[jim@cyberjunkees.com: Re: FW: Worm probes]
Sorry for the lame cross-list fertilisation, but this seemed like
a nice comprehensive summary.
I'm getting hit by this big-time, here.
----- Forwarded message from Jim Olsen
I received this warning from TruSecure regarding the latest worm attack.
Mike Braun First American CREDCO
-----Original Message----- TruSecure ALERT- TSA 01-023 - W32.nimda.a.mm
Date: September 18, 2001 Time: 1000 EDT
RISK INDICES:
Initial Assessment: RED HOT
Threat: VERY HIGH, (rapidly increasing)
Vulnerability Prevalence: VERY HIGH, effects IIS servers version 4.0, 5.0, and internal networks.
Cost: High, command execution is possible
Vulnerable Systems: IIS 4.0 and 5.0
SUMMARY: A new IIS worm is spreading rapidly. Its working name is Nimda: W32.nimda.a.mm
It started about 9am eastern time today, Tuesday,September 18, 2001, Mulitple sensors world-wide run by TruSecure corporation are getting multiple hundred hits per hour. And began at 9:08am am.
The worm seems to be targeting IIS 4 and 5 boxes and tests boxes for multiple vulnerabilities including:
Almost all are get scripts, and a get msadc (cmd.exe) get_mem_bin vti_bin owssvr.dll Root.exe CMD.EXE ../ (Unicode) Getadmin.dll Default.IDA /Msoffice/ cltreq.asp
This is not code red or a code red variant.
The worm, like code red attempts to infect its local sub net first, then spreads beyond the local address space.
It is spreading very rapidly.
TruSecure believes that this worm will infect any IIS 4 and IIS 5 box with well known vulnerabilities. We believe that there are nearly 1Million such machines currently exposed to the Internet.
Risks Indices: Vulnerability VULNERABILITY PREVALANCE is very high - Milllions of Internet Web server hosts: TruSecure process and essential configurations should generally be protective. The vulnerability prevalence world-wide is very high
Threat - VERY HIGH and Growing The rate of growth and spread is exceedingly rapid - significantly faster than any worm to date and significantly faster than any variant of Code red.
Cost -- Unknown, probably moderate per infected system.
The worm itself is a file called README.EXE, or ADMIN.DLL a 56K file which is advertised as an audio xwave mime type file.
Other RISKS: There is risk of DOS of network segments by traffic volume alone There is large risk of successful attack to both Internet exposed IIS boxes and to developer and Intranet boxes inside of corporations.
Judging by the Code Red II experience, we expect many subtle routes of infection leading to inside corporate infections.
We cannot discount the coincidence of the date and time of release, exactly one week to (probably to the minute) as the World Trade Center attack .
REPLICATION: There are at least three mechanisms of spread: The worm seems to spread both by a direct IIS across Internet (IP spread) It probably also spreads by local shares. (this is not known for sure at this time) There is also an email vector where README.EXE is sent via email to numerous accounts.
Mitigations TruSecure essential practices should work. Block all email with EXE attachments Filter for README.EXE Make sure IIS boxes are well patched and hardened, or removed from both the Internet and Intranets. Make sure any developer computing platforms are not running IIS of any version (many do so by default if either. Disconnect mail from the Internet Advise users not to double click on any unexpected attachments. Update anti-virus when your vendor has the signature.
-----Original Message----- From: Bryan Heitman [mailto:bryanh(a)communitech.net] Sent: Tuesday, September 18, 2001 8:22 AM To: nanog(a)merit.edu Subject: Re: Worm probes
We're also seeing a large increase in this activity. This seems to be more severe than the first time. Have an additional 30 to 40 meg inbound from this.
Best regards,
Bryan Heitman CommuniTech.Net, Inc. ----- Original Message ----- From:
To: Sent: Tuesday, September 18, 2001 10:05 AM Subject: Re: Worm probes ugh...this is way more impact...a 128k ISDN customer running an NT/Win2k box is at 100% BW, and my 2x T1's are at about 2x normal traffic for this time of day, although still well short of capacity...apache server processor load is WAY up just from the requests, and the logs are growing like mad.
On Tue, 18 Sep 2001, deeann mikula wrote:
On Tue, 18 Sep 2001, ravi pina wrote:
On Tue, Sep 18, 2001 at 09:54:31AM -0400, sigma(a)pair.com said at one
point in time:
Has anyone else been seeing a dramatic increase in /scripts/.. NT
worm
probes this morning? We're seeing about 8000/second, starting
around 9:15
Eastern time, to and from a wide variety of addresses.
affirmative. i just looked at my logs, and it looks like each probe tries a bunch of things. i haven't seen much on the lists, but i'm looking right now.
i'm pretty sure that the worm's attack phase starts on the 20th (which of course, depends upon a correctly set system clock) and also that attempting to execute something like /scripts/root.ext/c++ something is involved.
i think that cert's website would be a good place to look. i'm *not* a security/virus chick, but i did host a talk by marty linder of cert where he discected code red's activity and presented a summary.
cert is of course, http://www.cert.org.
deeann m.m. mikula
director of operations telerama public access internet http://www.telerama.com 1.877.688.3200
James Smallacombe PlantageNet, Inc. CEO and Janitor up(a)3.am http://3.am =========================================================================
"MMS
" made the following annotations on 09/18/01 08:34:15 --------------------------------------------------------------------------- --- "THIS E-MAIL MESSAGE AND ANY FILES TRANSMITTED HEREWITH, ARE INTENDED SOLELY FOR THE USE OF THE INDIVIDUAL(S) ADDRESSED AND MAY CONTAIN CONFIDENTIAL, PROPRIETARY OR PRIVILEGED INFORMATION. IF YOU ARE NOT THE ADDRESSEE INDICATED IN THIS MESSAGE (OR RESPONSIBLE FOR DELIVERY OF THIS MESSAGE TO SUCH PERSON) YOU MAY NOT REVIEW, USE, DISCLOSE OR DISTRIBUTE THIS MESSAGE OR ANY FILES TRANSMITTED HEREWITH. IF YOU RECEIVE THIS MESSAGE IN ERROR, PLEASE CONTACT THE SENDER BY REPLY E-MAIL AND DELETE THIS MESSAGE AND ALL COPIES OF IT FROM YOUR SYSTEM." =========================================================================== ===
-- "Computer games don't affect kids, I mean if Pacman affected us as kids, we'd all be running around in darkened rooms, munching pills, and listening to repetitive music." ~unknown **** Jim Olsen Systems Administrator CyberJunkees **** ----- End forwarded message ----- --------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
Would it manifest itself something like this in the logs? 03.79.72.4 - - [19/Sep/2001:07:01:31 +1200] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 288 "-" "-" 203.79.72.4 - - [19/Sep/2001:07:01:40 +1200] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 286 "-" "-" 203.79.72.4 - - [19/Sep/2001:07:01:49 +1200] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 296 "-" "-" 203.79.72.4 - - [19/Sep/2001:07:01:58 +1200] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 296 "-" "-" 203.234.139.253 - - [19/Sep/2001:07:13:35 +1200] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 288 "-" "-" 203.234.139.253 - - [19/Sep/2001:07:13:36 +1200] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 286 "-" "-" 203.234.139.253 - - [19/Sep/2001:07:13:37 +1200] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 296 "-" "-" 203.234.139.253 - - [19/Sep/2001:07:13:41 +1200] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 296 "-" "-" 203.234.139.253 - - [19/Sep/2001:07:13:42 +1200] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 310 " -" "-" 203.234.139.253 - - [19/Sep/2001:07:13:45 +1200] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+di r HTTP/1.0" 404 327 "-" "-" 203.234.139.253 - - [19/Sep/2001:07:13:46 +1200] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+di r HTTP/1.0" 404 327 "-" "-" 203.234.139.253 - - [19/Sep/2001:07:13:47 +1200] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../ winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 343 "-" "-" 203.234.139.253 - - [19/Sep/2001:07:13:48 +1200] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 309 "-" "-" 203.234.139.253 - - [19/Sep/2001:07:13:49 +1200] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 309 "-" "-" 203.234.139.253 - - [19/Sep/2001:07:13:58 +1200] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 309 "-" "-" 203.234.139.253 - - [19/Sep/2001:07:13:59 +1200] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 309 "-" "-" 203.234.139.253 - - [19/Sep/2001:07:14:00 +1200] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 293 "-" "-" 203.234.139.253 - - [19/Sep/2001:07:14:10 +1200] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 293 " -" "-" 203.234.139.253 - - [19/Sep/2001:07:14:18 +1200] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3 10 "-" "-" 203.234.139.253 - - [19/Sep/2001:07:14:22 +1200] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 310 " -" "-" 203.248.108.135 - - [19/Sep/2001:07:15:07 +1200] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 288 "-" "-" -- Juha :: -----Original Message----- :: From: owner-nznog(a)list.waikato.ac.nz :: [mailto:owner-nznog(a)list.waikato.ac.nz] On Behalf Of Joe Abley :: Sent: Wednesday, 19 September 2001 07:15 :: To: nznog(a)list.waikato.ac.nz :: Subject: [jim(a)cyberjunkees.com: Re: FW: Worm probes] :: :: :: Sorry for the lame cross-list fertilisation, but this seemed like :: a nice comprehensive summary. :: :: I'm getting hit by this big-time, here. --------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
On Wed, Sep 19, 2001 at 07:22:18AM +1200, Juha Saarinen wrote:
Would it manifest itself something like this in the logs?
03.79.72.4 - - [19/Sep/2001:07:01:31 +1200] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 288 "-" "-" 203.79.72.4 - - [19/Sep/2001:07:01:40 +1200] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 286 "-" "-"
Apparently so. About four times per second, apparently. Does wonders for a V.34 connection's performance, let me tell you. Joe --------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
:: Apparently so. About four times per second, apparently. Does :: wonders for a V.34 connection's performance, let me tell you. And now the 78KB emails are starting to roll in... groan... my ADSL bill will explode. (Telecom employees: please wipe that sick grin off your faces...). -- Juha --------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
On 18 Sep 2001 at 15:15, Joe Abley wrote:
Sorry for the lame cross-list fertilisation, but this seemed like a nice comprehensive summary.
I'm getting hit by this big-time, here.
This big: http://www.freebsddiary.org/stats-nimda/ stats should be updated every 15 minutes -- Dan Langille - DVL Software Limited The FreeBSD Diary - http://freebsddiary.org/ - practical examples --------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
participants (3)
-
Dan Langille
-
Joe Abley
-
Juha Saarinen