Microsoft hole spawns false alarm, real attacks
The backdoor.mipsiv code can open ports on compromised systems
April 28, 2004 12:00 PM ETIDG News Service -
Antivirus company Symantec Corp. backtracked today after claiming that it captured an example of a new Internet worm that takes advantage of a recently disclosed hole in Windows machines running Secure Sockets Layer.
The company yesterday trapped an example of the malicious code called backdoor.mipsiv and warned customers that it was either a new worm or a small automated program called a "bot" that exploits a new Windows Private Communications Transport Protocol (PCT) vulnerability, part of the Windows implementation of SSL. However, Symantec today said further analysis of the code showed that it was neither a worm nor a bot and that it didn't use the PCT vulnerability.
Instead, the code, still called backdoor.mipsiv, is described as a Trojan program. Mipsiv is placed on vulnerable machines by malicious hackers, after which it opens communications ports on systems it compromises and uses Internet Relay Chat channels to send instructions, Symantec said.
"We better understand what it's doing now and after further investigation, it doesn't look like it's self-propagating," said Jonah Paransky, senior manager of security product management at Symantec.
Symantec's confusion stemmed from its misinterpretation of a series of related, but isolated events, he said.
Malicious hackers have been scanning for machines that have the PCT vulnerability, then using exploit code targeted at that security hole to compromise those systems and place the mipsiv Trojan on them. Once installed, mipsiv communicates with the rest of the Internet through the same communications port, 443, that is used by PCT, he said.
However, the mipsiv code doesn't contain either worm or bot features and could have been placed on systems only by attackers who compromised the system using the PCT exploit code, or other means, he said.
That means that the effects of the PCT exploit will be felt on targeted networks, whereas a worm or virus that used it could harm systems across the Internet.
Microsoft warned customers about the buffer overrun vulnerability in PCT on April 13 and issued a software patch for affected systems. According to the company's security advisory MS04-011, the PCT hole could allow a remote attacker to take complete control of affected systems.
Sample computer code to exploit the hole appeared on the Internet within days of the company's warning, prompting Microsoft to issue a warning to customers last Thursday about the malicious activity.
In recent days, other security experts that monitor malicious activity on the Internet had been warning of increased attacks that use the SSL vulnerability and postulated that a worm may be responsible, but
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Viruses
Additional Resources



White Papers & Webcasts
Share our Strength
Download Now
Key Strategies for Managing Data Growth
What are you storage challenges?
Can Heuristic Technology Help Your Company Fight Viruses?
What is Heuristic Technology and how can it help safeguard your business against viruses? Learn more.
Extending Client Refresh - 11 Steps to Maximize Savings
Register Now!
Eradicate Spam & Gain 100% Asurance of Clean Mailboxes
Get this paper now!
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Mastering eDiscovery: The IT Manager's Guide to Preservation, Protection & Production
Get this paper now!
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Not Just Words: Enforce Your Email and Web Acceptable Usage Policies
Get this paper now!
Consolidate Your Servers and Storage to Lower Costs with Oracle Database 11g
Register for this webcast!
