![]() |
||||||
|
CERT-In Monthly Security Bulletin
November 2007 | ||||||
|
Cyber Intrusion Trends |
||||||
| In this month 47 security incidents were reported to CERT-In from various
National/ International agencies. As shown in the figure 51%
phishing incidents were reported in this month. 36% unauthorized scanning and 13% incidents related to virus/worm under the malicious code category were reported in this month.As compared to previous month the number of
phishing incidents have decreased while scanning and malicious code incidents have increased. In this month CERT-In tracked 2 C&C (Command & Control) servers and 1020 bot-infected computers existing in India.The concerned ISPs were intimated to dis-infect the bot infected systems and C&C servers to mitigate botnets. It has been observed that information stealing trojans such as Nethell are spreading widely which are capturing login credentials of online users through keyloggers. |
Cyber Intrusion during November 2007
| |||||
|
Indian Websites Defacement |
||||||
In total 177 Indian websites were defaced during November 2007. A chart depicting Top Level Domain(TLD) wise defacements is shown in the figure. The vulnerabilities which might have been exploited for the defacements are: 1. Multiple Vulnerabilities in PHP CVE-2007-5898, CVE-2007-5899, CVE-2007-5900 2. Denial of service vulnerability in PHP CVE-2007-6039 |
Statistics of Defaced Indian Websites in November 2007
| |||||
|
Open proxy servers |
||||||
|
Any proxy server that doesn't restrict its client base to its own set of clients and allows any other client to connect to it, is known as an open proxy server. An open proxy server will accept client connections from any IP address and make connections to any Internet resource. CERT-In tracked 71 open proxy servers functioning in India during November 2007. All the concerned ISPs were alerted immediately to shut down the open proxy servers. A bar chart of open proxy servers tracked during this year is shown in the figure. |
Statistics of Open Proxy Servers tracked during Jan - Nov 2007
| |||||
|
Security Alerts |
||||||
|
The critical and medium vulnerabilities in various Operating Systems, Application software and Network devices discovered during November 2007 and their countermeasures alongwith wide-spreading malicious code like virus/ worm/Trojan are given below: | ||||||
|
High Vulnerabilities | ||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||
| Microsoft | Multiple Vulnerabilities in various components of Microsoft Windows: Microsoft DNS Server, Microsoft Windows URI | November 14, 2007 |
||||
|
Unix |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||
| PHP | Multiple Vulnerabilities in PHP | November 12, 2007 |
||||
| Linux Kernel | Linux Kernel CIFS VFS Buffer Overflow Vulnerability | November 16, 2007 |
||||
|
Cisco |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Cisco | Cisco Unified MeetingPlace XSS Vulnerability | November 15, 2007 |
||||
| Cisco | Cisco VPN Client for Windows Multiple Local Privilege Escalation Vulnerabilities | November 21, 2007 |
||||
| Cisco | Cisco Unified IP Phone Remote Eavesdropping | November 30, 2007 |
||||
|
Miscellaneous |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Apple QuickTime | Multiple File Processing Code Execution Vulnerabilities in Apple QuickTime | November 07, 2007 |
||||
| Mozilla Firefox | jar: Protocol URI Handling Vulnerability in Mozilla Firefox | November 13, 2007 |
||||
| IBM AIX | Multiple Vulnerabilities in IBM AIX | November 19, 2007 |
||||
| Apple QuickTime | Apple QuickTime RTSP "Content-Type" Header Buffer Overflow Vulnerability | November 28, 2007 |
||||
|
Medium Vulnerabilities |
||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Microsoft DNS Server | Remote Code Execution Vulnerability in Microsoft DNS Server |
November 14, 2007 |
||||
|
Unix |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| PHP | Denial of service vulnerability in PHP | November 20, 2007 |
||||
| Samba | Multiple Vulnerabilities in Samba |
November 29, 2007 |
||||
Malicious Code Threats |
||||||
|
Title of Malicious Code |
Type |
Overview |
Aliases |
Discovery Date |
References | |
| RJump Worm |
Worm |
The worm propagates by dropping its copy into removable drives and network drives with random names. It establishes a SOCKS Proxy on infected system for facilitating malicious activities such as Spam. | Worm:Win32/RJump [Microsoft], Worm.Win32.RJump [Kaspersky], W32.Rajump [Symantec]
|
November 01, 2007 |
||
| Mac OS Trojan OSX/RSPlug | Trojan |
It has been observed that a trojan named OSX/Plug affecting Mac OS is circulating in the wild. It arrives on the victim users system by exploiting browser vulnerabilities or by any other social engineering technique. |
OSX/RSPlug-A [Sophos], OSX/Puper [McAfee], OSX.RSPlug.A [ Symantec ]
|
November 05, 2007 |
||
| ZLOB Trojan | ZLOB Trojans first appeared in late 2005. Initial variants use to download malware and update copies of malware, ensured running of the other variants of the malware by re-executing their process. In the year 2006 ZLOB variants started spreading through email spam containing links to the video file. Some ZLOB variants also get dropped by other malware. | November 06, 2007 |
http://www.cert-in.org.in/virus/ZLOB_Trojan.htm | |||
| Jeefo Virus | Virus | It has been observed that a parasitic file infector virus named Jeefo is circulating in the wild. It infects Portable Executable files with size equal to or greater than 102,400 Bytes using the technique of first encrypting its target host file and then appending the encrypted host code to its viral code. After successful infection the size of the infected file gets increased by 36,352 bytes. | Virus.Win32.Hidrag.a [Kaspersky] | November 20, 2007 |
http://www.cert-in.org.in/virus/Jeefo_Virus.htm | |
| Rontokbro Worm | Worm | The trojan propagates by attaching a copy of itself to the email messages with the subject line and message body which lures users into opening up the attachment to get malware installed on their system. It also spread by copying itself to network shares . | W32.Rontokbro@mm [Symantec], W32/Brontok-N [Sophos], Win32.Brontok.a [Kaspersky] | November 20, 2007 | http://www.cert-in.org.in/virus/Rontokbro_Worm.htm | |
| Conhook Trojan | Trojan | The Trojan propagates by being dropped by other malware or by pretending to be harmless file which gets downloaded by innocent users while navigating some malicious websites. | Trojan-Downloader.Win32.ConHook.b [Kaspersky Lab], Downloader-ZM [McAfee], Trojan Horse [Symantec] | November 30, 2007 | http://www.cert-in.org.in/virus/Conhook-Trojan.htm | |
|
Security News |
||||||
FBI crackdown on botnets gets results, but damage continues November 29, 2007 Targeted e-mail attacks spoof DOJ, business group November 20, 2007 Feds Put More Botmasters, Phishers Behind Bars November 29, 2007
Government-sponsored cyberattacks on the rise, McAfee says Trojan spreads using PI wiretapping scare November 20, 2007 Botmaster owns up to 250,000 zombie PCs November 09, 2007 Website for computer security experts hacked November 08, 2007
Deconstructing the Fake FTC E-mail Virus Attack November 05, 2007
Storm Worm Victims Get Stock Spam Pop-Up November 13, 2007
Storm Brews Over Geocities November 15, 2007 U.K. government's lost data 'worth billions to criminals' November 29, 2007 Google asks for help finding malicious Web sites November 30, 2007 Hackers re-poison Google search results November 30, 2007 |
||||||