Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 33 guests online
EH-Net Donations

Enter Amount:
$

Google Ads
ChicagoCon 2008f
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Columnsarrow RichMarrow Internet Storm Center
Ethical Hacker Community Forums
October 12, 2008, 07:22:15 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Registration Now Open for ChicagoCon 2008f Oct 27 - Nov 2! Visit www.chicagocon.com.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Internet Storm Center  (Read 6276 times)
0 Members and 1 Guest are viewing this topic.
RichM
EH-Net Columnist
Newbie
*****
Offline Offline

Posts: 49


View Profile
« on: March 29, 2007, 08:47:14 PM »

For anyone not familiar, Internet Storm Center (ISC) is a great way to keep track of the current condition of the internet.  Each day a different administrator is assigned to keep diary entries.  These entries vary from current attack vectors, to discussions of critical patches for various OS' and applications.  The ISC also contains a list of the top 10 ports being attacked and a world map depicting attack trends. 

The ISC is a resource that helps to paint a picture of what is going on in the cloud, the problem is that most of us have 20 tasks to complete, and even the two minutes needed to browse the site it too much to spare.  Luckily (and if you are running Windows), Tom Liston of Intelguardians, wrote an application that sits in the system tray http://handlers.sans.org/tliston/ISCAlert.zip.

Simply download the .zip file, and double click the .exe.  If you have an environment which restricts executables, simply copy the .exe into C:\Documents and Settings\uuser\Start Menu\Programs\Startup.  In the system tray you will see a small icon of the world, which hopefully will be green, this indicates that everything is normal.  As the threat level increases, the color of the icon changes; for a complete breakdown of each threat level and the color which represents the threat see http://isc.sans.org/infocon.html
Logged
Cutaway
Jr. Member
**
Offline Offline

Posts: 96


Cutaway


View Profile WWW
« Reply #1 on: March 29, 2007, 11:35:05 PM »

For those of you using Yahoo Widgets there are several that monitor ISC.  I prefer the one I developed  Grin which you can find at http://widgets.yahoo.com/gallery/view.php?widget=40554

Although the default skin is rather large the circle skin can be minimized very small. 

Enjoy,
Cutaway
Logged

Go forth and do good things,
Cutaway
BillV
Hero Member
*****
Offline Offline

Posts: 804


View Profile
« Reply #2 on: March 30, 2007, 08:06:36 AM »

oOoOo, Neato :-D

Will try 'em both out.
Logged
jimbob
Sr. Member
****
Offline Offline

Posts: 297



View Profile WWW
« Reply #3 on: April 02, 2007, 02:00:38 AM »

For info, ISC Internet Threat Level was raised to yellow following the issues surrounding the Windows ANI bug. ISC is a good place to get headlines and links to current topics and worth a visit.

Jimbob
Logged
RichM
EH-Net Columnist
Newbie
*****
Offline Offline

Posts: 49


View Profile
« Reply #4 on: April 03, 2007, 07:50:58 PM »

I noticed that and to be honest was a little suprised taht they waited a full day.  When the vuln. was first announced the level was left at green but the next morning it was yellow.  Does anyone know if the the threat level is up to the discretion of the incident handler of the day, or if a governing body at SANS  makes that decision.
Logged
Negrita
Sr. Member
****
Offline Offline

Posts: 289



View Profile
« Reply #5 on: April 04, 2007, 04:29:00 PM »

RichM, you'll find your answer here; *ANI exploit code drives INFOCon to Yellow.
Quote
Published: 2007-03-31,
Last Updated: 2007-03-31 14:31:15 UTC
by Kevin Liston (Version: 1)
The ANI vulnerability has been been of recent concern.  I've been waiting for a few key events to be confirmed before adjusting the INFOCon.  We don't take these decisions lightly.

Rating systems such as Symantec's ThreatCon (currently at 2 of 4,)  FS/ISAC's Cyber Threat Advisory (currently at Guarded,) and our INFOCon (now at Yellow) all have their particular niche.  Symantec focuses on their AV and managed-security-service customers.  FS/ISAC focuses on financial institutions.  The Internet Storm Center's INFOCon intent is to "to reflect changes in malicious traffic and the possibility of disrupted connectivity."

In the initial stages of this event, we did not satisfy the criteria to raise the INFOCon level.  Now, we have a different landscape.

    * Exploit code has been publicly released which allows trivial modification to add any arbitrary payload.
    * The number of malicious sites reported is rising rapidly, limiting the efficacy of blacklisting.
    * The number of compromised sites pointing to malicious sites is also on the rise.

Recommendations:

    * Keep anti-virus up-to-date.  So far this is the most effective layer, particularly generic signatures that detect non-compliant ANI files.  Also, the secondary payloads downloaded by these exploits are often detectable (not always though.)
    * Content-filtering.  If your environment supports it, dropping ANI files (not based on file extention, but actual file-inspection) may be prudent until patches are deployed.  This will impact your myspace.com browsing experience though.

We intend to maintain INFOCon Yellow status and reassess every 24 hours. (~1400 UTC)

BTW, were back to GREEN for now.  Cheesy
Logged

CEH, CCSA NG/AI, NNCSS, MCP, MCSA 2003

There are 10 kinds of people, those that understand binary, and those that don't.
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.5 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.049 seconds with 22 queries.
 
Polls
Why a Career in Ethical Hacking:
 
Support EH-Net
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.