This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

MS06-040, MS06-042 and MS06-046 Exploits on the Web

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=1574
Last Updated: 2006-08-09 11:55:47 UTC
"…It certainly didn't take long for some to start making available (those I've seen so far are not for free) exploits against the vulnerabilities described in MS06-040, MS06-042 and MS06-046, which where only released yesterday*.
Those of you're still testing patches, you'd better hurry up and get some of these fixed before you get hit.
Just as a reminder:
- Filtering ports 135-139 and 445 helps against MS06-040; as do private VLANs (preventing client-client communication in the switch). None of those will help your fileserver, so patching is critical.
Since there are still unpatched vulnerabilities in this software, filtering still remains crucial.
- If you cannot apply MS06-042: stop using MSIE now, use an alternate browser.
- Switching away to a browser not doing ActiveX (almost any will do) should help protect you against MS06-046 attacks as well.
But the best solution is to patch and do the above, layered defences!"
* https://isc.sans.org/diary.php?storyid=1573

:ph34r:
Another player makes a recommendation:

- http://www.dhs.gov/dhspublic/display?content=5789
August 9, 2006
"The Department of Homeland Security (DHS) is recommending that Windows Operating Systems users apply Microsoft security patch MS06-040 as quickly as possible. This security patch is designed to protect against a vulnerability that, if exploited, could enable an attacker to remotely take control of an affected system and install programs, view, change, or delete data, and create new accounts with full user rights… US-CERT has issued an alert* through the National Cyber Alert System and conducted a series of briefings with federal Chief Information Officers and Chief Information Security Officers, and critical infrastructure sectors through Information Sharing and Analysis Centers. Additionally, all federal agencies are required to provide US-CERT with regular updates on their patching status…"
* http://www.us-cert.gov/cas/techalerts/TA06-220A.html

:ph34r:
FYI…

MS06-040 exploit in the wild
- http://isc.sans.org/diary.php?compare=1&storyid=1592
Last Updated: 2006-08-13 00:12:49 UTC
"We have caught a live exploit against a Windows 2000 Server. The pcap packets of the exploit fire the signatures in Sourcefire VRT for the vulnerability described in MS06-040.
Update: The latest bleedingsnort signatures fire also on the pcap: "BLEEDING-EDGE EXPLOIT NETBIOS SMB-DS DCERPC NetrpPathCanonicalize request (possible MS06-040)"

It looks like it's building a botnet (as we expected).
* The exploit was carried out over port 445/TCP.
* In a second phase of the exploit, it connected back out to IRC servers running on non-standard ports on redundant hosts.
The md5 of the bot itself is: MD5: 9928a1e6601cf00d0b7826d13fb556f0

…We have a report of at least one second capture of what is on first looks is the same malware or at least something very related to it."
* https://isc1.sans.org/diary.php?storyid=1557

:ph34r:
FYI…

- http://isc.sans.org/diary.php?compare=1&storyid=1592
Last Updated: 2006-08-13 02:38:06 UTC (…Version: 6)
"…The pcap packets of the exploit fire the signatures in snort for the vulnerability described in MS06-040… Since this is a botnet, these bots might do much more depending on what the controller has in store for them. So unfortunately you basically only have the choice to clean them by wiping the disk if you ever want to trust the machines again…
…wgareg.exe messes in the windows registry. One of the things it adds is a description of itself: "Ensures that your copy of Microsoft Windows is genuine and registered. Stopping or disabling this service will result in system instability.". Right … It also appears to change settings related to firewalls and sharing.
LURHQ has also a story* on the same…"

* http://www.lurhq.com/mocbot-ms06040.html
"…Release Date - August 12, 2006
Summary
LURHQ's Threat Intelligence Group has detected a Mocbot variant in the wild utilizing the MS06-040 vulnerability in order to spread in a worm-like fashion.
File Details
Filename: wgareg.exe
Filesize: 9,609 bytes
MD5: 9928a1e6601cf00d0b7826d13fb556f0
SHA1: 352a276346eabde7bfce9efee732a973e0d26baa
Packer: MEW
CME Number: none assigned …
…At the time of this writing, anti-virus detection is not especially broad, with only 1/3 of all anti-virus engines tested reporting the file as malware or flagging it as suspicious. None of them recognize it as a Mocbot variant…"

:ph34r: :ph34r:
FYI…

MS06-040 (exploit) - wgareg / wgavm update
- http://isc.sans.org/diary.php?storyid=1594
Last Updated: 2006-08-13 13:37:49 UTC
"We have received samples and infection reports from several sources. It looks like there are so far two different binaries involved:

9928a1e6601cf00d0b7826d13fb556f0 wgareg.exe

2bf2a4f0bdac42f4d6f8a062a7206797 wgavm.exe

The former, wgareg.exe, apparently shows up simply as ".exe" (blank-dot-exe) on infected systems and only later gets renamed or copied to wgareg.exe. AV protection is slowly coming online…"

:ph34r:
FYI…

Spammers Exploiting Newly Detailed Windows Flaw
- http://blog.washingtonpost.com/securityfix…latest_mic.html
August 13, 2006
"…Update, 8:06 p.m. ET: It may be that Microsoft in its advisory* is talking a different threat that SANS and LURHQ are highlighting. For one thing, Microsoft calls this threat "Win32/Graweg," but I could find no links in Google to any writeup on that either at Microsoft or another third-party anti-virus company… (you'll notice that as of 4:39 p.m. ET Microsoft's own anti-virus service had not detected as malicious the threat that Stewart and SANS were pointing out)…"

* http://www.microsoft.com/technet/security/…ory/922437.mspx

:huh:
FYI…

- http://isc.sans.org/diary.php?storyid=1601
Last Updated: 2006-08-15 20:06:26 UTC
"The folks are LURHQ have done some excellent analysis of the latter stages of Mocbot. Exactly what is the final goal of this bot? Find out here*…"
* http://www.lurhq.com/mocbot-spam.html
"…Obviously there is money being made here - the economics of exploiting end-user systems for the purposes of spam has been an established business model for at least four years now. Can your antivirus protect you from becoming part of the proxy network? Not by itself - we saw that with the release of Mocbot, only 1/3 of tested antivirus scanners detected it, even though it was little changed from the variants released over the previous six months. Another factor is the use of the IRC C&C to provide instructions to automatically download the second-stage trojan executable. If your antivirus company is not spying on these control channels on an ongoing basis, there is no way to know what malware is being installed after the initial infection. So, when you remove Mocbot from an infected system, the malware that was subsequently downloaded may go undetected for some time - which is fine with the botherder, as that's the executable they really wanted you to run anyway. In the case of a system that has become infected with a trojan, worm or virus, unless you are a malware expert, the only way to be 100% sure the system is malware-free is to completely wipe the hard drive and reinstall the operating system. The lesson here is to not become infected in the first place - which means upgrade and patch early, and maintain several levels of defense against malware, including firewalls, antivirus, system hardening. The most important defense however, is maintaining a general awareness of the threats facing Internet users each day…"

:oops: :ph34r:
FYI…

Worm Adds MS06-040 To Four-Bug Attack Kit
- http://www.techweb.com/article/printableAr…_section=700028
August 22, 2006
"A network-aware worm that's added the MS06-040 vulnerability to its bag of exploitable bugs is on the make, Symantec said Tuesday. Dubbed "Randex.gel*," the worm opens a back door on any compromised computer, then tells the system to listen for additional commands over an IRC (Internet Rely Chat) channel. "It looks like it's a derivative of other Randex variants," said Oliver Friedrichs, director of Symantec's security response group. "But it's added the MS06-040 vulnerability". Earlier variations of the Randex worm clan exploited other patched flaws in Windows, including three fixed by MS04-007, MS05-017, and MS05-039. The last of those, a patch that quashed a bug in Windows' Plug and Play service, was used by the Zotob worm to hammer enterprises, in particular media companies, in 2005. Randex.gel adds the vulnerability in the Windows Server service that Microsoft patched Aug. 8 to the three-some. "It's usually just hours before [attacks] plug in new exploit code to existing worms to build something new," said Friedrichs. The exploit in Randex.gel appears to be identical, or if not, very similar to the code released two weeks ago by HD Moore of Metasploit. The new Randex variant can spread in several different ways, Symantec's analysis reported, including via the MSN Messenger, AOL Instant Messenger, Yahoo Messenger, and ICQ instant messaging clients. It will also propagate through network shares and Microsoft SQL servers. If Randex.gel finds an SQL server, it will try to execute a job to infect any databases on the system. In addition, the worm tries to steal account information when users of the eGold electronic payment system log onto the egold.com Web site…"

* http://www.symantec.com/enterprise/securit…-99&tabid=1

:ph34r: :wtf:
FYI…

MS06-040 Worm
- http://isc.sans.org/diary.php?compare=1&storyid=1660
Last Updated: 2006-09-01 12:41:08 UTC
"For the past several days, the Handlers here at ISC have received all kinds of emails about the recent increase in scanning on port 139*… It appears, in typical antivirus fashion to be named several things: McAfee is calling it "W32/SDbot.worm!MS06-040", Sophos is calling it, "W32/Vanebot-A", and Symantec is calling it, "W32.Randex.GEL". (Yes, it's been out for a couple days)… How does it spread.. well, it uses: MS04-007, MS05-017, MS05-039, and of course, our favorite bug of the moment, MS06-040…"

* http://isc.sans.org/port_details.php?port=139