![]() |
||||||
|
CERT-In Monthly Security Bulletin
February 2008 | ||||||
|
Cyber Intrusion Trends |
||||||
| In this month 85 security incidents were reported to CERT-In from various National/ International agencies. As shown in the figure 48% phishing incidents were reported in this month. 20% unauthorized scanning ,4% incidents related to virus/worm under the Malicious code category and 28% incidents related to technical help under the Others category were reported in this month.As compared to previous month the number of phishing incidents and incidents related to technical help under the Others category have incresaed while scanning and incidents related to virus/worm under the Malicious code category have decreased. In this month CERT-In tracked 10 C&C (Command & Control) servers and 1279 bot-infected computers existing in India.The concerned ISPs were intimated to dis-infect the bot infected systems and C&C servers to mitigate botnets. |
Cyber Intrusion during February 2008 |
|||||
| Attack Trends | ||||||
Propagation of Storm worm variants through Valentines Day greetings: It has been observed that new variants of ‘Storm Worm' are circulating via e-mails pretending to be Valentine's Day Greetings. These spam e-mails comes with the subject line such as “Valentine's Day”, “The Love Train” and other Valentine's Day related phrases. E-mail contains URL in form of IP address, which takes to the user to malicious website hosting malware “valentine.exe”. Fake Microsoft Windows Update Websites: It has been observed that Malicious files are being propagated through fraudulent websites pretending to be providing updates to Microsoft Windows.Spam emails are being sent to users to trick them to click on link to fraudulent Website. The malicious link directs users to a Webpage asking users to click upon Urgent Install button. As user clicks upon the button an executable file named WindowsUpdateAgent30-x86-x64.exe gets downloaded to the system. This executable file is malware named as Trojan- Dropper:W32/Agent.DYD which then drops another malware, identified as Backdoor:W32/Agent.CVU. ActiveX Vulnerabilities in Yahoo! MediaGrid, YMP Datagrid, Facebook and MySpace: It has been observed in this month that vulnerabilities in several ActiveX controls was used to exploit the vulnerable applications such as Yahoo! MediaGrid ActiveX control , YMP Datagrid ActiveX control and image uploader used by Facebook and MySpace.The vulnerabilities can be used to execute arbitrary code or crash the vulnerable application. |
||||||
| Training | ||||||
Workshop on “Implementation of Information Security Management in Government & Critical Sector Organisations” CERT-In conducted a one day Workshop on “Implementation of Information Security Management in Government & Critical Sector Organisations” on 12th February, 2008.The interactive workshop covered the following topics at length:
The presentation material is available here. |
||||||
Indian Websites Defacement |
||||||
In total 214 Indian websites under .in were defaced during February 2008. A chart depicting Top Level Domain(TLD) wise defacements is shown in the figure. The vulnerabilities which might have been exploited for the defacements are: 1. Duplicate Request-Processing and Information Disclosure Vulnerabilities in Apache Tomcat CIAD-2008-12
|
Statistics of Defaced Indian Websites in February 2008
|
|||||
| Open proxy servers | ||||||
Any proxy server that doesn't restrict its client base to its own set of clients and allows any other client to connect to it, is known as an open proxy server. An open proxy server will accept client connections from any IP address and make connections to any Internet resource. CERT-In tracked 60 open proxy servers functioning in India during February 2008. All the concerned ISPs were alerted immediately to shut down the open proxy servers. A bar chart of open proxy servers tracked during this year is shown in the figure. |
Statistics of Open Proxy Servers tracked during 2008
|
|||||
|
Security Alerts |
||||||
|
The critical and medium vulnerabilities in various Operating Systems, Application software and Network devices discovered during Feburary 2008 and their countermeasures alongwith wide-spreading malicious code like virus/ worm/Trojan are given below: | ||||||
|
High Vulnerabilities | ||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||
| Microsoft Windows | Microsoft Windows WebDAV Mini-Redirector Buffer Overflow Vulnerability | February 13, 2008 |
||||
| Microsoft Windows | Microsoft Object Linking and Embedding (OLE) Automation Heap Based Buffer Overflow Vulnerability |
February 13, 2008 |
||||
| Microsoft Word | Microsoft Word Memory Corruption Vulnerability | February 13, 2008 |
||||
| Microsoft Internet Explorer | HTML Rendering Memory Corruption, Property Memory Corruption, Argument handling memory corruption and ActiveX object memory corruption vulnerabilities in Microsoft Internet Explorer | February 13, 2008 |
||||
| Microsoft Office | Microsoft Office Publisher Invalid Memory Reference and Memory Corruption Vulnerabilities | February 13, 2008 |
||||
| Microsoft Office | Microsoft Office Object Parsing Memory Corruption Vulnerability | February 13, 2008 |
||||
| Microsoft | Multiple Vulnerabilities in various components of Microsoft Windows, Internet Explorer,IIS Server, Office, Active Directory, Works and Publisher | February 13, 2008 |
||||
|
Unix |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||
| Linux Kernel | Linux Kernel “vmsplice” system call, vserver-enabled, fault handler range check Vulnerabilities |
Februrary 15, 2008 |
||||
|
Miscellaneous |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Mozilla Products | Multiple Vulnerabilities in Mozilla Products | February 11, 2008 |
||||
| Adobe Reader/Acrobat | Multiple vulnerabilities in Adobe Reader/Acrobat | February 11, 2008 |
||||
| Mozilla Firefox | Multiple Vulnerabilities in Mozilla Firefox | February 11, 2008 |
||||
|
Medium Vulnerabilities |
||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Microsoft Windows | Microsoft Active Directory Denial of Service Vulnerability | February 13, 2008 |
||||
| Windows Vista | Windows Vista DHCP Packet Handling Denial of Service Vulnerability |
February 13, 2008 |
||||
| Microsoft IIS | Microsoft IIS File Change Notification vulnerability |
February 13, 2008 |
||||
| Microsoft IIS | Remote Code Execution Vulnerability in Microsoft Internet Information Services (IIS) |
February 13, 2008 |
||||
| Microsoft Works | Microsoft Works File Converter Vulnerabilities | February 13, 2008 |
||||
|
Unix |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Apache Tomcat | Duplicate Request-Processing and Information Disclosure Vulnerabilities in Apache Tomcat | Februrary 15, 2008 |
||||
|
Cisco |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Cisco | SQL injection vulnerability in Cisco Unified communications Manager | February 20, 2008 |
||||
| Cisco | Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities | February 20, 2008 |
||||
Malicious Code Threats |
||||||
|
Title of Malicious Code |
Type |
Overview |
Aliases |
Discovery Date |
References | |
| Cutwail Trojan |
Trojan |
The trojan propagates by attaching a copy of itself to the email messages with message body which lures users into opening up the attachment to get malware installed on their system. |
Trojan.Pandex [Symantec], Win32/Cutwail [Microsoft] |
February 05, 2008 |
||
| EXPL_PIDIEF | PDF Exploit | It arrives as an email attachment spammed by another malware or a malicious user. It exploits several vulnerability in versions of Adobe Reader earlier than 8.1.2. Upon successful exploitation the malware gets connected to certain websites to downloads other malwares on the infected system. | Exploit-PDF.b [McAfee], Trojan.Pidief.C [Symantec], HTML/Shellcode.Gen [Avira], Mal/JSShell-B [Sophos], Exploit:Win32/Pdfjsc.A [Microsoft] |
February 10, 2008 |
http://www.trendmicro.com/vinfo/ |
|
| SilentBanker Trojan | Trojan |
The trojan can intercept transactions carried out by users and change the user-entered destination bank account details to the attacker's account details without being noticed by the user. It propagates through web or dropped by some other malware and automatically gets executed on the users system. |
No Alias |
February 11, 2008 |
||
| BKDR_AGENT | Backdoor (Trojan) | The backdoor gets dropped into users systems by other malwares or gets installed unknowingly by users while visiting malicious Websites. It creates a backdoor through random ports on the infected system and listen to remote attacker’s commands. | Proxy-Agent.af.gen (McAfee), Trojan.Asprox (Symantec), BDS/Backdoor.Gen (Avira), Troj/AgentM-Fam (Sophos), Backdoor:Win32/Agent.ACG (Microsoft) |
Feb 21, 2008 |
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName =BKDR_AGENT.AKJZ |
|
|
Security News |
||||||
Malware writers think global, act local February 22, 2008 Fraud cases breached £1bn level in 2007 February 04, 2008
FTC lists 2007's top consumer frauds VMware vuln exposes the perils of virtualization February 25, 2008 Europe still top source of spam February 06, 2008
DoS attack prevents access to WordPress.com blogs February 19, 2008
Universities fend off phishing attacks February 01, 2008
E-Mail Carries Love And Viruses For Valentine's Day February 12, 2008 Flaws Found In ActiveX Controls Used By Facebook, MySpace February 05, 2008
Web Browsing, Search, And Online Ads Grow More Risky, Google Says February 12, 2008 Orkut worm feeds on scraps February 29, 2008 Japan brings down Godzilla of spam February 19, 2008
MayDay! MayDay! Ruskies reinvent cyber crime February 13, 2008 |
||||||