Atenção, validar o patch - MS08-067 RPC vulnerability

Num mundo de vírus, spyware e bugs nada como estar informado

Moderadores: Administradores, Moderadores

Atenção, validar o patch - MS08-067 RPC vulnerability

Mensagempor alr_tech » Terça Out 28, 2008 10:01

boas

a ter em atenção.
Desculpem pela não tradução.
SearchSecurity.com Escreveu:Trojan exploiting MS08-067 RPC vulnerability
October 24th, 2008 by Dennis Fisher

There are reports emerging Friday morning of a new Trojan exploiting the MS08-067 RPC vulnerability in Windows that Microsoft patched with an emergency fix yesterday. Known as Gimmiv.A, the Trojan propagates automatically through networks, and also installs a number of small programs on compromised machines. But its most worrisome capability is a feature that enables Gimmiv.A to find cached passwords in a number of locations and then send them off to a remote server. Before sending the data, the Trojan encrypts the passwords with AES encryption.

From the ThreatExpert description of Gimmiv.A:

It starts from probing other IPs from the same network by sending them a sequence of bytes “abcde” or “12345″. The worm then attempts to exploit other machines by sending them a malformed RPC request and relying on a vulnerable Server service. As known, Server service uses a named pipe SRVSVC as its RPC interface, which is registered with UUID equal to 4b324fc8-1670-01d3-1278-5a47bf6ee188.

Next, Gimmiv.A submits a maliciously crafted RPC request that instructs SRVSVC to canonicalize a path “\c\..\..\AAAAAAAAAAAAAAAAAAAAAAAAAAAAA” by calling the vulnerable RPC request NetPathCanonicalize.

Microsoft had some information about Gimmiv.A in its description of the new vulnerability yesterday, saying that the company had added signatures for the Trojan to the Microsoft Malware Protection Center and had shared the information with its AV partners as well.
The analysts at F-Secure have a good description of the Trojan’s behavior tool:

On execution, the malware drops a DLL component ( which is also detected as Trojan-Spy:W32/Gimmiv.A ) as

* [System Folder]\wbem\sysmgr.dll

and injects it to svchost.exe. The main executable file will then delete itself.

As part of its routine for connecting to a remote server, the trojan will take into account both the operating system version and the presence of any security applications in the system. The trojan checks for the following antivirus programs:

* BitDefender
* avp.exe
* Jiangmin
* KasperskyLab
* Kingsoft
* Symantec
* OneCare Protection
* Rising
* TrendMicro
* dwm.exe

The trojan then connects to:

* http://59.106.145.58/[…].php?abc=1?def=2

The two parameters ‘abc=’ and ‘def=’ are determined by the antivirus program and the operating system version, respectively. For example, if avp.exe is installed on an infected machine that runs Windows XP, then abc=1 and def=2.

The trojan then harvests the following information from the infected machine:

* MSN Credentials
* Outlook Express Credentials
* Protected Storage Information
* Username
* ComputerName
* Patches Installed
* Browser Information
* Username (web browsing)
* Password
* URL

Microsoft said in its advisory Thursday that the MS08-067 vulnerability could be a target for a worm, and other security experts warned of the possibility as well. Gimmiv.A does not seem to be a major threat right now, but these things have a way of gathering steam quickly once they get going.

Posted: October 24th, 2008 under Microsoft Security, Information Security Threats.

cumps
AMD XP 2400+, ASUS A7N8X-E Deluxe
1 Gb DDR 400, Seagate 80 GB ATA + 120 Gb ATA, ATI 9600 XT
alr_tech
Gurus
Gurus
 
Mensagens: 6768
Registado: Quinta Fev 17, 2005 18:01
Localização: Lisboa

Mensagempor PsicoPete » Terça Out 28, 2008 12:25

Que fazer então para ver se estamos seguros?
Verificar (e eventualmente proibir) no router ligações para aquele endereço? Que mais?

Cumps.
Imagem
"Some men see things as they are and say why - I dream things that never were and say why not." - George Bernard Shaw
PsicoPete
Membro Vitalício
Membro Vitalício
 
Mensagens: 2389
Registado: Sábado Ago 14, 2004 12:22

Mensagempor alr_tech » Terça Out 28, 2008 12:54

boas

aplicar o patch é claro..
o malandro só funca se não estiver o patch aplicado... (pelo menos é o que a Ms diz ;) )

o problema é que o dito, com o tempo, poderá ser refinado e tornar-se perigoso..

sém dúvida que se deverão tb ter uma firewall como deve ser...
eu sei que são chatas...

acho que a maioria dos antivirus está a ser updatado...

é só um aviso, para o pessoal avaliar os sistemas se aparecer alguma msg esquisita....

cumps
AMD XP 2400+, ASUS A7N8X-E Deluxe
1 Gb DDR 400, Seagate 80 GB ATA + 120 Gb ATA, ATI 9600 XT
alr_tech
Gurus
Gurus
 
Mensagens: 6768
Registado: Quinta Fev 17, 2005 18:01
Localização: Lisboa

Mensagempor PsicoPete » Terça Out 28, 2008 12:59

Ok, my bad, eu é que percebi mal.
Percebi que esse patch que a Ms lançou é que tinha a vulnerabilidade quando este patch é para corrigir essa vulnerabilidade.

É o que dá ler à pressa.

Cumps.
Imagem
"Some men see things as they are and say why - I dream things that never were and say why not." - George Bernard Shaw
PsicoPete
Membro Vitalício
Membro Vitalício
 
Mensagens: 2389
Registado: Sábado Ago 14, 2004 12:22

Mensagempor alr_tech » Terça Out 28, 2008 13:16

boas

eu sei...
mas, até agora ainda não foram detectados problemas com os patch da última terça feira....

se existirem publicarei aqui...

cumps
AMD XP 2400+, ASUS A7N8X-E Deluxe
1 Gb DDR 400, Seagate 80 GB ATA + 120 Gb ATA, ATI 9600 XT
alr_tech
Gurus
Gurus
 
Mensagens: 6768
Registado: Quinta Fev 17, 2005 18:01
Localização: Lisboa


Voltar para Segurança Informática

Quem está ligado:

Utilizador a ver este Fórum: Nenhum utilizador registado e 1 visitante

cron