Skip to main content

Alert A-02014C: worm per Windows 2000


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

******************************************************************

   Alert ID: A-02014C

   Data di creazione:  Wed Dec 18 14:24:29 CET 2002

   Titolo: worm per Windows 2000

   Gravita': alta

******************************************************************


Il CERT ha segnalato la presenza di un worm per Windows 2000, che 
utilizza la porta 445/tcp, ed effettua una scansione delle macchine alla 
ricerca di account senza password o con password 'deboli', installandosi 
sulle macchine vittima dell'attacco e replicandosi su altri host sulla rete.

Allego un estratto delle soluzioni esposte nell'advisory del CERT:

   Restrict or disable null sessions

   Depending on the services your systems are required to provide, it 
may be possible for you to restrict or disable anonymous null sessions 
on your Windows 2000 hosts. This can be done through the 
HKLMSYSTEMCurrentControlSetControlLSA key with the following parameters:

   Value: RestrictAnonymous Value Type: REG_DWORD Value Data: 0x1 or 0x2 
(Hex)
According to Microsoft Knowledge Base Article Q246261, this key can take 
on the following values:

   0x0 = None. Rely on default permissions 0x1 = Do not allow 
enumeration of SAM accounts and names 0x2 = No access without explicit 
anonymous permissions
   Note that this configuration could cause problems in certain network 
environments. The CERT/CC encourages you to review Microsoft Knowledge 
Base Article Q246261 before making any of these changes to your system(s).

   Windows XP sets the RestrictAnonymousSam key to 0x1 by default. 
Therefore, unless this setting has been altered by the system 
administrator, W32/Lioten should not be able to retrieve the account 
list via a null session on Windows XP systems.


Require strong passwords

   W32/Lioten exploits the use of weak or null passwords in order to 
propagate, hence requiring the use of strong passwords can help keep it 
from infecting your systems.


   Ingress/egress filtering

   Ingress filtering manages the flow of traffic as it enters a network 
under your administrative control. In the network usage policy of many 
sites, external hosts are only permitted to initiate inbound traffic to 
machines that provide public services on specific ports. Thus, ingress 
filtering should be performed at the border to prohibit externally 
initiated inbound traffic to non-authorized services.

   Egress filtering manages the flow of traffic as it leaves a network 
under your administrative control. There is typically limited need for 
internal systems to access NetBIOS shares across the Internet.

   In the case of W32/Lioten, blocking connections to port 445/tcp from 
entering or leaving your network reduces the risk of external infected 
systems attacking hosts inside your network or vice-versa.


cordiali saluti

massimo ianigro


Riferimenti:
   http://www.cert.org/incident_notes/IN-2002-06.html
   http://www.mynetwatchman.com/kb/security/articles/iraqiworm/
   http://support.microsoft.com/default.aspx?scid=KB;en-us;q246261


Appendice

   GARR-CERT Home Page:  http://www.cert.garr.it


- --

 

Alert di GARR-CERT Usata per la segnalazione di allarmi di sicurezza e comunicazioni di interesse generale diretti agli enti GARR. L'iscrizione è aperta e consigliata a tutti, il posting è riservato ai membri di GARR-CERT