Updated Acrobat Snort Sig / Cisco Advisory / Distributed Vulnerable Scripts Scans/ Diary Foot-note

Published: 2004-08-18
Last Updated: 2004-08-19 13:05:07 UTC
by Pedro Bueno (Version: 1)
0 comment(s)
Acrobat Snort Sig

We received a note that BleedingSnort posted a Snort sig for the acrobat vulnerability:


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"BLEEDING-EDGE Adobe Acrobat Reader Malicious URL Null Byte"; reference:url,idefense.com/application/poi/display?id=126&type=vulnerabilities; uricontent:".pdf%00"; classtype:attempted-admin; sid:2002001; rev:2;)



*UPDATED RULE:

Please use the following rule for the Adobe Acrobat Vulnerability:


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS
(msg:"BLEEDING-EDGE Adobe Acrobat Reader Malicious URL Null Byte";
flow:to_server,established; uricontent:".pdf|00|"; nocase;
reference:cve,2004-0629; classtype:web-application-attack; sid:2002001;
rev:???;)
Reference and Updates at: http://www.bleedingsnort.com
Cisco Security Advisory: Cisco IOS Malformed OSPF Packet Causes Reload

Cisco just released a Security Advisory about a possible DoS condition in Cisco devices that have OSPF enabled.
According to Cisco:

"A Cisco device running Internetwork Operating System (IOS) ® and enabled for the Open Shortest Path First (OSPF) protocol is vulnerable to a Denial of Service (DoS) attack from a malformed OSPF packet. The OSPF protocol is not enabled by default.

The vulnerability is only present in Cisco IOS release trains based on 12.0S, 12.2, and 12.3. Releases based on 12.0, 12.1 mainlines, and all Cisco IOS images prior to 12.0 are not affected.

Cisco has made free software available to address this vulnerability.

There are workarounds available to mitigate the effects."

Reference:
http://www.cisco.com/warp/public/707/cisco-sa-20040818-ospf.shtml

More distributed Scans

We received more logs from what looks like a distribuited scan for vulnerable scripts.

You can find an excerpt bellow:




[Mon Aug 16 07:05:40 2004] [error] [client 200.48.218.178] script not found or unable to stat: /yyyyyy/xxxxx/public_html/mail.cgi

[Mon Aug 16 07:05:39 2004] [error] [client 213.128.225.93] script not found or unable to stat: /yyyyyy/xxxxx/public_html/cgi-bin/FormMail.pl

[Mon Aug 16 07:05:34 2004] [error] [client 65.112.194.26] script not found or unable to stat: /yyyyyy/xxxxx/public_html/cgi-bin/formmail.cgi

[Mon Aug 16 07:05:23 2004] [error] [client 194.224.199.205] script not found or unable to stat: /yyyyyy/xxxxx/public_html/cgi-bin/mailform.pl

[Mon Aug 16 07:05:20 2004] [error] [client 216.145.226.35] script not found or unable to stat: /yyyyyy/xxxxx/public_html/cgi-bin/contact.cgi

[Mon Aug 16 07:05:19 2004] [error] [client 218.45.229.101] script not found or unable to stat: /yyyyyy/xxxxx/public_html/cgi-bin/formmail.pl


Diary foot-note

If do you ever had problems with spywares and related, be careful when choosing the right tools. The worst thing is that if you have a spyware in your computer, a lot of Anti-spywares tools pop-ups will appear in your window, offering the products. Be very very careful...!

I usually have a set of tools that I trust to clean up a computer, as many of you. So, if you are in doubt, drop us a line.

---------------------------------------------------

Olympic games 2004 status: Brazil - 2 bronze medals

Handler on Duty: Pedro Bueno (bueno/AT/ieee.org)
Keywords:
0 comment(s)

Comments

What's this all about ..?
password reveal .
<a hreaf="https://technolytical.com/">the social network</a> is described as follows because they respect your privacy and keep your data secure:

<a hreaf="https://technolytical.com/">the social network</a> is described as follows because they respect your privacy and keep your data secure. The social networks are not interested in collecting data about you. They don't care about what you're doing, or what you like. They don't want to know who you talk to, or where you go.

<a hreaf="https://technolytical.com/">the social network</a> is not interested in collecting data about you. They don't care about what you're doing, or what you like. They don't want to know who you talk to, or where you go. The social networks only collect the minimum amount of information required for the service that they provide. Your personal information is kept private, and is never shared with other companies without your permission
https://thehomestore.com.pk/
<a hreaf="https://defineprogramming.com/the-public-bathroom-near-me-find-nearest-public-toilet/"> public bathroom near me</a>
<a hreaf="https://defineprogramming.com/the-public-bathroom-near-me-find-nearest-public-toilet/"> nearest public toilet to me</a>
<a hreaf="https://defineprogramming.com/the-public-bathroom-near-me-find-nearest-public-toilet/"> public bathroom near me</a>
<a hreaf="https://defineprogramming.com/the-public-bathroom-near-me-find-nearest-public-toilet/"> public bathroom near me</a>
<a hreaf="https://defineprogramming.com/the-public-bathroom-near-me-find-nearest-public-toilet/"> nearest public toilet to me</a>
<a hreaf="https://defineprogramming.com/the-public-bathroom-near-me-find-nearest-public-toilet/"> public bathroom near me</a>
https://defineprogramming.com/
https://defineprogramming.com/
Enter comment here... a fake TeamViewer page, and that page led to a different type of malware. This week's infection involved a downloaded JavaScript (.js) file that led to Microsoft Installer packages (.msi files) containing other script that used free or open source programs.
distribute malware. Even if the URL listed on the ad shows a legitimate website, subsequent ad traffic can easily lead to a fake page. Different types of malware are distributed in this manner. I've seen IcedID (Bokbot), Gozi/ISFB, and various information stealers distributed through fake software websites that were provided through Google ad traffic. I submitted malicious files from this example to VirusTotal and found a low rate of detection, with some files not showing as malware at all. Additionally, domains associated with this infection frequently change. That might make it hard to detect.
https://clickercounter.org/
Enter corthrthmment here...

Diary Archives