phpbb and sql errors

Today´s Diary

If you have more information or corrections regarding our diary, click here to contact us.

Published: 2008-12-04,
Last Updated: 2008-12-04 17:41:34 UTC
by Bojan Zdrnja (Version: 1)
0 comment(s)

Fellow researchers from Symantec posted technical details about an interesting variant of a well known DNSChanger malware. The analysis is available at http://www.symantec.com/security_response/writeup.jsp?docid=2008-120318-5914-99&tabid=1

The DNSChanger malware has been in the wild for quite some time and already drew our attention previously when authors started attacking popular ADSL modems. As the name says, the malware changed DNS server settings, typically to servers in the "popular" 85.255 network. We published several diaries about this malware, the most recent one from Andre is available at http://isc.sans.org/diary.html?storyid=5390.

The evolution went from changing local DNS servers in the operating system (for both Windows and Mac!) to changing DNS server settings in ADSL modems/routers/cable modems.

The malware described by Symantec goes a step further – it installs a rogue DHCP server on the network. Besides the post by Symantec, we also got notified of this malware two days ago by our reader Tim, so we can confirm that this malware is in the wild.

What does it do? The malware installs a legitimate driver, NDISProt which allows it to send and receive raw Ethernet frames. Once the driver is installed, the malware "simulates" a DHCP server. It starts monitoring network traffic and when it sees a DHCP discover packet it replies with its own DHCP Offer packet. As you can guess, the offered DHCP lease will contain malicious DNS servers, as shown below:



While not too sophisticated, the whole attack is very interesting. First, it's about a race between the rogue DHCP server and the legitimate one. Second, once a machine has been poisoned it is impossible to detect how it actually got poisoned in the first place – you will have to analyze network traffic to see the MAC address of those DHCP Offer packets to find out where the infected machine actually is.

As we wrote numerous times before, it's probably wise to at least monitor traffic to 85.255.112.0 – 85.255.127.255, if not block it.

--
Bojan
 

Keywords: dns malware
0 comment(s)
Published: 2008-12-04,
Last Updated: 2008-12-04 17:04:59 UTC
by Bojan Zdrnja (Version: 2)
0 comment(s)

We got notified by couple of readers that Finjan's appliance started blocking access to isc.sans.org due to detected malicious behavior, whichi s a false positive. The URL analysis tool on the Finjan's web site confirms that this is indeed happening.

We notified Finjan and this should be fixed as soon as possible. In the mean time, you can put isc.sans.org on the white list so you can continue visiting us.

UPDATE

This has been fixed, thanks to fast support from Finjan.
--
Bojan
 

Keywords: false positive
0 comment(s)

If you have more information or corrections regarding our diary, click here to contact us.

Diary Archive

DateAuthorTitle
2008-12-04Bojan Zdrnja Finjan blocking access to isc.sans.org
2008-12-04Bojan Zdrnja Rogue DHCP servers
2008-12-03Stephen Hall Sun Java 6.0 Update 11 is now available
2008-12-03Stephen Hall VMware security advisories
2008-12-03Andre L. New ISC Poll! Has your organization suffered a DDoS (Distributed Denial of Service) attack in the last year?
2008-12-02Deborah Hale Sonicwall License Manager Failure
2008-12-01Jason Lam Input filtering and escaping in SQL injection mitigation
2008-11-29Pedro Bueno Possible Mumbai Scams?
2008-11-29Pedro Bueno Ubuntu users: Time to update!
2008-11-26Patrick Nolan MS - new malware using an ms08-067 exploit gained momentum
Complete Archive
Search Diaries:

Featured Event

Latest Reading Room Papers

Document Metadata, the Silent Killer...
Data carving Concepts
IOSMap: TCP and UDP Port Scanning on Cisco IOS Platforms
Mining for Malware - There's Gold in Them Thar Proxy Logs!
.NET Framework Rootkits: Backdoors inside your Framework

Poll

Has your organization suffered a DDoS (Distributed Denial of Service) attack in the last year?
No, we have not been attacked in the last year.
Yes, we have been attacked only once in the last year.
Yes, we have been attacked between 2-5 times in the last year.
Yes, we have been attacked between 6-10 times in the last year.
Yes, we have been attacked between 11-20 times in the last year.
Yes, we have been attacked between 21-30 times in the last year.
Yes, we have been attacked between 31- 40 times in the last year.
Yes, we have been attaked more then 40 times in the last year.
see results

Trends

trends more details

World Map

Worldmap