![]() |
||||||
|
CERT-In Monthly Security Bulletin March 2007 |
||||||
|
Cyber Intrusion Trends |
||||||
| In this month 47 security incidents were reported to CERT-In from various National/ International agencies. As shown in the figure 73% phishing incidents were reported in this month. 4% incidents related to virus/worm under the malicious code category and 23% unauthorized scanning incidents were reported. As compared to previous month the number of virus/worm incidents have decreased while scanning and phishing incidents have increased. In this month 2 of Indian websites were compromised to spread malicious link. CERT-In alerted its constituents through the advisory CIAD-2007-14 for taking appropriate preventive steps. |
Cyber Intrusion during March 2007
|
|||||
|
Indian Websites Defacement |
||||||
| In total 738 Indian websites were defaced during March 2007. Mostly the websites under .com domain were defaced by the hacker groups. A chart depicting Top Level Domain(TLD) wise defacements is shown in the figure. The vulnerabilities which might have been exploited for the defacements are:
|
Statistics of Defaced Indian Websites in March 2007
|
|||||
|
Open proxy servers |
||||||
|
Any proxy server that doesn't restrict its client base to its own set of clients and allows any other client to connect to it, is known as an open proxy server. An open proxy server will accept client connections from any IP address and make connections to any Internet resource. CERT-In tracked 109 open proxy servers functioning in India during March 2007. All the concerned ISPs were alerted immediately to shut down the open proxy servers. A bar chart of open proxy servers tracked during this year is shown in the figure. |
Statistics of Open Proxy Servers tracked during June 2006 - March 2007
|
|||||
|
Security Alerts |
||||||
|
The critical and medium vulnerabilities in various Operating Systems, Application software and Network devices discovered during March 2007 and their countermeasures alongwith wide-spreading malicious code like virus/ worm/Trojan are given below: |
||||||
|
High Vulnerabilities |
||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
|
Microsoft Windows |
Microsoft Windows Animated Cursor vulnerability |
March 30, 2007 |
||||
|
Microsoft |
Configuration Error in Microsoft Web Proxy Automatic Discovery (WPAD) Protocol |
March 28, 2007 |
||||
|
Unix |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Apache Tomcat | Apache Tomcat Mod_JK.SO Stack Overflow Vulnerability |
March 07, 2007 |
||||
| PHP | PHP Import_Request_Variables, MSSQL_Connect, SNMPGet (), shmop(),Reference Counter and PHP-Nuke SQL Injection vulnerabilities |
March 26, 2007 |
||||
| Linux kernel | Linux kernel bufprint function buffer overflow vulnerability |
March 13 , 2007 |
||||
| Linux kernel | Linux kernel ipv6_getsockopt_sticky function cause DoS | March 20 , 2007 |
||||
| TCPDump | TCPDump IEEE802.11 printer Remote Buffer Overflow Vulnerability | March 02 , 2007 |
||||
| Linux Kernel | Linux Kernel NULL Pointer Dereferences and Security Bypass Vulnerability | March 16 , 2007 |
||||
| OpenOffice | OpenOffice.org Office Suite Remote Arbitrary Code or Shell Commands Execution Vulnerability | March 21 , 2007 |
||||
|
Linux Kernel |
Linux Kernel DCCP Memory Disclosure Vulnerability |
March 28 , 2007 |
||||
Networking Devices |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Trend Micro Products | Trend Micro Products UPX Processing Denial of Service Vulnerability | March 20 , 2007 |
||||
| Cisco | Cisco Catalyst 6000,6500 and Cisco 7600Series MPLS Packet Vulnerability | March 05 , 2007 |
||||
| Cisco | Cisco Catalyst 6000, 6500 Series, and Cisco 7600 Series NAM (Network Analysis Module) Vulnerability | March 05 , 2007 |
||||
|
Miscellaneous |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Mozilla | Mozilla Products Privilege Escalation and Integer Overflow vulnerabilities |
March 13 , 2007 |
||||
| Compromised websites | Compromised websites propagating Malware | March 13 , 2007 |
||||
| Mozilla Firefox | Firefox onUnload + document.write() memory corruption vulnerability | March 03 , 2007 |
||||
| Mozilla Firefox | Mozilla Firefox Phishing Protection Bypass Vulnerability |
March 28 , 2007 |
||||
Medium Vulnerabilities |
||||||
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Internet Explorer 7 | Internet Explorer 7 navcancl.htm Cross-Site Scripting Vulnerability | March 20, 2007 |
||||
| Microsoft Windows | Microsoft Windows Vista Mail Client Local File Execution Vulnerability | March 30, 2007 |
||||
|
Unix |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| PHP 4 | PHP 4 unserialize() ZVAL Reference Counter Overflow |
March 06, 2007 |
||||
| PHP | Multiple Vulnerabilities in PHP |
March 20, 2007 |
||||
|
Database |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Oracle | Cross Site Scripting Vulnerability in Oracle Application Server |
March 23, 2007 |
||||
Malicious Code Threats |
||||||
|
Title of Malicious Code |
Type |
Overview |
Aliases |
Discovery Date |
References |
|
| Rinbot | Worm | It propagates via network shares and by exploiting software vulnerabilities. It opens a backdoor on random ports/ TCP port 4873 to connect to some IRC servers and listen to malicious commands from remote attackers. |
No Aliase |
March 10, 2007 |
http://www.cert-in.org.in/virus/Rinbot.htm | |
| W32.Mancsyn | Worm | It is a worm that spreads by exploiting the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability CVE-2003-0352 | No Aliase | March 23, 2007 |
http://www.symantec.com/enterprise/security_response/writeup.jsp? docid=2007-032316-0426-99 |
|
Gozi Trojan |
Trojan | It has been reported that a Trojan “GOZI” is spreading in the wild to steal SSL encrypted data. This Trojan spreads by exploiting recent vulnerabilities of Internet Explorer and uses the rootkit capabilities to hide itself. |
No Aliase |
March 26, 2007 |
http://www.cert-in.org.in/virus/Gozi_Trojan.htm | |
| Solaris.Midwebster | Trojan | Solaris.Midwebster is Trojan horse affecting Solaris system. It installed on the compromised computer by a remote attacker after the attacker has successfully exploited a remote vulnerability. | No Aliase | March 29, 2007 |
http://www.symantec.com/enterprise/security_response/writeup.jsp? docid=2007-032912-0728-99&tabid=2 |
|
| TROJ_ANICMOO.AX | Worm | This Trojan may arrive on a system as a specially crafted animated cursor (.ANI) file downloaded from the Internet by unsuspecting users. It may be downloaded by on a system via a specially crafted HTML email message | No Aliase | March 29, 2007 |
http://uk.trendmicro-europe.com/enterprise/vinfo/encyclopedia.php?LYstr=VMAINDATA&vNav=1&VName= TROJ_ANICMOO.AX |
|
|
Security News |
||||||
|
Phishing threats triple Online identity theft threats tripled in the first two months of 2007 as attackers shifted to simpler, more effective tactics, according to Cyveillance Blogger.com 'riddled' with malware Blogger.com, home of the weblog publishing system owned by Google, has been infiltrated by a number of phishing sites, security watchers report. In some cases, the Stration mass mailer is being used to drive traffic to these fraudulent sites. One such scam is a "storefront" for Pharmacy Express, which redirects from a Blogspot.com (now Blogger.com) link. The site is designed to harvest the personal information of prospective marks. Study: Identity theft keeps climbing Gartner's study, released Tuesday, shows that from mid-2005 until mid-2006, about 15 million Americans were victims of fraud that stemmed from identity theft, an increase of more than 50 percent from the estimated 9.9 million in 2003. It should be noted that the 2003 statistics and the mid-2006 statistics came from two different sources--and hence, two different statistical methodologies. The original 9.9 million figure came from the Federal Trade Commission, whereas the 15 million statistic is Gartner's own. FBI: Internet crime pays Cyber-crime is alive and kicking in the USA , and playfully swimming through its riches like Scrooge McDuck in a money vault, the FBI's Internet Crime Complaint Center annual report reveals today. In 2006 US consumers filed 207,492 complaints about internet crime and reported record losses of $198.4m. Online auction fraud, such as receiving a different item than expected, topped the list, accounting for 44.9 per cent of complaints. Undelivered merchandise and payments were next in line, accounting for 19 per cent. Most websites are open to attack Businesses leave themselves open to application-layer attacks because they don't understand their networks lack defences to deflect them. That's according to a study by Forrester Research, which found that "Most enterprises are not even aware that their traditional network firewalls cannot protect against these attacks". The report Web Application Firewall Forecast: 2007 to 2010 predicts that demand for web application firewalls (WAFs) will increase over the next three years, then drop. Web attacks get personal Malware makers are increasingly tailoring their attacks to specific classes of victim, according to researchers with the Internet Security Systems' X-Force team at IBM. X-Force experts said that malware writers, phishers, and botnet herders are more frequently using so-called personalisation tools to make their attacks more effective. Much like the online marketing companies that gather information to target advertising at individual web users, criminals are scanning readily-available details about people's computers to more easily find victims. Microsoft's search excels in spreading malware |
||||||