TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to [EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any problems! ----------------------------------------------------------------------------
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Copyright 2001 Internet Security Systems (trademark) THE POWER TO PROTECT INTERNET THREAT & SOLUTIONS UPDATE for Oct 18th - Oct 22nd, 2001 ISS X-Force Special Operations Group - ---------------------------------------- CURRENT THREAT ASSESSMENT & THREAT FORECAST - ---------------------------------------- AlertCon 1 Today, Oct 18th, 2001 AlertCon 1 For Oct 19th-22nd, 2001 Today's Special Topic: Making security decisions under pressure ************* - - We're remaining at AlertCon 1 and projecting this assessment through mid-day Monday because we're not seeing any threat issues that require focused attention or increased vigilance. - - AlertCon 1 is not 'low'. There is no such thing as a 'low' threat on the Internet. AlertCon 1 assumes the general chaotic, unregulated, insecure nature of the Web. Anyone connecting to it needs to be fully armored against its relentless assaults and focused attacks. - --------------------------------------- Today's Security Focus - Making security decisions under pressure - --------------------------------------- - - The security community is stressed and on something of a hair trigger these days. Understandable. - - With the new emphasis on security comes the heavy burden of making good decisions. Trouble is, people expect those good decisions as fast as possible, perhaps in areas we've not got much experience in. - - A paradigm in the security field shows speed and accuracy at opposite ends of the chart and we see the truth of that all the time. We quickly learn in this business that the first report of a bad thing is often mostly wrong. As you wait for the second and third reports to add clarity there is a growing impatience for some sort of assessment and recommendation for action. Eventually the pressure for this decision builds until you make your assessment, call for some action. Sometimes there's no avoiding an immediate judgment call but the more minutes you can hold out the less time you will spend correcting earlier reports or explaining subsequent changes. - - A great rule of thumb: whenever possible, get a second opinion. - -- Get a little bit of that 'I'm from Missouri, show me' thing going when you hear of a cyber threat that seems too bad, too efficient, too effective, and comes from somebody who says, 'The vendor says it's true" and/or "forward this to everyone in your address book". If the problem has been validated by a vendor, why aren't you getting the message from the vendor? Check their web site and the sites of their competitors to see if there is anything official on the problem. - -- In addition to the relevant vendor sites, a number of professional organizations exist to help you through your cyber emergencies. - -- You can contact the 24 x 7 Watch Desk at the National Infrastructure Protection Center, 202-323-3205, to see if they've got any additional information. You might even be the first person making the report, in which case you are alerting them to a potential problem that might affect the country. - -- You can urge your company to join the ISAC for your industry and validate your emergencies through them. Often, someone else in your industry has had the same problem and can tell you what the solution is. - -- You can use your local InfraGard chapter or your local FBI field office's cyber crime unit as a sounding board. - -- Many state and local governments also have cyber-crime units you can query and they're happy to help because it also keeps them in the loop. - -- There are a number of hoax and urban legend sites that it pays to check before you warn your employees about kidney harvesting in Las Vegas or the latest virus that will nuke your computer. A good source of virus hoax information is Trend Micro's hoax encyclopedia at: <http://www.antivirus.com/vinfo/hoaxes/hoax.asp>. A great urban legend site handy for rumor control is <http://www.snopes2.com/> . - -- You're only in this alone if you don't use the resources that are out there to help you. - ------------------------------------- Attack Signature Ranking - global IDS, midnight - midnight, previous day, % of total - ------------------------------------- Unauth Access Attempt 35.50% Suspicious Activity 34.22% Protocol Decode 19.95% Denial Of Service 06.73% Pre-Attack Probe 03.58% Back Door 00.01% - ------------------------------------- Top Ten Attack Destination Ports - global IDS, midnight - midnight, previous day, % of top ten (ports found at <http://www.iana.org/assignments/port-numbers> - ------------------------------------- 80 (http) 84.73% 21 (ftp) 12.37% 25 (smtp) 01.92% 443 (https) 00.25% 22 (tcp) 00.16% 143 (imap) 00.14% 139 (netbios-ss) 00.12% 4583 (unassigned) 00.11% 15104 (unassigned) 00.11% 69 (tftp) 00.09% - --------------------------------------- VIRUS, VULNERABILITY, NEWS UPDATES - --------------------------------------- - - Visit <http://www.iss.net> under 'Global Internet Threat Intelligence Service' - - According to Sophos <http://www.sophos.com/virusinfo/topten/> the top ten viruses in September 2001 were: 1. Nimda-A 71.2% 2. Sircam-A 11.4% 3. Magistr-A 03.7% 4. Magistr-B 03.0% 5. Hybris-B 01.5% 6. Apology-B 00.7% 7. VBS/Kakworm 00.7% 8. Floss 00.7% 9. Bymer-A 00.5% 10. Badtrans-A 00.4% - --------------------------------------- Defacement Watch - --------------------------------------- - - Alldas.de stats show that since April, 2000, the most defaced OS is Windows, with a total of 15,311 defacements reported, for 64% of the total. Although growing in popularity as a target, Linux is a distant second with 4052 defacements for 17% of the total. - - Alldas reports a very low 54 sites defaced yesterday. Details can be seen at <http://www.alldas.de> under 'current month'. - - All but one of yesterday's 54 defacement messages continue to show the work of the mostly adolescent and well known hacker community rather than any professional psyop staff. Thirty-nine had no political message, 5 were anti-war, 3 were anti-Brazil government, 2 were anti-bin Ladin, 2 showed concern about recreational hacking being labeled as terrorist acts under the new anti terrorist legislation in the US, and 1 was pro-bin Ladin. - - G-Force Pakistan defaced an NOAA site with an anti-US and anti-Israeli message and a message purporting to be from Al Qaeda. <http://defaced.alldas.de/mirror/2001/10/17/anburs.kc.noaa.gov/> This is the most focused threat message we've seen to date by any of the traditionally tracked web defacement groups and is a definite departure from the norm. Too early to tell if G-Force Pakistan is actually being used as a spokesman for the Taliban or Osama or both or is simply putting forth its own ideas. - --------------------------------------- NOTES, COPYRIGHT NOTICE, and DISCLAIMER - --------------------------------------- NOTE 1: Our web site has this information in more attractive format and graphics available to the public at no cost at www.iss.net <http://www.iss.net> under 'Global Internet Threat Intelligence Service' <https://gtoc.iss.net/secure/whatshot.php> Screen captures (Control/PrtSc) of the site's pages dropped into PowerPoint can be an effective way to communicate various aspects of the Internet threat, e.g. the graph depicting 'AlertCon Trends' <https://gtoc.iss.net/secure/graph.html> NOTE 2: We provide this information on Internet threat metrics, viruses, vulnerabilities, patches, and breaking news, in the spirit of PDD 63, to help security professionals wage the war against Internet threats more effectively. Information in this update derived primarily from global, real time, 24 x 7 IDS feeds, ISS X-Force R&D Team research, and professional liaison. Other sources as noted. AlertCon 1 reflects the global, malicious, determined, 24 x 7 attacks experienced by all networks. AlertCon 2 means increased vigilance/action recommended due to a specific threat or concern. AlertCon 3 means increased attacks against specific targets or vulnerabilities on a scale that is unusually high, action required. AlertCon 4 reflects an Internet emergency for a target or group of targets whose business continuity may depend on some sort of immediate, decisive action. All summaries cover 24 hours the previous workday, GMT. Monday summaries may cover some weekend activity. Copyright 2001 Internet Security Systems, Inc. Permission is granted for the redistribution of the Internet Threat Update electronically. It is not to be sold or edited in any way without express consent of ISS. Refer comments or questions to [EMAIL PROTECTED] mailto: [EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]> Disclaimer: This information is subject to change without notice. Use of this information constitutes acceptance for use in an 'as is' condition. There are no warranties with regard to this information. In no event shall the author be liable for any damages whatsoever arising out of or in connection with the use or spread of this information. Any use of this information is at the user's own risk. No other use authorized. FOIA Exemption 4. Dennis Dennis Treece Director, Global MSS Special Operations Group Internet Security Systems (ISS) 6303 Barfield Road Atlanta, Georgia 30328 404-236-4065 Cell 404-667-9345 Fax 404-236-2626 Internet Security Systems -- The Power to Protect -----BEGIN PGP SIGNATURE----- Version: PGP 6.5 iQA/AwUBO87+5uOOe/7N9KJeEQJtKACeLKb7SAs/4hTgtl38PI59/qbHtg4AoKwB Yd6czF2NKFBjp2gPOn3viEWR =Bb2t -----END PGP SIGNATURE-----
