Old Vulnerabilities Can Still Haunt You
Andrew writes in to say ..
"It just goes to show that old vulnerabilities can still be effective. I recently ran across a site that our IDS detected via the ANI exploit.
http://ww.xx.yyy.zz /oth/ms07-017.ani
http://ww.xx.yyy.zz /oth/ms07-017.php
One of our machines accessed this site and got exploited, but they had the MS07-017 patch. Very strange. After de-obfuscating the javascript to see what exploits it uses, it turns out the site goes after MS03-011, MS06-014 and MS07-017. The system was patched for the two newer exploits, but not for the old Microsoft JVM vulnerability.
To make things worse, the site drops ntos.exe, which contains rootkit functionality. At least the binary is fairly well detected by AV vendors.
Depending on how security savvy your organization is, legacy issues can slip by for years."
If you think you're patched to current, how do you know for sure?
An occasional scan (using MBSA for example) will show you any missing patches. In a perfect world, every system would be able to always be patched to current but if you are one of the people who can't deploy certain patches because it will break critical business functionality, these reports will be the start of the paper trail you will want for your audits showing why they can't be patched.
Comments