![]() |
||||||
|
CERT-In Monthly Security Bulletin
December 2008 | ||||||
|
Cyber Intrusion Trends |
||||||
In this month 255 security incidents were reported to CERT-In from various National/ International agencies. As shown in the figure, 53% incidents related to Spreading of malware through website compromise were reported in this month. 11 % incidents related to virus/worm under the Malicious code category , 12 % phishing incidents , 06 % incidents related to spamming ,07 % unauthorized scanning , and 11 % incidents related to technical help under the Others category were also reported in this month. In this month CERT-In tracked 04 C&C (Command & Control) servers and 8866 bot -infected computers existing in India . The concerned ISPs were intimated to dis-infect the bot infected systems and C&C servers to mitigate botnets .
|
Cyber Intrusion during December 2008 |
|||||
|
Indian Websites Defacement |
||||||
In total 300 Indian websites were defaced during December 2008. A chart depicting Top Level Domain (TLD) wise defacements is shown in the figure. The vulnerabilities which might have been exploited for the defacements are: 1. Microsoft SQL Server Memory Overwrite vulnerability CIVN-2008-1922. Microsoft Windows Server Service Vulnerability CIVN-2008-170 3. Microsoft Windows SMB Credential Reflection Vulnerability CIVN-2008-177 4. Multiple Vulnerabilities in Microsoft XML Core Services CIVN-2008-178 5. Apache Tomcat UTF-8 Directory Traversal Vulnerability CVE-2008-2938 6. Apache Tomcat ' RequestDispatcher ' Information Disclosure Vulnerability CVE-2008-2370 7. PHP extractTo() '.zip' Files Directory Traversal Vulnerability CVE-2008-5658 8. PHP Multiple Buffer Overflow Vulnerability CVE-2008-3658
|
Statistics of Defaced Indian Websites in December 2008
| |||||
|
Open proxy servers |
||||||
Any proxy server that doesn't restrict its client base to its own set of clients and allows any other client to connect to it is known as an open proxy server. An open proxy server will accept client connections from any IP address and make connections to any Internet resource. CERT-In tracked 111 open proxy servers functioning in India during December 2008. All the concerned ISPs were alerted immediately to shut down the open proxy servers. A bar chart of open proxy servers tracked during this year is shown in the figure. |
Statistics of Open Proxy Servers tracked during Jan - Dec 2008
|
|||||
| Attack Trend | ||||||
Spreading of DNSChanger malware and Rouge DHCP severs 0-day exploit for Internet Explorer in the wild Several websites are operational hosting obfuscated malicious JavaScript's (detected as JS_DLOAD.MD ,Trend Micro) that can exploit the said vulnerability through a Heap Spray on SDHTML. |
||||||
| Training | ||||||
Workshop on " Managing Organization's Network Security" on 16th December, 2008 A one day Workshop on "Managing Organization's Network Security" was conducted on 16th December, 2008 . The objective of the workshop is to create awareness among Indian IT Infrastructure and IT user organisations on the latest methods of managing organization's Network Security. Delegates were from Corporate and critical sector organizations. |
||||||
|
Security Alerts |
||||||
|
The critical and medium vulnerabilities in various Operating Systems, Application software and Network devices discovered during December 2008 and their countermeasures along with wide-spreading malicious code like virus/ worm/Trojan are given below: |
||||||
|
High Vulnerabilities | ||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||
| Microsoft | Exploitation of critical Microsoft Windows Vulnerabilities | 4-Dec-08 |
||||
| Microsoft | Multiple Vulnerabilities in Microsoft Windows, Internet Explorer, Visual Basic 6.0 | 11-Dec-08 |
||||
| Microsoft | Multiple Vulnerabilities Microsoft Visual Basic ActiveX Controls | 11-Dec-08 |
||||
| Microsoft | Multiple Vulnerabilities in Microsoft Windows GDI | 11-Dec-08 |
||||
| Microsoft | Microsoft Office Word Remote Code Execution | 11-Dec-08 |
||||
| Microsoft | Multiple Vulnerabilities in Microsoft Internet Explorer | 11-Dec-08 |
||||
| Microsoft | Microsoft Office Excel Remote Code Execution | 11-Dec-08 |
||||
| Microsoft | Microsoft Windows Explorer Search Handling Vulnerabilities | 11-Dec-08 |
||||
| Microsoft | Microsoft Internet Explorer Data binding Memory Corruption Vulnerability | 18-Dec-08 |
||||
| Microsoft | Microsoft Windows WordPad Text Converter File Handling Memory Corruption Vulnerability |
18-Dec-08 |
||||
| Microsoft | Microsoft SQL Server sp_replwritetovarbin limited memory overwrite vulnerability |
26-Dec-08 |
||||
|
Unix |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Linux | Linux Kernel 'lbs_process_bss()' Remote Denial of Service Vulnerability |
1-Dec-08 |
||||
|
Miscellaneous |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information |
|||
| Mozilla | Multiple Vulnerabilities in Mozilla products | 22-Dec-08 |
||||
| Adobe | Adobe Flash Player for Linux SWF Processing Vulnerability | 11-Dec-08 |
||||
| Sun | Multiple vulnerabilities in Sun Java Development Kit and Java Runtime Environment | 11-Dec-08 |
||||
| Novell | Novell Netware ApacheAdmin Security Bypass Vulnerability | 26-Dec-08 |
||||
| Trend Micro | Multiple Vulnerabilities in Trend Micro HouseCall ActiveX Control | 23-Dec-08 |
||||
| Opera | Multiple vulnerabilities in Opera | 26-Dec-08 |
||||
Medium Vulnerabilities |
||||||
|
Microsoft |
Title of Vulnerability |
Discovery/Publish Date |
CERT-In References & Patch Information
| |||
| Microsoft | Microsoft Windows Media Components Vulnerabilities | 11-Dec-08 |
||||
| Microsoft | Microsoft Office SharePoint Server Security Bypass Vulnerability | 11-Dec-08 |
||||
| Linux | sendmsg() and ATM subsystem Denial of Service Vulnerabilities in Linux Kernel | 15-Dec-08 |
||||
| Linux | Linux Kernel 'parisc_show_stack()' Local Denial of Service Vulnerability |
22-Dec-08 |
||||
Malicious Code Threats |
||||||
|
Title of Malicious Code |
Type |
Overview |
Aliases |
Discovery Date |
References | |
| Trojan:Win32/ |
Trojan
|
It has been observed that Trojan:Win32/ Yektel is circulating widely. It is a rogue security program that display fake warning messages indicating that” spyware or malware has been detected on the machine” in order to convince users to purchase rogue security software. |
Win32/Warax.P (CA), Trojan.Win32. FraudPack.gen (Kaspersky), Downloader. MisleadApp (Symantec) |
December 22, 2008 |
||
| Trojan Gimfan |
Trojan |
It has been |
No Aliases found |
December 22, 2008 |
http://www.symantec.com/business/security_response/writeup.jsp? |
|
| Trojan Alureon |
Trojan
|
It has been observed that a password stealing family of Trojans named Alureon is spreading in the wild. It spreads through shared and removable drives. These Trojan has the functionality of intercepting network traffic in order to steal user’s credentials such as usernames, passwords, and credit cards data. Further the malware may also change the DNS settings of the infected system to perform the malicious activities. |
No Aliases found |
December 23, 2008 |
http://www.microsoft.com/security/portal/Entry.aspx?name= |
|
|
Security News |
||||||
Lok Sabha passes IT Act Amendment Bill Indian organisations fare better than global organisations in Information System Security according to CERT-IN - FICCI - PWC Survey Security in Indian organisations is evolving at a rapid pace. No longer is security merely a line item in the overheads budget of Indian enterprises, nor is it a technical issue easily addressed by an off-the-shelf technology product, according to the Information Systems Security Survey,2007-08 titled 'From strength to strength', conducted by the Indian Computer Emergency Response Team (CERT-In), Federation of Indian Chambers of Commerce and Industry (FICCI) and PricewaterhouseCoopers (PwC). More than 140 organisations from a broad range of industries took part in the survey. About 90 percent of all email is spam: Cisco SSL Security Broken Top 9 IT security threats for 2009 Data center transformation a top priority in 2009 for CIOs Computer scientists find audio CAPTCHAs easy to crack
The Rise and Rise of Rogue Security Software Phishing Attacks Utilizing Port Numbers Statistics were taken for the phishing websites and it was seen that the maximum utilized port number was 82. It also came to light that the maximum amount of fraud against different port numbers came from the United States and Korea . DECT wireless eavesdropping made easy
|
||||||