DNS Exploit Used to Plant Backdoor on Windows Servers
By Scott M. Fulton, III | Published April 18, 2007, 6:58 PM
Security engineers are confirming that customers whose Windows servers were confirmed penetrated by a version of the recent DNS service exploit, were infected by any of three variants of backdoor worms identified by Sophos as W32/Delbot.
Sophos believes this to be a variant of the same worm that infected systems susceptible to vulnerabilities discovered in Symantec Anti-virus software late last year. In fact, versions of the worm that infect systems through the DNS service exploit are capable of spreading themselves via the Symantec exploit as well, along with other buffer overflow exploits.
The discovery is in indicator that the perpetrator may be more interested in identity theft and corporate electronic voyeurism than in disturbing the domain name system itself, as some sources earlier reported.
DNS services on Windows Server-based computers provide routing within company domains, not on the broader Internet.
In an update to its advisory today, Microsoft promised customers that something would be ready to address the DNS problem by May 8 -- the next Patch Tuesday -- although it wasn't explicit as to what that something was.
"We have teams around the world working on it twenty-four hours a day," reads the Security Response Center blog, "and hope to have updates no later than May 8, 2007 for the May monthly bulletin release." It went on to remind customers that the company has to write these updates in 133 languages, and tested independently.
Or just don't allow RPC over the internet. Port 53 is not affected.
Score: 0
|I can't fathom why someone would have RPC open to the world in the first place (other than being an idiot).
Score: 0
|Internet facing only allow port 53.
What about all the internal AD DC servers?
Could be fun if the virus is unleashed on the internal network?
Score: 0
|Its good to be on the greener side of the fence...
Score: 0
|And I remind MS that probably 90% of their Windows Server machines are running the English version, so releasing the patch ASAP for English should be the highest priority, then later add support for the rest...
Score: 0
|It's probable that they will if there are continued attacks.
Score: 0
|