Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: Old Vulnerabilities Can Still Haunt You SANS ISC InfoSec Forums

Watch ISC TV. Great for NOCs, SOCs and Living Rooms:

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Old Vulnerabilities Can Still Haunt You

Andrew writes in to say ..

"It just goes to show that old vulnerabilities can still be effective. I recently ran across a site that our IDS detected via the ANI exploit.

http://ww.xx.yyy.zz    /oth/ms07-017.ani

http://ww.xx.yyy.zz    /oth/ms07-017.php

One of our machines accessed this site and got exploited, but they had the MS07-017 patch. Very strange. After de-obfuscating the javascript to see what exploits it uses, it turns out the site goes after MS03-011, MS06-014 and MS07-017. The system was patched for the two newer exploits, but not for the old Microsoft JVM vulnerability.

To make things worse, the site drops ntos.exe, which contains rootkit functionality. At least the binary is fairly well detected by AV vendors.

Depending on how security savvy your organization is, legacy issues can slip by for years.

If you think you're patched to current, how do you know for sure?

An occasional scan (using MBSA for example) will show you any missing patches.  In a perfect world, every system would be able to always be patched to current but if you are one of the people who can't deploy certain patches because it will break critical business functionality, these reports will be the start of the paper trail you will want for your audits showing why they can't be patched.


140 Posts
Jul 19th 2007

Sign Up for Free or Log In to start participating in the conversation!