★ wanayoo — archive 1999 http://www.cert.org/current/current_activity.htmlNouvelle recherche | Portail wanayoo
The CERT/CC is part of the Software Engineering Institute at Carnegie Mellon University CERT® Coordination Center
CERT® Coordination Center

 Home | What's New | FAQ | Site Contents | Contact Us | SEARCH

About Us | Alerts | Education and Training | Events | FTP Archives | Improving Security | Other Resources | Reports | Survivability Research

CERT/CC Current Activity

Tue Feb 29 11:43:47 GMT-0500 2000

The CERT/CC Current Activity web page is a regularly updated summary of the most frequent, high-impact types of security incidents and vulnerabilities currently being reported to the CERT/CC.

  • Compromises via BIND Vulnerability
  • [ Updated: 29 February 2000 ]
  • Packet Flooding Denial of Service Attacks
  • [ Updated: 29 February 2000 ]
  • Compromises via Cron Vulnerability
  • [ Added: 29 February 2000 ]
  • Windows Trojan Horses
  • [ Added: 29 February 2000 ]
  • Web Server Compromises
  • [ Added: 29 February 2000 ]
  • Scans and Probes
  • [ Updated: 29 February 2000 ]

    Compromises via BIND Vulnerability

    We continue to receive daily reports of systems being root compromised via one of the most recent vulnerabilities in BIND. The "NXT bug" described in

    CA-99-14, Multiple Vulnerabilities in BIND

    can and is being exploited to gain root access to systems running a vulnerable version of BIND. An exploit is in public circulation and intruders are actively seeking out and compromising vulnerable hosts. Some sites with compromised systems have found the following empty directory resulting from the NXT record vulnerability being exploited:

    /var/named/ADMROCKS

    Sites are strongly encouraged to follow the advice contained in CA-99-14 to protect systems running BIND. If you believe your host has been compromised, please follow the steps outlined in

    Steps for Recovering From a Root Compromise


    Packet Flooding Denial of Service Attacks

    We continue to receive reports of administrators finding compromised systems where a distributed denial-of-service tool has been installed. In most all cases, intruders are exploiting well-known vulnerabilities to gain access to systems, which they then use to launch further attacks.

    We have received a number of inquiries from sites asking what they can do to prepare for denial of service attacks. We encourage these sites to read the report published from the DSIT Workshop that was held in November, 1999.

    Results of the Distributed-Systems Intruder Tools Workshop

    Also, we encourage you to read the following advisories and incident notes.

    IN-2000-01, Windows Based DDOS Agents
    CA-2000-01, Denial-of-Service Developments
    CA-99-17, Denial-of-Service Tools
    IN-99-07, Distributed Denial of Service Tools

    If you believe your host has been compromised and a distributed denial of service tool has been installed, please follow the steps outlined in

    Steps for Recovering From a Root Compromise

    We encourage you to contact other sites involved that may also have compromised systems being used as a node in a distributed network of attack tools. For general information about contacting sites, please see

    Finding Site Contacts

    Also note that while there has been quite a bit of discussion about advances in intruder denial of service technology with respect to distributed systems, keep in mind that other packet flooding denial of service attacks such as smurf, UDP floods, and SYN floods are still very common.


    Compromises via Cron Vulnerability

    We have been receiving occational but steady reports of compromised unprivileged accounts on systems being used to gain root privileges via exploitation of various vulnerabilities related to the 'cron' service. For more information, please see

    VN-2000-01 Multiple Vulnerabilities in Vixie Cron


    Windows Trojan Horses

    We have recently seen an increase in activity related to an email-bourne Trojan horse known as PrettyPark. This Trojan horse is well-known and well documented by the anti-virus vendor community. For more information, please see:


    Web Server Compromises

    We have recently seen an increase in activity related to compromises of Microsoft IIS web servers due to exploitations of a well-known vulnerability in Microsoft Data Access Components (MDAC). For more information, please see

    IN-99-08, Attacks against IIS web servers involving MDAC


    Scans and Probes

    We receive many daily reports of scanning and probing activity. The most frequent reports tend to involve services that have well-known vulnerabilities. Hosts continue to be affected by exploitation of well-known vulnerabilities in these services.

    Service Name Port/Protocol Related Information
    sunrpc 111/tcp
    111/udp
    CA-99-16, Buffer Overflow in Sun Solstice AdminSuite Daemon sadmind
    CA-99-12, Buffer overflow in amd
    CA-99-08, Buffer overflow in rpc.cmsd
    CA-99-05, Vulnerability in statd exposes vulnerability in automountd
    CA-98.12, Remotely Exploitable Buffer Overflow Vulnerability in mountd
    CA-98.11, Vulnerability in ToolTalk RPC service
    domain 53/tcp
    53/udp
    CA-99-14, Multiple Vulnerabilities in BIND
    CA-98.05, Multiple Vulnerabilities in BIND
    ftp 21/tcp CA-99-13, Multiple Vulnerabilities in WU-FTPD
    CA-97.27, FTP Bounce
    imap 143/tcp CA-98.09, Buffer Overflow in Some Implementations of IMAP Servers
    pop3 110/tcp Qpopper buffer overflow
    ssh 22/tcp CA-99-15, Buffer Overflows in SSH Daemon and RSAREF2 Library
    netbios-ns 137/udp Common port for NETBIOS name service, used in Microsoft Windows Networking
    socks 1080/tcp CA-98.03, WinGate IP Laundering
    ICMP echo
    ICMP echo reply
    ICMP type 8
    ICMP type 0
    CA-98.01, "smurf" IP Denial-of-Service Attacks


    For an overview of incident and vulnerability activity during the last quarter, see the most recent
    CERT Summary.


    Copyright 1999, 2000 Carnegie Mellon University.

    See the conditions for use, disclaimers, and copyright information.

    CERT® and CERT Coordination Center® are registered in the U.S. Patent and Trademark office.