SecurityFocus Newsletter #145

Stephen Entwisle <[email protected]>
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #145
------------------------------
This issue sponsored by CipherTrust.

SECURE THE EMAIL GATEWAY **FREE EMAIL SECURITY WHITE PAPER

Stop SPAM, HACKERS, VIRUSES, WORMS, and TROJAN HORSES from
threatening your Exchange and Notes servers. Powered by the Sophos
Anti-Virus engine, IronMail has INTEGRATED DEFENSES against hackers
and spam, provides secure message delivery and secures Outlook Web
Access, all in a hardened gateway appliance.

FREE white paper on email security risks:
http://www.ciphertrust.com/article/c0502_03s_10.htm
___________________________________________________

I. FRONT AND CENTER
     1. Bad Company
     2. Port Sentry For Attack Detection, Part One
     3. Memo to Microsoft: Stay Secretive, Please
     4. Securing Privacy Part Three: E-mail Issues
     5. Slot Machine Justice for Melissa Author
     6. Cutting-Edge High Tech Crime Fighting: Best Practices in Computer Forensics
     7. Meeting IT Security Benchmarks Through IT Audits
II. BUGTRAQ SUMMARY
     1. nCipher MSCAPI CSP Install Wizard 5.50 Incorrect Key Generation Vuln
     2. Phorum Reply Email Address Script Injection Vulnerability
     3. id Software Quake II Server Remote Information Disclosure Vuln
     4. Opera Frame Location Same Origin Policy Circumvention Vuln
     5. SonicWall SOHO3 Content Blocking Script Injection Vuln
     6. SunATM Agent SNMP Request Handling Vulnerability
     7. Bannermatic World Readable Data Files Information Disclosure Vuln
     8. NOCC Webmail Script Injection Vulnerability
     9. GNU SharUtils UUDecode Symbolic Link Attack Vulnerability
     10. SuSE AAA_Base_Clean_Core Script RM Race Condition Vulnerability
     11. Hosting Controller DSNManager Directory Traversal Vulnerability
     12. tinyproxy HTTP Proxy Memory Corruption Vulnerability
     13. Cisco Content Service Switch HTTPS Post Denial Of Service Vuln
     14. SuSE Shadow File Truncation Vulnerability
     15. CGIScript.net Information Disclosure Vulnerability
     16. LevCGI NetPad Unauthorized File Access Vulnerability
     17. Swatch Throttled Event Reporting Vulnerability
     18. Hosting Controller Import Root Directory Command Execution Vuln
     19. Xerox DocuTech Printer Weak Default Configuration Vulnerability
     20. Microsoft Internet Explorer Zone Spoofing Vulnerability
     21. Microsoft Internet Explorer Cookie Content Disclosure Vuln
     22. Phorum Remote Command Execution Vulnerability
     23. Xerox DocuTech Scanner Insecure Default Configuration Vuln
     24. Cisco IDS Device Manager Arbitrary File Read Access Vulnerability
     26. Gaim Sensitive World Readable Temporary File Vulnerability
     27. NetWin DNews Remote Access Vulnerability
     28. Cisco Content Service Switch XML Denial Of Service Vulnerability
     29. Cisco Cache Engine Default Configuration Arbitrary User Proxy Vuln
     30. Microsoft Internet Explorer Content-Disposition Handling...
     31. kv Poll Cookie Security Bypass Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
     1. 'Deceptive Duo' Hacker Under House Arrest
     2. O'Reilly Leaks Geeks' Info
IV.SECURITYFOCUS TOP 6 TOOLS
     1. mail2sh v1.0
     2. GrabItAll
     3. Saint Jude v0.10 (Solaris)
     4. Enigmail v0.2
     5. WatchMan v0.20
     6. Distributed Checksum Clearinghouse v1.1.0
V. SECURITYJOBS LIST SUMMARY
     1. Security Engineer Opportunity (Thread)
     2. Network Security Intrusion Software Developer, Austin TX...(Thread)
     3. Chicago based Unix Net Sec Engineer!...(Thread)
     4. Washington, D.C. Area Opening (Thread)
     5. WireX Software Engineer (Thread)
     6. Looking for Security Consultant/Engineer/Mgmt work ...(Thread)
     7. Looking for INFOSEC/IA/IW Professionals (Thread)
     8. Director of Security role (Thread)
     9. Hot Security Software Vendor - Major Account Executives (Thread)
     10. Security Engineer - NY Metro (Thread)
     11. Security Sales Account Manager-NYC (Thread)
     12. Seeking Regional Sales Engineer - CISSP - ...(Thread)
     13. Security Engineer in Washington DC (Thread)
     14. Resume - Experienced Information Security Engineer (Thread)
     15. Principal for Enterprise Security Solutions (Thread)
     16. Security Engineers Needed - Sierra Vista, Arizona (Thread)
     17. Intrusion Detection & Forensics (Thread)
     18. A technical security profesional still looking for a job (Thread)
     19. Security Engineer - Northern California (Thread)
     20. Forensics Investigations Analyst - NJ - #704 (Thread)
     21. Security Engineer/Architect Available (Thread)
     22. Application for Network Security Engineer (Thread)
VI. INCIDENTS LIST SUMMARY
     1. Windows Systems Defaced/destroyed, plus Port 3389 attacks (Thread)
     2. explanation of port 1433 scans... (Thread)
     3. Windows Systems Defaced (Thread)
     4. Nimda type attacks with broken GETs (Thread)
     5. Got 'em.  (was "Re: gw.ocg-corp.com") (Thread)
     6. gw.ocg-corp.com (Thread)
     7. [unisog] Windows Systems Defaced/destroyed, ...(Thread)
     8. Windows Systems Defaced/destroyed,...(Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. about cookies (Thread)
     2. Generating shellcode (Thread)
     3. GIF87a (Thread)
     4. PhotoParade hacking? (Thread)
     5. ps under FreeBSD (Thread)
     6. Multiple vendors web server source code disclosure...(Thread)
     7. Xerox DocuTech problems (Thread)
     8. Sonicwall SOHO Content Blocking Script Injection...(Thread)
     9. Sonicwall SOHO Content Blocking Script Injection...(Thread)
     10. #2 ps under FreeBSD (Thread)
     11. Phorum 3.3.2a remote command execution (Thread)
     12. Xerox DocuTech problems (Thread)
     13. A Proactive Approach from a vendor... (Thread)
     14. PDF modifications? (Thread)
     15. PDF modifications? (Thread)
     16. Security holes : mcNews (Thread)
     17. Exploiting Buffer Overflows on Compaq Tru64 and No-Exec Stack (Thread)
     18. Exploiting Buffer Overflows on Compaq Tru64 and No-Exec Stack (Thread)
     19. Apple OSX sliplogin overflow (Thread)
     20. NCSec: Local Buffer Overflow in Microsoft's Net Messenger...(Thread)
     21. Thinking about Security rules... (Thread)
     22. About  PHPImageview (Thread)
     23. Thinking about Security rules... (Thread)
     24. Vulnerability in PHP ?!? (Thread)
     25. Sybase default passwords? (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. About ping request? (Thread)
     2. Hotfixes overwritten? (Thread)
     3. XP or not XP - enterprise desktop? (Thread)
     4. Hotfixes overwritten? (Thread)
     5. XP or not XP - enterprise desktop? (Thread)
     6. Bypassing Windows 2000 Domain Password settings (Thread)
     7. renaming the IIS metabase (Thread)
     8. setting "List" (RX-unspecified) with xcacls.exe (Thread)
     9. setting "List" (RX-unspecified) with xcacls.exe (Thread)
     10. renaming the IIS metabase (Thread)
     11. Bypassing Windows 2000 Domain Password settings (Thread)
     12. SecurityFocus Microsoft Newsletter #86 (Thread)
     13. using SecEdit across different NT installations (Thread)
IX. SUN FOCUS LIST SUMMARY
     1. Locking down a network connection to a single machine. (Thread)
     2. Replies (Thread)
X. LINUX FOCUS LIST SUMMARY
     1. protecting DHCP servers (Thread)
     2. plain text vs. html (Thread)
XI. SPONSOR INFORMATION

I. FRONT AND CENTER
-------------------
1. Bad Company
By George Smith

You don't have much choice in anti-virus products if you make your
purchasing decisions based on Consumer Reports.

http://online.securityfocus.com/columnists/83

2. Port Sentry For Attack Detection, Part One
By Ido Dubrawsky

Portsentry is an attack detection tool developed by Psionic Technologies.
This article is the first of a two-part series that will describe in
detail how Portsentry works from both a theoretical and a technical point
of view.

http://online.securityfocus.com/infocus/1580

3. Memo to Microsoft: Stay Secretive, Please
By John Lasser

Unix and Linux security owes much to openness and public disclosure, but
Microsoft is too far gone for sunshine to do any good.

http://online.securityfocus.com/columnists/82

4. Securing Privacy Part Three: E-mail Issues
By Scott Granneman

This is the third article in a four-part series that will examine privacy
concerns as they relate to security. The first installment in the series
examined hardware-based privacy issues. The second part discussed
software-based issues. This article will discuss privacy issues that are
particularly relevant to e-mail.

http://online.securityfocus.com/infocus/1579

5. Slot Machine Justice for Melissa Author
By Mark Rasch

Under capricious computer crime sentencing rules, virus-writer David Smith
managed to get the right prison term for all the wrong reasons.

http://online.securityfocus.com/columnists/81

6. Cutting-Edge High Tech Crime Fighting: Best Practices in Computer Forensics
June 17-18, 2002
American Management Association, Washington, DC

Walk away able to perform computer forensic examinations that will not
only yield sound evidence but will also hold up in a court of law! Learn
to find, collect and preserve digital evidence, and present the evidence
in court. Also learn to successfully combine private and public computer
forensics forces to investigate computer crimes. Keynote speech by
Microsoft's Chief Security Strategist Scott Charney. Public sector
employee discounts available.

For more information, call 800-280-8440, or visit http://www.frallc.com
(see InfoTech events).

7. Meeting IT Security Benchmarks Through IT Audits
August 8-9, 2002, Washington, DC.
By Information Technology Research Associates

Agenda: www.frallc.com <http://www.frallc.com/>  (see InfoTech Events)

Have your IT security solutions kept pace with evolving threats?  Until
you conduct a thorough IT security audit, you won't know until after a
breach has occurred. To help you achieve the most ROI on your security
investment, ITRA is proud to present a step-by-step practical guide to
auditing your enterprise's IT security. For more information, call
800-280-8440.


II. BUGTRAQ SUMMARY
-------------------

1. nCipher MSCAPI CSP Install Wizard 5.50 Incorrect Key Generation Vulnerability
BugTraq ID: 4729
Remote: No
Date Published: May 13 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4729

Summary:

nCipher produces a range of hardware and software security products. An
issue has been reported in version 5.50 of the install wizard for the
MSCAPI CSP key generator under Windows 2000.

The nCipher key management model allows application keys to be provided
based on two requirements. A key may be provided to any nCipher module
appropriately programmed with a user's Administrator Cards, or may be
protected by additional Operator cards.

Under some circumstances, a key generated such that it should be protected
by an Operator card will in fact be generated as only module protected.
This may result in weaker security than anticipated, and under some
deployments reduce or break the security model.

This is caused by a problem in the installation process. An installation
option, a user may specify if generated keys are to be module protected,
or protected by an additional Operator Card Set.

If cardset protection is selected and a new Operator Card Set is not then
created by the user, default key generation may be set to only module
protection.

nCipher Support <[email protected]> has provided details on how to
determine if a given installation is vulnerable. They suggest running the
command 'c:\nfast\bin\csputils.exe -d' from the command line, and
examining key data to determine if incorrect protection levels have been
set.

For a key with Operator Card Set protection:

   Detailed report for container ID #cbfb7b11909b40ddc50da759d6029...

   Filename:       key_mscapi_container-cbfb7b11909b40ddc50da759d6...
   Container name: expimptst
   User name:      NCIPHER\james
   User SID:       s-1-5-21-1594850079-719136693-34565100-1111
   CSP DLL name:   ncsp.dll
   No signature key.
   Filename for key exchange key is key_mscapi_expimptst-ncsp-ujam...
      Key was generated by the CSP
      Key hash:    92c60edf376c26e9ee76db3a2a70dd031636a218
      Key is recoverable.
      Key is cardset protected.
         Cardset name:             mscapi-grimsby
         Sharing parameters:       1 of 1 shares required.
         Cardset hash:             4eb80f966c13bd735cb50f29ef19e5e...
         Cardset is persistent.

For a key with module protection:

   Filename:       key_mscapi_container-32a16394a3ffe52eb4db1127d8...
   Container name: james
   User name:      NCIPHER\james
   User SID:       s-1-5-21-1594850079-719136693-34565100-1111
   CSP DLL name:   ncsp.dll
   No signature key.
   Filename for key exchange key is key_mscapi_6fa4c59efefb6c01db6...
      Key was generated by the CSP
      Key hash:    6fa4c59efefb6c01db6eca9f1eadbb17158fc2a8
      Key is recoverable.
      Key is module protected.

2. Phorum Reply Email Address Script Injection Vulnerability
BugTraq ID: 4739
Remote: Yes
Date Published: May 13 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4739

Summary:

Phorum is a PHP based web forums package.

A script injection issue has been reported in Phorum. It has been reported
possible to inject script code into the body of a message response.
Reportedly, this may be done by constructing a malicious email address
included as part of a message reply.

The injected script code may execute in the web client of arbitrary users
who view the post, within the security context of the Phorum site.

Attackers may potentially exploit this issue to hijack web content or to
steal cookie-based authentication credentials. It may be possible to take
arbitrary actions as the victim user, including posting or deleting
content.

3. id Software Quake II Server Remote Information Disclosure Vulnerability
BugTraq ID: 4744
Remote: Yes
Date Published: May 15 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4744
Summary:

Quake II is a multiplayer game released by id Software. The source code
has been made publically available, and versions are available for Windows
and Linux. A vulnerability has been reported in some versions of the Quake
II server.

Quake II allows variable expansion in commands. For example, the
$rcon_password variable will be automatically expanded to the system
password. Under normal usage, these variables are expanded on the client
side before being transmitted to the server.

However, it has been reported that a modified or artifically constructed
client may fail to expand this variable. When the server then processes
the command, it will expand the variable within it's local context. As a
result, a number of system parameters may be disclosed to a remote
attacker, including the server password.

An attacker may exploit this vulnerability to gain administrative rights
to the vulnerable server.

4. Opera Frame Location Same Origin Policy Circumvention Vulnerability
BugTraq ID: 4745
Remote: Yes
Date Published: May 15 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4745
Summary:

Opera is a web browser product created by Opera Software, and is available
for a range of operating systems including Windows and Linux. A
vulnerability has been reported in some versions of the Opera Browser.

In modern browsers, script code executing in the context of one website
should not be able to access the properties of another. This is a security
feature known as the 'same origin policy', and it is put in place to
prevent malicious websites from interacting with and possibly stealing
sensitive information from others in different windows.

It is possible to bypass the same origin policy in some versions of Opera.
Javascript executing within the context of a page is able to modify the
location parameter of an IFRAME or FRAME within the page. By setting the
location to a javascript: URL, code may be injected into the context of
the frame.

Exploitation of this vulnerability results in arbitrary Javascript code
executing within an arbitrary context. The consequences can be severe. It
may be possible to access cookie data, including auhentication
credentials, or to take actions as an authenticated user.

It has also been demonstrated possible to execute script code, accessing
some elements of the local system. A provided proof of concept provides
access to information about the local file system layout.

5. SonicWall SOHO3 Content Blocking Script Injection Vulnerability
BugTraq ID: 4755
Remote: No
Date Published: May 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4755
Summary:

The Sonicwall SOHO3 is an Internet security appliance that provides
firewall security solutions.

Reportedly, a vulnerability exists in the product that allows for a script
injection attack to be launched from a malicious user within the internal
LAN. The vulnerability has been reported in Sonicwall SOHO3 firmware
revision 6.3.0.0 and ROM version 5.0.1.0.

It is possible to configure Sonicwall to block domains from a list of user
entered domains. Sonicwall will deny local users access to the websites
that have been blocked. A malicious user may be able to inject script code
as part of a URL of a blocked domain. Attempts to access blocked domains
will be entered into the log files of Sonicwall. An administrator viewing
the log files will automatically cause the malicious script code execute.

Sonicwall will log attempts to access banned domain names. Injected script
code within the URL of a banned domain will automatically execute when the
log files are viewed. It is reported that any script code will be able to
execute. This may lead to a denial of service attack by a malicious user.

It should be noted that an attacker must be aware of a domain that is
already on the blocked list of the SOHO3 appliance.

If the attacker's script code is injected into the logfile then the
administrator will not be able to access the log normally.  To regain
access to the logs the appliance will need to be rebooted.  It should be
noted that rebooting the appliance will cause the logs to be cleared and
will effectively eliminate any indication in the logs of which user
initiated the attack.

6. SunATM Agent SNMP Request Handling Vulnerability
BugTraq ID: 4732
Remote: Yes
Date Published: May 13 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4732

Summary:

The SunATM software package is an SNMP agent that supports the ATM UNI and
LAN Emulation MIBs.  This agent may be integrated with network management
systems such as SunNet Manager.

The SunATM SNMP agent suffers from a vulnerability related to the handling
of SNMP requests.  It is possible to crash the service by transmitting to
it a maliciously constructed SNMPv1 request PDU.  The nature of how the
PDU is malformed is not currently known.

The resultant crash may be due to a buffer overflow condition.  If this is
the case, attackers may be able to exploit this vulnerability to execute
arbitrary code.

7. Bannermatic World Readable Data Files Information Disclosure Vulnerability
BugTraq ID: 4738
Remote: Yes
Date Published: May 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4738

Summary:

Bannermatic is a banner ad rotation system maintained by Joe DePasquale of
GetCruising.

Reportedly, ban.log, ban.bak, ban.dat and banmat.pwd are world readable
files which all contain highly sensitive data. It is possible to gain
access to the information contained in either file by submitting a HTTP
request for the file.

ban.log stores visiting user information including hour/date, IP address
etc. The ban.bak file contains URLs relative to the banner being rotated.
ban.dat contains information on the image itself, number of user click
throughs, page views etc. banmat.pwd contains the administrator password
hash.

Obtaining the information contained in any of the above files could assist
an attacker in further attacks against the host.

8. NOCC Webmail Script Injection Vulnerability
BugTraq ID: 4740
Remote: Yes
Date Published: May 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4740

Summary:

NOCC is a web based email client implemented in PHP4.  It includes support
for POP3, SMTP and IMAP servers, MIME attachments and multiple languages.

NOCC webmail displays all email, including text only email, as HTML. NOCC
does not make any attempt to escape potentially harmful data in email
messages.  As a result, a malicious user may be able to craft an email
containing script code and then send it to any NOCC webmail user.  When
the message is viewed in a browser, the script code will execute.

The script code may modify or obtain any properties of the webmail
session, including the cookie set by the server.  This attack may result
in the adversary gaining access to the victim's mailbox.

9. GNU SharUtils UUDecode Symbolic Link Attack Vulnerability
BugTraq ID: 4742
Remote: No
Date Published: May 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4742

Summary:

Sharutils is a freely available, open source suite of tools maintained by
the GNU.  It is designed for use on Unix and Linux operating systems.

A problem with sharutils may make it possible to exploit symbolic link
attacks.  The problem is in the uudecode program.

Prior to decoding a uuencoded file, uudecode does not check for the
existence of the file to be created from the decoded archive.  As a
result, a decoded file may overwrite another file in the temporary
directory, provided the user of uudecode has write permission to the file.

This problem is further compounded by the fact that uudecode does not
check whether or not the file is a symbolic link.  In the event of the
temporary file being a symbolic link, the file at the end of the symbolic
link would be overwritten.  This could result in a corruption or loss of
data.

This problem makes it possible to exploit a symbolic link attack, and
potentially overwrite files.  It could additionally lead to elevated
privileges.

10. SuSE AAA_Base_Clean_Core Script RM Race Condition Vulnerability
BugTraq ID: 4758
Remote: No
Date Published: May 16 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4758

Summary:

SuSE Linux is a freely available, open source operating system.  It is
maintained by SuSE.

A problem in the operating system could result in a denial of service.
The problem is in the creation of temporary directories.

A user could create a deeply nested directory structure that would be
descended by the recursive rm command, executed by the aaa_base_clean_core
script daily.  Upon descent into this directory tree, a user could move
the current working directory of the process higher in the directory
structure, causing the rm process to ascend higher than intended and
remove system files, including the root directory.

This problem could make it possible for a local user to deny service to
legitimate users of the system.  This vulnerability based on the problem
described in Bugtraq ID 4266, though the problem in this case is insecure
creation of a temporary directory by the aaa_base_clean_core script.

11. Hosting Controller DSNManager Directory Traversal Vulnerability
BugTraq ID: 4759
Remote: Yes
Date Published: May 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4759

Summary:

Hosting Controller is an application which centralizes all hosting tasks
to one interface.  Hosting Controller runs on Microsoft Windows operating
systems.

The DSNManager script is bundled with Hosting Controller and enables users
to view and manage DSN (Data Source Number) information for an underlying
database.

The DSNManager script does not sufficiently filter dot-dot-slash (../)
sequences from URL parameters, making it prone to directory traversal
attacks.  The attacker may submit a web request which is capable of
breaking out of the webroot directory, effectively allowing the attacker
to browse the filesystem at large.  An attacker can exploit this condition
to disclose the contents of arbitrary web-readable files or potentially
add a DSN (Data Source Number) to an arbitrary directory.

12. tinyproxy HTTP Proxy Memory Corruption Vulnerability
BugTraq ID: 4731
Remote: Yes
Date Published: May 13 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4731
Summary:

tinyproxy HTTP Proxy is a small HTTP proxy.

A vulnerability has been reported in the handling of some invalid proxy
requests by TinyProxy. Under some circumstances, an invalid request may
result in allocated memory being freed twice.

It may be possible for an attacker to manipulate data layout in memory so
that an arbitrary word in memory is overwritten with a custom value when
'free()' is called for the second time. Arbitrary code may be executed if
critical values such as function return addresses, GOT entries, etc., are
overwritten.

13. Cisco Content Service Switch HTTPS Post Denial Of Service Vulnerability
BugTraq ID: 4747
Remote: Yes
Date Published: May 15 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4747
Summary:

The Cisco Content Service (CSS) switch is a Layer 5 and 7 aware switch
capable of providing a front-end to web server farms and caches.  These
switches run WebNS software.

It is possible to cause some Cisco Content Service Switches (CSS) to
reboot by sending a HTTPS POST request.  The attacker does not need to be
authenticated to cause this condition to occur.

This vulnerability may enable a remote attacker to negatively impact the
availability of services offered by the affected devices.

The CSS 11000 series switches are known to be affected by this
vulnerability.  This includes the CSS 11050, CSS 11150, CSS 11800 and CSS
11500 hardware platforms.

14. SuSE Shadow File Truncation Vulnerability
BugTraq ID: 4757
Remote: No
Date Published: May 16 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4757
Summary:

SuSE Linux is a freely available, open source distribution of the Linux
operating system.  It is maintained by SuSE.  shadow is a set of utilities
for maintaining entries in the /etc/passwd and /etc/shadow files.

A vulnerability has been discovered in the shadow package that ships with
SuSE Linux.  It has been reported that a local attacker may be able to
cause data in /etc/passwd and /etc/shadow to be truncated or possibly even
appended to with attacker-supplied data.  This can occur of the attacker
sets filesize limitations prior to invoking the shadow utilities that
operate on these files.

At the very least, local users can corrupt vital files.  This may result
in a denial of service.  Under some circumstances successful exploitation
of this vulnerability may enable a local attacker to elevate privileges,
possibly even gaining root privileges.  SuSE has stated that it is not
possible for local attackers to obtain root privileges with the default
configuration of SuSE Linux.

15. CGIScript.net Information Disclosure Vulnerability
BugTraq ID: 4764
Remote: Yes
Date Published: May 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4764
Summary:

CGIScript.net provides various webmaster related tools and is maintained
by Mike Barone and Andy Angrick.

It is possible to cause numerous scripts provided by CGIScript.net to
disclose sensitive system information.

A malformed POST request will cause the host to display debug data in an
error page. As a result, server path information, form input, and
environment variables could be revealed to remote users.

Other types of malformed web requests may also cause this condition to occur.

The following is a list of cgi scripts that are susceptible to this issue:

csBanner.cgi
csCreatePro.cgi
CSDownload.cgi
csFAQ.cgi
CSFiler.cgi
CSFileshare.cgi
CSGrid.cgi
CSIncludes.cgi
CSMailto.cgi
CSNews.cgi
CSNews.cgi (pro version)
CSRandomText.cgi
CSUpload.cgi

Path, form input, and environment variable information may aid the
attacker in making further attacks against the host.

16. LevCGI NetPad Unauthorized File Access Vulnerability
BugTraq ID: 4741
Remote: Yes
Date Published: May 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4741

Summary:

LevCGI NetPad is a web-based text editor.  It is available for Linux and
Unix variants as well as Microsoft Windows operating systems.

Write access to NetPad documents is password-protected.  However,
authentication is not required to read the contents of NetPad documents.

Arbitrary web users may request existing documents and view their
contents, causing sensitive information in the documents to be disclosed.

17. Swatch Throttled Event Reporting Vulnerability
BugTraq ID: 4746
Remote: Yes
Date Published: May 15 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4746

Summary:

Swatch is a freely available, open source log watching utility.  It is
available for the Unix and Linux platforms.

Swatch may fail to report activities.  The problem is in the design of the
program.

Under some circumstances, a message may not be reported by swatch.  When
an event occurs on a system numerous times, and swatch has placed a
throttle on the event to prevent multiple alerts, swatch does not
sufficiently handle events of the same type afterwards.  When an event has
occurred and alerts for the event are throttled, a bug in the swatch
throttle code prevents swatch from reporting the event if it occurs a
month later.

This problem could allow an attacker with knowledge of an event that has
previously occurred and been throttled on a system to reproduce the event
without being noticed by swatch.

18. Hosting Controller Import Root Directory Command Execution Vulnerability
BugTraq ID: 4761
Remote: Yes
Date Published: May 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4761

Summary:

Hosting Controller is an application which centralizes all hosting tasks
to one interface.  Hosting Controller runs on Microsoft Windows operating
systems.

The Import Root Directory (imp_rootdir.asp) script does not force an
authentication challenge when accessed.  This script allows users to
perform actions on files and directories on the host, but under normal
circumstances only to those files and directories below the administrative
root directory for the Hosting Controller.  However, it is possible to
manipulate URL parameters to change the root directory to another
arbitrary directory on the system (such as C:).

This may enable a remote attacker to execute arbitrary commands on the
underlying system, eventually leading to a full compromise.

19. Xerox DocuTech Printer Weak Default Configuration Vulnerability
BugTraq ID: 4765
Remote: Yes
Date Published: May 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4765
Summary:

DocuTech is a printer and scanner combination system distributed and
maintained by Xerox.

A problem with the printer could make it possible for a user to gain
arbitrary access to the system.  The problem is in the default
configuration.

The printer portion of the DocuTech system is a Sun system running Solaris
8.  By default, the Solaris 8 system is implemented insecurely, running
numerous services and a known root password.

In a default implementation, Solaris 8 runs services enabled in a default
install of the operating system.  Additionally, the system is deployed
using the same root password ("service!") on all systems.  The default
deployment is further insecure by exporting numerous directories via NFS
as world-writeable.

This problem could make the compromise of an affected system trival, and
lead to a remote attacker gaining local administrative privileges on a
vulnerable system.

20. Microsoft Internet Explorer Zone Spoofing Vulnerability
BugTraq ID: 4753
Remote: Yes
Date Published: May 15 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4753

Summary:

A privilege escalation issue has been discovered in Microsoft Internet
Explorer. It is possible for malicious web pages to bypass the Security
Zone settings in IE.

Due to a flaw in the way IE handles sites accessed using the NetBIOS
protocol, a maliciously crafted web page could trick IE into opening the
page as a trusted site. As a result, arbitrary web pages can be viewed in
the Local Intranet Zone. Under certain circumstances web pages can be
viewed in the Trusted Site Zone.

Exploitation of this issue will lead to arbitrary web pages being handled
with fewer security restrictions.

21. Microsoft Internet Explorer Cookie Content Disclosure Vulnerability
BugTraq ID: 4754
Remote: Yes
Date Published: May 15 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4754

Summary:

A flaw exists in the way that Microsoft Internet Explorer handles scripts
embedded within cookies.  Since cookies are essentially an extension of
the website from which they were received, they should be treated as
though they are in the Internet zone, and allowed access only to contents
of their domain of origin.

However, some versions of Internet Explorer treat all cookie content as
originating from the same domain. As a result, script code embedded in a
cookie will have access to the contents of all cookies on the local
machine.

In order to execute scripts embedded in cookie contents, the cookie file
must normally be referenced as a file on the local system. The ability of
a remote attacker to reference the file depends on their ability to
predict the file location of a known cookie.

Exploitation of this vulnerability may require that an attacker know the
exact name and original domain of additional cookies.

22. Phorum Remote Command Execution Vulnerability
BugTraq ID: 4763
Remote: Yes
Date Published: May 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4763

Summary:

Phorum is a PHP based web forums package designed for most UNIX variants,
Linux, and Microsoft Windows operating systems.

A vulnerability has been reported in Phorum that will allow remote
attackers to specify external PHP scripts and potentially execute
commands.

The vulnerability exists in 'plugin.php', 'admin.php' and 'del.php' files
found in the distribution of Phorum version 3.3.2a.  It is possible for a
malicious attacker to specify the location of a parameter to the
vulnerable PHP files by passing an argument via URL to the PHP files.  As
a consequence, the vulnerable system will interpret the arbitrary
attacker-supplied remote file (such as a PHP script).  The remote file may
potentially contain destructive commands that will be executed by the
vulnerable system.

23. Xerox DocuTech Scanner Insecure Default Configuration Vulnerability
BugTraq ID: 4766
Remote: Yes
Date Published: May 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4766

Summary:

DocuTech is a printer and scanner combination system distributed and
maintained by Xerox.

A problem with the scanner could make it possible for a user to gain
access to the system.  The problem is in the default configuration.

The scanner portion of the DocuTech system is a Microsoft Windows system
running Windows NT.  By default, the Windows NT system is implemented
insecurely, with the entire C drive shared and copies of all jobs run on
the system archived and available via a web interface.

The archived copies of jobs on the system could allow a remote user to
view all previously run jobs on the system, and the names of the users
that have run them.  This problem is further complicated by the fact that
Xerox uses the same password for all NT scanner stations ("administ"), and
makes a web interface available for remote users to anonymously submit
jobs.

This configuration could make it possible for a remote attacker to gain
local access, and administrative privileges on a vulnerable system.

24. Cisco IDS Device Manager Arbitrary File Read Access Vulnerability
BugTraq ID: 4760
Remote: Yes
Date Published: May 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4760

Summary:

IDS Device Manager is a web interface to the Cisco IDS systems.  It is
distributed and maintained by Cisco Systems.

A problem with the Device Manager could make it possible for a remote
attacker to gain access to sensitive information.

The IDS Device Manager allows a user to view logs in a web-based
environment.  This feature allows a user to use a web browser to browse
IDS events, rather than using the traditional commandline utilities
supplied with Cisco IDS systems.

The IDS Device Manager may allow a remote user to gain access to sensitive
information on the system.  Due to improper handling of user-supplied
input, it is possible for a user to gain access to arbitrary files on the
system using an elementary directory traversal attack.  By placing a
request to the process, with an appended dot-dot-slash (../) tag pointing
to a file, a remote user may read the specified file on the affected
system.

This problem makes it possible for remote users to gain arbitrary read
access to files on vulnerable systems.  As the IDS Device Manager runs
with the privileges of the superuser, a remote attacker may exploit this
vulnerability to gain access to the shadow file, yielding system accounts
and encrypted password hashes.

25. GRSecurity Linux Kernel Memory Protection Weakness
BugTraq ID: 4762
Remote: No
Date Published: May 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4762
Summary:

The grsecurity Linux Kernel patch is a source-code patch developed and
maintained by the grsecurity development team.

A design error may allow for attackers to bypass the protection of the
patch.

The patch operates by redirecting the write() system call when it is being
used to write to a memory device.  Unfortunately, there are other methods
that can be used to write to system memory (such as mapping the device to
memory using mmap()).

Local attackers with root access may exploit this weakness to modify
kernel data structures or inject backdoor code, evading the protection of
the patch.

26. Gaim Sensitive World Readable Temporary File Vulnerability
BugTraq ID: 4730
Remote: No
Date Published: May 13 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4730

Summary:

Gaim is a chat client which supports AOL Instant Messenger, ICQ, MSN
Instant Messenger, Yahoo Instant Messenger, Jabber and IRC. Gaim runs on a
number of Unix-based platforms, including Linux.

An issue has been reported in versions of Gaim, which could enable an
unauthorized user to gain access to sensitive files.

A feature exists which enables a user to configure Gaim to check for new
email messages from configured web mail services. This feature runs when
Gaim is started, and creates two /tmp files which are world readable.

Reportedly, these temporary files may include sensitive information,
including authentication credentials for the specified mail service.

This issue has been known to specifically affect Hotmail accounts,
although other configured email web services may be affected. There may be
a limited time window in which this information may be used to
authenticate to Hotmail, possibly based on timeout mechanisms inherent in
Hotmail.

27. NetWin DNews Remote Access Vulnerability
BugTraq ID: 4737
Remote: Yes
Date Published: May 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4737

Summary:

DNews is a commercially available NNTP server.  It is available for
various operating systems, including Linux, Unix, and Microsoft Windows.

A vulnerability has been announced by the distributors of DNews.
Information concerning this vulnerability is not readily available.  It
is, however, possible that this vulnerability is remotely exploitable, as
the distributors of DNews recommend the placement of access control
entries in dnews.conf configuration file.

Successful exploitation may allow for remote attackers to gain access to
target servers.  It has been suggested that this vulnerability affects the
management interface on port 7119, and could result in DNews system
reconfiguration.  This is yet unconfirmed.

28. Cisco Content Service Switch XML Denial Of Service Vulnerability
BugTraq ID: 4748
Remote: Yes
Date Published: May 15 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4748

Summary:

The Cisco Content Service (CSS) switch is a Layer 5 and 7 aware switch
capable of providing a front-end to web server farms and caches.  These
switches run WebNS software.

It is possible to cause some Cisco Content Service Switches (CSS) to
reboot by sending XML data via HTTP to the web management interface of the
device.  The affected web management interface listens on port 8081.

This vulnerability may enable a remote attacker to negatively impact the
availability of services offered by the affected devices.

The CSS 11000 series switches are known to be affected by this
vulnerability.  This includes the CSS 11050, CSS 11150, CSS 11800 and CSS
11500 hardware platforms.

29. Cisco Cache Engine Default Configuration Arbitrary User Proxy Vulnerability
BugTraq ID: 4751
Remote: Yes
Date Published: May 15 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4751

Summary:

Cache Engines are systems designed to cache visited web sites for faster
delivery of web content.  They are maintained and distributed by Cisco
Systems.

A problem with Cache Engines could make it possible for arbitrary users to
proxy requests.  The problem is in the configuration of the device
firmware.

Cisco Cache Engines offer the ability to proxy not only web services, but
HTTPS and FTP transactions as well.  Since HTTPS services may be placed on
one of numerous ports, the default configuration allows a user behind the
proxy to connect to another system on any port.  Insufficient default
access control is set on the device, allowing any user that can connect to
the system to proxy a request through to another system.

This problem could allow a remote user to launch attacks against other
systems while hiding their identity behind the Cache Engine.  This problem
additionally affects Cisco Content Engines.

30. Microsoft Internet Explorer Content-Disposition Handling File Execution Vulnerability
BugTraq ID: 4752
Remote: Yes
Date Published: May 15 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4752

Summary:

This vulnerability is a variant of Bugtraq ID 3578.

An HTTP header may include the fields 'content-type' and
'content-disposition'. These fields are normally used to define the type
of data being returned, and how it is expected to be handled by the
client.

An error exists with the way Microsoft Internet Explorer handles conflicts
between this information and the filename of an attached file. IE may,
under some circumstances, make a decision to trust a file based on these
HTTP header values, and a decision on how to launch the file based on the
file name.

A malicious web site owner may exploit this vulnerability. By providing
executable content with specially crafted HTTP headers, it is possible to
convince IE that provided content is a benign type (such as a Windows
Media file). Once downloaded, the file will passed to the application that
Explorer believes should handle it without any warning to the user.  An
executable file may be executed if the application, upon not being able to
interpret the content, passes it back to the operating system.

It has been demonstrated that variants of this vulnerability can be
exploited when Windows Media Player 6.4 or 7.1 is installed on the system.

If a vulnerable user viewed content that returned an HTTP header similar
to: Content-Type: audio/x-ms-wma Content-disposition: inline;
filename="foo.exe"

Windows Media Player would return "foo.exe" to the operating system
instead of returning an error flag.

An alert user may be able to cancel the download process, as a progress
dialog box is presented. This ability is highly dependant on the download
time of the file. For small files or fast network conditions, there may
not be sufficient time for manual intervention.

It is also possible to exploit this vulnerability through HTML formatted
email, which may contain external references. Files may be downloaded and
executed through reading or previewing email.

31. kv Poll Cookie Security Bypass Vulnerability
BugTraq ID: 4736
Remote: Yes
Date Published: May 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4736

Summary:

kv Poll is a web based poll script maintained by KillerVault.

An issue has been reported which could allow users to bypass the voting
poll security feature in kv Poll.

Reportedly, users can modify their cookie values to appear as though they
have not voted, and therefore vote more than once. The cookie is designed
as a security measure for kv Poll voting poll information.

As a result, the poll data could be corrupted by a malicious user.

III. SECURITYFOCUS NEWS AND COMMENTARY
------------------------------------------

1. 'Deceptive Duo' Hacker Under House Arrest
By  Kevin Poulsen

Former pro-Napster hacker Robert "Pimpshiz" Lyttle is revealed as one-half
of the mysterious Deceptive Duo, and sentenced to house arrest for
violating his no-more-hacking probation rules.

http://online.securityfocus.com/news/414

2. O'Reilly Leaks Geeks' Info
By  Kevin Poulsen

Techie publishing house offers textbook example of insecure Web code.

http://online.securityfocus.com/news/408

IV.SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. mail2sh v1.0
Platforms: Linux, POSIX, UNIX
by José MANS
Relevant URL: http://online.securityfocus.com/tools/2668

Mail2sh makes it possible to carry out shell commands by email. Email is
sent to a particular user on your host and the commands will be carried
out if the user and password given matches ones in /etc/passwd. Commands
are executed with the user's privileges, and combined with a PGP module
ensures a certain level of security for use. Note that the system is not
natively encrypted, so use of an encryption mechanism is highly
recommended for security reasons.

2. GrabItAll
Platforms: Windows 2000, Windows XP
by Arne Vidstrom ([email protected])
Relevant URL: http://ntsecurity.nu/toolbox/grabitall/

GrabItAll performs traffic redirection by sending spoofed ARP replies. It
can redirect traffic from one computer to the attackers computer, or
redirect traffic between two other computers through the attackers
computer. In the last case you need to enable IP Forwarding which can be
done with GrabItAll too.


3. Saint Jude v0.10 (Solaris)
Platforms: Linux, Solaris, SunOS
by Tim Lawless
Relevant URL: http://www.sourceforge.net/projects/stjude

Saint Jude is a wholly kernel-based intrusion detection and intrusion
response system that implements the Saint Jude Model for detection of
improper privilege transitions. Saint Jude can detect the presence of
ongoing and successful attacks, from sources both local and remote, that
would yield root-level access to the attacking individual. Detection is
performed using a rule-based anomaly detector that uses a model of normal
system behavior that is generated on the protected machine during a
training phase. By comparing actual actions against a fully developed
model, it is possible to detect attacks against vulnerabilities that are
both known and unknown with no false positives or negatives.

4. Enigmail v0.2
by Fang
Platforms: Perl (any system supporting perl)
Relevant URL: http://www.grawlfang.com/securemail/

Enigmail allows you to send enciphered email with an optional password
hint. The recipient receives a mail message with a link to the script to
facilitate deciphering.

5. WatchMan v0.20
Platforms: Linux, Posix
by Leandro
Relevant URL: http://www.drk.com.ar/watchman.php

WatchMan is a process killer daemon. It kills process which may become a
problem due to several reasons, like taking too much time in user or
kernel mode, using too much CPU or memory, etc. It is configurable via a
.conf file.

6. Distributed Checksum Clearinghouse v1.1.0
Platforms: FreeBSD, Linux, NetBSD, POSIX, Solaris, SunOS
by Vernon Schryver
Relevant URL: http://www.rhyolite.com/anti-spam/dcc/
Platforms: FreeBSD, Linux, NetBSD, POSIX, Solaris, SunOS

Distributed Checksum Clearinghouse (DCC) is a system of clients and
servers that collect and count checksums related to mail messages. The
counts can be used by SMTP servers and mail user agents to detect and
reject bulk mail. DCC servers can exchange common checksums. The checksums
include values that are "fuzzy", or constant across common variations in
bulk messages

V. SECURITY JOBS SUMMARY
------------------------

1. Security Engineer Opportunity (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

2. Network Security Intrusion Software Developer, Austin TX    (includes relo) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

3. Chicago based Unix Net Sec Engineer! (local candidates only please) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

4. Washington, D.C. Area Opening (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

5. WireX Software Engineer (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

6. Looking for Security Consultant/Engineer/Mgmt work - Boston region (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

7. Looking for INFOSEC/IA/IW Professionals (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

8. Director of Security role (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

9. Hot Security Software Vendor - Major Account Executives (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

10. Security Engineer - NY Metro (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

11. Security Sales Account Manager-NYC (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

12. Seeking Regional Sales Engineer - CISSP - Bay Area OR NY/NJ/CT (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

13. Security Engineer in Washington DC (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

14. Resume - Experienced Information Security Engineer (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

15. Principal for Enterprise Security Solutions (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/DD0B8E58BB15D211B95500104B9AE24502A4D7E3@US-LMB-EXCH-1

16. Security Engineers Needed - Sierra Vista, Arizona (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

17. Intrusion Detection & Forensics (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

18. A technical security profesional still looking for a job (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/050301c1fab6$1f648dc0$4b92cbc1@wintermute

19. Security Engineer - Northern California (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

20. Forensics Investigations Analyst - NJ - #704 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

21. Security Engineer/Architect Available (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

22. Application for Network Security Engineer (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]


VI. INCIDENTS LIST SUMMARY
-------------------------

1. Windows Systems Defaced/destroyed, plus Port 3389 attacks (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

2. explanation of port 1433 scans... (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

3. Windows Systems Defaced (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

4. Nimda type attacks with broken GETs (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

5. Got 'em.  (was "Re: gw.ocg-corp.com") (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/Pine.LNX.4.44.0205140055330.25291-100000@ultra1.hugo.vanderkooij.org

6. gw.ocg-corp.com (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

7. [unisog] Windows Systems Defaced/destroyed, plus Port 3389attacks (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

8. Windows Systems Defaced/destroyed, plus Port 3389 attacks (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]


VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------

1. about cookies (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

2. Generating shellcode (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

3. GIF87a (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

4. PhotoParade hacking? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

5. ps under FreeBSD (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

6. Multiple vendors web server source code disclosure (8.3 name format vulnerability - take II) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/F4158E9E43A9D511BE1100065B0432497B54E7@perfectopdc

7. Xerox DocuTech problems (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/3CE69DE9.11420.2FD489@localhost

8. Sonicwall SOHO Content Blocking Script Injection, LogFile Denial of Service (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

9. Sonicwall SOHO Content Blocking Script Injection, LogFile Denial of Service (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

10. #2 ps under FreeBSD (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

11. Phorum 3.3.2a remote command execution (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

12. Xerox DocuTech problems (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/002901c1fe0c$dce0d7b0$fdfea8c0@dellydoo

13. A Proactive Approach from a vendor... (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/006a01c1fe06$fba8b100$6401a8c0@testxppro

14. PDF modifications? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/02ea01c1fde4$94f8aae0$251f6881@tbp

15. PDF modifications? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

16. Security holes : mcNews (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

17. Exploiting Buffer Overflows on Compaq Tru64 and No-Exec Stack (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

18. Exploiting Buffer Overflows on Compaq Tru64 and No-Exec Stack (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/6FB083FB72EFD21181D30004AC4CA18A018FB722@srv002

19. Apple OSX sliplogin overflow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

20. NCSec: Local Buffer Overflow in Microsoft's Net Messenger Service (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

21. Thinking about Security rules... (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

22. About  PHPImageview (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

23. Thinking about Security rules... (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/FF5D83AD2BE6AC4EB388C0CA0A86CC4301671CF6@pelimmail01.pe.attla.corp

24. Vulnerability in PHP ?!? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

25. Sybase default passwords? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]


VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------

1. About ping request? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

2. Hotfixes overwritten? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

3. XP or not XP - enterprise desktop? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

4. Hotfixes overwritten? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

5. XP or not XP - enterprise desktop? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

6. Bypassing Windows 2000 Domain Password settings (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

7. renaming the IIS metabase (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

8. setting "List" (RX-unspecified) with xcacls.exe (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

9. setting "List" (RX-unspecified) with xcacls.exe (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

10. renaming the IIS metabase (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

11. Bypassing Windows 2000 Domain Password settings (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

12. SecurityFocus Microsoft Newsletter #86 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

13. using SecEdit across different NT installations (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]


IX. SUN FOCUS LIST SUMMARY
----------------------------

1. Locking down a network connection to a single machine. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]

2. Replies (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]


X. LINUX FOCUS LIST SUMMARY
---------------------------

1. protecting DHCP servers (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

2. plain text vs. html (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

XI. SPONSOR INFORMATION
-----------------------
This issue sponsored by CipherTrust.

SECURE THE EMAIL GATEWAY **FREE EMAIL SECURITY WHITE PAPER

Stop SPAM, HACKERS, VIRUSES, WORMS, and TROJAN HORSES from
threatening your Exchange and Notes servers. Powered by the Sophos
Anti-Virus engine, IronMail has INTEGRATED DEFENSES against hackers
and spam, provides secure message delivery and secures Outlook Web
Access, all in a hardened gateway appliance.

FREE white paper on email security risks:
http://www.ciphertrust.com/article/c0502_03s_10.htm
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.