SecurityFocus Newsletter #147

John Boletta <[email protected]>
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #147
-----------------------------

This issue sponsored by: Aladdin's eToken.

Enhance Windows network security with flexible, affordable USB-based
strong authentication.

-Out-of-the-box support for Microsoft 2000 SmartCard logon and for NT (98,
ME) network logon.

-Store network passwords on a small, secure USB device, or replace them
with random passwords that users never see.

-Keep users' private credentials, certificates, keys, and access profiles
in a trusted environment.

eToken from Aladdin.  Strong authentication made simple.

http://www.ealaddin.com/etoken/enterprise/datasheets/DS_Win2000_SC_Logon.asp
?cf=tl
[email protected]
1-800-562-2543

-------------------------------------------------------------------------------

I. FRONT AND CENTER
     1. Securing Privacy Part Four: Internet Issues
     2. PortSentry for Attack Detection - Part Two
     3. Black Hat Briefings
     4. Secure i-World
II. BUGTRAQ SUMMARY
     1. CVS Daemon RCS Off By One Local Buffer Overflow Vulnerability
     2. PHPBB2 Image Tag HTML Injection Vulnerability
     3. Microsoft IIS 5.0 Denial Of Service Vulnerability
     4. Microsoft Active Data Objects Buffer Overflow Vulnerability
     5. Microsoft Commerce Server 2000 Remote Buffer Overflow...
     6. Microsoft Windows HTML Help ActiveX Control Multiple...
     7. Tomahawk Technologies SteelArrow Web Application Server...
     8. Virtual Programming VP-ASP SQL Injection Vulnerability
     9. DataWizard FtpXQ Buffer Overflow Vulnerability
     10. TransSoft FTP-Broker Denial of Service Vulnerability
     11. FileZilla FTP Server Directory Traversal Vulnerability
     12. ECS K7S5A Boot Menu Access Vulnerability
     13. phpTest Test Result Disclosure Vulnerability
     14. Firestorm IDS IP Options Decoding Denial Of Service Vulnerability
     15. Image Display System Directory Existence Disclosure Vulnerability
     16. Charities.Cron Insecure Temporary File Creation Vulnerability
     17. Macromedia JRun Host Header Field Buffer Overflow Vulnerability
     18. Trend Micro Interscan Viruswall SMTP Header Removal Vulnerability
     19. IRSSI Trojaned Configure File Arbitrary Access Vulnerability
     20. Opera Arbitrary File Disclosure Vulnerability
     21. BlueFace Falcon Web Server File Disclosure Vulnerability
     22. TightVNC Plain Text Password Storage Vulnerability
     23. Yahoo! Messenger Call Center Buffer Overflow Vulnerability
     24. Yahoo! Instant Messenger Script Injection Vulnerability
     25. AMANDA amindexd Remote Buffer Overflow Vulnerability
     26. TightVNC Listening Viewer Multiple Non-Shared Connections DoS...
     27. AMANDA amcheck Local Buffer Overflow Vulnerability
     28. 3Com OfficeConnect ADSL Router Port Address Translation...
     29. NetScreen ScreenOS Remote Reboot Vulnerability
     30. Oracle Application Server PL/SQL Module Format String...
     31. Virtual Programming VP-ASP Test Page Information Disclosure...
     32. Ipswitch WS_FTP Pro Buffer Overflow Vulnerability
     33. Microsoft SQL Server 2000 Multiple Vulnerabilities
     34. iPlanet Web Server Buffer Overflow Vulnerability
     35. Oracle TNSListener Remote Buffer Overflow Vulnerability
     36. Microsoft Windows 2000 Remote Access Service Buffer Overflow...
     37. Oracle Reports Server Remote Buffer Overflow Vulnerability
     38. Microsoft IIS HTR ISAPI Extension Heap Overflow Vulnerability
     39. Oracle Web Cache Remotely Exploitable Buffer Overflow...
     40. WoltLab Burning Board Predictable Account Activation String...
III. SECURITYFOCUS NEWS ARTICLES
     1. FBI Shake-up Makes IT A Principal Priority
     2. Klez Infection Persists - Anti-Virus Companies
     3. News Sites Tackle E-mail 'Subversion' Security Holes
IV.SECURITYFOCUS TOP 6 TOOLS
     1. squidanalog v0.1
     2. LCDproc v0.4.3
     3. The Logging Project v0.2
     4. Secura v1.0
     5. SQLSnake Removal Utility 1.0 Beta
     6. UIF - Userfriendly Iptables Frontend v1.0.1
V. SECURITYJOBS LIST SUMMARY
     1. Product Marketing Manager - Security Software (Thread)
     2. Security Sales Engineer - SecurityFocus (Thread)
     3. Public Relations Manager - CA - #684 (Thread)
     4. Practice Manager - Information Security Professional Services - CA
     5. Software developer looking for work. (Thread)
     6. Need Awesome Network Exploitation Analysts (Thread)
     7. ADMINISTRIVIA (Thread)
     8. Lookign for InfoSec Engineer position in DC, Northern Virginia and
     9. Opening - Experienced Wireless Security Architect (Dallas, TX)
     10. Looking in Denver (Thread)
     11. Job Lead -- TX-Dallas-Data Security Administrator (Thread)
VI. INCIDENTS LIST SUMMARY
     1. Compromised Win2000 machine. - Follow UP (Thread)
     2. AW: strange .ch scan by 195.141.86.145 (Thread)
     3. Compromised Win2000 machine. (Thread)
     4. odd scans? (Thread)
     5. New Stacheldraht? (Thread)
     6. strange account in Win2k (Thread)
     7. parsing output from tools (Thread)
     8. Security contacts for cnn,time.com,usatoday,and boston globe
     9. Worms and CScript/WScript (Thread)
     10. SQLSnake email account shutdown? (Thread)
     11. GET /proxy-test.php (Thread)
     12. strange .ch scan by 195.141.86.145 (Thread)
     13. Strange scans (Thread)
     14. continues SCAN Proxy attempt (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. Wireless MAC Addy question (Thread)
     2. wireless woes ... Stats on WEP usage. (Thread)
     3. OT: snprintf() null termination (Thread)
     4. wireless woes in the triangle and beyond! (Thread)
     5. Microsoft IIS - Possible authentication flaw? (Thread)
     6. DirectX 9 SDK, Microsoft have got balls.... (Thread)
     7. sql injection and php (Thread)
     8. Re[2]: Microsoft IIS - Possible authentication flaw? (Thread)
     9. New Kismet Packages available - SayText() and suid kismet_server
     10. Verizon Call Intercept (Thread)
     11. sgid games - purity test. (Thread)
     12. Your favourite capture/edit/retransmit tool? (Thread)
     13. WinNT and previously used passwords (Thread)
     14. OT? Are chroots immune to buffer overflows? (Thread)
     15. Xandros based linux autorun -c (Thread)
     16. Fragroute segmentation fault? (Thread)
     17. AMANDA security issues (Thread)
     18. VP-ASP shopping cart software. (Thread)
     19. Achims Guestbook, InertiaNews, Pollen, MyPhpChat, mcPass (Thread)
     20. MacOS X 10.1.4 MAC Address Spoofing (Thread)
     21. On-Line Games and Privacy Issues (Thread)
     22. Sendmail file locking - PoC (Thread)
     23. [DER ADV#8] - Local off by one in CVSD (Thread)
     24. addition: CVS off by one (Thread)
     25. XSS And Headers... (Thread)
     26. High APAR - Microsoft:  Microsoft Security Bulletin MS02-024:
     27. game console hacking thread (Thread)
     28. COWS continuation (Thread)
     29. Online Games Consoles and Security Implications (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. Help with XP Hotfixes and Patches (Thread)
     2. Need free app for viewing metadata in Word documents (Thread)
     3. restrict software installation (Thread)
     4. Permissions on files (Thread)
     5. Wingate Replacement (Thread)
     6. SecurityFocus Microsoft Newsletter #88 (Thread)
     7. Dial up access problem - not a (solution) (Thread)
     8. How to disable WebDAV (Thread)
     9. Problem - Using IPSec to secure Windows Messenger Traffic (Thread)
     10. MS-SQL Blank Password Enumeration (Thread)
     11. Dial up access problem solution (Thread)
     12. About ping request? (Thread)
     13. Why does XP establish HTTP connection when browsing network
     14. Dialup access controls (Thread)
     15. Why does XP establish HTTP connection: ADDITIONALLY, (Thread)
     16. Question Regarding Securing Critical Executables (Thread)
     17. Reinstallation of Hotfixes (Thread)
IX. SUN FOCUS LIST SUMMARY
     1. xhost (Thread)
     2. tcp_wrappers x SSH (Thread)
     3. ANNOUNCE - new SunCluster security BluePrint and JASS (s9 support)
     4. ssh help (Thread)
     5. BSM tool (Thread)
     6. UseLogin and X11Forwarding (Thread)
     7. C2 security standards (Thread)
X. LINUX FOCUS LIST SUMMARY
     1. securing nic's for snort (Thread)
     2. How to get rid of spoofed IP-Address responses (Thread)
     3. Linux Hardening (Thread)
     4. irssi backdoor question (Thread)
     5. What Is hosts2-ns (Thread)
XI. SPONSOR INFORMATION


I. FRONT AND CENTER
-------------------
1.  Securing Privacy Part Four: Internet Issues
By Scott Granneman

This is the fourth and final installment in a series devoted to protecting
users' privacy on the Internet. In this article, we will look more
generally at our usage of the Internet. The Internet offers all of us
unparalleled access to information, but it also brings with it unique
threats to our privacy. This article will examine some of the ways you can
protect yourself.

http://online.securityfocus.com/infocus/1585

2. PortSentry for Attack Detection - Part Two
by Ido Dubrawsky

This is the second in a two-part series on PortSentry. The first article
discussed how PortSentry works to identify attacks, as well as what types
of attacks it identifies. This article will focus on building, installing,
and operating PortSentry. The focus here will be on the various
configuration options available for PortSentry, as well as some of the
benefits and drawbacks of those options.

http://online.securityfocus.com/infocus/1586

3. Black Hat Briefings

Attend Black Hat Briefings & Training, July 29 - August 1, Las Vegas, the
world's premier technical security event! 8 tracks, 12 training sessions,
Richard Clarke keynote, 500 delegates from 30 nations, with a near cult
following of both CSOs and "underground" security experts. See for
yourself what the buzz is all about.

http://www.blackhat.com

4. Secure i-World
August 19-21, 2002, San Diego, CA
Optional Workshops August 17, 18,  21, & 22
Vendor Expo August 19 & 20

WebSec 2002, Online Privacy Conference, Secure i-World Expo…two innovative
conferences and one outstanding expo, all in one blockbuster event.

http://www.secureiworld.com/06/sw02nl18inf.html


II. BUGTRAQ SUMMARY
-------------------
1. CVS Daemon RCS Off By One Local Buffer Overflow Vulnerability
BugTraq ID: 4829
Remote: No
Date Published: May 25 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4829
Summary:

CVS is the concurrent versioning system.  CVS is a freely available, open
source software development package for the Unix, Linux, and Microsoft
Windows platforms.

A problem with the software could make it possible for an attacker to gain
elevated privileges.

Due to a boundry condition error, it may be possible for a local attacker
to execute arbitrary code.  The rcs.c file contains an off-by-one error
that could result in an attacker overwriting portions of stack memory, and
executing arbitrary code.

This problem could result in an attacker gaining access to the CVS
archives with the privileges of the CVS user.  This could allow an
attacker to alter source code within the CVS archive, and potentially
backdoor source code.

2. PHPBB2 Image Tag HTML Injection Vulnerability
BugTraq ID: 4858
Remote: Yes
Date Published: May 26 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4858
Summary:

phpBB2 is free, open-source web forums software that is written in PHP and
backended by MySQL.  It will run on most Unix and Linux variants, as well
as Microsoft Windows operating systems.

BBCode is a feature which allows users to include HTML-style formatting
elements in their forum messages.

It is possible to inject arbitrary HTML into phpBB2 forum messages via the
use of BBCode image tags.  A similar issue is described in Bugtraq ID 4379
"PHPBB Image Tag User-Embedded Scripting Vulnerability".  However, phpBB2
was found to not be vulnerable to this previous issue.

When the image tag is translated into HTML, the following code is used:

<img src="$user_provided" border="0" />

phpBB2 checks to ensure that the user-provided image source is prepended
with "http://", which restricts the user from injecting arbitrary HTML as
the image source.  However, it has been reported that this measure may be
circumvented by using a double-quotation (") character to close the image
source tag.  The attacker may then include arbitrary HTML after the
double-quotation.

The attacker may exploit this issue to inject script code into forum
messages.  When such messages are displayed by a web user, the attacker's
script code will execute in their browser in the context of the website.
If the web user is an authenticated user of the phpBB2 forum, then the
attacker may exploit this condition to steal cookie-based authentication
credentials from the user.

phpBB versions prior to the phpBB2 series may also be affected by this
vulnerability.

3. Microsoft IIS 5.0 Denial Of Service Vulnerability
BugTraq ID: 4846
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4846
Summary:

A remotely exploitable denial of service condition in Microsoft IIS 5.0
has reported by a reliable source.

The denial of service is caused by resource exhaustion.

Additional technical details will be added to this vulnerability record
when they become available.

4. Microsoft Active Data Objects Buffer Overflow Vulnerability
BugTraq ID: 4849
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4849
Summary:

A reliable source has reported an exploitable buffer overflow condition in
Microsoft Active Data Objects (ADO).

Microsoft ADO are an Active-X object that handles data from the server to
the web client.  Microsoft ADO support any ODBC database.  ADO ships as a
part of MDAC (Microsoft Data Access Components).

This vulnerability may pose a risk for users of Microsoft Internet
Explorer, but is not present in the default configuration of the web
browser.  This issue is only present if the browser is configured to allow
access to datasources across domains.

Under some circumstances, there also may be a risk for Microsoft IIS
servers, in the case that the server is being used to host content which
may come from an untrusted source.  The attacker must be able to upload an
ASP page and execute it to exploit this issue in Microsoft IIS servers.
If the attacker has the ability to do this, then many other avenues of
attack exist.

5. Microsoft Commerce Server 2000 Remote Buffer Overflow Vulnerabilities
BugTraq ID: 4853
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4853
Summary:

A reliable source has reported that a number of remotely exploitable
buffer overflows exist in Microsoft Commerce Server 2000.  These
conditions may be exploited to execute arbitrary attacker-supplied
instructions with the privileges of the Microsoft Commerce Server 2000
process.

Additional technical details will be added to this vulnerability record
when they become available.

6. Microsoft Windows HTML Help ActiveX Control Multiple Vulnerabilities
BugTraq ID: 4857
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4857
Summary:

HTML Help ActiveX control (Hhctrl.ocx) ships as part of Microsoft HTML
Help, and is designed to work with Internet Explorer to provide
functionality for help systems.

The HTML Help ActiveX control can be used to exploit stack and heap based
overflow attacks. It may be possible for remote users to execute arbitrary
code on a user's system.

This problem may allow an attacker to overwrite stack and heap variables
including the return address, possibly to execute arbitrary code. The
attacker may also crash the service by sending excessive amounts of data
that has not specifically been designed to cause code execution.

Details of this vulnerability are currently unavailable, this record will
be updated as more information becomes available.

It should be noted that Windows ships with HTML Help.

7. Tomahawk Technologies SteelArrow Web Application Server Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 4860
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4860
Summary:

SteelArrow Web Application Server is a freely available application server
by Tomahawk Technologies Inc.

Due to multiple buffer overflow vulnerabilities in SteelArrow Web
Application Server, it may be possible for remote users to execute
arbitrary code on a target host.

Exploitation of these vulnerabilities may allow for an attacker to
overwrite stack variables, including the return address, possibly to
execute arbitrary code. The attacker may also crash the service by sending
excessive amounts of data that has not specifically been constructed to
cause code execution.

Additional technical details will be added to this vulnerability record
when they become available.

8. Virtual Programming VP-ASP SQL Injection Vulnerability
BugTraq ID: 4861
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4861
Summary:

Virtual Programming VP-ASP is a shopping cart application for e-commerce
enabled sites.

A SQL injection vulnerability has been reported in some versions of
Virtual Programming VP-ASP.

The authentication data supplied by the remote user is used directly to
construct SQL statements. As input sanitization is not properly performed,
an attacker may include unescaped special characters such as "'", and "="
as part of the username and password. Consequently, the structure and
logic of the query may be hijacked.

It has been reported that exploitation of this vulnerability may allow for
authentication to be bypassed.

9. DataWizard FtpXQ Buffer Overflow Vulnerability
BugTraq ID: 4862
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4862
Summary:

FtpXQ is a ftp daemon designed to provide ftp services for Microsoft
Operating Systems. The software package has been written for Microsoft
Windows 95/98/NT/2000. It is maintained and distributed by Datawizard
Technologies.

FtpXQ is contains a buffer overflow which can result in a denial of
services if exploited.  Creating a directory with a name longer than 254
characters will cause the server to crash.

It is also believed that attackers can cause arbirtary code to be executed
on target servers, however this is not confirmed.

10. TransSoft FTP-Broker Denial of Service Vulnerability
BugTraq ID: 4864
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4864
Summary:

Transoft Broker is an FTP server for the Windows platform.

It is possible for users to cause the FTP server to stop responding.
Reportedly, this is possible when submitting a CWD command along with
numerous '....' character sequences.

A remote attacker who exploits this issue may deny service to legitimate
users of the system.

A restart of the service may be required in order to regain normal
functionality.

11. FileZilla FTP Server Directory Traversal Vulnerability
BugTraq ID: 4865
Remote: Yes
Date Published: May 28 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4865
Summary:

FileZilla FTP Server is vulnerable to directory traversal attacks.

For security reasons, the server is designed restrict users to a specific
directory tree.  It has been reported that this mechanism is flawed.  By
using directory traversal sequences (ie '/../', '..'), an attacker can
obtain files outside of the permitted directory structure.

Disclosure of sensitive files and the filesystem layout may supply an
attacker with important information.  This information could lead to
further compromise of the vulnerable system.

12. ECS K7S5A Boot Menu Access Vulnerability
BugTraq ID: 4866
Remote: No
Date Published: May 28 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4866
Summary:

K7S5A is a line of mainboards manufactured and distributed by ECS.

A problem with the firmware could make it possible for a user with
physical access to the system to circumvent bios security measures.

The firmware distributed with K7S5A boards may allow users with physical
access to systems to boot of alternative media.  Though the firmware
allows the setting of administrative passwords and specification of
default boot media, it does not protect the boot menu.  With access to the
boot menu, arbitrary media such as a floppy or CD may be booted from.

This makes it possible for users with physical access to the system to
boot off an arbitrary medium.  This could lead to compromise of the
operating system, and integrity of data.

13. phpTest Test Result Disclosure Vulnerability
BugTraq ID: 4868
Remote: Yes
Date Published: May 28 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4868
Summary:

phpTest is a free web based testing application maintained by Brandon
Tallent.

A minor security vulnerability has been discovered in versions of phpTest
prior to 0.5.6.  The issue is related to handling of client input when
viewing test results.  According to the author of phpTest, it is possible
for users to exploit this vulnerability to view the test results of other
users.  Though unconfirmed, this may be accomplished by modifying the user
(or another) HTML form parameter.

Test results may be considered sensitive information in some environments.
Data obtained by a malicious party may also be used in social engineering
attacks.

This vulnerability was eliminated in phpTest 0.5.6.

14. Firestorm IDS IP Options Decoding Denial Of Service Vulnerability
BugTraq ID: 4871
Remote: Yes
Date Published: May 28 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4871
Summary:

Firestorm IDS is a freely available, open source intrusion detection
package.  It is maintained by public domain.

A problem with Firestorm IDS could make it possible to crash the software.

Firestorm IDS may become unstable when handling certain IP options.  It
has been reported that Firestorm IDS can be caused to crash when it has
received traffic with specific IP options set.  This could result in a
denial of service.

The problem is likely due to a memory management bug, though this is
unconfirmed.  If this is the case, it may additionally be possible to
execute arbitrary code on a vulnerable IDS implementation.  The code would
be executed with the privileges of the Firestorm IDS user.

15. Image Display System Directory Existence Disclosure Vulnerability
BugTraq ID: 4870
Remote: Yes
Date Published: May 28 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4870
Summary:

IDS (Image Display System) is an web based photo album application written
in Perl. IDS is freely available and is maintained by Ashley M. Kirchner.

Users can confirm the location of various directories residing on the host
through a trial and error method. This is accomplished when a request for
a directory and album name is sent to the host containing numerous '../'
character sequences. The error page returned will assist the user in
determining whether the directory exists or not.

The error page that will display if the directory is valid and the album
name is invalid is "Sorry, the album (album_name) doesn't exist". If the
directory specified is invalid the error message is as follows: "Sorry,
invalid directory name".

It is not currently known if it is possible to access the contents of the
guessed directory. The attacker may, however, be able to use this
information to perform further, intelligent attacks against the vulnerable
system.

16. Charities.Cron Insecure Temporary File Creation Vulnerability
BugTraq ID: 4869
Remote: No
Date Published: May 28 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4869
Summary:

Charities.cron is a cron script written in gawk, which clicks the links on
various charity websites.  Charities.cron is intended to be run as a daily
cron job.  It will run on most Unix and Linux variants.

Charities.cron uses the lynx web browser to poll various charity websites.
It downloads the charity webpages and stores them in temporary files.
However, Charities.cron creates these temporary files with predictable
filenames.  A local attacker may exploit this to cause arbitrary files
writeable by the cron scheduling daemon process to be written to via
symlink attacks.  This may result in a denial of service condition.

This vulnerability has existed in one form or another through various
releases of Charities.cron.  Since the most recent version (1.7.0) still
uses prediactable temporary filenames, it may be still be possible to
exploit this condition.  Charities.cron does check to see if the temporary
files used already exist before dumping the charity webpages, however,
this fix only creates a race condition which may still be potentially
exploitable.

17. Macromedia JRun Host Header Field Buffer Overflow Vulnerability
BugTraq ID: 4873
Remote: Yes
Date Published: May 29 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4873
Summary:

Macromedia JRun is a J2EE (Java 2 Platform Enterprise Edition) application
server for use with IIS (Internet Information Server) 4/5 on the Microsoft
Windows operating systems.

A vulnerability has been reported in Macromedia JRun version 3.1.  It is
reportedly possible to cause a buffer overflow condition in JRun if an
excessively long HTTP host header field is transmitted by the client.

JRun server will install itself as a ISAPI (Internet Server Application
Programming Interface) filter/application in the '/scripts' virtual
directory of the webserver.  When a '.jsp' page is requested, the JRun
filter is invoked.  The overflow will occur if a client makes a request
for a .jsp file with an overly long HTTP host header field.

This condition may be exploited by attackers to execute arbitrary code on
the vulnerable system in the security context of IIS.

18. Trend Micro Interscan Viruswall SMTP Header Removal Vulnerability
BugTraq ID: 4830
Remote: Yes
Date Published: May 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4830
Summary:

Interscan Viruswall is a mail gateway solution distributed and maintained
by Trend Micro.  This problem affects versions running on the Microsoft
Windows platform.

A flaw in Viruswall may make it possible to hide the origins of email.
The problem is in the editing of headers by the product.

When a mail is sent to a site using Interscan Viruswall, it is passed
first through the Viruswall software.  After processing by the Viruswall
package, if it clears the check it is passed on to the mail transport
agent (MTA) on the system, typically running on a different port.

Viruswall does not preserve headers from email when email is passed to the
MTA running on the system.  This problem makes it possible for outside
users to obscure the origins of mail sent to the server.  An attacker
could take advantage of this vulnerability to spam the host without the
risk of being traced.  This vulnerability could also be exploited to send
misinformation through the host, appearing to come from a local user of
the mail system.

It should be noted that the origins of email is logged by Interscan
Viruswall only when a virus is discovered.

19. IRSSI Trojaned Configure File Arbitrary Access Vulnerability
BugTraq ID: 4831
Remote: Yes
Date Published: May 25 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4831
Summary:

irssi is a freely available, open source irc client.  irssi is available
for the Linux and Unix operating systems.

A problem with the client could make it possible for a remote user to gain
control of a users account.

The server hosting irssi was compromised at some point.  After being
compromised, the source code to irssi was altered to include a backdoor.
This backdoor allowed a user from the IP address 204.120.36.206 to
remotely execute commands on the host that irssi was installed on.  The
source code is known to have been trojaned between the beginning of April,
and end of May.  Downloads of the source during this time likely contain
the trojan code.

This problem could lead to a remote attacker gaining access to system with
the privileges of the irssi process.  This problem could additionally lead
to further compromise.

20. Opera Arbitrary File Disclosure Vulnerability
BugTraq ID: 4834
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4834
Summary:

Opera is a web browser created by Opera Software.  It is available for a
range of operating systems including Windows and Linux.  A vulnerability
has been reported in Opera 6.01/6.02.

The vulnerability is related to handling of the 'file' HTML input-type.
The 'file' input-type supports upload of files as HTML form input, from a
client to a webserver.  By design, Opera does not prevent the server from
setting the filename to be uploaded.  To prevent malicious servers from
forcing the upload of arbitrary files, a warning dialog is presented to
the user when a form with a file upload is submitted.  If a form with a
'file' input type is submitted with no file value set, the dialog is not
displayed (as there is no file being uploaded).

It is possible for a server to set the file value while fooling Opera into
thinking no file has been specified.  An attacker may accomplish this if
the filename is appended with the string "&#10;".  This HTML-encoded
newline character will cause the browser to believe that no value has been
set.  Consequently, the form will be submitted and the specified file will
be uploaded to the server.  This may occur without knowledge or consent of
the victim user.

Exploitation of this vulnerability allows for malicious webmasters to
obtain arbitrary files from client systems.

21. BlueFace Falcon Web Server File Disclosure Vulnerability
BugTraq ID: 4833
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4833
Summary:

Falcon Web Server is a small web server that runs on several Microsoft
Windows platforms.  It is mainly intended for small to medium sized
businesses.

Password protected files residing on the Falcon Web Server may be
disclosed to unauthorized users.  The user would have to know the name of
the file in order to access it.

The file could be accessed simply by requesting a URL in the following
format from the web server: http://host/protectedfolder./

22. TightVNC Plain Text Password Storage Vulnerability
BugTraq ID: 4835
Remote: No
Date Published: May 25 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4835
Summary:

TightVNC is a VNC (Virtual Network Computing) distribution maintained by
Constantin Kaplinsky.

An issue has been reported in versions of TightVNC for Windows, which may
potentially disclose authentication credentials to attackers.

TightVNC stores authentication information in plaintext on the local
system in the password text control of the WinVNC Properties dialog.

As a result, it may be possible for a local user to steal authentication
credentials for the service. The attacker may then access the service as
that user.

TightVNC versions prior to 1.2.4 may be susceptible to this issue.

23. Yahoo! Messenger Call Center Buffer Overflow Vulnerability
BugTraq ID: 4837
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4837
Summary:

Yahoo! Messenger configures a handler for the 'ymsgr:' URI when it is
installed.  The handler invokes YPAGER.EXE with the supplied parameters.
YPAGER.EXE accepts the 'call' parameter and it's associated argument, used
for starting the 'Call Center' feature.

There is a stack overrun condition in the 'Call Center' component that may
be exploited through a specially constructed URI.  It has been reported
that the stack frame of the affected function will be corrupted if the
argument to the 'call' parameter is 268 bytes or greater in length.

This vulnerability may be exploited by crafting a 'ymsgr:' link.  The link
must consist of the 'call' parameter and the exploit-string as it's
argument.  For example:

ymsgr:call?+<aaaaaaaaaaaaaaaa...>

If such a link is clicked on by a victim, the 'call' parameter will cause
YPAGER.EXE to invoke the 'Call Center'.  The oversized argument will
trigger the overrun condition when the 'Call Center' component attempts to
process it.

Attackers may exploit this vulnerability to execute arbitrary code on
client systems.

24. Yahoo! Instant Messenger Script Injection Vulnerability
BugTraq ID: 4838
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4838
Summary:

Yahoo! Messenger is the main instant messaging client used on the Yahoo!
network.

URL's beginning with ymsgr:addview? allow users to add content to Yahoo!
Messenger content tabs for viewing through Yahoo! Messenger without the
use of a web browser.

It is possible to use ymsgr:addview? to point the Yahoo! Messenger to a
web page containing script that will in turn be rendered by the instant
messenger.

For example:
ymsgr:addview?http://rd.yahoo.com/messenger/?htt://webserver/scriptpage.htm

If this page contains Javascript or Visual Basic Script, the script will
be executed by the Yahoo! Messenger.

Scripts executed in this manner may mimic or replace the behaviour of
certain Yahoo! Messenger content tabs.  It is also possible that the
scripts could modify properties of the instant messenger allowing further
exploitation, however, this behaviour has not been confirmed.

25. AMANDA amindexd Remote Buffer Overflow Vulnerability
BugTraq ID: 4836
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4836
Summary:

AMANDA (Advanced Maryland Automatic Network Disk Archiver) is a system for
backing up multiple hosts onto a single tape drive.  It will run on most
Unix and Linux variants.

The AMANDA amindexd daemon is prone to a remotely exploitable buffer
overflow condition.  This condition is due to insufficient bounds checking
of command strings.  Overly long command strings (260+ bytes) may cause
stack variables such as the return address to be overwritten.

This vulnerability may be exploited by remote attackers to run arbitrary
instructions as root, leading to a complete compromise of the host running
the vulnerable software.

The amindexd daemon runs on port 10082.

This issue was reported for AMANDA 2.3.0.4, which is an older release.
Other versions may also be affected.

26. TightVNC Listening Viewer Multiple Non-Shared Connections DoS Vulnerability
BugTraq ID: 4839
Remote: Yes
Date Published: May 25 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4839
Summary:

TightVNC is a VNC (Virtual Network Computing) distribution maintained by
Constantin Kaplinsky.

A vulnerability has been reported in versions of TightVNC for Windows.
It is reportedly possible for maliciouis clients to crash the listening
viewer.

The viewer will fail if a client establishes a number of non-shared
connections. This issue exists in versions of TightVNC prior to 1.2.4.

Successful exploitation of this issue will shut down the listening viewer.
A restart of the service may be required in order to regain normal
functionality.

27. AMANDA amcheck Local Buffer Overflow Vulnerability
BugTraq ID: 4840
Remote: No
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4840
Summary:

AMANDA (Advanced Maryland Automatic Network Disk Archiver) is a system for
backing up multiple hosts onto a single tape drive.  It will run on most
Unix and Linux variants.

The AMANDA amcheck component is prone to a locally exploitable buffer
overflow condition.  The amcheck utility is installed setuid root by
default.  The overflow condition is due to insufficient bounds checking
when processing command line input.  It is possible for remote attackers
to overwrite the stack frame of the affected function when amcheck is
invoked with an oversized command parameter.

It should be noted that amcheck may only be executed by the user/group
'operator'.  Only attackers with sufficient privileges to execute amcheck
may exploit this vulnerability.

This issue was reported for AMANDA 2.3.0.4, which is an older release.
Other versions may also be affected.

28. 3Com OfficeConnect ADSL Router Port Address Translation Access Control Bypassing Vulnerability
BugTraq ID: 4841
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4841
Summary:

OfficeConnect ADSL routers are a hardware and switch solution distributed
by 3Com.

A problem with the router could make it possible for remote users to gain
unauthorized access to systems.  The problem is in the handling of port
address translation.

Port Address Translation (PAT) is functionality built into an
OfficeConnect router to allow redirection of some traffic.  PAT works by
taking connections to specific ports on an OfficeConnect router, and
redirecting them to a system behind the router, specified in the firmware
configuration.

Under some circumstances, it may be possible for a remote user to gain
unauthorized access to information systems behind a 3Com OfficeConnect
router.  The OfficeConnect does not properly handle PAT, and may allow a
remote attacker to connect to arbitrary ports on a system behind a PAT
rule.

An attacker sending a connection to PAT port will be routed to the system
behind the PAT rule.  If an additional connection attempt on a different
port is attempted immediately after the PAT connection, the router will
relay the connection to the appropriate port on the system with which the
PAT connection exists.

This could give an attacker unauthorized access to a system, and could
additionally result in the compromise of insecure systems.

29. NetScreen ScreenOS Remote Reboot Vulnerability
BugTraq ID: 4842
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4842
Summary:

NetScreen is a line of Internet security appliances integrating firewall,
VPN and traffic management features. ScreenOS is the software used to
manage and configure the firewall. NetScreen supports Microsoft Windows
95, 98, ME, NT and 2000 clients.

It is possible for remote attackers to cause the device to reboot by
sending an overly long username to the web interface.  An attacker may
create a prolonged denial of service condition by repeatedly causing the
device to reboot.

This condition may be the result of an unchecked buffer, which may
potentially allow the attacker to execute arbitrary code.  This
possibility has not been confirmed.

30. Oracle Application Server PL/SQL Module Format String Vulnerability
BugTraq ID: 4844
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4844
Summary:

Application Server is a commercially available web application development
package distributed by Oracle.

A problem with the Oracle Application Server could make it possible for
remote users to gain access to a system running the software.

A format string vulnerability has been discovered in the Application
Server.  This problem may allow an attacker to write data to arbitrary
addresses in memory, and potentially execute arbitrary code.  This would
likely result in a user gaining access to a vulnerable server with the
privileges of the oracle user.

Reports indicate the problem is in the administration pages of the PL/SQL
module.

31. Virtual Programming VP-ASP Test Page Information Disclosure Vulnerability
BugTraq ID: 4843
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4843
Summary:

Virtual Programming VP-ASP is a shopping cart application for e-commerce
enabled sites.

The '/demo400/shopdbtest.asp' test page is included in a default
installation of VP-ASP.  The absolute path of the page will be disclosed
when submitting a specially crafted request for 'shopdbtest.asp'.

Successful exploitation of this issue will provide remote users knowledge
of system path information, which may assist them in further attacks
against the host.

32. Ipswitch WS_FTP Pro Buffer Overflow Vulnerability
BugTraq ID: 4850
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4850
Summary:

Ipswitch WS_FTP Pro is a FTP client for Microsoft Windows systems.  A
buffer overflow condition has been reported in WS_FTP Pro.  Precise
details are not currently available, however it is believed that it may be
exploitable by a malicious server.

Successful exploitation of this vulnerability may result in remote
attackers gaining access to vulnerable client hosts.

This record will be updated as more information becomes available.

33. Microsoft SQL Server 2000 Multiple Vulnerabilities
BugTraq ID: 4847
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4847
Summary:

SQL Server 2000 is a commercially available enterprise level database
product from Microsoft.

Microsoft SQL Server 2000 has been reported to contain multiple
vulnerabilities.  These include heap and stack buffer overflows and
service/network denial of services attacks.

Details of this vulnerability are currently scarce, this record will be
updated as more information becomes available.

34. iPlanet Web Server Buffer Overflow Vulnerability
BugTraq ID: 4851
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4851
Summary:

iPlanet Webserver is an http server product offered by Sun Microsystems.

Due to a buffer overflow vulnerability in iPlanet Web Server, it may be
possible for remote users to execute arbitrary code with SYSTEM
privileges.

This problem may allow an attacker to overwrite stack variables including
the return address, possibly to execute arbitrary code. The attacker may
also crash the service by sending excessive amounts of data that has not
specifically been designed to cause code execution.

35. Oracle TNSListener Remote Buffer Overflow Vulnerability
BugTraq ID: 4845
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4845
Summary:

TNSListener is a component of the Oracle database, distributed by Oracle
Corporation.

A problem with the database may allow a remote user to gain access to a
vulnerable system.

A buffer overflow has been reported in the Oracle TNSListener.  This
buffer overflow may allow a user to remotely execute code on a vulnerable
system.  In doing so, a remote user may be able to gain access to the
local system, and potentially the privileges of the TNSListener process.

The TNSListener process typically runs as the user oracle, and group dba.
By gaining access to the system with these privileges, a user may be able
to access all data contained within the database files.

36. Microsoft Windows 2000 Remote Access Service Buffer Overflow Vulnerability
BugTraq ID: 4852
Remote: No
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4852
Summary:

Remote Access Service (RAS) is a service included in Microsoft Windows
2000 to allow users to connect to a corporate intranet or the Internet
from a remote computer.

It has been reported that the RAS service included in Windows 2000 is
vulnerable to a buffer overflow condition.  Details of this vulnerability
are scarce, however, successful exploitation could result in a denial of
service or possibly execution of arbitrary code.

This record will be updated as more information becomes available.

37. Oracle Reports Server Remote Buffer Overflow Vulnerability
BugTraq ID: 4848
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4848
Summary:

Reports Server is a commercially available reporting package distributed
by Oracle.

A problem with Reports Server may allow a remote user access to a
vulnerable host.

A buffer overflow has been reported in the Oracle Reports Server.  This
buffer overflow may allow a user to remotely execute code on a vulnerable
system.  In doing so, a remote user may be able to gain access to the
local system, and potentially the privileges of the Reports Server.

The Reports Server typically runs with the privileges of user oracle, and
group dba.  By gaining access to the system with these privileges, a user
may be able to access all data contained within the database files.

38. Microsoft IIS HTR ISAPI Extension Heap Overflow Vulnerability
BugTraq ID: 4855
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4855
Summary:

It has been reported that the HTR ISAPI extension for Microsoft IIS is
vulnerable to a heap overflow condition.

HTR is a scripting technology for IIS that has been largely superseded by
ASP (Active Server Pages).  A condition exists in the HTR ISAPI extension
that may allow a remote attacker to overwrite locations in memory with
attacker-supplied data.

This condition affects IIS 5.0 and may be effectively mitigated by
disabling the extension.

Exploitation of this vulnerability may result in a denial of service or
allow for a remote attacker to execute arbitrary instructions on the
victim host.

39. Oracle Web Cache Remotely Exploitable Buffer Overflow Vulnerabilities
BugTraq ID: 4856
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4856
Summary:

Web Cache is a commercially available web caching software distributed by
Oracle.

Several problems with Oracle Web Cache may make it possible for a remote
user to gain access to a vulnerable system.

It has been reported that several remotely exploitable buffer overflows
exist in the Oracle Web Cache.  These buffer overflows may allow a user to
remotely execute code on a vulnerable system.  In doing so, a remote user
may be able to gain access to the local system, and potentially the
privileges of the Web Cache process.

The Web Cache process typically runs as the user oracle, and group dba.
By gaining access to the system with these privileges, a user may be able
to access all data contained within the database files.

40. WoltLab Burning Board Predictable Account Activation String Vulnerability
BugTraq ID: 4859
Remote: Yes
Date Published: May 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4859
Summary:

WoltLab Burning Board is a free web-based bulletin board package based on
PHP and MySQL.

It is possible to hijack an account that has not yet been activated.
When a user creates a new account on a Burning Board forum, they will be
presented with a link which they must click in order to activate their
account:


http://forum.dom/forum/action.php?action=activation&userid=345&code=1563109322

The code variable is generated by the following operation:
$datum = date("s");
mt_srand($datum);
$z = mt_rand();

Since the variable is generated by performing an mt_srand operation on the
second that the request is submitted, there are only 60 possible values
for this variable.  An attacker could easily perform a brute force attack
on this variable and gain access to the user's account.


III. SECURITYFOCUS NEWS AND COMMENTARY
------------------------------------------
1. FBI Shake-up Makes IT A Principal Priority
By Wilson P. Dizard III, Newsbytes

As part of a massive shake-up of the FBI, Director Robert Mueller said
Wednesday that a technology upgrade is one of the agency's top 10
priorities.  Acknowledging that the FBI had handled terrorism clues
inefficiently before Sept. 11, Mueller pegged the agency's technology
upgrade as critical to its new counterterror focus.

http://online.securityfocus.com/news/456

2. Klez Infection Persists - Anti-Virus Companies
By Michael Bartlett, Newsbytes

The "Klez" worm and its variants, including Klez.E and Klez.H, continue to
spread at a dizzying rate, according to anti-virus experts.  The Klez
rampage has gotten so serious, recent media reports dubbed it the No. 1
virus of all time.

http://online.securityfocus.com/news/453

3. News Sites Tackle E-mail 'Subversion' Security Holes
By Brian McWilliams, Newsbytes

Security flaws in e-mail features at several popular news sites could have
been exploited by "spammers" or used to spread false information, a
security specialist cautioned today.  In response to the warning, Time
magazine has temporarily disabled the "e-mail-a-friend" function at its
Web site. Similar security flaws at sites operated by CNN and the Boston
Globe were corrected earlier this week by those news organizations.

http://online.securityfocus.com/news/454


IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. squidanalog v0.1
by Hendry D. Lee
Relevant URL:
http://www.dutnux.com/software/squidanalog.html
Platforms: Linux, POSIX
Summary:

squidanalog is a collection of programs and scripts that will gather data
from squid access logs and save it into a round robin database using
rrdtool. Nice customized graphics can be plotted from the gathered data.

2. LCDproc v0.4.3
by William W. Ferrell
Relevant URL:
http://lcdproc.omnipotent.net
Platforms: FreeBSD, Linux, OpenBSD, Solaris
Summary:

LCDproc is a utility to drive one or more LCD (and LCD-like) devices
attached to a host. It is comprised of a server, which uses a modular
device driver system to control attached displays, and one or more clients
to gather data as appropriate and send screen data to the server. The
included client displays a multitude of system statistics (CPU/memory/disk
usage, uptime, date and time, temperature, etc.). Multiple clients can
connect to the server simultaneously, and clients can set priorities on
the screens they provide to influence in what order items are displayed.
This facility can also be used to "pop" critical screens (such as an entry
from syslog from a log-watching client). All functionality is implemented
in userland. Support for many display devices and several platforms
(Linux, *BSD, and Solaris at least) is included.

3. The Logging Project v0.2
by Jason Royes
Relevant URL:
http://condor.gmu.edu/~jason/logging/
Platforms: POSIX
Summary:

The Logging Project (formerly salt) is a suite of tools which provide
centralized, secure, fault-tolerant logging. It is flexible, robust, and
easy to integrate, making it an attractive alternative to replacing
syslog.

4. Secura v1.0
by Goldie R [email protected]
Relevant URL:
http://www.checksum.org/
Platforms: Os Independent
Summary:

This is a blowfish encryption suite that uses CBC mode of encryption for
encryption and decryption of files. It is written in java and henceforth
can be used on all the platforms that supports java. The source code is
given under the GPL license. Make use of it and protect your assets.
Please find the answers in the readme.txt for your questions of usage.

5. SQLSnake Removal Utility 1.0 Beta
by [email protected]
Relevant URL:
http://www.nstalker.com/util.php
Platforms: Windows 2000, Windows 95/98, Windows XP
Summary:

SQLSnake Removal Utility detects and removes SQLSnake locally.

6. UIF - Userfriendly Iptables Frontend v1.0.1
by Jörg Platte [email protected]
Relevant URL:
http://lug.mfh-iserlohn.de/uif
Platforms: Linux, POSIX
Summary:

The Userfriendly Iptables Frontend is used to generate optimized iptables
packet filter rules, using a simple description file specified by the
user. Generated rules are provided in iptables- save style. UIF can be
used to read or write rulesets to or from LDAP servers in your network,
which provides a global storing mechanism. Its aim is to be an easy to
configure, human readable packet filter.


V. SECURITY JOBS SUMMARY
------------------------
1. Product Marketing Manager - Security Software (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

2. Security Sales Engineer - SecurityFocus (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

3. Public Relations Manager - CA - #684 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

4. Practice Manager - Information Security Professional Services - CA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/5544986F9407D611A5900008C70964061A612E@EXCHANGE

5. Software developer looking for work. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

6. Need Awesome Network Exploitation Analysts (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

7. ADMINISTRIVIA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

8. Lookign for InfoSec Engineer position in DC, Northern Virginia and MD (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

9. Opening - Experienced Wireless Security Architect (Dallas, TX) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

10. Looking in Denver (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

11. Job Lead -- TX-Dallas-Data Security Administrator (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]


VI. INCIDENTS LIST SUMMARY
-------------------------
1. Compromised Win2000 machine. - Follow UP (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

2. AW: strange .ch scan by 195.141.86.145 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

3. Compromised Win2000 machine. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

4. odd scans? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/4.3.2.7.2.20020529144459.030bee20@localhost

5. New Stacheldraht? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/5BA6439FCDF318459BC50C3BBB6A0BE302DDA2A5@GCSCEXC2

6. strange account in Win2k (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

7. parsing output from tools (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

8. Security contacts for cnn,time.com,usatoday,and boston globe needed (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

9. Worms and CScript/WScript (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/120097989CFFD1118B8C00805FFEE2460AE0DB3C@GBWTM001

10. SQLSnake email account shutdown? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

11. GET /proxy-test.php (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

12. strange .ch scan by 195.141.86.145 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

13. Strange scans (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

14. continues SCAN Proxy attempt (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/1022459537.1177.108.camel@bloodnock


VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. Wireless MAC Addy question (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

2. wireless woes ... Stats on WEP usage. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

3. OT: snprintf() null termination (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/75C025AE395F374B81F6416B1D4BDEFB7003FC@MTV-CORPMAIL

4. wireless woes in the triangle and beyond! (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

5. Microsoft IIS - Possible authentication flaw? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

6. DirectX 9 SDK, Microsoft have got balls.... (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/002d01c20755$eb5a6660$24029dd9@kain

7. sql injection and php (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

8. Re[2]: Microsoft IIS - Possible authentication flaw? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

9. New Kismet Packages available - SayText() and suid kismet_server issues (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

10. Verizon Call Intercept (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

11. sgid games - purity test. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

12. Your favourite capture/edit/retransmit tool? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

13. WinNT and previously used passwords (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

14. OT? Are chroots immune to buffer overflows? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

15. Xandros based linux autorun -c (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

16. Fragroute segmentation fault? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

17. AMANDA security issues (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

18. VP-ASP shopping cart software. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

19. Achims Guestbook, InertiaNews, Pollen, MyPhpChat, mcPass (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

20. MacOS X 10.1.4 MAC Address Spoofing (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

21. On-Line Games and Privacy Issues (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

22. Sendmail file locking - PoC (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

23. [DER ADV#8] - Local off by one in CVSD (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

24. addition: CVS off by one (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

25. XSS And Headers... (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

26. High APAR - Microsoft:  Microsoft Security Bulletin MS02-024: Authentication Flaw in Windows Debugger can Lead to Elevated Privileges (Q320206) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/OF862753BF.466457D7-ONC2256BC4.002B94F4-C2256BC4.002BC5BD@telaviv.ibm.com

27. game console hacking thread (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

28. COWS continuation (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

29. Online Games Consoles and Security Implications (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]


VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Help with XP Hotfixes and Patches (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/002d01c2077f$b3a03fe0$fdfea8c0@dellydoo

2. Need free app for viewing metadata in Word documents (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

3. restrict software installation (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

4. Permissions on files (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/000b01c206da$431bd590$3200a8c0@laptop

5. Wingate Replacement (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/9D884881F5E1F24FB845967851720FC3045FF0B4@red-msg-12.redmond.corp.microsoft.com

6. SecurityFocus Microsoft Newsletter #88 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

7. Dial up access problem - not a (solution) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/001301c2065d$9bdca8d0$0101a8c0@brucenew

8. How to disable WebDAV (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

9. Problem - Using IPSec to secure Windows Messenger Traffic (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

10. MS-SQL Blank Password Enumeration (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/1961728C54D822408201A22F84D170032FF5D2@USAPGHEVS01.fmkt.freemarkets.com

11. Dial up access problem solution (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

12. About ping request? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

13. Why does XP establish HTTP connection when browsing network shares? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/2335F28384FC3241BCB30ADECBD2D490592706@cheeseball.external.osr.com

14. Dialup access controls (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

15. Why does XP establish HTTP connection: ADDITIONALLY, (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/p04330100b917fcad6b80@[144.96.241.96]

16. Question Regarding Securing Critical Executables (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

17. Reinstallation of Hotfixes (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]


IX. SUN FOCUS LIST SUMMARY
----------------------------
1. xhost (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]

2. tcp_wrappers x SSH (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]

3. ANNOUNCE - new SunCluster security BluePrint and JASS (s9 support)  released (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]

4. ssh help (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/Pine.LNX.4.21.0205271233260.22543-100000@simpleinfo.simpleinfo.co.uk

5. BSM tool (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]

6. UseLogin and X11Forwarding (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/B6F40DC5FF58A44F8FCB30384BE3D6E4750560@emacil-exch01.emacdigital.com

7. C2 security standards (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/867E01F52CF2D311B0D90008C75D6561138CF825@CRMAXSVR02


X. LINUX FOCUS LIST SUMMARY
---------------------------
1. securing nic's for snort (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

2. How to get rid of spoofed IP-Address responses (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

3. Linux Hardening (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

4. irssi backdoor question (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

5. What Is hosts2-ns (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]


XI. SPONSOR INFORMATION
-----------------------
This issue sponsored by: Aladdin's eToken.

Enhance Windows network security with flexible, affordable USB-based
strong authentication.

-Out-of-the-box support for Microsoft 2000 SmartCard logon and for NT (98,
ME) network logon.

-Store network passwords on a small, secure USB device, or replace them
with random passwords that users never see.

-Keep users' private credentials, certificates, keys, and access profiles
in a trusted environment.

eToken from Aladdin.  Strong authentication made simple.

http://www.ealaddin.com/etoken/enterprise/datasheets/DS_Win2000_SC_Logon.asp
?cf=tl
[email protected]
1-800-562-2543

-------------------------------------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.