SecurityFocus Newsletter #137
John Boletta <[email protected]>
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #137
-----------------------------
This Issue is sponsored by: Alcatel
Are your Internet communications secure? You may be surprised to learn
that the Internet Protocol (IP) is inherently vulnerable to security
threats. However, the IPSec protocol suite can be used to secure
communications over IP-based networks like the Internet. This article
presents a review of IPSec and how it works.
http://alcatel.emark1.com/irc_ipsec.asp?form=SecurityFocus_IPSec_032502
-------------------------------------------------------------------------------
I. FRONT AND CENTER
1. Securing Windows 2000 Communications with IP Security Filters 1
2. Preventing and Detecting Insider Attacks Using IDS
3. Behavior Blocking: The Next Step in Anti-Virus Protection
4. From Joke to Alkahest
II. BUGTRAQ SUMMARY
1. BitVise WinSSHD Numerous Connections DoS Vulnerability
2. PHP Nuke Account Compromise Vulnerability
3. Board-TNK Web Information Cross Site Scripting Vulnerability
4. Qualcomm Eudora Known File Attachment Location Vulnerability
5. ARSC Really Simple Chat Path Disclosure Vulnerability
6. BSD TCP/IP Broadcast Connection Check Vulnerability
7. BG Guestbook Cross-Site Scripting Vulnerability
8. PHPNetToolpack Remote Command Execution Vulnerability
9. PHPNetToolpack Insecure Search Path Vulnerability
10. Hosting Controller Weak Permissions Checking Vulnerability
11. Multiple Vendor Java Web Start Unsigned Application Vulnerability
12. Big Sam Web Root Disclosure Vulnerability
13. Multiple Vendor Java Virtual Machine Bytecode Verifier...
14. Linux 2.4 UDP Constant IP Identification Field...
15. VBulletin Cross-Site Scripting Vulnerability
16. Microsoft MSN Messenger Message Spoofing Vulnerability
17. Macromedia Flash Undocumented Action File Access Vulnerability
18. Macromedia Flash Undocumented Command Arbitrary File Write...
III. SECURITYFOCUS NEWS ARTICLES
1. Hackers Deface Thousands Of Domains Parked At Verisign
2. Heckenkamp Jailed at Court Appearance
IV.SECURITYFOCUS TOP 6 TOOLS
1. Aware v0.3.1
2. OpenRADIUS v0.9.3
3. TLSWrap v0.7b4
4. BlackHole v0.9.38
5. CryptoHeaven v1.1
6. mod_protection v0.0.2
V. SECURITYJOBS LIST SUMMARY
1. Penetration Testers for the UK (Thread)
2. CISSP in NYC (Thread)
3. Audit Supervisor - Open Systems, Richmond, VA (Thread)
4. Group Manager, Threat Administration, Northern, VA (Thread)
5. Audit Supervisor - Security, Richmond, VA (Thread)
6. seeking security position (Thread)
7. Seeking Information Security Position (Thread)
8. Sr. Information Security Solutions Sales Executive - NY, NJ, CT -
9. Sales Engineers for Chicago/Detroit (Thread)
10. TEST LAB MANAGER - AUSTIN, TX (Thread)
11. Senior Information Security Solutions Sales Executive - #693 - CA
12. Seeking Job Opportunities [GSEC] (Thread)
13. Business Development Position in DC/Maryland Area (Thread)
14. Senior Security Engineer (Thread)
15. Western US security sales postions (Thread)
16. Seeking Security Jobs in Texas (Thread)
17. SR. EMBEDDED ENGINEER - Austin, TX (Thread)
18. Pre sales Security consultant role (Thread)
19. Security Lead Architect (Thread)
20. AppSec Firms?? (Thread)
21. ATLANTA - Software Engineering Dept. Openings (Thread)
22. InfoSec Admin, Bala Cynwyd, PA (Thread)
23. InfoSec Administrator, Equity Trading Firm, Philadelphia (Thread)
24. Student Summer Intern (Thread)
25. Intrusion Analyst - Myrtle Beach, SC / Washington, DC (Thread)
26. Security Engineer Opportunity (Thread)
27. Needs to Fill 2 Positions for Federal (ASAP) (Thread)
VI. INCIDENTS LIST SUMMARY
1. increase in scans for RPC (Thread)
2. ORBZ shut down (Thread)
3. Sub7 (SubSeven), Win2k, and IE 5.5 (Thread)
4. Major DNS cache poisoning at Verisign/WorldNIC (Thread)
5. increase in scans for RPC (Thread)
6. Question about HTTP DDOS attacks. (Thread)
7. A new hack tool - tcp port 3139 ? (Thread)
8. A new hack tool - tcp port 3139 ? (Thread)
9. increase in smb scans (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
1. Testing zlib vulnerability (Thread)
2. IDS and SSL (Thread)
3. DOCSIS vulnerability (Thread)
4. Vulnerability in Apache for Win32 batch file processing -Remote
5. useless security@ contacts (Thread)
6. NAV to test (Thread)
7. Vulnerability in Apache for Win32 batch file processing - Remote
8. CSS implication (Thread)
9. IDS and SSL (Thread)
10. Firewall and IDS, (the second way). (Thread)
11. Firewall and IDS, (the second way). (Thread)
12. Patch for gawk overflow (Thread)
13. Simple question about ActiveX and IE (Thread)
14. Buffer overflow in awk (Thread)
15. phpBB2 remote execution command (Thread)
16. Wireless Legality- Netstumbler and kin (Thread)
17. Simple question about ActiveX and IE (Thread)
18. phpBB2 remote execution command (fwd) (Thread)
19. Wireless Legality- Netstumbler and kin (Thread)
20. phpBB2 remote execution command (Thread)
21. Stolen source? (Thread)
22. Stolen source? (Thread)
23. Securiteinfo.com new tool : Domino Hash Breaker (Thread)
24. try number 2.. SOLARIS LOGIN remote via telnetd (Thread)
25. CSS implication (Thread)
26. Buffer overflow in awk (Thread)
27. Vulnerability in WinZip password protection ? (Thread)
28. [FWD] MSIE vulnerability exploitable with Eudora (and
29. [Re: Rather large MSIE-hole] another variant (NAV and Finjan...
30. All systems with Internet Explorer IE 6.x /OPERA getting...
31. Fw: [Re: Rather large MSIE-hole] another variant (Thread)
32. Rather large MSIE-hole (Thread)
33. [Re: Rather large MSIE-hole] another variant (Thread)
34. idq.dll problem?? (Thread)
35. SSH 3.1.0 Potential Exploit + FIX (Thread)
36. about gawk (Thread)
37. Rather large MSIE-hole (Thread)
38. idq.dll problem?? (Thread)
39. Vulnerability in winzip password protection ? (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
1. Sub7 (SubSeven), Win2k, and IE 5.5 (Thread)
2. Outlook/Exchange (Thread)
3. Group Policies on OUs not Propagated (Thread)
4. account lockout problems (Thread)
5. Between Forest IPSec Implementation? (Thread)
6. HFNetChk Pro vs. other means to push out updates (Thread)
7. ISA-Server Problem (Thread)
8. Sub7 (SubSeven), Win2k, and IE 5.5 (Thread)
9. ISA-Server Problem (Thread)
10. Outlook/Exchange (Thread)
11. HFNetChk Pro vs. other means to push out updates (Thread)
12. Between Forest IPSec Implementation? (Thread)
13. HP Jet Direct for the Web (Thread)
14. Free HFNetChkPro Enterprise Demo Download (Thread)
15. AW: account lockout problems (Thread)
16. SQL2000 and hisecweb (Thread)
17. SQL2000 and hisecweb (Thread)
18. Firewall or IDS (Thread)
19. Firewall or IDS (Thread)
20. FW: HFNetChk Pro vs. other means to push out updates (Thread)
21. account lockout problems (Thread)
22. SecurityFocus Microsoft Newsletter #78 (Thread)
23. ISA server 2k AUDIO/VIDEO blocking rules problems... (Thread)
24. limited remote access to a W2K Server (Thread)
25. limited remote access to a W2K Server (Thread)
26. IPC$ share issue (Thread)
27. ISA server 2k AUDIO/VIDEO blocking rules problems... (Thread)
28. New HFNetChk Beta available (Thread)
29. Windows 2000 login hack: Followup (Thread)
30. Need help with W2K/IIS 5 opening POP3 connections (Thread)
31. Need help with W2K/IIS 5 opening POP3 connections (Thread)
32. Windows 2000 login hack (Thread)
33. Windows 2000 login hack (Thread)
IX. SUN FOCUS LIST SUMMARY
1. ANNOUNCE: new security BluePrint and Solaris Security Toolkit
2. zlib on Solaris? (Thread)
X. LINUX FOCUS LIST SUMMARY
1. SecurID and FreeS/WAN GW (Thread)
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. Securing Windows 2000 Communications with IP Security Filters, Part One
by Joe Klemencic
This article is the first of a two-part series that will describe the
various methods of implementing Windows 2000 IP Security filters that are
integrated with IPSEC communications. This installment will offer an
overview of IP security policies, including defining, testing, and
expanding IP security policies.
http://online.securityfocus.com/infocus/1559
2. Preventing and Detecting Insider Attacks Using IDS
by Nathan Einwechter
Shortly after lunch break, an employee angrily strides out of his
supervisors office, down two rows of desks, and into a single cubicle. He
slumps down into his chair and releases an exasperated sigh, as he runs
his hands through his hair in disappointment.
http://online.securityfocus.com/infocus/1558
3. Behavior Blocking: The Next Step in Anti-Virus Protection
by Carey Nachenberg
Before the arrival of the fast-spreading worm/blended threat, the staple
technology of anti-virus software fingerprinting - arguably provided
both preventative and proactive protection against the average computer
virus. That is, in the past, vendors were able to ship new fingerprints
for most viruses before they could achieve widespread distribution. This
is because traditional viruses spread slowly - only when humans exchange
infected files - on the order of days or weeks. Consequently, in the
majority of cases, anti-virus software blocked initial infection,
preventing corporate machines from being compromised and precluding the
need for costly manual cleanup and downtime.
http://online.securityfocus.com/infocus/1557
4. From Joke to Alkahest
by George Smith
Remember when we'd call someone who believes in magic computer viruses
with supernatural powers a fool? Today, we call him Senator.
http://online.securityfocus.com/columnists/68
II. BUGTRAQ SUMMARY
-------------------
1. BitVise WinSSHD Numerous Connections DoS Vulnerability
BugTraq ID: 4300
Remote: Yes
Date Published: Mar 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4300
Summary:
SSH Secure Shell 2 is a protocol which provides a secure connection
between computers. WinSSHD is a SSH Secure Shell 2 server for Microsoft
Windows systems, and is maintained by BitVise.
An issue has been reported in WinSSHD which could allow a user to cause a
denial of service condition on a SSH Secure Shell 2 server.
Reportedly, if a user establishes an unusual number of incomplete
connections, it is possible that the SSH Secure Shell server will not
properly free up sessions which have been unexpectedly terminated, thus,
leaking nonpaged kernel memory.
This issue exists in builds of WinSSHD prior to 2002-03-16 and has
currently been successfully exploited on a Windows 2000 Server.
Successful exploitation of this issue will deny legitimate users of the
service access to desired resources. A restart of the service is required
in order to regain normal functionality.
2. PHP Nuke Account Compromise Vulnerability
BugTraq ID: 4302
Remote: Yes
Date Published: Mar 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4302
Summary:
PHP-Nuke is a popular web based Portal system. It allows users to create
accounts and contribute content to the site. PostNuke was originally
forked from PHP-Nuke, and is a similar project.
A vulnerability has been reported in some versions of PHP-Nuke. The file
article.php includes functionality that allows a connected user to update
several settings. After these settings are modified, the user information
is refreshed from the database, and the remote user has a new cookie set
to reflect the updated information.
The remote user is identified by a username, password and UID, a unique
identifier. The vulnerable section of code checks if the user has
authenticated by verifying that the UID and password match. However,
before the cookie is refreshed, all relevant user information is retrieved
from the database based on the given username.
A malicious user may forge a cookie with a valid UID and password, and an
arbitrary username. When the vulnerable function is called, they will
recieve a new cookie authenticating them as the provided, unchecked
username.
Exploitation of this vulnerability will result in access to any account on
the vulnerable system, including those with administrative privileges.
3. Board-TNK Web Information Cross Site Scripting Vulnerability
BugTraq ID: 4305
Remote: Yes
Date Published: Mar 16 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4305
Summary:
Linux-Sottises Board-TNK is a PHP based discussion board. Originally
developed for Linux, it may run on any platform supporting PHP and MySQL.
A cross site scripting vulnerability has been reported in some versions of
Board-TNK. User supplied input is not properly escaped when used as the
Web information associated with a post. As a result, a malicious user may
include JavaScript statements. This code will then execute within the
context of the Board-TNK page, possibly resulting in the theft of cookie
data.
4. Qualcomm Eudora Known File Attachment Location Vulnerability
BugTraq ID: 4306
Remote: Yes
Date Published: Mar 16 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4306
Summary:
Eudora an email client for Microsoft Windows based systems. Eudora uses
Internet Explorer to assist in the viewing of html messages if the 'Use
Microsoft Viewer' option is enabled.
A weakness has been discovered in some versions of Eudora. When email is
received including a file attachment, the file is automatically stored in
a predictable location on the local system (typically the 'Attachment'
directory). An attacker may be able to use this knowledge to launch
further attacks against the vulnerable system.
In particular, this vulnerability may allow the execution of arbitrary
code when used in conjunction with BID 3867, Microsoft Internet Explorer
Arbitrary Program Execution Vulnerability.
5. ARSC Really Simple Chat Path Disclosure Vulnerability
BugTraq ID: 4307
Remote: Yes
Date Published: Mar 16 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4307
Summary:
ARSC Really Simple Chat is an online chat application maintained by Manuel
Kiessling.
It has been reported that ARSC Really Simple Chat discloses path
information. When a web user makes a request for a non-existent page, an
error page is served up containing the absolute path to the web root on
the host running the vulnerable software.
This information may aid in further attacks against the host running the
vulnerable software.
Reportedly, requesting an invalid language type will successfully exploit
this issue.
6. BSD TCP/IP Broadcast Connection Check Vulnerability
BugTraq ID: 4309
Remote: Yes
Date Published: Mar 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4309
Summary:
An error has been reported in the TCP/IP implementation of multiple BSD
derived operating systems, including FreeBSD, NetBSD and possibly OpenBSD.
RFC 1122 specifies that a TCP implementation must silently discard an
incoming SYN segment addressed to a multicast or broadcast address. The
vulnerable BSD implementation will drop a packet based on the link layer
address. However, it does not properly check the destination IP address
for this condition.
As a result, a carefully constructed packet may bypass this restriction.
Under some circumstances, an attacker may be able to use this
implementation flaw to bypass access control rules. If a firewall assumes
that it is not possible to initiate a TCP/IP connection to a broadcast
address, traffic may not be adequately filtered.
7. BG Guestbook Cross-Site Scripting Vulnerability
BugTraq ID: 4308
Remote: Yes
Date Published: Mar 16 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4308
Summary:
BG Guestbook is a freely available web application written in PHP, which
is back-ended by a MySQL database. It can display content using either
HTML or Flash. It will run on most Unix and Linux variants as well as
Microsoft Windows operating systems.
BG Guestbook does not perform sufficient validation of user-supplied
input, especially with regards to HTML tags. As a result, BG Guestbook is
prone to cross-site scripting attacks.
An attacker may inject encoded variants of HTML tags/script code into
various fields. This may enable a remote attacker to cause arbitrary
script code to be executed in the browser of a legitimate web user, in the
context of the site running the vulnerable software.
This issue is present in both the HTML and Flash versions of the
vulnerable guestbook software.
Successful exploitation may enable an attacker to steal cookie-based
authentication credentials or cause malicious content to be displayed in
the browser of a web user who views the website running the vulnerable
software.
8. PHPNetToolpack Remote Command Execution Vulnerability
BugTraq ID: 4303
Remote: Yes
Date Published: Mar 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4303
Summary:
PHPNetToolpack provides a web interface for finger, whois and traceroute.
It is written in PHP and will run on most Unix and Linux variants.
PHPNetToolpack is prone to an issue which may enable a remote attacker to
execute arbitrary commands on the underlying shell of the host running the
vulnerable software.
PHPNetToolpack does not adequately filter shell metacharacters (such as ;,
|, etc.) from user-supplied input. As a result, it is possible for a
remote attacker to execute arbitrary commands with the privileges of the
webserver process.
Successful exploitation of this vulnerability will enable the attacker to
gain local, interactive access on the host running the vulnerable
software.
9. PHPNetToolpack Insecure Search Path Vulnerability
BugTraq ID: 4304
Remote: No
Date Published: Mar 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4304
Summary:
PHPNetToolpack provides a web interface for finger, whois and traceroute.
It is written in PHP and will run on most Unix and Linux variants.
PHPNetToolpack is prone to an input validation error which may enable an
attacker to gain elevated privileges.
PHPNetToolpack does not use an absolute path when searching for the
traceroute program. If a local attacker creates their own program entitled
"traceroute" in a directory in the PHPNetToolpack search path, then that
program will be executed instead of the legitimate traceroute.
As a result, a local attacker may be able to trick PHPNetToolpack to
execute arbitrary attacker-supplied code with the privileges of the
webserver.
10. Hosting Controller Weak Permissions Checking Vulnerability
BugTraq ID: 4311
Remote: Yes
Date Published: Mar 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4311
Summary:
Hosting Controller is an application which centralizes all hosting tasks
to one interface. Hosting Controller gives every user the required control
they need to manage the appropriate web site relevant to them. Hosting
Controller runs on Microsoft Windows systems.
An issue has been discovered in Hosting Controller which could allow for
the unauthorized modification of directory contents.
The 'folderactions.asp' page enables a user to create or delete files and
directories on the server. The 'file_editor.asp' page allows a user to
modify the contents of web pages.
Due to a flaw in the validation of user privileges, a request composed of
'../' sequences along with either 'folderactions.asp' or
'file_editor.asp', will allow an unauthorized user to modify, delete or
create files and directories outside of the web root.
11. Multiple Vendor Java Web Start Unsigned Application Vulnerability
BugTraq ID: 4310
Remote: Yes
Date Published: Mar 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4310
Summary:
Java Web Start is an application-deployment technology. It is designed to
allow users to easily launch, access and download Java applications via a
web-page link.
It has been reported that vulnerable versions of Java Web Start may be
used to gain unauthorized access to restricted resources. This
vulnerability affects how the Java Networking Launching Protocol is used
to open unsigned applications, and may potentially compromise the Java
security model.
12. Big Sam Web Root Disclosure Vulnerability
BugTraq ID: 4312
Remote: Yes
Date Published: Mar 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4312
Summary:
Big Sam is a stand along guestbook application written in PHP. It was
originally developed for Linux, but may operate under a wide range of Unix
and Windows platforms.
A vulnerability has been reported in some versions of Big Sam. If an
extremely large parameter is passed to the script as the displayBegin
parameter, execution may result in excessive resource consumption or in an
error message. The error message will contain the full path to the web
root. The outcome of exploitation has been reported to depend on the
server configuration.
More specifically, when executed under PHP's "safe_mode", the script will
return an error message after a timeout period passes.
13. Multiple Vendor Java Virtual Machine Bytecode Verifier Vulnerability
BugTraq ID: 4313
Remote: Yes
Date Published: Mar 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4313
Summary:
Java virtual machine implementations contain a vulnerability that may
allow for malicious Java applets to escape the security sandbox.
The vulnerability is due to a data casting error. It is possible for an
applet constructed at the bytecode-level to perform an illegal casting
operation. By doing so, the security sandbox intended to limit the
operations that can be performed by an applet may be escaped. This can
result in the unrestricted execution of system-level code with the
privileges of the user running the virtual machine (possibly through a
browser).
It should be noted that this is a variant of a previously discovered
vulnerability BID 740.
14. Linux 2.4 UDP Constant IP Identification Field Fingerprinting Vulnerability
BugTraq ID: 4314
Remote: Yes
Date Published: Mar 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4314
Summary:
A fingerprinting threat has been reported in some versions of the 2.4
Linux kernel IP stack implementation. UDP packets are transmitted with a
constant IP Identification field of 0. Normally, the IP Identification
field is intended to be a reasonably unique value, and is used to
reconstruct fragmented packets.
An attacker may be able to exploit this weakness to discover the operating
system and approximate kernel version of the vulnerable system. This
information may be of value in launching further attacks against the
system.
The ability to fingerprint operating systems based on minor differences in
network implementations is well known, and not limited to Linux based
systems.
15. VBulletin Cross-Site Scripting Vulnerability
BugTraq ID: 4315
Remote: Yes
Date Published: Mar 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4315
Summary:
vBulletin is commercial web forum software written in PHP and back-ended
by a MySQL database. It will run on most Linux and Unix variants, as well
as Microsoft operating systems.
vBulletin includes functionality to allow forum users to post images in
messages. To post an image, a user simply includes a link to the image
inside of [img] tags. However, vBulletin does not adequately filter
encoded script code in image tags. As a result, it is possible for an
attacker to post a maliciously constructed forum message which contains
arbitrary script code. When the message is viewed by legitimate users of
the website, the script code will be executed in their web browser, in the
context of the website running the vulnerable software.
This may enable an attacker to steal cookie-based authentication
credentials from a legitimate user of the website running the vulnerable
software.
It is not known whether vBulletin Lite is also affected by this
vulnerability.
16. Microsoft MSN Messenger Message Spoofing Vulnerability
BugTraq ID: 4316
Remote: Yes
Date Published: Mar 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4316
Summary:
Microsoft's MSN Messenger is an instant messenging client for Windows
based machines, based on the Passport system.
A vulnerability has been reported in some versions of MSN Messenger.
Reportedly, it is possible to send messages through the server such that
they appear to have originated from an arbitrary user. An attacker may be
able to use this to initate a social engineering attack, or create a
denial of service situation.
It has been reported that client to client communications occur through a
central server, and are tracked by a Session ID. This Session ID is
granted by the server to any authenticated user, without the need for
further authentication. An attacker may forge the client side of the
communication, and misuse the Session ID to transmit messages with an
arbitrary sender.
It is possible that other versions of Messenger share this vulnerability.
This has not, however, been confirmed.
17. Macromedia Flash Undocumented Action File Access Vulnerability
BugTraq ID: 4321
Remote: Yes
Date Published: Mar 20 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4321
Summary:
Macromedia Flash is a modular package designed to enhance web browsing and
enables users to view various multimedia web content.
An issue has been reported in Flash, which could allow for a remote user
to access known local files. The undocumented FSCommand 'exec' action, is
used to execute external applications. In order to utilize this command
the absolute path to the requested application must be argumented.
As a result an attacker could compose a malicious swf file and access a
known file residing on the user's system.
If used in conjunction with BID 4320, exploitation of malicious code may
be possible.
This issue is being exploited by a virus called SWF/LFM, please see
reference section for more details on this malicious code.
18. Macromedia Flash Undocumented Command Arbitrary File Write Vulnerability
BugTraq ID: 4320
Remote: Yes
Date Published: Mar 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4320
Summary:
Macromedia Flash is a modular package designed to enhance web browsing and
enables users to view various multimedia web content.
An issue has been reported in Flash, which could allow for a remote user
to write to a file on a local user's system. The undocumented FSCommand
'save' action, is used to save main timeline variables of a movie to a
file on the local drive.
It is possible for a shockwave flash file (swf), using the FSCommand
'save', to be used in such a way that when downloaded and run directly
from a standalone Flash player, attacker specified data will be written to
a file on the user's system.
This issue is being exploited by a virus called SWF/LFM, please see
reference section for more details on this malicious code.
If used in conjunction with BID 4321, exploitation of malicious code may
be possible.
III. SECURITYFOCUS NEWS AND COMMENTARY
------------------------------------------
1. Hackers Deface Thousands Of Domains Parked At Verisign
By Brian McWilliams, Newsbytes
A security breach Tuesday involving Verisign's Network Solutions unit
disrupted potentially thousands of domain customers.
http://online.securityfocus.com/news/357
2. Heckenkamp Jailed at Court Appearance
By Kevin Poulsen
Alleged hacker angers judge with caps lock defense.
http://online.securityfocus.com/news/356
IV.SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Aware v0.3.1
by Russell Leighton [email protected]
Relevant URL:
http://www.elegant-software.com/software/aware/
Platforms: Linux, POSIX
Summary:
Aware is a high performance distributed event processing framework built
for systems management. It comes with probes for common network services
and system resources. Additionally, Aware allows the cross-correllation of
many different streams of information, and includes a Web-based reporting
interface.
2. OpenRADIUS v0.9.3
by Emile van Bergen / E-Advies
Relevant URL:
http://www.xs4all.nl/~evbergen/openradius-index.html
Platforms: FreeBSD, Linux, OpenBSD, Solaris, SunOS
Summary:
OpenRADIUS is a RADIUS server that allows you to use external data sources
for anything: shared secrets, accounts and passwords, profiles, session
database, NAS- or called/calling nr. ACLs, accounting storage, and much
more. It has a powerful external module interface that uses pre-spawned
subprocesses and pipes for communication, allowing you to implement
modules in any language that supports Unix pipe I/O. Its behaviour is
fully configurable using built-in business rule language, which gives you
full control over the request- and reply list. The language is
strongly-typed, but has both automatic and explicit type conversion.
3. TLSWrap v0.7b4
by Tomas Svensson
Relevant URL:
http://tlswrap.sunsite.dk/
Platforms: POSIX, UNIX
Summary:
TLSWrap is a TLS/SSL FTP wrapper/proxy for UNIX and WIN32, allowing you to
use your favourite FTP client with any TLS/SSL-enabled FTP server.
Features include full encryption of both control and data connections.
4. BlackHole v0.9.38
by Chris Kennedy [email protected]
Relevant URL:
http://the.groovy.org/blackhole.shtml
Platforms: UNIX
Summary:
Blackhole is a C program designed to stop spam and prevent unwanted
senders from sending you email. It is put in the .qmail file and will
divert spam and viruses to separate files which can be checked with an
IMAP client if configured to do so. It not only uses the RBL type servers,
but also checks against your own list of good/bad domains/users. You can
also block email that is sent to an address that is not specified in a
list of addresses to use for emailing you. Blackhole can log and keep the
email it blocks, and you can configure it to either reply with a message
of your choice or make it look like you don't exist on the system.
Finally, you can add relays to the list of relays that will be skipped by
the script. It also has subject line checking with ^ and $ matching lines,
and includes a virus checking server program.
5. CryptoHeaven v1.1
by CryptoHeaven Development Team
Relevant URL:
http://www.cryptoheaven.com/Download/Download.htm
Platforms: UNIX, Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
Intended for individuals in need of high security working in groups. It is
a secure online system integrating multi-user based security into email,
instant messaging, file sharing and online file storage in one unique
package. Provides real time communication for text and data transfers in a
multi user secure environment.
6. mod_protection v0.0.2
by Pierpaolo Giacomin
Relevant URL:
http://www.twlc.net/download.php?op=viewsdownload&sid=20
Platforms: UNIX, Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
mod_protection is an Apache module that integrates the basic function of
an IDS (Intrusion Detection System) and a firewall. When a malicious
client sends a request that matches a rule, the administrator will be
warned and the client gets an error message.
V. SECURITY JOBS SUMMARY
------------------------
1. Penetration Testers for the UK (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
2. CISSP in NYC (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
3. Audit Supervisor - Open Systems, Richmond, VA (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
4. Group Manager, Threat Administration, Northern, VA (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
5. Audit Supervisor - Security, Richmond, VA (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
6. seeking security position (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
7. Seeking Information Security Position (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
8. Sr. Information Security Solutions Sales Executive - NY, NJ, CT - #693 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
9. Sales Engineers for Chicago/Detroit (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
10. TEST LAB MANAGER - AUSTIN, TX (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
11. Senior Information Security Solutions Sales Executive - #693 - CA (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
12. Seeking Job Opportunities [GSEC] (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
13. Business Development Position in DC/Maryland Area (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
14. Senior Security Engineer (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
15. Western US security sales postions (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
16. Seeking Security Jobs in Texas (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/001501c1cf9e$8d6651c0$640010ac@md03
17. SR. EMBEDDED ENGINEER - Austin, TX (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
18. Pre sales Security consultant role (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/D17093FC3CC7D311B7530050BAAED81808695A@ERA01
19. Security Lead Architect (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/000001c1cf3a$35672710$6701a8c0@coitvaioF370
20. AppSec Firms?? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
21. ATLANTA - Software Engineering Dept. Openings (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
22. InfoSec Admin, Bala Cynwyd, PA (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
23. InfoSec Administrator, Equity Trading Firm, Philadelphia (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
24. Student Summer Intern (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
25. Intrusion Analyst - Myrtle Beach, SC / Washington, DC (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
26. Security Engineer Opportunity (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
27. Needs to Fill 2 Positions for Federal (ASAP) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/2F9F9FEEA510A54F832CB794004D205C07791C@STGHQ-MAIL01
VI. INCIDENTS LIST SUMMARY
-------------------------
1. increase in scans for RPC (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
2. ORBZ shut down (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
3. Sub7 (SubSeven), Win2k, and IE 5.5 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
4. Major DNS cache poisoning at Verisign/WorldNIC (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
5. increase in scans for RPC (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
6. Question about HTTP DDOS attacks. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
7. A new hack tool - tcp port 3139 ? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
8. A new hack tool - tcp port 3139 ? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
9. increase in smb scans (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. Testing zlib vulnerability (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/E16o9KF-00004Q-00@debian-vmware
2. IDS and SSL (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/00d501c1d115$6bed0b60$3678a8c0@spinalcord
3. DOCSIS vulnerability (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
4. Vulnerability in Apache for Win32 batch file processing -Remote command execution (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
5. useless security@ contacts (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
6. NAV to test (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
7. Vulnerability in Apache for Win32 batch file processing - Remote command execution (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/F4158E9E43A9D511BE1100065B043249655E2F@perfectopdc
8. CSS implication (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
9. IDS and SSL (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
10. Firewall and IDS, (the second way). (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
11. Firewall and IDS, (the second way). (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
12. Patch for gawk overflow (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
13. Simple question about ActiveX and IE (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
14. Buffer overflow in awk (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
15. phpBB2 remote execution command (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/002701c1cf8d$8ea3ea90$8f00a8c0@mt8100
16. Wireless Legality- Netstumbler and kin (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
17. Simple question about ActiveX and IE (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/070AF1B4E6A5D4119C5400B0D078A8DD01155B@LONDON
18. phpBB2 remote execution command (fwd) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
19. Wireless Legality- Netstumbler and kin (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/Pine.LNX.4.30.0203181109330.22247-100000@penguin.penguinmaster.com
20. phpBB2 remote execution command (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
21. Stolen source? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
22. Stolen source? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
23. Securiteinfo.com new tool : Domino Hash Breaker (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/005301c1cdd1$1b5fb2c0$0300a8c0@xxxxx
24. try number 2.. SOLARIS LOGIN remote via telnetd (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/003201c1cd8d$f2012a50$1502a8c0@XPMORGAN
25. CSS implication (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/D524A0BD0DE5FF4E951B6EC5F919FD7A05F25D7C@red-msg-01.redmond.corp.microsoft.com
26. Buffer overflow in awk (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
27. Vulnerability in WinZip password protection ? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
28. [FWD] MSIE vulnerability exploitable with Eudora (and IncrediMail) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
29. [Re: Rather large MSIE-hole] another variant (NAV and Finjan block this) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/000e01c1ccfa$f1453720$67bbfea9@hal900
30. All systems with Internet Explorer IE 6.x /OPERA getting Files into your disk even if download is DISABLED Can be used also by BAD webs to fill your DISK (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
31. Fw: [Re: Rather large MSIE-hole] another variant (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
32. Rather large MSIE-hole (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
33. [Re: Rather large MSIE-hole] another variant (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
34. idq.dll problem?? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/000401c1cc61$4942e7a0$0a01a8c0@visp
35. SSH 3.1.0 Potential Exploit + FIX (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
36. about gawk (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
37. Rather large MSIE-hole (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
38. idq.dll problem?? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
39. Vulnerability in winzip password protection ? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Sub7 (SubSeven), Win2k, and IE 5.5 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/04c901c1d12a$4b256ca0$93a606d0@micheal
2. Outlook/Exchange (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
3. Group Policies on OUs not Propagated (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
4. account lockout problems (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
5. Between Forest IPSec Implementation? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
6. HFNetChk Pro vs. other means to push out updates (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/8628ADFB314FD5119C390008C7E9638EE7C890@MESSENGER
7. ISA-Server Problem (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
8. Sub7 (SubSeven), Win2k, and IE 5.5 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/2D91E1663BD330459B5D32C08AC4668243541A@huskirk.FATHOMTECHNOLOGY.COM
9. ISA-Server Problem (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
10. Outlook/Exchange (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
11. HFNetChk Pro vs. other means to push out updates (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/005901c1d047$8e52a1c0$8500000a@BossMan
12. Between Forest IPSec Implementation? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
13. HP Jet Direct for the Web (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
14. Free HFNetChkPro Enterprise Demo Download (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
15. AW: account lockout problems (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
16. SQL2000 and hisecweb (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
17. SQL2000 and hisecweb (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/00c501c1cf87$b4173940$c8b3dec7@baserem2
18. Firewall or IDS (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
19. Firewall or IDS (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
20. FW: HFNetChk Pro vs. other means to push out updates (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
21. account lockout problems (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
22. SecurityFocus Microsoft Newsletter #78 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
23. ISA server 2k AUDIO/VIDEO blocking rules problems... (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/9D884881F5E1F24FB845967851720FC302C8DD8C@red-msg-12.redmond.corp.microsoft.com
24. limited remote access to a W2K Server (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/99DA073EAC4CD4118039001083F91D4BBEE00B@orlexchange01.curascript.com
25. limited remote access to a W2K Server (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/E7EAF01D6CD3D411938F00508BAF919B0504678B@simail17.server.bosch.com
26. IPC$ share issue (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/000c01c1cd38$a6776630$0100a8c0@jackass
27. ISA server 2k AUDIO/VIDEO blocking rules problems... (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
28. New HFNetChk Beta available (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/C3729BBB6099B344834634EC67DE4AE104D234B6@red-msg-01.redmond.corp.microsoft.com
29. Windows 2000 login hack: Followup (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
30. Need help with W2K/IIS 5 opening POP3 connections (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
31. Need help with W2K/IIS 5 opening POP3 connections (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
32. Windows 2000 login hack (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/D503BBD92FE9D2118A010008C75F644812F3AFFE@usnssexc20.us.kworld.kpmg.com
33. Windows 2000 login hack (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
IX. SUN FOCUS LIST SUMMARY
----------------------------
1. ANNOUNCE: new security BluePrint and Solaris Security Toolkit (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
2. zlib on Solaris? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
X. LINUX FOCUS LIST SUMMARY
---------------------------
1. SecurID and FreeS/WAN GW (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/[email protected]
XI. SPONSOR INFORMATION
-----------------------
This Issue is sponsored by: Alcatel
Are your Internet communications secure? You may be surprised to learn
that the Internet Protocol (IP) is inherently vulnerable to security
threats. However, the IPSec protocol suite can be used to secure
communications over IP-based networks like the Internet. This article
presents a review of IPSec and how it works.
http://alcatel.emark1.com/irc_ipsec.asp?form=SecurityFocus_IPSec_032502
-------------------------------------------------------------------------------