SecurityFocus Newsletter #265
Peter Laborge <[email protected]> 8 Sep 2004 15:27:38 -0000
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #265
------------------------------
This issue sponsored by: SPI Dynamics
New Webcast: "The Hacking Evolution: New Trends in Exploits and
Vulnerabilities" Watch as Caleb Sima, CTO & Founder of SPI Dynamics shows
you how to defend against these new attacks in a FREE Web Cast that will
cover real examples of recent hacking methods such as: Google Hacking, SQL
Injection and Cell Phone Attacks.
http://www.securityfocus.com/sponsor/SPIDynamics_sf-news_040907
------------------------------------------------------------------------
I. FRONT AND CENTER
1. Metasploit Framework, Part 2
2. Feast of Egos
3. Simple and Secure isn't so Simple
II. BUGTRAQ SUMMARY
1. Ipswitch WS_FTP Server CD Command Malformed File Path Remote...
2. JazerNorth Scout Tracker Multiple Unspecified Vulnerabilitie...
3. WFTPD Server MLST Argument Remote Denial Of Service Vulnerab...
4. Symantec PowerQuest DeployCenter Boot Disk Plaintext Passwor...
5. Titan FTP Server CWD Command Remote Heap Overflow Vulnerabil...
6. ACLogic CesarFTP Buffer Overflow Vulnerability
7. Xedus Web Server Multiple Vulnerabilities
8. D-Link Securicam Network DCS-900 Internet Camera Remote Conf...
9. Web Animations Password Protect Multiple Input Validation Vu...
10. PvPGN Remote Buffer Overflow Vulnerability
11. CDRTools RSH Environment Variable Privilege Escalation Vulne...
12. Diebold GEMS Central Tabulator Vote Database Integrity Compr...
13. Bsdmainutils Calendar Information Disclosure Vulnerability
14. MIT Kerberos 5 Multiple Double-Free Vulnerabilities
15. MIT Kerberos 5 ASN.1 Decoder Denial Of Service Vulnerability
16. PHPScheduleIt HTML Injection Vulnerability
17. SuSE Linux PTMX Unspecified Local Denial Of Service Vulnerab...
18. pLog User Registration HTML Injection Vulnerability
19. Comersus Cart HTTP Response Splitting Vulnerability
20. IMLib/IMLib2 Multiple BMP Image Decoding Buffer Overflow Vul...
21. Cerbère Proxy Server Long Host Header Field Remote Denial of...
22. Newtelligence DasBlog Request Log HTML Injection Vulnerabili...
23. TorrentTrader Download.PHP SQL Injection Vulnerability
24. PHPWebSite Multiple Input Validation Vulnerabilities
25. IBM DB2 Universal Database Multiple Remote Buffer Overflow A...
26. Opera Web Browser Empty Embedded Object JavaScript Denial Of...
27. Oracle 10g Database DBMS_SCHEDULER Remote Command Execution ...
28. WinZip Multiple Unspecified Buffer Overflow Vulnerabilities
29. LHA Multiple Code Execution Vulnerabilities
30. Apache mod_ssl Denial Of Service Vulnerability
31. SiteCubed MailWorks Professional Authentication Bypass Vulne...
32. Kerio Personal Firewall Application Security Bypass Vulnerab...
33. CuteNews 'index.php' Cross-Site Scripting Vulnerability
34. Squid Proxy NTLM Authentication Denial Of Service Vulnerabil...
35. Oracle Database Server ctxsys.driload Access Validation Vuln...
36. Oracle Database Server dbms_system.ksdwrt Remote Buffer Over...
37. Altnet ADM ActiveX Control Remote Buffer Overflow Vulnerabil...
38. Dynalink RTA 230 ADSL Router Default Backdoor Account Vulner...
39. PhpMyBackupPro Unspecified Potential Input Validation Vulner...
40. QNX PPPoEd Multiple Local Buffer Overrun Vulnerabilities
41. QNX PPPoEd Path Environment Variable Local Command Execution...
42. Ipswitch IMail Server Multiple Buffer Overflow Denial Of Ser...
43. Nullsoft Winamp ActiveX Control Remote Buffer Overflow Vulne...
44. Engenio Storage Controller Remote Denial Of Service Vulnerab...
45. Ipswitch WhatsUp Gold Notification Instance Name Remote Buff...
46. Ipswitch WhatsUp Gold prn.htm Denial Of Service Vulnerabilit...
47. Keene Digital Media Server Cross-Site Scripting Vulnerabilit...
48. Keene Digital Media Server Admin Authentication Bypass Vulne...
III. SECURITYFOCUS NEWS ARTICLES
1. Plea deal in 'war spamming' prosecution
2. Appeals court slams garage door DMCA claim
3. Website offers Caller I.D. falsification service
4. Nevadans to become first to use touch-screen voting that pro...
5. Caller ID spoofing service for sale
6. Old PCs are goldmine for data thieves
IV. SECURITYFOCUS TOP 6 TOOLS
1. CifsPwScanner 1.0.5
2. Attack Tool Kit (ATK) 2.0
3. FREEping - Server pinging 1.0
4. Softros LAN Messenger 3.4
5. Healthmonitor 1.9
6. THC-Hydra v4.3
V. SECURITYJOBS LIST SUMMARY
1. [SJ-JOB] Sr. Security Analyst, D.C., US (Thread)
2. [SJ-JOB] Developer, Dusseldorf, DE (Thread)
3. [SJ-JOB] Manager, Information Security, San Marcos, ... (Thread)
4. [SJ-JOB] Security Architect, Boston, US (Thread)
5. [SJ-JOB] Sales Engineer, Chicago, US (Thread)
6. [SJ-JOB] Application Security Engineer, London and S... (Thread)
7. [SJ-JOB] Security Engineer, Palo Alto, US (Thread)
8. [SJ-JOB] VP of Regional Sales, Munich, DE (Thread)
9. [SJ-JOB] Sr. Security Analyst, Boise, US (Thread)
10. [SJ-JOB] Account Manager, London, GB (Thread)
11. [SJ-JOB] Application Security Engineer, New York, US (Thread)
12. [SJ-JOB] VP of Regional Sales, London, NL (Thread)
13. [SJ-JOB] Customer Support, San Jose, US (Thread)
14. [SJ-JOB] Security Architect, Kirkland, US (Thread)
15. [SJ-JOB] Manager, Information Security, Boston, US (Thread)
16. [SJ-JOB] Security Architect, NY, US (Thread)
17. [SJ-JOB] Sr. Security Engineer, Broomfield, US (Thread)
18. [SJ-JOB] Security System Administrator, Chantilly, U... (Thread)
19. [SJ-JOB] Account Manager, DC or VA, US (Thread)
20. [SJ-JOB] Security Engineer, dublin, IE (Thread)
VI. INCIDENTS LIST SUMMARY
1. Systems compromised with ShellBOT perl script - part... (Thread)
2. Systems compromised with ShellBOT perl script (Thread)
3. Uptick in telnetd scanners - possible worm activity. (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
1. Cross-Site Scripting Vulnerability in Newtelligence ... (Thread)
2. [SHATTER Team Security Alert] Multiple vulnerabiliti... (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
1. XP-SP2 "Feature" (Thread)
2. Windows/Exchange security auditing tool (Thread)
3. SecurityFocus Microsoft Newsletter #204 (Thread)
IX. SUN FOCUS LIST SUMMARY
1. allowing ordinary users to open privileged ports (Thread)
2. RESOLUTION: E450 - hangs when booting without keyboa... (Thread)
3. E450 - hangs when booting without keyboard and monit... (Thread)
X. LINUX FOCUS LIST SUMMARY
1. How to make a core dump? (Thread)
2. redhat patch problem? (Thread)
3. Reverse SSH tunelling (Thread)
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. Metasploit Framework, Part 2
By Pukhraj Singh and K.K. Mookhey
Newly updated. This article provides insight into the Metasploit Framework,
a very useful tool for the penetration tester. Part two of three.
http://www.securityfocus.com/infocus/1790
2. Feast of Egos
By Tim Mullen
Eager to tarnish Microsoft's shiny new Service Pack 2, the security press
managed to spin the most thin and marginal issues into "gaping holes" and
"security craters."
http://www.securityfocus.com/columnists/265
3. Simple and Secure isn't so Simple
By Daniel Hanson
Simple to code does not always mean simple for the user. And simple for the
user is often not easy to code.
http://www.securityfocus.com/columnists/264
II. BUGTRAQ SUMMARY
-------------------
1. Ipswitch WS_FTP Server CD Command Malformed File Path Remote...
BugTraq ID: 11065
Remote: Yes
Date Published: Aug 30 2004
Relevant URL: http://www.securityfocus.com/bid/11065
Summary:
WS_FTP Server is reported prone to a remote denial of service vulnerability. This issue presents itself when the application processes a malformed file path through the 'cd' command.
WS_FTP Server version 5.0.2 is reported prone to this issue, however, other versions may be affected as well.
2. JazerNorth Scout Tracker Multiple Unspecified Vulnerabilitie...
BugTraq ID: 11066
Remote: Yes
Date Published: Aug 28 2004
Relevant URL: http://www.securityfocus.com/bid/11066
Summary:
Scout Tracker version 0.10 has been released. This version addresses various unspecified security vulnerabilities associated with passwords and user groups.
Scout Tracker versions 0.9 and prior are affected by these issues.
This BID will be updated as more information becomes available.
3. WFTPD Server MLST Argument Remote Denial Of Service Vulnerab...
BugTraq ID: 11067
Remote: Yes
Date Published: Aug 30 2004
Relevant URL: http://www.securityfocus.com/bid/11067
Summary:
WFTPD server is reported to be prone to a denial of service. The issue is reported to present itself if a user who is logged into the affected service issues MLST requests with varying parameter sizes. This will cause the server to behave in an unstable manner potentially preventing normal service.
4. Symantec PowerQuest DeployCenter Boot Disk Plaintext Passwor...
BugTraq ID: 11068
Remote: No
Date Published: Aug 30 2004
Relevant URL: http://www.securityfocus.com/bid/11068
Summary:
Symantec PowerQuest DeployCenter is reportedly affected by a boot disk plaintext password disclosure vulnerability. This issue is due to a failure of the application to handle exceptional conditions.
This issue will allow an attacker to steal a password to the remote computer that the offending boot disk is designed to access, facilitating further attacks against the affected computer.
5. Titan FTP Server CWD Command Remote Heap Overflow Vulnerabil...
BugTraq ID: 11069
Remote: Yes
Date Published: Aug 30 2004
Relevant URL: http://www.securityfocus.com/bid/11069
Summary:
Titan FTP server is reported prone to a remote heap overflow vulnerability. This issue exists due to insufficient boundary checks performed by the application and may result in arbitrary code execution.
The issue presents itself when the server processes user-supplied data passed through the 'cwd' command.
All versions of Titan FTP server are considered vulnerable to this issue.
6. ACLogic CesarFTP Buffer Overflow Vulnerability
BugTraq ID: 11070
Remote: Yes
Date Published: Aug 30 2004
Relevant URL: http://www.securityfocus.com/bid/11070
Summary:
It is reported that CesarFTP is susceptible to a buffer overflow vulnerability. This vulnerability is due to a lack of proper bounds checking in the application. This leads to a buffer of fixed size being overrun, corrupting the contents of adjacent memory regions.
It is reported that this vulnerability is exploitable before authenticating to the FTP server, allowing anonymous attackers to either crash the FTP server, or possibly to execute arbitrary code in the context of the FTP server process.
7. Xedus Web Server Multiple Vulnerabilities
BugTraq ID: 11071
Remote: Yes
Date Published: Aug 30 2004
Relevant URL: http://www.securityfocus.com/bid/11071
Summary:
It is reported that Xedus is susceptible to multiple vulnerabilities.
The first reported issue is a denial of service vulnerability. The affected application is unable to service multiple simultaneous connections, denying access to the hosted site for legitimate users.
The second reported issue is a cross-site scripting vulnerability in included sample scripts. This vulnerability is due to a failure of the application to properly sanitize user-supplied URI input before including it in the output of the scripts.
The third reported issue is a directory traversal vulnerability. The affected application will reportedly serve documents located outside of the configured web root. This may allow an attacker the ability to read arbitrary, potentially sensitive files on the hosting computer with the privileges of the web server. This may aid malicious users in further attacks.
These vulnerabilities are reported to exist in version 1.0 of Xedus.
8. D-Link Securicam Network DCS-900 Internet Camera Remote Conf...
BugTraq ID: 11072
Remote: Yes
Date Published: Aug 31 2004
Relevant URL: http://www.securityfocus.com/bid/11072
Summary:
D-Link Securicam Network DCS-900 Internet Camera is reportedly affected by a remote configuration vulnerability. This issue is due to a design error that allow remote, unauthorized users to update the IP address of the vulnerable camera.
An attacker may leverage this issue to hijack the vulnerable camera, ultimately triggering a denial of service condition, as the unsuspecting user will be unable to connect to the device without having its IP address.
9. Web Animations Password Protect Multiple Input Validation Vu...
BugTraq ID: 11073
Remote: Yes
Date Published: Aug 31 2004
Relevant URL: http://www.securityfocus.com/bid/11073
Summary:
Password Protect is reported prone to a multiple cross-site scripting and SQL injection vulnerabilities. These issues occur due to insufficient sanitization of user-supplied input. Successful exploitation of these issues may result in arbitrary HTML and script code execution and/or compromise of the underlying database.
It is reported that these issues could be exploited to gain unauthorized administrative access to the application.
All versions of Password Protect are considered vulnerable to these issues.
10. PvPGN Remote Buffer Overflow Vulnerability
BugTraq ID: 11074
Remote: Yes
Date Published: Aug 29 2004
Relevant URL: http://www.securityfocus.com/bid/11074
Summary:
PvPGN is reported prone to a remote buffer overflow vulnerability. This issue can allow an attacker to execute arbitrary code to gain unauthorized access to a vulnerable computer.
An attacker can trigger this vulnerability by supplying an excessively long string value through the 'watchall' and 'unwatchall' commands.
All versions of PvPGN including 1.6.5 and prior are affected by this vulnerability.
11. CDRTools RSH Environment Variable Privilege Escalation Vulne...
BugTraq ID: 11075
Remote: No
Date Published: Aug 31 2004
Relevant URL: http://www.securityfocus.com/bid/11075
Summary:
CDRTools is reportedly vulnerable to an RSH environment variable privilege escalation vulnerability. This issue is due to a failure of the application to properly implement security controls when executing an application specified by the RSH environment variable.
An attacker may leverage this issue to gain superuser privileges on a computer running the affected software.
12. Diebold GEMS Central Tabulator Vote Database Integrity Compr...
BugTraq ID: 11076
Remote: Yes
Date Published: Aug 31 2004
Relevant URL: http://www.securityfocus.com/bid/11076
Summary:
It is reported that the GEMS Central Tabulator stores received votes in three segregated regions of an Access database. The GEMs system harvests data from each of these database regions in order to generate reports.
All of the tables in these separate database regions are linked together in an attempt to prevent database tampering, by ensuring that the table data corresponds to table data in other database regions.
The Diebold GEMS Central Tabulator is reported prone to a vulnerability, where a two-digit code can be entered into a hidden location to de-link the tables in the GEMS database. This will permit an attacker to add sets of fake votes.
13. Bsdmainutils Calendar Information Disclosure Vulnerability
BugTraq ID: 11077
Remote: No
Date Published: Aug 31 2004
Relevant URL: http://www.securityfocus.com/bid/11077
Summary:
The calendar utility contained in the bsdmainutils package on Debian GNU/Linux systems is reported susceptible to an information disclosure vulnerability. This is due to a lack of proper file authorization checks by the application.
The application fails to enforce permissions of included files when run as the superuser with the '-a' argument, therefore it is possible for a local attacker to create a calendar file that will disclose the contents of arbitrary, potentially sensitive files. This may aid them in further attacks against the affected computer.
By default, the package is installed with a crontab file that will not call the calendar utility. Systems are only affected if the crontab is enabled by administrators.
Debian GNU/Linux computers with bsdmainutils versions prior to 6.0.15 are reported to be vulnerable.
14. MIT Kerberos 5 Multiple Double-Free Vulnerabilities
BugTraq ID: 11078
Remote: Yes
Date Published: Aug 31 2004
Relevant URL: http://www.securityfocus.com/bid/11078
Summary:
There are multiple double-free vulnerabilities reported to exist in MIT Kerberos 5.
All vulnerabilities stem from inconsistent memory handling routines in the krb5 library.
These vulnerabilities are exploitable in various ways:
- An attacker can execute arbitrary code in the context of a KDC server process, potentially compromising the entire Kerberos realm.
- An attacker can execute arbitrary code in the context of a krb524d server process, potentially compromising the entire Kerberos realm if it is running on the same computer as a KDC.
- An attacker can execute arbitrary code in the context of various other server processes utilizing the krb5 library.
- An attacker impersonating a KDC or application server may be able to execute arbitrary code in the context of a client process attempting to authenticate.
Versions up to and including 1.3.4 are reported vulnerable.
15. MIT Kerberos 5 ASN.1 Decoder Denial Of Service Vulnerability
BugTraq ID: 11079
Remote: Yes
Date Published: Aug 31 2004
Relevant URL: http://www.securityfocus.com/bid/11079
Summary:
It is reported that MIT Kerberos V is susceptible to a denial of service vulnerability in its ASN.1 decoder.
This vulnerability presents itself when the krb5 library attempts to decode a malformed ASN.1 buffer.
As a result of this vulnerability, a remote attacker may be able to deny all Kerberos service in a realm by sending malicious UDP packets to all KDCs (Key Distribution Center). The affected KDCs would then stop servicing further authentication requests. All services utilizing Kerberos for authentication would fail to allow further requests.
MIT Kerberos V versions 1.2.2 through to 1.3.4 are reportedly affected by this vulnerability.
16. PHPScheduleIt HTML Injection Vulnerability
BugTraq ID: 11080
Remote: Yes
Date Published: Aug 31 2004
Relevant URL: http://www.securityfocus.com/bid/11080
Summary:
phpScheduleIt is reported to contain an HTML injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before including it in dynamically generated web page content.
This may allow an attacker to inject malicious HTML and script code into the application. An unsuspecting user viewing the schedule will have the attacker-supplied script code executed within their browser in the context of the vulnerable site. This issue may be leverage to steal cookie based authentication credentials. Other attacks are also possible.
Although this issue reportedly affects version 1.0.0RC1 of the affected software, it is likely that other versions are affected as well.
17. SuSE Linux PTMX Unspecified Local Denial Of Service Vulnerab...
BugTraq ID: 11081
Remote: No
Date Published: Sep 01 2004
Relevant URL: http://www.securityfocus.com/bid/11081
Summary:
Reportedly SuSE Linux is vulnerable to a local ptmx denial of service vulnerability; fixes are available. The underlying cause of this issue is currently unknown; this BID will be updated as more information is released.
An attacker may leverage this issue to cause the affected computer to hang or crash, denying service to legitimate users.
18. pLog User Registration HTML Injection Vulnerability
BugTraq ID: 11082
Remote: Yes
Date Published: Sep 01 2004
Relevant URL: http://www.securityfocus.com/bid/11082
Summary:
pLog is prone to an HTML injection vulnerability that is exposed via the user registration form. Fields in the form are not adequately sanitized of HTML and script code.
This may permit execution of hostile script code when a user views pages that include the injected code. The hostile code would be rendered in the context of the site hosting the vulnerable software. Exploitation could allow for theft of cookie-based authentication credentials or other attacks.
19. Comersus Cart HTTP Response Splitting Vulnerability
BugTraq ID: 11083
Remote: Yes
Date Published: Sep 01 2004
Relevant URL: http://www.securityfocus.com/bid/11083
Summary:
Comersus Cart is reported prone to a HTTP response splitting vulnerability. A remote attacker may exploit this vulnerability to influence or misrepresent how web content is served, cached or interpreted. This could aid in various attacks, which try to entice client users into a false sense of trust.
This issue was identified in Comersus Shopping Cart 5.0991, however, other versions may be affected as well.
20. IMLib/IMLib2 Multiple BMP Image Decoding Buffer Overflow Vul...
BugTraq ID: 11084
Remote: Yes
Date Published: Sep 01 2004
Relevant URL: http://www.securityfocus.com/bid/11084
Summary:
Multiple buffer overflow vulnerabilities are reported to exist in the Iimlib/Imlib2 libraries. These issues may be triggered when handling malformed bitmap images.
These vulnerabilities could be exploited by a remote attacker to cause a denial of service in applications that use the vulnerable library to render images. It is also reported that these vulnerabilities may be exploited to execute code arbitrary code.
21. Cerbère Proxy Server Long Host Header Field Remote Denial of...
BugTraq ID: 11085
Remote: Yes
Date Published: Sep 01 2004
Relevant URL: http://www.securityfocus.com/bid/11085
Summary:
Cerbère Proxy server is reported prone to a remote denial of service vulnerability. This issue presents itself when a remote attacker sends a malformed HTTP GET request to the server.
A remote attacker may cause a denial of service condition in the proxy leading to a crash or hang.
Cerbère Proxy 1.2 is reported prone to this issue, however, other versions may be affected as well.
22. Newtelligence DasBlog Request Log HTML Injection Vulnerabili...
BugTraq ID: 11086
Remote: Yes
Date Published: Sep 01 2004
Relevant URL: http://www.securityfocus.com/bid/11086
Summary:
DasBlog is reportedly susceptible to an HTML injection vulnerability in its request log. This vulnerability is due to a failure of the application to properly sanitize user-supplied input data before using it in the generation of dynamic web pages.
This may allow an attacker to inject malicious HTML and script code into the application. An administrator displaying the 'Activity and Events Viewer' will have the attacker-supplied script code executed within their browser in the context of the vulnerable site. This issue may be leverage to steal cookie based authentication credentials. Other attacks are also possible.
Although this issue reportedly affects versions 1.3 through 1.6 of the affected software.
23. TorrentTrader Download.PHP SQL Injection Vulnerability
BugTraq ID: 11087
Remote: Yes
Date Published: Sep 01 2004
Relevant URL: http://www.securityfocus.com/bid/11087
Summary:
TorrentTrader is vulnerable to a remote SQL injection vulnerability in the 'download.php' script. This issue is due to a failure of the application to properly validate user-supplied input prior to including it in an SQL query.
An attacker may exploit this issue to manipulate and inject SQL queries onto the underlying database. It will be possible to leverage this issue to steal database contents including administrator password hashes and user credentials as well as to make attacks against the underlying database.
24. PHPWebSite Multiple Input Validation Vulnerabilities
BugTraq ID: 11088
Remote: Yes
Date Published: Sep 01 2004
Relevant URL: http://www.securityfocus.com/bid/11088
Summary:
It is reported that phpWebSite is susceptible to multiple cross-site scripting, HTML injection and SQL injection vulnerabilities.
The cross-site scripting issue is present in a parameter of the comments module script. An attacker can exploit these issues by creating a malicious link to the vulnerable module containing HTML and script code and send this link to a vulnerable user. When the user follows the link, the attacker-supplied code renders in the user's browser.
An SQL injection issue exists in the application as well. This issue affects a parameter of the calendar module script. This issue may be exploited to cause sensitive information to be disclosed to a remote attacker.
Finally, a HTML Injection vulnerability is reported to affect the application. The problem is said to occur in the notes module due to a lack of sufficient sanitization performed on user supplied data.
Attackers may potentially exploit this issue to manipulate web content, take unauthorized site actions in the context of the victim, or to steal cookie-based authentication credentials.
These vulnerabilities were reported in phpWebsite 0.9.3-4, previous versions are also reported to be vulnerable.
25. IBM DB2 Universal Database Multiple Remote Buffer Overflow A...
BugTraq ID: 11089
Remote: Yes
Date Published: Sep 01 2004
Relevant URL: http://www.securityfocus.com/bid/11089
Summary:
NGSSoftware have reported that multiple remote buffer overflow and unspecified vulnerabilities exist in IBM DB2 Universal Database.
Details about any of the vulnerabilities are not known at this time.
26. Opera Web Browser Empty Embedded Object JavaScript Denial Of...
BugTraq ID: 11090
Remote: Yes
Date Published: Sep 01 2004
Relevant URL: http://www.securityfocus.com/bid/11090
Summary:
Opera is a web browser available for a number of platforms, including Microsoft Windows, Linux and Unix variants and Apple MacOS.
Opera Web Browser is reported to be susceptible to a JavaScript denial of service vulnerability. This vulnerability presents itself when Opera attempts to execute a specific JavaScript command. Upon executing this command, Opera will reportedly crash.
This vulnerability was reported to exist in version 7.23 of Opera for Microsoft Windows. Other versions are also likely affected. Version 7.54 does not seem to be susceptible.
27. Oracle 10g Database DBMS_SCHEDULER Remote Command Execution ...
BugTraq ID: 11091
Remote: Yes
Date Published: Sep 01 2004
Relevant URL: http://www.securityfocus.com/bid/11091
Summary:
Oracle 10g Database is reported prone to a remote command execution vulnerability. It is reported that the vulnerability exists in the scheduler functionality that was added to Oracle 10g R1.
A remote authenticated attacker may exploit this vulnerability to execute arbitrary commands in the context of the vulnerable software.
This issue was originally announced as an undisclosed issue in BID 10871.
28. WinZip Multiple Unspecified Buffer Overflow Vulnerabilities
BugTraq ID: 11092
Remote: Yes
Date Published: Sep 01 2004
Relevant URL: http://www.securityfocus.com/bid/11092
Summary:
WinZip is reported prone to multiple unspecified buffer overflow vulnerabilities. These issues may allow a remote or local attacker to potentially execute arbitrary code on a vulnerable computer. A successful attack may allow an attacker to gain unauthorized access to a computer. The problems likely occur due to insufficient bounds checking when processing zip archives.
A local buffer overflow vulnerability was reported as well. This issue can be triggered through the command line.
WinZip versions 9.0 and prior are affected by these issues.
Due to a lack of details, further information is not available at the moment. This BID will be updated as more information becomes available.
29. LHA Multiple Code Execution Vulnerabilities
BugTraq ID: 11093
Remote: Yes
Date Published: Sep 01 2004
Relevant URL: http://www.securityfocus.com/bid/11093
Summary:
LHA is reported prone to multiple vulnerabilities. These issues include multiple local and remote buffer overflow vulnerabilities and a remote command execution vulnerability. Successful exploitation of these issues may allow an attacker to execute arbitrary code and gain unauthorized access to a vulnerable computer.
The following specific issues were reported:
The application is prone to a stack overflow vulnerability when processing a malicious archive.
Multiple local buffer overflow vulnerabilities were reported as well. These issues can be triggered by supplying an excessive string value to the application through the command line.
Additionally, a remote command execution issue affects the application. This issue is triggered when LHA processes a directory with a malformed name.
LHA versions 1.14 and prior are affected by these issues.
30. Apache mod_ssl Denial Of Service Vulnerability
BugTraq ID: 11094
Remote: Yes
Date Published: Sep 02 2004
Relevant URL: http://www.securityfocus.com/bid/11094
Summary:
Apache mod_ssl is reported susceptible to a denial of service vulnerability.
This issue presents itself during SSL connections to a vulnerable Apache server. The affected software may enter into an infinite loop in certain circumstances. This will consume CPU resources and potentially cause further connections to the affected server to fail.
All Apache versions from 2.0 through to 2.0.50 are reported vulnerable.
31. SiteCubed MailWorks Professional Authentication Bypass Vulne...
BugTraq ID: 11095
Remote: Yes
Date Published: Sep 02 2004
Relevant URL: http://www.securityfocus.com/bid/11095
Summary:
MailWorks Professional is reported prone to an authentication bypass vulnerability.
The application uses cookies to store variables that determine the status of the authentication process. An attacker browsing the web application using specially crafted cookie data is able to bypass the authentication process to access the site as an administrative user.
This vulnerability allows a remote attacker to gain administrative access to the affected application.
32. Kerio Personal Firewall Application Security Bypass Vulnerab...
BugTraq ID: 11096
Remote: No
Date Published: Sep 02 2004
Relevant URL: http://www.securityfocus.com/bid/11096
Summary:
A vulnerability is reported to affect Kerio Personal Firewall (KPF) 'Application Security' functionality that could permit an executable that is run by an administrator to disable KPF 'Application Security' functionality.
It is reported that (KPF) 'Application Security' functionality employs a modified Service Description Table in order to function. It is possible to restore the Service Description Table to its original state. A malicious application that is run by an administrator can read an intact SDT table from kernel memory and restore the SDT table in the running kernel by writing to kernel memory space. This will disable Kerio Personal Firewall (KPF) 'Application Security' functionality.
33. CuteNews 'index.php' Cross-Site Scripting Vulnerability
BugTraq ID: 11097
Remote: Yes
Date Published: Sep 02 2004
Relevant URL: http://www.securityfocus.com/bid/11097
Summary:
It is reported that CuteNews is affected by a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input.
This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.
This vulnerability is reported to exist in versions 1.3.6 and prior of CuteNews.
34. Squid Proxy NTLM Authentication Denial Of Service Vulnerabil...
BugTraq ID: 11098
Remote: Yes
Date Published: Sep 02 2004
Relevant URL: http://www.securityfocus.com/bid/11098
Summary:
Squid is reported to be susceptible to a denial of service vulnerability in its NTLM authentication module.
This vulnerability presents itself when attacker supplied input data is passed to the affected NTLM module without proper sanitization.
This vulnerability allows an attacker to crash the NTLM helper application. Squid will respawn new helper applications, but with a sustained, repeating attack, it is likely that proxy authentication depending on the NTLM helper application would fail. Failure of NTLM authentication would result in the Squid application denying access to legitimate users of the proxy.
Squid versions 2.x and 3.x are all reported to be vulnerable to this issue. A patch is available from the vendor.
35. Oracle Database Server ctxsys.driload Access Validation Vuln...
BugTraq ID: 11099
Remote: Yes
Date Published: Sep 03 2004
Relevant URL: http://www.securityfocus.com/bid/11099
Summary:
Oracle Database Server is prone to an access validation vulnerability that may permit unprivileged users to execute commands as the DBA. This could compromise the database.
This issue corresponds to one of the unspecified vulnerabilities mentioned in BID 10871 and addressed by Oracle Alert #68.
36. Oracle Database Server dbms_system.ksdwrt Remote Buffer Over...
BugTraq ID: 11100
Remote: Yes
Date Published: Sep 03 2004
Relevant URL: http://www.securityfocus.com/bid/11100
Summary:
A remotely exploitable buffer overflow exists in Oracle Database Server.
The issue can be triggered when an overly long string is passed to an internal logging function. Authorized users could exploit this issue to execute arbitrary code in the context of the server process or to cause a denial of service.
This issue corresponds to one of the unspecified vulnerabilities mentioned in BID 10871 and addressed by Oracle Alert #68.
37. Altnet ADM ActiveX Control Remote Buffer Overflow Vulnerabil...
BugTraq ID: 11101
Remote: Yes
Date Published: Sep 03 2004
Relevant URL: http://www.securityfocus.com/bid/11101
Summary:
Altnet is reported prone to a remote buffer overflow vulnerability. This issue presents itself in an ActiveX control installed by the application. Reportedly, a malicious attacker can exploit this issue to execute arbitrary code.
38. Dynalink RTA 230 ADSL Router Default Backdoor Account Vulner...
BugTraq ID: 11102
Remote: Yes
Date Published: Sep 03 2004
Relevant URL: http://www.securityfocus.com/bid/11102
Summary:
The Dynalink RTA 230 ADSL router is reported susceptible to a default backdoor account vulnerability.
It is reported that the firmware contains a backdoor account. This account is not visible or modifiable from the web administration interface. Both the web configuration application and the telnet service are not listening on the WAN interface by default.
Attackers with network access to internal interfaces of the device can gain complete access to a vulnerable access point by using the default credentials.
Other devices utilizing similar firmware may also be affected, but this has not been confirmed. Other potential devices reported are:
- US Robotics 9105 and 9106
- Siemens SE515
- Buffalo WMR-G54
39. PhpMyBackupPro Unspecified Potential Input Validation Vulner...
BugTraq ID: 11103
Remote: Yes
Date Published: Aug 29 2004
Relevant URL: http://www.securityfocus.com/bid/11103
Summary:
phpMyBackupPro is reported prone to multiple unspecified input validation vulnerabilities. These issues were identified by the vendor. The cause and impact of these issues is currently unknown, however, they are reported to occur due to insufficient validation of some configuration entries and validation of mySQL username and password values. It is conjectured that these issues may allow an attacker to gain unauthorized access to the application. Disclosure of database backups is a possibility as well.
phpMyBackupPro versions 0.6.2 and prior are affected by these issues.
40. QNX PPPoEd Multiple Local Buffer Overrun Vulnerabilities
BugTraq ID: 11104
Remote: No
Date Published: Sep 03 2004
Relevant URL: http://www.securityfocus.com/bid/11104
Summary:
QNX PPPoEd is reported to be prone to multiple local buffer overflow vulnerabilities. The issues presents themselves when PPPoEd handles certain command line arguments that are greater than 256 bytes in length.
Because variables that are crucial to controlling program execution flow for PPPoEd are stored adjacent to the affected buffers, an attacker may corrupt these values and influence PPPoEd program execution flow into attacker-controlled memory. Ultimately this may lead to the execution of arbitrary instructions in the context of the superuser.
41. QNX PPPoEd Path Environment Variable Local Command Execution...
BugTraq ID: 11105
Remote: No
Date Published: Sep 03 2004
Relevant URL: http://www.securityfocus.com/bid/11105
Summary:
QNX PPoEd is reported prone to a problem that exists in the handling of paths to external executables that are employed by PPPoEd. Because of this, an attacker may be able to gain elevated privileges on a host with a vulnerable version of PPPoEd installed.
42. Ipswitch IMail Server Multiple Buffer Overflow Denial Of Ser...
BugTraq ID: 11106
Remote: Yes
Date Published: Sep 03 2004
Relevant URL: http://www.securityfocus.com/bid/11106
Summary:
It is reported that IMail is susceptible to multiple buffer overflow denial of service vulnerabilities.
These vulnerabilities allow a remote attacker to crash the affected application, denying service to legitimate users. It is conjectured that it may be possible for an attacker to execute arbitrary code in the context of the affected server application.
Versions of the application prior to 8.13 are reported affected by these vulnerabilities.
43. Nullsoft Winamp ActiveX Control Remote Buffer Overflow Vulne...
BugTraq ID: 11107
Remote: Yes
Date Published: Sep 03 2004
Relevant URL: http://www.securityfocus.com/bid/11107
Summary:
Nullsoft Winamp ActiveX Control is alleged to be prone to a remote buffer overflow vulnerability. This issue presents itself in an ActiveX control installed by the application. Reportedly, a malicious attacker can exploit this issue to execute arbitrary code.
44. Engenio Storage Controller Remote Denial Of Service Vulnerab...
BugTraq ID: 11108
Remote: Yes
Date Published: Sep 04 2004
Relevant URL: http://www.securityfocus.com/bid/11108
Summary:
It is reported that hardware based on Engenio Storage Controllers are prone to a remote denial of service vulnerability. This could also result reportedly result in unrecoverable corruption of data.
Affected hardware includes Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches. Other devices may be affected such as other Storagetek and IBM FastT storage controllers, SGI, and Teradata storage controllers though this has not confirmed. The problem may exist in the underlying vxWorks operating system though this has also not been confirmed.
45. Ipswitch WhatsUp Gold Notification Instance Name Remote Buff...
BugTraq ID: 11109
Remote: Yes
Date Published: Sep 03 2004
Relevant URL: http://www.securityfocus.com/bid/11109
Summary:
The Ipswitch WhatsUp Gold web interface is prone to a remotely exploitable buffer overflow vulnerability. This may be exploited by authenticated users of the interface to execute arbitrary code in the context of the program.
46. Ipswitch WhatsUp Gold prn.htm Denial Of Service Vulnerabilit...
BugTraq ID: 11110
Remote: Yes
Date Published: Sep 04 2004
Relevant URL: http://www.securityfocus.com/bid/11110
Summary:
Ipswitch WhatsUp Gold is prone to a remotely exploitable denial of service vulnerability when handling certain HTTP GET requests to the web interface by authenticated users.
47. Keene Digital Media Server Cross-Site Scripting Vulnerabilit...
BugTraq ID: 11111
Remote: Yes
Date Published: Sep 04 2004
Relevant URL: http://www.securityfocus.com/bid/11111
Summary:
Keene Digital Media Server is prone to multiple cross-site scripting vulnerabilities. These issues span multiple scripts. The source of the problem is that affected scripts do not sufficiently sanitize externally supplied data before rendering it to a client user. An attacker may exploit these issues by enticing a victim user to follow a malicious link.
These issues could be exploited to steal cookie-based authentication credentials or launch other attacks.
48. Keene Digital Media Server Admin Authentication Bypass Vulne...
BugTraq ID: 11112
Remote: Yes
Date Published: Sep 04 2004
Relevant URL: http://www.securityfocus.com/bid/11112
Summary:
Keene Digital Server is prone to an authentication bypass vulnerability. It is reported that remote unprivileged user may access administration pages without needing to authenticate as an administrator.
This may allow for unauthorized administrative actions.
This issue appears similar to one of the issues described in BID 10933 "Keene Digital Media Server Directory Traversal and Authentication Bypass Vulnerabilities".
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Plea deal in 'war spamming' prosecution
By: Kevin Poulsen
Los Angeles man allegedly used unsecured wi-fi networks to send thousands of messages promoting porn sites.
http://www.securityfocus.com/news/9453
2. Appeals court slams garage door DMCA claim
By: Kevin Poulsen
In refusing to outlaw a universal garage door opener, judges rule that a device has to facilitate copyright infringement to fall under the ambit of the DMCA.
http://www.securityfocus.com/news/9445
3. Website offers Caller I.D. falsification service
By: Kevin Poulsen
Not just for phone hackers anymore, a California entrepreneur hopes to sell bill collectors and private investigators on the virtues of spoofing.
http://www.securityfocus.com/news/9419
4. Nevadans to become first to use touch-screen voting that pro...
By: Rachel Konrad, The Associated Press
http://www.securityfocus.com/news/9461
5. Caller ID spoofing service for sale
By: John Leyden, The Register
The founder of a US Caller ID falsification service is selling up, just days after setting up in business.
http://www.securityfocus.com/news/9458
6. Old PCs are goldmine for data thieves
By: John Leyden, The Register
Organisations are risking seeing sensitive information ending up in the wrong hands, because they are failing to ensure that their unwanted PCs are properly datawiped.
http://www.securityfocus.com/news/9452
IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. CifsPwScanner 1.0.5
By: Patrik Karlsson
Relevant URL: http://www.cqure.net/tools/cifspwscan-bin-1_0_5.tar.gz
Platforms: Java
Summary:
A CIFS/SMB password scanner based on the jcifs implementation. The scanner and jcifs are both 100% pure java, making it possible to run the scanner on a few different platforms. CifsPwScanner is released under the GPL Licence
2. Attack Tool Kit (ATK) 2.0
By: Marc Ruef
Relevant URL: http://www.computec.ch/projekte/atk/
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
The acronym ATK stands for Attack Tool Kit. It was first developed to provide a very small and handy tool for Windows to realize fast checks for dedicated vulnerabilities. The special thing about ATK is that the tool is able to do the work without great interaction. But there is also always the possibility to vary and change the behaviour of the software. This concern the plugins, checking, enumeration and reporting.
3. FREEping - Server pinging 1.0
By: Tools4Ever
Relevant URL: http://www.tools4ever.com/products/free/freeping/
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
Free graphical ping utility with built-in statistics, background pinging and popup notification.
4. Softros LAN Messenger 3.4
By: Softros Systems Inc
Relevant URL: http://messenger.softros.com
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
Softros LAN Messenger is a instant LAN messaging software for home or office users. It does not require a server and is very easy to install and use.
With current version you will be able to:
1. Send and receive private messages.
2. Send and receive group messages.
3. Send and receive files.
4. Restrict Messenger's functions to users.
5. Healthmonitor 1.9
By: Vittorio Pavesi
Relevant URL: http://healthmonitor.sourceforge.net
Platforms: Windows 2000, Windows NT, Windows XP
Summary:
HealthMonitor is a free powerful and featureful monitoring tool for Windows.
It works as a Windows Service and check system status (event viewer, disk free space, services status, performance....) and notify the administration by E-Mail or by NET SEND; a database logging feature is also available. It is under constant development, and releases are usually frequent. The latest news regarding HealthMonitor can be found on Sourceforge.
6. THC-Hydra v4.3
By: THC
Relevant URL: http://www.thc.org/releases/hydra-4.3-src.tar.gz
Platforms: AIX, FreeBSD, HP-UX, IRIX, Linux, NetBSD, OpenBSD, Solaris, UNIX
Summary:
THC-Hydra - parallized login hacker is available: for Samba, FTP, POP3, IMAP, Telnet, HTTP Auth, LDAP, NNTP, MySQL, VNC, ICQ, Socks5, PCNFS, Cisco and more. Includes SSL support and is part of Nessus. Visit the project web site to download Win32, Palm and ARM binaries. Changes: important bugfix!
V. SECURITYJOBS LIST SUMMARY
----------------------------
1. [SJ-JOB] Sr. Security Analyst, D.C., US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/374471
2. [SJ-JOB] Developer, Dusseldorf, DE (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/374467
3. [SJ-JOB] Manager, Information Security, San Marcos, ... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/374465
4. [SJ-JOB] Security Architect, Boston, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/374463
5. [SJ-JOB] Sales Engineer, Chicago, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/374450
6. [SJ-JOB] Application Security Engineer, London and S... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/374438
7. [SJ-JOB] Security Engineer, Palo Alto, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/374425
8. [SJ-JOB] VP of Regional Sales, Munich, DE (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/374410
9. [SJ-JOB] Sr. Security Analyst, Boise, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/374409
10. [SJ-JOB] Account Manager, London, GB (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/374408
11. [SJ-JOB] Application Security Engineer, New York, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/374404
12. [SJ-JOB] VP of Regional Sales, London, NL (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/374394
13. [SJ-JOB] Customer Support, San Jose, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/374386
14. [SJ-JOB] Security Architect, Kirkland, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/374385
15. [SJ-JOB] Manager, Information Security, Boston, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/374384
16. [SJ-JOB] Security Architect, NY, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/374383
17. [SJ-JOB] Sr. Security Engineer, Broomfield, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/373923
18. [SJ-JOB] Security System Administrator, Chantilly, U... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/373904
19. [SJ-JOB] Account Manager, DC or VA, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/373859
20. [SJ-JOB] Security Engineer, dublin, IE (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/373849
VI. INCIDENTS LIST SUMMARY
--------------------------
1. Systems compromised with ShellBOT perl script - part... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/374468
2. Systems compromised with ShellBOT perl script (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/374454
3. Uptick in telnetd scanners - possible worm activity. (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/373755
VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Cross-Site Scripting Vulnerability in Newtelligence ... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/82/374239
2. [SHATTER Team Security Alert] Multiple vulnerabiliti... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/82/373917
VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. XP-SP2 "Feature" (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/374466
2. Windows/Exchange security auditing tool (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/374451
3. SecurityFocus Microsoft Newsletter #204 (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/373692
IX. SUN FOCUS LIST SUMMARY
--------------------------
1. allowing ordinary users to open privileged ports (Thread)
Relevant URL:
http://www.securityfocus.com/archive/92/374472
2. RESOLUTION: E450 - hangs when booting without keyboa... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/92/374201
3. E450 - hangs when booting without keyboard and monit... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/92/374021
X. LINUX FOCUS LIST SUMMARY
---------------------------
1. How to make a core dump? (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/374319
2. redhat patch problem? (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/374309
3. Reverse SSH tunelling (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/373984
XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XII. SPONSOR INFORMATION
-----------------------
This issue sponsored by: SPI Dynamics
New Webcast: "The Hacking Evolution: New Trends in Exploits and
Vulnerabilities" Watch as Caleb Sima, CTO & Founder of SPI Dynamics shows
you how to defend against these new attacks in a FREE Web Cast that will
cover real examples of recent hacking methods such as: Google Hacking, SQL
Injection and Cell Phone Attacks.
http://www.securityfocus.com/sponsor/SPIDynamics_sf-news_040907
------------------------------------------------------------------------