![]() |
||||||
|
CERT-In Monthly Security Bulletin
October 2007 | ||||||
|
Cyber Intrusion Trends |
||||||
| In this month 49 security incidents were reported to CERT-In from various
National/ International agencies. As shown in the figure 61%
phishing incidents were reported in this month. 27% unauthorized scanning , 8% incidents related to virus/worm under the malicious code category and 4% incidents from others category were reported in this month.As compared to previous month the number of
phishing incidents have decreased and scanning incidents have increased. In this month CERT-In tracked 4 C&C (Command & Control) servers and 1370 bot-infected computers existing in India.The concerned ISPs were intimated to dis-infect the bot infected systems and C&C servers to mitigate botnets. In this month CERT-In tracked 450 storm-bot infected computers. The concerned ISPs were communicated to dis-infect these systems. |
Cyber Intrusion during October 2007
| |||||
|
Indian Websites Defacement |
||||||
In total 143 Indian websites were defaced during October 2007. A chart depicting Top Level Domain(TLD) wise defacements is shown in the figure. The vulnerabilities which might have been exploited for the defacements are: 1. Apache Tomcat WebDAV Arbitrary File Content Disclosure CVE-2007-5461 2. PHP COM Objects Security Bypass CVE-2007-5653
|
Statistics of Defaced Indian Websites in October 2007
| |||||
|
Open proxy servers |
||||||
|
Any proxy server that doesn't restrict its client base to its own set of clients and allows any other client to connect to it, is known as an open proxy server. An open proxy server will accept client connections from any IP address and make connections to any Internet resource. CERT-In tracked 61 open proxy servers functioning in India during October 2007. All the concerned ISPs were alerted immediately to shut down the open proxy servers. A bar chart of open proxy servers tracked during this year is shown in the figure. |
Statistics of Open Proxy Servers tracked during Jan - Oct 2007
| |||||
|
Security Alerts |
||||||
|
The critical and medium vulnerabilities in various Operating Systems, Application software and Network devices discovered during October 2007 and their countermeasures alongwith wide-spreading malicious code like virus/ worm/Trojan are given below: | ||||||
|
High Vulnerabilities | ||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||
| Microsoft | Network News Transfer Protocol Memory Corruption Vulnerability | October 10, 2007 |
||||
| Microsoft | Multiple Vulnerabilities in Microsoft IE could Allow Remote Code Execution | October 10, 2007 |
||||
| Microsoft Word | Microsoft Word Memory Corruption Vulnerability |
October 10, 2007 |
||||
| Microsoft | Multiple Vulnerabilities in various components of Microsoft Windows: Microsoft Windows Kodak Image Viewer, Network News Transfer Protocol, Microsoft IE, RPC Authentication, Microsoft Windows Share Point Service 3.0 and Share point server 2007, Microsoft Word |
October 10, 2007 |
||||
|
Unix |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||
| OpenSSL | OpenSSL SSL_get_shared_ciphers () Function and DTLS Implementation Vulnerability | October 19, 2007 |
||||
| PHP | PHP COM Objects Security Bypass | October 23, 2007 |
||||
|
Database |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Oracle | Multiple vulnerabilities Exist in various Oracle products | October 22, 2007 |
||||
|
Cisco |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Cisco | Cisco Wireless Control System Conversion Utility Adds Default Password | October 12, 2007 |
||||
| Cisco | Cisco IOS LPD Remote Stack Overflow | October 12, 2007 |
||||
| Cisco | Multiple Vulnerabilities in Cisco PIX and ASA Appliances | October 24, 2007 |
||||
| Cisco | Cisco Unified Communications Web-based Management Vulnerability | October 24, 2007 |
||||
| Cisco | Cisco Unified Communications Manager Denial of Service Vulnerabilities | October 24, 2007 |
||||
| Cisco | Extensible Authentication Protocol Vulnerability |
October 30, 2007 |
||||
|
Miscellaneous |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| RealPlayer | RealPlayer Playlist Handling Buffer Overflow Vulnerability | October 24, 2007 |
||||
| Firewall | Multiple Vulnerabilities in Firewall Services Module | October 24, 2007 |
||||
| Mozilla | Multiple Vulnerabilities in Mozilla Products | October 24, 2007 |
||||
|
Medium Vulnerabilities |
||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Microsoft Windows | Microsoft Windows Kodak Image Viewer Remote Code Execution Vulnerability |
October 10, 2007 |
||||
| Microsoft Windows | Microsoft Windows RPC Authentication Denial of Service Vulnerability | October 10, 2007 |
||||
| Microsoft Windows | Cross-site scripting vulnerability in Microsoft Windows Share Point Service 3.0 and Share point server 2007 | October 10, 2007 |
||||
|
Unix |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Linux Kernel | Multiple Vulnerabilities in Linux Kernel |
October 01, 2007 |
||||
| Apache Tomcat | Apache Tomcat WebDAV Arbitrary File Content Disclosure | October 25, 2007 |
||||
Malicious Code Threats |
||||||
|
Title of Malicious Code |
Type |
Overview |
Aliases |
Discovery Date |
References | |
| Nethell Trojan |
Trojan |
Nethell Trojan , also known as TR/Drop.NetHell started spreading in April 2006. It uses key logging features to capture information from the infected system as user enters any login information and sends the captured information to the malicious attacker. | Trojan-Dropper.Win32.Agent.ayg [Kaspersky], PWS-Banker.gen.ad [McAfee], Trojan.Nethell [Symantec], TR/Drop.NetHell.A [Avira] |
October 12, 2007 |
||
| Worm Minera | Worm |
It propagates by copying itself to the network shares and newly attached media such as removable drives in the form of the following executables : %DriveLetter%\Minerva Game.exe %DriveLetter%\New_Games.exe |
W32/Minerv-A [Sophos] |
October 26, 2007 |
http://www.symantec.com/business/security_response/writeup.jsp?docid=2007-102615-0143-99&tabid=1 |
|
| Trojan Exploiting PDF Vulnerability | Trojan |
The Trojan comes as a PDF attachment in spammed e-mails with subject lines enticing innocent users into opening the malicious file and executing the malware on their systems. It is exploiting Remote code Execution vulnerability in Adobe Acrobat PDF File described in CIVN-2007-128 |
EXPL_PIDIEF.B [FrSirt], Trojan.Pidief.A [Symantec], EXPL_PIDIEF.B [Trend Micro], Exploit.Win32.AdobeReader.b [Kaspersky] |
October 30, 2007 |
||
|
Security News |
||||||
Report: U.S. tops list of spam-offending countries October 26, 2007 Spammers turn YouTube into spam relay channel October 05, 2007 Research Shows Image-Based Threat on the Rise October 18, 2007 Death by iFrame October 08, 2007 Yahoo! Teams! With! eBay! And! PayPal! To! End! Phishing! October 06, 2007 Report: PDF files used to attack computers October 27, 2007 Russian Crooks Spreading Gozi Trojan with PDFs Storm Worm Sent 15 Million Pump-And-Dump E-Mails Last Month October 25, 2007 'Storm worm' exploits YouTube October 10, 2007 Storm worm pulls Halloween hoax October 31, 2007 Malware is Multiplying, Study Warns F-Secure sees smaller botnets on the rise October 01, 2007 Skype Trojan steals login credentials October 17, 2007
Industry Hears First 'SingingSpam'
October 30, 2007
Spyware Fighting Tools Needed October 30, 2007 One of the spyware bills passed by the House of Representatives earlier this year, the Spy Act, would give the FTC authority to impose civil fines on companies that distribute spyware to consumers' computers. The bill, along with the Internet Spyware Prevention (or I-SPY) Act have stalled in the Senate since passing the House in May and June. The FTC has the authority to collect profits from spyware operations and collect money for consumer redress, but it lacks the authority to impose other fines, as it does when going after spammers, said Commissioner Jon Leibowitz, speaking at a spyware forum in Washington , D.C.
|
||||||