![]() |
||||||||||||||||||||||||||||||||||||||||
|
CERT-In Monthly Security Bulletin
April 2009 | ||||||||||||||||||||||||||||||||||||||||
|
Cyber Intrusion Trends |
||||||||||||||||||||||||||||||||||||||||
In this month 505 security incidents were reported to CERT-In from various National/ International agencies. As shown in the figure, 76 % incidents related to Spreading of malware through website compromise were reported in this month. 08 % phishing incidents , 06 % unauthorized scanning , 06 % incidents related to technical help under the Others category, 03 % incidents related to virus/worm under the Malicious code category, and 01 % incidents related to spamming were also reported in this month.. In this month CERT-In observed that the conficker worm has infected around 15 lakhs computer systems across India .CERT-In has informed all the concerned ISPs for dis -infecting the systems. CERT-In has also communicated to CISOs and Govt , Defense, Banks and Public sector organizations to prepare themselves for safeguarding against conficker worm infections.
|
Cyber Intrusion during April 2009 ![]() |
|||||||||||||||||||||||||||||||||||||||
|
Indian Websites Defacement |
||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||
|
Open proxy servers |
||||||||||||||||||||||||||||||||||||||||
Any proxy server that doesn't restrict its client base to its own set of clients and allows any other client to connect to it is known as an open proxy server. An open proxy server will accept client connections from any IP address and make connections to any Internet resource. CERT-In tracked 231 open proxy servers functioning in India during April 2009. All the concerned ISPs were alerted immediately to shut down the open proxy servers. A bar chart of open proxy servers tracked during this year is shown in the figure. . |
Statistics of Open Proxy Servers tracked during April 2009
|
|||||||||||||||||||||||||||||||||||||||
| Attack Trend | ||||||||||||||||||||||||||||||||||||||||
Worm Conficker/Downadup/Kido widely propagating Propagation of Waledac worm variants It has been observed that ‘ Win32/Waledac Worm' is circulating via spam e-mails pretending to be Valentine's Day Greetings to deceive users to download the greeting card or the attached file. |
||||||||||||||||||||||||||||||||||||||||
|
Security Alerts |
||||||||||||||||||||||||||||||||||||||||
|
The critical and medium vulnerabilities in various Operating Systems, Application software and Network devices discovered during April 2009 and their countermeasures along with wide-spreading malicious code like virus/ worm/Trojan are given below: |
||||||||||||||||||||||||||||||||||||||||
|
High Vulnerabilities | ||||||||||||||||||||||||||||||||||||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||||||||||||||||||||||||||||||||||||
| Microsoft | Multiple Vulnerabilities in Windows Kernel and Windows DNS | 29-Apr-09
|
||||||||||||||||||||||||||||||||||||||
| Microsoft | Multiple Vulnerabilities in Microsoft Windows DNS Server and WINS Server | 15-Apr-09
|
||||||||||||||||||||||||||||||||||||||
| Microsoft | Multiple Vulnerabilities in Microsoft Windows DNS Server and | 15-Apr-09 |
||||||||||||||||||||||||||||||||||||||
| Microsoft | Multiple Vulnerabilities in Microsoft Windows DNS Server and | 15-Apr-09 |
||||||||||||||||||||||||||||||||||||||
| Microsoft | Multiple Vulnerabilities in Microsoft Windows DNS Server and | 15-Apr-09 |
||||||||||||||||||||||||||||||||||||||
| Microsoft | Multiple Vulnerabilities in Microsoft Windows DNS Server and | 15-Apr-09 |
||||||||||||||||||||||||||||||||||||||
| Microsoft | Multiple Vulnerabilities in Microsoft Windows DNS Server and | 15-Apr-09 |
||||||||||||||||||||||||||||||||||||||
| Microsoft | Microsoft Windows Secure Channel Security Package Authentication Bypass Vulnerability | 15-Apr-09
|
||||||||||||||||||||||||||||||||||||||
| Microsoft | Microsoft Windows Kernel Code Execution and Privilege Escalation Vulnerabilities | 04-Apr-09
|
||||||||||||||||||||||||||||||||||||||
|
CISCO
|
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||||||||||||||||||||||||||||||||||||
| CISCO | Cisco ASA and Cisco PIX TCP Packet Processing Denial of Service Vulnerability | 21-Apr-09 |
||||||||||||||||||||||||||||||||||||||
| CISCO | Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability | 9-Apr-09 |
||||||||||||||||||||||||||||||||||||||
| CISCO |
|
9-Apr-09 |
||||||||||||||||||||||||||||||||||||||
| CISCO | Cisco IOS Software WebVPN and SSLVPN Vulnerabilities | 9-Apr-09 |
||||||||||||||||||||||||||||||||||||||
| CISCO | Cisco IOS Software Multiple Features Crafted TCP Sequence Vulnerability | 6-Apr-09 |
||||||||||||||||||||||||||||||||||||||
| CISCO | Cisco IOS Software IP Sockets Denial of Service Vulnerability | 6-Apr-09 |
||||||||||||||||||||||||||||||||||||||
| CISCO | Cisco IOS Mobile IP and Mobile IPv6 Vulnerabilities | 6-Apr-09
|
||||||||||||||||||||||||||||||||||||||
|
Linux
|
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||||||||||||||||||||||||||||||||||||
| Linux | Multiple Vulnerabilities in Linux Kernel | 29-Apr-09
|
||||||||||||||||||||||||||||||||||||||
|
Miscellaneous |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||||||||||||||||||||||||||||||||||||
| Adobe | Adobe Reader JavaScript Vulnerabilities | 30-Apr-09
|
||||||||||||||||||||||||||||||||||||||
| Mozilla | Mozilla Firefox "nsTextFrame::ClearTextRun()" Memory Corruption Vulnerability | 30-Apr-09 |
||||||||||||||||||||||||||||||||||||||
| Mozilla | Multiple Vulnerabilities in Mozilla Products | 24-Apr-09 |
||||||||||||||||||||||||||||||||||||||
Medium Vulnerabilities |
||||||||||||||||||||||||||||||||||||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||||||||||||||||||||||||||||||||||||
| Microsoft | Microsoft ISA Server and Forefront Threat Management Gateway Denial of Service Vulnerabilities | 15-Apr-09 |
||||||||||||||||||||||||||||||||||||||
| Microsoft | Remote code execution vulnerability in SearchFunction of Microsoft Windows | 15-Apr-09
|
||||||||||||||||||||||||||||||||||||||
|
Miscellaneous |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||||||||||||||||||||||||||||||||||||
| Apache | Apache Tomcat mod_jk Content Length Information Disclosure Vulnerability | 17-Apr-09
|
||||||||||||||||||||||||||||||||||||||
| Joomla! | Cross-Site Scripting and Cross-Site Request Forgery Vulnerabilities in Joomla! | 17-Apr-09
|
||||||||||||||||||||||||||||||||||||||
Malicious Code Threats |
||||||||||||||||||||||||||||||||||||||||
|
Title of Malicious Code |
Type |
Overview |
Aliases |
Discovery Date |
References | |||||||||||||||||||||||||||||||||||
| Rustock Trojan/ |
Trojan |
It has been observed that a multi- component family of rootkit-enabled backdoor Trojans named Rustock is spreading in the wild which has been known primarily as a prolific spam source. It comes to the system as attachments in spammed mails or dropped by other malware (Trojan “ Costrat” |
|
April 22, 2009 |
||||||||||||||||||||||||||||||||||||
| Qakbot |
Worm |
It has been |
BKDR_QAKBOT |
April 22, 2009 |
http://www.symantec.com/business/security_response/writeup.jsp? |
|||||||||||||||||||||||||||||||||||
| Neeris |
Worm |
It has been observed that a worm named Neeris is spreading in the wild. It spreads through multiple vectors such as network shares, removable drives, instant messenger, MSN Messenger. After successful installation the Worm drops a rootkit component to hide its process. It also opens random port on the infected system to receive commands from the remote attacker |
No aliases found |
April 07, 2009 |
http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp? |
|||||||||||||||||||||||||||||||||||
|
Security News |
||||||||||||||||||||||||||||||||||||||||
Windows Bugs Never Truly Squashed According to data that Qualys Inc. culled from scans of more than 80 million machines, between 5% and 20% of all systems are never patched for any vulnerabilities, including those disclosed by Microsoft in its monthly security updates. Qualys, a provider of on-demand IT security systems, tracked four vulnerability bulletins issued by Microsoft in 2008 and in each case found that a sizable fraction of the PCs it scanned had not been patched, even though in some cases more than a year had passed since Microsoft issued fixes. Microsoft supplies Interpol with DIY forensics tool Cofee, short for Computer Online Forensic Evidence Extractor, is a thumb drive containing more than 150 investigative applications police can use to collect digital evidence at crime scenes. When Microsoft announced the free tool last year, it said some 2,000 officers in 15 countries were using it. Cofee is designed to ease that burden by providing investigators with easy-to-use tools that allows them to collect electronic data on the fly. It also allows them to collect data without necessarily having to lug gear to headquarters first. Encrypted USB drive solution with anti-malware capability Mobile Armor announced the addition of anti-malware support to its existing KeyArmor product group. Sun Announces MySQL Cluster 7.0 for Real-Time, Mission-Critical Database Applications Today's announcement was made at the seventh annual MySQL Conference & Expo being held this week at the Santa Clara Convention Center. With more than 2,000 attendees, it is the world's largest community event for open source database developers, DBAs, vendors and corporate IT managers. Malicious Activity in India on the Rise, Says Symantec Report The report is derived from data collected by millions of Internet sensors, first-hand research, and active monitoring of hacker communications, and provides a global view of the state of Internet security. The study period for the ISTR XIV covers January 2008 to December 2008. It noted that Web surfing remained the primary source of new infections in 2008, and attackers are relying more on customized malicious code toolkits to develop and distribute their threats. Computers from the United States and China were observed to be the leading source of Web-based attacks targeting India , accounting for 84 percent and 5 percent respectively. SANS: Newest WLAN Hacks Come From Afar The good news is that this type of attack is tough to execute in Windows XP. But not so for Vista or Windows 7, where the API calls make it relatively simple to write code that talks to the wireless interface, according to Skoudis. JavaScript flaw reported in Adobe Reader The United States ' Computer Emergency Readiness Team (US- CERT ) warned users of the ubiquitous Adobe Reader to disable the program's use of Javascript after Adobe warned that a possible flaw had been found. In a post to its product security blog, the company said it was investigating reports of a serious flaw in Adobe Reader. While initial reports only stated that a flaw had been found in the Linux version of Adobe Reader, the company updated the post to include Windows and Mac OS X versions as well. "Adobe plans to provide updates for all affected versions for all platforms — Windows, Macintosh and Unix — to resolve this issue," the company stated on its blog. "We are working on a development schedule for these updates and will post a timeline as soon as possible. We are currently not aware of any reports of exploits in the wild for this issue." The warnings appear similar to those that forced Adobe to issue a security advisory in February, and a patch the following month, urging users to beware of Reader attacks. Because of their ubiquity, Adobe's Acrobat and Flash software have become popular targets of security researchers, who try to find vulnerabilities to help secure software, and online criminals, who try to exploit the vulnerabilities. The repeated vulnerabilities and the lure of such a large user base have caused at least one security company, F-Secure, to recommend that people use alternate applications. . [More] Windows 7 RC is now available Today Microsoft reached a significant milestone with the Release Candidate (RC) of Windows 7, now available for download to MSDN and TechNet subscribers. Broader public availability will begin May 5. New to the Windows 7 RC are advancements such as Remote Media Streaming, Windows XP Mode (beta) and the upcoming beta of the Windows 7 Upgrade Advisor:
Swine flu email scams circulating The event-based social engineering campaign is similar to the recent fake ‘Conficker infection alerts‘, the bogus Conficker removal tools pushed through SEO practices, and the timely spam campaign serving malware as a fake Microsoft patch Tuesday message. Strangely, the massive spam campaign doesn't seem to be targeting the specific market segment since upon clicking on the links the users are directed to the ubiquitous Canadian Pharmacy scam. Based on previous experience with related campaigns, cybercriminals are prone to diversify the traffic acquisition tactics, so consider keeping yourself informed on the issue by using the right sources. |
||||||||||||||||||||||||||||||||||||||||