Re: [VulnDiscuss] eEye - SQL Sapphire Worm Analysis
Aj Effin Reznor <[email protected]>
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <[email protected]> |
"Mark Litchfield was known to say....." > > Not quite - > > Your rational is that a 6 month old exploit doesn't need the > re-investigation, > esp. once a worm affecting it comes out. - What I was suggesting is that it > is an INTERESTING fact that it is 6 MONTHS TO THE DAY. In regards to the > re-investigation of a vulnerability once a worm is in the wild, if you have > the available resources, I would totally agree. OK, fair enough. I admittedly neglected getting into the point of the 6-months- to-the-day issue. This is *very* interesting and does suggest that it may very well have been a dormant payload, but how did it get there first without being noticed, and would it be using that same vector when it triggers (on the 6 month anniversary, in this case) ? Seems this type of activity would've been noticed before, unless the pre-sleep iteration was purposely designed to move at a MUCH slower rate... I'm not sure if capturing and analyzing the current variant (if it is indeed a variation on its earlier self) would yield anything, as it may have rewritten or morphed itself on delivery, tailoring itself for the type of traffic we are seeing now. > Face it, the "ease of use" of MS OS's leads to "ease of neglect" also - That > maybe your theory, it's certainly not mine. If a patch is released, where > possible it should be applied. I think the real problem is the This I agree totally with. Considering patching on MS's platforms, to some degree, is easier for MS-centric admins. To someone used to patching a Solaris box it's familiar territory and a comfortable one, but to someone unfamiliar with either, the double-click style of patching is much easier from the get-go. Which brings us to your next point: > communication between a software vendor releasing a patch / SP and the > network administrator becoming aware that firstly the problem exists and > secondly the impact it has to them. Agreed, patch / SP testing is required > to be performed first, but 6 months testing? I still feel some admins who just aren't up on patching never will be. There are some who may believe that "Trustworthy Computing" may indeed be saving the world. Dunno, I realize that's a damn far-fetched statement; it's not meant to be taken seriously at all and is only an extreme view of which many lessor degrees exist. Consider MS also has a historical tendency to label almost every vulnerability and medium or lower, and many admins may be less inclined to rush to grab the patch and begin testing it before rolling it out. Some aren't inspired to do so until a fire is lit under their seat by something like... a worm :) I don't disagree with you at all on any of these points, mind you, just elaborating a bit in a few different non-specific directions. > The hole that Code Red leveraged was Old News - Eeye's Advisory on the .IDA > ISAPI filter was released on June 18th 2001, Eeye's advisory on CODE RED was > the 17th of July. If by your calculations 1 month is OLD News as you put > it, then what is 6 months? On the internet, 6 months is almost an eternity :) I don't see why someone could take a full month to fully test a patch, let alone 6. The fact that machines are still coming online and trolling with CR and Nimda infections is beyond me. No reason a machine can't be brought online and either patched from a CD or at least kept behind a FW or two, but it still happens constantly. So, to summarize, I still think the analysis is worthwhile. I do also think that things should be patched ASAP, when applicable. And that it triggered at 6 months on the nose is either one hell of a coincidence or well planned. And it'd be great to find a SQL server with a wrong date on it that's running late and comb over it and see if there is a precursor to this worm which may be still dormant and perhaps looking a little different. Note to honeypot owners: Consider tossing out a machine with a date rolled back on purpose in the near future :) Otherwise Mark, much respect for you and your work, as always. Not trying to be argumentative for once (mark your calendars), just looking at things from what's maybe a different perspective. -aj. (Funny, another nimda scan (25/Jan/2003:16:03:26 -0800) as I'm writing this.) :)