TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Copyright 2001 Internet Security Systems (trademark) THE POWER TO
PROTECT

INTERNET THREAT & SOLUTIONS UPDATE for September 21st - 24th, 2001
ISS X-Force Special Operations Group

- --------------------------------------
CURRENT THREAT ASSESSMENT & THREAT FORECAST
- --------------------------------------

AlertCon 2              Today, September 21st, 2001
AlertCon 2      Projected for September 22nd - 24th, 2001

Today's Focus: Nimda Clean-up; Aggressive security patching

*************

- - We have reduced to AlertCon 2 (increased vigilance) for today and
we're projecting AlertCon 2 through the weekend. We should all be
watching for two things; an uptick in Nimda or signs indicating the
arrival of a new, fast spreading worm. There is no reason to conclude
that the authors of these worms are finished with us.

- - Nimda activity on our monitored networks is down considerably,
though since Nimba alarms can look like both Code Red and Code Blue
it's hard to peg the numbers accurately to any specific code across a
global IDS network.

- - Recommended security focus for today should be on the last stages of
Nimda clean-up accompanied by an aggressive campaign to make sure all
OS in use are up to date with the latest security patch. If Nimda
taught us anything, it's that all vulnerabilities are fair game, not
just IIS.

- ---------------------------------------
SOLUTIONS
- ---------------------------------------

- - Patch everything and continue to upgrade your patches as new
vulnerability solutions are released. Whenever OS are installed or
reinstalled if all the patches since that OS release date are not
included in this task you have left a gaping hole in your network. The
same is true for anti-virus updates. 

- - Microsoft's web site has the full solution set for its products at
this site:
<http://www.microsoft.com/technet/treeview/default.asp?url=/technet/sec
urity/topics/Nimda.asp> 

- - All the major anti-virus vendors now have Nimda solutions. Aris has
an excellent write-up on the Worm and some further links to security
solutions:
<http://aris.securityfocus.com/alerts/nimda/010919-Analysis-Nimda.pdf>


- - Make sure you have procedures for backing up key data, and that all
users understand and comply. Ensure that backups are stored off site
and off line. 

- - Check your firewall policies to make sure only the minimum number of
ports and protocols are allowed. Because Nimda spreads via file
shares, ensure netbios traffic (port 139 especially) is not passing
through the firewall. This prevents share points from being accessed
from outside the firewall. Any network using file sharing between
geographical areas is a bad idea and should be questioned and ended if
not fully justified. If justified, it should be handled via VPN
connection.

- -------------------------------------
Attack Signatures - global IDS, midnight - midnight, previous day, %
of total
- -------------------------------------

Denial Of Service            69.80%
Suspicious Activity          13.21%
Protocol Decode              08.34%
Unauth Access Attempts       07.78%
Pre-Attack Probe             00.87%
Back Doors                   00.01%

- -------------------------------------
Top Ten Destination Ports - global IDS, midnight - midnight, previous
day, % of top ten (ports found at 
<http://www.iana.org/assignments/port-numbers>  
- -------------------------------------

80       (http)              85.59%
25       (smtp)              07.69%
69       (tftp)              03.95%
139      (netbios-ssn)       01.04%
443      (https)             00.37%
31500    (unassigned)        00.35%
53       (domain)            00.30%
6768     (bmc-perf-mgrd)     00.24%
137      (netbios-ns)        00.23%
2560     (labrat)            00.22%

- ---------------------------------------
VIRUS, VULNERABILITY, NEWS UPDATES
- ---------------------------------------

<http://www.iss.net/> under "Global Internet Threat Intelligence
Service"

- ---------------------------------------
NOTE, DISCLAIMER AND COPYRIGHT NOTICE
- ---------------------------------------

NOTE: Our web site with this information in more attractive format and

graphics is available to the public at no cost at
<http://www.iss.net/> under "Global Internet Threat Intelligence
Service". Screen
captures (Control/PrtSc) of the site's pages dropped into PowerPoint
can be an effective way to communicate various aspects of the Internet
threat, e.g. the graph depicting "AlertCon Trends".

We provide this information on Internet threat metrics, viruses,
vulnerabilities, patches, and breaking news, in the spirit of PDD 63,
to help security professionals wage the war against Internet threats
more effectively. Information in this update derived primarily from
global, real time, 24 x 7 IDS feeds, ISS X-Force R&D Team research,
and professional liaison. Other sources as noted. AlertCon 1 reflects
the global, malicious, determined, 24 x 7 attacks experienced by all
networks. AlertCon 2 means increased vigilance/action recommended due
to a specific threat or concern. AlertCon 3 means increased attacks
against specific targets or vulnerabilities on a scale that is
unusually high, action required. AlertCon 4 reflects an Internet
emergency for a target or group of targets whose business continuity
may depend on some sort of immediate, decisive action. All summaries
cover 24 hours the previous workday, GMT. Monday summaries may cover
some weekend activity. 

Copyright 2001 Internet Security Systems, Inc. Permission is granted
for the redistribution of the Internet Threat Update electronically.
It is not to be sold or edited in any way without express consent of
ISS. Refer comments or questions to [EMAIL PROTECTED]
<mailto:[EMAIL PROTECTED]>. Disclaimer: This information is subject to
change without notice. Use of this information constitutes acceptance
for use in an "as is" condition. There are no warranties with regard
to this information. In no event shall the author be liable for any
damages whatsoever arising out of or in connection with the use or
spread of this information. Any use of this information is at the
user's own risk. No other use authorized. FOIA Exemption 4.



Dennis
Dennis Treece
Director, 
Global MSS Special Operations Group
Internet Security Systems (ISS)
6303 Barfield Road
Atlanta, Georgia 30328
404-236-4065
Cell 404-667-9345
Fax 404-236-2626

Internet Security Systems -- The Power to Protect

Confidentiality Notice: This message is being sent by or on behalf of
a network security professional. It is intended exclusively for the
individual to whom it is addressed. This communication may contain
information that is proprietary, privileged or confidential.


-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5

iQA/AwUBO6trheOOe/7N9KJeEQKhWgCfUI5DlrDvk0+3mFTeOhQFKMNhiLAAmgMr
/UQK3zP8qJ5iNx35Ls10g1py
=7+tY
-----END PGP SIGNATURE-----


Reply via email to