Endpoint Protection

 View Only
Expand all | Collapse all

OS Attack

  • 1.  OS Attack

    Posted Jan 10, 2013 11:52 PM

    Hi,

     

    Iam getting the following errors time and again. Found solution to be a microsoft patch installation but even after installing the same, the message is still coming. Please help:

     

    [SID: XXXXX] OS Attack: MSRPC Server Service RPC CVE-2008-4250 detected

     

    The client will block traffic from IP address <10.x.x.x> for the next 600 seconds.

     

    Regards,

    Anish



  • 2.  RE: OS Attack

    Posted Jan 10, 2013 11:59 PM

    HI,

     

    OS Attack: MSRPC Server Service RPC CVE-2008-4250

    http://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=23179

    Check this thread

    http://www.symantec.com/connect/forums/msrpc-server-service-rpc-cve-2008-4250-detected

    http://www.symantec.com/connect/forums/need-help-sid-23179-os-attack

    Check this thread

    https://www-secure.symantec.com/connect/forums/sid-23179-os-attack-msrpc-server-service-rpc-cve-2008-4250-attack-blocked-traffic-has-been-bl



  • 3.  RE: OS Attack

    Broadcom Employee
    Posted Jan 11, 2013 12:00 AM

    make sure the patch has been installed correctly.

    OS Attack: MS Windows Server Service RPC Handling CVE-2008-4250

    http://www.symantec.com/business/security_response/attacksignatures/detail.jsp?asid=23179

    Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability

    http://www.securityfocus.com/bid/31874/solution



  • 4.  RE: OS Attack

    Posted Jan 11, 2013 08:29 AM

    Run the Conficker removal tool on the affect machines. Download here:

    W32.Downadup Removal Tool

    http://www.symantec.com/security_response/writeup.jsp?docid=2009-011316-0247-99



  • 5.  RE: OS Attack

    Trusted Advisor
    Posted Jan 11, 2013 08:47 AM

    Hello,

    Take a close look at the logs you're reviewing where you see these alerts...if the IP address(es) are external, there's not much you can do...the nature of the internet is to allow unsolicited attempts for communication.

    If the communications are coming from external sources, you can certainly block those IP addresses at the perimeter firewall, and other things such as leveraging intrusion prevention (assuming you've got that, or it's part of the perimeter firewall).

    If the attacks are coming from WITHIN your network, you'll need to do some seluthing to get to the bottom of what's actually attacking and deal with it.  My gut, however, leads me to believe that your logs show external IP addresses.

    Script kiddies out there are constantly running programs that will try to use exploits on machines...odds are low that you're specifically being targeted.

    If the IP addresses in the logs are external to your network, the only way you can completely block the alerts is to configure your perimeter firewall to not allow incoming external traffic to this machine...which, I suspect, would completely negate the usefulness of the server itself.

    Also, Please check the Symantec Article below and get assisted.

    OS Attack: MS Windows Server Service RPC Handling CVE-2008-4250

    http://www.symantec.com/business/security_response/attacksignatures/detail.jsp?asid=23179

    Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability

    http://www.securityfocus.com/bid/31874/solution

    You may be also interested to have a look at this Thread: 

    https://www-secure.symantec.com/connect/forums/multiple-attacks-showing-sepm

    Hope that helps you to upload all the updates on the system.!!


  • 6.  RE: OS Attack

    Posted Jan 12, 2013 12:25 AM

    Hi Mithun,

     

    Thanks for the post. The ip address are not external ip's but belonging in our network.

     

    Regards,

    Anish



  • 7.  RE: OS Attack

    Trusted Advisor
    Posted Jan 14, 2013 10:40 AM

    Hello,

    You may be also interested to have a look at this Thread: 

    https://www-secure.symantec.com/connect/forums/multiple-attacks-showing-sepm

    Hope that helps!!

     



  • 8.  RE: OS Attack

    Posted Jan 14, 2013 04:46 PM

    If the IP in the block alert belongs to a machine from within your network then that machine is infected. Verify it has AV installed at the minimum, preferably all features, and is not missing any Microsoft patches, specifically MS08-067.



  • 9.  RE: OS Attack

    Posted Mar 14, 2013 02:08 AM

    Hello Mithun,

    We are also getting same kind of attacks on all computers on network from four IP, all are internal in which three are Windows XP machine with Norton AV installed and one is Ububtu 12.04 LTS machine.

    Please help me in figuring out what should I do.

    Thanks,

    Anubhav



  • 10.  RE: OS Attack

    Posted Mar 15, 2013 04:51 AM

    Can you verify the remote host (source of attack) is installed with working AV and related windows patches?

    Sometimes there could be more than 1 source machine... do check and go through