![]() |
||||||
|
CERT-In Monthly Security Bulletin
September 2007 | ||||||
|
Cyber Intrusion Trends |
||||||
| In this month 33 security incidents were reported to CERT-In from various
National/ International agencies. As shown in the figure 73%
phishing incidents were reported in the month.15% unauthorized scanning , 3% incidents related to virus/worm under the malicious code category and 9% incidents from others category were reported in this month.As compared to previous month the number of
phishing incidents have increased. In this month CERT-In tracked 4 C&C (Command & Control) servers and 1976 bot-infected computers existing in India.The concerned ISPs were intimated to dis-infect the bot infected systems and C&C servers to mitigate botnets. |
Cyber Intrusion during September 2007
| |||||
|
Indian Websites Defacement |
||||||
In total 60 Indian websites were defaced during September 2007. A chart depicting Top Level Domain(TLD) wise defacements is shown in the figure. The vulnerabilities which might have been exploited for the defacements are: 1. Apache Undefined Charset UTF-7 Cross-Site Scripting (XSS) Vulnerability CIVN-2007-124 2. Multiple Vulnerabilities in PHP CIAD-2007-48
|
Statistics of Defaced Indian Websites in September 2007
| |||||
|
Open proxy servers |
||||||
|
Any proxy server that doesn't restrict its client base to its own set of clients and allows any other client to connect to it, is known as an open proxy server. An open proxy server will accept client connections from any IP address and make connections to any Internet resource. CERT-In tracked 42 open proxy servers functioning in India during September 2007. All the concerned ISPs were alerted immediately to shut down the open proxy servers. A bar chart of open proxy servers tracked during this year is shown in the figure. |
Statistics of Open Proxy Servers tracked during Jan - Sep 2007
| |||||
|
Security Alerts |
||||||
|
The critical and medium vulnerabilities in various Operating Systems, Application software and Network devices discovered during September 2007 and their countermeasures alongwith wide-spreading malicious code like virus/ worm/Trojan are given below: | ||||||
|
High Vulnerabilities | ||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||
| Microsoft Agent ActiveX | Remote Code Execution Vulnerability in Microsoft Agent ActiveX (agentdpv.dll) control | September 12,2007 |
||||
| Microsoft | Multiple Vulnerabilities in various components of Microsoft Windows, Visual Studio , Windows Services for UNIX, Subsystem for UNIX-based Applications , MSN Messenger, Windows Live Messenger | September 12,2007 |
||||
|
Unix |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||
| MIT Kerberos | MIT Kerberos Multiple Vulnerabilities | September 06,2007 |
||||
| PHP | Multiple Vulnerabilities in PHP | September 11,2007 |
||||
| OpenOffice | OpenOffice TIFF file Buffer Overflow Vulnerability | September 19,2007 |
||||
| Linux Kernel | Information disclosure vulnerability in Linux Kernel | September 27,2007 |
||||
|
Cisco |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Cisco | XSS and SQL Injection in Cisco CallManager/Unified Communications Manager Logon Page | September 07 , 2007 |
||||
| Cisco | Denial of Service Vulnerabilities in Content Switching Module |
September 07 , 2007 |
||||
| Cisco | Cisco Video Surveillance IP Gateway and Services Platform Authentication Vulnerabilities |
September 07 , 2007 |
||||
|
Miscellaneous |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| MSN Messenger and Windows Live Messenger | Remote Code Execution Vulnerability in MSN Messenger and Windows Live Messenger | September 12,2007 |
||||
| OpenSSH | OpenSSH Trusted X11 Forwarding Vulnerability |
September 12,2007 |
||||
| Mozilla Firefox | Mozilla Firefox 2.0.0.6 Unspecified Protocol Handling Command Injection Vulnerability | September 12,2007 |
||||
| Mozilla | disclosure of information vulnerability in Mozilla | September 13,2007 |
||||
| Apple QuickTime | Apple QuickTime Remote Code Execution Vulnerability |
September 22,2007 |
||||
| Cross-Site Scripting (XSS) Vulnerabilities in google | September 27,2007 |
|||||
|
Medium Vulnerabilities |
||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Microsoft Visual Studio | Remote Code Execution Vulnerability in Crystal Reports for Microsoft Visual Studio |
September 12,2007 |
||||
| Microsoft Windows | Microsoft Windows Services for UNIX Privilege Escalation Vulnerability | September 12,2007 |
||||
| Microsoft Windows | Microsoft Windows CFileFind Class "FindFile()" Buffer Overflow vulnerability |
September 19,2007 |
||||
| Microsoft ISA Server | Information Disclosure Vulnerability in Microsoft ISA Server SOCKS4 Proxy Connection | September 26,2007 |
||||
|
Unix |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| PHP | Multiple Iconv functions denial of service vulnerability in PHP | September 12,2007 |
||||
| Apache | Apache Undefined Charset UTF-7 Cross-Site Scripting (XSS) Vulnerability |
September 20,2007 |
||||
Malicious Code Threats |
||||||
|
Title of Malicious Code |
Type |
Overview |
Aliases |
Discovery Date |
References | |
| Pykse Worm Variant | Worm |
This worm is spreading via Skype Instant Messanger or removable drives.It collects e-mail addresses from the compromised computer and send messages to download a copy of itself by using various social engineering techniques. | WORM_SKIPI.A [Trend], W32/Pykse.worm.b [McAfee], WORM_SKIPI.B [Trend], W32.Pykspa.D [Symantec] |
September 14,2007 |
||
| Virut | Virus |
It is a polymorphic file infector virus which infects the file with .exe and .scr extensions. This virus creates an IRC backdoor on the infected system to connect itself to the IRC server and listen commands from the remote attacker. | Virus.Win32.Virut.n [Kaspersky], W32/Virut.gen [McAfee], W32.Virut.U[Symantec], W32/Virut.U [Avira] |
September 14,2007 |
||
| W32.Yalove | Worm |
This worm spreads through Yahoo! Instant Messenger and by copying itself to all drives.It redirects the Internet browser to the malicious Urls which hosts copy of the worm. | No Alias |
September 20,2007 |
http://www.symantec.com/business/security_response/writeup.jsp?docid=2007-092102-4040-99&tabid=1 |
|
| W32.Imaut.BA | Worm |
This worm spreads itself by sending a malicious link embedded in different messangers like Yahoo! Instant Messenger, AOL. | No Alias |
September 20,2007 |
http://www.symantec.com/business/security_response/writeup.jsp?docid=2007-092105-2813-99&tabid=1 |
|
Googbot |
Worm |
The worm exploits Trend Micro ServerProtect multiple stack-based buffer overflow vulnerability and Windows LSA (Local Security Authority) Service Stack-Based Buffer Overflow vulnerability. Further it opens a backdoor on the infected system on TCP port 7001 to listen for remote attacker commnads. | WORM_AGENT.AAWD [Trend], W32 Duce.a@mm [McAfee], Backdoor.W32.GoogBot.A [Kaspersky] |
September 24,2007 | ||
|
Security News |
||||||
| Botnet Steals eBay Accounts September 04, 2007 Skype Warns Users of P-to-P Worm September 10, 2007 Microsoft downplays stealth update concerns September 13, 2007 New cracks in Google mail September 28, 2007 Yesterday, we reported on an unholy trinity of Google vulnerabilities that put emails, private photos and website security at risk. Today came word of a new weakness that makes it easy for bad guys to silently put a backdoor in Gmail accounts. The technique comes courtesy of Petko D. Petkov, a researcher at GNU Citizen, who writes in a blog post that the backdoor is installed simply by luring a victim to a specially crafted website while logged in to Gmail. The naughty site uses a sleight of hand known as a multipart/form-data POST, which writes a filter to Gmail that causes all email with attachments to be forwarded to collect@evil.com. Unholy trinity of flaws put Google users at risk September 24, 2007 China leads Asia in malicious online activity September 20, 2007 Hacked GOP site infects visitors with notorious bot-making malware New twist on Nigerian email scam August 22, 2007 The reason Fotouh wants to share this obvious fact can be traced back to his computer. Last week someone gained control of Fotouh's home computer, changed the password then started sending e-mails to everyone Fotouh knows with an urgent plea for money. "The guy is speaking on my behalf, from my email address, to make people believe I am the one who originated the message," Fotouh said. Trojan planted on US Consulate website September 20, 2007 Viruses: One in 28 e-mails September 12, 2007 Canadian police detain Nigerian in alleged 419 scam
A Nigerian national who had been living in Canada was taken into custody by Winnipeg police in connection with a West African email scam alleged to have bilked an 84-year old man of $30,000. Toluwalade Alonge Owolabi, 36, of Toronto, was charged with fraud in excess of $5,000, fraud of less than $5,000 and five other offenses, according to an article in the Edmonton Sun . The suspect was nabbed at the victim's Winnipeg home, after traveling there to pick up another payment, police said. By then, the victim had grown wise to the scam and alerted the cops. Symantec: Bank account details fetch $400 online September 17, 2007 The online trade in stolen data highlights the commercialization of Internet crime, with gangs researching, developing and marketing nefarious software for other criminals, said William Beer, director of Symantec's security practice for Europe. AIM vulnerable to worm attack, researchers warn September 26, 2007
Infrastructure threats: Botnets show DoS who's boss September 18, 2007 Cybercrime is a US$105 billion business now September 26, 2007 Investigators: Homeland Security Computers Hacked September 26, 2007 |
||||||