![]() |
||||||
|
CERT-In Monthly Security Bulletin
February 2007 | ||||||
|
Cyber Intrusion Trends | ||||||
| In this month 39 security incidents were reported to CERT-In from various National/ International agencies. As shown in the figure 64% phishing incidents were reported in this month.18% incidents related to virus/worm under the malicious code category and 18% unauthorized scanning incidents were reported. As compared to previous month the number of scanning and virus/worm incidents have increased while and phishing incidents have decreased. |
Cyber Intrusion during February 2007
| |||||
|
Indian Websites Defacement | ||||||
|
In total 858 Indian websites were defaced during February 2007. Mostly
the websites under .com domain were defaced by
the hacker groups. A chart depicting Top Level Domain(TLD) wise
defacements is shown in the figure. The vulnerabilities which might have been exploited for the defacements are: 1.Multiple vulnerabilities in PHP
|
Statistics of Defaced Indian Websites in February 2007
| |||||
|
Open proxy servers | ||||||
|
Any proxy server that doesn't restrict its client base to its own set of clients and allows any other client to connect to it, is known as an open proxy server. An open proxy server will accept client connections from any IP address and make connections to any Internet resource. CERT-In tracked 76 open proxy servers functioning in India during February 2007. All the concerned ISPs were alerted immediately to shut down the open proxy servers. A bar chart of open proxy servers tracked during this year is shown in the figure. |
Statistics of Open Proxy Servers tracked during May 2006 - Feb 2007
| |||||
|
Security Alerts | ||||||
|
The critical and medium vulnerabilities in various Operating Systems, Application software and Network devices discovered during Feburary 2007 and their countermeasures alongwith wide-spreading malicious code like virus/ worm/Trojan are given below: | ||||||
|
High Vulnerabilities | ||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||
|
Microsoft Office |
Microsoft Office Remote Code Execution Vulnerability |
February 05, 2007 |
||||
|
Microsoft Windows |
Microsoft Windows HTML Help ActiveX Control Vulnerability |
February 14, 2007 |
||||
|
Microsoft PDF File |
Microsoft Malware Protection Engine PDF File parsing vulnerability |
February 14, 2007 |
||||
|
Microsoft Office |
Microsoft Office Malformed Record Vulnerabilities |
February 14, 2007 |
||||
|
Microsoft Internet Explorer |
Microsoft Internet Explorer COM Object Instantiation and FTP server Response Parsing Vulnerabilities |
February 14, 2007 |
||||
| Microsoft | Multiple Vulnerabilities in Microsoft Windows, Internet Explorer, Microsoft Malware Protection Engine, Microsoft Data Access Components, HTML Help ActiveX Control and Microsoft office |
February 14, 2007 |
||||
| Microsoft Word | Microsoft Word Unspecified String Handling Memory Corruption Vulnerability |
February 21, 2007 |
||||
|
Unix |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||
| Sun Solaris | Sun Solaris Telnet Authentication Bypass Vulnerability |
February 19, 2007 |
||||
| Wireshark | Wireshark Multiple Denial of Service Vulnerabilities | February 01, 2007 |
||||
| phpBB++ and samba server | Multiple vulnerabilities have been reported in phpBB++ and samba server | February 07, 2007 |
||||
| PHP and SpamAssassin | Multiple vulnerabilities in PHP and SpamAssassin |
February 21, 2007 |
||||
|
Networking Devices |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Cisco | Cisco IOS IPS Multiple vulnerability |
February 19, 2007 |
||||
| Cisco | Multiple Vulnerabilities in Cisco Firewall Services Module (FWSM) | February 19, 2007 |
||||
|
Miscellaneous |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Trend Micro | Buffer Overflow Vulnerability in Trend Micro Scan engine |
February 09, 2007 |
||||
| Mozilla Firefox | Mozilla Firefox "locations.hostname" DOM Property Handling Vulnerability | February 19, 2007 |
||||
| Mozilla Products | Mozilla Products Multiple XSS, Spoofing and Remote Code Execution Vulnerabilities |
February 27, 2007 |
||||
| KDE Konqueror | KDE Konqueror "parseSpecial()" and "parseComment()" Cross Site Scripting Issue | February 07, 2007 |
||||
| Trend Micro | Multiple stack-based buffer overflow vulnerabilities in Trend Micro ServerProtect |
February 23, 2007 |
||||
|
Medium Vulnerabilities | ||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Microsoft Windows | Microsoft Windows Interactive Training Bookmark Link File Buffer overflow Vulnerability |
February 14, 2007 |
||||
| Windows Shell | Privilege Elevation Vulnerability in Windows Shell | February 14, 2007 |
||||
| Microsoft Windows | Microsoft Windows Image Acquisition (WIA) Service Local Privilege Escalation Vulnerability | February 14, 2007 |
||||
| Microsoft Windows | Microsoft Windows workstation Service Memory Corruption Vulnerability | February 14, 2007 |
||||
| Microsoft Windows | Microsoft Windows Interactive Training Bookmark Link File Buffer overflow Vulnerability |
February 14, 2007 |
||||
| Microsoft Windows | Microsoft RichEdit OLE Dialog Memory Corruption Vulnerability | February 14, 2007 |
||||
| Microsoft Word | Microsoft Word Multiple Vulnerabilities | February 14, 2007 |
||||
| Microsoft Internet Explorer | Internet Explorer "onunload" Event Spoofing Vulnerability | February 25, 2007 |
||||
| Microsoft Windows | Microsoft Windows "ReadDirectoryChangesW()" Information Disclosure vulnerability | February 25, 2007 |
||||
|
Unix |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||
| Sourcefire | Sourcefire Snort DCE/RPC Preprocessor Buffer Overflow vulnerability |
February 21, 2007 |
||||
| Mambo | Mambo Unspecified Content Edit Cancel SQL Injection | February 05, 2007 |
||||
| pam_ssh | pam_ssh "allow_blank_passphrase" Bypass Security Issue | February 08, 2007 |
||||
| Linux Kernel | Linux Kernel "key_alloc_serial()" Denial of Service | February 13, 2007 |
||||
| Linux Kernel | Linux Kernel NFSACL "ACCESS" Denial of Service | February 20, 2007 |
||||
| Sun Microsystem | Sun Microsystem Solaris ld.so Directory Travaversal vulnerability |
February 06, 2007 |
||||
|
Malicious Code Threats | ||||||
|
Title of Malicious Code |
Type |
Overview |
Aliases |
Discovery Date |
References | |
| Nurech.A Worm | Worm | It is a mass mailing worm using its own SMTP engine. It contains strings with romantic relationship related words in the subject line of emails that it sends. | No Aliase | February 09, 2007 | http://www.cert-in.org.in/virus/Nurech_Worm.htm | |
| W32.Rinbot.A | Worm | W32.Rinbot.A is a worm that opens a back door, connects to an IRC server, and awaits commands from an attacker. The worm spreads using known vulnerabilities. | No Aliase | February 16, 2007 | http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-021615-1555-99 | |
|
Solaris.Wanuk.Worm |
Worm |
It is a worm that spreads by exploiting the Sun Solaris Telnet Authentication Bypass Vulnerability described in CIVN-2007-23 and drops other malware. |
ELF_WANUK.A [ Trend Micro ] | February 28, 2007 | http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-022810-3637-99 | |
| File Infector FUJACKS | Virus | PE_FUJACKS is a multi-component, focused, web-based malware aimed for monetary gain. It arrives on the system while navigating some malicious websites or via download by other malware. | W32/Fujacks-J, W32/Fujacks.s, Win32/Emerleox.BM | February 28, 2007 | http://www.cert-in.org.in/virus/FileInfectorFUJACKS.htm | |
|
Security News | ||||||
| Botnet attack hits Internet root servers [Source: www.Techworld.com] Online attackers have briefly disrupted service on at least two of the 13 "root" servers that are used to direct traffic on the Internet. The attack, which began Tuesday at about 5:30 a.m. Eastern time, was the most significant attack against the root servers since an October 2002 distributed denial of service (DDOS) attack, said Ben Petro, senior vice president of services with Internet service provider Neustar Inc. Root servers manage the Internet's Domain Name System (DNS), used to translate Web addresses such as Amazon.com into the numerical Internet Protocol addresses used by machines. Hack lets intruders sneak into home routers If you haven't changed the default password on your home router, let this recent threat serve as a reminder. Attackers could change the configuration of home routers using JavaScript code, security researchers at Indiana University and Symantec have discovered. The researchers first published their work in December , but Symantec publicized the findings on Thursday. The researchers found that it is possible to change the DNS, or Domain Name System, settings of a router if the owner uses a connected PC to view a Web page with the JavaScript code. Viruses promise heartbreak on Valentine's Day Beware of e-mails bearing Valentine's Day greetings, or you may get a digital heartache. At least two romance-themed security threats are arriving in e-mail in-boxes on Wednesday, researchers have warned. One purports to be an electronic card from American Greetings and includes "Happy Valentine's Day!" in the subject line. When a recipient clicks on an in-message link to view the "card," however, a Trojan horse virus surreptitiously turns the computer into a spambot, or zombie, said Dmitri Alperovitch, a research scientist at Secure Computing. Anatomy sheds new light on Storm Worm A deluge of Trojan-laced spam that slyly tricked recipients by promising information about winter storms ravaging Northern Europe last month was even more crafty than we thought. Among the new revelations: The Storm Worm malware launched DDoS attacks on a host of websites related to spam, antispam and just about anything else that may have piqued the perpetrators' ire, according to Joe Stewart, senior security researcher for SecureWorks . It also appears to be a close descendant of worms that spread in November and December, a connection that few if any have made until now. Spam uses John Howard heart attack as phishing bait Having seemingly exhausted the possibilities of sending phishing mails which use headlines stolen from the news, scammers have now come up with a new tactic: headlines that didn't even happen. Their first target: John Howard, who is claimed to be recovering from a heart attack in a new message now doing the rounds. "The Prime Minister of Australia, John Howard have survived a heart attack," the message ungrammatically claims, before adding that "the best surgeons of Australia are struggling for his life". The entirely fake message, dated February 18, also includes a large chunk of incomplete text apparently lifted from an online biography of Howard. Trojan phishing attack claims multiple victims Security watchers have discovered a string of malicious websites that install Trojan code, allowing hackers to compromise end-user banking credentials for more than 50 financial institutions and ecommerce websites. Thousands of surfers a day are falling victim to the sophisticated attack, net security firm Websense warns. The websites are hosted in Germany, England, and Estonia, and use a round robin DNS, resolving to five unique IP addresses that change on each occasion. 'Pharming' attack hits 50 banks Global Banks Suffer “Pharming” Attacks A global financial scam ring attacked more than 65 financial institutions and e-commerce corporations worldwide and stole personal information from these companies using a new hacking technology called “pharming.” nternet security experts and financial circles at home and abroad said yesterday that the hacking first took place in Australia on February 19 and rapidly spread throughout the world, using an average of over 1,000 internet users daily to access sites and steal internet banking IDs and passwords. Websites wide open to attack Seven out of every 10 websites contains a security vulnerability that could allow attackers to steal confidential information or cripple the website, according to a study by security vendor Acunetix .“The results show clearly that the problem of unsafe web applications is being ignored completely,” said Kevin Vella, a vice president with Acunetix. Kernel-level malware on the rise Online criminals are increasingly turning to kernel-level malware to attack systems, according to security researchers at F-Secure . Kernel-level malware acts inside the operating system's kernel, the component that links the system to the computer's hardware. Traditional malware acts like a regular application that runs on top of the operating system. Kimmo Kasslin, a security researcher at F-Secure, said in a study that this type of malware is "a scary thought". New NIST documents released The NIST (National Institute of Standards and Technology ) released yesterday 3 new documents: NIST releases info security documents The National Institute of Standards and Technology has published two new interagency reports designed to help auditors, inspectors general and senior management understand and evaluate information security programs. Hacker faces jail for Trojan horse A US man has pleaded guilty to charges of writing and distributing a Trojan horse designed to steal usernames and passwords. Richard C Honour, 31, faces a maximum five years in prison and a $250,000 fine after admitting releasing the malware. The Trojan affected users of the DarkMyst IRC chatroom, which is popular with online gamers. Using the name 'Fyle/Anatoly', Honour sent messages to other IRC users claiming to contain links to online movies.
|
||||||