Code Red - internal meltdowns

From: Russ (Russ.Cooper@RC.ON.CA)
Date: 08/08/01


Message-ID:  <E9A01F52DC939448BBDE44ED2E1C468F167C51@muskie.rc.on.ca>
Date:         Wed, 8 Aug 2001 11:56:02 -0400
From: Russ <Russ.Cooper@RC.ON.CA>
Subject:      Code Red - internal meltdowns
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM


-----BEGIN PGP SIGNED MESSAGE-----

A lot of organizations have been focusing on preventing Code Red from
coming through their Internet gateways, while forgetting other
methods of infection.

Windows 2000 Professional on laptops usually has hibernation enabled.
If Personal Web Server (which is IIS) is installed, and the laptop
gets connected to the Internet from home or another company's office,
it can easily become infected. Since its memory resident, if
hibernation is used during travel back to the office, as soon as the
machine is brought up it can start emitting attacks on your internal
network.

This is true for all variants known to date.

So don't believe your internal network is secure just because you
block port 80 at your router/firewall. More than a few internal
networks have been infected with Code Red, likely for this reason. If
Code Red has access to a LAN to propagate, it doesn't take long for
it to saturate it.

Also remember your VPN connections, both your own employees and any
you might have with partners. They often work both ways, more often
than not with only a little filtering (if at all). Home workers might
very well have several computers behind their NAT'd gateway, all may
also be able to pump traffic out the VPN (depending on how its
configured). Scanning your own internal address space may not be
sufficient to identify all of possibly infectable machines.

Is little Johnny's computer (W2K Pro?) at the CEO's home continually
re-infecting your internal network over daddy's VPN?

Time to take stock of all of the possibilities...it might even help
you get some of your policies effected!

Cheers,
Russ - Surgeon General of TruSecure Corporation/NTBugtraq Editor

-----BEGIN PGP SIGNATURE-----
Version: PGP Personal Privacy 6.5.2

iQCVAwUBO3FhEhBh2Kw/l7p5AQFjFQQAxpR4BUr3Nh9DImaveLPwpYLi+0DP+o6Z
PJ6DZu3PgKF6Di2IXRzO8c2HlTWoeB7nCmhM6RKoUqn48+ZPQ51J3WtB/WK2f2GB
SpJuvlsv9DUpuLrAj3kVhylxSXwjjKrlzFVMapS3aha+CVnuxR2VOsZ6JDt2bklk
/m7wHmN/aec=
=Hv2c
-----END PGP SIGNATURE-----



Relevant Pages

  • Re: Intermittent Firewall 15108 Events on SBS2003/ISA2004
    ... This newsgroup only focuses on SBS technical issues. ... of |> the internal network object). ... If the ISA server receives a package with an |> internal IP as source address from the external port, the package would be |> treated as a spoof attack. ... |> 825763 How to configure Internet access in Windows Small Business ...
    (microsoft.public.windows.server.sbs)
  • Re: How to get through iptables/NAT, reality and risk calculation
    ... there have been no security issues with the ... # the external interface, and/or the internal one on all ports but 22 tcp ... # so the firewall itself can't talk to anything but the internal network over ... >> accepting traffic from the internet part of an existing connection (with ...
    (Security-Basics)
  • 192.168.x.x oddities
    ... and unrouteable on the Internet. ... from within the internal network. ... Ethical Hacking at the InfoSec Institute. ... Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. ...
    (Security-Basics)
  • Re: Hyper-V, RAAS woes. . . Please help
    ... From the host I am able to ping www.news.com. ... Can you ping the host's static public IP from the guest? ... > My Hyper-V Guests cannot traverse through NAT to gain internet access. ... Pointed internet network to the internal network ...
    (microsoft.public.windows.server.general)
  • Re: new to ISA, but not firewalls
    ... the internal network in a direct way, and this is of the things that ISA2004 ... internet and the internal network, however i don't a know why any one would ... Remember if ISA LAT is empty, ... >> include the internal interface IP. ...
    (microsoft.public.isaserver)