|
|
Log in / Subscribe / Register

Security

That OpenSSL Worm

This worm has been referred to by at least four different names: Apache/mod_ssl worm, linux.slapper.worm, bugtraq.c worm and Modap worm.

On Friday September 13th the first reports appeared on Bugtraq of an active worm exploiting the OpenSSL buffer overflow vulnerability reported at the end of July. The next day CERT issued Advisory CA-2002-27 Apache/mod_ssl Worm.

Compromise by the Apache/mod_ssl worm indicates that a remote attacker can execute arbitrary code as the apache user on the victim system. It may be possible for an attacker to subsequently leverage a local privilege escalation exploit in order to gain root access to the victim system. Furthermore, the DDoS capabilities included in the Apache/mod_ssl worm allow victim systems to be used as platforms to attack other systems.

By Sunday September 15th, at 17:00 GMT, F-Secure Corporation reported 13,000 infected servers out of "over 1,000,000 active OpenSSL installations in the public web." Updates to fix the problem, including backports to earlier versions of OpenSSL, had been available for over a month from the OpenSSL project, Caldera, Conectiva, Debian, EnGarde, Eridani, Gentoo, Mandrake, OpenPKG, Red Hat, SuSE, Trustix and Yellow Dog.

SecurityFocus has completed and released a full analysis (PDF format) of the worm in addition to their initial incident Alert (PDF format). F-Secure is maintaining a "Virus Description" of this worm with lots of interesting information.

The first reports in the press appeared Friday, the day the worm was first seen, in CNET and Network World Fusion. The next day CNET put up another story with additional information. By Monday evening both the Register and TechWeb had published their reports on events to date. On Tuesday Network World Fusion reported that the worm has infected at least 30,000 Linux Apache Web servers.

Also, see this other article from TechWeb on the worm:

According to Dan Ingevaldson, team lead of the X-Force R&D division at ISS, the first version may be a test to see how well the worm works before more deadlier versions surface. "Unlike Code Red and Nimda, where virus writers didn't have immediate access to the source code, the source code for this worm is already widely public," he says. "I'd expect new versions to start to surface."

RUS-CERT has made available a tool to remotely detect vulnerable servers. However, Eric Rescorla has observed behavior different from what that tool expects.

In the unlikely event that you haven't already, applying the appropriate OpenSSL update might be a very good thing to do before reading any further.

Comments (3 posted)

Brief items

Mozilla bug leaks Web surfing data (CNET)

CNET has a short article about a little privacy bug in Mozilla's handling of referers. "The bug reveals the URL of the page someone is viewing to the Web server of the site last visited. This allows a Web server to track where people go after they leave the site, even if the next Web address comes from a bookmark or is manually typed into the browser." If you are using a Gecko-based browser, you can see the bug in action on this page.

Comments (none posted)

September CRYPTO-GRAM newsletter

Bruce Schneier's CRYPTO-GRAM newsletter for September is out. It looks at possible new attack strategies for algorithms like AES, the Word97 vulnerability, and more. "We're seeing more and more of this: vulnerabilities in products that are no longer supported. When the SNMP vulnerabilities were published earlier this year, many products with the vulnerability were no longer supported. Some were made by companies no longer in business."

Full Story (comments: none)

Security reports

ht://Check cross-site scripting problems

Ulf Harnhammar reports potential cross-site scripting problems in ht://Check version 1.1, and possibly earlier versions as well. "It doesn't remove HTML tags before displaying the crawled web servers' "Server:" headers and other information."

ht://Check is a link checker derived from ht://Dig. It can retrieve information through HTTP/1.1 and store it in a MySQL database so that after a "crawl", ht://Check can return broken links, anchors not found, content-types, and HTTP status codes summaries. A PHP interface lets the user to query and view the results directly via the web

Full Story (comments: none)

xbreaky symlink vulnerability

Marco van Berkum reports a symlink vulnerability in the xbreaky breakout game for X. If xbreaky is installed as suid, the vulnerabilty can be abused by any user to overwrite any file on the filesystem. Distributions which include xbreaky may or may not install it suid root.

Full Story (comments: none)

MIMEDefang version 2.21 scans fragmented mail messages

The folks at Roaring Penguin Software have released, under the GPL, version 2.21 of MIMEDefang to deal with this Outlook Express based attack to bypass SMTP-based content filter engines.

MIMEDefang is a program for inspecting and modifying e-mail messages as they pass through your mail relay. MIMEDefang is written in Perl, and its filter actions are expressed in Perl, so it's highly flexible.

A patched version of MIME-Tools that addresses the problem is also avilable as well as version 1.2-F17 of Roaring Penguin's commercial CanIt anti-spam solution based on MIMEDefang 2.21.

Full Story (comments: none)

(Proprietary product) Race conditions in BRU Workstation 17.0

A race condition in TolisGroup's BRU Workstation 17.0 can be used to clobber any system file." According to this followup post, TolisGroup have responded with confirmation of an update for a race condition reported previously, and an estimated date for a new update for this one.

Full Story (comments: none)

(Proprietary product) File disclosure vulnerability in DB4Web application server

Stefan Bagdohn reports a file disclosure vulnerability in the DB4Web high-performance application server from Guardeonic Solutions AG. The DB4Web team has already provided an update which is available from here.

Full Story (comments: none)

New vulnerabilities

Local privilege escalation vulnerability in XFree86

Package(s):xf86 xfree86 CVE #(s):
Created:September 18, 2002 Updated:October 27, 2002
Description: XFree86 version 4.2.1 fixes a problem in Xlib that made it possible to execute arbitrary code in privileged clients. Other libraries are dynamically loaded by libX11.so as needed. When linking against a setuid program, arbitrary code could be loaded and executed from a pathname controlled by the user.
Alerts:
Gentoo xfree-20021024 xfree 2002-10-24
Conectiva CLA-2002:533 XFree86 2002-10-16
Conectiva CLA-2002:529 XFree86 2002-10-03
SuSE SuSE-SA:2002:032 xf86 2002-09-18

Comments (none posted)

Cross-site scripting vulnerability in Konqueror for KDE 3.0.3

Package(s):kdelibs CVE #(s):
Created:September 17, 2002 Updated:November 18, 2002
Description: Konqueror for KDE 3.0.3, and earlier versions, is subject to this cross-site scripting vulnerability. Since the problem is in kdelibs, any other application which uses the KHTML renderer is also vulnerable. Javascript code running in one frame can access other frames which should be inaccessible. The problem is fixed in kdelibs 3.0.3a.
Alerts:
SCO Group CSSA-2002-047.0 KDE 2002-11-15
Mandrake MDKSA-2002:064 kdelibs 2002-10-09
Conectiva CLA-2002:525 kdelibs 2002-09-20
Debian DSA-167-1 Konquerer 2002-09-16

Comments (2 posted)

Buffer overflow vulnerabilities in purity

Package(s):purity CVE #(s):
Created:September 17, 2002 Updated:September 26, 2002
Description: It seems that the "purity" game isn't entirely pure itself - a couple of buffer overflows have been found which could be exploited to gain access to the "games" group on Debian systems. Rather than face the prospect of people tampering with their nethack scores, the Debian Project released the first upgrade closing the vulnerability.
Alerts:
Debian DSA-166-1 purity 2002-09-13

Comments (none posted)

Resources

Linux Security Week and Advisory Watch

The September 16th Linux Security Week and September 13th Linux Advisory Watch newsletters from LinuxSecurity.com are available.

Comments (none posted)

chkrootkit 0.37 is now available

Klaus Steding-Jessen announces the release of chkrootkit version 0.37. chkrootkit is a tool to locally check for signs of a rootkit.

Well worth a look, especially if you arn't familiar with this useful tool.

Full Story (comments: none)

Four final computer security guidelines availble from NIST

The US National Institute of Standards and Technology (NIST) announces the final publication of four computer security guidelines available from here.

The four NIST Special Publications are:

  1. Security for Telecommuting and Broadband Communications
  2. Security Guide for Interconnecting Information Technology Systems
  3. Procedures for Handling Security Patches
  4. Use of the Common Vulnerabilities and Exposures (CVE) Vulnerability Naming Scheme.

Full Story (comments: none)

Choosing passwords: random, mnemonic phrases and more

Folks at the Cambridge University Computer Laboratory have done a good study on different password selection approaches which is summarized in two papers:
  1. The Memorability and Security of Passwords - Some Empirical Results by Jianxin Yan, Alan Blackwell, Ross Anderson and Alasdair Grant (PDF format)
  2. A Note on Proactive Password Checking by Jianxin Jeff Yan (PDF format)

Crispin Cowan also has some interesting comments on the conclutions reached by the study.

Comments (none posted)

Events

Final Speakers Announced for HiverCon 2002

HiverCon 2002 is scheduled for November 26th and 27th, 2002 in Dublin Ireland.

In total ten speakers have been announced as confirmed to speak at HiverCon 2002. The industry recognized names will be presenting papers on a myriad of information security topics, introducing new tools and research, as well as discussing newly highlighted security problems and solutions.

Full Story (comments: none)

Upcoming Security Events

Date Event Location
September 19 - 20, 2002SEcurity of Communications on the Internet 2002(SECI'02)Tunis, Tunisia
September 23 - 26, 2002New Security Paradigms Workshop 2002(The Chamberlain Hotel)Hampton, Virginia, USA
September 23 - 25, 2002University of Idaho Workshop on Computer Forensics(University of Idaho)Moscow, Idaho, USA
September 27 - 29, 2002ToorCon 2002(San Diego Concourse)San Diego, CA, USA
October 16 - 18, 2002Recent Advances in Intrusion Detection 2002(RAID 2002)Zurich, Switzerland
November 26 - 27, 2002HiverCon 2002(Burlington Hotel)Dublin, Ireland

For additional security-related events, included training courses (which we don't list above) and events further in the future, check out Security Focus' calendar, one of the primary resources we use for building the above list. To submit an event directly to us, please send a plain-text message to lwn@lwn.net.

Comments (none posted)

Page editor: Dennis Tenney
Next page: Kernel development>>


Copyright © 2002, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds