June 25, 2004

Experts agree on method, not scope of IIS attacks

Accounts of impact vary

At gift basket supplier Young's Inc. in Dundee, Michigan, network administrators first became aware of the new threat on Thursday morning, when employees, including the chief executive officer of the company, received warnings about Trojan programs when they tried to load the company's Intranet Web page, said Ron Guyor, a systems administrator at Young's.

The company uses IIS Version 5.0 with SSL and had not applied the April patch, which Guyor believes was the opening hackers used to compromise his Web server. After shutting down IIS, Guyor used searches for recently updated files in IIS and information from online system administrator news groups to locate and remove the malicious files installed by hackers, he said.

While he is confident that desktop antivirus software from Symantec Corp. prevented the main Trojan horse file from being installed on his users' desktops, he's concerned about the unpatched hole in Internet Explorer and wary that other malicious code may have also been downloaded that Symantec's antivirus engine was not able to detect, he said.

"Internet Explorer is a big concern. If there's something Symantec doesn't know about yet, all you have to do is hit the wrong Web site and (hackers) can install whatever they want to," he said.

Microsoft hasn't seen evidence of widespread attacks, despite dire warnings from some security companies and a handful of tales like Guyor's, Toulouse said.

"Our investigation is showing us that this is not widespread. We haven't seen or heard a lot about this," he said.

That's the case at Network Associates Inc. (NAI), as well, according to Vincent Gullotto, vice president of research at NAI's McAfee Antivirus Emergency Response Team.

"We don't have significant reports of Web sites compromised or of people sending us examples of the new Trojans," he said. "I'd rate this a low risk if you're patched and a medium risk if you're not."

Still, other security companies reported widespread infections.

"Hundreds of thousands of computers have likely been infected in the past 24 hours," said Ken Dunham, director of malicious code in an e-mail statement from iDefense Inc., a security intelligence company in Reston, Virginia.

Managed security company NetSec Inc., in Herndon, Virginia, said it has seen infections across the majority of its customer accounts and knows of infections at large Web hosting farms, where a small number of IIS servers out of a large farm of servers have been compromised, said Dan Frasnelli, manager of NetSec's Technical Assistance Center.

The confusion about the extent of attacks shouldn't be surprising, especially given the novelty of the attack, said Chris Kraft, a senior security analyst at Sophos PLC.

"There tends to be confusion when something new and interesting happens. You get a broad disparity of what people say at the outset of the attack."

Sophos did not receive many reports from customers about the attacks. Still, Kraft thinks the strategy used by the virus writers makes the IIS attacks worth noting.

"The interesting thing is the delivery mechanism. These hackers usurped Web sites that people normally consider safe, then exploited vulnerabilities in the Web browser to download a set of instructions," he said.

If used successfully against a major Web site such as Yahoo.com or eBay.com, the same approach could net millions of computers in just a short time that could then be controlled using Trojan horse programs and used to launch denial of service attacks or distribute unsolicited commercial ("spam") e-mail, he said.

NAI's Gullotto agrees, saying that the vulnerabilities, Trojan programs and exploits used in the attacks are well-known to information technology security experts and have been circulating on the Internet. Their combined use in an attack is new.

"We've had all this stuff for quite a while. The deal is that it happened -- that somebody put the pieces together," he said.

 

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.