Welcome | Sign In
LinuxInsider.com
Security

VeriSign Reports Massive Worm in the Works

Print Version
E-Mail Article
Reprints
VeriSign Reports Massive Worm in the Works

Mikko Hyppönen, director of antivirus research at F-Secure in Finland, told TechNewsWorld in an e-mail interview on Saturday that there is cause for alarm. He said he expects something bigger than just a denial-of-service (DOS) attack. "There's lots of activity going around right now as the bad boys have dozens of juicy fresh security vulnerabilities to choose from," Hyppönen noted.


An increase in suspicious activity this weekend has Internet security experts bracing for what some analysts warn could be the next big worm attack worldwide. Virus monitors spent the weekend watching an increased level of activity that experts said could be the start of a Blaster-like attack.

A spokesperson for VeriSign (Nasdaq: VRSN) engineers told TechNewsWorld late Friday that new exploits are possible for the ASN.1 and LSASS buffer overflow vulnerability in Windows machines.

"At this point, we can report that we are seeing a statistical deviation in normal traffic patters, and we have identified multiple exploits in the wild," Charles Kaplan, Information Security Officer for the MSS division at VeriSign, told TechNewsWorld. "Although these exploits have not materialized into a worm, with the information we have today, an attack early next week is likely."

Mikko Hyppönen, director of antivirus research at F-Secure in Finland, told TechNewsWorld in an e-mail interview on Saturday that there is cause for alarm. He said he expects something bigger than just a denial-of-service (DOS) attack.

"There's lots of activity going around right now as the bad boys have dozens of juicy fresh security vulnerabilities to choose from," Hyppönen told TechNewsWorld. "So we're seeing a lot of probing for various SSL-RPC ports. However, so far we've seen nothing that there would actually be something more organized happening right now or any signs of a new worm.

"I would expect to see a Blaster-like RPC worm within the next two to three weeks, though," Hyppönen warned.

Two Vulnerabilities Revealed

Kaplan said VeriSign's engineers identified two different vulnerabilities. One involves the Secure Sockets Layer (SSL), a critical technology designed to secure most Web and many e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse transactions. The other involves the remote procedure call (RPC) protocol, which allows heterogeneous systems to communicate with one another.

VeriSign's engineers also noted a statistically significant increase in traffic on port 443 across the company's customer base. Port 443 is a common SSL service port.

"It would appear as if we are bearing witness to a broad-reaching reconnaissance scan to discover open SSL servers, followed by targeted denial-of-service attacks against some of those servers," Kaplan told TechNewsWorld.

He said the other traffic anomaly VeriSign began noticing Friday was an increase in port 1025 traffic. That activity is causing concerns because port 1025 is known to be used by Windows 2000 and Windows XP for RPC services.

Microsoft (Nasdaq: MSFT) released a new security patch last Tuesday for a new RPC vulnerability.

According to Internet security experts, Kaplan said, the activity surrounding port 1025 is particularly worrisome because many older firewalls have port 1025 exposed to the Internet. Those older devices often rely on packet-filtering technology only. That weakness can leave systems connected to them vulnerable to attack.

Preparing for the Vulnerability Now

Kaplan said engineers have not yet seen an actual new exploit of the ASN.1 and the LSASS Microsoft Windows vulnerabilities or evidence of such an exploit's use. But he added that VeriSign is preparing its engineers and clients for it now.

"While we can never predict with true certainty the next big Slammer or Blaster, our statistical traffic modeling surrounding the past week's traffic has all the telltale markers of a big worm coming," he said.

By late Friday, activity on the 443 port, an SSL port, had "gone through the roof," Kaplan said, adding that the report confirms the company's expectations that this is an issue requiring substantial attention.

"It looks as though it is a one-packet attack, which can be caught in the intrusion detection system, but it is critical that companies patch or they can get knocked offline," he said.

BlackIce Device Targeted

In what could be a related event, the Internet Storm Center this weekend issued its own alert about a possible worm attack having started against BlackIce firewall devices -- the second such attack on this software in three weeks.

According to the alert, the center said it detected an upsurge in User Datagram Protocol (UDP) traffic from source port 4000 early Saturday morning. The alert identified the cause of this traffic as a new variant of the Witty worm. It said the worm exploits a vulnerability in BlackIce's ICQ parser.

A bulletin posted this weekend on the center's Web site said infected hosts will send large amounts of UDP traffic, typically saturating a local network connection. As a result, users will not be able to shut down BlackIce. Instead, users will see a message that reads: "Operation could not be completed. Access is denied."

The bulletin, which said infected systems will crash as a result of corrupted hard disks, warned that the worm will not write itself to disk, causing virus scanners to fail to detect it.


Print Version E-Mail Article Reprints More by Jack M. Germain


More by Jack M. Germain

Microsoft FOSSifies .Net Micro Framework
November 18, 2009
Microsoft has declared its .Net Micro framework open source under the Apace 2.0 license. Not all bits of .Net Micro are covered, however. Its TCP/IP stack has been stripped, as has its cryptography libraries. Rights to the TCP/IP stack aren't Redmond's to give, and the cryptography libraries are used outside of the scope of the .Net Micro framework, according to the company.
New Ubuntu OS Features Create Good Karma
November 13, 2009
Amidst the OS upgrades from Apple and Microsoft over the last few months, the Linux OS Ubuntu got a version bump of its own. Ubuntu 9.10, or Karmic Koala, is well worth the effort to upgrade, and its developers have made the process easier -- if you're using the full-sized desktop/notebook version. The Remix version, intended for netbooks, caused quite a few headaches.
Samsung Chimes In With Bada Mobile OS
November 11, 2009
With Android, iPhone, BlackBerry, WinMo, Symbian, WebOS and plenty other mobile platforms fighting for space, is there room for one more? Samsung believes there is, and it's announced a new open mobile platform called "Bada." The company, which already makes handsets for several existing platforms, says Bada will make app-making easy for developers. The first Bada handset should be out in the first half of 2010.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network