By Jack M. Germain TechNewsWorld Part of the ECT News Network
04/19/04 7:56 AM PT
Mikko Hyppönen, director of antivirus research at F-Secure in Finland, told TechNewsWorld in an e-mail interview on Saturday that there is cause for alarm. He said he expects something bigger than just a denial-of-service (DOS) attack. "There's lots of activity going around right now as the bad boys have dozens of juicy fresh security vulnerabilities to choose from," Hyppönen noted.
An increase in suspicious activity this weekend has Internet security experts bracing for what some analysts warn could be the next big worm attack worldwide. Virus monitors spent the weekend watching an increased level of activity that experts said could be the start of a Blaster-like attack.
A spokesperson for VeriSign (Nasdaq: VRSN) engineers told TechNewsWorld late Friday that new exploits are possible for the ASN.1 and LSASS buffer overflow vulnerability in Windows machines.
"At this point, we can report that we are seeing a statistical deviation in normal traffic patters, and we have identified multiple exploits in the wild," Charles Kaplan, Information Security Officer for the MSS division at VeriSign, told TechNewsWorld. "Although these exploits have not materialized into a worm, with the information we have today, an attack early next week is likely."
Mikko Hyppönen, director of antivirus research at F-Secure in Finland, told TechNewsWorld in an e-mail interview on Saturday that there is cause for alarm. He said he expects something bigger than just a denial-of-service (DOS) attack.
"There's lots of activity going around right now as the bad boys have dozens of juicy fresh security vulnerabilities to choose from," Hyppönen told TechNewsWorld. "So we're seeing a lot of probing for various SSL-RPC ports. However, so far we've seen nothing that there would actually be something more organized happening right now or any signs of a new worm.
"I would expect to see a Blaster-like RPC worm within the next two to three weeks, though," Hyppönen warned.
Two Vulnerabilities Revealed
Kaplan said VeriSign's engineers identified two different vulnerabilities. One involves the Secure Sockets Layer (SSL), a critical technology designed to secure most Web and many e-mail transactions. The other involves the remote procedure call (RPC) protocol, which allows heterogeneous systems to communicate with one another.
VeriSign's engineers also noted a statistically significant increase in traffic on port 443 across the company's customer base. Port 443 is a common SSL service port.
"It would appear as if we are bearing witness to a broad-reaching reconnaissance scan to discover open SSL servers, followed by targeted denial-of-service attacks against some of those servers," Kaplan told TechNewsWorld.
He said the other traffic anomaly VeriSign began noticing Friday was an increase in port 1025 traffic. That activity is causing concerns because port 1025 is known to be used by Windows 2000 and Windows XP for RPC services.
Microsoft (Nasdaq: MSFT) released a new security patch last Tuesday for a new RPC vulnerability.
According to Internet security experts, Kaplan said, the activity surrounding port 1025 is particularly worrisome because many older firewalls have port 1025 exposed to the Internet. Those older devices often rely on packet-filtering technology only. That weakness can leave systems connected to them vulnerable to attack.
Preparing for the Vulnerability Now
Kaplan said engineers have not yet seen an actual new exploit of the ASN.1 and the LSASS Microsoft Windows vulnerabilities or evidence of such an exploit's use. But he added that VeriSign is preparing its engineers and clients for it now.
"While we can never predict with true certainty the next big Slammer or Blaster, our statistical traffic modeling surrounding the past week's traffic has all the telltale markers of a big worm coming," he said.
By late Friday, activity on the 443 port, an SSL port, had "gone through the roof," Kaplan said, adding that the report confirms the company's expectations that this is an issue requiring substantial attention.
"It looks as though it is a one-packet attack, which can be caught in the intrusion detection system, but it is critical that companies patch or they can get knocked offline," he said.
BlackIce Device Targeted
In what could be a related event, the Internet Storm Center this weekend issued its own alert about a possible worm attack having started against BlackIce firewall devices -- the second such attack on this software in three weeks.
According to the alert, the center said it detected an upsurge in User Datagram Protocol (UDP) traffic from source port 4000 early Saturday morning. The alert identified the cause of this traffic as a new variant of the Witty worm. It said the worm exploits a vulnerability in BlackIce's ICQ parser.
A bulletin posted this weekend on the center's Web site said infected hosts will send large amounts of UDP traffic, typically saturating a local network connection. As a result, users will not be able to shut down BlackIce. Instead, users will see a message that reads: "Operation could not be completed. Access is denied."
The bulletin, which said infected systems will crash as a result of corrupted hard disks, warned that the worm will not write itself to disk, causing virus scanners to fail to detect it.
Average PC Plagued with Spyware April 16, 2004
"When Internet users have questions about spyware, we want them to turn to the SpyAudit report as a reliable source of current information about this growing threat to Internet privacy," said Matt Cobb, EarthLink's vice president of core applications.
Related Stories
Microsoft Issues New Round of 'Critical' Patches April 14, 2004
"When eight of 20 are what they thought to classify as critical, it's pretty significant," Michael Sutton, director of iDefense Labs, told TechNewsWorld. "Critical means they're remotely exploitable, and they also emphasize that a critical one is something that could be taken advantage of through malicious code, which has been a problem for Microsoft for a long time."
Browser-Based Attacks on the Rise April 13, 2004
"The explosion of dynamic, created-on-the-fly Web pages, which often incorporate individual personal preferences, is exposing organizations' IT systems to new security threats," John Venator, president and CEO of CompTIA, said.
Mac OS X Attacked by Trojan Horse April 09, 2004
Forrester analyst Jan Sundgren told TechNewsWorld that with far fewer vulnerabilities and viruses than Windows, Mac users could be in danger with their guard down. However, Sundgren downplayed the threat of MP3Virus.Gen, adding that Mac OS X is not nearly as popular of a target for attackers who are looking to get an "explosive outbreak."
Sites Brace for Netsky-Q Onslaught April 08, 2004
While some versions of the worm contain a message saying the malware's authors oppose file-sharing, they also claim to be against hacking and virus-writing, undermining the credibility of those messages.
In the Trenches with Antivirus Guru Mikko Hypponen April 07, 2004
"All reverse engineers and virus crackers are here in my team, which works from our headquarters in Helsinki," F-Secure's Mikko Hypponen told the E-Commerce Times. "Right now we have people from Finland, Hungary, Spain, Bulgaria and Russia. Everybody has their own area of expertise, such as Windows binary analysis, scripts and macro code, Linux stuff, mobile phone and PDA expertise, et cetera."
Related News Alerts
More by Jack M. Germain
Microsoft FOSSifies .Net Micro Framework November 18, 2009
Microsoft has declared its .Net Micro framework open source under the Apace 2.0 license. Not all bits of .Net Micro are covered, however. Its TCP/IP stack has been stripped, as has its cryptography libraries. Rights to the TCP/IP stack aren't Redmond's to give, and the cryptography libraries are used outside of the scope of the .Net Micro framework, according to the company.
New Ubuntu OS Features Create Good Karma November 13, 2009
Amidst the OS upgrades from Apple and Microsoft over the last few months, the Linux OS Ubuntu got a version bump of its own. Ubuntu 9.10, or Karmic Koala, is well worth the effort to upgrade, and its developers have made the process easier -- if you're using the full-sized desktop/notebook version. The Remix version, intended for netbooks, caused quite a few headaches.
Samsung Chimes In With Bada Mobile OS November 11, 2009
With Android, iPhone, BlackBerry, WinMo, Symbian, WebOS and plenty other mobile platforms fighting for space, is there room for one more? Samsung believes there is, and it's announced a new open mobile platform called "Bada." The company, which already makes handsets for several existing platforms, says Bada will make app-making easy for developers. The first Bada handset should be out in the first half of 2010.