Windows DNS attack feared

Port scans a portent of upcoming exploits?

Attackers may be planning an attack against Windows servers running a vulnerable domain name system service, according to security researchers.

A major spike in activity targeting TCP Port 1025 on Windows systems may be a sign of intelligence gathering for an upcoming attack against unpatched servers, Symantec warned.

Symantec's DeepSight threat network has seen a "pretty sizable" increase in the number of sensors that have registered events on port 1025, said Mimi Hoang, group product manager with the company's security response team.

Nominum wants to make a packet in the hosted DNS market

"A normal level of activity would be 30 or so [source] IP addresses, give or take, with the number of events below 100," said Hoang. "But here we're seeing 1,400 to 1,500 IP addresses and more than 8,000 events.

"A spike like this doesn't happen without a reason," she said.

Hoang wouldn't definitively connect it with the Windows DNS Server Service vulnerability that Microsoft acknowledged last week, but she did say, "We suspect it's because any high port above 1024 is associated with Microsoft's RPC [Remote Procedure Call protocol]. And 1025 is the first open port used by RPC."

The bug in Windows 2000 Server and Windows Server 2003 can be exploited by sending a malicious RPC packet via port 105 or higher. Microsoft, in fact, has recommended that businesses block all inbound unsolicited traffic on ports 1024 and greater.

"Considering the recent Microsoft Windows DNS Remote Procedure Call Interface Vulnerability, this traffic spike may be associated with scanning and intelligence gathering aimed at assessing available Windows RPC endpoints," Symantec's warning said. "The traffic may also be indicating an increase in exploit attempts over TCP 1025, although this has not been verified at the time of this writing."

Hoang reiterated that Symantec has not confirmed any link between the port activity and actual exploits.

Exploits, however, continue to proliferate, Symantec and other security organisations said. Florida-based Immunity has released an exploit for the DNS server bug for its Canvas penetration-testing framework, putting the total of publicly posted exploits at five. One recent exploit reportedly uses TCP and UDP Port 445, which Microsoft recommended blocking only yesterday.

Researchers are positing additional attack strategies, in part because the normal routes through client PCs running Windows 2000, Windows XP or Windows Vista aren't available.

Maarten Van Horenbeeck, one of the analysts in SANS Institute's Internet Storm Center, noted that hosting service servers running Windows 2003 Server may be at risk because although they run DNS services as well as others - HTTP and FTP, for example - they're usually not shielded by a separate firewall. Active Directory servers may be in danger, too, said Van Horenbeeck.

"Active directory servers hosted on the internal network are often combined with DNS functionality," Horenbeeck said in an ISC research note. "These machines are usually less protected than DMZ DNS servers, and other functionality provisioned may require the RPC ports to be available. If your active directory server is compromised, the game is essentially over."

Microsoft has said several times that it is working on a patch, but it has not yet committed to a release date. The company's next scheduled patch day is three weeks away, on 8 May.


What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Related Security news

US military plotted revenge on Wikileaks

Considered using site to spread propaganda

Microsoft Excel glitch turns English into Chinese

Software giant admits update error

Iran hacks US spy websites, arrests cyber activists

Islamic Revolutionary Guards say opposition sites were waging cyber-war

Internet fraud losses doubled in 2009

FBI's IC3 report details most common Internet scams



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Email archiving: Top 10 myths and challenges

This survey looks at a number of challenges and myths around email archiving that may also slow adoption of full archiving.

Download Whitepaper

Strategic mobile deployments

Deploying mobile applications? Supporting multiple devices? See why mobile platforms should be part of your IT strategy.

Download Whitepaper

Creating an AUP: Common myths & mistakes

Avoid the common myths & mistakes when implementing your AUP

Download Whitepaper

Legal risks of uncontrolled email and web use

Exploring the challenges facing IT Mangers today and vital steps to ensure safe internet an email use by employees.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Virtualisation 2.0
Driving to higher ground beyond the basics

Virtualisation can deliver unparalleled efficiency and cost reductions to your business, allowing direct access to servers and guaranteeing a dependable, rapid response in times of crisis. Read this e-book to learn more about consolidation, discover the latest technologies and find out how to reduce the TCO of virtualisation.

Download E-Book
COLT White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One

Techworld are running a short survey to discover how UK businesses are managing Internet and email misuse in the Enterprise.

Complete Survey

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *