TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------

 
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

INTERNET THREAT UPDATE for 03-19-2002
ISS X-Force Internet Threat Intelligence Center

www.iss.net - Click on AlertCon logo for more
information.

********************************************
ALERTCON 1
Projected:  AlertCon 1
********************************************

ALERTCON 1 - AlertCon 1 reflects the malicious,
determined, global, 24 x 7 attacks experienced by
all networks.

U.S. DEPARTMENT OF STATE:  PUBLIC ANNOUNCEMENT -
The U.S. Government continues to receive credible
reports that extremist individuals are planning
additional terrorist actions against U.S.
interests. Such actions may be imminent and
include suicide operations. They have no further
information on specific targets, timing or method
of attack. They are reminding American citizens
to remain vigilant with regard to their personal
security and to exercise caution. Travelers
abroad should monitor local news and maintain
contact with the nearest American Embassy or
Consulate

HP:  A vulnerability in Java(TM) Web Start may
allow an application
using it to gain access to restricted resources. 
This relates to HP9000 Series 700/800 running
HP-UX releases 11.x only.

MICROSOFT:  On March 4, 2002, Microsoft released
the first version of bulletin MS02-013.asp.  On
March 18, 2002, Microsoft re-released this
bulletin to make customers aware of an additional
vulnerability that is eliminated by the updated
VM (Microsoft VM build 3805). Customers who have
previously installed the new build do not need to
take any additional action.

ZLIB:  A warning about the security flaw
identified last week in the zlib
compression/decompression library affecting Linux
systems has been broadened to include Windows and
any other operating systems that use the zlib
code.  In an update about the flaw on their Web
site, it is explained that the code is used in
far more programs than they originally believed. 
Affected applications on the site include
Microsoft's DirectX 8, FrontPage, GDI+, Internet
Explorer, Office, NetShow, Train Simulator,
Visual Studio, and Windows Messenger. Also,
Netscape Navigator, Network Associates' PGP
security software, Symantec's Norton Antivirus,
and Jasc Software's PaintShop Pro are affected.

VIRUSES/WORMS: TROJ_JUNTADOR.B is compiled in
Delphi, and is capable of sending ICQ messages.
It drops files in the Windows directory and the
System directory. It drops two backdoor programs,
detected as BKDR_PSYCHWARD.F and
BKDR_OBLIVION.B1.

********************************************
RECOMMENDATIONS
********************************************

For the full Department of State announcement,
please see:
http://www.travel.state.gov/wwc1.html 

For the HP vulnerability, obtain and install the
latest release of the Java Web Start product. 
This will be found by going to:
www.hp.com/go/java 

For the Microsoft bulletin, please refer to:
<http://www.microsoft.com/technet/treeview/default
.asp?url=/technet/security/bulletin/MS02-013.asp>

For the zlib patch and further clarification,
please see:
http://www.gzip.org/zlib 

For information on the TROJ_JUNTADOR.B Trojan,
please see:
<http://www.antivirus.com/vinfo/virusencyclo/defau
lt5.asp?VName=TROJ_JUNTADOR.B>   

Information regarding viruses and worms please
see:
<https://gtoc.iss.net/viruses.php>   

********************************************

FACTOID:  Businesses lose an estimated $10
billion or more annually due to security breaches
in their computer systems, according to the
Computer Security Institute.

********************************************
ATTACK SIGNATURE RANKING - global IDS, midnight -
midnight, previous
Day, % of total
********************************************
 
Protocol Decode              36.95%       
Unauthorized Access Attempt  25.14%        
Suspicious Activity          21.41%       
Denial Of Service            13.23%        
Pre-Attack Probe             03.26%         
Back Door                    00.02%  

********************************************
TOP TEN ATTACK DESTINATION PORTS - global IDS,
midnight - midnight,
previous day, % of top ten (ports found at) 
http://www.networkice.com/Advice/Exploits/Ports/de
fault.htm 
********************************************

80        (http)             61.30%       
161       (SNMP)             17.44%        
21        (ftp)              07.52%       
23        (telnet)           03.97%         
162       (SNMPTrap)         03.36%         
25        (smtp)             02.30%         
139       (NetBIOS)          01.18%         
443       (ssl)              01.07%         
22        (ssh)              00.98%         
1500      (vlsi-lm)          00.89%

********************************************
BACKGROUND, COPYRIGHT NOTICE, and DISCLAIMER 
********************************************

Background. We provide this information in the
spirit of PDD 63 to help security professionals
wage the war against Internet threats more
effectively. Information in this update derived
primarily from global, real time, 24 x 7 IDS
feeds, ISS X-Force R&D Team research, and
professional liaison. Other sources as noted.
AlertCon 1 reflects the global, malicious,
determined, 24 x 7 attacks experienced by all
networks. AlertCon 2 means increased
vigilance/action recommended due to a specific
threat or concern. AlertCon 3 means increased
attacks against specific targets or
vulnerabilities on a scale that is unusually
high, action required. AlertCon 4 reflects an
Internet emergency for a target or group of
targets whose business continuity may depend on
some sort of immediate, decisive action. All
summaries cover 24 hours the previous workday,
GMT. Monday summaries may cover some weekend
activity. 

Copyright 2001 Internet Security Systems, Inc.
Permission is granted for the redistribution of
the Internet Threat Update electronically.
It is not to be sold or edited in any way without
express consent of
ISS. Refer comments or questions to:
[EMAIL PROTECTED] or [EMAIL PROTECTED] 

Disclaimer: This information is subject to change
without notice. Use of this information
constitutes acceptance for use in an 'as is'
condition. There are no warranties with regard to
this information. In no event shall the author be
liable for any damages whatsoever arising out of
or in connection with the use or spread of this
information. Any use of this information is at
the user's own risk. No other use authorized.
FOIA Exemption 4.

You can download the public key from MIT's PGP
key server and PGP.com's key server.

Patrick Gray
Manager, X-Force
Internet Threat Intelligence Center
Internet Security Systems
6303 Barfield Road
Atlanta, GA 30328

-----BEGIN PGP SIGNATURE-----
Version: PGP 7.0.4

iQA/AwUBPJdPa5G41ROSQPncEQI5iQCgiY3VFU/ZFEKchraMteNQMxqRPu8AoKrk
dhKUGupnTCO06PvsL7Dlbc/b
=x+Yu
-----END PGP SIGNATURE-----


Reply via email to