This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Alert - Black Ice Worm!

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…from the Internet Storm Center:

- http://isc.sans.org/diary.html?date=2004-03-20
Updated March 21st 2004 02:42 UTC

"Witty" worm attacks BlackICE firewall

"Summary
=======
At around 12:00 AM EST (05:00 UTC) on Saturday, we detected an upsurge in UDP traffic from source port 4000. This traffic is caused by a new worm ("Witty") which exploits a vulnerability in BlackIce's ICQ parser. This component is frequently refered to as 'PAM' (Protocol Analysis Module). Later today, variations of the worm apparently used source ports other then port 4000. However, it is not clear if this is a new variant or a side effect caused by NAT.
Given that this worm generates large amounts of traffic, and the wide spread use of BlackIce, we will keep the InfoCon level at 'YELLOW', likely until Monday morning.

Detection
=========
Infected hosts will send large amounts of UDP traffic, typically saturating a local network connection. The BlackIce task bar icon will no longer allow the user to shut down BlackIce. It will display a message reading "Operation could not be completed. Access is denied".
Eventually, the system will crash. Infected systems are reported to show corrupted hard disks.
The worm will not write itself to disk. As a result, Virus scanners may not detect it…

Removal
=======
A reboot will remove the worm from the system. However, the worm causes random hard disk corruption and the system may no longer function.

Links
=====
ISS Black Ice downloads - http://blackice.iss.net/update_center/index.php
Vulnerability Information - http://xforce.iss.net/xforce/alerts/id/166
F-Secure Writeup - http://www.f-secure.com/v-descs/witty.shtml
Symantec - http://securityresponse.symantec.com/avcen…witty.worm.html
McAffee - http://vil.nai.com/vil/content/v_101118.htm …"

.
More info available:

- http://www.lurhq.com/witty.html

- http://www.eweek.com/print_article/0,1761,a=122130,00.asp

- http://www.sarc.com/avcenter/venc/data/w32.witty.worm.html
Last Updated on: March 21, 2004
"…The worm has a payload of overwriting random sectors of a random hard disk.
NOTE: If your system is not running a vulnerable version of one of the products affected, then you will not be infected. Products affected by this vulnerability are listed below:

BlackICE Agent for Server 3.6 ebz, ecd, ece, ecf
BlackICE PC Protection 3.6 cbz, ccd, ccf
BlackICE Server Protection 3.6 cbz, ccd, ccf
RealSecure® Network 7.0, XPU 22.4 and 22.10
RealSecure Server Sensor 7.0 XPU 22.4 and 22.10
RealSecure Desktop 7.0 ebf, ebj, ebk, ebl
RealSecure Desktop 3.6 ebz, ecd, ece, ecf
RealSecure Guard 3.6 ebz, ecd, ece, ecf
RealSecure Sentry 3.6 ebz, ecd, ece, ecf

If you are running a product that has the vulnerability used by the worm, we recommend that you apply the relevant patch as soon as possible. Patches for this vulnerability are available at

>>> http://blackice.iss.net/update_center/index.php …"

.