Saturday, January 28, 2006

W32.Blackmal.E@mm

Discovered: January 17, 2006
Updated: February 13, 2007 12:50:39 PM
Also Known As: CME-24, Win32.Blackmal.F [Computer Ass, Email-Worm.Win32.Nyxem.e [F-Se, Email-Worm.Win32.Nyxem.e [Kasp, W32/MyWife.d@MM [McAfee], W32/MyWife.d@MM!M24 [McAfee], Win32/Mywife.E@mm [Microsoft], W32/Small.KI@mm [Norman], Tearec.A [Panda Software], W32/Nyxem-D [Sophos], WORM_GREW.{A, B} [Trend Micro]
Type: Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP


W32.Blackmal.E@mm is a mass-mailing worm that attempts to spread through network shares and lower security settings. On the third day of every month it attempts to rewrite files with certain extensions with custom text.



High level detection - Here are some symptoms that may help determine the presence of W32.Blackmal.E@mm.
Uses its own SMTP engine to send an email with a copy of itself as an attachment.

Look for non-mail server machines sending port 25 traffic

Enumerates the computers in the same domain as the host computer by using WNetOpenEnum. The worm then executes the command "net use \\[COMPUTER NAME] /user:administrator """ to connect to that computer. However, if the user on the compromised computer is already connected to some other network computer, the worm will be able to use that connection.

Look for locked user accounts due to brute password attacks

Attempts to access the following URL: [http://]webstats.web.rcn.net/[REMOVED]/Count.cgi?df=765247

Look for any computer that accessed this website. Isolate and use the repair tool or scan with updated defs

Labels: ,

Thursday, January 12, 2006

execution of arbitrary code when the Microsoft Execution of arbitrary code on Microsoft Exchange Server

From: NGSSoftware Insight Security Research (mark at ngssoftware . com)
Date: Tue Jan 10 2006 - 16:49:03 CST
John Heasman and Mark Litchfield of NGSSoftware have discovered a critical vulnerability affecting Microsoft Exchange. The vulnerable versions include:

Microsoft Exchange Server 5.0 Service Pack 2
Microsoft Exchange Server 5.5 Service Pack 4
Microsoft Exchange 2000 Server Pack 3 with the Post-Service Pack 3 Update Rollup of August 2004

Microsoft Exchange Server 2003 Service Pack 1 and Microsoft Exchange Server 2003 Service Pack 2 are *not* affected.


The vulnerability potentially allows execution of arbitrary code when the Microsoft Exchange Server Information Store processes a specially crafted email message.


The flaw has now been addressed and patches are available from:
http://www.microsoft.com/technet/security/Bulletin/MS06-003.mspx


NGSSoftware are going to withhold details of this flaw for three months. Full details will be published on the 10th April 2006. This three month window will allow system administrators the time needed to obtain the patch before the details are released to the general public. This reflects NGSSoftware's approach to responsible disclosure.

http://www.ngssoftware.com/disclosure.pdf


NGSSoftware Insight Security Research
http://www.ngssoftware.com
http://www.databasesecurity.com/
http://www.nextgenss.com/
+44(0)208 401 0070

Mark Litchfield
www.ngssoftware.com
Tel: +44 208 40 100 70
Fax: +44 208 40 100 76
Cell: +1 253 414 4749

Labels: , , ,