TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------

 
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

INTERNET THREAT UPDATE for 03-18-2002
ISS X-Force Internet Threat Intelligence Center

www.iss.net - Click on AlertCon logo for more
information.

********************************************
ALERTCON 1
Projected:  AlertCon 1
********************************************

ALERTCON 1 - AlertCon 1 reflects the malicious,
determined, global, 24 x 7 attacks experienced by
all networks.

ZLIB: There is a vulnerability in the zlib/libz
library decompression routines in version 1.1.3
and earlier.  Although there are no reported
exploits in the wild, this vulnerability
potentially affects both Linux and Microsoft
Operating Systems; databases such as Oracle;
encryption software; and a long list of other
affected products.  Check your vendor for
information and solutions.
 
SNMP UPDATE: Microsoft has just re-published a
patch for the English and German versions of NT
4.0. Users need to install this updated patch.
Currently, there are no exploits in the wild. We
remind all users to visit their vendor's web
sites frequently for updated remedial information
/ patches for products in use.
 
VIRUSES/WORMS:  WORM_PORKIS.A is out.  This
Internet worm propagates via Microsoft Outlook by
sending email with itself as an attachment,
Porkis.exe, to all addresses listed in the
infected user's Windows Address Book (WAB).

********************************************
RECOMMENDATIONS
********************************************

zlib: Vendors / code writers should upgrade their
use of zlib to version 1.1.4. Users need to check
with their vendors for impact of zlib on the
product, and if necessary, update their product
when a patch becomes available.
SNMP:  Check your vendor for new or updated
patches regarding this vulnerability. 
https://gtoc.iss.net/snmpvendor.pdf 
For information on the WORM_PORKIS>A, please see:
<http://www.antivirus.com/vinfo/virusencyclo/defau
lt5.asp?VName=WORM_PORKIS.A>   

Information regarding viruses and worms please
see:
<https://gtoc.iss.net/viruses.php>   

********************************************

FACTOID:  Businesses lose an estimated $10
billion or more annually due to security breaches
in their computer systems, according to the
Computer Security Institute.

********************************************
ATTACK SIGNATURE RANKING - global IDS, midnight -
midnight, previous
Day, % of total
********************************************
 
Protocol Decode              47.64%        
Unauthorized Access Attempt  37.06%        
Denial Of Service            06.96%        
Suspicious Activity          05.39%       
Pre-Attack Probe             02.94%        
Back Door                    00.01%     

********************************************
TOP TEN ATTACK DESTINATION PORTS - global IDS,
midnight - midnight,
previous day, % of top ten (ports found at) 
http://www.networkice.com/Advice/Exploits/Ports/de
fault.htm 
********************************************

80       (http)              74.16%       
161      (SNMP)              12.87%        
162      (SNMPTrap)          03.63%         
23       (telnet)            02.23%         
25       (smtp)              01.88%        
21       (ftp)               01.53%         
22       (ssh)               01.18%         
1500     (vlsi-lm)           01.06%         
139      (NetBIOS)           00.89%         
113      (identd/auth)       00.58%  

********************************************
BACKGROUND, COPYRIGHT NOTICE, and DISCLAIMER 
********************************************

Background. We provide this information in the
spirit of PDD 63 to help security professionals
wage the war against Internet threats more
effectively. Information in this update derived
primarily from global, real time, 24 x 7 IDS
feeds, ISS X-Force R&D Team research, and
professional liaison. Other sources as noted.
AlertCon 1 reflects the global, malicious,
determined, 24 x 7 attacks experienced by all
networks. AlertCon 2 means increased
vigilance/action recommended due to a specific
threat or concern. AlertCon 3 means increased
attacks against specific targets or
vulnerabilities on a scale that is unusually
high, action required. AlertCon 4 reflects an
Internet emergency for a target or group of
targets whose business continuity may depend on
some sort of immediate, decisive action. All
summaries cover 24 hours the previous workday,
GMT. Monday summaries may cover some weekend
activity. 

Copyright 2001 Internet Security Systems, Inc.
Permission is granted for the redistribution of
the Internet Threat Update electronically.
It is not to be sold or edited in any way without
express consent of
ISS. Refer comments or questions to:
[EMAIL PROTECTED] or [EMAIL PROTECTED] 

Disclaimer: This information is subject to change
without notice. Use of this information
constitutes acceptance for use in an 'as is'
condition. There are no warranties with regard to
this information. In no event shall the author be
liable for any damages whatsoever arising out of
or in connection with the use or spread of this
information. Any use of this information is at
the user's own risk. No other use authorized.
FOIA Exemption 4.

You can download the public key from MIT's PGP
key server and PGP.com's key server.

Patrick Gray
Manager, X-Force
Internet Threat Intelligence Center
Internet Security Systems
6303 Barfield Road
Atlanta, GA 30328

-----BEGIN PGP SIGNATURE-----
Version: PGP 7.0.4

iQA/AwUBPJX9ipG41ROSQPncEQLW4wCfUDMuB9fDVHcboy1M3ZKCko4YdBgAoMGr
QzDzTPIvhuGBCKVs6RZSuDln
=lkUZ
-----END PGP SIGNATURE-----


Reply via email to