TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Copyright 2001 Internet Security Systems (trademark) THE POWER TO
PROTECT

INTERNET THREAT & SOLUTIONS UPDATE for Oct 23rd - Oct 25th, 2001
ISS X-Force Special Operations Group

- ----------------------------------------
CURRENT THREAT ASSESSMENT & THREAT FORECAST
- ----------------------------------------

AlertCon 1              Today, Oct 23rd, 2001
AlertCon 1      For Oct 24th-25th, 2001 

Today's Focus: Minimizing your Exposure - Port and Protocol
restrictions
*************

- - We remain at AlertCon 1 and project this out through Thursday.

- - While AlertCon 1 is our lowest level, it is by no means 'low'. There
is no such thing as a low threat level on the Internet. Attack probes
are constant and weaknesses detected in any network are instantly
exploited by automated scripts that run 24 x 7. It is not uncommon to
see a combination of attacks and probes numbering near 6 figures
against a single network in a single day. 

- - Networks connecting to the Internet must always 'suit up'
appropriately with firewalls, ACL, IDS, strong authentication, default
settings off, smart choices on allowable inbound and outbound traffic,
critical servers alarmed and monitored, all OS and anti-virus up to
date. 

- - Individual computers connecting to the Internet, especially if with
high speed access, must use a personal firewall and reporting
mechanism, have the latest version of OS running with all patches
applied, have file sharing disabled (unless strong permissions are
set), and keep the anti-virus software up to date.

- -------------------------------------
Today's Focus Solutions
- -------------------------------------

- - Errata: Yesterday and Friday we had a typo in our defensive blocking
information. The correct line is 203.133.252.0 -- 203.133.255.255  

- - In addition to blocking IP addresses you also need to take a hard
look at what type of traffic is allowed into and out of your network.
The days when everything is defaulted to "allow" are gone forever.
What ports and protocols do you really need? Here are some handy tips
on what kind of defensive permissions we advise for your network.

- - In addition to limiting the IP Blocks you allow through your ACL or
firewalls, we advise limiting the ports and protocols that are
available in your network. Known Trojan ports is a good start. 
Blocking unused or unneeded protocols is another simple item to
implement or verify.  For example, you might quickly determine there
is no need for things like the time protocol (port 37); POP2 (port
109); and IRC (port 6667).  Apprehension towards hampering legitimate
business can be overcome by initially taking a much more restrictive
position on inbound traffic and a more conservative implementation of
outbound restrictions (at least while a policy is being refined and
tightened down.) From there, a more thorough assessment of ports
needed to support your business can be initiated using things like
audit logs, network sniffers, protocol analyzers and other tools
common to network operations.  Adopt a rule-base that states if it is
not specifically needed, shut it off or restrict to specific users or
networks, versus allowing the entire Internet and all its features
complete access. More information on port assignments can be found at
<http://www.iana.org/assignments/port-numbers>. 


- -------------------------------------
Attack Signature Ranking - global IDS, midnight - midnight, previous
day, % of total
- -------------------------------------

Suspicious Activity          52.17%
Unauth Access Attempt        22.82%
Protocol Decode              15.58%
Denial Of Service            07.40%
Pre-Attack Probe             02.03%
Back Door                    00.01%

- -------------------------------------
Top Ten Attack Destination Ports - global IDS, midnight - midnight,
previous day, % of top ten (ports found at 
<http://www.iana.org/assignments/port-numbers>       
- -------------------------------------

80       (http)              63.31%
21       (ftp)               33.55%
25       (smtp)              02.03%
79       (finger)            00.29%
443      (https)             00.23%
15104    (unassigned)        00.15%
12754    (unassigned)        00.14%
123      (ntp)               00.11%
143      (imap)              00.09%
6723     (unassigned)        00.08%

- ---------------------------------------
Top 10 Vulnerabilities
- ---------------------------------------

TOP 10 Vulnerabilities found when Penetration Testing over the last
year, listed in order of magnitude

1. IIS Decode.
        <http://xforce.iss.net/alerts/advise77.php#list> 

2. IIS Unicode translation errors.
        <http://xforce.iss.net/alerts/advise68.php#list> 

3. IIS unauthorized ODBC data access with RDS.
        <http://xforce.iss.net/static/1212.php>

4. SQL injection.
discussed in <http://xforce.iss.net/static/5972.php> , papers at:


<http://www.securityfocus.com/templates/archive.pike?list=98&mid=200002>
  


<http://www.blackhat.com/presentations/win-usa-01/Litchfield/BHWin01Litc
hfield.doc> 
 
<http://www.securityfocus.com/templates/archive.pike?list=1&mid=13882>


5. mssql sa blank password <http://xforce.iss.net/static/1459.php>

6. netbios blank/guessable passwords. 
general issues - CAN-1999-0504 and CAN-1999-0505
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-1999-0505>  

7. open x-windows.
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0526>
This is a direct function of poor security architecture.

8. Poor server configuration.  e.g. web server directories without
index files or access control.

9. Weak Passwords and poorly protected password files.
Easy access to SAM databases; server daemons running with root or
system privileges.

10. Lack of 'defense in depth'.
Over-relieance on firewalls. Lack of host-based security. Excessive or
incorrectly implemented firewall rules. Lack of change control.

- ---------------------------------------
VIRUS, VULNERABILITY, NEWS UPDATES
- ---------------------------------------

- - Visit <http://www.iss.net> under 'Global Internet Threat
Intelligence Service'

- - According to Sophos <http://www.sophos.com/virusinfo/topten/> the
top ten viruses in September 2001 were:

1.  Nimda-A         71.2%
2.  Sircam-A        11.4%
3.  Magistr-A       03.7%
4.  Magistr-B       03.0%
5.  Hybris-B        01.5%
6.  Apology-B       00.7%
7.  VBS/Kakworm     00.7%
8.  Floss           00.7%
9.  Bymer-A         00.5%
10. Badtrans-A      00.4%

- ---------------------------------------
Defacement Watch
- ---------------------------------------

- - Alldas.de stats show that since April, 2000, the most defaced OS is
Windows, with a total of 15,417 defacements reported, for 63% of the
total. Although growing in popularity as a target, Linux is a distant
second with 4193 defacements for 17% of the total.

- - Alldas.de reports a total of 98 sites defaced yesterday. Dtails can
be seen at <http://www.alldas.de> under 'current month'. 

- ---------------------------------------
NOTES, COPYRIGHT NOTICE, and DISCLAIMER 
- ---------------------------------------

NOTE 1: Our web site has this information in more attractive format
and graphics available to the public at no cost at www.iss.net
<http://www.iss.net> under 'Global Internet Threat Intelligence
Service' <https://gtoc.iss.net/secure/whatshot.php> Screen captures
(Control/PrtSc) of the site's pages dropped into PowerPoint can be an
effective way to communicate various aspects of the Internet threat,
e.g. the graph depicting 'AlertCon Trends'
<https://gtoc.iss.net/secure/graph.html> 

NOTE 2: We provide this information on Internet threat metrics,
viruses, vulnerabilities, patches, and breaking news, in the spirit of
PDD 63, to help security professionals wage the war against Internet
threats more effectively. Information in this update derived primarily
from global, real time, 24 x 7 IDS feeds, ISS X-Force R&D Team
research, and professional liaison. Other sources as noted. AlertCon 1
reflects the global, malicious, determined, 24 x 7 attacks experienced
by all networks. AlertCon 2 means increased vigilance/action
recommended due to a specific threat or concern. AlertCon 3 means
increased attacks against specific targets or vulnerabilities on a
scale that is unusually high, action required. AlertCon 4 reflects an
Internet emergency for a target or group of targets whose business
continuity may depend on some sort of immediate, decisive action. All
summaries cover 24 hours the previous workday, GMT. Monday summaries
may cover some weekend activity. 

Copyright 2001 Internet Security Systems, Inc. Permission is granted
for the redistribution of the Internet Threat Update electronically.
It is not to be sold or edited in any way without express consent of
ISS. Refer comments or questions to [EMAIL PROTECTED] mailto:
[EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]>   

Disclaimer: This information is subject to change without notice. Use
of this information constitutes acceptance for use in an 'as is'
condition. There are no warranties with regard to this information. In
no event shall the author be liable for any damages whatsoever arising
out of or in connection with the use or spread of this information.
Any use of this information is at the user's own risk. No other use
authorized. FOIA Exemption 4. 



Dennis
Dennis Treece
Director, 
Global MSS Special Operations Group
Internet Security Systems (ISS)
6303 Barfield Road
Atlanta, Georgia 30328
404-236-4065
Cell 404-667-9345
Fax 404-236-2626




-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5

iQA/AwUBO9WgL+OOe/7N9KJeEQLqJgCdGBNoVP/K8xu4zshs3KVXtdJr6IcAn39X
slAcrcsIkvKWBzwcLG4S4NKI
=NRBp
-----END PGP SIGNATURE-----


Reply via email to