Endpoint Protection

 View Only
Expand all | Collapse all

I keep getting web injection notifications.

ℬrίαη

ℬrίαηJul 16, 2013 09:15 AM

  • 1.  I keep getting web injection notifications.

    Posted Jul 15, 2013 09:35 AM

    Every now and then, I keep getting some sort of web injection notification. The most recent one has been something along the line of "Plesk command injection." After this appears, I run a virus scan, but nothing appears. 

     

    Is this a potential danger to my computer? What steps should I take to fix this?

     

    Thanks for the help,

    Non Sequitur



  • 2.  RE: I keep getting web injection notifications.

    Posted Jul 15, 2013 09:36 AM

    This is likely the IPS catching malicious traffic. Check the security log for confirmation as to which signature is firing.

    Do you get this when browsing the web?

    The IPS is blocking this so you won't find any infection on your machine. The infection attempt is being blocked.



  • 3.  RE: I keep getting web injection notifications.

    Trusted Advisor
    Posted Jul 15, 2013 09:45 AM

    Hello,

    Many threats inject into legitimate services, etc, to hide themselves.  SEP will block those.

    Check these links below:

    http://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=24187

    http://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=25297

    In such cases, there are few things, you need to look at:

    1) Make sure the autorun.inf is turned off.

    2) Check if the host file has not been changed or you check if the same is not tampered with.

    3) If there are any unknown Browser Helper Objects, please disable and remove their enteries from the registry.

    4) Make sure the server is up to date with all the Latest Microsoft Security patches and all Browsers are running the latest version.

    5) Run the Symantec Endpoint Support Tool, which would identify the suspicious file on your machine and the same have to be submitted the Symantec Security Response Team.

    Using Symantec Help (SymHelp) Tool, how do we Collect the Suspicious Files and Submit the same to Symantec Security Response Team.

    Hope that helps!!



  • 4.  RE: I keep getting web injection notifications.

    Posted Jul 15, 2013 01:13 PM

    Thank you for the help, everyone. I'm sure it's not what I'm browsing on the web, even more so after what I found in the logs...

     

    I went to the security logs as Brian81 recommended, and I found two entries from today and yesterday. They both had the same description:

     

    [SID: 26825] Web Attack: Plesk Command Injection attack blocked. Traffic has been blocked for this application: \DEVICE\HARDDISKVOLUME3\PROGRAM FILES (X86)\SKYPE\PHONE\SKYPE.EXE

     

    Does this mean that the attack (or whatever this turns out to be) is coming from Skype? 



  • 5.  RE: I keep getting web injection notifications.

    Broadcom Employee
    Posted Jul 15, 2013 01:16 PM

    check this

    http://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=26825

    Description

    This signature detects attempts to exploit php-cgi information disclosure vulnerability

    Additional Information

    Exploiting this issue allows remote attackers to view the source code of files in the context of the server process. This may allow the attacker to obtain sensitive information and to run arbitrary PHP code on the affected computer; other attacks are also possible.

     

     



  • 6.  RE: I keep getting web injection notifications.

    Posted Jul 16, 2013 09:15 AM

    Yes, this traffic is coming from Skype.



  • 7.  RE: I keep getting web injection notifications.

    Posted Jul 29, 2013 12:28 PM

    I want to know some more information about this. I just got attacked by the same thing. So I already know by reading this thread what this attack are able to do, but how did it happend and what should I do to prevent it from happening again? Does this mean that Skype is infected? Should I format my computer?

    Would really appreciate some more information.

    Greetings,

    David



  • 8.  RE: I keep getting web injection notifications.

    Posted Jul 29, 2013 12:34 PM

    Here is an additional writeup on it:

    http://static1.symanteccontent.com/security_response/attacksignatures/detail.jsp?asid=26825



  • 9.  RE: I keep getting web injection notifications.

    Posted Jul 29, 2013 12:44 PM

    Thank you. But i've already read that 5 times.

    " You should take immediate action to stop any damage or prevent further damage from happening."

    Action? Action to do what? It feels like they tell me "Yes, this is not good, you should do something about it".
    But without giving any information on how to 
    proceed..

    Is it network related like a SQL injection or is it something that have been downloaded and now infected?



  • 10.  RE: I keep getting web injection notifications.

    Posted Jul 29, 2013 01:05 PM

    First off the IPS is doing it's job by blocking the infection attempt. You're not actually infected so running a virus scan won't turn up anything. It is malicious traffic be detected and blocked which stops the infection attempt.

    Are you running a version of PHP? This seems to be an attack specific to it.

    Have you upgraded to the latest version of skype? There is a chance it could be a false positive.



  • 11.  RE: I keep getting web injection notifications.

    Posted Jul 29, 2013 01:23 PM

    Im not running PHP and yes I got the latest version of skype. Ye, could be a false positive. 

    Thanks for your help :)

    Greetings,

    David



  • 12.  RE: I keep getting web injection notifications.

    Posted Jul 29, 2013 01:40 PM

    What is the remote (attacking) IP address?

    Is this an ongoing issue or did it happen once? Or every time you use Skype?



  • 13.  RE: I keep getting web injection notifications.

    Posted Jul 29, 2013 01:53 PM

    The attack IP was: 95.110.132.11
    It have just happend once so far but I got it today for the first time.



  • 14.  RE: I keep getting web injection notifications.

    Posted Jul 29, 2013 02:02 PM

    This remote IP appears to be running a vulnerable version of Plesk web admin. It doesn't appear to be configured correctly.

    When skyping, did you receive and messages or links that you may have clicked on?



  • 15.  RE: I keep getting web injection notifications.

    Posted Jul 29, 2013 03:58 PM

    No, I did not. I was watching Youtube and Reddit at the time it happend. It pretty much just came out of nowhere.

    Edit: found this thread http://www.bleepingcomputer.com/forums/t/500524/need-help-understanding-attack-log/

    What is probably happening, is that these connections (with the HTTP requests that try to attack Plesk) connect to a port that is open on your machine.

    That port is probably opened by Skype, and that is why Norton is reporting Skype in the attack log.


    It sounds like this could be the case. And I am using a OpenVPN VPN so the IP i'm using isnt really hard to get for other VPN users. So maybe someone is trying to find ppl with PHP and Plesk installed by just testing every IP on the VPN server..



  • 16.  RE: I keep getting web injection notifications.

    Posted Jul 29, 2013 03:59 PM

    It certainly is a high possibility a mischevious person is out there poking around at different boxes to find soemthing misconfigured.