Re: [VulnDiscuss] eEye - SQL Sapphire Worm Analysis

Aj Effin Reznor <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>
"Mark Litchfield was known to say....."
> 
> Not quite -
> 
> Your rational is that a 6 month old exploit doesn't need the
> re-investigation,
> esp. once a worm affecting it comes out. - What I was suggesting is that it
> is an INTERESTING fact that it is 6 MONTHS TO THE DAY.  In regards to the
> re-investigation of a vulnerability once a worm is in the wild, if you have
> the available resources, I would totally agree.

OK, fair enough.  I admittedly neglected getting into the point of the 6-months-
to-the-day issue.  This is *very* interesting and does suggest that it may
very well have been a dormant payload, but how did it get there first without
being noticed, and would it be using that same vector when it triggers (on
the 6 month anniversary, in this case) ?  Seems this type of activity would've
been noticed before, unless the pre-sleep iteration was purposely designed to
move at a MUCH slower rate...  I'm not sure if capturing and analyzing the
current variant (if it is indeed a variation on its earlier self) would
yield anything, as it may have rewritten or morphed itself on delivery, tailoring
itself for the type of traffic we are seeing now.

 
> Face it, the "ease of use" of MS OS's leads to "ease of neglect" also - That
> maybe your theory, it's certainly not mine.  If a patch is released, where
> possible it should be applied.  I think the real problem is the

This I agree totally with.  Considering patching on MS's platforms, to some
degree, is easier for MS-centric admins.  To someone used to patching a 
Solaris box it's familiar territory and a comfortable one, but to someone
unfamiliar with either, the double-click style of patching is much easier
from the get-go.  Which brings us to your next point:

> communication between a software vendor releasing a patch / SP and the
> network administrator becoming aware that firstly the problem exists and
> secondly the impact it has to them.  Agreed, patch / SP testing is required
> to be performed first, but 6 months testing?

I still feel some admins who just aren't up on patching never will be.  There
are some who may believe that "Trustworthy Computing" may indeed be saving
the world.  Dunno, I realize that's a damn far-fetched statement; it's not
meant to be taken seriously at all and is only an extreme view of which many
lessor degrees exist.

Consider MS also has a historical tendency to label almost every vulnerability
and medium or lower, and many admins may be less inclined to rush to grab the
patch and begin testing it before rolling it out.  Some aren't inspired to do
so until a fire is lit under their seat by something like... a worm :)

I don't disagree with you at all on any of these points, mind you, just
elaborating a bit in a few different non-specific directions.

 
> The hole that Code Red leveraged was Old News  - Eeye's Advisory on the .IDA
> ISAPI filter was released on June 18th 2001, Eeye's advisory on CODE RED was
> the 17th of July.  If by your calculations 1 month is OLD News as you put
> it, then what is 6 months?

On the internet, 6 months is almost an eternity :)  I don't see why someone
could take a full month to fully test a patch, let alone 6.  The fact that
machines are still coming online and trolling with CR and Nimda infections
is beyond me.  No reason a machine can't be brought online and either patched
from a CD or at least kept behind a FW or two, but it still happens constantly.

So, to summarize, I still think the analysis is worthwhile.  I do also think
that things should be patched ASAP, when applicable.  And that it triggered at 6
months on the nose is either one hell of a coincidence or well planned.  And
it'd be great to find a SQL server with a wrong date on it that's running late
and comb over it and see if there is a precursor to this worm which may be still
dormant and perhaps looking a little different.

Note to honeypot owners:  Consider tossing out a machine with a date rolled back
on purpose in the near future :)

Otherwise Mark, much respect for you and your work, as always.  Not trying to be
argumentative for once (mark your calendars), just looking at things from what's
maybe a different perspective.


-aj.


(Funny, another nimda scan (25/Jan/2003:16:03:26 -0800) as I'm writing this.) :)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.