SecurityFocus Newsletter #266

Peter Laborge <[email protected]> 14 Sep 2004 21:00:10 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #266
------------------------------

This Issue is Sponsored By: SecurityFocus 

Want to keep up on the latest security vulnerabilities? Don't have time to
visit a myriad of mailing lists and websites to read the news? Just add the
new SecurityFocus RSS feeds to your freeware RSS reader, and see all the
latest posts for Bugtraq and the SF Vulnernability database in one
convenient place. Or, pull in the latest news, columnists and feature
articles in the SecurityFocus aggregated news feed, and stay on top of
what's happening in the community!

http://www.securityfocus.com/rss/index.shtml

------------------------------------------------------------------------
I. FRONT AND CENTER
     1. Metasploit Framework, Part 3
     2. I Spy With My Little Eye
II. BUGTRAQ SUMMARY
     1. Engenio Storage Controller Remote Denial Of Service Vulnerab...
     2. Ipswitch WhatsUp Gold Notification Instance Name Remote Buff...
     3. Ipswitch WhatsUp Gold prn.htm Denial Of Service Vulnerabilit...
     4. Keene Digital Media Server Cross-Site Scripting Vulnerabilit...
     5. Keene Digital Media Server Admin Authentication Bypass Vulne...
     6. OpenCA HTML Injection Vulnerability
     7. Fujitsu-Siemens ServerView Insecure Permissions Vulnerabilit...
     8. Multi Gnome Terminal Information Leak Vulnerability
     9. Sun Solaris in.named Remote Denial of Service Vulnerability
     10. Call of Duty Remote Denial of Service Vulnerability
     11. Oracle Database 9i SQL Command Buffer Overflow Vulnerability
     12. MPG123 Remote Stereo Boundary Buffer Overflow Vulnerability
     13. Webmin / Usermin HTML Email Command Execution Vulnerability
     14. gnubiff Multiple Remote POP3 Protocol Vulnerabilities
     15. PSnews No Parameter Cross-Site Scripting Vulnerability
     16. Net-Acct Symbolic Link Vulnerability
     17. UtilMind Solutions Site News Authentication Bypass Vulnerabi...
     18. Tutti Nova Multiple Unspecified Vulnerabilities
     19. Cosminexus Portal Framework Information Disclosure Vulnerabi...
     20. eZ/eZphotoshare Remote Denial Of Service Vulnerability
     21. PHPGroupWare Wiki Cross-Site Scripting Vulnerability
     22. SAFE TEAM Regulus Staffile Information Disclosure Vulnerabil...
     23. SAFE TEAM Regulus Custchoice.PHP Update Your Password Action...
     24. SAFE TEAM Regulus Customer Statistics Information Disclosure...
     25. Apple CoreFoundation Privileged Plug-In Execution Vulnerabil...
     26. Apple CoreFoundation Unspecified Environment Variable Buffer...
     27. OpenLDAP Ambiguous Password Attribute Weakness
     28. Apple QuickTime Streaming Server Deadlock Denial of Service ...
     29. Apple PPPDialer Insecure Log File Creation Vulnerability
     30. Apple Safari Cross-Domain Frame Loading Vulnerability
     31. Cerulean Studios Trillian Client MSN Module Remote Buffer Ov...
     32. Ulrik Petersen Emdros Database Engine Denial Of Service Vuln...
     33. MailEnable Mail Exchange Record Denial Of Service Vulnerabil...
     34. F-Secure Content Scanner Server Remote Denial of Service Vul...
     35. BBS E-Market Professional Remote File Include Vulnerability
     36. Gearbox Software Halo Combat Evolved Game Server Remote Deni...
     37. PostNuke Modules Factory Subjects Module SQL Injection Vulne...
     38. GetSolutions GetIntranet Multiple Remote Input Validation Vu...
     39. GetSolutions GetInternet Multiple SQL Injection Vulnerabilit...
     40. OpenOffice/StarOffice Local File Disclosure Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
     1. Mitnick movie comes to the U.S.
     2. Plea deal in 'war spamming' prosecution
     3. Appeals court slams garage door DMCA claim
     4. Virus writers add network sniffer to worm
     5. Hackers Join Homeland Security Effort
     6. SP2 Fights Worms, Has Bugs
IV. SECURITYFOCUS TOP 6 TOOLS
     1. Nmap v3.70
     2. DmpE32 -Symbian Executable Information Dumper 1.0
     3. IP Firewall Hook ATL/COM 1.2
     4. IP Firewall Lite ATL/COM 1.2
     5. Password Generator 2004 1.2.1628
     6. CifsPwScanner 1.0.5
V. SECURITYJOBS LIST SUMMARY
     1. [SJ-JOB] Security Architect, Zurich, CH (Thread)
     2. [SJ-JOB] VP of Regional Sales, Dublin, IE (Thread)
     3. [SJ-JOB] Security Consultant, Metro Detroit, US (Thread)
     4. [SJ-JOB] Developer, Boulder, US (Thread)
     5. [SJ-JOB] Security Consultant, Flanders, US (Thread)
     6. [SJ-JOB] Customer Support, Santa Monica, US (Thread)
     7. [SJ-JOB] Sales Engineer, Indianapolis, US (Thread)
     8. [SJ-JOB] Security Auditor, Charlotte, US (Thread)
     9. [SJ-JOB] VP of Regional Sales, London, GB (Thread)
     10. [SJ-JOB] Account Manager, Ettelbruck, LU (Thread)
     11. [SJ-JOB] VP of Marketing, Boston, US (Thread)
     12. [SJ-JOB] VP of Regional Sales, Paris, FR (Thread)
     13. [SJ-JOB] Security Engineer, Boston, US (Thread)
     14. [SJ-JOB] Sales Engineer, NY, US (Thread)
     15. [SJ-JOB] Security Engineer, Arlington, US (Thread)
     16. [SJ-JOB] Sales Engineer, New York, US (Thread)
     17. [SJ-JOB] Developer, Annapolis, US (Thread)
     18. [SJ-JOB] Account Manager, Redwood Shores, US (Thread)
     19. [SJ-JOB] Security Product Manager, Boston, US (Thread)
     20. [SJ-JOB] Sr. Security Engineer, Cardiff, GB (Thread)
     21. [SJ-JOB] Security Consultant, San Diego, US (Thread)
     22. [SJ-JOB] Account Manager, Flexible, US (Thread)
     23. [SJ-JOB] Security Engineer, Clarksburg, US (Thread)
     24. [SJ-JOB] Security Engineer, Alexandria, US (Thread)
     25. [SJ-JOB] Security Architect, Boston, US (Thread)
     26. [SJ-JOB] Sales Engineer, Santa Clara, US (Thread)
     27. [SJ-JOB] Account Manager, Kirkland (Seattle), US (Thread)
     28. [SJ-JOB] Quality Assurance, Herndon, US (Thread)
     29. [SJ-JOB] Security Product Manager, dublin, IE (Thread)
     30. [SJ-JOB] Sr. Security Analyst, Basel, CH (Thread)
     31. [SJ-JOB] Sales Engineer, Englewood, US (Thread)
     32. [SJ-JOB] Developer, Austin, US (Thread)
     33. [SJ-JOB] Sales Engineer, Kirkland, US (Thread)
     34. [SJ-JOB] Security Engineer, Dearborn, US (Thread)
     35. [SJ-JOB] Security Auditor, London, GB (Thread)
     36. [SJ-JOB] Developer, Denver, US (Thread)
     37. [SJ-JOB] Sr. Security Analyst, D.C., US (Thread)
     38. [SJ-JOB] Developer, Dusseldorf, DE (Thread)
     39. [SJ-JOB] Manager, Information Security, San Marcos, ... (Thread)
     40. [SJ-JOB] Sales Engineer, Chicago, US (Thread)
     41. [SJ-JOB] Application Security Engineer, London and S... (Thread)
     42. [SJ-JOB] Security Engineer, Palo Alto, US (Thread)
     43. [SJ-JOB] VP of Regional Sales, Munich, DE (Thread)
     44. [SJ-JOB] Sr. Security Analyst, Boise, US (Thread)
     45. [SJ-JOB] Account Manager, London, GB (Thread)
     46. [SJ-JOB] Application Security Engineer, New York, US (Thread)
     47. [SJ-JOB] VP of Regional Sales, London, NL (Thread)
     48. [SJ-JOB] Customer Support, San Jose, US (Thread)
     49. [SJ-JOB] Security Architect, Kirkland, US (Thread)
     50. [SJ-JOB] Manager, Information Security, Boston, US (Thread)
     51. [SJ-JOB] Security Architect, NY, US (Thread)
VI. INCIDENTS LIST SUMMARY
     1. Systems compromised with ShellBOT perl script - part... (Thread)
     2. Wireless router behaviour (Thread)
     3. FW: [Intrusions] Linux SSH scanning - test/guest (Thread)
     4. Odd mail traffic (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. challenge (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. RKDetect - behaviour based rootkit detection (update... (Thread)
     2. Windows/Exchange security auditing tool (Thread)
     3. How to Recovering files encrypted with Microsoft EFS... (Thread)
     4. Windows2000 Security events (Thread)
     5. Listing usernames via a null session on Windows XP (Thread)
     6. XP-SP2 "Feature" (Thread)
     7. Network Monitor/sniffer (Thread)
     8. FW: Network Monitor/sniffer (Thread)
IX. SUN FOCUS LIST SUMMARY
     1. allowing ordinary users to open privileged ports (Thread)
     2. Solaris 9 authentication and access control into Act... (Thread)
X. LINUX FOCUS LIST SUMMARY
     1. rooted ? (Thread)
     2. redhat patch problem? (Thread)
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION

I. FRONT AND CENTER
-------------------
1. Metasploit Framework, Part 2
By Pukhraj Singh and K.K. Mookhey

This third and final article in the Metasploit series covers the msfcli
scripting interface as well as the intuitive web interface to the
Framework. The article also discusses what's new with version 2.2, and then
introduces the exploit development process through an example.

http://www.securityfocus.com/infocus/1800


2. I Spy With My Little Eye
By Mark Rasch

Forget Congress' myopic efforts to outlaw spyware. What we really need is
better enforcement of existing computer crime laws. 

http://www.securityfocus.com/columnists/266

II. BUGTRAQ SUMMARY
-------------------
1. Engenio Storage Controller Remote Denial Of Service Vulnerab...
BugTraq ID: 11108
Remote: Yes
Date Published: Sep 04 2004
Relevant URL: http://www.securityfocus.com/bid/11108
Summary:
It is reported that hardware based on Engenio Storage Controllers are prone to a remote denial of service vulnerability.  This could also result reportedly result in unrecoverable corruption of data.

Affected hardware includes Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches.  Other devices may be affected such as other Storagetek and IBM FastT storage controllers, SGI, and Teradata storage controllers though this has not confirmed.  The problem may exist in the underlying vxWorks operating system though this has also not been confirmed.

2. Ipswitch WhatsUp Gold Notification Instance Name Remote Buff...
BugTraq ID: 11109
Remote: Yes
Date Published: Sep 03 2004
Relevant URL: http://www.securityfocus.com/bid/11109
Summary:
The Ipswitch WhatsUp Gold web interface is prone to a remotely exploitable buffer overflow vulnerability.  This may be exploited by authenticated users of the interface to execute arbitrary code in the context of the program.

3. Ipswitch WhatsUp Gold prn.htm Denial Of Service Vulnerabilit...
BugTraq ID: 11110
Remote: Yes
Date Published: Sep 04 2004
Relevant URL: http://www.securityfocus.com/bid/11110
Summary:
Ipswitch WhatsUp Gold is prone to a remotely exploitable denial of service vulnerability when handling certain HTTP GET requests to the web interface by authenticated users.

4. Keene Digital Media Server Cross-Site Scripting Vulnerabilit...
BugTraq ID: 11111
Remote: Yes
Date Published: Sep 04 2004
Relevant URL: http://www.securityfocus.com/bid/11111
Summary:
Keene Digital Media Server is prone to multiple cross-site scripting vulnerabilities.  These issues span multiple scripts.  The source of the problem is that affected scripts do not sufficiently sanitize externally supplied data before rendering it to a client user.  An attacker may exploit these issues by enticing a victim user to follow a malicious link.

These issues could be exploited to steal cookie-based authentication credentials or launch other attacks.

5. Keene Digital Media Server Admin Authentication Bypass Vulne...
BugTraq ID: 11112
Remote: Yes
Date Published: Sep 04 2004
Relevant URL: http://www.securityfocus.com/bid/11112
Summary:
Keene Digital Server is prone to an authentication bypass vulnerability.  It is reported that remote unprivileged user may access administration pages without needing to authenticate as an administrator.  

This may allow for unauthorized administrative actions.

This issue appears similar to one of the issues described in BID 10933 "Keene Digital Media Server Directory Traversal and Authentication Bypass Vulnerabilities".

6. OpenCA HTML Injection Vulnerability
BugTraq ID: 11113
Remote: Yes
Date Published: Sep 06 2004
Relevant URL: http://www.securityfocus.com/bid/11113
Summary:
It has been reported that OpenCA is vulnerable to a HTML injection attack due to inadequate validation / filtering of user input into a web form frontend.  The vulnerability is present in the OpenCA PKI software.  According to the report, malicious user-data containing embedded HTML will persist in the system after it is injected.

7. Fujitsu-Siemens ServerView Insecure Permissions Vulnerabilit...
BugTraq ID: 11114
Remote: No
Date Published: Sep 06 2004
Relevant URL: http://www.securityfocus.com/bid/11114
Summary:
It has been reported that local, unprivileged users may corrupt the SNMP MIB and, possibly, other sensitive system components.  This is reportedly due to insecure permissions set on file "/usr/share/snmp/mibs/.index", which specifies the location of files used to build the MIB tree.

8. Multi Gnome Terminal Information Leak Vulnerability
BugTraq ID: 11117
Remote: No
Date Published: Sep 06 2004
Relevant URL: http://www.securityfocus.com/bid/11117
Summary:
It has been reported that Multi Gnome Terminal may output active user keystrokes to a file that is potentially world readable.  According to the report, Gnome Multi Terminal "has been known to" (i.e. under some circumstances, which are unclear at this time) write keystroke data to ~/.xsession-errors.  As this file can be world readable, this may result in a leak of confidential information to other local users.

9. Sun Solaris in.named Remote Denial of Service Vulnerability
BugTraq ID: 11118
Remote: Yes
Date Published: Sep 06 2004
Relevant URL: http://www.securityfocus.com/bid/11118
Summary:
Sun has reported that a remotely exploitable denial of service affects the Solaris 8 version of in.named, the primary DNS daemon.  According to the report, a remote attacker can crash a running in.named process by sending it dynamic updates.  Sun has stated that the remote attacker must be "privileged".

Sun had made patches available.  It is not known if this vulnerability is present in the ISC BIND source tree. If this were so, many other systems would be affected.

10. Call of Duty Remote Denial of Service Vulnerability
BugTraq ID: 11119
Remote: Yes
Date Published: Sep 06 2004
Relevant URL: http://www.securityfocus.com/bid/11119
Summary:
It has been reported that it is possible for a remote attacker to immediately terminate instances of Call of Duty on target systems.  This can be accomplished by sending a large (> 1024 bytes) query or response to the target.  
Both the client and server are affected.

11. Oracle Database 9i SQL Command Buffer Overflow Vulnerability
BugTraq ID: 11120
Remote: Yes
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11120
Summary:
This issue corresponds to one of the unspecified vulnerabilities mentioned in BID 10871 (Oracle Multiple Unspecified Vulnerabilities) and addressed by Oracle Alert #68. The issue is being assigned its own BID due to the release of specific technical information.

Reportedly Oracle Database 9i is affected by an SQL command buffer overflow vulnerability.  This issue is due to a failure of the application to properly verify user-supplied string lengths prior to copying them into finite process buffers.

Successful exploitation of this issue would allow a malicious user to manipulate the memory of the affected database process.  This issue will ultimately facilitate arbitrary code execution with the privileges of the affected process.

12. MPG123 Remote Stereo Boundary Buffer Overflow Vulnerability
BugTraq ID: 11121
Remote: Yes
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11121
Summary:
Reportedly mpg123 is affected by a remote stereo boundary buffer overflow vulnerability.  This issue is due to a failure of the application to properly validate user-supplied string sizes prior to copying them into process buffers.

This issue will allow a malicious user to manipulate process memory ultimately leading to arbitrary code execution in the context of the user that started the vulnerable application.

13. Webmin / Usermin HTML Email Command Execution Vulnerability
BugTraq ID: 11122
Remote: Yes
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11122
Summary:
Webmin / Usermin are reportedly affected by a command execution vulnerability when rendering HTML email messages. This issue is due to a failure to sanitize HTML email messages and may allow an attacker to execute arbitrary commands on a vulnerable computer.

This issue is reported to affect Usermin versions 1.080 and prior.

14. gnubiff Multiple Remote POP3 Protocol Vulnerabilities
BugTraq ID: 11123
Remote: Yes
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11123
Summary:
Reportedly gnubiff is affected by multiple pop3 protocol vulnerabilities.  The first issue is due to a design error in the pop3 protocol implementation that causes the application the crash.  The second issue is a buffer overflow in the pop3 implementation.

An attacker might leverage these issues to cause the affected application to crash and to manipulate process memory ultimately facilitating arbitrary code execution.

15. PSnews No Parameter Cross-Site Scripting Vulnerability
BugTraq ID: 11124
Remote: Yes
Date Published: Sep 05 2004
Relevant URL: http://www.securityfocus.com/bid/11124
Summary:
PSnews is affected by a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input.

This vulnerability is reported to exist in version 1.1 of PSnews.

16. Net-Acct Symbolic Link Vulnerability
BugTraq ID: 11125
Remote: No
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11125
Summary:
Net-Acct is reportedly affected by a symbolic link vulnerability. This issue is due to a design error that fails to properly verify files prior to writing to them.

This issue will allow an attacker to overwrite arbitrary files. Reportedly, this issue could be leveraged to facilitate privilege escalation.

17. UtilMind Solutions Site News Authentication Bypass Vulnerabi...
BugTraq ID: 11126
Remote: Yes
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11126
Summary:
Reportedly UtilMind Solutions Site News is affected by an authentication bypass vulnerability.  This issue is due to an access validation error.

An unauthenticated attacker can leverage this issue to display and manipulate arbitrary news items.

18. Tutti Nova Multiple Unspecified Vulnerabilities
BugTraq ID: 11127
Remote: Yes
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11127
Summary:
Tutti Nova is reported prone to multiple unspecified vulnerabilities. Because these issues are related to a fix that unsets all global variables during initialization, it is conjectured that these issues may be of a remote script include nature, this is not confirmed.

Further details regarding these vulnerabilities is not available at this time. This BID will be updated, as further details are made available.

19. Cosminexus Portal Framework Information Disclosure Vulnerabi...
BugTraq ID: 11128
Remote: Yes
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11128
Summary:
Cosminexus Portal Framework is reported susceptible to an information disclosure vulnerability.

In certain undisclosed circumstances, it may be possible for contents of cache objects to be replaced by the contents of other cache objects. This may allow for potentially sensitive information to be sent to a different user than intended. This may include potentially sensitive information, that may aid malicious users in attacks against the application.

As this application framework is designed to handle business information, attackers may be able to gain access to potentially sensitive business data.

20. eZ/eZphotoshare Remote Denial Of Service Vulnerability
BugTraq ID: 11129
Remote: Yes
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11129
Summary:
eZ and eZphotoshare servers are reported prone to a remote denial of service vulnerability. A successful attacker can deny access to legitimate users of the application.

This vulnerability is reported to affect eZ version 3.4.0 and eZphotoshare version 1.2.1. Other versions might also be affected.

21. PHPGroupWare Wiki Cross-Site Scripting Vulnerability
BugTraq ID: 11130
Remote: Yes
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11130
Summary:
It is reported that PHPGroupWare is affected by a cross-site scripting vulnerability in its wiki application.  This issue is due to a failure of the application to properly sanitize user-supplied URI input.

This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

This vulnerability is reported to exist in versions prior to 0.9.16.003 of PHPGroupWare.

22. SAFE TEAM Regulus Staffile Information Disclosure Vulnerabil...
BugTraq ID: 11132
Remote: Yes
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11132
Summary:
SAFE TEAM Regulus is reported prone to an information disclosure vulnerability. It is reported that any user may make a request for the Regulus 'staffile' file hosted on a target server. This file contains a list of Regulus 'staff' users and their corresponding password hashes.

An attacker may employ data that is obtained in this manner to aid in further attacks launched against the vulnerable software.

23. SAFE TEAM Regulus Custchoice.PHP Update Your Password Action...
BugTraq ID: 11133
Remote: Yes
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11133
Summary:
Regulus is reported prone to an information disclosure vulnerability. It is reported that a specified user/customer password hash is contained in a hidden tag of the 'Update Your Password' action page.  

An attacker may employ data that is obtained in this manner to aid in further attacks launched against the vulnerable software.

This vulnerability is reported to affect all versions of SAFE TEAM Regulus.

24. SAFE TEAM Regulus Customer Statistics Information Disclosure...
BugTraq ID: 11134
Remote: Yes
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11134
Summary:
Regulus is reported prone to an information disclosure vulnerability. It is reported that it is possible to view a target users connection statistics without requiring valid credentials.

An attacker may employ data that is obtained in this manner to aid in further attacks launched against the vulnerable software.

This vulnerability is reported to affect all versions of SAFE TEAM Regulus.

25. Apple CoreFoundation Privileged Plug-In Execution Vulnerabil...
BugTraq ID: 11135
Remote: No
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11135
Summary:
It is reported that bundles using CoreFoundation can be made to automatically load plug-in executables using the CFPlugIn feature.  This is a security vulnerability allowing for local privilege escalation as malicious executable plug-ins can be loaded by a privileged application.  At this time, it is not clear whether the application targeted must be in the form of a bundle or if the attacker can perform the attack against any privileged application with a custom bundle.  

Users are advised to apply the patch provided by Apple, which changes the feature to prevent loading of plug-ins automatically if an executable is already loaded.

26. Apple CoreFoundation Unspecified Environment Variable Buffer...
BugTraq ID: 11136
Remote: No
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11136
Summary:
It is reported that a buffer overflow vulnerability is present in CoreFoundation related to its handling of an unspecified environment variable.  Consequently, privileged applications using CoreFoundation may be exploited by local users to elevate their access level to that of the application.  It is not known if all applications using CoreFoundation are vulnerable.

27. OpenLDAP Ambiguous Password Attribute Weakness
BugTraq ID: 11137
Remote: Yes
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11137
Summary:
It is reported that in certain undisclosed cases, OpenLDAP is susceptible to an ambiguous password attribute weakness.

If an attacker is able to retrieve a password hash as contained in the OpenLDAP database, they are possibly able to directly authenticate to the LDAP database. An attacker is able to gain unauthorized access if they can sniff password hashes from the network, or retrieve the contents of the 'userPassword' attribute from a database backup, or through weak permissions on the database.

The OpenLDAP that is included with Apple Mac OS X, versions 10.3.4 and 10.3.5 is reported to be affected. Versions of OpenLDAP included in other operating systems are also possibly affected.

28. Apple QuickTime Streaming Server Deadlock Denial of Service ...
BugTraq ID: 11138
Remote: Yes
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11138
Summary:
It is reported that Apple QuickTime Streaming Server is vulnerable to a remotely exploitable denial of service attack.  According to the report, remote clients can cause the process to deadlock by issuing a specific sequence of operations.  This can render the service inoperable, resulting in a denial of service, until the server is restarted.

29. Apple PPPDialer Insecure Log File Creation Vulnerability
BugTraq ID: 11139
Remote: No
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11139
Summary:
The Apple PPPDialer utility is reported to contain an insecure log file creation vulnerability. The result of this is that log files created by the application are created in a world writeable location.

A local attacker may possibly exploit this vulnerability to execute symbolic link file overwrite attacks.
  
Privilege escalation may be possible using this method of attack, if the attacker can control the data that is being written to the target file.

30. Apple Safari Cross-Domain Frame Loading Vulnerability
BugTraq ID: 11140
Remote: Yes
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11140
Summary:
Apple Safari is reported prone to a cross-domain frame loading vulnerability. It is reported that if the name of a frame rendered in a target site is known, then an attacker may potentially render arbitrary HTML in the frame of the target site.

An attacker may exploit this vulnerability to spoof an interface of a trusted web site. To exploit this vulnerability a victim will need to visit a website hosted by an attacker. The attackers site will then spawn a trusted site in a window, if exploited successfully; the attackers site will place data into the IFRAME of the trusted site. This vulnerability may aid in Phishing style attacks.

The version of Safari included in Apple Mac OS X versions 1.2.8, 10.3.4, and 10.3.5 is reported vulnerable to this issue.

31. Cerulean Studios Trillian Client MSN Module Remote Buffer Ov...
BugTraq ID: 11142
Remote: Yes
Date Published: Sep 08 2004
Relevant URL: http://www.securityfocus.com/bid/11142
Summary:
Trillian is reported prone to a remote buffer overflow vulnerability.  This issue occurs due to insufficient boundary checks performed by the application and may allow an attacker to execute arbitrary code on a vulnerable computer.  This could ultimately lead to an attacker gaining unauthorized access to the computer.

The vulnerability affects the MSN module and requires an attacker to pose as an MSN server through means such as a man-in-the-middle attack.

Trillian version 0.74i is reported prone to this issue, however, it is likely that other versions are affected as well.

32. Ulrik Petersen Emdros Database Engine Denial Of Service Vuln...
BugTraq ID: 11143
Remote: Yes
Date Published: Sep 08 2004
Relevant URL: http://www.securityfocus.com/bid/11143
Summary:
It is reported that Emdros is prone to a denial of service vulnerability, due to a memory leak while running as a daemon.

This vulnerability is present in the 'mql' process. This process contains a memory leak, and if it is run as a daemon, a remote attacker has the ability to consume all available memory until the process crashes.

Versions prior to 1.1.20 are reported susceptible to this vulnerability.

33. MailEnable Mail Exchange Record Denial Of Service Vulnerabil...
BugTraq ID: 11144
Remote: Yes
Date Published: Sep 09 2004
Relevant URL: http://www.securityfocus.com/bid/11144
Summary:
Reportedly MailEnable is affected by a remote denial of service vulnerability due to mishandling of mail exchange records.  This issue is caused by a failure of the application to properly handle exception mail exchange records.

This issue may be leveraged by an attacker to cause the affected application to crash, denying service to legitimate users.

34. F-Secure Content Scanner Server Remote Denial of Service Vul...
BugTraq ID: 11145
Remote: Yes
Date Published: Sep 09 2004
Relevant URL: http://www.securityfocus.com/bid/11145
Summary:
F-Secure Content Scanner Server is reported prone to a remote denial of service vulnerability.  This issue presents itself when the application handles certain malformed packets.  This vulnerability causes an unhandled exception in the process leading to a crash in the process.

F-Secure Anti-Virus for Microsoft Exchange and F-Secure Internet Gatekeeper are vulnerable to this issue.

35. BBS E-Market Professional Remote File Include Vulnerability
BugTraq ID: 11146
Remote: Yes
Date Published: Sep 09 2004
Relevant URL: http://www.securityfocus.com/bid/11146
Summary:
BBS E-Market Professional is reported to be affected by a remote file include vulnerability that may allow an attacker to include malicious files containing arbitrary code to be executed on a vulnerable system.

36. Gearbox Software Halo Combat Evolved Game Server Remote Deni...
BugTraq ID: 11147
Remote: Yes
Date Published: Sep 09 2004
Relevant URL: http://www.securityfocus.com/bid/11147
Summary:
The Halo Combat Evolved game server is reported prone to a remote denial of service vulnerability.

A remote attacker may exploit this vulnerability to deny service for legitimate game players.

Patches are available to address the issue.

37. PostNuke Modules Factory Subjects Module SQL Injection Vulne...
BugTraq ID: 11148
Remote: Yes
Date Published: Sep 10 2004
Relevant URL: http://www.securityfocus.com/bid/11148
Summary:
Reportedly the PostNuke Modules Factory Subjects module is affected by a remote SQL injection vulnerability.  This issue is due to a failure of the application to properly sanitize user-supplied URI parameters.

An attacker might exploit this issue to manipulate SQL queries carried out against the database; it may be possible to disclose sensitive information such as the administrator password hash, as well as corrupt arbitrary data.  SQL injection issues may also facilitate attacks against latent vulnerabilities in the underlying database.

38. GetSolutions GetIntranet Multiple Remote Input Validation Vu...
BugTraq ID: 11149
Remote: Yes
Date Published: Sep 10 2004
Relevant URL: http://www.securityfocus.com/bid/11149
Summary:
Reportedly getSolutions getIntranet is affected by multiple remote input validation vulnerabilities.  These issues are caused by a failure of the application to properly sanitize user-supplied input.

These issues may be leveraged to carry out SQL injection attacks, HTML injection attacks, arbitrary file uploads, privilege escalation, command execution in the context of the vulnerable application, and command execution in the context of the affected system.

39. GetSolutions GetInternet Multiple SQL Injection Vulnerabilit...
BugTraq ID: 11150
Remote: Yes
Date Published: Sep 10 2004
Relevant URL: http://www.securityfocus.com/bid/11150
Summary:
getInternet is vulnerable to multiple remote SQL injection vulnerabilities in the 'welcome.asp', 'checklogin.asp', and 'lostpassword.asp' scripts. These issues are due to a failure of the application to properly validate user-supplied input prior to including it in an SQL query. 

An attacker may exploit these issues to manipulate and inject SQL queries onto the underlying database. It is possible to leverage this issue to steal database contents including administrator password hashes and user credentials as well as to make attacks against the underlying database.

40. OpenOffice/StarOffice Local File Disclosure Vulnerability
BugTraq ID: 11151
Remote: No
Date Published: Sep 10 2004
Relevant URL: http://www.securityfocus.com/bid/11151
Summary:
StarOffice and OpenOffice are reported prone to a local file disclosure vulnerability.  This issue presents itself because the application creates insecure temporary files.  Each time a user saves a file, a compressed copy of the file is saved in a temporary direcotry.  This can allow a local attacker to disclose files of other users.

OpenOffice 1.1.2 and StarOffice 7.0 are reported prone to this vulnerability.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Mitnick movie comes to the U.S.
By: Kevin Poulsen

Trouble-plagued hacker film won't stay dead. 
http://www.securityfocus.com/news/9470

2. Plea deal in 'war spamming' prosecution
By: Kevin Poulsen

Los Angeles man allegedly used unsecured wi-fi networks to send thousands of messages promoting porn sites.

http://www.securityfocus.com/news/9453

3. Appeals court slams garage door DMCA claim
By: Kevin Poulsen

In refusing to outlaw a universal garage door opener, judges rule that a device has to facilitate copyright infringement to fall under the ambit of the DMCA.  

http://www.securityfocus.com/news/9445

4. Virus writers add network sniffer to worm
By: John Leyden, The Register

Virus writers have grafted a network sniffer into the latest variant of the SDBot worm series.
http://www.securityfocus.com/news/9503

5. Hackers Join Homeland Security Effort
By: Adam Tanner, Washington Post

IDAHO FALLS, Idaho -- Jason Larsen types in a few lines of computer code to hack into the controls of a nearby chemical plant. Then he finds an online video
camera inside and confirms that he has pumped up a pressure value.
http://www.securityfocus.com/news/9502

6. SP2 Fights Worms, Has Bugs
By: Mike Musgrove, Washington Post

After a rough couple of years of embarrassing and serious hacker attacks hitting the Windows-using world, Microsoft Corp. struck back in August with the
security-minded upgrade it dubbed Service Pack 2.

http://www.securityfocus.com/news/9496

IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Nmap v3.70
By: Fyodor
Relevant URL: http://www.insecure.org/nmap/
Platforms: AIX, BSDI, FreeBSD, HP-UX, IRIX, Linux, NetBSD, OpenBSD, Solaris, SunOS, UNIX
Summary: 

Nmap is a utility for port scanning large networks, although it works fine for single hosts. Sometimes you need speed, other times you may need stealth. In some cases, bypassing firewalls may be required. Not to mention the fact that you may want to scan different protocols (UDP, TCP, ICMP, etc.). Nmap supports Vanilla TCP connect() scanning, TCP SYN (half open) scanning, TCP FIN, Xmas, or NULL (stealth) scanning, TCP ftp proxy (bounce attack) scanning, SYN/FIN scanning using IP frag

2. DmpE32 -Symbian Executable Information Dumper 1.0
By: Jimmy Shah
Relevant URL: http://www.geocities.com/jfldars/DmpE32.zip
Platforms: 
Summary: 

Symbian Exe File dumper
* Useful for analysis of potential malware.

* Determine wheteher or not an executable has been inappropiately modified(Mosquitos "Trojan").

* Provides information on:
  - Header
    (UIDs,Section sizes, Entry Point, Application Type)
  - Imported functions list
    (DLL name and number of functions by default)

3. IP Firewall Hook ATL/COM 1.2
By: Egemen Tas
Relevant URL: http://www.modemwall.com/tipfwhook.htm
Platforms: Windows 2000, Windows XP
Summary: 

IP Firewall Hook is a *FREE and open source* ATL/COM component based on "Windows Firewall-Hook Driver" technology. It is a powerful packet filtering component for Windows 2000/XP. A sample application firewall is also provided with it.

4. IP Firewall Lite ATL/COM 1.2
By: Egemen Tas
Relevant URL: http://www.modemwall.com/tipfwlite.htm
Platforms: Windows 2000, Windows XP
Summary: 

IP Firewall Lite is a *FREE and open source* ATL/COM component based on "Windows IP Filter Driver" technology. It is a powerful packet filtering component for Windows 2000/XP. A sample application firewall is also provided along with it.

5. Password Generator 2004 1.2.1628
By: Diplodock
Relevant URL: http://www.diplodock.com/Products/PasswordGenerator/default.aspx
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary: 

Diplodock Password Generator 2004 is a professional, random password generator that can produce 100,000 passwords, serial numbers, registration codes, masked strings, and usernames of any length and character content in seconds. With features such as built-in dictionaries, customizable character groups, password options module, randomization settings module, word-choice, and character density controls, it is extremely flexible, and allows you to create passwords that wil

6. CifsPwScanner 1.0.5
By: Patrik Karlsson
Relevant URL: http://www.cqure.net/tools/cifspwscan-bin-1_0_5.tar.gz
Platforms: Java
Summary: 

A CIFS/SMB password scanner based on the jcifs implementation. The scanner and jcifs are both 100% pure java, making it possible to run the scanner on a few different platforms.  CifsPwScanner is released under the GPL Licence

V. SECURITYJOBS LIST SUMMARY
----------------------------
1. [SJ-JOB] Security Architect, Zurich, CH (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374945

2. [SJ-JOB] VP of Regional Sales, Dublin, IE (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374944

3. [SJ-JOB] Security Consultant, Metro Detroit, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374933

4. [SJ-JOB] Developer, Boulder, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374880

5. [SJ-JOB] Security Consultant, Flanders, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374879

6. [SJ-JOB] Customer Support, Santa Monica, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374828

7. [SJ-JOB] Sales Engineer, Indianapolis, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374819

8. [SJ-JOB] Security Auditor, Charlotte, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374786

9. [SJ-JOB] VP of Regional Sales, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374784

10. [SJ-JOB] Account Manager, Ettelbruck, LU (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374782

11. [SJ-JOB] VP of Marketing, Boston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374775

12. [SJ-JOB] VP of Regional Sales, Paris, FR (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374772

13. [SJ-JOB] Security Engineer, Boston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374758

14. [SJ-JOB] Sales Engineer, NY, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374757

15. [SJ-JOB] Security Engineer, Arlington, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374744

16. [SJ-JOB] Sales Engineer, New York, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374741

17. [SJ-JOB] Developer, Annapolis, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374736

18. [SJ-JOB] Account Manager, Redwood Shores, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374735

19. [SJ-JOB] Security Product Manager, Boston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374721

20. [SJ-JOB] Sr. Security Engineer, Cardiff, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374690

21. [SJ-JOB] Security Consultant, San Diego, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374682

22. [SJ-JOB] Account Manager, Flexible, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374667

23. [SJ-JOB] Security Engineer, Clarksburg, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374662

24. [SJ-JOB] Security Engineer, Alexandria, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374661

25. [SJ-JOB] Security Architect, Boston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374655

26. [SJ-JOB] Sales Engineer, Santa Clara, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374628

27. [SJ-JOB] Account Manager, Kirkland (Seattle), US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374606

28. [SJ-JOB] Quality Assurance, Herndon, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374580

29. [SJ-JOB] Security Product Manager, dublin, IE (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374571

30. [SJ-JOB] Sr. Security Analyst, Basel, CH (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374563

31. [SJ-JOB] Sales Engineer, Englewood, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374529

32. [SJ-JOB] Developer, Austin, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374527

33. [SJ-JOB] Sales Engineer, Kirkland, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374514

34. [SJ-JOB] Security Engineer, Dearborn, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374511

35. [SJ-JOB] Security Auditor, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374495

36. [SJ-JOB] Developer, Denver, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374494

37. [SJ-JOB] Sr. Security Analyst, D.C., US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374471

38. [SJ-JOB] Developer, Dusseldorf, DE (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374467

39. [SJ-JOB] Manager, Information Security, San Marcos, ... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374465

40. [SJ-JOB] Sales Engineer, Chicago, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374450

41. [SJ-JOB] Application Security Engineer, London and S... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374438

42. [SJ-JOB] Security Engineer, Palo Alto, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374425

43. [SJ-JOB] VP of Regional Sales, Munich, DE (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374410

44. [SJ-JOB] Sr. Security Analyst, Boise, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374409

45. [SJ-JOB] Account Manager, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374408

46. [SJ-JOB] Application Security Engineer, New York, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374404

47. [SJ-JOB] VP of Regional Sales, London, NL (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374394

48. [SJ-JOB] Customer Support, San Jose, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374386

49. [SJ-JOB] Security Architect, Kirkland, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374385

50. [SJ-JOB] Manager, Information Security, Boston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374384

51. [SJ-JOB] Security Architect, NY, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/374383

VI. INCIDENTS LIST SUMMARY
--------------------------
1. Systems compromised with ShellBOT perl script - part... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/375147

2. Wireless router behaviour (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/375098

3. FW: [Intrusions] Linux SSH scanning - test/guest (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/375063

4. Odd mail traffic (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/374572

VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. challenge (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/375056

VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. RKDetect - behaviour based rootkit detection (update... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/375150

2. Windows/Exchange security auditing tool (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/375138

3. How to Recovering files encrypted with Microsoft EFS... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/375133

4. Windows2000 Security events (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/375130

5. Listing usernames via a null session on Windows XP (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/375122

6. XP-SP2 "Feature" (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/374946

7. Network Monitor/sniffer (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/374925

8. FW: Network Monitor/sniffer (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/374870

IX. SUN FOCUS LIST SUMMARY
--------------------------
1. allowing ordinary users to open privileged ports (Thread)
Relevant URL:

http://www.securityfocus.com/archive/92/375146

2. Solaris 9 authentication and access control into Act... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/92/375136

X. LINUX FOCUS LIST SUMMARY
---------------------------
1. rooted ? (Thread)
Relevant URL:

http://www.securityfocus.com/archive/91/375114

2. redhat patch problem? (Thread)
Relevant URL:

http://www.securityfocus.com/archive/91/374675

XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.
    
XII. SPONSOR INFORMATION
-----------------------

This Issue is Sponsored By: SecurityFocus 

Want to keep up on the latest security vulnerabilities? Don't have time to
visit a myriad of mailing lists and websites to read the news? Just add the
new SecurityFocus RSS feeds to your freeware RSS reader, and see all the
latest posts for Bugtraq and the SF Vulnernability database in one
convenient place. Or, pull in the latest news, columnists and feature
articles in the SecurityFocus aggregated news feed, and stay on top of
what's happening in the community!

http://www.securityfocus.com/rss/index.shtml

------------------------------------------------------------------------