August 14, 2007
CIVN-2007-101
Cisco Multiple vulnerabilities in Cisco IOS
August 14, 2007
CIAD-2007-41
Cisco SIP Vulnerability in the Cisco 7960 IP Phones
August 24, 2007
CIVN-2007-113
Cisco Local Privilege Escalation Vulnerabilities in Cisco VPN Client
August 24, 2007
CIAD-2007-45
Miscellaneous
Title of Vulnerability
Discovery/Publish Date
CERT-In References & Patch Information
xpdf, gpdf, kpdf, CUPS xpdf, gpdf, kpdf, CUPS, Poppler StreamPredictor::StreamPredictor() Integer Overflow Vulnerability
August 02, 2007
CIVN-2007-93
Mozilla Mozilla Products Privilege Escalation and Unescaped URI's Handling Vulnerabilities
August 02, 2007
CIAD-2007-40
IBM AIX Multiple Buffer Overflow Vulnerabilities in IBM AIX
August 10, 2007
CIVN-2007-95
Symantec Symantec ActiveX Control Vulnerabilities
August 10, 2007
CIVN-2007-96
OpenSSL OpenSSL RSA Encryption Algorithm Implementation Vulnerability
August 10, 2007
CIVN-2007-97
Trend Micro Multiple Buffer Overflow Vulnerabilities in Trend Micro ServerProtect
August 24, 2007
CIAD-2007-46
Medium Vulnerabilities
Microsoft
Title of Vulnerability
Discovery/Publish Date
CERT-In References & Patch Information
Microsoft Windows Vista Gadgets Multiple Vulnerabilities in Microsoft Windows Vista Gadgets
August 16, 2007
CIVN-2007-108
Microsoft Windows Microsoft Windows Virtual PC and Virtual Server Privilege Escalation Vulnerability
August 16, 2007
CIVN-2007-109
Unix
Title of Vulnerability
Discovery/Publish Date
CERT-In References & Patch Information
Apache Tomcat Apache Tomcat SendMailServlet Cross Site Scripting Vulnerability
August 06, 2007
CIVN-2007-94
phpMyAdmin phpMyAdmin Multiple Cross-Site Scripting Vulnerabilities
August 10, 2007
CVE-2007-4306
Linux Kernel Linux Kernel CIFS Secure Signing Vulnerability
August 17, 2007
CIVN-2007-112
PHP PHP Win32std Extension Local Buffer Overflow Vulnerability
August 22, 2007
CVE-2007-4441
PHP PHP 5.2.3 php_ntuser ntuser_getuserlist() Local Buffer Overflow vulnerability
August 23, 2007
CVE-2007-4507
Apache Apache mod_proxy "date" Denial of Service Vulnerability
August 30, 2007
CVE-2007-3847
Malicious Code Threats
Title of Malicious Code
Type
Overview
Aliases
Discovery Date
References
W32.Mimbot Worm
Bot
The worm propagates by sending a zipped copy of itself through MSN Instant Messenger with some attractive message which tricks a user to open the attachment
named as PictureAlbum2007.zip
W32.Mimbot [Symantec] , W32/Delf-EXR [Sophos]
August 17, 2007
http://www.cert-in.org.in/virus/W32_Mimbot.htm
Trojan.Randsom
Trojan
This Trojan compromises users system and encrypt important data found on the compromised system. Further perpetrators asks for the ransoms to make the valuable data to its original form.
TR/Gpcode.H (Avira)
August 17, 2007
http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-081705-2952-99
W32.Scrimge!gen
Worm
This worm spread through MSN instant messenger.This worm placed itslf in a zipped file and then send this zipped file to all the contacts listed in MSN messenger with attractive messages which entice user to open the zipped file.Upon opening of the zipped file the system gets compromises and opens a backdoor and gets connected to an IRC server to listen further commands from a remote attacker
W32/Generic.Delphi.a(McAfee)
August 17, 2007
http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-081716-1758-99&tabid=2
Tspy_Mamaw
Trojan
The Trojan compromises the database of monster.com and steals personal information from the compromised system. Further send this stealed information to a remote server for performing malicious activities.
No Alias
August 22, 2007
http://blog.trendmicro.com/here-there-be-28monsters29-trojans/
Storm Variants
Worm
Storm worm, also known as Zhelatin started spreading in
January 2007 through email attachments with subject lines related to European storm video.

Trojan.Peacomm (Symantec), CME-711

August 23 , 2007 http://www.cert-in.org.in/currentacts/currentact07.htm#RPSW
Nuwar Variant
Worm
It arrives in spammed e-mail messages which contain a malicious link to You Tube video. As user clicks upon that link, it gets redirected to an IP address which contains HTML script tags instead of You Tube video.
WORM_ZHELATI.MAB
August 29, 2007
http://blog.trendmicro.com/page/6/
Security News

DoS Attack Feared As Storm Worm Siege Escalates
[Source: www.informationweek.com]

August 2, 2007
As the Storm worm grows into a prolonged online siege 10 times larger than any other e-mail attack in the last two years -- amassing a botnet of nearly 2 million computers -- researchers worry about the damage hackers could wreak if they unleash a denial-of-service attack with it.Between July 16 and Aug. 1, researchers at software security firm Postini have recorded 415 million spam e-mails luring users to malicious Web sites, according to Adam Swidler, a senior manager with Postini. Before the Storm worm began its attack, an average day sees about 1 million virus-laden e-mails crossing the Internet. On July 19, Postini recorded 48.6 million and on July 24, researchers tracked 46.2 million malicious messages -- more than 99% of them are from the Storm worm.

[More]

Storm Botnet Behind Canadian DoS Attack
[Source: www.informationweek.com]

August 13, 2007
Researchers are blaming the virulent Storm worm for a widespread denial-of-service attack that hit Canadian Web sites over the weekend.The attack may have been unfocused and unsuccessful, but it could have been an early test of the denial-of-service power that the Storm worm botnet now holds. Johannes Ullrich, chief research officer at the SANS Institute and CTO for the Internet Storm Center, said in an interview that while sites in Canada were "pounded" over the weekend, he doesn't think it was a targeted denial-of-service attack. The attacks weren't aimed at any particular Web sites. It was just spread across a wide swath of the Internet.

[More]

Storm Worm using YouTube
[Source: www.f-secure.com]

August 26, 2007
The latest twist with the Storm Worm / Zhelatin e-mails is that the e-mails now contain fake links to YouTube. In reality, the link redirects to a Zhelatin distribution site. They've added a YouTube logo to the page and the link now points to video.exe. Otherwise it's the same old game.

[More]

Storm Worm of a thousand faces
[Source: www.theregister.com]

August 21, 2007
Authors of a particularly nasty piece of malware known as Storm Worm have yet again shifted their tactics. They are creating a flood of email hoaxes that try to install a bogus "applet" so victims can redeem membership benefits to clubs related to music, online dating and other interests. The new emails bear subject headings such as "User info," "Membership support" and "Login information," and contain purported login credentials for sites that offer the gamut of services tailored to online music aficionados, cat lovers and poker players, according to this post by F-Secure.

[More]

Universities warned of Storm Worm attacks
[Source:www.theregister.com]

August 17, 2007
Colleges and universities have come under attack by Storm Worm botnets following attempts to detect infections through vulnerability scanning, a response centre for academic networks stated last week.The Research and Education Networking Information Sharing and Analysis Centre (REN-ISAC) sent out the warning last Thursday following "numerous incidents" and advised school information technology managers to respond quickly to any infection on their networks.

[More]

Storm Worm Attack Shifts To Malicious Web Pages
[Source: www.informationweek.com]

August 09, 2007
Storm worm attacks have always come in the form of massive e-mail campaigns, but researchers have spotted the attackers creating malicious Web sites. The virulent Storm worm which has been hammering the Internet has changed tactics, opening up a new attack vector. Researchers at SecureWorks discovered late Wednesday that the Storm worm authors have taken their full attention off of e-mail-based attacks and have started creating malicious Web pages. E-mail-based attacks -- phony e-cards and fake news alerts -- have worked exceedingly well, helping the attackers build up a botnet at least 1.7 million strong , according to SecureWorks.

[More]

Spammers debut FDF spam
[Source:www.theregister.co.uk]

August 13, 2007
Spammers have begun experimenting with a new file format as part of their ongoing quest to slip their tiresome messages past junk mail filters.Following on from junk mail messages in the images of emails or in PDF attachments, users now have to contend with spam messages in the FDF (Forms Data Format). FDF files can be read by Acrobat or other PDF reader packages.

[More]

Latest Nuwar Spamming Uses YouTube Lure
[Source:www.avertlabs.com]

August 27, 2007
McAfee Avert Labs has observed a new trend in W32/Nuwar spamming over the weekend. The authors of this malware have resorted to spamming HTML formatted emails that pretend to be from a friend sending a link to a video from YouTube. A copy of the spammed email is as follows:

[More]

Old worm threat returns
[Source:www.techworld.com]

August 24, 2007
An old worm known as Slammer, which originated back in January 2003, is still going strong according to Gunter Ollmann, director of security strategy at IBM's Internet Security Systems (IBM ISS). Ollmann, the author of the white paper " Old threats never die ," says that Slammer is still the threat most commonly encountered by IBM ISS.But it isn't just high-profile vulnerabilities and malware that are a problem, Ollmann said. In effect, the security industry is now witnessing a snowball effect, where threats are accumulating at an "exponential" rate, and it isn't really possible to eradicate any of those threats.

[More]

e-Passports get hacked in new security threat
[Source:www.money.cnn.com]

August 06, 2007
As the nation grapples with difficulties getting new passports, a technology researcher has found another problem with the radio frequency ID technology the new documents carry. Computer security expert Lukas Grunwald cloned and manipulated the content of an RFID passport, then used the hacked e-Passport to crash the machine needed to read it.Grunwald says that although the passport wasn't American the threat certainly extends to American passports, which use similar technology. RFID technology combines silicon chips with antennas to make data accessible via radio waves. It's already a $650 million industry, according to ABI Research, which expects the market to more than triple by 2011.

[More]

Monster data theft also hit U.S. job site
[Source: www.news.com.com]

August 31, 2007
The theft on the USAjobs.gov site, which has about 2 million users, was part of a hacking operation apparently run out of Ukraine that Monster disclosed last week, said Peter Graves, a spokesman for the U.S. Office of Personnel Management.Monster runs the site on behalf of the government.On Wednesday, the government temporarily restricted recruiters from accessing the database until Monster completes efforts to ensure its computer system is secure, Graves said."We disabled it yesterday as an extra precaution on our part to best protect our users," he said by telephone late on Thursday.

[More]

German gov't PCs hacked, China offers to investigate
[Source: www.computerworld.com]

August 28, 2007
Chinese premier Wen Jiabao described reports of Chinese hackers breaking into German computers as a matter of "grave concern" and said Monday that his country will cooperate with Germany to resolve the matter.Jiabao's comments, made during a press conference with German Chancellor Angela Merkel in Beijing, were prompted by a report published two days earlier in the German news magazine Der Spiegel claiming that Chinese hackers had been able to infect German government computers with spyware. Merkel said that for Chinese relations with industrialized countries to move ahead, everyone needs to "respect a set of game rules" and "protect intellectual property rights."

[More]

Sony pleads innocent in latest rootkit fiasco
[Source:www.news.com.com]

August 31, 2007
Sony says the rootkit-like behavior of a device driver used to run its biometric Micro Vault USM-F thumb drive was unintentional.Sony Sweden spokesman Fredrik Fagerstedt told local press this week that sometimes even actions undertaken with "good will" can go wrong.Fagerstedt's comments came the same day that antivirus firm McAfee joined the growing chorus of companies criticizing Sony for compromising its customers' security. The Micro Vault drive is a USB device featuring fingerprint-reading software intended to add an extra layer of security for PC users. The software needed to be installed on the PC for the USB to work contains the rootkit technology.

[More]

NIST Draft Special Publication
[Source:www.csrc.nist.gov]

August 02, 2007
Draft Special Publication 800-111 Guide to Storage Encryption Technologies for End User Devices
Draft Special Publication 800-48 Revision 1 Wireless Network Security for IEEE 802.11a/b/g and Bluetooth

[More]

 

How to neutralize today's worst Web attacks
[Source:www.networkworld.com]

August 22, 2007
Symantec recently posted details about a new version of MPack, a for-sale Web attack kit that loads up a site with exploits against Windows, QuickTime , and WinZip . The $400 kit was used in the June Italian Job online assault that hijacked tens of thousands of Web sites, most of them in Italy . Crooks can buy MPack and a host of other nefarious programs on a thriving online black market . In its post, Symantec listed only which holes the new MPack version targets; I followed up with the company to get specifics and links to fixes.

[More]

300,000 malicious items approaching fast
[Source:www.avertlabs.com]

August 01, 2007
The new threat comes from a number of newly registered Web sites that pretend to represent Italian organizations, but are really just vehicles for using malicious IFrames to spread malware.The Italian job that last month saw more than 10,000 legit Web pages embedded with malicious IFrames has resurfaced, this time with even more international intrigue. Last month's threat pushed malicious HTML files onto Web pages of several Italian Web sites and infected Web surfers visiting those sites.

[More]