Newsletters: @RISK

Subscribe to SANS Newsletters

Join the SANS Community to receive the latest curated cyber security news, vulnerabilities and mitigations, training opportunities, and our webcast schedule.





SANS NewsBites
@Risk: Security Alert
OUCH! Security Awareness
Case Leads DFIR Digest
Industrial Control Systems
Industrials & Infrastructure


@RISK provides a reliable weekly summary of (1) newly discovered attack vectors, (2) vulnerabilities with active new exploits, (3) insightful explanations of how recent attacks worked, and other valuable data

A key purpose of the @RISK is to provide the data that will ensure that the 20 Critical Controls (the US and UK benchmark for effective protection of networked systems) continue to be the most effective defenses for all known attack vectors. But since it is also valuable for security practitioners, SANS is making it available to the 145,000 security practitioners who have completed SANS security training and others at their organizations who hope to stay current with the offensive methods in use.

October 31, 2013
=============================================================

@RISK: The Consensus Security Vulnerability Alert

Vol. 13, Num. 44

Providing a reliable, weekly summary of newly discovered attack vectors, vulnerabilities with active exploits, and explanations of how recent attacks worked.

=============================================================

CONTENTS:

NOTABLE RECENT SECURITY ISSUES
INTERESTING NEWS FROM AROUND THE SECURITY COMMUNITY
VULNERABILITIES FOR WHICH EXPLOITS ARE AVAILABLE
MOST PREVALENT MALWARE FILES 10/21/2013 - 10/25/2013
============================================================

TOP VULNERABILITY THIS WEEK: Magnitude Exploit Kit on the rise

******************** Sponsored By Symantec *********************

New Symantec Intelligence Report
This report provides the latest analysis of cyber security threats, trends, and insights from the Symantec Intelligence team concerning malware, spam, and other potentially harmful business risks. Learn more
http://www.sans.org/info/142355

============================================================

TRAINING UPDATE

--SANS Chicago 2013 Chicago, ILOctober 28-November 2, 2013
7 courses. Bonus evening presentations include SANS 8 Mobile Device Security Steps; and Privileged Domain Account Protection: How to Limit Credentials Exposure.
http://www.sans.org/event/chicago-2013

--South Florida 2013 Ft. Lauderdale, IL November 4-9, 2013 5 courses. Bonus evening presentations include The Security Impact of IPv6; Evolving Threats; and Real-World Risk - What Incident Responders Can leverage from IT Operations. http://www.sans.org/event/south-florida-2013

- --October Singapore 2013 Singapore, Singapore October 21-November 2, 2013
5 courses. Bonus evening presentations include Pen Testing the Smart Grid; and You Can Panic Now. Host Protection is (Mostly) Dead.
http://www.sans.org/event/singapore-sos-2013

- -- SANS Dubai 2013Dubai, UAEOctober 26th - November 7th 2013
SANS returns to Dubai with four essential courses at the Hilton Jumeirah Beach.
http://www.sans.org/event/dubai-2013

- -- SANS London 2013 London, UKNovember 16-25, 2013
17 courses. Bonus evening presentations include Real World Risk - What Incident Responders Can Leverage From IT Operations; Information Assurance Metrics: Practical Steps to Measurement; and APT: It Is Time To Act.
http://www.sans.org/event/london-2013

- -- Multi-week Live SANS training
http://www.sans.org/mentor/about
Contact mentor@sans.org

- -- Looking for training in your own community?
http://www.sans.org/community/

- --Save on On-Demand training (30 full courses) - See samples at
http://www.sans.org/ondemand/specials

Plus Johannesburg, Abu Dhabi, Seoul, and Bangalore all in the next 90 days.

For a list of all upcoming events, on-line and live: www.sans.org

********************** Sponsored Links: ********************

1) PCI DSS Simplified: What You Need to Know. Friday, November 01 at 1:00 PM EDT Sandy Hawke, VP, Product Marketing, AlienVault. http://www.sans.org/info/142360

2) Special Webcast: Finding Hidden Threats by Decrypting SSL/TLS. Friday, November 08 at 1:00 PM EST. J. Michael Butler, SANS Analyst, and Timothy Chiu, Blue Coat Systems. http://www.sans.org/info/142365

3) Special Webcast: "Reading the Security Tea Leaves" - The Story from 50 million Vulnerabilities: Thursday, November 07 at 12:00 PM EST. Matt Johansen, Threat Research Center Manager at WhiteHat Security Inc. & Ed Bellis, CoFounder, Risk I/O, Inc. http://www.sans.org/info/142370

============================================================
NOTABLE RECENT SECURITY ISSUES
SELECTED BY THE SOURCEFIRE VULNERABILITY RESEARCH TEAM

Title: Magnitude Exploit Kit on the rise
Description: The Sourcefire VRT monitors the activity of Exploit Kits throughout the day, and the activity of which exploit kit would be clamoring for the "top title" since the arrest of Blackhole/Cool Exploit Kits author 'paunch' has been interesting to watch. Sweet Orange Exploit Kit had a sharp rise right after the arrest, but as of the writing of this, Magnitude/PopAds seems to be the most active.
Magnitude is currently using ports
51423
44449
33300
and g01pack has been observed on port
15489

Reference:
http://vrt-blog.snort.org/2013/10/sweet-orange-exploit-kit-was-new-king.html
Snort SID: Multiple
ClamAV: Multiple

Title: EMC AlphaStor Device Manager Format String Vulnerability
Description: EMC AlphaStore uses a proprietary protocol to handle tape-backup tasks. It is vulnerable to a format string attack in five of the EMC NetWorker commands when a certain OpCode is used.
Reference:
http://www.osvdb.org/show/osvdb/89435
Snort SID: 28394-28398
ClamAV: N/A

Title: HP Intelligent Management Center BIMS UploadServlet Arbitrary File Upload
Description: An arbitrary file upload vulnerability exists in the HP Intelligent Management Center Branch Intelligent Management Software module.
Reference:
http://www.osvdb.org/show/osvdb/98247
Snort SID: 28407 ClamAV: N/A

============================================================
INTERESTING NEWS FROM AROUND THE SECURITY COMMUNITY

Meet 'Muscular': NSA accused of tapping links between Yahoo, Google datacenters
http://www.zdnet.com/meet-muscular-nsa-accused-of-tapping-links-between-yahoo-google-datacenters-7000022624/

A Malware Classification
http://blog.kaspersky.com/a-malware-classification/

Tech Support Scam Update: Still Flourishing, Still Evolving
http://www.welivesecurity.com/2013/10/29/tech-support-scam-update-still-flourishing-still-evolving/

Infection rates and end of support for Windows XP
http://blogs.technet.com/b/mmpc/archive/2013/10/29/infection-rates-and-end-of-support-for-windows-xp.aspx

Rent-A-Hacker
http://www.f-secure.com/weblog/archives/00002629.html

Legislation Unveiled to Bar NSA's Bulk Phone Metadata Collection
http://feeds.wired.com/c/35185/f/661467/s/330ec4d6/sc/1/l/0L0Swired0N0Cthreatlevel0C20A130C10A0Cusa0Efreedom0Eact0C/story01.htm

Researchers Detail Widespread iOS Application Vulnerability
http://www.tripwire.com/state-of-security/top-security-stories/researchers-detail-widespread-ios-app-vulnerability/

Obama Administration to Review NSA Capabilities
http://threatpost.com/obama-administration-to-review-nsa-capabilities/102730

Cutwail Spam Campaign Changes Tactics
http://www.allspammedup.com/2013/10/cutwail-spam-campaign-changes-tactics/

============================================================
RECENT VULNERABILITIES FOR WHICH EXPLOITS ARE AVAILABLE
COMPILED BY THE QUALYS VULNERABILITY RESEARCH TEAM.

This is a list of recent vulnerabilities for which exploits are available. System administrators can use this list to help in prioritization of their remediation activities. The Qualys Vulnerability Research Team compiles this information based on various exploit frameworks, exploit databases, exploit kits and monitoring of internet activity.

ID: CVE-2013-4822
Title: HP Intelligent Management Center BIMS UploadServlet Directory Traversal
Vendor: HP
Description: Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka BIMS) allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1606.

ID: CVE-2013-6021
Title: WatchGuard Firewall XTM 11.7.4u1 Remote Buffer Overflow
Vendor: WatchGuard
Description: Buffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code via a long sessionid value in a cookie.
CVSS v2 Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)

ID: Not Available
Title: D-Link Authentication Security Bypass Vulnerability
Vendor: D-Link
Description: A remote exploitation of a design error vulnerability in D-Link Systems Inc.'s routers could allow attackers to bypass authentication security restrictions. The router allows any user with a Web browser having the user agent string "xmlset_roodkcableoj28840ybtide" to gain access to the Web interface of the device without the requirement for any authentication credentials. Affects D-Link Firmware v1.13 and other versions may also be affected.
CVSS v2 Base Score: 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)

ID: CVE-2013-3897
Title: Microsoft Internet Explorer CDisplayPointer Use-After-Free (MS13-080)
Vendor: Microsoft
Description: Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka "Internet Explorer Memory Corruption Vulnerability."
CVSS v2 Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)

ID: CVE-2013-2251
Title: Apache Struts 2 DefaultActionMapper Prefixes OGNL Code Execution
Vendor: Apache
Description: Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
CVSS v2 Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)

=========================================================
MOST PREVALENT MALWARE FILES 10/21/2013 - 10/25/2013
COMPILED BY SOURCEFIRE

SHA 256: DAD74779542E84D9358B7F24CC21A831C2F63BAB4931C2DD2A4D561A24794AB6
MD5: b0709680a86bdd99f968752c9449b809
VirusTotal:
https://www.virustotal.com/en/file/DAD74779542E84D9358B7F24CC21A831C2F63BAB4931C2DD2A4D561A24794AB6/analysis/
Typical Filename: Bitguard.dll
Claimed Product: Bitguard.dll
Claimed Publisher: Bitguard.dll
Detection Name: W32.Variant:BProtector.16l1.1201

SHA 256: DF83A0D6940600E4C4954F4874FCD4DD73E781E6690C3BF56F51C95285484A3C
MD5: a2a4e91cdf63cfdd05592d355335bcaa
VirusTotal:
https://www.virustotal.com/en/file/6F2717BCC3428D7044C488976788695B60F1C3F9F29AA791DEAA31E21A3F049D/analysis/
Typical Filename: Random
Claimed Product: None
Claimed Publisher: None
Detection Name: Sality

SHA 256: 7BEB3EAED035809B9F9DC11ABBD8B33ADC534ED1F2AC80D096C57820330A6E80
MD5: 25aa9bb549ecc7bb6100f8d179452508
VirusTotal:
https://www.virustotal.com/en/file/DF83A0D6940600E4C4954F4874FCD4DD73E781E6690C3BF56F51C95285484A3C/analysis/
Typical Filename: Random
Claimed Product: None
Claimed Publisher: None
Detection Name: W32.Sality:StubOfSalityTrj.16g1

SHA 256: d14b66bd4c4c8f66a6edf2820fd4162d09b326beaf6a42014596571e81a1a503
MD5: 68b7f7a26b76805432e3d50009d2ab1f
VirusTotal:
https://www.virustotal.com/en/file/D14B66BD4C4C8F66A6EDF2820FD4162D09B326BEAF6A42014596571E81A1A503/analysis/
Typical Filename: W32.Agent:B.16lp.1201
Claimed Product: W32.Agent:B.16lp.1201
Claimed Publisher: W32.Agent:B.16lp.1201
Detection Name: W32.Agent:B.16lp.1201

SHA 256: AA0BBAECB678868E1E7F57C7CA9D61B608B3D788BE490790EB1D148BEADF4615
MD5: 3291e1603715c47a23b60a8bf2ca73db
VirusTotal:
https://www.virustotal.com/en/file/AA0BBAECB678868E1E7F57C7CA9D61B608B3D788BE490790EB1D148BEADF4615/analysis/
Typical Filename: Confiker
Claimed Product: None
Claimed Publisher: Nonebr
Detection Name: Confiker

=============================================================

(c) 2013. All rights reserved. The information contained in this newsletter, including any external links, is provided "AS IS," with no express or implied warranty, for informational purposes only.

Please feel free to share this with interested parties via email, but no posting is allowed on web sites. For a free subscription, (and for free posters) or to update a current subscription, visit https://www.sans.org/account