SecurityFocus Newsletter #248

John Boletta <[email protected]> 10 May 2004 21:52:22 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #248
------------------------------

This Issue is Sponsored By: SecurityFocus 

Want to keep up on the latest security vulnerabilities? Don't have time to
visit a myriad of mailing lists and websites to read the news? Just add
the new SecurityFocus RSS feeds to your freeware RSS reader, and see all
the latest posts for Bugtraq and the SF Vulnernability database in one
convenient place. Or, pull in the latest news, columnists and feature
articles in the SecurityFocus aggregated news feed, and stay on top of
what's happening in the community!

http://www.securityfocus.com/rss/index.shtml

------------------------------------------------------------------------
I. FRONT AND CENTER
     1. Automating Windows Patch Mngt: Part III
II. BUGTRAQ SUMMARY
     1. Sysklogd Crunch_List Buffer Overrun Vulnerability
     2. Sesame Unauthorized Repository Access Vulnerability
     3. 3Com SuperStack 3 NBX Netset Application Port Scan Denial of...
     4. JForum Unauthorized Forum Access Vulnerability
     5. Midnight Commander Multiple Unspecified Vulnerabilities
     6. Multiple LHA Buffer Overflow/Directory Traversal Vulnerabili...
     7. LibPNG Broken PNG Out Of Bounds Access Denial Of Service Vul...
     8. SquirrelMail Folder Name Cross-Site Scripting Vulnerability
     9. Microsoft Internet Explorer Meta Data Foreign Domain Spoofin...
     10. Rosiello Security Sphiro HTTPD Remote Heap Buffer Overflow V...
     11. ReciPants SQL Injection and Cross-Site Scripting Vulnerabili...
     12. Moodle Cross Site Scripting Vulnerability
     13. ProFTPD CIDR Access Control Rule Bypass Vulnerability
     14. Coppermine Photo Gallery Multiple Input Validation Vulnerabi...
     15. Web Wiz Forum Multiple Vulnerabilities
     16. Apple QuickTime Sample-to-Chunk Integer Overflow Vulnerabili...
     17. PROPS SQL Injection and Cross-Site Scripting Vulnerabilities
     18. Emacs flim Library Insecure Temporary File Creation Vulnerab...
     19. Business Objects Crystal Reports Multiple Unspecified Vulner...
     20. Sun Solaris Patch Information Disclosure Vulnerability
     21. Aldo's Web Server Multiple Input Validation Vulnerabilities
     22. YaBB Bulletin Board Corruption Vulnerability
     23. PaX 2.6 Kernel Patch Denial Of Service Vulnerability
     24. SmartPeer Undisclosed Local Vulnerability
     25. APSIS Pound Remote Format String Vulnerability
     26. IPMenu Log File Symbolic Link Vulnerability
     27. Apple Mac OS X CoreFoundation Unspecified Large Input Vulner...
     28. Apple Mac OS X AppleFileServer Remote Buffer Overflow Vulner...
     29. Titan FTP Server LIST Denial Of Service Vulnerability
     30. Check Point VPN-1 ISAKMP Remote Buffer Overflow Vulnerabilit...
     31. OMail Webmail Remote Command Execution Variant Vulnerability
     32. Verity Ultraseek Error Message Path Disclosure Vulnerability
     33. E-Zone Media FuzeTalk AddUser.CFM Administrator Command Exec...
     34. Kolab Groupware Server OpenLDAP Plaintext Password Storage V...
     35. E-Zone Media FuzeTalk Banning.CFM Authentication Bypass Vuln...
     36. SuSE Linux Kernel HbaApiNode Improper File Permissions Denia...
     37. JelSoft VBulletin Forum Creation HTML Injection Vulnerabilit...
     38. Simple Machines Forum Size Tag HTML Injection Vulnerability
     39. PHPNuke Modules.php Multiple SQL Injection Vulnerabilities
     40. PHPX Multiple Cross-Site Scripting Vulnerabilities
     41. PHPX Multiple Administrator Command Execution Vulnerability
     42. FreeBSD Kernel VM_Map Local Denial Of Service Vulnerability
     43. P4DB Multiple Input Validation Vulnerabilities
     44. SGI IRIX  Unspecified UDP Denial Of Service Vulnerability
     45. Heimdal K5AdminD Remote Heap Buffer Overflow
     46. SGI IRIX IFConfig -ARP Failure To Disable ARP Functionality ...
     47. Exim Sender Verification Remote Stack Buffer Overrun Vulnera...
     48. Exim Header Syntax Checking Remote Stack Buffer Overrun Vuln...
     49. Microsoft ASP.NET Malformed HTTP Request Information Disclos...
     50. e107 Website System Multiple Script HTML Injection Vulnerabi...
     51. SurgeLDAP Web Administration Authentication Bypass Vulnerabi...
     52. DeleGate SSLway Filter Remote Stack Based Buffer Overflow Vu...
     53. KAME Racoon Remote IKE Message Denial Of Service Vulnerabili...
     54. SuSE LINUX 9.1 Personal Edition Live CD-ROM SSH Server Defau...
III. SECURITYFOCUS NEWS ARTICLES
     1. Prison time for cyber stock swindler
     2. Student hacks iTunes for compatibility
     3. Charges filed in 'Deceptive Duo' hacks
     4. New version of Sasser undermines lone coder theory
     5. German teenager admits creating Sasser
     6. Mystery of MS's missing AV software
IV. SECURITYFOCUS TOP 6 TOOLS
     1. Password Spyer 2k 2.4
     2. NatACL 1.0
     3. PCX Firewall (CGI Web Frontend) 1.3
     4. Burp proxy 1.22 1.22
     5. GNUnet v0.6.2a
     6. FTimes v3.4.0
V. SECURITYJOBS LIST SUMMARY
     1. Sales Executive - Midwest (Chicago) (Thread)
     2. Practice Director Security Technologies (Thread)
     3. Cisco Security Agent Consultant (Thread)
     4. NY Sales Executive (Thread)
     5. SE - NY/Boston based (Thread)
     6. Information Security Project Manager - Wash DC (Thread)
     7. Information Security Specialist ? Wash DC (Thread)
     8. Looking for a Security Analyst position in Toronto, ... (Thread)
     9. Security Engineer, STM Installation & Configuration (Thread)
     10. JOB: US-NY-NYC: Windows Security Engineer (Thread)
     11. SECURITY ENGINEER II WANTED - Charleston, SC (Thread)
     12. Security Engineer - (2 openings) New York, Bay Area ... (Thread)
     13. NETWORK SECURITY ENGINEER III WANTED - Charleston, S... (Thread)
     14. InfoSec job in Canberra (Thread)
     15. Lead Qualification Representatives (Thread)
     16. Security Vulnerability Analyst/Security Researcher -... (Thread)
     17. Pre-Sales Systems Engineers - Symantec - St. Louis &... (Thread)
     18. Unix Security Specialist - U. S. Government - Austin... (Thread)
     19. Inside Sales Position - Bay Area, CA (Thread)
     20. FW: AE - Security Sales, Phili (Thread)
     21. (job offered) Strategic Field Sales Exec - North Ame... (Thread)
     22. Security Audit Principal Engineer at Citrix Systems ... (Thread)
     23. IT Security Manager- Salt Lake, UT  $80-$105K (Thread)
     24. Sr. Security Software Developer/Analyst for Security... (Thread)
     25. Director of Public Relations Silicon Valley (Thread)
     26. Unix Security Engineer London Uk (Thread)
     27. Security Software Developer at Citrix Systems in For... (Thread)
     28. Pre Sales Security Engineer  Silicon Valley (Thread)
     29. Product Marketing Manager  Silicon Valley CA (Thread)
     30. Product Planning & Strategy Senior Product Manager a... (Thread)
     31. Director Quality Assurance Silicon Valley (Thread)
     32. Metaframe Password Manager Senior Security Software ... (Thread)
     33. Seeking Common Criteria, Cryptography, or FIPS 140 r... (Thread)
     34. FW: AE - Security Sales, SF, DC, Chi, Dall (Thread)
     35. Senior Security Software Developer/Analyst Florida (Thread)
     36. Security Architects in DC, VA, MA, TX (Thread)
     37. Sr. Software Engineer - Southern CA (Thread)
     38. 3 salaried/full-time Senior SMS/Security Consultants... (Thread)
     39. (job offered) Senior Consultant - Secure Technologie... (Thread)
     40. Principal Consultant - Secure Technologies, Seattle,... (Thread)
     41. Seeking  Information Security Systems contractor in ... (Thread)
     42. Software Engineer, Security (Thread)
     43. Senior Security Consultant Chicago, IL  $90-$110K (Thread)
     44. Unix Security Engineer (Thread)
     45. Security Engineer, DC Metro Area (Thread)
     46. Sr. Security Analyst - AntiVirus - Southern CA (Thread)
     47. Seeking contract Security Software Developer in Lond... (Thread)
     48. Software Quality Assurance Engineer (Thread)
     49. Active Directory/Identity Mgt positions: HCA - Nashv... (Thread)
     50. RelSec: Security Consultant - Risk Assessment/Audit/... (Thread)
     51. Security Engineer - Columbus, OH (Thread)
     52. Manager & Sr. Manager in Dallas, TX (Thread)
     53. DIrector of Product Marketing MA (Thread)
     54. San Diego Area Security Engineering/Information Assu... (Thread)
     55. Security Engineer HIPAA (Thread)
     56. Application Security Enginner (Thread)
     57. Pre-Sales Systems Engineer Need - Network Security (Thread)
     58. Risk Assessment Scientist (Thread)
     59. security event analyst (Thread)
     60. Engagement Manager (Thread)
     61. Senior Sales Executive Need - Chicago - Security (Thread)
     62. Senior Federal Sales Executive Need - DC - Security (Thread)
     63. ArcSight needs Regional Sales Manager, New York (Thread)
     64. CISSP, IAM and TS clearance Looking in DC Area (Thread)
     65. Perimeter Security Specialist needed in Boston (Thread)
VI. INCIDENTS LIST SUMMARY
     1. SSH probes? (Thread)
     2. Port 3889 Traffic (Thread)
     3. Odd attack string (Thread)
     4. Vacation trawling by the list moderator... please ig... (Thread)
     5. Increase in Port Scan Attempts? (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. unpacking UPX or PE-packed binaries (Thread)
     2. Basic authentication with IIS 5, IE 6.0 on Windows 2... (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. Relative Security Provided by Cached Domain Credenti... (Thread)
     2. RE: Restricting the change of the local administrato... (Thread)
     3. Restricting the change of the local administrator ac... (Thread)
     4. Restricting the change of the local administrator ac... (Thread)
     5. IE questions (Thread)
     6. Restricting the change of the local administrator ac... (Thread)
     7. SecurityFocus Microsoft Newsletter #187 (Thread)
IX. SUN FOCUS LIST SUMMARY
     NO NEW POSTS FOR THE WEEK 2004-05-03 to 2004-05-10.
X. LINUX FOCUS LIST SUMMARY
     1. Secure Form Script? (Thread)
     2. decent loadbalancing with 2 different ISP's with min... (Thread)
     3. decent loadbalancing with 2 different ISP's with min... (Thread)
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION

I. FRONT AND CENTER
-------------------
1. Automating Windows Patch Mngt: Part III
By Jonathan Hassell

The final installment of this series discusses two alternative, low cost 
tools to manage the application of patches to Windows systems, and also 
provides information on the upcoming, revised Software Update Services 
(SUS) from Microsoft.

http://www.securityfocus.com/infocus/1778

II. BUGTRAQ SUMMARY
-------------------
1. Sysklogd Crunch_List Buffer Overrun Vulnerability
BugTraq ID: 10238
Remote: No
Date Published: Apr 29 2004
Relevant URL: http://www.securityfocus.com/bid/10238
Summary:
Sysklogd has been reported to prone to a buffer overrun vulnerability.  

This condition may theoretically permit a local attacker to crash the server.  It is not believed that this condition may be exploited to execute arbitrary with elevated privileges, since the syslogd component may not be installed with setuid/setgid permissions, though this has not been confirmed.

2. Sesame Unauthorized Repository Access Vulnerability
BugTraq ID: 10239
Remote: Yes
Date Published: Apr 29 2004
Relevant URL: http://www.securityfocus.com/bid/10239
Summary:
It has been reported that the Sesame RDF repository application is prone to an unauthorized repository access vulnerability.  This issue is due to a failure of the application to properly secure repository contents in memory once they have been accessed.

This issue might allow an attacker to gain access to other users repositories; potentially leading to the disclosure of sensitive information.

3. 3Com SuperStack 3 NBX Netset Application Port Scan Denial of...
BugTraq ID: 10240
Remote: Yes
Date Published: Apr 30 2004
Relevant URL: http://www.securityfocus.com/bid/10240
Summary:
A vulnerability has been discovered in 3Com SuperStack 3 NBX IP telephones. 

This issue occurs when an affected port is scanned with the Nessus security audit tool, configured in safeChecks mode. This will effectively cause the NBX Netset application to crash.

It is reported that a hard reboot is required to restore normal functionality.

4. JForum Unauthorized Forum Access Vulnerability
BugTraq ID: 10241
Remote: Yes
Date Published: Apr 30 2004
Relevant URL: http://www.securityfocus.com/bid/10241
Summary:
Reportedly JForum is prone to an unauthorized forum access vulnerability.  This issue is due to an input validation error that allows an unauthorized individual to access a restricted forum.

This issue may allow an attacker to gain unauthorized access to a restricted forum.

5. Midnight Commander Multiple Unspecified Vulnerabilities
BugTraq ID: 10242
Remote: Unknown
Date Published: Apr 30 2004
Relevant URL: http://www.securityfocus.com/bid/10242
Summary:
It has been reported that Midnight Commander is prone to multiple, unspecified vulnerabilities.  These issues are due to various design and boundary condition errors.

These issues could be leveraged by an attacker to execute arbitrary code on an affected system, which may facilitate unauthorized access. It is also possible for an attacker to carry out symbolic link attacks against an affected system, potentially facilitating a system wide denial of service.

6. Multiple LHA Buffer Overflow/Directory Traversal Vulnerabili...
BugTraq ID: 10243
Remote: Yes
Date Published: Apr 30 2004
Relevant URL: http://www.securityfocus.com/bid/10243
Summary:
LHA has been reported prone to multiple vulnerabilities that may allow a malicious archive to execute arbitrary code or corrupt arbitrary files when the archive is operated on.

The first issues reported have been assigned the CVE candidate identifier (CAN-2004-0234). It is reported that LHA is prone to two stack based buffer overflow vulnerabilities. These vulnerabilities may be exploited to execute  supplied instructions with the privileges of the user who invoked the affected LHA utility.

The second set of issues has been assigned CVE candidate identifier (CAN-2004-0235). In addition to the buffer overflow vulnerabilities that were reported, LHA has been reported prone to a several directory traversal issues. These directory traversal vulnerabilities may likely be exploited to corrupt/overwrite files in the context of the user who is running the affected LHA utility.

7. LibPNG Broken PNG Out Of Bounds Access Denial Of Service Vul...
BugTraq ID: 10244
Remote: Yes
Date Published: Apr 30 2004
Relevant URL: http://www.securityfocus.com/bid/10244
Summary:
The libpng graphics library is reported to be prone to a denial of service vulnerability when handling certain types of broken images.

It is conjectured that this issue will cause an access violation on certain systems if software that is linked to the vulnerable library is used to handle a malicious broken PNG image that is sufficient to trigger the vulnerability.

8. SquirrelMail Folder Name Cross-Site Scripting Vulnerability
BugTraq ID: 10246
Remote: Yes
Date Published: Apr 30 2004
Relevant URL: http://www.securityfocus.com/bid/10246
Summary:
It has been reported that SquirrelMail is affected by a cross-site scripting vulnerability in the handling of folder name displays.  This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamic web content.

This issue may allow for theft of cookie-based authentication credentials.  Other attacks are also possible.

9. Microsoft Internet Explorer Meta Data Foreign Domain Spoofin...
BugTraq ID: 10248
Remote: Yes
Date Published: Apr 30 2004
Relevant URL: http://www.securityfocus.com/bid/10248
Summary:
A vulnerability has been reported in Microsoft Internet Explorer that may facilitate certificate spoofing.  This issue could aid in attacks which falsify web content to victim users.

The cause of the vulnerability is that it is possible to embed a certificate and content from a foreign domain (via SSL) into a web page.  When the web page is visited by the client user, the user will be prompted to authorize the certificate from the foreign domain.  This will make it appear as though the web page they are visiting is in the foreign domain.

It should be noted that while the connection will appear to be secure, as denoted by the closed lock icon in the right bottom corner of the browser window, the spoofed certicate may not be manually inspected (by clicking the lock icon).  The browser will return a message stating that the document does not have a certificate associated with it when the lock is clicked by the user.  This may give an indication that the certificate has been spoofed.

This vulnerability may be exploited to entice a user to trust a hostile web page.

This issue has been reported in Microsoft Internet Explorer 6.  Earlier versions may also be affected.

10. Rosiello Security Sphiro HTTPD Remote Heap Buffer Overflow V...
BugTraq ID: 10249
Remote: Yes
Date Published: Apr 30 2004
Relevant URL: http://www.securityfocus.com/bid/10249
Summary:
It has been reported that Sphiro HTTPD is prone to a remote heap based buffer overflow vulnerability.  This issue is due to a failure of the application to properly verify buffer boundaries before storing input in fixed buffers.

Immediate consequences of this attack may cause the affected daemon to crash, denying service to legitimate users. Furthermore, due to the nature this issue, arbitrary code execution may be possible. This would occur in the context running daemon process.

11. ReciPants SQL Injection and Cross-Site Scripting Vulnerabili...
BugTraq ID: 10250
Remote: Yes
Date Published: Apr 30 2004
Relevant URL: http://www.securityfocus.com/bid/10250
Summary:
It has been reported that ReciPants is vulnerable to SQL injection and cross-site scripting vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied input prior to using the input in database queries. When a query fails, the error message, including the malicious content is displayed to the victim's browser.

These issues may allow an attacker to gain access to sensitive information, corrupt database contents, and steal authentication credentials. Other attacks are also possible.

12. Moodle Cross Site Scripting Vulnerability
BugTraq ID: 10251
Remote: Yes
Date Published: Apr 30 2004
Relevant URL: http://www.securityfocus.com/bid/10251
Summary:
It has been reported that Moodle is susceptible to a cross-site scripting vulnerability in the 'help.php' script. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamic web content.

This issue may allow for theft of cookie-based authentication credentials.  Other attacks are also possible.

13. ProFTPD CIDR Access Control Rule Bypass Vulnerability
BugTraq ID: 10252
Remote: Yes
Date Published: Apr 30 2004
Relevant URL: http://www.securityfocus.com/bid/10252
Summary:
ProFTPD has been reported prone to an access control rule bypass vulnerability. The issue was reportedly introduced when a "portability workaround" was applied to ProFTPD version 1.2.9.

This vulnerability may lead a system administrator into a false sense of security, where it is believed that access to the ProFTPD server is restricted by access control rules. In reality the access control restriction will not be enforced at all.

14. Coppermine Photo Gallery Multiple Input Validation Vulnerabi...
BugTraq ID: 10253
Remote: Yes
Date Published: Apr 30 2004
Relevant URL: http://www.securityfocus.com/bid/10253
Summary:
Reportedly Coppermine Photo Gallery is prone to multiple input validation vulnerabilities, some of which may lead to arbitrary command execution.  These issues are due to the application failing to properly sanitize and validate user-supplied input prior to using it in dynamic content and system command execution function calls.

These issues may be exploited to steal cookie based authentication credentials, map the application root directory of the affected application, execute arbitrary commands and include arbitrary files.  Other attacks are also possible.

15. Web Wiz Forum Multiple Vulnerabilities
BugTraq ID: 10255
Remote: Yes
Date Published: Apr 30 2004
Relevant URL: http://www.securityfocus.com/bid/10255
Summary:
It has been reported that Web Wiz Forum is affected by multiple vulnerabilities.  These issues are due to failure to properly sanitize user-supplied input facilitating SQL injection attacks, and design errors that allow unauthorized access to certain web forum functionality.

As a result of the SQL injection issue an attacker could modify the logic and structure of database queries. Other attacks may also be possible, such as gaining access to sensitive information.

A design error allows any user to access the topic modification and IP address blocking scripts, permitting unauthorized users to change forum topics and block arbitrary IP addresses.

16. Apple QuickTime Sample-to-Chunk Integer Overflow Vulnerabili...
BugTraq ID: 10257
Remote: Yes
Date Published: Apr 30 2004
Relevant URL: http://www.securityfocus.com/bid/10257
Summary:
Apple QuickTime Player is vulnerable to an integer overflow vulnerability.  

This issue can be triggered by a malformed .mov file and is reported to be exploitable to execute arbitrary code on Microsoft Windows platforms.  This issue could also cause the player to crash on other platforms.  Conflicting information has been released by the vendor that suggests that this issue will only result in a denial of service on Mac OS X.

17. PROPS SQL Injection and Cross-Site Scripting Vulnerabilities
BugTraq ID: 10258
Remote: Yes
Date Published: May 01 2004
Relevant URL: http://www.securityfocus.com/bid/10258
Summary:
It has been reported that PROPS is vulnerable to SQL injection and cross-site scripting vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied input prior to using the input in database queries. When a query fails, the error message, including the malicious content is displayed to the victim's browser.

These issues may allow an attacker to gain access to sensitive information, corrupt database contents, and steal authentication credentials. Other attacks are also possible.

18. Emacs flim Library Insecure Temporary File Creation Vulnerab...
BugTraq ID: 10259
Remote: No
Date Published: May 02 2004
Relevant URL: http://www.securityfocus.com/bid/10259
Summary:
The Emacs flim library is prone to a symlink vulnerability.  This could allow files to be overwritten with the privileges of the user running Emacs.

19. Business Objects Crystal Reports Multiple Unspecified Vulner...
BugTraq ID: 10260
Remote: Yes
Date Published: May 03 2004
Relevant URL: http://www.securityfocus.com/bid/10260
Summary:
It has been reported that Crystal Reports may be prone to multiple vulnerabilities in the web interface supplied with the application.  These issues could allow an attacker to disclose or delete files from a server running the application as well as cause a denial of service condition.

Crystal Reports versions 10.0 and prior are assumed to be vulnerable to these issues.

Due to a lack of details further information is not available at the moment.  This BID will be updated as more information becomes available.

20. Sun Solaris Patch Information Disclosure Vulnerability
BugTraq ID: 10261
Remote: Yes
Date Published: Apr 30 2004
Relevant URL: http://www.securityfocus.com/bid/10261
Summary:
Sun has announced that some patches released for Solaris may in fact present a new security vulnerability.  The issue presents itself in Solaris 9 systems running as NIS servers containing secure maps and patches 113579-02 through 113579-05 (for SPARC) or 114342-02 through 114342-05 (for x86) installed.

Successful exploitation of this issue could result in an attacker disclosing sensitive information that could be used to launch further attacks against a vulnerable system.

21. Aldo's Web Server Multiple Input Validation Vulnerabilities
BugTraq ID: 10262
Remote: Yes
Date Published: May 03 2004
Relevant URL: http://www.securityfocus.com/bid/10262
Summary:
Two vulnerabilities have been reported in the Aldo's Web Server product.

A remote attacker could possibly learn information about the running web server process, and a directory traversal vulnerability is also reported, allowing an attacker to access information outside of the web server's document root.

These vulnerabilities could be used to access sensitive information that could aid an attacker in further compromises of the affected server.

22. YaBB Bulletin Board Corruption Vulnerability
BugTraq ID: 10263
Remote: Yes
Date Published: May 03 2004
Relevant URL: http://www.securityfocus.com/bid/10263
Summary:
It has been reported that YaBB is affected by a bulletin board corruption vulnerability.  This is due to an input validation issue that allows users to specify arbitrary values in a text file associated with the application.

This issue might cause the bulletin board related to the application to become corrupted and unreadable, denying service to legitimate users.  Other attacks might also be possible.

23. PaX 2.6 Kernel Patch Denial Of Service Vulnerability
BugTraq ID: 10264
Remote: No
Date Published: May 03 2004
Relevant URL: http://www.securityfocus.com/bid/10264
Summary:
PaX for 2.6 series Linux kernels has been reported prone to a local denial of service vulnerability. The issue is reported to present itself when PaX Address Space Layout Randomization Layout (ASLR) is enabled. 

The vulnerability may be exploited by a local attacker to influence the kernel into an infinite loop.

24. SmartPeer Undisclosed Local Vulnerability
BugTraq ID: 10265
Remote: No
Date Published: May 03 2004
Relevant URL: http://www.securityfocus.com/bid/10265
Summary:
SmartPeer has been reported prone to an undisclosed vulnerability. The issue is reported to present itself when the smartpeer -p mynewpassword command is invoked. 

SmartPeer version 0.1 is reported prone to this vulnerability, previous versions might also be affected.

25. APSIS Pound Remote Format String Vulnerability
BugTraq ID: 10267
Remote: Yes
Date Published: May 03 2004
Relevant URL: http://www.securityfocus.com/bid/10267
Summary:
APSIS Pound has been found to be prone to a remote format string vulnerability. The problem presents itself when Pound handles certain requests containing embedded format string specifiers. 

Ultimately this vulnerability could allow for execution of arbitrary code on the system implementing the affected software, which would occur in the security context of the server process.

26. IPMenu Log File Symbolic Link Vulnerability
BugTraq ID: 10269
Remote: No
Date Published: May 04 2004
Relevant URL: http://www.securityfocus.com/bid/10269
Summary:
It has been reported that ipmenu is affected by a symbolic link vulnerability.  This issue is due to a design error that allows for the creation of temporary files in an insecure fashion, facilitating symbolic links attacks.

This issue may be leveraged to create a system wide denial of service condition.  This issue may also be leveraged to escalate privileges on the affected system, although this is currently unverified.

27. Apple Mac OS X CoreFoundation Unspecified Large Input Vulner...
BugTraq ID: 10270
Remote: No
Date Published: May 03 2004
Relevant URL: http://www.securityfocus.com/bid/10270
Summary:
It has been reported that CoreFoundation is affected by a local unspecified large input vulnerability.  This issue is apparently due to an inability of certain library-defined classes to handle large input.

Currently sufficient information does not exist to provide more details. This BID will be updated when more information becomes available.

This issue could potentially be leveraged to execute arbitrary code on the affected system, although this has not been confirmed.

This issue was previously disclosed in a multiple BID 10268 (Apple OS X Multiple Unspecified Large Input Vulnerabilities), however, it is being assigned a new BID.

28. Apple Mac OS X AppleFileServer Remote Buffer Overflow Vulner...
BugTraq ID: 10271
Remote: Yes
Date Published: May 03 2004
Relevant URL: http://www.securityfocus.com/bid/10271
Summary:
It has been reported that AppleFileServer is prone to a remote buffer overflow vulnerability that may allow a remote attacker to execute arbitrary code in order to gain unauthorized access.  The issue presents itself when the application receives a 'LoginExt' packet containing a malformed 'PathName' argument.

Apple Mac OS X 10.3.3 and prior are reported to be prone to this issue.

This issue was previously disclosed in a multiple BID 10268 (Apple OS X Multiple Unspecified Large Input Vulnerabilities), however, it is being assigned a new BID as a result of new information available.

29. Titan FTP Server LIST Denial Of Service Vulnerability
BugTraq ID: 10272
Remote: Yes
Date Published: May 04 2004
Relevant URL: http://www.securityfocus.com/bid/10272
Summary:
Titan FTP is prone to a remote denial of service vulnerability when handling the 'LIST' command.

A remote attacker can cause the FTP server to crash by improperly handling a non-existent socket.

30. Check Point VPN-1 ISAKMP Remote Buffer Overflow Vulnerabilit...
BugTraq ID: 10273
Remote: Yes
Date Published: May 04 2004
Relevant URL: http://www.securityfocus.com/bid/10273
Summary:
It has been reported that Check Point VPN-1 products may be prone to a remote buffer overflow vulnerability that may allow a remote attacker to execute arbitrary code in order to gain unauthorized access.

The issue is reported to present itself in Check Point VPN-1 products during negotiations of a VPN tunnel.  Specifically, a buffer overflow condition may be triggered by sending a malformed ISAKMP packet during the negotiations.

Check Point Software user who do not use Remote Access VPNs or gateway-to-gateway VPNs are not vulnerable to this issue.

Due to a lack of details, further information cannot be provided at the moment.  This BID will be updated as more information becomes available.

31. OMail Webmail Remote Command Execution Variant Vulnerability
BugTraq ID: 10274
Remote: Yes
Date Published: May 04 2004
Relevant URL: http://www.securityfocus.com/bid/10274
Summary:
A vulnerability has been reported in OMail that allows a remote attacker to execute arbitrary commands on a vulnerable host. The problem is due to insufficient sanitization of shell metacharacters that are passed to the vulnerable software through URI parameters.

Exploitation of the vulnerability could allow a non-privileged user to remotely execute arbitrary commands in the context of the web server that is hosting the vulnerable application.

32. Verity Ultraseek Error Message Path Disclosure Vulnerability
BugTraq ID: 10275
Remote: Yes
Date Published: May 05 2004
Relevant URL: http://www.securityfocus.com/bid/10275
Summary:
It has been reported that Verity Ultraseek search application is prone to a remote path disclosure vulnerability that may allow an attacker to disclose the server document root.

Verity Ultraseek 5.2.1 and prior versions are reported to be vulnerable to this issue.

33. E-Zone Media FuzeTalk AddUser.CFM Administrator Command Exec...
BugTraq ID: 10276
Remote: Yes
Date Published: May 05 2004
Relevant URL: http://www.securityfocus.com/bid/10276
Summary:
It has been reported that FuseTalk is affected by an administrator command execution vulnerability in the adduser.cfm script.  This issue is due to a failure of the application to properly validate the origin of user supplied data.

This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were followed by a forum administrator, the attacker supplied command would be carried out with the viewer's privileges. This would occur in the security context of the affected web site and may allow creation of arbitrary users, and other attacks.

34. Kolab Groupware Server OpenLDAP Plaintext Password Storage V...
BugTraq ID: 10277
Remote: No
Date Published: May 05 2004
Relevant URL: http://www.securityfocus.com/bid/10277
Summary:
It has been reported that Kolab groupware server is prone to a plaintext password storage vulnerability that may allow an attacker to disclose OpenLDAP passwords that are stored in plaintext format.

Kolab Server versions 1.0.8 and prior may be prone to this issue.

35. E-Zone Media FuzeTalk Banning.CFM Authentication Bypass Vuln...
BugTraq ID: 10278
Remote: Yes
Date Published: May 05 2004
Relevant URL: http://www.securityfocus.com/bid/10278
Summary:
It has been reported that FuseTalk is affected by an authentication bypass vulnerability allowing access to the 'banning.cfm' script. This issue is due to a failure of the application to properly validate authentication credentials.

This issue may be leveraged by an attacker ban arbitrary hosts from accessing the affected forum by flagging their IP address.

36. SuSE Linux Kernel HbaApiNode Improper File Permissions Denia...
BugTraq ID: 10279
Remote: No
Date Published: May 03 2004
Relevant URL: http://www.securityfocus.com/bid/10279
Summary:
A vulnerability has been identified in the SuSE Linux kernel that may allow a local attacker to cause a denial of service condition on a vulnerable system.  The issue is reported to be caused by improper file permissions on '/proc/scsi/qla2300/HbaApiNode' file.

SuSE Linux Enterprise Server 8.0, SuSE Linux 8.1 and 9.0 are reported to be affected by this issue.

Due to a lack of details, further information cannot be provided at the moment.  This BID will be updated as more information becomes available.

37. JelSoft VBulletin Forum Creation HTML Injection Vulnerabilit...
BugTraq ID: 10280
Remote: Yes
Date Published: May 05 2004
Relevant URL: http://www.securityfocus.com/bid/10280
Summary:
Reportedly Jelsoft vBulletin is affected by an HTML injection vulnerability when creating a new forum.  This issue is due to a failure of the application to properly sanitize user-supplied input.

It is reported that an attacker must have administrator privileges to carry out an attack.

An attacker may exploit this issue to have arbitrary HTML and script code rendered in the browser of an unsuspecting user. It may be possible to steal cookie-based authentication credentials, as well as other sensitive information. Other attacks may also be possible.

38. Simple Machines Forum Size Tag HTML Injection Vulnerability
BugTraq ID: 10281
Remote: Yes
Date Published: May 05 2004
Relevant URL: http://www.securityfocus.com/bid/10281
Summary:
It has been reported that Simple Machines Forum (SMF) may be prone to an HTML injection vulnerability that may allow an attacker to execute arbitrary HTML or script code in a user's browser. The issue exists due to insufficient sanitization of user-supplied input via the font size attribute.

Exploitation could allow for theft of cookie-based authentication credentials. Other attacks are also possible.

39. PHPNuke Modules.php Multiple SQL Injection Vulnerabilities
BugTraq ID: 10282
Remote: Yes
Date Published: May 05 2004
Relevant URL: http://www.securityfocus.com/bid/10282
Summary:
Multiple SQL vulnerabilities have been identified in the 'modules.php' module of the application. These vulnerabilities may allow a remote attacker to manipulate query logic, potentially leading to unauthorized access to sensitive information.

PHPNuke 7.2 and prior are reported to be prone to these issues.

40. PHPX Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 10283
Remote: Yes
Date Published: May 05 2004
Relevant URL: http://www.securityfocus.com/bid/10283
Summary:
It has been reported that PHPX is affected by multiple cross-site scripting vulnerabilities.  These issues are due to a failure of the application to properly sanitize user-supplied URI input.

These issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

41. PHPX Multiple Administrator Command Execution Vulnerability
BugTraq ID: 10284
Remote: Yes
Date Published: May 05 2004
Relevant URL: http://www.securityfocus.com/bid/10284
Summary:
It has been reported that PHPX is affected by multiple administrator command execution vulnerabilities.  These issues are due to a failure of the application to properly validate access to administrative commands.

This issue could permit a remote attacker to create a malicious URI link or embed a malicious URI between bbCode image tags, which includes hostile HTML and script code. If an unsuspecting forum administrator activated this URI, the attacker-supplied command would be carried out with the administrator's privileges. This would occur in the security context of the affected web site and would cause various administrator actions to be taken.

42. FreeBSD Kernel VM_Map Local Denial Of Service Vulnerability
BugTraq ID: 10285
Remote: No
Date Published: May 05 2004
Relevant URL: http://www.securityfocus.com/bid/10285
Summary:
The virtual memory mapping module for the FreeBSD kernel has been reported prone to a local denial of service vulnerability.

A local user may exploit this issue to influence the virtual memory mapping module of the FreeBSD kernel into allocating arbitrary amounts of memory. This may potentially exhaust system resources. Once memory resources are exhausted, a kernel panic will likely occur, effectively denying service to legitimate users.

It is not currently known if other BSD derivatives are affected by this issue.

43. P4DB Multiple Input Validation Vulnerabilities
BugTraq ID: 10286
Remote: Yes
Date Published: May 05 2004
Relevant URL: http://www.securityfocus.com/bid/10286
Summary:
It has been reported that P4DB is affected by multiple input validation vulnerabilities.  These issues are due to a failure of the application to properly sanitize user-supplied URI input.

Both cross-site scripting and remote, arbitrary command execution vulnerabilities have been reported.

The cross-site scripting issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

Exploitation of the command execution vulnerabilities could allow a remote, unauthenticated user to remotely execute arbitrary commands on the underlying system with the privileges of the web server that is hosting the vulnerable application.

Currently the information available is not sufficient to provide more information; this BID will be updated as new details are released.

44. SGI IRIX  Unspecified UDP Denial Of Service Vulnerability
BugTraq ID: 10287
Remote: Yes
Date Published: May 05 2004
Relevant URL: http://www.securityfocus.com/bid/10287
Summary:
SGI IRIX is reportedly prone to an undisclosed UDP denial of service vulnerability.

SGI has released an advisory that tells users of various version of IRIX to apply patches that reportedly resolve two SGI bugs, 773203 and 897764.

45. Heimdal K5AdminD Remote Heap Buffer Overflow
BugTraq ID: 10288
Remote: Yes
Date Published: May 05 2004
Relevant URL: http://www.securityfocus.com/bid/10288
Summary:
It has been reported that a remote heap overflow vulnerability exists in the k5admind daemon.  This issue is due to an input validation error that fails to validate length given in the framing in kerberos 4 network communication packets.

It has been reported that this issue will only affect versions of the daemon that include Kerberos 4 support;  If the daemon does not include this compatibility then it is not vulnerable.

The immediate consequences of an attacker will trigger a denial of service condition in the affected server.  It might also be possible that this issue could facilitate remote code execution that would take place with the privileges of the affected daemon.

46. SGI IRIX IFConfig -ARP Failure To Disable ARP Functionality ...
BugTraq ID: 10289
Remote: No
Date Published: May 05 2004
Relevant URL: http://www.securityfocus.com/bid/10289
Summary:
Expected functionality of ifconfig %interface% -arp is that ARP communications are disabled for the specified interface.

SGI IRIX ifconfig %interface% -arp fails to disable ARP handling on the specified interface. This may lead a network administrator into a false sense of security.

47. Exim Sender Verification Remote Stack Buffer Overrun Vulnera...
BugTraq ID: 10290
Remote: Yes
Date Published: May 06 2004
Relevant URL: http://www.securityfocus.com/bid/10290
Summary:
Exim has been reported prone to a remotely exploitable stack-based buffer overrun vulnerability.  

This is exposed if sender verification has been enabled in the agent and may be triggered by a malicious e-mail.  Exploitation may permit execution of arbitrary code in the content of the mail transfer agent.

This issue is reported in exist in Exim 3.35.  Earlier versions may also be affected. 

It should be noted that the vulnerable functionality is not enabled in the default install, though some Linux/Unix distributions that ship the software may enable it.

48. Exim Header Syntax Checking Remote Stack Buffer Overrun Vuln...
BugTraq ID: 10291
Remote: Yes
Date Published: May 06 2004
Relevant URL: http://www.securityfocus.com/bid/10291
Summary:
Exim is reportedly prone to a remotely exploitable stack-based buffer overrun vulnerability.  

This issue is exposed if header syntax checking has been enabled in the agent and may be triggered by a malicious e-mail.  Though not confirmed to be exploitable, if this condition were to be exploited, it would result in execution of arbitrary code in the context of the mail transfer agent.  Otherwise, the agent would crash when handling malformed syntax in an e-mail message.

The issue is reported to exist in both Exim 3.35 and 4.32, though the vulnerable code exists in different source files in each of these versions.

It should be noted that the vulnerable functionality is not enabled in the default install, though some Linux/Unix distributions that ship the software may enable it.

49. Microsoft ASP.NET Malformed HTTP Request Information Disclos...
BugTraq ID: 10292
Remote: Yes
Date Published: May 06 2004
Relevant URL: http://www.securityfocus.com/bid/10292
Summary:
It has been reported that ASP.NET may be prone to a remote information disclosure vulnerability that could allow an attacker to disclose sensitive information.  This issue occurs when a malformed cookie header is sent to a server via a HTTP GET request.

Successful exploitation of this issue may allow a remote attacker to disclose sensitive information, which could be used to launch further attacks against a vulnerable system.

50. e107 Website System Multiple Script HTML Injection Vulnerabi...
BugTraq ID: 10293
Remote: Yes
Date Published: May 06 2004
Relevant URL: http://www.securityfocus.com/bid/10293
Summary:
It has been reported that e107 website system may be prone to an HTML injection vulnerability that could allow an attacker to steal cookie-based authentication credentials.

e107 versions 0.614 and prior are reported to be prone to this issue.

51. SurgeLDAP Web Administration Authentication Bypass Vulnerabi...
BugTraq ID: 10294
Remote: Yes
Date Published: May 05 2004
Relevant URL: http://www.securityfocus.com/bid/10294
Summary:
SurgeLDAP is an LDAP server implementation for Microsoft Windows and various Unix operating systems. It includes a built-in web server to permit remote user access via HTTP. 

It has been reported that the SurgeLDAP web administration application is prone to an authentication bypass vulnerability, possibly allowing remote attackers manager access.

Once administration access is granted, it may be possible for an attacker to modify records in the LDAP database, destroy data, crash the server, or possibly further attacks on other services utilizing SurgeLDAP for it's authentication data.

52. DeleGate SSLway Filter Remote Stack Based Buffer Overflow Vu...
BugTraq ID: 10295
Remote: Yes
Date Published: May 06 2004
Relevant URL: http://www.securityfocus.com/bid/10295
Summary:
A remote buffer overflow vulnerability has been reported to affect the DeleGate SSLway filter. This filter is employed when DeleGate is applying SSL to arbitrary protocols.

The issue presents itself due to a lack of sufficient boundary checks performed, when copying user-supplied certificate field contents.

A remote attacker may potentially exploit this issue, to overwrite the return address of the static ssl_prcert() function. The attacker may corrupt any other saved value that is within 768 bytes from the end of the affected buffers.

It has been reported that the X509_NAME_oneline() function will perform character conversion on characters below '0x20' or above '0x7e'; this may hinder exploitation of this issue.

53. KAME Racoon Remote IKE Message Denial Of Service Vulnerabili...
BugTraq ID: 10296
Remote: Yes
Date Published: May 06 2004
Relevant URL: http://www.securityfocus.com/bid/10296
Summary:
It has been reported that KAME is affected by a remote denial of service vulnerability when processing malformed IKE messages.  This issue is due to a failure of the daemon to properly handle malformed messages.

This issue can be leveraged to cause the affected daemon to enter an infinite loop; effectively denying service to legitimate users.

54. SuSE LINUX 9.1 Personal Edition Live CD-ROM SSH Server Defau...
BugTraq ID: 10297
Remote: Yes
Date Published: May 06 2004
Relevant URL: http://www.securityfocus.com/bid/10297
Summary:
It has been reported that SuSE LINUX 9.1 Personal Edition Live CD-ROM can allow an attacker to gain full access to a vulnerable system.  The issue presents itself when a user boots the machine with the affected CD-ROM.  It has been reported that due to a configuration error, the system configures an SSH server on the host with a default root account.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Prison time for cyber stock swindler
By: Kevin Poulsen

Teen scammer hacked a brokerage account to dump worthless Cisco options.
http://www.securityfocus.com/news/8564

2. Student hacks iTunes for compatibility
By: Patrick Gray

Weakness in Apple's authentication technology is music to iTunes hacker's ears. 

http://www.securityfocus.com/news/8561

3. Charges filed in 'Deceptive Duo' hacks
By: Kevin Poulsen

Benjamin Stark, a.k.a. "The-Rev," faces a felony conviction for allegedly cracking and defacing government systems for our own good. 

http://www.securityfocus.com/news/8559

4. New version of Sasser undermines lone coder theory
By: John Leyden, The Register

The appearance of a new version of the infamous Sasser worm shortly after the arrest of its admitted author has fuelled speculation that its creator worked with other virus writers.
http://www.securityfocus.com/news/8568

5. German teenager admits creating Sasser
By: Claus-Peter Tiemann, The Associated Press

http://www.securityfocus.com/news/8567

6. Mystery of MS's missing AV software
By: John Leyden, The Register

Microsoft's plans to improve the security of Windows through the purchase of an anti-virus company almost a year ago appear to be stuck in limbo. The software giant entered the AV market with the surprise acquisition of little known Romanian AV firm GeCAD Software for an undisclosed sum in June last year.
http://www.securityfocus.com/news/8566

IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Password Spyer 2k 2.4
By: Maro's Tools
Relevant URL: http://www.maros-tools.com/products/spyer/
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary: 

Password Spyer 2k is a password recovery tool for windows. Password Spyer 2k reveals passwords hidden by asterkis (***) in all windows version (including 2000 and XP). You can use it to recover lost or forgotten passwords in most windows applications such as outlook, cute ftp, ws ftp, ICQ and others. You can use it to also reveal saved web passwords. Password Spyer 2k supports two methods for revealing passwords for better password retrieval.

2. NatACL 1.0
By: Fabio Yasusi Yamamoto
Relevant URL: http://www.hostname.org/proxy_auth/
Platforms: FreeBSD, Java, NetBSD, OpenBSD
Summary: 

NatACL is a authentication daemon for NAT and Transparent Proxy.

The authentication input is done by the browser, it will redirect any URL to a internal page, asking for login and password.

If the login and password are correct, it will create a NAT rule to forward the traffic, or redirect to the proxy port ( in case of transparent proxy ).

3. PCX Firewall (CGI Web Frontend) 1.3
By: James A. Pattie
Relevant URL: http://pcxfirewall.sf.net/frontends/index.html
Platforms: Linux, POSIX
Summary: 

PCX Firewall is an IPTables firewalling solution that uses Perl to generate static shell scripts based upon the user's configuration settings. This allows the firewall to startup quickly, as it does not have to parse config files every time it starts.

4. Burp proxy 1.22 1.22
By: PortSwigger
Relevant URL: http://portswigger.net/proxy/
Platforms: Os Independent
Summary: 

Burp proxy is an interactive HTTP/S proxy server for attacking Web-enabled applications. It operates as a man-in-the-middle between the end browser and the target Web server, and allows the attacker to intercept, inspect, and modify the raw traffic passing in both directions. Text and hex editing may be performed on intercepted traffic. Downstream proxies are supported. Authentication may be done to downstream proxy and Web servers, using basic, NTLM, or digest authentication types.

5. GNUnet v0.6.2a
By: Christian Grothoff
Relevant URL: http://www.ovmj.org/GNUnet/
Platforms: FreeBSD, Linux, NetBSD, OpenBSD, POSIX
Summary: 

GNUnet is a peer-to-peer framework with focus on providing security. All link-to-link messages in the network are confidential and authenticated. The framework provides a transport abstraction layer and can currently encapsulate the peer-to-peer traffic in UDP, TCP, or SMTP messages. GNUnet supports accounting to provide contributing nodes with better service. The primary service build on top of the core GNUnet framework is anonymous file sharing.

6. FTimes v3.4.0
By: Klayton Monroe
Relevant URL: http://ftimes.sourceforge.net/FTimes/
Platforms: AIX, FreeBSD, Linux, MacOS, POSIX, Solaris, SunOS, Windows 2000, Windows NT
Summary: 

FTimes is a system baselining and evidence collection tool. Its primary purpose is to gather and/or develop information about specified directories and files in a manner conducive to intrusion analysis. It was designed to support the following initiatives: content integrity monitoring, incident response, intrusion analysis, and computer forensics.

V. SECURITYJOBS LIST SUMMARY
----------------------------
1. Sales Executive - Midwest (Chicago) (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362620

2. Practice Director Security Technologies (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362586

3. Cisco Security Agent Consultant (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362585

4. NY Sales Executive (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362584

5. SE - NY/Boston based (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362583

6. Information Security Project Manager - Wash DC (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362580

7. Information Security Specialist ? Wash DC (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362579

8. Looking for a Security Analyst position in Toronto, ... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362578

9. Security Engineer, STM Installation & Configuration (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362577

10. JOB: US-NY-NYC: Windows Security Engineer (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362575

11. SECURITY ENGINEER II WANTED - Charleston, SC (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362574

12. Security Engineer - (2 openings) New York, Bay Area ... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362573

13. NETWORK SECURITY ENGINEER III WANTED - Charleston, S... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362572

14. InfoSec job in Canberra (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362449

15. Lead Qualification Representatives (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362448

16. Security Vulnerability Analyst/Security Researcher -... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362447

17. Pre-Sales Systems Engineers - Symantec - St. Louis &... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362445

18. Unix Security Specialist - U. S. Government - Austin... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362444

19. Inside Sales Position - Bay Area, CA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362443

20. FW: AE - Security Sales, Phili (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362442

21. (job offered) Strategic Field Sales Exec - North Ame... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362372

22. Security Audit Principal Engineer at Citrix Systems ... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362355

23. IT Security Manager- Salt Lake, UT  $80-$105K (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362354

24. Sr. Security Software Developer/Analyst for Security... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362353

25. Director of Public Relations Silicon Valley (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362352

26. Unix Security Engineer London Uk (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362351

27. Security Software Developer at Citrix Systems in For... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362349

28. Pre Sales Security Engineer  Silicon Valley (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362348

29. Product Marketing Manager  Silicon Valley CA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362347

30. Product Planning & Strategy Senior Product Manager a... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362346

31. Director Quality Assurance Silicon Valley (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362345

32. Metaframe Password Manager Senior Security Software ... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362344

33. Seeking Common Criteria, Cryptography, or FIPS 140 r... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362303

34. FW: AE - Security Sales, SF, DC, Chi, Dall (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362298

35. Senior Security Software Developer/Analyst Florida (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362295

36. Security Architects in DC, VA, MA, TX (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362283

37. Sr. Software Engineer - Southern CA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362281

38. 3 salaried/full-time Senior SMS/Security Consultants... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362277

39. (job offered) Senior Consultant - Secure Technologie... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362275

40. Principal Consultant - Secure Technologies, Seattle,... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362274

41. Seeking  Information Security Systems contractor in ... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362261

42. Software Engineer, Security (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362258

43. Senior Security Consultant Chicago, IL  $90-$110K (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362251

44. Unix Security Engineer (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362248

45. Security Engineer, DC Metro Area (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362246

46. Sr. Security Analyst - AntiVirus - Southern CA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362245

47. Seeking contract Security Software Developer in Lond... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362215

48. Software Quality Assurance Engineer (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362214

49. Active Directory/Identity Mgt positions: HCA - Nashv... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362169

50. RelSec: Security Consultant - Risk Assessment/Audit/... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362168

51. Security Engineer - Columbus, OH (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362167

52. Manager & Sr. Manager in Dallas, TX (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362158

53. DIrector of Product Marketing MA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362151

54. San Diego Area Security Engineering/Information Assu... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362137

55. Security Engineer HIPAA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362131

56. Application Security Enginner (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362129

57. Pre-Sales Systems Engineer Need - Network Security (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362128

58. Risk Assessment Scientist (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362125

59. security event analyst (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362122

60. Engagement Manager (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362121

61. Senior Sales Executive Need - Chicago - Security (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362120

62. Senior Federal Sales Executive Need - DC - Security (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362118

63. ArcSight needs Regional Sales Manager, New York (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362116

64. CISSP, IAM and TS clearance Looking in DC Area (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362005

65. Perimeter Security Specialist needed in Boston (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/362002

VI. INCIDENTS LIST SUMMARY
--------------------------
1. SSH probes? (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/362662

2. Port 3889 Traffic (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/362659

3. Odd attack string (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/362165

4. Vacation trawling by the list moderator... please ig... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/362015

5. Increase in Port Scan Attempts? (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/361969

VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. unpacking UPX or PE-packed binaries (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/362590

2. Basic authentication with IIS 5, IE 6.0 on Windows 2... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/362589

VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. Relative Security Provided by Cached Domain Credenti... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/362656

2. RE: Restricting the change of the local administrato... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/362542

3. Restricting the change of the local administrator ac... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/362540

4. Restricting the change of the local administrator ac... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/362533

5. IE questions (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/362529

6. Restricting the change of the local administrator ac... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/362528

7. SecurityFocus Microsoft Newsletter #187 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/362009

IX. SUN FOCUS LIST SUMMARY
--------------------------
NO NEW POSTS FOR THE WEEK 2004-05-03 to 2004-05-10.

X. LINUX FOCUS LIST SUMMARY
---------------------------
1. Secure Form Script? (Thread)
Relevant URL:

http://www.securityfocus.com/archive/91/362763

2. decent loadbalancing with 2 different ISP's with min... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/91/362709

3. decent loadbalancing with 2 different ISP's with min... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/91/362708

XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.
    
XII. SPONSOR INFORMATION
-----------------------

This Issue is Sponsored By: SecurityFocus 

Want to keep up on the latest security vulnerabilities? Don't have time to
visit a myriad of mailing lists and websites to read the news? Just add
the new SecurityFocus RSS feeds to your freeware RSS reader, and see all
the latest posts for Bugtraq and the SF Vulnernability database in one
convenient place. Or, pull in the latest news, columnists and feature
articles in the SecurityFocus aggregated news feed, and stay on top of
what's happening in the community!

http://www.securityfocus.com/rss/index.shtml

------------------------------------------------------------------------