Home || Feedback || FAQ || Site map
CERT-In Monthly Security Bulletin March 2007
Cyber Intrusion Trends
In this month 47 security incidents were reported to CERT-In from various National/ International agencies. As shown in the figure 73% phishing incidents were reported in this month. 4% incidents related to virus/worm under the malicious code category and 23% unauthorized scanning incidents were reported. As compared to previous month the number of virus/worm incidents have decreased while scanning and phishing incidents have increased.
In this month 2 of Indian websites were compromised to spread malicious link. CERT-In alerted its constituents through the advisory CIAD-2007-14 for taking appropriate preventive steps.

Cyber Intrusion during March 2007

Indian Websites Defacement
In total 738 Indian websites were defaced during March 2007. Mostly the websites under .com domain were defaced by the hacker groups. A chart depicting Top Level Domain(TLD) wise defacements is shown in the figure.

The vulnerabilities which might have been exploited for the defacements are:
  1. CERT-In Vulnerability Note CIVN-2007-34
    Internet Explorer 7 navcancl.htm Cross-Site Scripting Vulnerability
  2. CERT-In Vulnerability Note CIVN-2007-37
    Cross Site Scripting Vulnerability in Oracle Application Server
  3. CERT-In Vulnerability Note CIVN-2007-33
    Linux kernel bufprint function buffer overflow vulnerability
  4. CERT-In Vulnerability Note CIVN-2007-32
    Apache Tomcat Mod_JK.SO Stack Overflow Vulnerability

Statistics of Defaced Indian Websites in March 2007

Open proxy servers

Any proxy server that doesn't restrict its client base to its own set of clients and allows any other client to connect to it, is known as an open proxy server. An open proxy server will accept client connections from any IP address and make connections to any Internet resource.

CERT-In tracked 109 open proxy servers functioning in India during March 2007. All the concerned ISPs were alerted immediately to shut down the open proxy servers. A bar chart of open proxy servers tracked during this year is shown in the figure.

Statistics of Open Proxy Servers tracked during June 2006 - March 2007

Security Alerts

The critical and medium vulnerabilities in various Operating Systems, Application software and Network devices discovered during March 2007 and their countermeasures alongwith wide-spreading malicious code like virus/ worm/Trojan are given below:

High Vulnerabilities
Microsoft
Title of Vulnerability
Discovery/Publish Date
CERT-In References & Patch Information
Microsoft Windows

Microsoft Windows Animated Cursor vulnerability

March 30, 2007
CIVN-2007-39

Microsoft
Configuration Error in Microsoft Web Proxy Automatic Discovery (WPAD) Protocol
March 28, 2007
CIAD-2007-16

Unix
Title of Vulnerability
Discovery/Publish Date
CERT-In References & Patch Information
Apache Tomcat Apache Tomcat Mod_JK.SO Stack Overflow Vulnerability
March 07, 2007
CIVN-2007-32
PHP PHP Import_Request_Variables, MSSQL_Connect, SNMPGet (), shmop(),Reference Counter and PHP-Nuke SQL Injection vulnerabilities
March 26, 2007
CIAD-2007-15
Linux kernel Linux kernel bufprint function buffer overflow vulnerability
March 13 , 2007
CIVN-2007-33
Linux kernel Linux kernel ipv6_getsockopt_sticky function cause DoS
March 20 , 2007
CIVN-2007-35
TCPDump TCPDump IEEE802.11 printer Remote Buffer Overflow Vulnerability
March 02 , 2007
CVE-2007-1218
Linux Kernel Linux Kernel NULL Pointer Dereferences and Security Bypass Vulnerability
March 16 , 2007
CVE-2007-1497
OpenOffice OpenOffice.org Office Suite Remote Arbitrary Code or Shell Commands Execution Vulnerability
March 21 , 2007
CVE-2007-0239,CVE-2007-0238
Linux Kernel

Linux Kernel DCCP Memory Disclosure Vulnerability

March 28 , 2007

CVE-2007-1734

Networking Devices
Title of Vulnerability
Discovery/Publish Date
CERT-In References & Patch Information
Trend Micro Products Trend Micro Products UPX Processing Denial of Service Vulnerability
March 20 , 2007
CIVN-2007-36
Cisco Cisco Catalyst 6000,6500 and Cisco 7600Series MPLS Packet Vulnerability
March 05 , 2007
CIAD-2007-11
Cisco Cisco Catalyst 6000, 6500 Series, and Cisco 7600 Series NAM (Network Analysis Module) Vulnerability
March 05 , 2007
CIAD-2007-12
Miscellaneous
Title of Vulnerability
Discovery/Publish Date
CERT-In References & Patch Information
Mozilla Mozilla Products Privilege Escalation and Integer Overflow vulnerabilities
March 13 , 2007
CIAD-2007-13
Compromised websites Compromised websites propagating Malware
March 13 , 2007
CIAD-2007-14
Mozilla Firefox Firefox onUnload + document.write() memory corruption vulnerability
March 03 , 2007
CVE-2007-1256
Mozilla Firefox Mozilla Firefox Phishing Protection Bypass Vulnerability
March 28 , 2007
CVE-2007-1736
Medium Vulnerabilities
Microsoft
Title of Vulnerability
Discovery/Publish Date
CERT-In References & Patch Information
Internet Explorer 7 Internet Explorer 7 navcancl.htm Cross-Site Scripting Vulnerability
March 20, 2007
CIVN-2007-34
Microsoft Windows Microsoft Windows Vista Mail Client Local File Execution Vulnerability
March 30, 2007
CIVN-2007-38
Unix
Title of Vulnerability
Discovery/Publish Date
CERT-In References & Patch Information
PHP 4 PHP 4 unserialize() ZVAL Reference Counter Overflow
March 06, 2007
CVE-2007-1286
PHP Multiple Vulnerabilities in PHP
March 20, 2007
CVE-2007-1488 , CVE-2007-1584 , CVE-2007-1583 ,
CVE-2007-1582
, CVE-2007-1581 , CVE-2007-1522
Database
Title of Vulnerability
Discovery/Publish Date
CERT-In References & Patch Information
Oracle Cross Site Scripting Vulnerability in Oracle Application Server
March 23, 2007
CIVN-2007-37
Malicious Code Threats
Title of Malicious Code
Type
Overview
Aliases
Discovery Date
References
Rinbot Worm It propagates via network shares and by exploiting software vulnerabilities. It opens a backdoor on random ports/ TCP port 4873 to connect to some IRC servers and listen to malicious commands from remote attackers.
No Aliase
March 10, 2007
http://www.cert-in.org.in/virus/Rinbot.htm
W32.Mancsyn Worm It is a worm that spreads by exploiting the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability CVE-2003-0352 No Aliase
March 23, 2007
http://www.symantec.com/enterprise/security_response/writeup.jsp?
docid=2007-032316-0426-99

Gozi Trojan

Trojan

It has been reported that a Trojan “GOZI” is spreading in the wild to steal SSL encrypted data. This Trojan spreads by exploiting recent vulnerabilities of Internet Explorer and uses the rootkit capabilities to hide itself.

No Aliase
March 26, 2007
http://www.cert-in.org.in/virus/Gozi_Trojan.htm
Solaris.Midwebster Trojan Solaris.Midwebster is Trojan horse affecting Solaris system. It installed on the compromised computer by a remote attacker after the attacker has successfully exploited a remote vulnerability. No Aliase
March 29, 2007
http://www.symantec.com/enterprise/security_response/writeup.jsp?
docid=2007-032912-0728-99&tabid=2
TROJ_ANICMOO.AX Worm This Trojan may arrive on a system as a specially crafted animated cursor (.ANI) file downloaded from the Internet by unsuspecting users. It may be downloaded by on a system via a specially crafted HTML email message No Aliase
March 29, 2007
http://uk.trendmicro-europe.com/enterprise/vinfo/encyclopedia.php?LYstr=VMAINDATA&vNav=1&VName=
TROJ_ANICMOO.AX
Security News

Phishing threats triple
[Source: www.techworld.com]

Online identity theft threats tripled in the first two months of 2007 as attackers shifted to simpler, more effective tactics, according to Cyveillance
The risk monitoring company compiled data from its internet sweeps to report that the average daily count of URLs hosting malicious downloads climbed to 60,000 in February, 200 percent over the December 2006 figure. A single-day spike mid-month came close to 140,000 such sites.

[More]

Blogger.com 'riddled' with malware
[Source: www.theregister.co.uk ]

Blogger.com, home of the weblog publishing system owned by Google, has been infiltrated by a number of phishing sites, security watchers report.

In some cases, the Stration mass mailer is being used to drive traffic to these fraudulent sites. One such scam is a "storefront" for Pharmacy Express, which redirects from a Blogspot.com (now Blogger.com) link. The site is designed to harvest the personal information of prospective marks.

[More]

Study: Identity theft keeps climbing
[Source: www.news.com.com]

Gartner's study, released Tuesday, shows that from mid-2005 until mid-2006, about 15 million Americans were victims of fraud that stemmed from identity theft, an increase of more than 50 percent from the estimated 9.9 million in 2003.

It should be noted that the 2003 statistics and the mid-2006 statistics came from two different sources--and hence, two different statistical methodologies. The original 9.9 million figure came from the Federal Trade Commission, whereas the 15 million statistic is Gartner's own.

[More]

FBI: Internet crime pays
[Source: www.theregister.co.uk ]

Cyber-crime is alive and kicking in the USA , and playfully swimming through its riches like Scrooge McDuck in a money vault, the FBI's Internet Crime Complaint Center annual report reveals today. In 2006 US consumers filed 207,492 complaints about internet crime and reported record losses of $198.4m. Online auction fraud, such as receiving a different item than expected, topped the list, accounting for 44.9 per cent of complaints. Undelivered merchandise and payments were next in line, accounting for 19 per cent.

[More]

Most websites are open to attack
[Source: www.techworld.com]

Businesses leave themselves open to application-layer attacks because they don't understand their networks lack defences to deflect them. That's according to a study by Forrester Research, which found that "Most enterprises are not even aware that their traditional network firewalls cannot protect against these attacks". The report Web Application Firewall Forecast: 2007 to 2010 predicts that demand for web application firewalls (WAFs) will increase over the next three years, then drop.

[More]

Web attacks get personal
[Source:www.techworld.com]

Malware makers are increasingly tailoring their attacks to specific classes of victim, according to researchers with the Internet Security Systems' X-Force team at IBM. X-Force experts said that malware writers, phishers, and botnet herders are more frequently using so-called personalisation tools to make their attacks more effective. Much like the online marketing companies that gather information to target advertising at individual web users, criminals are scanning readily-available details about people's computers to more easily find victims.

[More]

Microsoft's search excels in spreading malware
[Source: www.theregister.co.uk ]

Everybody knows that Windows Live Search, Microsoft's little search engine that could, lags far behind Google and Yahoo! in the race to capture eyeballs. Here's one place where the software juggernaut's offering leads the pack: referrals for sites that actively try to infect end users' machines with some of the vilest malware known to man.

[More]