TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Copyright 2001 Internet Security Systems (trademark) THE POWER TO
PROTECT

INTERNET THREAT & SOLUTIONS UPDATE for Oct 17th - Oct 19th, 2001
ISS X-Force Special Operations Group

- ----------------------------------------
CURRENT THREAT ASSESSMENT & THREAT FORECAST
- ----------------------------------------

AlertCon 1              Today, Oct 17th, 2001
AlertCon 1      For Oct 18th-19th, 2001 

This Week's Focus: Disaster Planning and Recovery

*************

- - We're remaining at AlertCon 1 and projecting this assessment through
mid-day Friday because we're not seeing any threat issues that require
focused attention or increased vigilance. 

- - AlertCon 1 is not 'low'. There is no such thing as a 'low' threat on
the Internet. AlertCon 1 assumes the general chaotic, unregulated,
insecure nature of the Web. Anyone connecting to it needs to be fully
armored against its relentless assaults and focused attacks.

- - Nothing much seems to have come from Sircam Worm's anniversary
yesterday. Here's a commentary on why this may have failed to ignite:

<http://news.cnet.com/news/0-1003-200-7544896.html?tag=dd.ne.dht.nl-sty.
0> 

- - A new worm has surfaced that seems to be poorly written but which
uses social engineering to cause people to open the attachment and
execute the harmful payload. The subject line to watch for is 'Antrax
Info' (quote marks are not part of the actual subject line.) Actual
e-mail text is in Spanish.
<http://www.symantec.com/avcenter/venc/data/vbs.vbswg.af.html> 

- ---------------------------------------
Security Focus This Week - Disaster Planning and Recovery
- ---------------------------------------

- - Today the subject is planning for the implausible.

- - Before the events of 9/11 and the later Anthrax scares it would have
been hard to justify devoting resources to implausible scenarios.
Today it's prudent to have another look.

- - Situation: An anthrax discovery in the mailroom has caused a
complete evacuation of the building that houses your NOC and primary
data center, plus the bulk of your finance and accounting staff, among
others. Equipment is functioning just fine. You can't get back into
the building until cleared by medical and law enforcement authorities.

- - Once the people all complete their medical screening and can return
to work, where do they return to? How will you perform remote
management on the network and how will you access your e-mail and the
files you need to do your jobs?

- - There are numerous commercial solutions available for remote
management, remote access, and for security for remote management and
remote access. This is a good time to start doing your basic research
and shopping for the solution that will best fit your situation.

- -------------------------------------
Attack Signature Ranking - global IDS, midnight - midnight, previous
day, % of total
- -------------------------------------

Pre-Attack Probe             53.98%
Suspicious Activity          29.34%
Unauth Access Attempt        08.68%
Denial Of Service            04.02%
Protocol Decode              03.85%
Back Door                    00.13%

- -------------------------------------
Top Ten Attack Destination Ports - global IDS, midnight - midnight,
previous day, % of top ten (ports found at 
<http://www.iana.org/assignments/port-numbers>       
- -------------------------------------

111      (sunrpc)            47.32%
80       (http)              35.00%
21       (ftp)               10.12%
22       (tcp)               05.99%
25       (smtp)              01.09%
443      (https)             00.15%
31337    (unassigned)        00.12%
143      (imap)              00.08%
15104    (unassigned)        00.06%
69       (tftp)              00.05%

- ---------------------------------------
VIRUS, VULNERABILITY, NEWS UPDATES
- ---------------------------------------

- - Visit <http://www.iss.net> under 'Global Internet Threat
Intelligence Service'

- - According to Sophos <http://www.sophos.com/virusinfo/topten/> the
top ten viruses in September 2001 were:

1.  Nimda-A         71.2%
2.  Sircam-A        11.4%
3.  Magistr-A       03.7%
4.  Magistr-B       03.0%
5.  Hybris-B        01.5%
6.  Apology-B       00.7%
7.  VBS/Kakworm     00.7%
8.  Floss           00.7%
9.  Bymer-A         00.5%
10. Badtrans-A      00.4%

- ---------------------------------------
Defacement Watch
- ---------------------------------------

- - Alldas.de stats show that since April, 2000, the most defaced OS is
Windows, with a total of 15,303 defacements reported, for 64% of the
total. Linux is a distant second with 4022 defacements for 17% of the
total.

- - Alldas reports a very low 18 sites defaced yesterday. Details can be
seen at <http://www.alldas.de> under 'current month'. 

- - A check of yesterday's 18 defacement messages continues to show the
work of the known hacker community rather than any professional psyop
staff. Thirteen had no political message, 5 were concerned about
recreational hacking being labeled as terrorist acts under the new
anti terrorist legislation in the US, and 1 was concerned about the
effect of the FBI's new search powers on Internet privacy.

- - G-Force Pakistan has today defaced an NOAA site with an anti-US and
anti-Israeli message and a message purporting to be from Al Qaeda.
<http://defaced.alldas.de/mirror/2001/10/17/anburs.kc.noaa.gov/> This
is the most focused threat message we've seen to date by any of the
traditionally tracked web defacement groups
 
- ---------------------------------------
NOTES, COPYRIGHT NOTICE, and DISCLAIMER 
- ---------------------------------------

NOTE 1: Our web site has this information in more attractive format
and graphics available to the public at no cost at www.iss.net
<http://www.iss.net> under 'Global Internet Threat Intelligence
Service' <https://gtoc.iss.net/secure/whatshot.php> Screen captures
(Control/PrtSc) of the site's pages dropped into PowerPoint can be an
effective way to communicate various aspects of the Internet threat,
e.g. the graph depicting 'AlertCon Trends'
<https://gtoc.iss.net/secure/graph.html> 

NOTE 2: We provide this information on Internet threat metrics,
viruses, vulnerabilities, patches, and breaking news, in the spirit of
PDD 63, to help security professionals wage the war against Internet
threats more effectively. Information in this update derived primarily
from global, real time, 24 x 7 IDS feeds, ISS X-Force R&D Team
research, and professional liaison. Other sources as noted. AlertCon 1
reflects the global, malicious, determined, 24 x 7 attacks experienced
by all networks. AlertCon 2 means increased vigilance/action
recommended due to a specific threat or concern. AlertCon 3 means
increased attacks against specific targets or vulnerabilities on a
scale that is unusually high, action required. AlertCon 4 reflects an
Internet emergency for a target or group of targets whose business
continuity may depend on some sort of immediate, decisive action. All
summaries cover 24 hours the previous workday, GMT. Monday summaries
may cover some weekend activity. 

Copyright 2001 Internet Security Systems, Inc. Permission is granted
for the redistribution of the Internet Threat Update electronically.
It is not to be sold or edited in any way without express consent of
ISS. Refer comments or questions to [EMAIL PROTECTED] mailto:
[EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]>   

Disclaimer: This information is subject to change without notice. Use
of this information constitutes acceptance for use in an 'as is'
condition. There are no warranties with regard to this information. In
no event shall the author be liable for any damages whatsoever arising
out of or in connection with the use or spread of this information.
Any use of this information is at the user's own risk. No other use
authorized. FOIA Exemption 4. 



Dennis
Dennis Treece
Director, 
Global MSS Special Operations Group
Internet Security Systems (ISS)
6303 Barfield Road
Atlanta, Georgia 30328
404-236-4065
Cell 404-667-9345
Fax 404-236-2626

Internet Security Systems -- The Power to Protect




-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5

iQA/AwUBO82xw+OOe/7N9KJeEQK7qgCgryzGot6n/lzGyg6pjy/dni+8yKoAnAy0
j8AsGN+r/qyy0iatCdxPO1wf
=c61k
-----END PGP SIGNATURE-----


Reply via email to