SecurityFocus Newsletter #147
John Boletta <[email protected]>
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #147 ----------------------------- This issue sponsored by: Aladdin's eToken. Enhance Windows network security with flexible, affordable USB-based strong authentication. -Out-of-the-box support for Microsoft 2000 SmartCard logon and for NT (98, ME) network logon. -Store network passwords on a small, secure USB device, or replace them with random passwords that users never see. -Keep users' private credentials, certificates, keys, and access profiles in a trusted environment. eToken from Aladdin. Strong authentication made simple. http://www.ealaddin.com/etoken/enterprise/datasheets/DS_Win2000_SC_Logon.asp ?cf=tl [email protected] 1-800-562-2543 ------------------------------------------------------------------------------- I. FRONT AND CENTER 1. Securing Privacy Part Four: Internet Issues 2. PortSentry for Attack Detection - Part Two 3. Black Hat Briefings 4. Secure i-World II. BUGTRAQ SUMMARY 1. CVS Daemon RCS Off By One Local Buffer Overflow Vulnerability 2. PHPBB2 Image Tag HTML Injection Vulnerability 3. Microsoft IIS 5.0 Denial Of Service Vulnerability 4. Microsoft Active Data Objects Buffer Overflow Vulnerability 5. Microsoft Commerce Server 2000 Remote Buffer Overflow... 6. Microsoft Windows HTML Help ActiveX Control Multiple... 7. Tomahawk Technologies SteelArrow Web Application Server... 8. Virtual Programming VP-ASP SQL Injection Vulnerability 9. DataWizard FtpXQ Buffer Overflow Vulnerability 10. TransSoft FTP-Broker Denial of Service Vulnerability 11. FileZilla FTP Server Directory Traversal Vulnerability 12. ECS K7S5A Boot Menu Access Vulnerability 13. phpTest Test Result Disclosure Vulnerability 14. Firestorm IDS IP Options Decoding Denial Of Service Vulnerability 15. Image Display System Directory Existence Disclosure Vulnerability 16. Charities.Cron Insecure Temporary File Creation Vulnerability 17. Macromedia JRun Host Header Field Buffer Overflow Vulnerability 18. Trend Micro Interscan Viruswall SMTP Header Removal Vulnerability 19. IRSSI Trojaned Configure File Arbitrary Access Vulnerability 20. Opera Arbitrary File Disclosure Vulnerability 21. BlueFace Falcon Web Server File Disclosure Vulnerability 22. TightVNC Plain Text Password Storage Vulnerability 23. Yahoo! Messenger Call Center Buffer Overflow Vulnerability 24. Yahoo! Instant Messenger Script Injection Vulnerability 25. AMANDA amindexd Remote Buffer Overflow Vulnerability 26. TightVNC Listening Viewer Multiple Non-Shared Connections DoS... 27. AMANDA amcheck Local Buffer Overflow Vulnerability 28. 3Com OfficeConnect ADSL Router Port Address Translation... 29. NetScreen ScreenOS Remote Reboot Vulnerability 30. Oracle Application Server PL/SQL Module Format String... 31. Virtual Programming VP-ASP Test Page Information Disclosure... 32. Ipswitch WS_FTP Pro Buffer Overflow Vulnerability 33. Microsoft SQL Server 2000 Multiple Vulnerabilities 34. iPlanet Web Server Buffer Overflow Vulnerability 35. Oracle TNSListener Remote Buffer Overflow Vulnerability 36. Microsoft Windows 2000 Remote Access Service Buffer Overflow... 37. Oracle Reports Server Remote Buffer Overflow Vulnerability 38. Microsoft IIS HTR ISAPI Extension Heap Overflow Vulnerability 39. Oracle Web Cache Remotely Exploitable Buffer Overflow... 40. WoltLab Burning Board Predictable Account Activation String... III. SECURITYFOCUS NEWS ARTICLES 1. FBI Shake-up Makes IT A Principal Priority 2. Klez Infection Persists - Anti-Virus Companies 3. News Sites Tackle E-mail 'Subversion' Security Holes IV.SECURITYFOCUS TOP 6 TOOLS 1. squidanalog v0.1 2. LCDproc v0.4.3 3. The Logging Project v0.2 4. Secura v1.0 5. SQLSnake Removal Utility 1.0 Beta 6. UIF - Userfriendly Iptables Frontend v1.0.1 V. SECURITYJOBS LIST SUMMARY 1. Product Marketing Manager - Security Software (Thread) 2. Security Sales Engineer - SecurityFocus (Thread) 3. Public Relations Manager - CA - #684 (Thread) 4. Practice Manager - Information Security Professional Services - CA 5. Software developer looking for work. (Thread) 6. Need Awesome Network Exploitation Analysts (Thread) 7. ADMINISTRIVIA (Thread) 8. Lookign for InfoSec Engineer position in DC, Northern Virginia and 9. Opening - Experienced Wireless Security Architect (Dallas, TX) 10. Looking in Denver (Thread) 11. Job Lead -- TX-Dallas-Data Security Administrator (Thread) VI. INCIDENTS LIST SUMMARY 1. Compromised Win2000 machine. - Follow UP (Thread) 2. AW: strange .ch scan by 195.141.86.145 (Thread) 3. Compromised Win2000 machine. (Thread) 4. odd scans? (Thread) 5. New Stacheldraht? (Thread) 6. strange account in Win2k (Thread) 7. parsing output from tools (Thread) 8. Security contacts for cnn,time.com,usatoday,and boston globe 9. Worms and CScript/WScript (Thread) 10. SQLSnake email account shutdown? (Thread) 11. GET /proxy-test.php (Thread) 12. strange .ch scan by 195.141.86.145 (Thread) 13. Strange scans (Thread) 14. continues SCAN Proxy attempt (Thread) VII. VULN-DEV RESEARCH LIST SUMMARY 1. Wireless MAC Addy question (Thread) 2. wireless woes ... Stats on WEP usage. (Thread) 3. OT: snprintf() null termination (Thread) 4. wireless woes in the triangle and beyond! (Thread) 5. Microsoft IIS - Possible authentication flaw? (Thread) 6. DirectX 9 SDK, Microsoft have got balls.... (Thread) 7. sql injection and php (Thread) 8. Re[2]: Microsoft IIS - Possible authentication flaw? (Thread) 9. New Kismet Packages available - SayText() and suid kismet_server 10. Verizon Call Intercept (Thread) 11. sgid games - purity test. (Thread) 12. Your favourite capture/edit/retransmit tool? (Thread) 13. WinNT and previously used passwords (Thread) 14. OT? Are chroots immune to buffer overflows? (Thread) 15. Xandros based linux autorun -c (Thread) 16. Fragroute segmentation fault? (Thread) 17. AMANDA security issues (Thread) 18. VP-ASP shopping cart software. (Thread) 19. Achims Guestbook, InertiaNews, Pollen, MyPhpChat, mcPass (Thread) 20. MacOS X 10.1.4 MAC Address Spoofing (Thread) 21. On-Line Games and Privacy Issues (Thread) 22. Sendmail file locking - PoC (Thread) 23. [DER ADV#8] - Local off by one in CVSD (Thread) 24. addition: CVS off by one (Thread) 25. XSS And Headers... (Thread) 26. High APAR - Microsoft: Microsoft Security Bulletin MS02-024: 27. game console hacking thread (Thread) 28. COWS continuation (Thread) 29. Online Games Consoles and Security Implications (Thread) VIII. MICROSOFT FOCUS LIST SUMMARY 1. Help with XP Hotfixes and Patches (Thread) 2. Need free app for viewing metadata in Word documents (Thread) 3. restrict software installation (Thread) 4. Permissions on files (Thread) 5. Wingate Replacement (Thread) 6. SecurityFocus Microsoft Newsletter #88 (Thread) 7. Dial up access problem - not a (solution) (Thread) 8. How to disable WebDAV (Thread) 9. Problem - Using IPSec to secure Windows Messenger Traffic (Thread) 10. MS-SQL Blank Password Enumeration (Thread) 11. Dial up access problem solution (Thread) 12. About ping request? (Thread) 13. Why does XP establish HTTP connection when browsing network 14. Dialup access controls (Thread) 15. Why does XP establish HTTP connection: ADDITIONALLY, (Thread) 16. Question Regarding Securing Critical Executables (Thread) 17. Reinstallation of Hotfixes (Thread) IX. SUN FOCUS LIST SUMMARY 1. xhost (Thread) 2. tcp_wrappers x SSH (Thread) 3. ANNOUNCE - new SunCluster security BluePrint and JASS (s9 support) 4. ssh help (Thread) 5. BSM tool (Thread) 6. UseLogin and X11Forwarding (Thread) 7. C2 security standards (Thread) X. LINUX FOCUS LIST SUMMARY 1. securing nic's for snort (Thread) 2. How to get rid of spoofed IP-Address responses (Thread) 3. Linux Hardening (Thread) 4. irssi backdoor question (Thread) 5. What Is hosts2-ns (Thread) XI. SPONSOR INFORMATION I. FRONT AND CENTER ------------------- 1. Securing Privacy Part Four: Internet Issues By Scott Granneman This is the fourth and final installment in a series devoted to protecting users' privacy on the Internet. In this article, we will look more generally at our usage of the Internet. The Internet offers all of us unparalleled access to information, but it also brings with it unique threats to our privacy. This article will examine some of the ways you can protect yourself. http://online.securityfocus.com/infocus/1585 2. PortSentry for Attack Detection - Part Two by Ido Dubrawsky This is the second in a two-part series on PortSentry. The first article discussed how PortSentry works to identify attacks, as well as what types of attacks it identifies. This article will focus on building, installing, and operating PortSentry. The focus here will be on the various configuration options available for PortSentry, as well as some of the benefits and drawbacks of those options. http://online.securityfocus.com/infocus/1586 3. Black Hat Briefings Attend Black Hat Briefings & Training, July 29 - August 1, Las Vegas, the world's premier technical security event! 8 tracks, 12 training sessions, Richard Clarke keynote, 500 delegates from 30 nations, with a near cult following of both CSOs and "underground" security experts. See for yourself what the buzz is all about. http://www.blackhat.com 4. Secure i-World August 19-21, 2002, San Diego, CA Optional Workshops August 17, 18, 21, & 22 Vendor Expo August 19 & 20 WebSec 2002, Online Privacy Conference, Secure i-World Expo two innovative conferences and one outstanding expo, all in one blockbuster event. http://www.secureiworld.com/06/sw02nl18inf.html II. BUGTRAQ SUMMARY ------------------- 1. CVS Daemon RCS Off By One Local Buffer Overflow Vulnerability BugTraq ID: 4829 Remote: No Date Published: May 25 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4829 Summary: CVS is the concurrent versioning system. CVS is a freely available, open source software development package for the Unix, Linux, and Microsoft Windows platforms. A problem with the software could make it possible for an attacker to gain elevated privileges. Due to a boundry condition error, it may be possible for a local attacker to execute arbitrary code. The rcs.c file contains an off-by-one error that could result in an attacker overwriting portions of stack memory, and executing arbitrary code. This problem could result in an attacker gaining access to the CVS archives with the privileges of the CVS user. This could allow an attacker to alter source code within the CVS archive, and potentially backdoor source code. 2. PHPBB2 Image Tag HTML Injection Vulnerability BugTraq ID: 4858 Remote: Yes Date Published: May 26 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4858 Summary: phpBB2 is free, open-source web forums software that is written in PHP and backended by MySQL. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems. BBCode is a feature which allows users to include HTML-style formatting elements in their forum messages. It is possible to inject arbitrary HTML into phpBB2 forum messages via the use of BBCode image tags. A similar issue is described in Bugtraq ID 4379 "PHPBB Image Tag User-Embedded Scripting Vulnerability". However, phpBB2 was found to not be vulnerable to this previous issue. When the image tag is translated into HTML, the following code is used: <img src="$user_provided" border="0" /> phpBB2 checks to ensure that the user-provided image source is prepended with "http://", which restricts the user from injecting arbitrary HTML as the image source. However, it has been reported that this measure may be circumvented by using a double-quotation (") character to close the image source tag. The attacker may then include arbitrary HTML after the double-quotation. The attacker may exploit this issue to inject script code into forum messages. When such messages are displayed by a web user, the attacker's script code will execute in their browser in the context of the website. If the web user is an authenticated user of the phpBB2 forum, then the attacker may exploit this condition to steal cookie-based authentication credentials from the user. phpBB versions prior to the phpBB2 series may also be affected by this vulnerability. 3. Microsoft IIS 5.0 Denial Of Service Vulnerability BugTraq ID: 4846 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4846 Summary: A remotely exploitable denial of service condition in Microsoft IIS 5.0 has reported by a reliable source. The denial of service is caused by resource exhaustion. Additional technical details will be added to this vulnerability record when they become available. 4. Microsoft Active Data Objects Buffer Overflow Vulnerability BugTraq ID: 4849 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4849 Summary: A reliable source has reported an exploitable buffer overflow condition in Microsoft Active Data Objects (ADO). Microsoft ADO are an Active-X object that handles data from the server to the web client. Microsoft ADO support any ODBC database. ADO ships as a part of MDAC (Microsoft Data Access Components). This vulnerability may pose a risk for users of Microsoft Internet Explorer, but is not present in the default configuration of the web browser. This issue is only present if the browser is configured to allow access to datasources across domains. Under some circumstances, there also may be a risk for Microsoft IIS servers, in the case that the server is being used to host content which may come from an untrusted source. The attacker must be able to upload an ASP page and execute it to exploit this issue in Microsoft IIS servers. If the attacker has the ability to do this, then many other avenues of attack exist. 5. Microsoft Commerce Server 2000 Remote Buffer Overflow Vulnerabilities BugTraq ID: 4853 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4853 Summary: A reliable source has reported that a number of remotely exploitable buffer overflows exist in Microsoft Commerce Server 2000. These conditions may be exploited to execute arbitrary attacker-supplied instructions with the privileges of the Microsoft Commerce Server 2000 process. Additional technical details will be added to this vulnerability record when they become available. 6. Microsoft Windows HTML Help ActiveX Control Multiple Vulnerabilities BugTraq ID: 4857 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4857 Summary: HTML Help ActiveX control (Hhctrl.ocx) ships as part of Microsoft HTML Help, and is designed to work with Internet Explorer to provide functionality for help systems. The HTML Help ActiveX control can be used to exploit stack and heap based overflow attacks. It may be possible for remote users to execute arbitrary code on a user's system. This problem may allow an attacker to overwrite stack and heap variables including the return address, possibly to execute arbitrary code. The attacker may also crash the service by sending excessive amounts of data that has not specifically been designed to cause code execution. Details of this vulnerability are currently unavailable, this record will be updated as more information becomes available. It should be noted that Windows ships with HTML Help. 7. Tomahawk Technologies SteelArrow Web Application Server Multiple Buffer Overflow Vulnerabilities BugTraq ID: 4860 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4860 Summary: SteelArrow Web Application Server is a freely available application server by Tomahawk Technologies Inc. Due to multiple buffer overflow vulnerabilities in SteelArrow Web Application Server, it may be possible for remote users to execute arbitrary code on a target host. Exploitation of these vulnerabilities may allow for an attacker to overwrite stack variables, including the return address, possibly to execute arbitrary code. The attacker may also crash the service by sending excessive amounts of data that has not specifically been constructed to cause code execution. Additional technical details will be added to this vulnerability record when they become available. 8. Virtual Programming VP-ASP SQL Injection Vulnerability BugTraq ID: 4861 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4861 Summary: Virtual Programming VP-ASP is a shopping cart application for e-commerce enabled sites. A SQL injection vulnerability has been reported in some versions of Virtual Programming VP-ASP. The authentication data supplied by the remote user is used directly to construct SQL statements. As input sanitization is not properly performed, an attacker may include unescaped special characters such as "'", and "=" as part of the username and password. Consequently, the structure and logic of the query may be hijacked. It has been reported that exploitation of this vulnerability may allow for authentication to be bypassed. 9. DataWizard FtpXQ Buffer Overflow Vulnerability BugTraq ID: 4862 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4862 Summary: FtpXQ is a ftp daemon designed to provide ftp services for Microsoft Operating Systems. The software package has been written for Microsoft Windows 95/98/NT/2000. It is maintained and distributed by Datawizard Technologies. FtpXQ is contains a buffer overflow which can result in a denial of services if exploited. Creating a directory with a name longer than 254 characters will cause the server to crash. It is also believed that attackers can cause arbirtary code to be executed on target servers, however this is not confirmed. 10. TransSoft FTP-Broker Denial of Service Vulnerability BugTraq ID: 4864 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4864 Summary: Transoft Broker is an FTP server for the Windows platform. It is possible for users to cause the FTP server to stop responding. Reportedly, this is possible when submitting a CWD command along with numerous '....' character sequences. A remote attacker who exploits this issue may deny service to legitimate users of the system. A restart of the service may be required in order to regain normal functionality. 11. FileZilla FTP Server Directory Traversal Vulnerability BugTraq ID: 4865 Remote: Yes Date Published: May 28 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4865 Summary: FileZilla FTP Server is vulnerable to directory traversal attacks. For security reasons, the server is designed restrict users to a specific directory tree. It has been reported that this mechanism is flawed. By using directory traversal sequences (ie '/../', '..'), an attacker can obtain files outside of the permitted directory structure. Disclosure of sensitive files and the filesystem layout may supply an attacker with important information. This information could lead to further compromise of the vulnerable system. 12. ECS K7S5A Boot Menu Access Vulnerability BugTraq ID: 4866 Remote: No Date Published: May 28 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4866 Summary: K7S5A is a line of mainboards manufactured and distributed by ECS. A problem with the firmware could make it possible for a user with physical access to the system to circumvent bios security measures. The firmware distributed with K7S5A boards may allow users with physical access to systems to boot of alternative media. Though the firmware allows the setting of administrative passwords and specification of default boot media, it does not protect the boot menu. With access to the boot menu, arbitrary media such as a floppy or CD may be booted from. This makes it possible for users with physical access to the system to boot off an arbitrary medium. This could lead to compromise of the operating system, and integrity of data. 13. phpTest Test Result Disclosure Vulnerability BugTraq ID: 4868 Remote: Yes Date Published: May 28 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4868 Summary: phpTest is a free web based testing application maintained by Brandon Tallent. A minor security vulnerability has been discovered in versions of phpTest prior to 0.5.6. The issue is related to handling of client input when viewing test results. According to the author of phpTest, it is possible for users to exploit this vulnerability to view the test results of other users. Though unconfirmed, this may be accomplished by modifying the user (or another) HTML form parameter. Test results may be considered sensitive information in some environments. Data obtained by a malicious party may also be used in social engineering attacks. This vulnerability was eliminated in phpTest 0.5.6. 14. Firestorm IDS IP Options Decoding Denial Of Service Vulnerability BugTraq ID: 4871 Remote: Yes Date Published: May 28 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4871 Summary: Firestorm IDS is a freely available, open source intrusion detection package. It is maintained by public domain. A problem with Firestorm IDS could make it possible to crash the software. Firestorm IDS may become unstable when handling certain IP options. It has been reported that Firestorm IDS can be caused to crash when it has received traffic with specific IP options set. This could result in a denial of service. The problem is likely due to a memory management bug, though this is unconfirmed. If this is the case, it may additionally be possible to execute arbitrary code on a vulnerable IDS implementation. The code would be executed with the privileges of the Firestorm IDS user. 15. Image Display System Directory Existence Disclosure Vulnerability BugTraq ID: 4870 Remote: Yes Date Published: May 28 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4870 Summary: IDS (Image Display System) is an web based photo album application written in Perl. IDS is freely available and is maintained by Ashley M. Kirchner. Users can confirm the location of various directories residing on the host through a trial and error method. This is accomplished when a request for a directory and album name is sent to the host containing numerous '../' character sequences. The error page returned will assist the user in determining whether the directory exists or not. The error page that will display if the directory is valid and the album name is invalid is "Sorry, the album (album_name) doesn't exist". If the directory specified is invalid the error message is as follows: "Sorry, invalid directory name". It is not currently known if it is possible to access the contents of the guessed directory. The attacker may, however, be able to use this information to perform further, intelligent attacks against the vulnerable system. 16. Charities.Cron Insecure Temporary File Creation Vulnerability BugTraq ID: 4869 Remote: No Date Published: May 28 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4869 Summary: Charities.cron is a cron script written in gawk, which clicks the links on various charity websites. Charities.cron is intended to be run as a daily cron job. It will run on most Unix and Linux variants. Charities.cron uses the lynx web browser to poll various charity websites. It downloads the charity webpages and stores them in temporary files. However, Charities.cron creates these temporary files with predictable filenames. A local attacker may exploit this to cause arbitrary files writeable by the cron scheduling daemon process to be written to via symlink attacks. This may result in a denial of service condition. This vulnerability has existed in one form or another through various releases of Charities.cron. Since the most recent version (1.7.0) still uses prediactable temporary filenames, it may be still be possible to exploit this condition. Charities.cron does check to see if the temporary files used already exist before dumping the charity webpages, however, this fix only creates a race condition which may still be potentially exploitable. 17. Macromedia JRun Host Header Field Buffer Overflow Vulnerability BugTraq ID: 4873 Remote: Yes Date Published: May 29 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4873 Summary: Macromedia JRun is a J2EE (Java 2 Platform Enterprise Edition) application server for use with IIS (Internet Information Server) 4/5 on the Microsoft Windows operating systems. A vulnerability has been reported in Macromedia JRun version 3.1. It is reportedly possible to cause a buffer overflow condition in JRun if an excessively long HTTP host header field is transmitted by the client. JRun server will install itself as a ISAPI (Internet Server Application Programming Interface) filter/application in the '/scripts' virtual directory of the webserver. When a '.jsp' page is requested, the JRun filter is invoked. The overflow will occur if a client makes a request for a .jsp file with an overly long HTTP host header field. This condition may be exploited by attackers to execute arbitrary code on the vulnerable system in the security context of IIS. 18. Trend Micro Interscan Viruswall SMTP Header Removal Vulnerability BugTraq ID: 4830 Remote: Yes Date Published: May 24 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4830 Summary: Interscan Viruswall is a mail gateway solution distributed and maintained by Trend Micro. This problem affects versions running on the Microsoft Windows platform. A flaw in Viruswall may make it possible to hide the origins of email. The problem is in the editing of headers by the product. When a mail is sent to a site using Interscan Viruswall, it is passed first through the Viruswall software. After processing by the Viruswall package, if it clears the check it is passed on to the mail transport agent (MTA) on the system, typically running on a different port. Viruswall does not preserve headers from email when email is passed to the MTA running on the system. This problem makes it possible for outside users to obscure the origins of mail sent to the server. An attacker could take advantage of this vulnerability to spam the host without the risk of being traced. This vulnerability could also be exploited to send misinformation through the host, appearing to come from a local user of the mail system. It should be noted that the origins of email is logged by Interscan Viruswall only when a virus is discovered. 19. IRSSI Trojaned Configure File Arbitrary Access Vulnerability BugTraq ID: 4831 Remote: Yes Date Published: May 25 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4831 Summary: irssi is a freely available, open source irc client. irssi is available for the Linux and Unix operating systems. A problem with the client could make it possible for a remote user to gain control of a users account. The server hosting irssi was compromised at some point. After being compromised, the source code to irssi was altered to include a backdoor. This backdoor allowed a user from the IP address 204.120.36.206 to remotely execute commands on the host that irssi was installed on. The source code is known to have been trojaned between the beginning of April, and end of May. Downloads of the source during this time likely contain the trojan code. This problem could lead to a remote attacker gaining access to system with the privileges of the irssi process. This problem could additionally lead to further compromise. 20. Opera Arbitrary File Disclosure Vulnerability BugTraq ID: 4834 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4834 Summary: Opera is a web browser created by Opera Software. It is available for a range of operating systems including Windows and Linux. A vulnerability has been reported in Opera 6.01/6.02. The vulnerability is related to handling of the 'file' HTML input-type. The 'file' input-type supports upload of files as HTML form input, from a client to a webserver. By design, Opera does not prevent the server from setting the filename to be uploaded. To prevent malicious servers from forcing the upload of arbitrary files, a warning dialog is presented to the user when a form with a file upload is submitted. If a form with a 'file' input type is submitted with no file value set, the dialog is not displayed (as there is no file being uploaded). It is possible for a server to set the file value while fooling Opera into thinking no file has been specified. An attacker may accomplish this if the filename is appended with the string " ". This HTML-encoded newline character will cause the browser to believe that no value has been set. Consequently, the form will be submitted and the specified file will be uploaded to the server. This may occur without knowledge or consent of the victim user. Exploitation of this vulnerability allows for malicious webmasters to obtain arbitrary files from client systems. 21. BlueFace Falcon Web Server File Disclosure Vulnerability BugTraq ID: 4833 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4833 Summary: Falcon Web Server is a small web server that runs on several Microsoft Windows platforms. It is mainly intended for small to medium sized businesses. Password protected files residing on the Falcon Web Server may be disclosed to unauthorized users. The user would have to know the name of the file in order to access it. The file could be accessed simply by requesting a URL in the following format from the web server: http://host/protectedfolder./ 22. TightVNC Plain Text Password Storage Vulnerability BugTraq ID: 4835 Remote: No Date Published: May 25 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4835 Summary: TightVNC is a VNC (Virtual Network Computing) distribution maintained by Constantin Kaplinsky. An issue has been reported in versions of TightVNC for Windows, which may potentially disclose authentication credentials to attackers. TightVNC stores authentication information in plaintext on the local system in the password text control of the WinVNC Properties dialog. As a result, it may be possible for a local user to steal authentication credentials for the service. The attacker may then access the service as that user. TightVNC versions prior to 1.2.4 may be susceptible to this issue. 23. Yahoo! Messenger Call Center Buffer Overflow Vulnerability BugTraq ID: 4837 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4837 Summary: Yahoo! Messenger configures a handler for the 'ymsgr:' URI when it is installed. The handler invokes YPAGER.EXE with the supplied parameters. YPAGER.EXE accepts the 'call' parameter and it's associated argument, used for starting the 'Call Center' feature. There is a stack overrun condition in the 'Call Center' component that may be exploited through a specially constructed URI. It has been reported that the stack frame of the affected function will be corrupted if the argument to the 'call' parameter is 268 bytes or greater in length. This vulnerability may be exploited by crafting a 'ymsgr:' link. The link must consist of the 'call' parameter and the exploit-string as it's argument. For example: ymsgr:call?+<aaaaaaaaaaaaaaaa...> If such a link is clicked on by a victim, the 'call' parameter will cause YPAGER.EXE to invoke the 'Call Center'. The oversized argument will trigger the overrun condition when the 'Call Center' component attempts to process it. Attackers may exploit this vulnerability to execute arbitrary code on client systems. 24. Yahoo! Instant Messenger Script Injection Vulnerability BugTraq ID: 4838 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4838 Summary: Yahoo! Messenger is the main instant messaging client used on the Yahoo! network. URL's beginning with ymsgr:addview? allow users to add content to Yahoo! Messenger content tabs for viewing through Yahoo! Messenger without the use of a web browser. It is possible to use ymsgr:addview? to point the Yahoo! Messenger to a web page containing script that will in turn be rendered by the instant messenger. For example: ymsgr:addview?http://rd.yahoo.com/messenger/?htt://webserver/scriptpage.htm If this page contains Javascript or Visual Basic Script, the script will be executed by the Yahoo! Messenger. Scripts executed in this manner may mimic or replace the behaviour of certain Yahoo! Messenger content tabs. It is also possible that the scripts could modify properties of the instant messenger allowing further exploitation, however, this behaviour has not been confirmed. 25. AMANDA amindexd Remote Buffer Overflow Vulnerability BugTraq ID: 4836 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4836 Summary: AMANDA (Advanced Maryland Automatic Network Disk Archiver) is a system for backing up multiple hosts onto a single tape drive. It will run on most Unix and Linux variants. The AMANDA amindexd daemon is prone to a remotely exploitable buffer overflow condition. This condition is due to insufficient bounds checking of command strings. Overly long command strings (260+ bytes) may cause stack variables such as the return address to be overwritten. This vulnerability may be exploited by remote attackers to run arbitrary instructions as root, leading to a complete compromise of the host running the vulnerable software. The amindexd daemon runs on port 10082. This issue was reported for AMANDA 2.3.0.4, which is an older release. Other versions may also be affected. 26. TightVNC Listening Viewer Multiple Non-Shared Connections DoS Vulnerability BugTraq ID: 4839 Remote: Yes Date Published: May 25 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4839 Summary: TightVNC is a VNC (Virtual Network Computing) distribution maintained by Constantin Kaplinsky. A vulnerability has been reported in versions of TightVNC for Windows. It is reportedly possible for maliciouis clients to crash the listening viewer. The viewer will fail if a client establishes a number of non-shared connections. This issue exists in versions of TightVNC prior to 1.2.4. Successful exploitation of this issue will shut down the listening viewer. A restart of the service may be required in order to regain normal functionality. 27. AMANDA amcheck Local Buffer Overflow Vulnerability BugTraq ID: 4840 Remote: No Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4840 Summary: AMANDA (Advanced Maryland Automatic Network Disk Archiver) is a system for backing up multiple hosts onto a single tape drive. It will run on most Unix and Linux variants. The AMANDA amcheck component is prone to a locally exploitable buffer overflow condition. The amcheck utility is installed setuid root by default. The overflow condition is due to insufficient bounds checking when processing command line input. It is possible for remote attackers to overwrite the stack frame of the affected function when amcheck is invoked with an oversized command parameter. It should be noted that amcheck may only be executed by the user/group 'operator'. Only attackers with sufficient privileges to execute amcheck may exploit this vulnerability. This issue was reported for AMANDA 2.3.0.4, which is an older release. Other versions may also be affected. 28. 3Com OfficeConnect ADSL Router Port Address Translation Access Control Bypassing Vulnerability BugTraq ID: 4841 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4841 Summary: OfficeConnect ADSL routers are a hardware and switch solution distributed by 3Com. A problem with the router could make it possible for remote users to gain unauthorized access to systems. The problem is in the handling of port address translation. Port Address Translation (PAT) is functionality built into an OfficeConnect router to allow redirection of some traffic. PAT works by taking connections to specific ports on an OfficeConnect router, and redirecting them to a system behind the router, specified in the firmware configuration. Under some circumstances, it may be possible for a remote user to gain unauthorized access to information systems behind a 3Com OfficeConnect router. The OfficeConnect does not properly handle PAT, and may allow a remote attacker to connect to arbitrary ports on a system behind a PAT rule. An attacker sending a connection to PAT port will be routed to the system behind the PAT rule. If an additional connection attempt on a different port is attempted immediately after the PAT connection, the router will relay the connection to the appropriate port on the system with which the PAT connection exists. This could give an attacker unauthorized access to a system, and could additionally result in the compromise of insecure systems. 29. NetScreen ScreenOS Remote Reboot Vulnerability BugTraq ID: 4842 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4842 Summary: NetScreen is a line of Internet security appliances integrating firewall, VPN and traffic management features. ScreenOS is the software used to manage and configure the firewall. NetScreen supports Microsoft Windows 95, 98, ME, NT and 2000 clients. It is possible for remote attackers to cause the device to reboot by sending an overly long username to the web interface. An attacker may create a prolonged denial of service condition by repeatedly causing the device to reboot. This condition may be the result of an unchecked buffer, which may potentially allow the attacker to execute arbitrary code. This possibility has not been confirmed. 30. Oracle Application Server PL/SQL Module Format String Vulnerability BugTraq ID: 4844 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4844 Summary: Application Server is a commercially available web application development package distributed by Oracle. A problem with the Oracle Application Server could make it possible for remote users to gain access to a system running the software. A format string vulnerability has been discovered in the Application Server. This problem may allow an attacker to write data to arbitrary addresses in memory, and potentially execute arbitrary code. This would likely result in a user gaining access to a vulnerable server with the privileges of the oracle user. Reports indicate the problem is in the administration pages of the PL/SQL module. 31. Virtual Programming VP-ASP Test Page Information Disclosure Vulnerability BugTraq ID: 4843 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4843 Summary: Virtual Programming VP-ASP is a shopping cart application for e-commerce enabled sites. The '/demo400/shopdbtest.asp' test page is included in a default installation of VP-ASP. The absolute path of the page will be disclosed when submitting a specially crafted request for 'shopdbtest.asp'. Successful exploitation of this issue will provide remote users knowledge of system path information, which may assist them in further attacks against the host. 32. Ipswitch WS_FTP Pro Buffer Overflow Vulnerability BugTraq ID: 4850 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4850 Summary: Ipswitch WS_FTP Pro is a FTP client for Microsoft Windows systems. A buffer overflow condition has been reported in WS_FTP Pro. Precise details are not currently available, however it is believed that it may be exploitable by a malicious server. Successful exploitation of this vulnerability may result in remote attackers gaining access to vulnerable client hosts. This record will be updated as more information becomes available. 33. Microsoft SQL Server 2000 Multiple Vulnerabilities BugTraq ID: 4847 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4847 Summary: SQL Server 2000 is a commercially available enterprise level database product from Microsoft. Microsoft SQL Server 2000 has been reported to contain multiple vulnerabilities. These include heap and stack buffer overflows and service/network denial of services attacks. Details of this vulnerability are currently scarce, this record will be updated as more information becomes available. 34. iPlanet Web Server Buffer Overflow Vulnerability BugTraq ID: 4851 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4851 Summary: iPlanet Webserver is an http server product offered by Sun Microsystems. Due to a buffer overflow vulnerability in iPlanet Web Server, it may be possible for remote users to execute arbitrary code with SYSTEM privileges. This problem may allow an attacker to overwrite stack variables including the return address, possibly to execute arbitrary code. The attacker may also crash the service by sending excessive amounts of data that has not specifically been designed to cause code execution. 35. Oracle TNSListener Remote Buffer Overflow Vulnerability BugTraq ID: 4845 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4845 Summary: TNSListener is a component of the Oracle database, distributed by Oracle Corporation. A problem with the database may allow a remote user to gain access to a vulnerable system. A buffer overflow has been reported in the Oracle TNSListener. This buffer overflow may allow a user to remotely execute code on a vulnerable system. In doing so, a remote user may be able to gain access to the local system, and potentially the privileges of the TNSListener process. The TNSListener process typically runs as the user oracle, and group dba. By gaining access to the system with these privileges, a user may be able to access all data contained within the database files. 36. Microsoft Windows 2000 Remote Access Service Buffer Overflow Vulnerability BugTraq ID: 4852 Remote: No Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4852 Summary: Remote Access Service (RAS) is a service included in Microsoft Windows 2000 to allow users to connect to a corporate intranet or the Internet from a remote computer. It has been reported that the RAS service included in Windows 2000 is vulnerable to a buffer overflow condition. Details of this vulnerability are scarce, however, successful exploitation could result in a denial of service or possibly execution of arbitrary code. This record will be updated as more information becomes available. 37. Oracle Reports Server Remote Buffer Overflow Vulnerability BugTraq ID: 4848 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4848 Summary: Reports Server is a commercially available reporting package distributed by Oracle. A problem with Reports Server may allow a remote user access to a vulnerable host. A buffer overflow has been reported in the Oracle Reports Server. This buffer overflow may allow a user to remotely execute code on a vulnerable system. In doing so, a remote user may be able to gain access to the local system, and potentially the privileges of the Reports Server. The Reports Server typically runs with the privileges of user oracle, and group dba. By gaining access to the system with these privileges, a user may be able to access all data contained within the database files. 38. Microsoft IIS HTR ISAPI Extension Heap Overflow Vulnerability BugTraq ID: 4855 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4855 Summary: It has been reported that the HTR ISAPI extension for Microsoft IIS is vulnerable to a heap overflow condition. HTR is a scripting technology for IIS that has been largely superseded by ASP (Active Server Pages). A condition exists in the HTR ISAPI extension that may allow a remote attacker to overwrite locations in memory with attacker-supplied data. This condition affects IIS 5.0 and may be effectively mitigated by disabling the extension. Exploitation of this vulnerability may result in a denial of service or allow for a remote attacker to execute arbitrary instructions on the victim host. 39. Oracle Web Cache Remotely Exploitable Buffer Overflow Vulnerabilities BugTraq ID: 4856 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4856 Summary: Web Cache is a commercially available web caching software distributed by Oracle. Several problems with Oracle Web Cache may make it possible for a remote user to gain access to a vulnerable system. It has been reported that several remotely exploitable buffer overflows exist in the Oracle Web Cache. These buffer overflows may allow a user to remotely execute code on a vulnerable system. In doing so, a remote user may be able to gain access to the local system, and potentially the privileges of the Web Cache process. The Web Cache process typically runs as the user oracle, and group dba. By gaining access to the system with these privileges, a user may be able to access all data contained within the database files. 40. WoltLab Burning Board Predictable Account Activation String Vulnerability BugTraq ID: 4859 Remote: Yes Date Published: May 27 2002 12:00A Relevant URL: http://www.securityfocus.com/bid/4859 Summary: WoltLab Burning Board is a free web-based bulletin board package based on PHP and MySQL. It is possible to hijack an account that has not yet been activated. When a user creates a new account on a Burning Board forum, they will be presented with a link which they must click in order to activate their account: http://forum.dom/forum/action.php?action=activation&userid=345&code=1563109322 The code variable is generated by the following operation: $datum = date("s"); mt_srand($datum); $z = mt_rand(); Since the variable is generated by performing an mt_srand operation on the second that the request is submitted, there are only 60 possible values for this variable. An attacker could easily perform a brute force attack on this variable and gain access to the user's account. III. SECURITYFOCUS NEWS AND COMMENTARY ------------------------------------------ 1. FBI Shake-up Makes IT A Principal Priority By Wilson P. Dizard III, Newsbytes As part of a massive shake-up of the FBI, Director Robert Mueller said Wednesday that a technology upgrade is one of the agency's top 10 priorities. Acknowledging that the FBI had handled terrorism clues inefficiently before Sept. 11, Mueller pegged the agency's technology upgrade as critical to its new counterterror focus. http://online.securityfocus.com/news/456 2. Klez Infection Persists - Anti-Virus Companies By Michael Bartlett, Newsbytes The "Klez" worm and its variants, including Klez.E and Klez.H, continue to spread at a dizzying rate, according to anti-virus experts. The Klez rampage has gotten so serious, recent media reports dubbed it the No. 1 virus of all time. http://online.securityfocus.com/news/453 3. News Sites Tackle E-mail 'Subversion' Security Holes By Brian McWilliams, Newsbytes Security flaws in e-mail features at several popular news sites could have been exploited by "spammers" or used to spread false information, a security specialist cautioned today. In response to the warning, Time magazine has temporarily disabled the "e-mail-a-friend" function at its Web site. Similar security flaws at sites operated by CNN and the Boston Globe were corrected earlier this week by those news organizations. http://online.securityfocus.com/news/454 IV. SECURITYFOCUS TOP 6 TOOLS ----------------------------- 1. squidanalog v0.1 by Hendry D. Lee Relevant URL: http://www.dutnux.com/software/squidanalog.html Platforms: Linux, POSIX Summary: squidanalog is a collection of programs and scripts that will gather data from squid access logs and save it into a round robin database using rrdtool. Nice customized graphics can be plotted from the gathered data. 2. LCDproc v0.4.3 by William W. Ferrell Relevant URL: http://lcdproc.omnipotent.net Platforms: FreeBSD, Linux, OpenBSD, Solaris Summary: LCDproc is a utility to drive one or more LCD (and LCD-like) devices attached to a host. It is comprised of a server, which uses a modular device driver system to control attached displays, and one or more clients to gather data as appropriate and send screen data to the server. The included client displays a multitude of system statistics (CPU/memory/disk usage, uptime, date and time, temperature, etc.). Multiple clients can connect to the server simultaneously, and clients can set priorities on the screens they provide to influence in what order items are displayed. This facility can also be used to "pop" critical screens (such as an entry from syslog from a log-watching client). All functionality is implemented in userland. Support for many display devices and several platforms (Linux, *BSD, and Solaris at least) is included. 3. The Logging Project v0.2 by Jason Royes Relevant URL: http://condor.gmu.edu/~jason/logging/ Platforms: POSIX Summary: The Logging Project (formerly salt) is a suite of tools which provide centralized, secure, fault-tolerant logging. It is flexible, robust, and easy to integrate, making it an attractive alternative to replacing syslog. 4. Secura v1.0 by Goldie R [email protected] Relevant URL: http://www.checksum.org/ Platforms: Os Independent Summary: This is a blowfish encryption suite that uses CBC mode of encryption for encryption and decryption of files. It is written in java and henceforth can be used on all the platforms that supports java. The source code is given under the GPL license. Make use of it and protect your assets. Please find the answers in the readme.txt for your questions of usage. 5. SQLSnake Removal Utility 1.0 Beta by [email protected] Relevant URL: http://www.nstalker.com/util.php Platforms: Windows 2000, Windows 95/98, Windows XP Summary: SQLSnake Removal Utility detects and removes SQLSnake locally. 6. UIF - Userfriendly Iptables Frontend v1.0.1 by Jörg Platte [email protected] Relevant URL: http://lug.mfh-iserlohn.de/uif Platforms: Linux, POSIX Summary: The Userfriendly Iptables Frontend is used to generate optimized iptables packet filter rules, using a simple description file specified by the user. Generated rules are provided in iptables- save style. UIF can be used to read or write rulesets to or from LDAP servers in your network, which provides a global storing mechanism. Its aim is to be an easy to configure, human readable packet filter. V. SECURITY JOBS SUMMARY ------------------------ 1. Product Marketing Manager - Security Software (Thread) Relevant URL: http://online.securityfocus.com/archive/77/[email protected] 2. Security Sales Engineer - SecurityFocus (Thread) Relevant URL: http://online.securityfocus.com/archive/77/[email protected] 3. Public Relations Manager - CA - #684 (Thread) Relevant URL: http://online.securityfocus.com/archive/77/[email protected] 4. Practice Manager - Information Security Professional Services - CA (Thread) Relevant URL: http://online.securityfocus.com/archive/77/5544986F9407D611A5900008C70964061A612E@EXCHANGE 5. Software developer looking for work. (Thread) Relevant URL: http://online.securityfocus.com/archive/77/[email protected] 6. Need Awesome Network Exploitation Analysts (Thread) Relevant URL: http://online.securityfocus.com/archive/77/[email protected] 7. ADMINISTRIVIA (Thread) Relevant URL: http://online.securityfocus.com/archive/77/[email protected] 8. Lookign for InfoSec Engineer position in DC, Northern Virginia and MD (Thread) Relevant URL: http://online.securityfocus.com/archive/77/[email protected] 9. Opening - Experienced Wireless Security Architect (Dallas, TX) (Thread) Relevant URL: http://online.securityfocus.com/archive/77/[email protected] 10. Looking in Denver (Thread) Relevant URL: http://online.securityfocus.com/archive/77/[email protected] 11. Job Lead -- TX-Dallas-Data Security Administrator (Thread) Relevant URL: http://online.securityfocus.com/archive/77/[email protected] VI. INCIDENTS LIST SUMMARY ------------------------- 1. Compromised Win2000 machine. - Follow UP (Thread) Relevant URL: http://online.securityfocus.com/archive/75/[email protected] 2. AW: strange .ch scan by 195.141.86.145 (Thread) Relevant URL: http://online.securityfocus.com/archive/75/[email protected] 3. Compromised Win2000 machine. (Thread) Relevant URL: http://online.securityfocus.com/archive/75/[email protected] 4. odd scans? (Thread) Relevant URL: http://online.securityfocus.com/archive/75/4.3.2.7.2.20020529144459.030bee20@localhost 5. New Stacheldraht? (Thread) Relevant URL: http://online.securityfocus.com/archive/75/5BA6439FCDF318459BC50C3BBB6A0BE302DDA2A5@GCSCEXC2 6. strange account in Win2k (Thread) Relevant URL: http://online.securityfocus.com/archive/75/[email protected] 7. parsing output from tools (Thread) Relevant URL: http://online.securityfocus.com/archive/75/[email protected] 8. Security contacts for cnn,time.com,usatoday,and boston globe needed (Thread) Relevant URL: http://online.securityfocus.com/archive/75/[email protected] 9. Worms and CScript/WScript (Thread) Relevant URL: http://online.securityfocus.com/archive/75/120097989CFFD1118B8C00805FFEE2460AE0DB3C@GBWTM001 10. SQLSnake email account shutdown? (Thread) Relevant URL: http://online.securityfocus.com/archive/75/[email protected] 11. GET /proxy-test.php (Thread) Relevant URL: http://online.securityfocus.com/archive/75/[email protected] 12. strange .ch scan by 195.141.86.145 (Thread) Relevant URL: http://online.securityfocus.com/archive/75/[email protected] 13. Strange scans (Thread) Relevant URL: http://online.securityfocus.com/archive/75/[email protected] 14. continues SCAN Proxy attempt (Thread) Relevant URL: http://online.securityfocus.com/archive/75/1022459537.1177.108.camel@bloodnock VII. VULN-DEV RESEARCH LIST SUMMARY ---------------------------------- 1. Wireless MAC Addy question (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 2. wireless woes ... Stats on WEP usage. (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 3. OT: snprintf() null termination (Thread) Relevant URL: http://online.securityfocus.com/archive/82/75C025AE395F374B81F6416B1D4BDEFB7003FC@MTV-CORPMAIL 4. wireless woes in the triangle and beyond! (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 5. Microsoft IIS - Possible authentication flaw? (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 6. DirectX 9 SDK, Microsoft have got balls.... (Thread) Relevant URL: http://online.securityfocus.com/archive/82/002d01c20755$eb5a6660$24029dd9@kain 7. sql injection and php (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 8. Re[2]: Microsoft IIS - Possible authentication flaw? (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 9. New Kismet Packages available - SayText() and suid kismet_server issues (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 10. Verizon Call Intercept (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 11. sgid games - purity test. (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 12. Your favourite capture/edit/retransmit tool? (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 13. WinNT and previously used passwords (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 14. OT? Are chroots immune to buffer overflows? (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 15. Xandros based linux autorun -c (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 16. Fragroute segmentation fault? (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 17. AMANDA security issues (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 18. VP-ASP shopping cart software. (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 19. Achims Guestbook, InertiaNews, Pollen, MyPhpChat, mcPass (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 20. MacOS X 10.1.4 MAC Address Spoofing (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 21. On-Line Games and Privacy Issues (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 22. Sendmail file locking - PoC (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 23. [DER ADV#8] - Local off by one in CVSD (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 24. addition: CVS off by one (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 25. XSS And Headers... (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 26. High APAR - Microsoft: Microsoft Security Bulletin MS02-024: Authentication Flaw in Windows Debugger can Lead to Elevated Privileges (Q320206) (Thread) Relevant URL: http://online.securityfocus.com/archive/82/OF862753BF.466457D7-ONC2256BC4.002B94F4-C2256BC4.002BC5BD@telaviv.ibm.com 27. game console hacking thread (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 28. COWS continuation (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] 29. Online Games Consoles and Security Implications (Thread) Relevant URL: http://online.securityfocus.com/archive/82/[email protected] VIII. MICROSOFT FOCUS LIST SUMMARY --------------------------------- 1. Help with XP Hotfixes and Patches (Thread) Relevant URL: http://online.securityfocus.com/archive/88/002d01c2077f$b3a03fe0$fdfea8c0@dellydoo 2. Need free app for viewing metadata in Word documents (Thread) Relevant URL: http://online.securityfocus.com/archive/88/[email protected] 3. restrict software installation (Thread) Relevant URL: http://online.securityfocus.com/archive/88/[email protected] 4. Permissions on files (Thread) Relevant URL: http://online.securityfocus.com/archive/88/000b01c206da$431bd590$3200a8c0@laptop 5. Wingate Replacement (Thread) Relevant URL: http://online.securityfocus.com/archive/88/9D884881F5E1F24FB845967851720FC3045FF0B4@red-msg-12.redmond.corp.microsoft.com 6. SecurityFocus Microsoft Newsletter #88 (Thread) Relevant URL: http://online.securityfocus.com/archive/88/[email protected] 7. Dial up access problem - not a (solution) (Thread) Relevant URL: http://online.securityfocus.com/archive/88/001301c2065d$9bdca8d0$0101a8c0@brucenew 8. How to disable WebDAV (Thread) Relevant URL: http://online.securityfocus.com/archive/88/[email protected] 9. Problem - Using IPSec to secure Windows Messenger Traffic (Thread) Relevant URL: http://online.securityfocus.com/archive/88/[email protected] 10. MS-SQL Blank Password Enumeration (Thread) Relevant URL: http://online.securityfocus.com/archive/88/1961728C54D822408201A22F84D170032FF5D2@USAPGHEVS01.fmkt.freemarkets.com 11. Dial up access problem solution (Thread) Relevant URL: http://online.securityfocus.com/archive/88/[email protected] 12. About ping request? (Thread) Relevant URL: http://online.securityfocus.com/archive/88/[email protected] 13. Why does XP establish HTTP connection when browsing network shares? (Thread) Relevant URL: http://online.securityfocus.com/archive/88/2335F28384FC3241BCB30ADECBD2D490592706@cheeseball.external.osr.com 14. Dialup access controls (Thread) Relevant URL: http://online.securityfocus.com/archive/88/[email protected] 15. Why does XP establish HTTP connection: ADDITIONALLY, (Thread) Relevant URL: http://online.securityfocus.com/archive/88/p04330100b917fcad6b80@[144.96.241.96] 16. Question Regarding Securing Critical Executables (Thread) Relevant URL: http://online.securityfocus.com/archive/88/[email protected] 17. Reinstallation of Hotfixes (Thread) Relevant URL: http://online.securityfocus.com/archive/88/[email protected] IX. SUN FOCUS LIST SUMMARY ---------------------------- 1. xhost (Thread) Relevant URL: http://online.securityfocus.com/archive/92/[email protected] 2. tcp_wrappers x SSH (Thread) Relevant URL: http://online.securityfocus.com/archive/92/[email protected] 3. ANNOUNCE - new SunCluster security BluePrint and JASS (s9 support) released (Thread) Relevant URL: http://online.securityfocus.com/archive/92/[email protected] 4. ssh help (Thread) Relevant URL: http://online.securityfocus.com/archive/92/Pine.LNX.4.21.0205271233260.22543-100000@simpleinfo.simpleinfo.co.uk 5. BSM tool (Thread) Relevant URL: http://online.securityfocus.com/archive/92/[email protected] 6. UseLogin and X11Forwarding (Thread) Relevant URL: http://online.securityfocus.com/archive/92/B6F40DC5FF58A44F8FCB30384BE3D6E4750560@emacil-exch01.emacdigital.com 7. C2 security standards (Thread) Relevant URL: http://online.securityfocus.com/archive/92/867E01F52CF2D311B0D90008C75D6561138CF825@CRMAXSVR02 X. LINUX FOCUS LIST SUMMARY --------------------------- 1. securing nic's for snort (Thread) Relevant URL: http://online.securityfocus.com/archive/91/[email protected] 2. How to get rid of spoofed IP-Address responses (Thread) Relevant URL: http://online.securityfocus.com/archive/91/[email protected] 3. Linux Hardening (Thread) Relevant URL: http://online.securityfocus.com/archive/91/[email protected] 4. irssi backdoor question (Thread) Relevant URL: http://online.securityfocus.com/archive/91/[email protected] 5. What Is hosts2-ns (Thread) Relevant URL: http://online.securityfocus.com/archive/91/[email protected] XI. SPONSOR INFORMATION ----------------------- This issue sponsored by: Aladdin's eToken. Enhance Windows network security with flexible, affordable USB-based strong authentication. -Out-of-the-box support for Microsoft 2000 SmartCard logon and for NT (98, ME) network logon. -Store network passwords on a small, secure USB device, or replace them with random passwords that users never see. -Keep users' private credentials, certificates, keys, and access profiles in a trusted environment. eToken from Aladdin. Strong authentication made simple. http://www.ealaddin.com/etoken/enterprise/datasheets/DS_Win2000_SC_Logon.asp ?cf=tl [email protected] 1-800-562-2543 -------------------------------------------------------------------------------