Black Ice

Moderators: Moderator, Global Moderator

Post Reply
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Black Ice

Post by Tami »

[color=\"#41121C\"]Originally Posted on GraphixGround March 20 2004

Alerts
Internet Security Systems Security Alert
March 20, 2004

BlackICE Witty Worm Propagation

Synopsis:

ISS X-Force has learned of a worm that is spreading via the ICQ parsing
vulnerability in ISS products that was announced on March 18th. The worm
targets unpatched versions of the BlackICE PC Protection product. If a
vulnerable system is infected, the Witty worm attempts to propagate by
scanning random IP addresses. The Witty worm progressively writes junk
data to physical hard drives after transmitting 20,000 packets, causing
data damage.

Impact:

The Witty worm uses hard-coded addresses and only has the ability to
infect certain builds of the Protocol Analysis Module (PAM). The Witty
worm is destructive to the target system, and overwrites key hard disk
sectors after sending out its payload. The junk data written to disk
may impact system stability and cause a "blue screen" to occur upon reboot.

The Witty worm only infects specific builds of PAM listed below, and can
only infect Win32 systems.

Affected Versions:

BlackICE™ Agent for Server 3.6 ebz, ecb, ecd, ece, ecf
BlackICE PC Protection 3.6 cbz, ccb, ccd, ccf
BlackICE Server Protection 3.6 cbz, ccb, ccd, ccf
RealSecure® Network 7.0, XPU 22.4 and 22.10
RealSecure Server Sensor 7.0 XPU 22.4 and 22.10
RealSecure Desktop 7.0 ebf, ebj, ebk, ebl
RealSecure Desktop 3.6 ebz, ecb, ecd, ece, ecf
RealSecure Guard 3.6 ebz, ecb, ecd, ece, ecf
RealSecure Sentry 3.6 ebz, ecb, ecd, ece, ecf

Note: No Proventia products are affected by the Witty worm. The newest
updates for all products are not vulnerable to exploitation.

Description:

The Witty worm exploits a stack-based overflow in ICQ response parsing
in the Protocol Analysis Module (PAM) of ISS products. It is a memory-
resident worm only, and contains no file payload. Witty propagates via
UDP, sending UDP packets with a random destination and destination port.
The source port of Witty traffic is 4000, and the source address is not
spoofed.

The worm will attempt to propagate immediately by sending copies of
itself out across the wire to random targets. After sending a predefined
number of packets, Witty attempts to open a randomly determined physical
drive and write 64k of data to a random location. This cycle repeats for
every 20,000 packets sent.

Recommendations:

ISS Product updates that address this vulnerability have been available
since March 9, 2004. For a complete listing of those updates,
please see the following X-Force Alert:[/color]

Alert 166
[color=\"green\"]
ISS has also made the following updates available to provide detection and
blocking capabilities for the Witty Worm and to detect the underlying
vulnerability:

Proventia M Series 1.12:
ICQ_PAM_Parser_Overflow -
(http://xforce.iss.net/xforce/xfdb/15442)
ICQ_Witty_Worm
(http://xforce.iss.net/xforce/xfdb/15543)

Proventia G Series 22.14:
ICQ_PAM_Parser_Overflow -
(http://xforce.iss.net/xforce/xfdb/15442)
ICQ_Witty_Worm
(http://xforce.iss.net/xforce/xfdb/15543)

Proventia A Series 22.14:
ICQ_PAM_Parser_Overflow -
(http://xforce.iss.net/xforce/xfdb/15442)
ICQ_Witty_Worm
(http://xforce.iss.net/xforce/xfdb/15543)

RealSecure Network 22.14:
ICQ_PAM_Parser_Overflow -
(http://xforce.iss.net/xforce/xfdb/15442)
ICQ_Witty_Worm
(http://xforce.iss.net/xforce/xfdb/15543)

RealSecure Server 22.14:
ICQ_PAM_Parser_Overflow -
(http://xforce.iss.net/xforce/xfdb/15442)
ICQ_Witty_Worm
(http://xforce.iss.net/xforce/xfdb/15543)

All updates are accessible via the ISS Download
Center:
http://www.iss.net/download/

ISS X-Force recommends that networks block UDP packets with a source
port of 4000 at the network gateway to block inbound worm propagation.

Data on infected systems may be damaged. ISS X-Force recommends that
systems that are infected are removed from the network, and powered
down. ISS X-Force further recommends that data recovery techniques
are employed to assess damage and to recover data.

ISS X-Force recommends that affected individuals investigate one or
more of the following data recovery techniques:

1. Launch the Windows XP or Windows 2000 recovery console:
http://support.microsoft.com/default.as ... -us;307654
http://support.microsoft.com/default.as ... -us;268106

2. Create a parallel install of the operating system into something
other then the default directory to gain access critical files:
http://support.microsoft.com/?id=259003

3. Run chkdsk /f on the affected volumes to see if it will repair
the corruption

4. Restore the system from the most recent backup if chkdsk is not able
to repair the corruption.

------

About Internet Security Systems, Inc.
Internet Security Systems, Inc. (ISS) is the trusted expert to
global enterprises and world governments, providing products and
services that protect against Internet threats. An established
world leader in security since 1994, ISS delivers proven cost
efficiencies and reduces regulatory and business risk across the
enterprise for more than 11,000 customers worldwide. ISS products
and services are based on the proactive security intelligence
conducted by ISS' X-Force® research and development team - the
unequivocal world authority in vulnerability and threat research.
Headquartered in Atlanta, Internet Security Systems has additional
operations throughout the Americas, Asia, Australia, Europe and
the Middle East. For more information, visit the Internet Security
Systems Web site at www.iss.net or call 800-776-2362.

Internet Security Systems and Proventia are trademarks, and X-Force
is a registered trademark of Internet Security Systems, Inc. Cobion
is a registered trademark of Cobion AG. All other companies and
products mentioned are trademarks and property of their respective
owners.

This document is not to be edited or altered in any way without the
express written consent of Internet Security Systems, Inc. If you wish
to reprint the whole or any part of this document, please email
xforce@iss.net for permission. You may provide links to this document
from your web site, and you may make copies of this document in
accordance with the fair use doctrine of the U.S. copyright laws.

Disclaimer: The information within this paper may change without notice.
Use of this information constitutes acceptance for use in an AS IS
condition. There are NO warranties, implied or otherwise, with regard to
this information or its use. Any use of this information is at the
user's risk. In no event shall the author/distributor (Internet Security
Systems X-Force) be held liable for any damages whatsoever arising out
of or in connection with the use or spread of this information.
Source
(ty NightStorm for the info)[/color]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Post Reply

Return to “General”