{"id":8207,"date":"2017-06-30T04:10:34","date_gmt":"2017-06-30T12:10:34","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/06\/30\/news-1982\/"},"modified":"2017-06-30T04:10:34","modified_gmt":"2017-06-30T12:10:34","slug":"news-1982","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2017\/06\/30\/news-1982\/","title":{"rendered":"TippingPoint Threat Intelligence and Zero-Day Coverage \u2013 Week of June 26, 2017"},"content":{"rendered":"<p><strong>Credit to Author: Elisa Lippincott (TippingPoint Global Product Marketing)| Date: Fri, 30 Jun 2017 12:00:57 +0000<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"205\" src=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205-300x205.jpg\" class=\"webfeedsFeaturedVisual wp-post-image\" alt=\"\" style=\"float: left; margin-right: 5px;\" srcset=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205.jpg 300w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205-125x85.jpg 125w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>The late 70s\/early 80s American television show <em>Three\u2019s Company<\/em> was one of my favorite shows growing up. The central theme of the show revolved around the lives of three roommates. Each episode usually involved a misunderstanding, then chaos would ensue. In the end, everything would turn out okay. Unfortunately, this week\u2019s episode of \u201cransomware in the news\u201d isn\u2019t over \u2013 there are still misunderstandings about the latest attack named \u201cPetya,\u201d even on what to call it!<\/p>\n<p>This past Tuesday, a ransomware attack similar to WannaCry shut down computers all over the world. It was initially thought that this new attack was an updated version of Petya from 2016. Others said it was a whole new malware that had Petya characteristics. Even further, now there is speculation that it\u2019s not ransomware at all \u2013 that its objective was to permanently destroy data. No extortion \u2013 just destruction \u2013 and no happy ending to this week\u2019s episode.<\/p>\n<p>Trend Micro TippingPoint continues to actively review the situation in order to recommend coverage for customers using TippingPoint solutions. As of this blog posting, we have verified the following vulnerability Digital Vaccine\u00ae (DV) filters that protect against the propagation of the Petya ransomware listed in the table below:<\/p>\n<p>&nbsp;<\/p>\n<table width=\"0\">\n<tbody>\n<tr>\n<td width=\"114\"><strong>CVE Number<\/strong><\/td>\n<td width=\"72\"><strong>DV Filter(s)<\/strong><\/td>\n<td width=\"108\"><strong>Category<\/strong><\/td>\n<td width=\"102\"><strong>Default Deployment<\/strong><\/td>\n<td width=\"252\"><strong>Comments<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"114\">CVE-2017-0144<\/p>\n<p>CVE-2017-0146<\/td>\n<td width=\"72\">27298<\/td>\n<td width=\"108\">Vulnerabilities<\/td>\n<td width=\"102\">Disabled<\/td>\n<td width=\"252\">SMB: Microsoft Windows SMB Remote Code Execution Vulnerability (EternalBlue)<\/td>\n<\/tr>\n<tr>\n<td width=\"114\">CVE-2017-0147<\/td>\n<td width=\"72\">27931<\/td>\n<td width=\"108\">Vulnerabilities<\/td>\n<td width=\"102\">Disabled<\/td>\n<td width=\"252\">SMB: Microsoft Windows SMBv1 Information Disclosure Vulnerability (EternalRomance)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p>Customers who wish to enforce generic policy at the network perimeter can use the following security policy filter to block all inbound SMBv1 traffic:<\/p>\n<p>&nbsp;<\/p>\n<table width=\"0\">\n<tbody>\n<tr>\n<td width=\"114\"><strong>CVE Number<\/strong><\/td>\n<td width=\"72\"><strong>DV Filter(s)<\/strong><\/td>\n<td width=\"108\"><strong>Category<\/strong><\/td>\n<td width=\"102\"><strong>Default Deployment<\/strong><\/td>\n<td width=\"252\"><strong>Comments<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"114\">None<\/td>\n<td width=\"72\">28471<\/td>\n<td width=\"108\">Security Policy<\/td>\n<td width=\"102\">Disabled<\/td>\n<td width=\"252\">SMB: SMBv1 Successful Protocol Negotiation<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p>Customers with questions or who need technical assistance can contact the TippingPoint Technical Assistance Center (TAC). For further information related to Trend Micro\u2019s response and our recommendations as a whole, please visit <a href=\"https:\/\/success.trendmicro.com\/solution\/1117665\">https:\/\/success.trendmicro.com\/solution\/1117665<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Zero-Day Filters<\/strong><\/p>\n<p>There are nine new zero-day filters covering three vendors in this week\u2019s Digital Vaccine (DV) package. A number of existing filters in this week\u2019s DV package were modified to update the filter description, update specific filter deployment recommendation, increase filter accuracy and\/or optimize performance. You can browse the list of <a href=\"http:\/\/www.zerodayinitiative.com\/advisories\/published\/\">published advisories<\/a> and <a href=\"http:\/\/www.zerodayinitiative.com\/advisories\/upcoming\/\">upcoming advisories<\/a> on the <a href=\"http:\/\/www.zerodayinitiative.com\/\">Zero Day Initiative<\/a> web site.<\/p>\n<p>&nbsp;<\/p>\n<p><strong><em>Foxit (4)<\/em><\/strong><\/p>\n<ul>\n<li>28746: ZDI-CAN-4721: Zero Day Initiative Vulnerability (Foxit Reader)<\/li>\n<li>28747: ZDI-CAN-4722: Zero Day Initiative Vulnerability (Foxit Reader)<\/li>\n<li>28748: ZDI-CAN-4723: Zero Day Initiative Vulnerability (Foxit Reader)<\/li>\n<li>28749: ZDI-CAN-4855: Zero Day Initiative Vulnerability (Foxit Reader)<\/li>\n<\/ul>\n<p><strong><em>\u00a0<\/em><\/strong><\/p>\n<p><strong><em>Hewlett Packard Enterprise (1)<\/em><\/strong><\/p>\n<ul>\n<li>28898: ZDI-CAN-4869: Zero Day Initiative Vulnerability (Hewlett Packard Enterprise Intelligent Management)<\/li>\n<\/ul>\n<p><strong><em>\u00a0<\/em><\/strong><\/p>\n<p><strong><em>Quest (4)<\/em><\/strong><\/p>\n<ul>\n<li>28751: ZDI-CAN-4224,4225,4229-4235,4237,4286,4316: Zero Day Initiative Vulnerability(Quest NetVault Backup)<\/li>\n<li>28893: ZDI-CAN-4226-4228: Zero Day Initiative Vulnerability (Quest NetVault Backup)<\/li>\n<li>28894: ZDI-CAN-4238,4287,4289,4292,4294: Zero Day Initiative Vulnerability (Quest NetVault Backup)<\/li>\n<li>28896: ZDI-CAN-4752: Zero Day Initiative Vulnerability (Quest NetVault Backup)<\/li>\n<\/ul>\n<p><strong><em>\u00a0<\/em><\/strong><\/p>\n<p><strong>Missed Last Week\u2019s News?<\/strong><\/p>\n<p>Catch up on last week\u2019s news in my <a href=\"http:\/\/blog.trendmicro.com\/tippingpoint-threat-intelligence-zero-day-coverage-week-june-19-2017\/\">weekly recap<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"http:\/\/blog.trendmicro.com\/tippingpoint-threat-intelligence-zero-day-coverage-week-june-26-2017\/\" target=\"bwo\" >http:\/\/feeds.trendmicro.com\/TrendMicroSimplySecurity<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Elisa Lippincott (TippingPoint Global Product Marketing)| Date: Fri, 30 Jun 2017 12:00:57 +0000<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"205\" src=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205-300x205.jpg\" class=\"webfeedsFeaturedVisual wp-post-image\" alt=\"\" style=\"float: left; margin-right: 5px;\" srcset=\"http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205.jpg 300w, http:\/\/blog.trendmicro.com\/wp-content\/uploads\/2016\/04\/TP-WeeklyBlog-300x205-125x85.jpg 125w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>The late 70s\/early 80s American television show Three\u2019s Company was one of my favorite shows growing up. The central theme of the show revolved around the lives of three roommates. Each episode usually involved a misunderstanding, then chaos would ensue. In the end, everything would turn out okay. Unfortunately, this week\u2019s episode of \u201cransomware in&#8230;<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10413],"tags":[10384,714,10415],"class_list":["post-8207","post","type-post","status-publish","format-standard","hentry","category-security","category-trendmicro","tag-network","tag-security","tag-zero-day-initiative"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/8207","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=8207"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/8207\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=8207"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=8207"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=8207"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}