Telecom and Logistics Associates 

Security NEWs Service: TLAnews

publication: Christian ALT  new6.gif (1031 bytes) TLAalert    Security Service 
Translate this page from:  Save Time and Money 

3.6.2000 SecurityHackers'top 10 list of  favorite security holes revealed
It's the 10 Most Wanted of cybersecurity. Administrators, act now

En français: La listes des "top 10" trous de sécurités favoris des pirates.
C'est les "top 10" les plus recherchés de la cybersécurité. Administrateurs agissez maintenant.

English version
 On Thursday, the System Administration, Networking and Security (SANS) Institute published a list of exploits most often used to gain illegal access to network servers.

The Systems Administration, Networking and Security Institute (SANS) has published a "Top 10 List" of the most popular ways hackers gain illegal access to network servers and computer systems.

The SANS list accounts for "probably 70 percent of the attacks occurring on the Internet," said the institute's director of research, Alan Paller. 

Cybercrime on the Rise
Hackers cost U.S. corporations $266 million (US$) last year, double the losses suffered during the previous three years. Cybercrimes being investigated by the U.S. Federal Bureau of Investigation (FBI) have more than doubled in the past year. The number of reported incidents in the private sector has soared from 3,700 in 1998 to 8,300 in 1999, according to a recent report by the Computer Emergency Response Team (CERT) at Carnegie Mellon University in Pittsburgh, Pennsylvania.

Ninety percent of those who responded to a CERT survey, mostly large corporations and government agencies, indicated some form of security breach last year and 70 percent reported serious breaches, such as financial fraud, denial-of-service attacks and data theft.

In response to security concerns, President Clinton convened an Internet security summit earlier this year after several incidents adversely affected some of the Internet's most popular sites.

Administrators take the right steps
"There are a lot of system administrators out there that are aware that security holes exist in their systems," said Jim Magadych, security research manager with Network Associates and a contributor to the report, "but they see the alerts coming out daily and are overwhelmed by sheer numbers."

The Top-10 list gives administrators a set of priorities, said Alan Paller.

Each exploit on the list is followed by a description about how to close the security hole.

Once a system administrator has fixed these 10, however, the job is not over, continued Paller. "As soon as the first large organization has fixed the first 10, we will release the next 10," he said.

Hackers Take Easy Routes
The SANS report found that most hackers gain access through a limited number of methods. "A few software vulnerabilities account for the majority of successful attacks because hackers are opportunistic -- taking the easiest and most convenient route," the report said. "They count on organizations not fixing the problem and they often attack indiscriminately by scanning the Internet for vulnerable systems."

While most of the SANS cyber-loopholes are already known to system administrators, the list shows them which security concerns should be made a priority.

Résumé en français

Jeudi dernier l'institut SANS (System Administration, Networking and Security) a publié la liste des 10 méthodes d'attaques les plus courantes utilisées par les pirates. Cette liste selon SANS devraient correspondre à 70 pourcents des attaques sur Internet.

Il y a beaucoup d'administrateurs systèmes qui savent que ces vulnérabilitées existent dans leurs systèmes, mais ils sont débordés et ne prennent pas les mesures nécessaires.

Cette liste propose des priorités aux administrateurs.

La majorité des pirates utilisent un nombre limité de methodes. Nous trouvons par ordre de fréquence les attaques sur

1. Les serveurs de domaine BIND

2. Les processus automatisés du web, CGI et autres formes d'interaction automatique avec des serveurs web

3. Les appels a des procedures distantes (RPC Remote Procedure Call)

4. Les vulnérabilités des serveurs web IIS de Microsoft

5. Le service de messagerie Sendmail sous UNIX

6. Partage de fichiers sous UNIX en utilisant NFS et administration permettent en utilisant des techniques de buffer overflow de prendre le contrôle de serverus UNIX à distance

7. Partage de disques et d'informations avec NETBIOS notamment en environnement Microsoft

8. Les noms d'utilisateur qui n'ont pas de mots de passe ou des mots de passe faibles. Et oui cela existe encore !

9. Les acces à la messagerie depuis Internet en utilisant les protocoles POP3 et IMAP4

10. Les outils de gestion permettent d'obtenir de l'information en utilisant le protocole SNMP, trop souvent avec des "community definient par les mots "public" et "private". Les pirates les utilisent pour obtenir de l'information , pour reconfigurer des systèmes ou mêmes les arrêter.

 
1. BIND is No. 1
Taking the No. 1 spot, a popular Internet service known as the Berkeley Internet Name Domain, or BIND, service is believed to have vulnerabilities that affect more than half of its installations.

 
2CGI are No. 2
Common gateway interface, scripts designed to add interactivity to Web sites took the No. 2 position. In many Web servers, default installation of example CGI scripts leave servers open to exploitation.
3. Remote procedure calls (RPC) are No. 3
The third most popular exploit takes advantage of functions called remote procedure calls, which allow one computer to execute programs on a second computer. The successful attack on U.S. military systems during the Solar Sunrise incident exploited the RPC vulnerabilities on hundreds of military servers. 
4. RDS security hole in the Microsoft Internet Information Server (IIS).
Microsoft’s Internet Information Server (IIS) is the web server software found on most web sites deployed on Microsoft Windows NT and Windows 2000 servers. Programming flaws in IIS’s Remote Data Services (RDS) are being employed by malicious users to run remote commands with administrator privileges. Other IIS flaws, such as .HTR files, are at least as common as exploits of RDS. 

Prudence dictates that organizations using IIS install patches or upgrades to correct all known IIS security flaws when they install patches or upgrades to fix the RDS flaw.

 

5. Sendmail buffer overflow weaknesses, pipe attacks and MIMEbo, that allow immediate root compromise.
Sendmail is the program that sends, receives, and forwards most electronic mail processed on UNIX and Linux computers. Sendmail’s widespread use on the Internet makes it a prime target of attackers. Several flaws have been found over the years.  In one of the most common exploits, the attacker sends a crafted mail message to the machine running Sendmail, and Sendmail reads the message as instructions requiring the victim machine to send its password file to the attacker’s machine (or to another victim) where the passwords can be cracked.

 

6. sadmind and mountd
Sadmind allows remote administration access to Solaris systems, providing graphical access to system administration functions. Mountd controls and arbitrates access to NFS mounts on UNIX hosts. Buffer overflows in these applications can be exploited allowing attackers to gain control with root access.

 

7. Global file sharing and inappropriate information sharing via NetBIOS and
Windows NT ports 135->139 (445 in Windows2000), or UNIX NFS exports on port
2049, or Macintosh Web sharing or AppleShare/IP on ports 80, 427, and 548.
These services allow file sharing over networks. When improperly configured, they can expose critical system files or give full file system access to any hostile party connected to the network. Many computer owners and administrators use these services to make their file systems readable and writeable in an effort to improve the convenience of data access. Administrators of a government computer site used for software development for mission planning made their files world readable so people at a different government facility could get easy access. Within two days, other people had discovered the open file shares and stolen the mission planning software.

When file sharing is enabled on Windows machines they become vulnerable to both information theft and certain types of quick-moving viruses. A recently released virus called the 911 Worm uses file shares on Windows 95 and 98 systems to propagate and causes the victim’s computer to dial 911 on its modem. Macintosh computers are also vulnerable to file sharing exploits.

The same NetBIOS mechanisms that permit Windows File Sharing may also be used to enumerate sensitive system information from NT systems. User and Group information (usernames, last logon dates, password policy, RAS information), system information, and certain Registry keys may be accessed via a "null session" connection to the NetBIOS Session Service. This information is typically used to mount a password guessing or brute force password attack against the NT target.

 

8. User IDs, especially root/administrator with no passwords or weak passwords.
Some systems come with "demo" or "guest" accounts with no passwords or with widely-known default passwords. Service workers often leave maintenance accounts with no passwords, and some database management systems install administration accounts with default passwords. In addition, busy system administrators often select system passwords that are easily guessable ("love," "money," "wizard" are common) or just use a blank password. Default passwords provide effortless access for attackers. Many attackers try default passwords and then try to guess passwords before resorting to more sophisticated methods. Compromised user accounts get the attackers inside the firewall and inside the target machine. Once inside, most attackers can use widely-accessible exploits to gain root or administrator access.

 

9. IMAP and POP buffer overflow vulnerabilities or incorrect configuration.
IMAP and POP are popular remote access mail protocols, allowing users to access their e-mail accounts from internal and external networks. The "open access" nature of these services makes them especially vulnerable to exploitation because openings are frequently left in firewalls to allow for external e-mail access. Attackers who exploit flaws in IMAP or POP often gain instant root-level control.

 

10. Default SNMP community strings set to ‘public’ and ‘private.’
The Simple Network Management Protocol (SNMP) is widely used by network administrators to monitor and administer all types of network-connected devices ranging from routers to printers to computers. SNMP uses an unencrypted "community string" as its only authentication mechanism. Lack of encryption is bad enough, but the default community string used by the vast majority of SNMP devices is "public", with a few "clever" network equipment vendors changing the string to "private". Attackers can use this vulnerability in SNMP to reconfigure or shut down devices remotely. Sniffed SNMP traffic can reveal a great deal about the structure of your network, as well as the systems and devices attached to it. Intruders use such information to pick targets and plan attacks.

 

Could Affect Insurance Coverage

The institute developed its report after consulting with almost 50 Internet security experts from a variety of government and private agencies. SANS officials admit, however, that it is far from a complete list. One recent survey by a British firm revealed that as many as 60 new computer vulnerabilities are found every month.

"The list could ultimately prove to be an important economic factor for e-commerce," said Paller. "The insurance industry may use this list as a foundation for whether the company can be insured."

 

Author information.
Copyright © [Telecom and Logistics Associates Sàrl]. All rights reserved.
Revised: juin 03, 2000 .

All information provided is of a general nature and is not intended to address the circumstances of any particular individual or entity. Although we endeavor to provide accurate and timely information, there can be no guarantee that such information is accurate as of the date it is received or that it will continue to be accurate in the future. No one should act upon such information without appropriate professional advice after a thorough examination of the facts of the particular situation.