This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

"Big Yellow" Worm attacks Symantec Enterprise AV

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=1947
Last Updated: 2006-12-16 19:51:27 UTC

- http://www.informationweek.com/shared/prin…cleID=196700262
Dec. 15, 2006 - "A "significant" worm is successfully attacking unpatched Symantec enterprise anti-virus software because companies focus too much attention on Microsoft's flaws and ignore those from other vendors, a security company warned Friday. "Big Yellow," the name eEye Digital Security* has given the worm, was first captured Thursday by one of the company's honeypot systems. The worm, which also has a botnet component that turns a victimized machine into a zombie at the beck and call of its controller, exploits a critical vulnerability in Symantec AntiVirus and Symantec Client Security, two of the vendor's business security products. That vulnerability was reported to Symantec by eEye in May; the former fixed the flaw in June. Symantec's first notice of the vulnerability in AntiVirus and Client Security was posted May 26**, and patches were made available June 6. On Nov. 29, Symantec made note of the release of exploit code… Symantec's current advice is to patch Symantec AntiVirus and Client Security to protect systems against threats such as Big Yellow. A detailed guide on what versions must be patched and how is available on the Symantec support site***."

* http://research.eeye.com/html/alerts/AL20061215.html

** http://www.symantec.com/avcenter/security/…2006.05.25.html

*** http://service1.symantec.com/SUPPORT/ent-s…006052609181248

- http://www.symantec.com/enterprise/securit…-99&tabid=2
Updated: December 15, 2006
"…SUMMARY: W32.Sagevo is a worm that spreads by exploiting the Symantec Client Security and Symantec AntiVirus Elevation of Privilege (as described in Symantec Advisory SYM06-010**) and lowers security settings…"

:ph34r:
FYI…

- http://www.informationweek.com/shared/prin…cleID=196701740
Dec 22, 2006
"Symantec said Friday that it had detected another surge in scans for a port associated with a worm that's been sniffing for vulnerable software made by the security company and warned users to patch immediately in case the malicious code morphs into something more dangerous. Sensors monitored by Symantec's DeepSight threat management service have reported a significant spike in traffic related to TCP port 2967, which Symantec has traced to scans generated by the "Sagevo" worm, recently released malware looking for systems running some of the company's enterprise antivirus software…"
> http://isc.sans.org/port_details.php?port=2967

:ph34r:
FYI…

- http://isc.sans.org/diary.php?storyid=1998
Last Updated: 2007-01-03 08:51:56 UTC
"Thanks to Mike who sent us the following note about what he's seen on his network. Anyone else seeing similar movement?
'The Symantec AV attacks have picked up over the last day or so, as systems that were probably turned off over the holidays are turned on and infected by the worm. Almost all of the attacks we saw just before Christmas were from other .edus; now we are seeing more attacks from systems in countries other than the US. About 70% of the 186 systems that tried attacking us today were outside the US. Brazil and Taiwan take top honors for most attacking hosts.'"

> http://isc.sans.org/port_details.php?port=2967

:ph34r:
Ongoing…

- http://isc.sans.org/diary.html?storyid=2040
Last Updated: 2007-01-11 17:37:01 UTC
"We have captured a fair number of attacks against ports 2968 and 2967 over the past 24 hours and they appear to be identical in payload. The attack is effective against Symantec Antivirus version 10.0.2.2000 and below. The shellcode opens a bindshell on port 8555, which is then connected to and either ftp.exe or tftp.exe are used to download what appears to be a botnet client… v10.0.2.2002 remediates the problem…"

:ph34r: