I. Description
Based on preliminary analysis, the sadmind/IIS worm exploits a
vulnerability in Solaris systems and subsequently installs software to
attack Microsoft IIS web servers. In addition, it includes a component
to propagate itself automatically to other vulnerable Solaris
systems. It will add "+ +" to the .rhosts file in the root user's home
directory. Finally, it will modify the index.html on the host Solaris
system after compromising 2,000 IIS systems.
To compromise the Solaris systems, the worm takes advantage of a two-year-old
buffer overflow vulnerability in the Solstice sadmind program. For more
information on this vulnerability, see
-
http://www.kb.cert.org/vuls/id/28934
-
http://www.cert.org/advisories/CA-1999-16.html
After successfully compromising the Solaris systems, it uses a seven-month-old
vulnerability to compromise the IIS systems. For additional information about
this vulnerability, see
-
http://www.kb.cert.org/vuls/id/111677
Solaris systems that are successfully compromised via the worm exhibit the following characteristics:
Microsoft IIS servers that are successfully compromised exhibit the
following characteristics:
- Modified web pages that read as follows:
fuck USA Government
fuck PoizonBOx
contact:sysadmcn@yahoo.com.cn
-
Sample Log from Attacked IIS Server
2001-05-06 12:20:19 10.10.10.10 - 10.20.20.20 80 GET /scripts/../../winnt/system32/cmd.exe /c+dir 200 -
2001-05-06 12:20:19 10.10.10.10 - 10.20.20.20 80 GET /scripts/../../winnt/system32/cmd.exe /c+dir+..\ 200 -
2001-05-06 12:20:19 10.10.10.10 - 10.20.20.20 80 \
GET /scripts/../../winnt/system32/cmd.exe /c+copy+\winnt\system32\cmd.exe+root.exe 502 -
2001-05-06 12:20:19 10.10.10.10 - 10.20.20.20 80 \
GET /scripts/root.exe /c+echo+<HTML code inserted here>.././index.asp 502 -