SecurityFocus Newsletter #249
Peter Laborge <[email protected]> 17 May 2004 16:42:12 -0000
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #249
------------------------------
This Issue is Sponsored By: TruSecure
FREE 14-DAY TRIAL: INTELLISHIELD ALERT MANAGER?
IS Alert Manager, TruSecure's threat and vulnerability service, helps
organizations better protect critical information assets with unmatched
intelligence and analysis from TruSecure's ICSA Labs and other resources.
Try it today! Sign up for your FREE 14-day trial below!
http://www.securityfocus.com/sponsor/TruSecure_sf-news_040517
------------------------------------------------------------------------
I. FRONT AND CENTER
1. Secure by Default
2. TCP/IP Skills Required for Security Analysts
II. BUGTRAQ SUMMARY
1. Qualcomm Eudora Embedded Hyperlink Buffer Overrun Vulnerabil...
2. Microsoft Internet Explorer Unconfirmed Memory Corruption Vu...
3. Trend Micro OfficeScan Weak Default Permissions Vulnerabilit...
4. Sun Java Runtime Environment Unspecified Remote Denial Of Se...
5. Linux Kernel Local IO Access Inheritance Vulnerability
6. MyWeb HTTP Server GET Request Buffer Overflow Vulnerability
7. EFFingerD Remote Buffer Overflow Vulnerability
8. Qualcomm Eudora Embedded Hyperlink URI Obfuscation Weakness
9. Adam Webb NukeJokes Module For PHP-Nuke Multiple Input Valid...
10. Microsoft Outlook 2003 Predictable File Location Weakness
11. Microsoft Internet Explorer Embedded Image URI Obfuscation W...
12. IBM Parallel Environment Network Table API Sample Code Undis...
13. Icecast Server Base64 Authorization Request Remote Buffer Ov...
14. MailEnable Mail Server HTTPMail Remote Heap Overflow Vulnera...
15. PHPShop Remote PHP Script Execution Vulnerability
16. Tutorials Manager Multiple Remote SQL Injection Vulnerabilit...
17. National Science Foundation Squid Proxy Internet Access Cont...
18. Open WebMail Remote Command Execution Variant Vulnerability
19. EMule Web Control Panel Denial Of Service Vulnerability
20. Microsoft Internet Explorer XML Parsing Denial Of Service Vu...
21. NetBSD/FreeBSD Port Systrace Exit Routine Access Validation ...
22. Microsoft Windows HSC DVD Driver Upgrade Code Execution Vuln...
23. Apple Mac OS X TrueBlueEnvironment Local Denial Of Service V...
24. Microsoft Outlook Mail Client E-mail Address Verification We...
25. Multiple Mail Transfer Agent Embedded Hyperlink URI Obfuscat...
26. Microsoft Windows Terminal Server Patch Unspecified Denial O...
27. Linux Kernel SCTP_SetSockOpt Integer Overflow Vulnerability
28. BEA WebLogic Server and WebLogic Express Denial of Service V...
29. BEA WebLogic Server And WebLogic Express Lowered Security Se...
30. Multiple Linksys Devices DHCP Information Disclosure and Den...
31. Linux Kernel Serial Driver Proc File Information Disclosure ...
32. Linux Kernel STRNCPY Information Leak Vulnerability
33. HP B6848AB GTK+ Library Insecure File Permissions Vulnerabil...
34. Symantec Client Firewall NetBIOS Name Service Response Buffe...
35. Symantec Client Firewall DNS Response Buffer Overflow Vulner...
36. Symantec Client Firewall NetBIOS Handler Remote Heap Overflo...
37. Symantec Client Firewall Remote DNS Response Denial Of Servi...
38. Opera Web Browser Address Bar Spoofing Weakness
39. Agnitum Outpost Firewall Remote Denial of Service Vulnerabil...
40. Sweex Wireless Broadband Router/Access Point Unauthorized Ac...
41. Triornis ZoneMinder Multiple Remote Buffer Overflow Vulnerab...
42. Opera Web Browser Telnet URI handler Arbitrary File Creation...
43. Multiple Vendor IEEE 802.11 Protocol Remote Denial Of Servic...
44. Mah-Jong Server NULL Pointer Dereference Remote Denial Of Se...
45. Microsoft Outlook Express URI Obfuscation Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
1. Sasser suspect has fans
2. New flaw takes WiFi off the air
3. Prison time for cyber stock swindler
4. Spam fighters infiltrate spam clubs
5. Symantec fights auto-responder menace
6. Dabber exploits Sasser flaw
IV. SECURITYFOCUS TOP 6 TOOLS
1. Syhunt TS Security Scanner 6.7 Build 96
2. Astaro Security Linux (Stable 5.x) v5.007
3. TinyCA v0.6.0
4. afick v2.2-0
5. OS-SIM v0.9.4
6. Automatic Firewall v0.3
V. SECURITYJOBS LIST SUMMARY
1. Senior Product Manager $90k + San Diego (Thread)
2. Sr. UI Developer (Thread)
3. Netscreen/Sygate Administrator - 25-35/hr - Seattle ... (Thread)
4. Sr. Technical Product Manager ? Network Security (Thread)
5. Principle SWE (Thread)
6. No VA / Annapolis Junction, MD Based INFOSEC Engine... (Thread)
7. IT APPLICATION SECURITY CONSULTANTS - Chicago - Inte... (Thread)
8. Policy, Standards and Guidance Coordinator - NYC (Thread)
9. NetSPI Sales Executive - Security Services - Minneap... (Thread)
10. NetSPI Security Consultant - Assessment Focus - Minn... (Thread)
11. Virus Analyst (Thread)
12. NYC and Dallas SE (Thread)
13. Sales Exec openings in Columbus, OH and California (Thread)
14. JOB: US-NY-NYC-Financial Firm: Senior Security Engin... (Thread)
15. Intrusion Detection System Engineer - Niles, IL - Gr... (Thread)
16. Firewall Engineer - Niles, IL - Grainger (Thread)
17. SAP Security Ananlyst (Thread)
18. Senior Implementation positions (Web Access Control/... (Thread)
19. Senior Identity Management position with Ernst & Yo... (Thread)
20. Management position with Ernst & Young Security and... (Thread)
21. Director Data Protection - Atlanta - $90-$100K (Thread)
22. W.W. Grainger - SAP Security Team Lead (Thread)
23. CISO with Sarbanes Oxley, CISA and CISSP, Los Angele... (Thread)
24. IT Security Auditor Essex UK (Thread)
25. IDS Signature Engineer - Fremont, CA (Thread)
26. Senior Implementation positions (Directory Service) ... (Thread)
27. Senior Advisory positions with Ernst & Young, Securi... (Thread)
28. Systems/Security Engineer - Santa Clara, CA (Thread)
29. IDS Engineers -- Washington, DC weekend shifts (Thread)
30. Looking for Network Security and or Project Manageme... (Thread)
31. Applied Watch Technologies: Sales Engineer - Chicago... (Thread)
32. Applied Watch: Technologies: DBA - Glenview, IL (Thread)
33. Professional Services Director vacancy (Thread)
34. SE in DC (Thread)
35. Senior Software Sales Exec ? Application Security (Thread)
36. New security consulting role (Thread)
37. Telecoms IT Security Auditor Riyadh Saudi Arabia (Thread)
38. Active Directory Development - Nashville, TN (Thread)
39. Metro Boston: Director of Prod Mktg, Network Securit... (Thread)
40. Please start putting job location in Subject Line! (Thread)
41. IP Network Security Architect (Thread)
42. Sr. Marketing Manager (Thread)
43. IT Security & IT Continuity Consultant (contract) (Thread)
44. Virus Analysts at Symantec in Santa Monica (Thread)
45. Symantec- Santa Monica Needs Windows Development Man... (Thread)
46. Operations Security/Intelligence Specialist - Northe... (Thread)
VI. INCIDENTS LIST SUMMARY
1. New Piece of spyware (Thread)
2. Crackers Targeting Web JetAdmin 6.5 Vulnerability (Thread)
3. New piece of spyware -- RESOLVED (Thread)
4. Solegg ? (Thread)
5. New piece of spyware? (Thread)
6. Dead Thread: New piece of spyware? (Thread)
7. Re: New piece of spyware? (Thread)
8. SSH probes? (Thread)
9. Somebody exploiting (badly designed) yahoo service? (Thread)
10. wmon16.exe (Thread)
11. Port 3889 Traffic (Thread)
12. wmon16 follow-up (Thread)
13. SecurityFocus new article announcement: Automating W... (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
1. IE Crash - Anyone Seen This Before? (Thread)
2. unpacking UPX or PE-packed binaries (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
1. Password Management with Services (Thread)
2. Sequential/incremental IPID in Windows IP stack (Thread)
3. Relative Security Provided by Cached Domain Credenti... (Thread)
4. Virus is getting domain account listing (Thread)
5. RKDetect - behaviour based rootkit detection utility (Thread)
6. NT and 2000 account policies administrations (Thread)
7. SecurityFocus Microsoft Newsletter #188 (Thread)
IX. SUN FOCUS LIST SUMMARY
1. sunscreen multiple independent stealth bridging (Thread)
X. LINUX FOCUS LIST SUMMARY
1. Secure Form Script? (Thread)
2. decent loadbalancing with 2 different ISP's with min... (Thread)
3. decent loadbalancing with 2 different ISP's with min... (Thread)
4. Did RedHat's OpenSSL patch miss Apache? (Thread)
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. Secure by Default
By Jason Miller
Why "Secure By Default" is a step in the right direction.
http://www.securityfocus.com/columnists/241
2. TCP/IP Skills Required for Security Analysts
By Don Parker
This article guides users new to the security field through some of the
key skills required to work as a security analyst. The focus is on core
TCP/IP competency and related technologies such as intrusion detection
systems, firewalls and routers.
http://www.securityfocus.com/infocus/1779
II. BUGTRAQ SUMMARY
-------------------
1. Qualcomm Eudora Embedded Hyperlink Buffer Overrun Vulnerabil...
BugTraq ID: 10298
Remote: Yes
Date Published: May 07 2004
Relevant URL: http://www.securityfocus.com/bid/10298
Summary:
Qualcomm Eudora is reported to be prone to a remotely exploitable buffer overrun vulnerability.
The issue is exposed when an excessively long hyperlink to a file resource is embedded in an HTML e-mail. This may permit remote attackers to execute arbitrary code via malicious e-mail in the context of the client user.
This issue was reported in Eudora on Windows platforms. Eudora for Apple Mac operating systems may be similarly affected, though this has not been confirmed.
2. Microsoft Internet Explorer Unconfirmed Memory Corruption Vu...
BugTraq ID: 10299
Remote: Yes
Date Published: May 07 2004
Relevant URL: http://www.securityfocus.com/bid/10299
Summary:
It has been reported that Internet Explorer may be prone to a potential memory corruption vulnerability that could allow a remote attacker to cause a denial of service condition in the browser. The issue is reported to present itself when an attacker creates a malicious site, which employs the 'onLoad' event and the 'window.location' javascript method to access a local file.
3. Trend Micro OfficeScan Weak Default Permissions Vulnerabilit...
BugTraq ID: 10300
Remote: No
Date Published: May 07 2004
Relevant URL: http://www.securityfocus.com/bid/10300
Summary:
It has been reported that OfficeScan is affected by weak default permissions vulnerabilities. This issue is due to insufficient default permissions on the application directory.
These issues would allow a local attacker or malicious software to deactivate the affected antivirus service without requiring any authorization; hosts thought to be secure might have a false sense of security.
4. Sun Java Runtime Environment Unspecified Remote Denial Of Se...
BugTraq ID: 10301
Remote: Yes
Date Published: May 07 2004
Relevant URL: http://www.securityfocus.com/bid/10301
Summary:
It has been reported that Sun's Java Runtime Environment, as well as the Java Software Development Kit are affected by an unspecified, remote denial of service vulnerability.
This issue would allow an attacker to cause the affected JRE to become unresponsive, denying service to legitimate users.
5. Linux Kernel Local IO Access Inheritance Vulnerability
BugTraq ID: 10302
Remote: No
Date Published: May 07 2004
Relevant URL: http://www.securityfocus.com/bid/10302
Summary:
It has been reported that the Linux Kernel is affected by an IO access inheritance vulnerability. This issue is due to an access validation error that fails to invalidate all io_bitmap pointers before a process exits.
This issue could allow local users to lock up the affected system, denying service to legitimate users. This issue might also allow an attacker to gain escalated privileges.
6. MyWeb HTTP Server GET Request Buffer Overflow Vulnerability
BugTraq ID: 10303
Remote: Yes
Date Published: May 07 2004
Relevant URL: http://www.securityfocus.com/bid/10303
Summary:
A vulnerability has been reported for MyWeb HTTP server. The problem occurs due to insufficient bounds checking when handling GET requests.
As a result, an attacker may be capable of corrupting sensitive data such as a return address, and thereby effectively control the execution flow of the program. This would ultimately allow for the execution of arbitrary code. Immediate consequences of exploitation of this issue may result in denial of service.
7. EFFingerD Remote Buffer Overflow Vulnerability
BugTraq ID: 10304
Remote: Yes
Date Published: May 08 2004
Relevant URL: http://www.securityfocus.com/bid/10304
Summary:
efFingerD has been reported prone to a remote buffer overflow vulnerability. The problem occurs due to insufficient bounds checking performed when handling requests.
As a result, an attacker may be capable of corrupting sensitive data such as a return address, and thereby effectively control the execution flow of the program. This would ultimately allow for the execution of arbitrary code. Immediate consequences of exploitation of this issue may result in denial of service.
8. Qualcomm Eudora Embedded Hyperlink URI Obfuscation Weakness
BugTraq ID: 10305
Remote: Yes
Date Published: May 08 2004
Relevant URL: http://www.securityfocus.com/bid/10305
Summary:
It has been reported that the Qualcomm Eudora MTA is prone to a URI obfuscation weakness that may hide the true contents of a link. The problem occurs when a user@location URI is formatted in such a way that a "^A" control character is located after the user value. The user value may then be appended with space characters to obfuscate status bar and mouseover details. It is said that, when doing a mouseover of such a URI, it will cause the status bar to only display the contents of the user value, not the entire link.
9. Adam Webb NukeJokes Module For PHP-Nuke Multiple Input Valid...
BugTraq ID: 10306
Remote: No
Date Published: May 08 2004
Relevant URL: http://www.securityfocus.com/bid/10306
Summary:
It has been reported that the NukeJokes module is affected by multiple input validation vulnerabilities. These issues are due to a failure of the application to properly sanitize user supplied user input.
Multiple SQL injection issues exists due to a failure of the application to do any sanitization on user input prior to using the offending input in an SQL query.
These SQL issues may allow a remote attacker to manipulate query logic, potentially leading to unauthorized access to sensitive information such as the administrator password hash or corruption of database data.
Multiple cross-site scripting vulnerabilities have been reported to exist due to a failure of the application to properly sanitize user-supplier input before its inclusion in dynamic web content.
These cross-site scripting issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were followed, the hostile code may be rendered in the web browser of the victim user.
10. Microsoft Outlook 2003 Predictable File Location Weakness
BugTraq ID: 10307
Remote: Yes
Date Published: May 10 2004
Relevant URL: http://www.securityfocus.com/bid/10307
Summary:
Microsoft Outlook 2003 is reported to be prone to store files that are specified in img tags, in predictable locations.
This may present a security risk because many known (and potential) Internet Explorer vulnerabilities depend on the attacker being able to directly reference malicious content on a victim system. Given both the ability to place such content on the file system and reference it specifically by location, exploitation of many browser-based vulnerabilities becomes possible.
11. Microsoft Internet Explorer Embedded Image URI Obfuscation W...
BugTraq ID: 10308
Remote: Yes
Date Published: May 10 2004
Relevant URL: http://www.securityfocus.com/bid/10308
Summary:
It has been reported that Microsoft Internet Explorer is prone to a URI obfuscation weakness that may hide the true contents of a URI link. The issue occurs when an image is contained within a properly formatted HREF tag.
This weakness could be employed to trick a user into following a malicious link.
An attacker could exploit this issue by supplying a malicious image that appears to be a URI link pointing to a page designed to mimic that of a trusted site. If an unsuspecting victim were to mouseover the link in an attempt to verify the authenticity of where it references, they may be deceived into believing that the link references the actual trusted site.
12. IBM Parallel Environment Network Table API Sample Code Undis...
BugTraq ID: 10310
Remote: No
Date Published: May 10 2004
Relevant URL: http://www.securityfocus.com/bid/10310
Summary:
IBM Parallel Environment for AIX has been reported prone to an undisclosed command execution vulnerability. The issue is reported to present itself within the Parallel Environment network table API sample code.
It is reported that this vulnerability may be exploited by a local user to execute commands with root privileges.
13. Icecast Server Base64 Authorization Request Remote Buffer Ov...
BugTraq ID: 10311
Remote: Yes
Date Published: May 10 2004
Relevant URL: http://www.securityfocus.com/bid/10311
Summary:
It has been reported that Icecast server may be prone to a remote buffer overflow vulnerability when processing an excessively long base64 authentication request. A remote attacker could execute arbitrary code in the context of the server leading to unauthorized access.
This issue is reported to exist in Icecast 2.0.0, however, it is possible that previous versions are affected as well.
14. MailEnable Mail Server HTTPMail Remote Heap Overflow Vulnera...
BugTraq ID: 10312
Remote: Yes
Date Published: May 09 2004
Relevant URL: http://www.securityfocus.com/bid/10312
Summary:
MailEnable is a commercially available POP3 and SMTP server for the Windows platform.
The 'Professional' and 'Enterprise' editions of MailEnable are reported to be prone to a remote heap buffer overflow. The overflow allows the attacker to control the EAX and ECX registers, allowing arbitrary code execution as SYSTEM.
All versions up to and including 1.18 are reported to be affected.
15. PHPShop Remote PHP Script Execution Vulnerability
BugTraq ID: 10313
Remote: Yes
Date Published: May 10 2004
Relevant URL: http://www.securityfocus.com/bid/10313
Summary:
Reportedly phpShop is affected by a remote PHP script execution vulnerability. This issue is due to improper validation of user-supplied variables passed to the application via URI, POST or COOKIE parameters.
This issue is present whether or not the PHP Apache module is configured with 'register_globals' turned off or on.
This issue would allow an attacker to execute arbitrary PHP scripts on an affected host; issuing commands to the underlying operating system with the privileges of the web server is possible.
16. Tutorials Manager Multiple Remote SQL Injection Vulnerabilit...
BugTraq ID: 10314
Remote: Yes
Date Published: May 10 2004
Relevant URL: http://www.securityfocus.com/bid/10314
Summary:
Reportedly Tutorials Manager is affected by multiple SQL injection vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied input.
These SQL injection issues might allow a remote attacker to manipulate query logic, potentially leading to unauthorized access to sensitive information such as the administrator password hash or corruption of database data. SQL injection attacks may also potentially be used to exploit latent vulnerabilities in the underlying database implementation.
17. National Science Foundation Squid Proxy Internet Access Cont...
BugTraq ID: 10315
Remote: Yes
Date Published: May 10 2004
Relevant URL: http://www.securityfocus.com/bid/10315
Summary:
Squid proxy has been reported to be affected by an Internet access control bypass vulnerability. This issue is caused by a failure of the application to properly handle access controls when evaluating malformed URI requests.
This issue is reported to affect version 2.3.STABLE5 of the software, it is likely however that other versions are also affected.
This issue would allow users that are restricted from accessing Internet-based resources to access arbitrary web sites.
18. Open WebMail Remote Command Execution Variant Vulnerability
BugTraq ID: 10316
Remote: Yes
Date Published: May 10 2004
Relevant URL: http://www.securityfocus.com/bid/10316
Summary:
A vulnerability has been reported in Open WebMail that allows a remote attacker to execute arbitrary commands on a vulnerable host. The problem is due to insufficient sanitization of shell metacharacters that are passed to the vulnerable software through URI parameters.
Exploitation of the vulnerability could allow a non-privileged user to remotely execute arbitrary commands in the context of the web server that is hosting the vulnerable application.
19. EMule Web Control Panel Denial Of Service Vulnerability
BugTraq ID: 10317
Remote: Yes
Date Published: May 10 2004
Relevant URL: http://www.securityfocus.com/bid/10317
Summary:
It has been reported that eMule's Web Control Panel is susceptible to a remote denial of service vulnerability.
This issue is reportedly triggered by sending malformed requests to the web interface. Upon processing malformed requests, the affected application will crash, denying service to legitimate users.
20. Microsoft Internet Explorer XML Parsing Denial Of Service Vu...
BugTraq ID: 10318
Remote: Yes
Date Published: May 10 2004
Relevant URL: http://www.securityfocus.com/bid/10318
Summary:
Internet Explorer is reportedly affected by a XML parsing denial of service vulnerability. This issue is due to a failure of the application to properly handle malformed XML tags.
Successful exploitation of this issue might allow a remote attacker to crash a vulnerable web browser.
21. NetBSD/FreeBSD Port Systrace Exit Routine Access Validation ...
BugTraq ID: 10320
Remote: No
Date Published: May 11 2004
Relevant URL: http://www.securityfocus.com/bid/10320
Summary:
A vulnerability has been reported that affects Systrace on NetBSD, as well as the FreeBSD port by Vladimir Kotal.
The source of the issue is insufficient access validation when a systraced process is restoring privileges.
This issue can be exploited by a local attacker to gain root privileges on a vulnerable system.
22. Microsoft Windows HSC DVD Driver Upgrade Code Execution Vuln...
BugTraq ID: 10321
Remote: Yes
Date Published: May 11 2004
Relevant URL: http://www.securityfocus.com/bid/10321
Summary:
A security vulnerability has been reported in Microsoft Windows XP and Server 2003 operating systems. This issue exists in the Help and Support Center (HSC) and is due to how the feature handles HCP invocation URIs for DVD driver upgrades.
This issue could be exploited from a malicious web page or HTML e-mail to cause a malicious executable to be run on a vulnerable system. This would occur in the context of the victim user, though it has been reported that significant user interaction is required for exploitation to occur.
While this issue may be exploited through Internet Explorer, it should also be noted that third-party web client software could also invoke HSC via a HCP URI.
23. Apple Mac OS X TrueBlueEnvironment Local Denial Of Service V...
BugTraq ID: 10322
Remote: No
Date Published: May 11 2004
Relevant URL: http://www.securityfocus.com/bid/10322
Summary:
It has been reported that TrueBlueEnvironment is affected by a local denial of service vulnerability. This issue is due to an inability of the application to properly handle user input.
This issue could be leveraged to lock up the affected system, denying service to legitimate users. Reportedly a reboot is required to return the system to a usable state.
24. Microsoft Outlook Mail Client E-mail Address Verification We...
BugTraq ID: 10323
Remote: Yes
Date Published: May 11 2004
Relevant URL: http://www.securityfocus.com/bid/10323
Summary:
It has been reported that Microsoft Outlook mail client may be prone to a weakness that could allow a remote attacker to verify the validity of a recipient's e-mail address. This issue may result in a victim receiving more junk e-mail.
Microsoft Outlook 2003 is reported to be affected by this issue.
25. Multiple Mail Transfer Agent Embedded Hyperlink URI Obfuscat...
BugTraq ID: 10324
Remote: Yes
Date Published: May 11 2004
Relevant URL: http://www.securityfocus.com/bid/10324
Summary:
It has been reported that multiple Mail Transfer Agents are prone to a URI obfuscation weakness variant that may hide the true contents of a link. The problem occurs when a URI is formatted in such a way that a "*" character is located after the initial URI and a secondary URI is appended to this string. It is said that, when performing a mouseover of such a URI, it will cause the status bar to only display the contents of the first URI value, not the entire link.
This could be used to trick a user into following a malicious link.
26. Microsoft Windows Terminal Server Patch Unspecified Denial O...
BugTraq ID: 10325
Remote: Unknown
Date Published: May 11 2004
Relevant URL: http://www.securityfocus.com/bid/10325
Summary:
The Terminal Server patch issued in Microsoft advisory MS01-052 has been found to be prone to an unspecified denial of service vulnerability. The affected patch was originally issued to deal with the issue outlined in the Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability (BID 3445).
This issue could be leveraged to cause the affected server to stop responding, denying service to legitimate users.
27. Linux Kernel SCTP_SetSockOpt Integer Overflow Vulnerability
BugTraq ID: 10326
Remote: No
Date Published: May 11 2004
Relevant URL: http://www.securityfocus.com/bid/10326
Summary:
An integer overflow vulnerability has been reported in the sctp_setsockopt() system call of the Linux kernel. This issue is related to the code for handling the SCTP_SOCKOPT_DEBUG_NAME socket option.
The issue presents itself in the sctp_setsockopt() function of the net/sctp/socket.c source file, due to a lack of sufficient validation performed on user supplied integer values.
This vulnerbaility may result in the allocation of a zero byte chunk in kernel memory space. Likely resulting in a kernel panic. The issue may also potentially be exploited however to compromise the system.
This vulnerability is reported to affect Linux kernel versions up to and including version 2.4.25.
28. BEA WebLogic Server and WebLogic Express Denial of Service V...
BugTraq ID: 10327
Remote: No
Date Published: May 11 2004
Relevant URL: http://www.securityfocus.com/bid/10327
Summary:
It has been reported that WebLogic Server and WebLogic Express are prone to a denial of service vulnerability that may allow an attacker to shut down a vulnerable server. The issue presents itself when a site restricts the ability to start or stop servers to users in the Admin and Operator security role.
29. BEA WebLogic Server And WebLogic Express Lowered Security Se...
BugTraq ID: 10328
Remote: No
Date Published: May 11 2004
Relevant URL: http://www.securityfocus.com/bid/10328
Summary:
BEA WebLogic Builder and the SecurityRoleAssignmentMBean.toXML() method are reported prone to an issue that could result in security properties of a Servlet container being compromised. This will result in the Servlet container assigning default settings for the security role, resulting in the web application being available to unauthorized users.
30. Multiple Linksys Devices DHCP Information Disclosure and Den...
BugTraq ID: 10329
Remote: Yes
Date Published: May 13 2004
Relevant URL: http://www.securityfocus.com/bid/10329
Summary:
It has been reported that the built-in DHCP server on these devices are prone to an information disclosure vulnerability. When attempting to exploit this issue, it has been reported that a denial of service condition may occur, stopping legitimate users from using the device.
The DHCP server application on the device reportedly does not handle BOOTP packets properly, and can disclose the contents of the devices memory to an attacker. It may be possible for an attacker to use this vulnerability to watch traffic on an affected device. It may also be possible for an attacker to crash the device and deny service to legitimate users.
31. Linux Kernel Serial Driver Proc File Information Disclosure ...
BugTraq ID: 10330
Remote: No
Date Published: May 12 2004
Relevant URL: http://www.securityfocus.com/bid/10330
Summary:
It has been reported that the Linux kernel is prone to a serial driver proc file information disclosure vulnerability. This issue is due to a design error that allows unprivileged access to potentially sensitive information.
This issue might allow an attacker to gain access to sensitive information such as user password lengths.
32. Linux Kernel STRNCPY Information Leak Vulnerability
BugTraq ID: 10331
Remote: No
Date Published: May 12 2004
Relevant URL: http://www.securityfocus.com/bid/10331
Summary:
This issue is reported to affect the vulnerable kernel only on platforms other than x86.
It has been reported that the Linux kernel is prone to a 'strncpy()' information leak vulnerability. This issue is due to a failure of the libc code to properly implement the offending function on platforms other than x86.
This issue might lead to information leakage, potentially facilitating further attacks against an affected system or process.
33. HP B6848AB GTK+ Library Insecure File Permissions Vulnerabil...
BugTraq ID: 10332
Remote: No
Date Published: May 12 2004
Relevant URL: http://www.securityfocus.com/bid/10332
Summary:
HP B6848AB GTK+ Support Library may provide for local privilege escalation. The issue is due to weak default permissions that are set on the installation directories and library files during installation.
This vulnerability may be exploited to execute code with elevate privileges.
34. Symantec Client Firewall NetBIOS Name Service Response Buffe...
BugTraq ID: 10333
Remote: Yes
Date Published: May 12 2004
Relevant URL: http://www.securityfocus.com/bid/10333
Summary:
It has been reported that Symantec Client Firewall products may be prone to a remote buffer overflow vulnerability when processing NetBIOS Name Service responses. As a result, an attacker on a local network could respond to a NetBIOS Name Service query from a client and send a malformed response in return that overflows a vulnerable buffer.
A successful attack could allow an attacker to gain SYSTEM level privileges on a vulnerable system.
35. Symantec Client Firewall DNS Response Buffer Overflow Vulner...
BugTraq ID: 10334
Remote: Yes
Date Published: May 12 2004
Relevant URL: http://www.securityfocus.com/bid/10334
Summary:
A remotely exploitable buffer overflow vulnerability has been reported in various Symantec Firewall Products. Affected products include Norton Internet Security, Norton Personal Firewall, Norton AntiSpam, Client Firewall, and Client Security.
The issue is due to insufficient bounds checking of DNS response data and may be exploited to gain SYSTEM/kernel level access to a computer hosting the vulnerable software.
The source of the vulnerability is that the CNAME (Canonical Name) data field specified in incoming DNS Resource Records is copied into an internal buffer in an insecure manner, resulting in a stack-based buffer overflow.
36. Symantec Client Firewall NetBIOS Handler Remote Heap Overflo...
BugTraq ID: 10335
Remote: Yes
Date Published: May 12 2004
Relevant URL: http://www.securityfocus.com/bid/10335
Summary:
Symantec Client Firewall products have been reported prone to a remote heap memory corruption vulnerability. This vulnerability will result in the corruption of inline heap memory management structures, and may ultimately be exploited by a remote attacker to execute arbitrary code on the affected system.
37. Symantec Client Firewall Remote DNS Response Denial Of Servi...
BugTraq ID: 10336
Remote: Yes
Date Published: May 12 2004
Relevant URL: http://www.securityfocus.com/bid/10336
Summary:
Various Symantec Client Firewall products are prone to a remote denial of service vulnerability.
This vulnerability is due to a failure of the application to properly handle DNS response packets.
38. Opera Web Browser Address Bar Spoofing Weakness
BugTraq ID: 10337
Remote: Yes
Date Published: May 13 2004
Relevant URL: http://www.securityfocus.com/bid/10337
Summary:
Opera Web Browser is prone to a security weakness that may permit malicious web pages to spoof address bar information.
This is reportedly possible through malicious use of the JavaScript "unOnload" event handler when the browser is redirected to another page.
This issue could be exploited to spoof the domain of a malicious web page, potentially causing the victim user to trust the spoofed domain.
The vulnerability reportedly affects Opera 7.23 releases on Windows and Linux platforms. Earlier versions may also be affected.
39. Agnitum Outpost Firewall Remote Denial of Service Vulnerabil...
BugTraq ID: 10338
Remote: Yes
Date Published: May 13 2004
Relevant URL: http://www.securityfocus.com/bid/10338
Summary:
It has been reported that Outpost Firewall may be prone to a remote denial of service vulnerability that could allow an attacker to crash or hang the application. The issue is reported to present itself when an attacker sends multiple incomplete requests to the application.
Agnitum Outpost Pro Firewall version 2.1 is reported to be affected by this issue, however, prior versions may be vulnerable as well.
40. Sweex Wireless Broadband Router/Access Point Unauthorized Ac...
BugTraq ID: 10339
Remote: Yes
Date Published: May 13 2004
Relevant URL: http://www.securityfocus.com/bid/10339
Summary:
It has been reported that Sweex Wireless Broadband Router/Access Point is prone to a vulnerability that may allow a remote attacker to gain unauthorized access to a vulnerable access point. It has been reported that the access point has a TFTP service running that is enabled by default.
Successful exploitation of this issue may allow a remote attacker to gain access to sensitive information that could eventually allow an attacker to completely compromise the access point.
Sweex Wireless Broadband Router/Access Point 11g is reported to be prone to this issue.
41. Triornis ZoneMinder Multiple Remote Buffer Overflow Vulnerab...
BugTraq ID: 10340
Remote: Yes
Date Published: May 13 2004
Relevant URL: http://www.securityfocus.com/bid/10340
Summary:
Reportedly ZoneMinder is affected by multiple remote buffer overflow vulnerabilities, potentially leading to unauthorized access. These issues are due to a failure of the application to properly validate buffer boundaries when processing user input.
These issues could allow a remote attacker to execute arbitrary code in the context of the affected software, which could lead to unauthorized access.
42. Opera Web Browser Telnet URI handler Arbitrary File Creation...
BugTraq ID: 10341
Remote: Yes
Date Published: May 13 2004
Relevant URL: http://www.securityfocus.com/bid/10341
Summary:
It has been reported that Opera web browser is prone to a vulnerability that may allow a remote attacker to create and modify arbitrary files on a system. The vulnerability presents itself because the telnet URI handler in Opera fails to sanitize user-supplied input. Specifically, if a '-' character is present at the beginning of a host name, options may be passed to the telnet program to carry out an attack remotely.
Opera version 7.23 is reported to be affected by this issue. Earlier versions may also be affected.
**It has been reported that various web browsers are affected by this issue. The affected products include Apple Safari, Microsoft Internet Explorer, Mozilla Firefox, OmniWeb, iCab, TrailBlazer, and possibly others. These applications are currently undergoing further review and individual BIDs will be created when more information becomes available.
43. Multiple Vendor IEEE 802.11 Protocol Remote Denial Of Servic...
BugTraq ID: 10342
Remote: Yes
Date Published: May 13 2004
Relevant URL: http://www.securityfocus.com/bid/10342
Summary:
It has been reported that the IEEE 802.11 wireless network protocol is affected by a remote denial of service vulnerability. This issue is due to a design error that might cause an affected device to stop transmitting network data through wireless mediums.
This issue is reported to affect only wireless hardware devices that implement IEEE 802.11 using a DSSS physical layer.
This issue might allow an attacker to cause all nodes on a wireless network, both access points and hosts, to stop transmitting network data; this would effectively cause a network wide denial of service condition.
44. Mah-Jong Server NULL Pointer Dereference Remote Denial Of Se...
BugTraq ID: 10343
Remote: Yes
Date Published: May 13 2004
Relevant URL: http://www.securityfocus.com/bid/10343
Summary:
It has been reported that Mah-Jong server is prone to a remote denial of service vulnerability that may cause the server to crash. The issue has been reported to be exploitable so that a remote attacker may cause a vulnerable server to crash by dereferencing a NULL pointer.
It is not currently known whether this issue is restricted to Debian maintained versions of mah-jong or not. Although unconfirmed, other versions may also be affected.
45. Microsoft Outlook Express URI Obfuscation Vulnerability
BugTraq ID: 10345
Remote: Yes
Date Published: May 13 2004
Relevant URL: http://www.securityfocus.com/bid/10345
Summary:
Microsoft Outlook Express has been reported prone to a URI obfuscation vulnerability.
This issue is reported to affect version 6.0 of the affected software, other versions might also be affected.
An attacker could reportedly get a user to visit an attacker controlled site without the usual address bar feature in a web browser. This could potentially make it easier for an attacker to fool a user into trusting the site contents.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Sasser suspect has fans
By: Kevin Poulsen
Free Jaschan site pops up in record time, and quickly begins raising money.
http://www.securityfocus.com/news/8581
2. New flaw takes WiFi off the air
By: Patrick Gray
Vandals could jam nearby wireless networks with ease, researchers find.
http://www.securityfocus.com/news/8575
3. Prison time for cyber stock swindler
By: Kevin Poulsen
Teen scammer hacked a brokerage account to dump worthless Cisco options.
http://www.securityfocus.com/news/8564
4. Spam fighters infiltrate spam clubs
By: John Leyden, The Register
Spam fighters are gaining vital clues in the battle to keep in-boxes clean of junk mail by infiltrating spammer clubs.
Online spammer forums like the <a target=_blank href="http://www.emaillistclub.com/">Pro Bulk Club</a> the <a target=_blank href="http://www.thebulkclub.com/">Bulk Club</a> and <a target=_blank href="http://www.bulkmails.org/">bulkmails.org</a> have been gatecrashed by activists from organisations like Spamhaus. Steve Linford of Spamhaus said spammers know this already but they don't know who amongst their number is working for the other side. In theory invitation to the members-only forums of these sites is only by invitation and only to individuals who have a proven track record in spamming. Apart from playing with the paranoia of spammers, the undercover investigation cast light on the latest spammer techniques.
http://www.securityfocus.com/news/8580
5. Symantec fights auto-responder menace
By: John Leyden, The Register
Virus notification alerts will hopefully become less of a nuisance after modifications to Symantec's mail server security products announced this week.
Mass mailing viruses frequently spoof the sender's address in infected emails sent out from pox-ridden PCs. This forged email address is often randomly plucked off the infected computer by a virus.
http://www.securityfocus.com/news/8579
6. Dabber exploits Sasser flaw
By: John Leyden, The Register
Virus writers have created a worm that exploits coding flaws in the infamous Sasser worm to spread.
<a target=_blank href="http://www.lurhq.com/dabber.html">Dabber</a> uses a flaw in the FTP server component of the Sasser worm. The worm will only infect users already infected by Sasser, according to security services firm LURHQ. "Even though we have seen worms utilize backdoors left behind by other worms, this is the first time we have seen a worm using a vulnerability in another worm in order to propagate," it said.
http://www.securityfocus.com/news/8578
IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Syhunt TS Security Scanner 6.7 Build 96
By: Syhunt
Relevant URL: http://www.syhunt.com/section.php?id=scanner
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
Syhunt TS Security Scanner is able to find the unfindable, not only known vulnerabilities, but also potential new ones. The new version can identify and exploit vulnerabilities in a matter of minutes and is a key tool for security professionals and administrators.
2. Astaro Security Linux (Stable 5.x) v5.007
By: astaro
Relevant URL: http://www.astaro.com/
Platforms: Linux, POSIX
Summary:
Astaro Security Linux is a firewall solution. It does stateful packet inspection filtering, content filtering, user authentication, virus scanning, VPN with IPSec and PPTP, and much more. With its Web-based management tool, WebAdmin, and the ability to pull updates via the Internet, it is pretty easy to manage. It is based on a special hardened Linux 2.4 distribution where most daemons are running in change-roots and are protected by kernel capabilities.
3. TinyCA v0.6.0
By: Stephan Martin
Relevant URL: http://tinyca.sm-zone.net/
Platforms: Linux, OpenNMS, POSIX
Summary:
TinyCA is a simple GUI written in Perl/Tk to manage a small certification authority. It is based on OpenSSL and Perl modules from the OpenCA project. TinyCA lets you manage x509 certificates. It is possible to export data in PEM or DER format for use with servers, as PKCS#12 for use with clients, or as S/MIME certificates for use with email programs. It is also possible to import your own PKCS#10 requests and generate certificates from them.
4. afick v2.2-0
By: Gerbier Eric
Relevant URL: http://afick.sourceforge.net/
Platforms: Os Independent
Summary:
afick is another file integrity checker, designed to be fast and fully portable between Unix and Windows platforms. It works by first creating a database that represents a snapshot of the most essential parts of your computer system. You can then run the script to discover all modifications made since the snapshot was taken (i.e. files added, changed, or removed). The configuration syntax is very close to that of aide or tripwire, and a graphical interface is provided.
5. OS-SIM v0.9.4
By: Dominique Karg
Relevant URL: http://www.ossim.net/
Platforms: Linux, MacOS, POSIX
Summary:
OSSIM pretends to unify network monitoring, security, correlation, and qualification in one single tool. It combines Snort, Acid, HotSaNIC, NTOP, OpenNMS, nmap, nessus, and rrdtool to provide the user with full control over every aspect of networking or security.
6. Automatic Firewall v0.3
By: Baruch Even
Relevant URL: http://baruch.ev-en.org/proj/autofw/autofw.html
Platforms: Linux
Summary:
Automatic Firewall configures your firewall by looking at your environment and deciding what is a good fit for your needs. It is intended for the novice broadband user to install and forget about, but still be fairly well protected.
V. SECURITYJOBS LIST SUMMARY
----------------------------
1. Senior Product Manager $90k + San Diego (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363493
2. Sr. UI Developer (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363491
3. Netscreen/Sygate Administrator - 25-35/hr - Seattle ... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363490
4. Sr. Technical Product Manager ? Network Security (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363489
5. Principle SWE (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363488
6. No VA / Annapolis Junction, MD Based INFOSEC Engine... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363487
7. IT APPLICATION SECURITY CONSULTANTS - Chicago - Inte... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363483
8. Policy, Standards and Guidance Coordinator - NYC (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363481
9. NetSPI Sales Executive - Security Services - Minneap... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363480
10. NetSPI Security Consultant - Assessment Focus - Minn... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363479
11. Virus Analyst (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363478
12. NYC and Dallas SE (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363477
13. Sales Exec openings in Columbus, OH and California (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363476
14. JOB: US-NY-NYC-Financial Firm: Senior Security Engin... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363475
15. Intrusion Detection System Engineer - Niles, IL - Gr... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363474
16. Firewall Engineer - Niles, IL - Grainger (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363473
17. SAP Security Ananlyst (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363472
18. Senior Implementation positions (Web Access Control/... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363142
19. Senior Identity Management position with Ernst & Yo... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363141
20. Management position with Ernst & Young Security and... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363138
21. Director Data Protection - Atlanta - $90-$100K (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363137
22. W.W. Grainger - SAP Security Team Lead (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363133
23. CISO with Sarbanes Oxley, CISA and CISSP, Los Angele... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363131
24. IT Security Auditor Essex UK (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363119
25. IDS Signature Engineer - Fremont, CA (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363118
26. Senior Implementation positions (Directory Service) ... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363114
27. Senior Advisory positions with Ernst & Young, Securi... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363113
28. Systems/Security Engineer - Santa Clara, CA (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363082
29. IDS Engineers -- Washington, DC weekend shifts (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363081
30. Looking for Network Security and or Project Manageme... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363079
31. Applied Watch Technologies: Sales Engineer - Chicago... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363077
32. Applied Watch: Technologies: DBA - Glenview, IL (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363075
33. Professional Services Director vacancy (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363061
34. SE in DC (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363048
35. Senior Software Sales Exec ? Application Security (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363043
36. New security consulting role (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363040
37. Telecoms IT Security Auditor Riyadh Saudi Arabia (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363037
38. Active Directory Development - Nashville, TN (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363036
39. Metro Boston: Director of Prod Mktg, Network Securit... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363035
40. Please start putting job location in Subject Line! (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/363034
41. IP Network Security Architect (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/362934
42. Sr. Marketing Manager (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/362915
43. IT Security & IT Continuity Consultant (contract) (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/362905
44. Virus Analysts at Symantec in Santa Monica (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/362838
45. Symantec- Santa Monica Needs Windows Development Man... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/362835
46. Operations Security/Intelligence Specialist - Northe... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/362723
VI. INCIDENTS LIST SUMMARY
--------------------------
1. New Piece of spyware (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/363514
2. Crackers Targeting Web JetAdmin 6.5 Vulnerability (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/363513
3. New piece of spyware -- RESOLVED (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/363512
4. Solegg ? (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/363343
5. New piece of spyware? (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/363325
6. Dead Thread: New piece of spyware? (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/363324
7. Re: New piece of spyware? (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/363289
8. SSH probes? (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/363073
9. Somebody exploiting (badly designed) yahoo service? (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/363038
10. wmon16.exe (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/362919
11. Port 3889 Traffic (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/362877
12. wmon16 follow-up (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/362867
13. SecurityFocus new article announcement: Automating W... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/362773
VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. IE Crash - Anyone Seen This Before? (Thread)
Relevant URL:
http://www.securityfocus.com/archive/82/363471
2. unpacking UPX or PE-packed binaries (Thread)
Relevant URL:
http://www.securityfocus.com/archive/82/362797
VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. Password Management with Services (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/363298
2. Sequential/incremental IPID in Windows IP stack (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/363295
3. Relative Security Provided by Cached Domain Credenti... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/363140
4. Virus is getting domain account listing (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/363018
5. RKDetect - behaviour based rootkit detection utility (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/363015
6. NT and 2000 account policies administrations (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/363012
7. SecurityFocus Microsoft Newsletter #188 (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/362945
IX. SUN FOCUS LIST SUMMARY
--------------------------
1. sunscreen multiple independent stealth bridging (Thread)
Relevant URL:
http://www.securityfocus.com/archive/92/363397
X. LINUX FOCUS LIST SUMMARY
---------------------------
1. Secure Form Script? (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/363468
2. decent loadbalancing with 2 different ISP's with min... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/362894
3. decent loadbalancing with 2 different ISP's with min... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/362893
4. Did RedHat's OpenSSL patch miss Apache? (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/362892
XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XII. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored By: TruSecure
FREE 14-DAY TRIAL: INTELLISHIELD ALERT MANAGER?
IS Alert Manager, TruSecure's threat and vulnerability service, helps
organizations better protect critical information assets with unmatched
intelligence and analysis from TruSecure's ICSA Labs and other resources.
Try it today! Sign up for your FREE 14-day trial below!
http://www.securityfocus.com/sponsor/TruSecure_sf-news_040517
------------------------------------------------------------------------