Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

[SID: 24225] Web Attack: Blackhole Toolkit Website 5 detected. Traffic has been blocked

Created: 05 Jul 2011 | 5 comments
mchristal's picture
0 0 Votes
Login to vote

Hello,

Some of my users, from time to time, get this report in the IPS log.

What annoys me is that traffic direction is outgoing.

I tried scanning (including using SERT) / checking the computers but didn't find anything.

Is this detection a false positive ?

How to check ?

Many thanks

 

Comments

Vikram Kumar-SAV to SEP's picture
05
Jul
2011
0 Votes 0
Login to vote

I would say read this blog on

I would say read this blog on Blackhole Toolkit and make sure your browsers are updated with security updates.

https://www-secure.symantec.com/connect/blogs/blackhole-fever-continues

chris_delay's picture
05
Jul
2011
1 Vote +1
Login to vote

Don't know if it's false positive yet

I'd suggest grabbing a support tool with load point selected to get a deeper look first.

It *is* possible that it's a false positive, but we'd need more data.

Have you shut down whatever normally uses network traffic to rule other things out?  Like, for example, do the detections happen if, say, Outlook is open, and when it's closed, it doesn't?  This could help to narrow the scope down.

Optimus.prime's picture
05
Jul
2011
0 Votes 0
Login to vote

Hi

Hi, 

 My suggestion is , run sep support tool and get the log . Get the packet log . Call the techinical support .

They will take care . they will tell what to do ? ...

BNH's picture
05
Jul
2011
0 Votes 0
Login to vote

Our IPS signature for those

Our IPS signature for those type of detection are normally quite or if not very accurate.

Check in your logs which remote IP address it is talking to and check using your favorite search engine about reputation of that IP address.

Best to have our Support team assist  you in narrowing down the threat.

-- Got new virus ? Try update your defs here : ftp://ftp.symantec.com/AVDEFS/norton_antivirus/rap... --

VeeKee's picture
05
Jul
2011
0 Votes 0
Login to vote

Vulnerability assessment.

 

Hi,

It is quite possible that all Microsoft patches are installed. However, what about patches for toher softwares for example Adobe. The CVE website talks about some vulnerabilities related Microsoft, Sun Java, Adobe PDF.

Perform a Vulnerability assessment using automated tools. You can use automated tools to scan your network for vulnerabilities. You can scan for IP addresses and get granular to port numbers and protocols as well (TCP or UDP). These tools have updated information of vulnerabilities. Below are some tools. Nessus can be used for free for non commercial use.
 

 

Please ensure that the tool used to scan vulnerabilities is updated.

 

IBM ISS: http://www.iss.net/

Nessus : http://www.tenable.com/products/nessus

Core Impact http://www.coresecurity.com/content/core-impact-ov...

SAINT http://www.saintcorporation.com/

SARA http://www-arc.com/sara/

I have used Nessus, it is quite simple tool.

Here are some sites that provide information of the latest vulnerabilities.

Common Vulnerability Database http://cve.mitre.org/

Security focus http://www.securityfocus.com/

DHS National Vulnerability Database http://nvd.nist.gov

United States Computer Emergency Readiness Team http://www.us-cert.gov/

Open Source Vulnerability Database http://osvdb.org/

---------------------------------
Vikas
--
Don't forget to mark your thread as 'solved' with the answer that best helped you!