AplusWebMaster
Topic Starter
FYI…from the Internet Storm Center:
- http://isc.sans.org/diary.html?date=2004-03-20
Updated March 21st 2004 02:42 UTC
"Witty" worm attacks BlackICE firewall
"Summary
=======
At around 12:00 AM EST (05:00 UTC) on Saturday, we detected an upsurge in UDP traffic from source port 4000. This traffic is caused by a new worm ("Witty") which exploits a vulnerability in BlackIce's ICQ parser. This component is frequently refered to as 'PAM' (Protocol Analysis Module). Later today, variations of the worm apparently used source ports other then port 4000. However, it is not clear if this is a new variant or a side effect caused by NAT.
Given that this worm generates large amounts of traffic, and the wide spread use of BlackIce, we will keep the InfoCon level at 'YELLOW', likely until Monday morning.
Detection
=========
Infected hosts will send large amounts of UDP traffic, typically saturating a local network connection. The BlackIce task bar icon will no longer allow the user to shut down BlackIce. It will display a message reading "Operation could not be completed. Access is denied".
Eventually, the system will crash. Infected systems are reported to show corrupted hard disks.
The worm will not write itself to disk. As a result, Virus scanners may not detect it…
Removal
=======
A reboot will remove the worm from the system. However, the worm causes random hard disk corruption and the system may no longer function.
Links
=====
ISS Black Ice downloads - http://blackice.iss.net/update_center/index.php
Vulnerability Information - http://xforce.iss.net/xforce/alerts/id/166
F-Secure Writeup - http://www.f-secure.com/v-descs/witty.shtml
Symantec - http://securityresponse.symantec.com/avcen…witty.worm.html
McAffee - http://vil.nai.com/vil/content/v_101118.htm …"
.
- http://isc.sans.org/diary.html?date=2004-03-20
Updated March 21st 2004 02:42 UTC
"Witty" worm attacks BlackICE firewall
"Summary
=======
At around 12:00 AM EST (05:00 UTC) on Saturday, we detected an upsurge in UDP traffic from source port 4000. This traffic is caused by a new worm ("Witty") which exploits a vulnerability in BlackIce's ICQ parser. This component is frequently refered to as 'PAM' (Protocol Analysis Module). Later today, variations of the worm apparently used source ports other then port 4000. However, it is not clear if this is a new variant or a side effect caused by NAT.
Given that this worm generates large amounts of traffic, and the wide spread use of BlackIce, we will keep the InfoCon level at 'YELLOW', likely until Monday morning.
Detection
=========
Infected hosts will send large amounts of UDP traffic, typically saturating a local network connection. The BlackIce task bar icon will no longer allow the user to shut down BlackIce. It will display a message reading "Operation could not be completed. Access is denied".
Eventually, the system will crash. Infected systems are reported to show corrupted hard disks.
The worm will not write itself to disk. As a result, Virus scanners may not detect it…
Removal
=======
A reboot will remove the worm from the system. However, the worm causes random hard disk corruption and the system may no longer function.
Links
=====
ISS Black Ice downloads - http://blackice.iss.net/update_center/index.php
Vulnerability Information - http://xforce.iss.net/xforce/alerts/id/166
F-Secure Writeup - http://www.f-secure.com/v-descs/witty.shtml
Symantec - http://securityresponse.symantec.com/avcen…witty.worm.html
McAffee - http://vil.nai.com/vil/content/v_101118.htm …"
.