TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to [EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any problems! ----------------------------------------------------------------------------
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Copyright 2001 Internet Security Systems (trademark) THE POWER TO PROTECT INTERNET THREAT & SOLUTIONS UPDATE for Oct 24th - Oct 26th, 2001 ISS X-Force Special Operations Group - ---------------------------------------- CURRENT THREAT ASSESSMENT & THREAT FORECAST - ---------------------------------------- AlertCon 1 Today, Oct 24th, 2001 AlertCon 1 For Oct 25th-26th, 2001 Today's Focus: Minimizing your Exposure - Port and Protocol restrictions ************* - - We remain at AlertCon 1 and project this out through Friday. - - While AlertCon 1 is our lowest level, it is by no means 'low'. There is no such thing as a low threat level on the Internet. Attack probes are constant and weaknesses detected in any network are instantly exploited by automated scripts that run 24 x 7. It is not uncommon to see a combination of attacks and probes numbering near 6 figures against a single network in a single day. - - We have seen an increase in Unix/Linux attacks, which may be attributed to the increased number of associated vulnerabilities, <https://gtoc.iss.net/secure/vulnerabilityalerts.php> published in the last few weeks. There has been a lot of recent focus on Windows vulnerabilities and exploits but other OS offer ways to exploit our networks and should not be ignored. - ------------------------------------- Today's Focus Solutions - ------------------------------------- - - In addition to blocking IP addresses you also need to take a hard look at what type of traffic is allowed into and out of your network. The days when everything is defaulted to "allow" are gone forever. What ports and protocols do you really need? Here are some handy tips on what kind of defensive permissions we advise for your network. - - In addition to limiting the IP Blocks you allow through your ACL or firewalls, we advise limiting the ports and protocols that are available in your network. Known Trojan ports are a good start. Blocking unused or unneeded protocols is another simple item to implement or verify. For example, you might quickly determine there is no need for things like the time protocol (port 37); POP2 (port 109); and IRC (port 6667). Apprehension towards hampering legitimate business can be overcome by initially taking a much more restrictive position on inbound traffic and a more conservative implementation of outbound restrictions (at least while a policy is being refined and tightened down.) From there, a more thorough assessment of ports needed to support your business can be initiated using things like audit logs, network sniffers, protocol analyzers and other tools common to network operations. Adopt a rule-base that states if it is not specifically needed, shut it off or restrict to specific users or networks, versus allowing the entire Internet and all its features complete access. More information on port assignments can be found at <http://www.iana.org/assignments/port-numbers> . - - Patches for the Solaris rpc.yppasswdd vulnerability can be located at <http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=salert%2F27486&zone_32 =yppasswd%2A%20%202748%2A%20> - ------------------------------------- Attack Signature Ranking - global IDS, midnight - midnight, previous day, % of total - ------------------------------------- Suspicious Activity 38.85% Unauth Access Attempt 23.33% Protocol Decode 19.64% Denial Of Service 12.77% Pre-Attack Probe 05.39% Back Door 00.02% - ------------------------------------- Top Ten Attack Destination Ports - global IDS, midnight - midnight, previous day, % of top ten (ports found at <http://www.iana.org/assignments/port-numbers> - ------------------------------------- 80 (http) 90.68% 25 (smtp) 03.38% 21 (ftp) 01.94% 514 (shell) 01.56% 513 (login) 01.13% 443 (https) 00.36% 143 (imap) 00.31% 12754 (unassigned) 00.25% 32773 (unassigned) 00.21% 113 (ident) 00.18% - --------------------------------------- Top 10 Vulnerabilities - --------------------------------------- TOP 10 Vulnerabilities found when Penetration Testing over the last year, listed in order of magnitude 1. IIS Decode. <http://xforce.iss.net/alerts/advise77.php#list> 2. IIS Unicode translation errors. <http://xforce.iss.net/alerts/advise68.php#list> 3. IIS unauthorized ODBC data access with RDS. <http://xforce.iss.net/static/1212.php> 4. SQL injection. discussed in <http://xforce.iss.net/static/5972.php> , papers at: <http://www.securityfocus.com/templates/archive.pike?list=98&mid=200002> <http://www.blackhat.com/presentations/win-usa-01/Litchfield/BHWin01Litc hfield.doc> <http://www.securityfocus.com/templates/archive.pike?list=1&mid=13882> 5. mssql sa blank password <http://xforce.iss.net/static/1459.php> 6. netbios blank/guessable passwords. general issues - CAN-1999-0504 and CAN-1999-0505 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-1999-0505> 7. open x-windows. <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0526> This is a direct function of poor security architecture. 8. Poor server configuration. e.g. web server directories without index files or access control. 9. Weak Passwords and poorly protected password files. Easy access to SAM databases; server daemons running with root or system privileges. 10. Lack of 'defense in depth'. Over-relieance on firewalls. Lack of host-based security. Excessive or incorrectly implemented firewall rules. Lack of change control. - --------------------------------------- VIRUS, VULNERABILITY, NEWS UPDATES - --------------------------------------- - - Visit <http://www.iss.net> under 'Global Internet Threat Intelligence Service' - - According to Sophos <http://www.sophos.com/virusinfo/topten/> the top ten viruses in September 2001 were: 1. Nimda-A 71.2% 2. Sircam-A 11.4% 3. Magistr-A 03.7% 4. Magistr-B 03.0% 5. Hybris-B 01.5% 6. Apology-B 00.7% 7. VBS/Kakworm 00.7% 8. Floss 00.7% 9. Bymer-A 00.5% 10. Badtrans-A 00.4% - --------------------------------------- Defacement Watch - --------------------------------------- - - Alldas.de stats show that since April, 2000, the most defaced OS is Windows, with a total of 15,442 defacements reported, for 63% of the total. Although growing in popularity as a target, Linux is a distant second with 44207 defacements for 17% of the total. - - Alldas.de reports a total of 41 sites defaced yesterday. Details can be seen at <http://www.alldas.de> under 'current month'. - --------------------------------------- NOTES, COPYRIGHT NOTICE, and DISCLAIMER - --------------------------------------- NOTE 1: Our web site has this information in more attractive format and graphics available to the public at no cost at www.iss.net <http://www.iss.net> under 'Global Internet Threat Intelligence Service' <https://gtoc.iss.net/secure/whatshot.php> Screen captures (Control/PrtSc) of the site's pages dropped into PowerPoint can be an effective way to communicate various aspects of the Internet threat, e.g. the graph depicting 'AlertCon Trends' <https://gtoc.iss.net/secure/graph.html> NOTE 2: We provide this information on Internet threat metrics, viruses, vulnerabilities, patches, and breaking news, in the spirit of PDD 63, to help security professionals wage the war against Internet threats more effectively. Information in this update derived primarily from global, real time, 24 x 7 IDS feeds, ISS X-Force R&D Team research, and professional liaison. Other sources as noted. AlertCon 1 reflects the global, malicious, determined, 24 x 7 attacks experienced by all networks. AlertCon 2 means increased vigilance/action recommended due to a specific threat or concern. AlertCon 3 means increased attacks against specific targets or vulnerabilities on a scale that is unusually high, action required. AlertCon 4 reflects an Internet emergency for a target or group of targets whose business continuity may depend on some sort of immediate, decisive action. All summaries cover 24 hours the previous workday, GMT. Monday summaries may cover some weekend activity. Copyright 2001 Internet Security Systems, Inc. Permission is granted for the redistribution of the Internet Threat Update electronically. It is not to be sold or edited in any way without express consent of ISS. Refer comments or questions to [EMAIL PROTECTED] mailto: [EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]> Disclaimer: This information is subject to change without notice. Use of this information constitutes acceptance for use in an 'as is' condition. There are no warranties with regard to this information. In no event shall the author be liable for any damages whatsoever arising out of or in connection with the use or spread of this information. Any use of this information is at the user's own risk. No other use authorized. FOIA Exemption 4. Dennis Dennis Treece Director, Global MSS Special Operations Group Internet Security Systems (ISS) 6303 Barfield Road Atlanta, Georgia 30328 404-236-4065 -----BEGIN PGP SIGNATURE----- Version: PGP 6.5 iQA/AwUBO9becOOOe/7N9KJeEQI9JgCgmY1UDMM+QBXWY59jaUFx0yPqgIcAoLz8 +MQ5z7j/WMToRX/rJdbQLEzM =42u1 -----END PGP SIGNATURE-----
