![]() |
||||||
|
CERT-In Monthly Security Bulletin
July 2007 | ||||||
|
Cyber Intrusion Trends |
||||||
| In this month 38 security incidents were reported to CERT-In from various National/ International agencies. As shown in the figure 63% phishing incidents were reported in the month. 29% unauthorized scanning and 8% incidents related to virus/worm under the malicious code category were reported in this month.As compared to previous month the number of phishing incidents have increased and scanning incidents have decreased..In this month CERT-In tracked 4 C&C (Command & Control) servers and 14,835 bot-infected computers existing in India.The concerned ISPs were intimated to dis-infect the bot infected systems and C&C servers to mitigate botnets. |
Cyber Intrusion during July 2007
| |||||
|
Indian Websites Defacement |
||||||
In total 48 Indian websites were defaced during July 2007. A chart depicting Top Level Domain(TLD) wise defacements is shown in the figure. The vulnerabilities which might have been exploited for the defacements are: 1. Microsoft IIS (Internet Information Server 5.1) DLL Request Denial of Service Vulnerability CIVN-2007-86 2. PHP-Fusion ShoutBox_Panel.PHP Cross-Site Scripting Vulnerability CVE-2007-3559 3.PHP "glob()" Function Arguments Processing Arbitrary Code Execution Vulnerability 4.PHP Win32STD Extension Safe_Mode and Disable_Functions Restriction Bypass Vulnerability
|
Statistics of Defaced Indian Websites in July 2007
| |||||
|
Open proxy servers |
||||||
|
Any proxy server that doesn't restrict its client base to its own set of clients and allows any other client to connect to it, is known as an open proxy server. An open proxy server will accept client connections from any IP address and make connections to any Internet resource. CERT-In tracked 54 open proxy servers functioning in India during July 2007. All the concerned ISPs were alerted immediately to shut down the open proxy servers. A bar chart of open proxy servers tracked during this year is shown in the figure. |
Statistics of Open Proxy Servers tracked during Jan - July 2007
| |||||
|
Security Alerts |
||||||
|
The critical and medium vulnerabilities in various Operating Systems, Application software and Network devices discovered during July 2007 and their countermeasures alongwith wide-spreading malicious code like virus/ worm/Trojan are given below: | ||||||
|
High Vulnerabilities | ||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||
|
Microsoft Excel |
Microsoft Excel Remote Code Execution vulnerabilities |
July 11, 2007 |
||||
| Microsoft Windows | Microsoft Windows Active Directory Vulnerabilities | July 11, 2007 |
||||
| Microsoft .NET | Remote Code Execution Vulnerabilities in Microsoft .NET Framework | July 11, 2007 |
||||
| Microsoft | Multiple Vulnerabilities in various components of Microsoft Windows, Windows Active Directory, Microsoft IIS, Microsoft .NET Framework, Microsoft Vista, Microsoft Office Publisher 2007 and Microsoft Office | July 11, 2007 |
||||
| Microsoft | Microsoft DirectX RLE Compressed Targa Image Processing Buffer Overflow Vulnerability | July 25, 2007 |
||||
| Microsoft Windows | Microsoft Windows URI Handling Command Execution Vulnerability | July 31, 2007 |
||||
|
Unix |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||
| PHP | PHP "glob()" Function Arguments Processing Arbitrary Code Execution Vulnerability | July 16,2007 |
||||
| TCPDump | tcpdump print-bgp.c Buffer Overflow Vulnerability | July 19,2007 |
||||
|
Database |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Oracle | Multiple vulnerabilities exist in various Oracle products | July 19, 2007 |
||||
|
Miscellaneous |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Mozilla Firefox | Mozilla Firefox OnKeyDown Event File Upload Vulnerability | July 04, 2007 |
||||
| Mozilla Firefox | Mozilla Firefox and Internet Explorer URL Protocol Handler Vulnerability | July 16, 2007 |
||||
| Adobe Flash Player | Input Validation Error, HTTP Referer and Information Disclosure Vulnerabilities in Adobe Flash Player | July 16, 2007 |
||||
| Cisco | Cisco Unified Communications Manager and Presence Server Unauthorized Access Vulnerability | July 16, 2007 |
||||
| Apple QuickTime | Multiple Memory corruption vulnerabilities in Apple QuickTime | July 18, 2007 |
||||
| Mozilla Firefox | Multiple Vulnerabilities in Mozilla Firefox | July 19, 2007 |
||||
| Cisco | Wireless ARP Storm Vulnerabilities | July 26, 2007 |
||||
|
Medium Vulnerabilities |
||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Microsoft Office | Microsoft Office Publisher 2007 Invalid Memory Reference Vulnerability |
July 11, 2007 |
||||
| Microsoft Windows | Microsoft Windows Vista Teredo Interface Firewall Bypass Vulnerability | July 11,2007 |
||||
| Microsoft IIS | Microsoft IIS (Internet Information Server 5.1) DLL Request Denial of Service Vulnerability | July 11,2007 |
||||
|
Unix |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Linux Kernel | Linux Kernel USBLCD Memory Consumption Denial Of Service Vulnerability | July 03,2007 |
||||
| PHP-Fusion | PHP-Fusion ShoutBox_Panel.PHP Cross-Site Scripting Vulnerability | July 04,2007 |
||||
| Linux Kernel | Linux Kernel Decode_Choices Function Remote Denial Of Service Vulnerability | July 09,2007 |
||||
| Sun Solaris | Sun Solaris "rcp" Command Filename Processing Code Execution Vulnerability | July 11,2007 |
||||
| PHP | PHP Win32STD Extension Safe_Mode and Disable_Functions Restriction Bypass Vulnerability | July 26,2007 |
||||
Malicious Code Threats |
||||||
|
Title of Malicious Code |
Type |
Overview |
Aliases |
Discovery Date |
References | |
| W32.Fubalca.N |
Worm | It is a worm that spreads through removable storage devices and by infecting various types of files. It disables antivirus programs and lowers security settings on the compromised computer.Tries to exploit the vulnerability described in CIVN-2007-63 | No Alias |
July 12, 2007 |
http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-071301-4136-99&tabid=1 | |
| TROJ_BANLOAD | Trojan | It is circulating via spam email messages or dropped by other malware and exploiting Brazilian plane crash tragedy to compromise the system in order to steal information for some monetary gain purpose. |
No Alias |
July 24, 2007 |
http://www.cert-in.org.in/virus/TROJ_BANLOAD.htm | |
| Rubble Worm | Trojan | It scans local and removable drives of a system for the file of any extension.It steals the name of the scanned files for malicious purpose and overwrites them with its own copy and rename their extension to exe. | No Alias |
July 24, 2007 |
http://www.cert-in.org.in/virus/RUBBLEWORM.htm | |
| Linux.Backdoor.Rexob | Trojan | It is a trojan horse program that opens a backdoor on the compromise linux system. |
No Alias |
July 26, 2007 |
http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-072612-1704-99&tabid=1 | |
| Trojan.Srizbi | Trojan | Trojan.Srizbi is a full kernel malware which gets downloaded while visiting the websites compromised from Mpack toolkit. | Rootkit:W32/Agent.EA [F-Secure], Trojan.Srizbi [Symantec], Troj/RKAgen-A [Sophos] |
July 30, 2007 |
http://www.cert-in.org.in/virus/Srizbi_troj.htm | |
|
Security News |
||||||
|
Hackers steal government, corporate data Hackers stole information from the Department of Transportation and several U.S. corporations by seducing employees with fake job listings on ads and e-mail, a computer security firm said on Monday.The list of victims included several companies known for providing security services to government agencies. Details on defacement of Microsoft's U.K. Web site Details have emerged of an attack which defaced Microsoft's U.K. Web site.Hackers broke through the site's security, defacing it and replacing genuine content with a photo of a child waving a Saudi Arabian flag.It is likely that the company's U.K. site, which was breached on Wednesday, was subverted using an SQL injection, in which hackers exploit application vulerabilities to alter server settings or mine data, according to Zone-H, which has also run a picture of the defacement. DNS Security Problems Widespread and Poorly Understood: Study Nearly half of IT and business professionals surveyed by Mazerov Research reported a security compromise of their Domain Name System servers, despite spending money on overlapping security products. Web application security -- time for services Web application security, like other forms of vulnerability scanning is as much an art as science. The vendors are pretty good at detecting known vulnerabilities, and generating lovely reports for IT on all that they've found. However, for all of the advances in the technology, the vendors are unable to tell their customers that their customer-facing applications are secure or to articulate business benefits beyond meeting a PCI requirement. Chinese computers vulnerable to viruses With over half of computers attacked by viruses in the first half of this year, China has become one of the most serious computer virus-stricken regions in the world, sources report. In a report from a Chinese anti-virus company, Rising Technology Company, the Mainland has over 35 million computers attacked by viruses during the first half of this year. Spammers Exploit Brazilian Plane Crash Spammers are luring unsuspecting users to a malicious Web site by sending out e-mails promising information about the crash and the victims onboard. Spammers were quick to take advantage of the tragic plane crash in Brazil this week. FBI Analyst Sentenced To 10 Years For Stealing National Secrets McAfee sets Rootkit Detective free Auction site sells security exploits An eBay-like auction site that sells vulnerabilities will improve security by ensuring researchers get a fair price for their work, its founders say."The existing business model to reward researchers is a failure," said Herman Zampariolo, chief executive of WSLabi, and the man behind the WabiSabiLabi auction site. A tiny minority of vulnerabilities currently get patched, he said, because IT experts aren't paid for their work in uncovering them: "If the firemen are not paid, it's not easy to extinguish a fire." Virus Top 20 for July 2007 The activity of the botnet that was created in May via the Agent.bqs Trojan was only reaching its “design capacity” in June; by July it was in full swing. Another member of the Warezov family, which is distributed by this zombie network, reached the top position on the chart, accounting for 22% of the malicious code in mail traffic. Sophos has published its latest report on the top twelve spam-relaying countries over the second quarter of 2007 SophosLabs scanned all spam messages received in the company's global network of spam traps, and have revealed that the US continues to relay more spam than any other nation, accounting for 19.6 per cent - a decrease of just 0.2 per cent from the previous quarter. However, Europe now has six entries in the dirty dozen, which when combined, account for even more spam-relaying than the US. Escaping a virtual machine Excel Latest Vehicle for 'Pump-and-Dump' Spam "Pump-and-dump" spammers have found a new package for their scam: Excel files. Commtouch researchers reported the appearance of pump-and-dump spam in Excel files for the first time on July 21. The spam promotes stocks in file attachments with names such as "invoice20202.xls," "stock information-3572.xls" and "requested report.xls." Recent change in Stock-Spam Tactics (PDF and excel) It started nearly a month ago, a shift from image-based spam to spams containing PDF files.I'm sure that you've seen these in your mailbox, the shift over to PDF was effective in evading spam-filters. You have also likely noted their shift in tactics from a simple text message in the PDF over to encoded images in the PDF (to foil pdf2text-like tools, I presume.) New Attack Uses Bogus Web Sites To Deliver Malware The new threat comes from a number of newly registered Web sites that pretend to represent Italian organizations, but are really just vehicles for using malicious IFrames to spread malware.The Italian job that last month saw more than 10,000 legit Web pages embedded with malicious IFrames has resurfaced, this time with even more international intrigue. Last month's threat pushed malicious HTML files onto Web pages of several Italian Web sites and infected Web surfers visiting those sites. The return of the ransom-ware Trojan Virus writers are revisiting the tactic of holding data on compromised machines to ransom with a new strain of so-called "ransom-ware" Trojan. PayPal data stealing trojan and IcePack malware installer PayRob.A is a Trojan designed to steal data from PayPal accounts. Like most Trojans, PayRob.A cannot spread by itself, but needs intervention from a malicious user to reach computers.If the targeted user runs the file carrying PayRob.A, it gives itself hidden file attributes and modifies the Windows Registry to ensure it is run whenever the system is restarted. Fun & Games - A new Storm Worm variant - 'Trojan.Win32.Agent.auh' We're seeing a substantial seeding of a new Storm Worm variant. The attachment is static, and the emails look like this (sender information varies): Worm eats music on infected PCs Virus writers have unleashed a worm that attempts to delete MP3 files from infected machines.The Deletemusic worm spreads via removable devices. As soon as an infected device is accessed the worm will be executed. Thereafter it copies itself onto all drives, including removable devices, and executes whenever Windows is started up on compromised PCs. Storm Worm Erupts Into Worst Virus Attack In 2 Years The Storm worm authors are waging a multi-pronged attack and generating the largest virus attack some researchers say they've seen in two years.
|
||||||