Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Virus and Vulnerability Roundup
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Microsoft hole spawns false alarm, real attacks

The backdoor.mipsiv code can open ports on compromised systems

April 28, 2004 12:00 PM ET

IDG News Service - Antivirus company Symantec Corp. backtracked today after claiming that it captured an example of a new Internet worm that takes advantage of a recently disclosed hole in Windows machines running Secure Sockets Layer.
The company yesterday trapped an example of the malicious code called backdoor.mipsiv and warned customers that it was either a new worm or a small automated program called a "bot" that exploits a new Windows Private Communications Transport Protocol (PCT) vulnerability, part of the Windows implementation of SSL. However, Symantec today said further analysis of the code showed that it was neither a worm nor a bot and that it didn't use the PCT vulnerability.
Instead, the code, still called backdoor.mipsiv, is described as a Trojan program. Mipsiv is placed on vulnerable machines by malicious hackers, after which it opens communications ports on systems it compromises and uses Internet Relay Chat channels to send instructions, Symantec said.
"We better understand what it's doing now and after further investigation, it doesn't look like it's self-propagating," said Jonah Paransky, senior manager of security product management at Symantec.
Symantec's confusion stemmed from its misinterpretation of a series of related, but isolated events, he said.
Malicious hackers have been scanning for machines that have the PCT vulnerability, then using exploit code targeted at that security hole to compromise those systems and place the mipsiv Trojan on them. Once installed, mipsiv communicates with the rest of the Internet through the same communications port, 443, that is used by PCT, he said.
However, the mipsiv code doesn't contain either worm or bot features and could have been placed on systems only by attackers who compromised the system using the PCT exploit code, or other means, he said.
That means that the effects of the PCT exploit will be felt on targeted networks, whereas a worm or virus that used it could harm systems across the Internet.
Microsoft warned customers about the buffer overrun vulnerability in PCT on April 13 and issued a software patch for affected systems. According to the company's security advisory MS04-011, the PCT hole could allow a remote attacker to take complete control of affected systems.
Sample computer code to exploit the hole appeared on the Internet within days of the company's warning, prompting Microsoft to issue a warning to customers last Thursday about the malicious activity.
In recent days, other security experts that monitor malicious activity on the Internet had been warning of increased attacks that use the SSL vulnerability and postulated that a worm may be responsible, but


Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Jump to comments

Viruses

Additional Resources

WHITE PAPER
Approximately 60 percent of data migration projects overrun time or budget, while some fail completely. Download this white paper, "Enhancing Your Chance for Successful Data Migration," to learn the critical steps you need to take to execute a data migration project with minimum cost and risk to your business.
WHITE PAPER
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is around 50% lower than that of an unmanaged desktop deployment.
WHITE PAPER
Economic downturns have a tendency to accelerate emerging technologies, boost the adoption of effective solutions, and punish solutions that are not cost competitive or that are out of synch with industry trends. This IDC White Paper presents the results of an IDC survey of 330 companies in Western Europe, Asia/Pacific and the Americas that measures the receptiveness to Linux and takes into consideration changing views driven by the disruptive economic environment that businesses face today.