SecurityFocus Newsletter #149
John Boletta <[email protected]>
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #149
-----------------------------
This newsletter is sponsored by SecurityFocus (www.securityfocus.com)
Attention Non-profits and Universities: Sign-up now for preferred pricing
on the only global early-warning system for cyber attacks - SecurityFocus
ARIS Threat Management System.
Click here for more info
http://www.securityfocus.com/corporate/products/pdpsection.shtml
-------------------------------------------------------------------------------
I. FRONT AND CENTER
1. Developing an Effective Incident Cost Analysis Mechanism
2. Assessing Security Risk, Part One: What is Risk Assessment?
3. The Commoner's Virus
4. Black Hat Briefings & Training
II. BUGTRAQ SUMMARY
1. X Window System Oversized Font Denial Of Service Vulnerability
2. Geeklog pid CGI Variable SQL Injection Vulnerability
3. Geeklog Multiple Cross Site Scripting Vulnerabilities
4. MyHelpDesk HTML Injection Vulnerability
5. MyHelpDesk Cross-Site Scripting Vulnerability
6. MyHelpDesk SQL Injection Vulnerability
7. ZenTrack Ticket.PHP Information Disclosure Vulnerability
8. Geeklog Calendar Event Form Script Injection Vulnerability
9. W-Agora Remote File Include Vulnerability
10. Datalex Bookit! Consumer Plaintext Authentication Credentials...
11. BizDesign ImageFolio Authorized User Web Root Disclosure...
12. Seanox DevWex File Disclosure Vulnerability
13. Seanox DevWex Buffer Overflow Vulnerability
14. LPRNG Remote Print Submission Vulnerability
15. Lokwa BB Multiple SQL Injection Vulnerabilities
16. Belkin F5D5230-4 Router Internal Web Request Vulnerability
17. AlienForm2 Directory Traversal Vulnerability
18. RHMask Local File Overwrite Vulnerability
19. Caldera OpenServer XSCO Color Database File Heap Overflow...
20. LinkSys EtherFast Router Remote Administration Enabled...
21. Pinboard Task List HTML Injection Vulnerability
22. MMFTPD SysLog Format String Vulnerability
23. BBGallery Image Tag HTML Injection Vulnerability
24. CGIScript.net csNews Double URL Encoding Unauthorized...
25. CGIScript.net csNews Header File Type Restriction Bypass...
26. CGIScript.net CSNews Sensitive File Disclosure Vulnerability
27. Apache Tomcat JSP Engine Denial of Service Vulnerability
28. Macromedia JRun JSP Engine Denial Of Service Vulnerability
29. SGI MediaMail Memory Corruption Vulnerability
30. CGIForum Infinite Recursion Denial of Service Vulnerability
31. WebCalendar Include Files Information Disclosure Vulnerability
32. Pine Unix Username Account Information Leakage Vulnerability
33. Multiple Bugzilla Security Vulnerabilities
III. SECURITYFOCUS NEWS ARTICLES
1. Feds, Industry, Battle the Biggest Bug
2. MS security hole extravaganza
3. Hill Eyes Shifting Parts of FBI, CIA
4. Pentagon on track to add biometrics to access card
IV.SECURITYFOCUS TOP 6 TOOLS
1. wicap v0.4
2. JSpamFilter v1.0
3. Vipul's Razor v2.03
4. Echelog v0.6
5. Web shell v1.0
6. PassGuard Framework v0.01a
V. SECURITYJOBS LIST SUMMARY
1. Part-time Weekend opportunities at Ft. Meade, Maryland for
2. Innermail/UNIX/CheckPoint Firewall Postion in Reston VA (Thread)
3. RE-POST - Looking for infosec position (Thread)
4. Regional Sales Manager Guru w/VPN, Security, Networking sales .
5. Seeking Position in Austin, Texas (Thread)
6. RE-POST - Wireless Security Architect - Mobile Technologies - Open
7. Experienced Technical Writer - Buenos Aires; New York (Thread)
8. Repost: Senior Information Security Professional seeking position
9. InfoSec Position Sought (Thread)
10. Information Security Sales - NY Metro (Thread)
11. Enterprise Risk Manager - OH - #701JS (Thread)
12. Opportunity in Maryland for Cleared Computer Forensics Specialist
13. Graduate in Information Security looking for a security
14. Looking for Security position in SF Bay
15. Enterprise Security Compliance Manager (Thread)
16. Authentication Technology Engineer Position in Washington DC
17. Senior Security Administrator Needed (Thread)
VI. INCIDENTS LIST SUMMARY
1. Odd traffic on port 7002 need help figuring it out. (Thread)
2. DSL Modem or Router Cracked? (Thread)
3. remote openssh probe or crack?. (Thread)
4. [logs] nimda web server logs (Thread)
5. Spooky traffic from a loopback address? (Thread)
6. Dial-Up Percentage Abuse (Thread)
7. increase of scans against port 1524 (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
1. ToorCon 2002 Call For Papers (Thread)
2. wireless woes in the triangle and beyond! (Thread)
3. internet explorer view-source url (Thread)
4. A different type of sniffer: Hafiye (Thread)
5. Tools for Wireless fun stuff- detection from the wired side
6. Phone Switches + telephone banking etc (Thread)
7. DNS zone transfer (Thread)
8. PGP spoof decrypted output? (Thread)
9. Disclosure of internal ip address of a Yahoo! Messenger user
10. Coding Conservative CGI Perl (Thread)
11. SCO Openserver Xsco heap overflow. (Thread)
12. Bug in linuxthreads-2.0.6 (Thread)
13. 13 local PoC root exploit programs for Progress Database (Thread)
14. Belkin GCable/DSL router problem with http requests (Thread)
15. VS: DNS zone transfer (Thread)
16. [LoWNOISE] ImageFolio Pro 2.2 (Thread)
17. Security holes in LokwaBB and W-Agora (Thread)
18. Trad.Goth Advisory #1- Multiple Information Leaks in MTA's
19. Hesiod security (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
1. CA certificates on W2k (Thread)
2. O-u-t O-f O-f-f-i-c-e Replies (Thread)
3. Out Of Office Replies (Thread)
4. Changing Terminal Server port in TSAC ActiveX Web Control (Thread)
5. ISA best practice (Thread)
6. Help me and my ISA server (Thread)
7. Help me and my ISA server => ISA best practice (Thread)
8. Windows Reverification (Thread)
9. SecurityFocus Microsoft Newsletter #90 (Thread)
10. MS Exchange Server 5.5/ NT User Name Harvesting ? (Thread)
11. How to determine when a patch was applied ? (Thread)
IX. SUN FOCUS LIST SUMMARY
1. Solaris home directories & Firewall test server?? (Thread)
2. Password Mgmt (Thread)
3. SUN VPN for 10.x.x.x Network (Thread)
4. FYI: Paper on running the BIND DNS Server securely (Thread)
5. ssh help (Thread)
6. looking for package to enhance security on login and dtlogin
7. Administrivia (Thread)
8. looking for package to enhance security on login and dtlogin
9. Where's Sun Security Bulletin #00219? (Thread)
X. LINUX FOCUS LIST SUMMARY
1. Web filtering? (Thread)
2. RE: Web filtering? (Thread)
3. Have I been kitted? (Thread)
4. Time Stamp Server under Linux (Thread)
5. Thanks for the feedback (Thread)
6. Snort vs. other (Thread)
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. Developing an Effective Incident Cost Analysis Mechanism
By David A. Dittrich
One of the challenges facing security and accounting personnel is to
calculate the real costs of security incidents. In this article,
SecurityFocus contributor Dave Dittrich discusses the Incident Cost
Analysis Modeling Project (I-CAMP), an attempt to develop a workable model
for estimating the costs of computer security incidents.
http://online.securityfocus.com/infocus/1592
2. Assessing Internet Security Risk, Part One: What is Risk Assessment?
by Charl Van der Walt
The Internet, like the Wild West of old, is an uncharted new world, full
of fresh and exciting opportunities. However, like the Wild West, the
Internet is also fraught with new threats and obstacles; dangers the
average businessman and home user hasn't even begun to understand. But I
dont have to tell you this. Youve heard that exact speech at just about
every single security conference or seminar youve ever attended, usually
accompanied by a veritable array of slides and graphs demonstrating
exactly how serious the threat is and how many millions of dollars your
company stands to loose. The death toll statistic are then almost always
followed by a sales pitch for some or other product thats supposed to
make it all go away. Yeah right.
http://online.securityfocus.com/infocus/1591
3. The Commoner's Virus
By George Smith
Despite its virulence, the Klez worm is ignored by the newspapers and
dismissed by the digerati. Could the demographics of its victims be a
factor?
http://online.securityfocus.com/columnists/87
4. Black Hat Briefings & Training
Attend Black Hat Briefings & Training, July 29 - August 1, Las Vegas, the
world's premier technical security event! 8 tracks, 12 training sessions,
Richard Clarke keynote, 500 delegates from 30 nations, with a near cult
following of both CSOs and "underground" security experts. See for
yourself what the buzz is all about.
Please visit www.blackhat.com for more information.
II. BUGTRAQ SUMMARY
-------------------
1. X Window System Oversized Font Denial Of Service Vulnerability
BugTraq ID: 4966
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4966
Summary:
A problem has been reported in X Window System, which may be exploited to
crash the browser and cause system-wide instability.
X Window System is prone to a denial of service condition when attempting
to handle an overly large font size (font-size: 1666666px). X Window
System reportedly produces an exception when handling the overly large
font size. Instead of handling the exception gracefully, this may cause X
Window System components to behave unpredictably, potentially requiring X
Window System to be restarted to regain normal functionality. Other
reports indicate that this may crash X outright. The results may vary
depending on the environment.
This is reported to be a problem with xfs (X Font Server) and the libXfont
component.
Remote exploitation of this issue is possible via web clients or other
applications which do not check that the font size is sane before passing
it to the X Window System.
This is reported to affect various X Window System implementations,
including XFree86. Implementations that bundle variations of xfs (X Font
Server) and libXfont are believed to be prone to this issue.
2. Geeklog pid CGI Variable SQL Injection Vulnerability
BugTraq ID: 4968
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4968
Summary:
Geeklog is freely available, open-source weblog software. It is written in
PHP and will run on most Unix and Linux variants, as well as Microsoft
Windows NT/2000. Geeklog is backended by MySQL. Geeklog version 1.3.5 and
prior are subject to SQL injection attacks.
Geeklog does not properly validate externally-supplied input when
including arbitrary characters and additional SQL statements in the 'pid'
variable of some CGI requests. As a result, attackers may be able to
modify SQL queries performed by the application.
This issue has been reported in the comment.php script, and the following
URL has been supplied as an example:
/comment.php?mode=display&sid=foo&pid=PROBLEM_HERE&title=ALPER_Research_Labs
It should be noted that if the 'Magic Quotes' PHP feature is enabled, it
may be difficult for attackers to obtain user information from SQL tables.
This feature may, however, not be sufficient to remove all possibilities
of exploitation.
Exploitation of this vulnerability may result in data corruption,
disclosure of sensitive information and intrusion into the database
server.
3. Geeklog Multiple Cross Site Scripting Vulnerabilities
BugTraq ID: 4969
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4969
Summary:
Geeklog is freely available, open-source weblog software. It is written in
PHP and will run on most Unix and Linux variants, as well as Microsoft
Windows NT/2000. Geeklog is backended by MySQL.
Geeklog does not filter script code from URL parameters, making it prone
to cross-site scripting attacks. Attacker-supplied script code may be
included in a malicious link to the 'index.php' or 'comment.php' script.
The attacker-supplied script code will be executed in the browser of a web
user who visits this link, in the security context of the host running
Geeklog. Such a link might be included in a HTML e-mail or on a malicious
webpage.
This may enable a remote attacker to steal cookie-based authentication
credentials from legitimate users of a host running Geeklog.
This issue has been reported to exist in Geeklog 1.3.5, earlier versions
may also be susceptible to this issue.
4. MyHelpDesk HTML Injection Vulnerability
BugTraq ID: 4967
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4967
Summary:
MyHelpDesk is a web-based helpdesk system written in PHP. It is freely
available and will run on most Unix and Linux variants as well as
Microsoft Windows operating systems.
A vulnerability has been reported for MyHelpDesk (version 20020509 and
earlier) that will allow attackers to inject malicious HTML code.
MyHelpDesk does not properly sanitize HTML tags from form fields.
Attackers may pass arbitrary HTML code through the unsanitized form
fields. The attacker-supplied HTML code will end up being displayed in
MyHelpDesk webpages and will be executed by the web client of users who
visit such pages, in the security context of the site running the
vulnerable software.
The 'Title', 'Description' and 'Update' fields are not properly santized
for malicious HTML input. Additionally, an opportunity for HTML injection
exists when a new ticket is created or edited.
This may potentially be exploited to hijack web content or steal
cookie-based authentication credentials from legitimate users.
5. MyHelpDesk Cross-Site Scripting Vulnerability
BugTraq ID: 4970
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4970
Summary:
MyHelpDesk is a web-based helpdesk system written in PHP. It is freely
available and will run on most Unix and Linux variants as well as
Microsoft Windows operating systems.
It is reported that MyHelpDesk (version 20020509 and earlier) are
vulnerable to cross site scripting attacks.
The vulnerability is present in the 'index.php' script. MyHelpDesk does
not properly sanitize HTML from the 'id' CGI parameter prior to output.
Attackers may exploit this vulnerability by constructing a link to a
vulnerable scripts, passing malicious HTML code as a value for unsanitized
CGI parameters. If the link is sent to a MyHelpDesk user and clicked on,
the attacker-supplied HTML code will run in the context of the site
running the vulnerable software.
This issue may be exploited to steal cookie-based authentication
credentials from legitimate users of MyHelpDesk.
6. MyHelpDesk SQL Injection Vulnerability
BugTraq ID: 4971
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4971
Summary:
MyHelpDesk is a web-based helpdesk system written in PHP. It is freely
available and will run on most Unix and Linux variants as well as
Microsoft Windows operating systems. MyHelpDesk is back-ended by a MySQL
database.
It is reported that MyHelpDesk (version 20020509 and earlier) are
vulnerable to an SQL injection attack.
A SQL injection vulnerability has been reported within the index.php
script. Data supplied by the remote user, via CGI parameters, is used
directly as part of SQL statements. As input sanitization is not properly
performed, it is possible to modify the logic of a SQL query.
Cleverly executed SQL injection attacks may potentially allow a malicious
party to view or modify sensitive information. Additionally, an attacker
might potentially use this issue to exploit any existing vulnerabilities
in the underlying database.
7. ZenTrack Ticket.PHP Information Disclosure Vulnerability
BugTraq ID: 4973
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4973
Summary:
ZenTrack is designed to be a complete project management, bug tracking,
and ticketing system. It is implemented in PHP and is able to run on Unix
and Linux variants as well as Windows operating systems.
A path disclosure vulnerability has been reported in ZenTrack version
2.0.3 and earlier.
By requesting a ticket that doesn't exist, an attacker is able to cause
ZenTrack to reveal the absolute path to the web root in the error output.
It may also cause ZenTrack to reveal other sensitive information to the
attacker.
This information may be used by attackers to mount further attacks against
a vulnerable system.
8. Geeklog Calendar Event Form Script Injection Vulnerability
BugTraq ID: 4974
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4974
Summary:
Geeklog is freely available, open-source weblog software. It is written in
PHP and will run on most Unix and Linux variants, as well as Microsoft
Windows NT/2000. Geeklog is backended by MySQL.
Geeklog does not sufficiently sanitize script code from form fields,
making it prone to script injection attacks.
Attacker-supplied script code included in the Link field of a new Calendar
Event submission form, may potentially end up in webpages generated by
Geeklog and will execute in the browser of a user who views such pages, in
the security context of the website.
It should be noted that new Calendar Event submissions are sent to the web
site administrator for approval.
This issue may potentially be exploited to hijack web content or steal
cookie-based authentication credentials from legitimate users.
9. W-Agora Remote File Include Vulnerability
BugTraq ID: 4977
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4977
Summary:
W-Agora is a web publishing and forum software. It is implemented in PHP
and will run on most Linux and Unix variants, in addition to Microsoft
Windows operating systems.
W-Agora is prone to an issue which may allow an attacker to include
arbitrary files located on a remote server. In particular, the 'inc_dir'
variable found in a number of W-Agora scripts defines the path to the
configuration file. It is possible, under some configurations, for an
attacker to specify an arbitrary value for the location of the
configuration file which points to a file on a remote server.
If the included file is a PHP script, this may allow for execution of
arbitrary attacker-supplied code.
Successful exploitation depends partly on the configuration of PHP on the
host running the vulnerable software. If 'all_url_fopen' is set to 'off'
then exploitation of this issue may be limited.
10. Datalex Bookit! Consumer Plaintext Authentication Credentials Vulnerability
BugTraq ID: 4972
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4972
Summary:
Datalex Bookit! Consumer is web-based software for provided travel booking
services. It will run on most Unix and Linux variants in addition to
Microsoft Windows operating systems.
Datalex Bookit! Consumer may be configured to remember authentication
credentials. If a user chooses to have their authentication credentials
'remembered', then the credentials will be stored in a cookie. However,
these credentials are stored in plaintext. This becomes an issue if the
authentication credentials ever become exposed to an attacker.
It should be also noted that in some cases form data is posted using the
GET method. As a result, sensitive information (including plaintext
authentication credentials) is sent in CGI parameters.
A number of situations exist where an attacker may be able to gain access
to the plaintext credentials. For example, the authentication credentials
may be cached on a proxy server. Also, this may be exploited by an
attacker in an appropriate position to sniff network traffic between a
user's web client and the server running the software. Lastly,
cookie-based authentication credentials may potentially be exposed via
cross-site scripting or HTML injection attacks.
11. BizDesign ImageFolio Authorized User Web Root Disclosure Vulnerability
BugTraq ID: 4976
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4976
Summary:
ImageFolio Pro is a web based image archive package, including
administrative support through a web interface. A vulnerability exists in
versions of ImageFolio Pro prior to 2.27.
A remote user with sufficient access to the web administration page may
create a new image category. It is possible for a malicious user to force
this process to fail through the inclusion of "../" character strings in
the supplied file name. When this operation fails, a displayed error
message will include the full path to the attempted file.
Under most configurations, this path will include information on the web
root. An attacker may be able to use this information to launch further,
intelligent attacks against the server.
The remote user must have valid access to the administration page, and
must have additional permissions to create a new category.
12. Seanox DevWex File Disclosure Vulnerability
BugTraq ID: 4978
Remote: Yes
Date Published: Jun 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4978
Summary:
Seanox DevWex is a webserver. It is available as a stand-alone Microsoft
Windows binary or as a Java application.
The Seanox DevWex Windows binary version is prone to an issue which may
cause arbitrary web-readable files to be disclosed to remote attackers.
This problem occurs because DevWex does not sufficiently filter '..\'
sequences from web requests. As a result, attackers may break out of the
webroot directory by making a malicious request containing '..\'
sequences. Files targetted by the attacker may be disclosed in this
manner.
13. Seanox DevWex Buffer Overflow Vulnerability
BugTraq ID: 4979
Remote: Yes
Date Published: Jun 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4979
Summary:
Seanox DevWex is a webserver. It is available as a stand-alone Microsoft
Windows binary or as a Java application.
The Seanox DevWex Windows binary version is prone to a buffer overflow
condition. This condition is due to insufficient bounds checking on the
length of a HTTP GET request. Excessively long requests (258383+
characters) will trigger the condition.
This may be potentially exploited to execute arbitrary attacker-supplied
instructions with the privileges of the webserver process (normally
SYSTEM). Additionally, remote attackers may exploit this to cause the
server to crash.
14. LPRNG Remote Print Submission Vulnerability
BugTraq ID: 4980
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4980
Summary:
The LPRng software is an enhanced, extended, and portable implementation
of the Berkeley LPR print spooler functionality.
Default configurations of LPRng accept all remote print submissions to the
print queue. A malicious attacker may be able to submit many print
requests to the existing print queue. It may be possible to exhaust
resources and cause a denial of service condition.
15. Lokwa BB Multiple SQL Injection Vulnerabilities
BugTraq ID: 4981
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4981
Summary:
Lokwa BB is a freely available message board forum. Versions of Lokwa are
subject to SQL injection attacks.
Lokwa BB does not properly validate externally-supplied input when
including arbitrary characters and additional SQL statements in an SQL
query. As a result, attackers may be able to modify SQL queries performed
by the application. The disclosure of sensitive information may be
possible.
Under some circumstances, reports indicate that it may be possible to
access and reply to arbitrary private messages.
This issue has been reported in the 'member.php', 'misc.php' and 'pm.php'
scripts. The 'pm.php' script can be used to disclose and reply to
arbitrary private messages. 'misc.php' and 'member.php can assist an
attacker in gathering user information such as, identifying which users
are administrators and which users have a specified password.
16. Belkin F5D5230-4 Router Internal Web Request Vulnerability
BugTraq ID: 4982
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4982
Summary:
The Belkin F5D5230-4 4-Port Cable/DSL Gateway Router is a hardware router
for a home or small office.
As a feature of the device, it is possible to designate a server on the
internal network which will receive incoming traffic for a given port. For
example, the internal web server may receive all port 80 traffic. A
potential issue has been reported in this feature.
Reportedly, a malicious internal attacker may take advantage of this
feature. If the attacker makes a request to the web server, it will appear
to originate from the router's external interface. The web server will log
the request as originating from this IP address.
A local attacker may be able to take advantage of this vulnerability to
launch attacks against the web server. If detected, the attacks will not
be traced back to the attacker.
17. AlienForm2 Directory Traversal Vulnerability
BugTraq ID: 4983
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4983
Summary:
AlienForm2 is an interface to the email gateway written in Perl and is
maintained by Jon Hedley.
Due to a reported directory traversal issue, it is possible for users to
access arbitrary files residing on a host and potentially modify file
contents.
Reportedly, in an attempt to sanitize user supplied input, some
questionable characters are stripped from incoming HTTP requests. As a
result, the character string '.|.' is translated into the string '..'.
It has been reported that it is possible to exploit this vulnerability to
access arbitrary files on the server through a directory traversal attack.
This may be accomplished by a GET request including the string '.|.%2F'
repeatedly.
It may be possible to use this vulnerability in conjunction with a feature
which forwards user supplied data to a file. In this case, it may be
possible for a remote user to append arbitrary data to an arbitrary system
file, with the permissions of the script user.
Successful exploitation of this vulnerability could reveal sensitive data
which may be used to assist in further attacks against the host.
18. RHMask Local File Overwrite Vulnerability
BugTraq ID: 4984
Remote: No
Date Published: Jun 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4984
Summary:
rhmask is a is a Red Hat Linux utility for distributing files as masks
against other files.
rhmask does not sufficiently validate the output filename supplied in mask
files. Attackers may potentially exploit this issue to create a mask file
which may cause other system files to be overwritten via symlinks when the
mask is applied. Under normal circumstances, the user is prompted with
the name of the target file. However, rhmask does not check if the target
filename is a symbolic link.
rhmask is not installed by default in recent versions of Red Hat Linux.
19. Caldera OpenServer XSCO Color Database File Heap Overflow Vulnerability
BugTraq ID: 4985
Remote: No
Date Published: Jun 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4985
Summary:
OpenServer is commercial Unix operating system originally developed by
SCO, and distributed by Caldera.
A problem in the OpenServer windowing software package could make it
possible for a local user to gain elevated privileges. The problem is in
the handling of some commandline options by the Xsco program.
Xsco is the X Window System server binary distributed with OpenServer.
It is on top of this program that desktop environments distributed with
OpenServer run. Xsco is by default installed as a setuid root executable.
The Xsco commandline option of -co is used to load a color database file.
It may be possible for a local user to gain elevated privileges. When
Xsco is executed, and an excessively long argument is supplied to the -co
flag, a heap overflow occurs. This problem could allow a local user to
supply a maliciously formatted string with the -co option that could
result in the execution of arbitrary code, and elevated privileges.
The overflow has been reproduced when 9000 or more characters are supplied
as the argument to the -co option. This problem could result in a local
user executing arbitrary code with the group privileges of root, and
gaining local administrative access.
20. LinkSys EtherFast Router Remote Administration Enabled Vulnerability
BugTraq ID: 4987
Remote: Yes
Date Published: Jun 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4987
Summary:
Linksys EtherFast routers are small four port routers designed to optimize
the use of DSL or Cable connections. EtherFast routers provide advanced
features such as Network Address Translation, and DHCP support.
A vulnerability has been introduced into the current version of the
firmware (1.42.7) released May 1, 2002. Reportedly, the firmware does not
respect existing rules that deny remote administration of the router. The
current version of the firmware opens TCP port 5678 for remote
administration.
The firmware opens up a TCP port for remote administration even though
"Block WAN" and "Remote Admin" options are disabled.
An attacker may be able to exploit this vulnerability to mount further
attacks against a vulnerable device.
Earlier versions of the firmware are not affected by this issue.
21. Pinboard Task List HTML Injection Vulnerability
BugTraq ID: 4988
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4988
Summary:
Pinboard is a web-based task list manager written in PHP.
Pinboard does not sufficiently filter HTML tags from form fields. This
may allow users of Pinboard to inject arbitrary HTML and script code into
tasklists. HTML and script code injected in this manner will be executed
in the browser of a web user who views the task list, in the context of
the site running the task list software.
This may enable malicious users to hijack web content or potentially steal
cookie-based authentication credentials.
22. MMFTPD SysLog Format String Vulnerability
BugTraq ID: 4990
Remote: Yes
Date Published: Jun 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4990
Summary:
mmftpd is a freely available, open source FTP server for Linux operating
systems.
A problem with the daemon could make it possible for a remote attacker to
execute arbitrary code.
Due to improper use of the syslog call, a problem exists which could make
the execution of arbitrary code possible. A syslog call in the program
which logs user-supplied information could be exploited to print to
specified places in memory, including potentially overwriting the return
address of a function and executing arbitrary code.
This problem could allow an attacker to send a malicious format string to
the syslog function of the program. The malicious format string, and any
code supplied with it, would be executed with the privileges of the mmftpd
user.
23. BBGallery Image Tag HTML Injection Vulnerability
BugTraq ID: 4992
Remote: Yes
Date Published: Jun 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4992
Summary:
BBGallery is a Perl script which generates HTML files from jpeg images,
the thumbnail images make up an image gallery which can be viewed in any
web browser. BBGallery is maintained by Bodo Bauer.
Versions of BBGallery prior to 1.1.0 does not filter HTML from image tags.
This may allow an attacker to inject arbitrary script code in BBGallery
images. Injected script code will be executed in the browser of an
arbitrary web user who views the malicious image, in the context of the
website running BBGallery.
This may potentially be exploited to hijack web content or steal
cookie-based authentication credentials from legitimate users.
24. CGIScript.net csNews Double URL Encoding Unauthorized Administrative Access Vulnerability
BugTraq ID: 4993
Remote: Yes
Date Published: Jun 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4993
Summary:
csNews is a script for managing news items on a website. It will run on
most Unix and Linux variants, as well as Microsoft Windows operating
systems.
csNews may be configured through a web interface. Different users may be
defined with varying levels of access. Users with "public" access may
modify page content, while admin users are able to configure the script.
Reportedly, users with public access may view and modify some
configuration pages normally restricted to admin level users. This may be
accomplished by double url encoding metacharacters in the database name
provided as a CGI parameter.
Users will be able to view and modify options on the 'Advanced Settings'
page, as well as view 'Admin Options'.
This may be exploited by submitting URLs with database names such as
default%2edb.
25. CGIScript.net csNews Header File Type Restriction Bypass Vulnerability
BugTraq ID: 4994
Remote: Yes
Date Published: Jun 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4994
Summary:
csNews is a script for managing news items on a website. It will run on
most Unix and Linux variants, as well as Microsoft Windows operating
systems.
It is possible for an administrator to define a header and footer
displayed by csNews. Normally this is restricted to txt, html and htm
files. However, it is possible for a malicious adminstrator to bypass this
restriction and specify an arbitrary file type.
Reportedly, this may be done simply by submitting a manually constructed
HTTP request with the new configuration information.
Exploitation of this vulnerability allows an attacker to display any
system file as a header or footer. An attacker may, for example, specify a
CGI script file which include authentication information.
The ability to exploit this vulnerability may only require "public" access
to csNews if used in conjunction with issues discussed in BID 4993.
26. CGIScript.net CSNews Sensitive File Disclosure Vulnerability
BugTraq ID: 4991
Remote: Yes
Date Published: Jun 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4991
Summary:
csNews is a script for managing news items on a website. It will run on
most Unix and Linux variants, as well as Microsoft Windows operating
systems.
A number of sensitive csNews files may be accessed by unauthorized users.
Database files may be accessed in this manner, potentially exposing
database authentication credentials and other sensitive information.
Metacharacters in requests for database files must be double URL encoded.
For example:
default%2edb
27. Apache Tomcat JSP Engine Denial of Service Vulnerability
BugTraq ID: 4995
Remote: Yes
Date Published: Jun 12 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4995
Summary:
Apache Tomcat is a freely available, open source servlet container that is
used to display and interpret Java Servlet and JavaServer Pages (JSP)
technologies. Apache Tomcat is available for Unix and Linux variants as
well as the Microsoft Windows operating environments.
A vulnerability has been reported in Apache Tomcat for Windows that
results in a denial of service condition. The vulnerability occurs when
Tomcat encounters a malicious JSP page.
The following snippet of code is reported to crash the Tomcat JSP engine:
new WPrinterJob().pageSetup(null,null);
An attacker may exploit this vulnerability by creating a malicious page on
vulnerable systems and by requesting the page from the server. This would
result in the Tomcat JSP engine to attempt to interpret the page and
subsequently crash leading to the denial of service condition.
28. Macromedia JRun JSP Engine Denial Of Service Vulnerability
BugTraq ID: 4997
Remote: Yes
Date Published: Jun 12 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4997
Summary:
Macromedia JRun is a J2EE (Java 2 Platform Enterprise Edition) application
server for use with IIS (Internet Information Server) 4/5 on the Microsoft
Windows operating systems.
A vulnerability has been reported in Macromedia JRun for Windows that
results in a denial of service condition. The vulnerability occurs when
JRun encounters a malicious JSP page.
The following snippet of code is reported to crash the JRun JSP engine:
new WPrinterJob().pageSetup(null,null);
An attacker may exploit this vulnerability by creating a malicious page on
vulnerable systems and by requesting the page from the server. This would
result in the JRun JSP engine to attempt to interpret the page and
subsequently crash leading to the denial of service condition.
29. SGI MediaMail Memory Corruption Vulnerability
BugTraq ID: 4959
Remote: No
Date Published: Jun 07 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4959
Summary:
MediaMail is a mail application distributed with SGI IRIX.
Problems with MediaMail have been reported that could lead to a local user
gaining elevated privileges.
It has been reported by SGI that certain command line argument passed to
MediaMail may result in core dumps. These core dumps are due to memory
corruption, and are likely exploitable. The MediaMail and MediaMail Pro
applications are typically installed setgid mail. If attackers
successfuly exploit MediaMail, they may gain these privileges.
This issue is likely either a buffer overflow or format string
vulnerability. As there are no details available, the method of
exploitation of these vulnerabilities is uncertain. In the case of a
buffer overflow vulnerability, it is likely that an attacker will be able
to execute code by passing an exceptionally long string and
attacker-supplied instructions to one or several of the arguments handled
by MediaMail. In the case of a format string vulnerability, an attacker
will likely pass a malicious format string and attacker-supplied
instructions with one or several of the arguments handled by MediaMail.
It should be noted that MediaMail Pro is also affected by this
vulnerability. An attacker gaining an effective gid of mail will be able
to read other users mail.
30. CGIForum Infinite Recursion Denial of Service Vulnerability
BugTraq ID: 4960
Remote: Yes
Date Published: Jun 07 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4960
Summary:
CGIForum is a freely available cgi script from Markus Triska which is
designed to facilitate web-based threaded discussion forums.
CGIForum fails to properly handle malformed user supplied data. Under some
conditions, an infinite recursion may occur, consuming system resources.
The server may stop responding to new requests, resulting in a denial of
service condition.
Versions of CGIForum prior to 1.06 are susceptible to this issue.
A restart of the service may be required in order to regain normal
functionality.
31. WebCalendar Include Files Information Disclosure Vulnerability
BugTraq ID: 4961
Remote: Yes
Date Published: Jun 07 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4961
Summary:
WebCalendar is a web application used to maintain a calendar for a single
or multiple users. It is implemented in PHP, and should function under any
system supporting the language, including Windows and Linux.
A vulnerability has been reported in WebCalendar that may allow attackers
to view potentially sensitive information.
The vulnerability exists in the naming convention of include files.
Typically include files end with an extension of '.inc' so that they are
easily distinguishable from other files. However, these files aren't
parsed as PHP code by the PHP interpreter and an attacker can easily get
access to the source code. This is a real problem when sensitive
configuration data (e.g database credentials) is placed in these PHP
files.
This information can then be used to mount further attacks against a
vulnerable system.
32. Pine Unix Username Account Information Leakage Vulnerability
BugTraq ID: 4963
Remote: Yes
Date Published: Jun 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4963
Summary:
Pine is a freely available, open source mail user agent (MUA). It is
available for most Unix and Linux operating systems.
A problem with pine may make it possible for remote users to gain
information about accounts on a system.
Pine allows users to specify their own From: field. This feature can be
used to mask individual user accounts in such a scenario as a role email
account. This feature can also be used to obscure user accounts to
prevent third parties from gaining information about local system
accounts.
Pine will leak the Unix username of the original sender. When a mail is
sent, pine adds headers to the email in the form of either the "Sender:"
field or the "X-X-Sender:" field. This could allow a remote attacker to
discover the username of the user sending an email, and could be used in
an information gathering attack.
33. Multiple Bugzilla Security Vulnerabilities
BugTraq ID: 4964
Remote: Yes
Date Published: Jun 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4964
Summary:
Bugzilla is a freely available, open source bug tracking software package.
It is available for Linux, Unix, and Microsoft Operating Systems.
Several problems have been discovered in Bugzilla that may allow remote
users to gain information through information leakage, or unauthorized
access to Bugzilla.
The queryhelp.cgi script distributed with Bugzilla could allow remote
users to gain access to information products that set as confidential in
the Bugzilla database.
An attacker may be able to hijack user sessions provided the attacker has
reverse resolution authority for an IP address, and is able to steal a
user's authentication cookie.
When a directory does not exist, Mozilla will attempt to create it.
However, by default, the directory is usually created with world-writeable
permissions.
It is possible for any user with permissions to edit any other user's
details to delete any other user of the board through the edituser.cgi
script.
The Real Names field does not filter HTML. An attacker may be able to
input malicious HTML in the field, resulting in a cross-site scripting
attack.
When performing a mass change, the groupset of all bugs are set to the
groupset of the first bug in the mass change sequence.
Bugzilla did not handle encoding from some browsers, which could lead to
unintended consequences, such as setting private or confidential
information to a publicly displayed mode.
The syncing of the shadow database was done insecurely. Under some
circumstances, this could output sensitive data to a user of Bugzilla at
random.
III. SECURITYFOCUS NEWS AND COMMENTARY
------------------------------------------
1. Feds, Industry, Battle the Biggest Bug
By Kevin Poulsen
A security hole in implementations of Abstract Syntax Notation One may
threaten some of America's most crucial networks. Relax, the President's
been briefed.
http://online.securityfocus.com/news/474
2. MS security hole extravaganza
By Thomas C. Greene, The Register
We've got a treat here; it seems MS has been sitting on a number of
security holes which it's decided to dump on us all at once. So, what do
you want to patch today?
http://online.securityfocus.com/news/479
3. Hill Eyes Shifting Parts of FBI, CIA
By Dan Eggen, Washington Post
Congressional leaders are strongly considering granting to a new
Department of Homeland Security authority over parts of the CIA and the
FBI, a complex and controversial restructuring of the nation's
intelligence apparatus that President Bush opposes.
http://online.securityfocus.com/news/478
4. Pentagon on track to add biometrics to access card
By William Jackson, Government Computer News
The Defense Department is pursuing an aggressive timetable for
incorporating biometric identifiers in its Common Access smart card.
http://online.securityfocus.com/news/477
IV.SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. wicap v0.4
by Brian Caswell
Relevant URL:
http://www.snort.org/~bmc/software/wicap/
Platforms: FreeBSD, OpenBSD, POSIX, Solaris, SunOS
Summary:
wicap is a captive portal that is easy to set up and supports OpenBSD.
2. JSpamFilter v1.0
by Daryl Banttari
Relevant URL:
http://www.darylb.net/JSpamFilter/
Platforms: Os Independent
Summary:
JSpamfilter is software that intercepts connections from remote Internet
mail servers before they can connect to your mail server. The originating
IP address for the inbound connection is then checked against one of the
DNS-based SPAM Blackhole (DNSBL) lists maintained on the Internet by
various organizations. If the check passes, the connection is allowed to
proceed to your mail server; if it fails, the connection is told that the
mail server is unavailable, then dropped.
3. Vipul's Razor v2.03
by hackworth
Relevant URL:
http://razor.sourceforge.net
Platforms: Os Independent
Summary:
Vipul's Razor is a distributed, collaborative, spam detection and
filtering network that exploits the broadcast characteristic of spam
distribution to limit its propagation. The primary focus of the system is
to identify and disable an email spam before its injection and processing
is complete. Razor establishes a distributed and constantly updating
catalogue of spam in propagation. This catalogue is used by clients to
filter out known spam.
4. Echelog v0.6
by Kamil Toman
Relevant URL:
http://echelog.sourceforge.net/
Platforms: FreeBSD, Linux, OpenBSD, POSIX, Solaris, SunOS
Summary:
Echelog is a distributed system consisting of one or more agents and one
or more servers. Agents, distributed on computers over network, are
monitoring the network's and hosts' state. Gained information is sent
using SSL protocol to a safe server where the data is archived.
5. Web shell v1.0
by Alex Dyatlov [email protected]
Relevant URL:
http://dyatlov.ru
Platforms: UNIX
Summary:
Webshell is a remote UNIX shell that works via HTTP. The client script
provides a shell-like prompt, encapsulating user commands into HTTP POST
requests and sending them to the server script. The server script extracts
and executes commands and returns STDOUT and STDERR output. Features
include command line history support, file upload/download, and it can
work through an HTTP proxy server.
6. PassGuard Framework v0.01a
by RUAUDEL Frédéric
Relevant URL:
http://passguard.sourceforge.net
Platforms: Linux, POSIX, UNIX
Summary:
PassGuard Framework is a library for the PassGuard suite of programs that
is used to manage numerous passwords in an encrypted file. Encryption is
managed with a plugin system, which allows easy support for any kind of
encrypted file.
V. SECURITY JOBS SUMMARY
------------------------
1. Part-time Weekend opportunities at Ft. Meade, Maryland for CLEARED professional (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
2. Innermail/UNIX/CheckPoint Firewall Postion in Reston VA (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
3. RE-POST - Looking for infosec position (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
4. Regional Sales Manager Guru w/VPN, Security, Networking sales . (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
5. Seeking Position in Austin, Texas (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
6. RE-POST - Wireless Security Architect - Mobile Technologies - Open Position (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
7. Experienced Technical Writer - Buenos Aires; New York (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
8. Repost: Senior Information Security Professional seeking position (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
9. InfoSec Position Sought (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/003401c210de$e54602b0$52521342@qapmoc6g6vahpi
10. Information Security Sales - NY Metro (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
11. Enterprise Risk Manager - OH - #701JS (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
12. Opportunity in Maryland for Cleared Computer Forensics Specialist (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
13. Graduate in Information Security looking for a security consultancy post (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
14. Looking for Security position in SF Bay Area(South Bay) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
15. Enterprise Security Compliance Manager (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
16. Authentication Technology Engineer Position in Washington DC (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
17. Senior Security Administrator Needed (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/5544986F9407D611A5900008C70964061A6252@EXCHANGE
VI. INCIDENTS LIST SUMMARY
-------------------------
1. Odd traffic on port 7002 need help figuring it out. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
2. DSL Modem or Router Cracked? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
3. remote openssh probe or crack?. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/20020613212334.D2CA44DCB@rome
4. [logs] nimda web server logs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
5. Spooky traffic from a loopback address? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
6. Dial-Up Percentage Abuse (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/005b01c20e54$a36df7d0$030010ac@purity
7. increase of scans against port 1524 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. ToorCon 2002 Call For Papers (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/B92E6DB6.A1FC%[email protected]
2. wireless woes in the triangle and beyond! (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
3. internet explorer view-source url (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/1023915657.26847.4.camel@woody
4. A different type of sniffer: Hafiye (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
5. Tools for Wireless fun stuff- detection from the wired side (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
6. Phone Switches + telephone banking etc (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
7. DNS zone transfer (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
8. PGP spoof decrypted output? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/009301c21149$65bc4fc0$943fddc8@home
9. Disclosure of internal ip address of a Yahoo! Messenger user (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
10. Coding Conservative CGI Perl (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
11. SCO Openserver Xsco heap overflow. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
12. Bug in linuxthreads-2.0.6 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
13. 13 local PoC root exploit programs for Progress Database (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
14. Belkin GCable/DSL router problem with http requests (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
15. VS: DNS zone transfer (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
16. [LoWNOISE] ImageFolio Pro 2.2 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
17. Security holes in LokwaBB and W-Agora (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
18. Trad.Goth Advisory #1- Multiple Information Leaks in MTA's (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/003701c20e07$fc752210$1e01320a@drizzt
19. Hesiod security (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. CA certificates on W2k (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/65590D572241D311AB160090278618A0D4D610@EIG_MAIL
2. O-u-t O-f O-f-f-i-c-e Replies (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
3. Out Of Office Replies (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
4. Changing Terminal Server port in TSAC ActiveX Web Control (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
5. ISA best practice (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
6. Help me and my ISA server (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/9D884881F5E1F24FB845967851720FC302C8DECA@red-msg-12.redmond.corp.microsoft.com
7. Help me and my ISA server => ISA best practice (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
8. Windows Reverification (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
9. SecurityFocus Microsoft Newsletter #90 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
10. MS Exchange Server 5.5/ NT User Name Harvesting ? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
11. How to determine when a patch was applied ? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
IX. SUN FOCUS LIST SUMMARY
----------------------------
1. Solaris home directories & Firewall test server?? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
2. Password Mgmt (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
3. SUN VPN for 10.x.x.x Network (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/3F237B2CDEE8D51180690002A5AD752E01CEA9D2@beavertn-svr-75.nike.com
4. FYI: Paper on running the BIND DNS Server securely (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
5. ssh help (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
6. looking for package to enhance security on login and dtlogin (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
7. Administrivia (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
8. looking for package to enhance security on login and dtlogin (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
9. Where's Sun Security Bulletin #00219? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
X. LINUX FOCUS LIST SUMMARY
---------------------------
1. Web filtering? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/[email protected]
2. RE: Web filtering? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/[email protected]
3. Have I been kitted? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/[email protected]
4. Time Stamp Server under Linux (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/[email protected]
5. Thanks for the feedback (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/[email protected]
6. Snort vs. other (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/[email protected]
XI. SPONSOR INFORMATION
-----------------------
This newsletter is sponsored by SecurityFocus (www.securityfocus.com)
Attention Non-profits and Universities: Sign-up now for preferred pricing
on the only global early-warning system for cyber attacks - SecurityFocus
ARIS Threat Management System.
Click here for more info
http://www.securityfocus.com/corporate/products/pdpsection.shtml
-------------------------------------------------------------------------------