Port scans could foreshadow Windows DNS Server exploit

Symantec warns of potential attack against unpatched Windows DNS Servers

A major spike in activity targeting TCP Port 1025 on Windows systems may be a sign that attackers are gathering intelligence for an upcoming attack against unpatched servers, Symantec warned Monday.

Symantec's DeepSight threat network has seen a "pretty sizable" increase in the number of sensors that have registered events on TCP Port 1025, said Mimi Hoang, group product manager with the company's security response team. "A normal level of activity would be 30 or so [source] IP addresses, give or take, with the number of events below 100," said Hoang. "But here we're seeing 1,400 to 1,500 IP addresses and more than 8,000 events.

"A spike like this doesn't happen without a reason," she said.

Hoang wouldn't definitively connect it with the Windows DNS Server Service vulnerability that Microsoft acknowledged last Thursday, but she did say, "We suspect it's because any high port above 1024 is associated with Microsoft's RPC [Remote Procedure Call protocol]. And 1025 is the first open port used by RPC."

The bug in Windows 2000 Server and Windows Server 2003 can be exploited by sending a malicious RPC packet via Port 105 or higher. Microsoft, in fact, has recommended that businesses block all inbound unsolicited traffic on ports 1024 and greater.

"Considering the recent Microsoft Windows DNS Remote Procedure Call Interface Vulnerability, this traffic spike may be associated with scanning and intelligence gathering aimed at assessing available Windows RPC endpoints," Symantec's warning said. "The traffic may also be indicating an increase in exploit attempts over TCP 1025, although this has not been verified at the time of this writing."

By midday Monday, Hoang had reiterated that Symantec had not confirmed any link between the port activity and actual exploits.

Exploits, however, continue to proliferate, Symantec and other security organizations said. Immunity in Miami Beach, Florida, released an exploit for the DNS server bug Monday for its Canvas penetration-testing framework, putting the total of publicly posted exploits at five. One recent exploit reportedly uses TCP and UDP Port 445, which Microsoft recommended blocking only yesterday.

Researchers are also positing additional attack strategies, in part because the normal routes through client PCs running Windows 2000, Windows XP or Windows Vista aren't available.

Maarten Van Horenbeeck, one of the analysts in SANS Institute's Internet Storm Center, noted that hosting service servers running Windows 2003 Server may be at risk because although they run DNS services as well as others -- HTPP and FTP, for example -- they're usually not shielded by a separate firewall. Active Directory servers may be in danger, too, said Van Horenbeeck.

"Active directory servers hosted on the internal network are often combined with DNS functionality," Horenbeeck said in an ISC research note. "These machines are usually less protected than DMZ DNS servers, and other functionality provisioned may require the RPC ports to be available. If your active directory server is compromised, the game is essentially over."

Microsoft has said several times that it is working on a patch, but it has not yet committed to a release date. The company's next scheduled patch day is three weeks away, on May 8.

Join the PC World newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Gregg Keizer

Computerworld
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Armand Abogado

HP OfficeJet 250 Mobile Printer

Wireless printing from my iPhone was also a handy feature, the whole experience was quick and seamless with no setup requirements - accessed through the default iOS printing menu options.

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?