SecurityFocus Newsletter #268

Peter Laborge <[email protected]> 28 Sep 2004 21:51:09 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #268
------------------------------

This Issue is Sponsored By: SecurityFocus 

Want to keep up on the latest security vulnerabilities? Don't have time to
visit a myriad of mailing lists and websites to read the news? Just add the
new SecurityFocus RSS feeds to your freeware RSS reader, and see all the
latest posts for Bugtraq and the SF Vulnernability database in one
convenient place. Or, pull in the latest news, columnists and feature
articles in the SecurityFocus aggregated news feed, and stay on top of
what's happening in the community!

http://www.securityfocus.com/rss/index.shtml

------------------------------------------------------------------------
I. FRONT AND CENTER
     1. Online Theft
     2. Detecting Worms and Abnormal Activities with NetFlow, Part 2
     3. Defeating Honeypots : Network issues, Part 1
II. BUGTRAQ SUMMARY
     1. Jörg Schilling SDD Remote Tape Support  Client Undisclosed V...
     2. Microsoft Windows CE KDatastruct Information Disclosure Vuln...
     3. ReMOSitory SQL Injection Vulnerability
     4. Mambo Open Source Multiple Input Validation Vulnerabilities
     5. Tutos Multiple Remote Input Validation Vulnerabilities
     6. FreeRADIUS Access-Request Denial Of Service Vulnerability
     7. Impressions Games Lords of the Realm III Nickname Remote Den...
     8. Getmail Local Symbolic Link Vulnerability
     9. Symantec ON Command CCM Remote Database Default Password Vul...
     10. EmuLive Server4 Authentication Bypass And Denial Of Service ...
     11. OpenBSD Radius Authentication Bypass Vulnerability
     12. Virtual Programming VP-ASP Denial Of Service Vulnerability
     13. Computer Associates Unicenter Management Portal Username Dis...
     14. LeadMind Pop Messenger Illegal Character Remote Denial Of Se...
     15. Jabber Studio JabberD Remote Denial Of Service Vulnerability
     16. Pinnacle ShowCenter Web Interface Skin Denial Of Service Vul...
     17. LaTeX2rtf Remote Buffer Overflow Vulnerability
     18. AllWebScripts MySQLGuest HTML Injection Vulnerability
     19. YaBB 1 Gold Multiple Input Validation Vulnerabilities
     20. Symantec Enterprise Firewall/VPN Appliance Multiple Remote V...
     21. Alt-N MDaemon IMAP/SMTP Server Multiple Remote Buffer Overfl...
     22. Apache Satisfy Directive Access Control Bypass Vulnerability
     23. Red Hat redhat-config-nfs Exported Shares Configuration Vuln...
     24. Motorola WR850G Wireless Router Remote Authentication Bypass...
     25. Inkra Router Virtual Service Switch Remote Denial Of Service...
     26. Subversion Mod_Authz_Svn Metadata Information Disclosure Vul...
     27. ActivePost Messenger Multiple Remote Vulnerabilities
     28. Macromedia JRun Multiple Remote Vulnerabilities
     29. Full Revolution aspWebCalendar and aspWebAlbum Multiple SQL ...
     30. Canon ImageRUNNER 5000 Printer Email Printing Vulnerability
     31. Zinf Malformed Playlist File Remote Buffer Overflow Vulnerab...
     32. HP StorageWorks Command View XP Unspecified Access Restricti...
III. SECURITYFOCUS NEWS ARTICLES
     1. U.N. warns of nuclear cyber attack risk
     2. Feds invite comment on Internet wiretaps
     3. Bill would narrow intruder surveillance
     4. House votes to make video cameras in movie theaters a federa...
     5. Schwarzenegger signs bill banning paperless voting systems
     6. Terrorists grow fat on email scams
IV. SECURITYFOCUS TOP 6 TOOLS
     1. ATK Plugin Creator 1.0
     2. PlugAPOP 1.00
     3. PIKT - Problem Informant/Killer Tool v1.17.0
     4. TX 1.0
     5. EPX Crypting Software 2.1
     6. Hacme Bank 1.0
V. SECURITYJOBS LIST SUMMARY
     1. [SJ-JOB] Sales Engineer, Bay Area, US (Thread)
     2. [SJ-JOB] VP of Regional Sales, Bay Area, US (Thread)
     3. [SJ-JOB] Security Consultant, Kansas City, US (Thread)
     4. [SJ-JOB] Security Product Manager, Boston, US (Thread)
     5. [SJ-JOB] Security Product Manager, Southern, US (Thread)
     6. [SJ-JOB] Security Engineer, Boston, US (Thread)
     7. [SJ-JOB] Security Researcher, Santa Monica, US (Thread)
     8. [SJ-JOB] Management, New Haven, US (Thread)
     9. [SJ-JOB] Account Manager, New York, US (Thread)
     10. [SJ-JOB] Jr. Security Analyst, Montreal area, CA (Thread)
     11. [SJ-JOB] Auditor, Montreal Region, CA (Thread)
     12. [SJ-JOB] Application Security Engineer, Kansas City,... (Thread)
     13. [SJ-JOB] Security Consultant, Montreal area, CA (Thread)
     14. [SJ-JOB] Security Consultant, London, GB (Thread)
     15. [SJ-JOB] Sr. Security Engineer, Kansas City, US (Thread)
     16. [SJ-JOB] Forensics Engineer, London, GB (Thread)
     17. [SJ-JOB] Account Manager, Jacksonville, US (Thread)
     18. [SJ-JOB] Security Director, London, GB (Thread)
     19. [SJ-JOB] Security Consultant, West Palm Beach, US (Thread)
     20. [SJ-JOB] Sales Engineer, Lexington, US (Thread)
     21. [SJ-JOB] Sr. Security Analyst, Herndon, US (Thread)
     22. [SJ-JOB] Account Manager, Anywhere, USA, US (Thread)
     23. [SJ-JOB] Sr. Security Engineer, Atlanta, US (Thread)
     24. [SJ-JOB] Security Consultant, Herndon, US (Thread)
     25. [SJ-JOB] Sr. Security Engineer, Boston, US (Thread)
     26. [SJ-JOB] Security Architect, London, GB (Thread)
     27. [SJ-JOB] Security Researcher, Boulder, US (Thread)
     28. [SJ-JOB] CHECK Team Leader, London and remote, GB (Thread)
     29. [SJ-JOB] Evangelist, various locations, US (Thread)
     30. [SJ-JOB] Security Consultant, Seattle, US (Thread)
     31. [SJ-JOB] Sales Engineer, Framingham, US (Thread)
     32. [SJ-JOB] Security Researcher, Reston, US (Thread)
     33. [SJ-JOB] Security Engineer, Herndon, US (Thread)
     34. [SJ-JOB] Quality Assurance, San Mateo, US (Thread)
     35. [SJ-JOB] Sales Engineer, Arlington, US (Thread)
     36. [SJ-JOB] Account Manager, San Francisco, US (Thread)
     37. [SJ-JOB] Security Engineer, Yardley, US (Thread)
     38. [SJ-JOB] Security Auditor, Phoenix, US (Thread)
     39. [SJ-JOB] Security Engineer, North East or DC Area, U... (Thread)
     40. [SJ-JOB] Security Researcher, New York, US (Thread)
     41. [SJ-JOB] Jr. Security Analyst, Herndon, US (Thread)
     42. [SJ-JOB] Sales Engineer, Houston OR Dallas, US (Thread)
VI. INCIDENTS LIST SUMMARY
     1. DoS/DDoS on port 1863(MSN protocol) (Thread)
     2. Port 7000 (Apple File Share) DoS/DDoS underway (Thread)
     3. Yahoo Account hacking (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. Help on hardware flaws (Thread)
     2. No body emails and Norton antivirus (Thread)
     3. ALPHA2 C Source (Thread)
     4. New XSS vulnerabilities in paFileDB 3.1 final (Thread)
     5. Multiple Vulnerabilities in Symantec Enterprise Fire... (Thread)
     6. More problems with handling remote cmd.exe shell (Thread)
     7. FreeBSD shellcode (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. Items within XP SP2 and Win2003 (Thread)
     2. VBScript to audit shares and share permissions (Thread)
     3. Serious Security Issue in Windows XP SP2's Firewall (Thread)
     4. Are MS Powerpoint's vulnerable to this JPEG Vuln? (Thread)
     5. Change password shortcut (Thread)
     6. Fw: Serious Security Issue in Windows XP SP2's Firew... (Thread)
     7. AW: Serious Security Issue in Windows XP SP2's Firew... (Thread)
     8. Application sniffer-next step (Thread)
     9. Hardening Desktop (Thread)
     10. How to Enforce Complex Password Policy for Selected ... (Thread)
     11. Restrict Anonymous (Thread)
     12. Application sniffer (Thread)
     13. Restrict Clinet IP address on Terminal Service (Thread)
     14. SecurityFocus Microsoft Newsletter #207 (Thread)
IX. SUN FOCUS LIST SUMMARY
     1. Security Configuration Settings? (Thread)
X. LINUX FOCUS LIST SUMMARY
     1. iptables & tcp wrappers (Thread)
     2. Network "Change Management" (Thread)
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION

I. FRONT AND CENTER
-------------------
1. Online Theft
By Kelly Martin

Identity theft meets the global virus epidemic, enabling fraud that has
finally started to get people's attention.

http://www.securityfocus.com/columnists/268


2. Detecting Worms and Abnormal Activities with NetFlow, Part 2
By Yiming Gong

This paper discusses the use of NetFlow, a traffic profile monitoring
technology available on many routers, for use in the early detection of
worms, spammers, and other abnormal network activity in large enterprise
networks and service providers. Part 2 of 2.

http://www.securityfocus.com/infocus/1802


3. Defeating Honeypots : Network issues, Part 1
By Laurent Oudot and Thorsten Holz

The purpose of this paper is to explain how attackers behave when they
attempt to identify and defeat honeypots, and is useful for security
professionals to deploy honeypots in a more stealthy manner.

http://www.securityfocus.com/infocus/1803

II. BUGTRAQ SUMMARY
-------------------
1. Jörg Schilling SDD Remote Tape Support  Client Undisclosed V...
BugTraq ID: 11217
Remote: Unknown
Date Published: Sep 18 2004
Relevant URL: http://www.securityfocus.com/bid/11217
Summary:
Jörg Schilling sdd is reported prone to an undisclosed vulnerability. The issue is reported to present itself in the RMT client.

This BID will be updated as soon as further analysis of this vulnerability is completed.

2. Microsoft Windows CE KDatastruct Information Disclosure Vuln...
BugTraq ID: 11218
Remote: No
Date Published: Sep 18 2004
Relevant URL: http://www.securityfocus.com/bid/11218
Summary:
An information disclosure vulnerability is reported to affect the Windows CE kernel.

It is reported that the kernel memory structure KDataStruct is available to userland applications. This can be ultimately employed on any Windows CE system to gain addresses of the export sections of several kernel libraries.

This vulnerability is exploited by the virus WinCE.Duts.A (MCID 3238) in order to provide portability and reliability.

3. ReMOSitory SQL Injection Vulnerability
BugTraq ID: 11219
Remote: Yes
Date Published: Sep 18 2004
Relevant URL: http://www.securityfocus.com/bid/11219
Summary:
It is reported that the ReMOSitory module for Mambo is prone to an SQL injection vulnerability. This issue is due to a failure of the module to properly validate user supplied URI input.

Because of this, a malicious user may influence database queries in order to view or modify sensitive information, potentially compromising the software or the database. It may be possible for an attacker to disclose the administrator password hash by exploiting this issue.

4. Mambo Open Source Multiple Input Validation Vulnerabilities
BugTraq ID: 11220
Remote: Yes
Date Published: Sep 20 2004
Relevant URL: http://www.securityfocus.com/bid/11220
Summary:
Mambo open source is reportedly affected by multiple input validation vulnerabilities.  These issues are due to a failure of the application to properly validate user-supplied URI parameters.

An attacker may leverage these issues to execute arbitrary server-side script code on an affected computer, to carry out cross-site scripting attacks, and to make SLQ injection attacks against the vulnerable application.

5. Tutos Multiple Remote Input Validation Vulnerabilities
BugTraq ID: 11221
Remote: Yes
Date Published: Sep 20 2004
Relevant URL: http://www.securityfocus.com/bid/11221
Summary:
Tutos is reported prone to multiple remote input validation vulnerabilities.  These issues exist due to insufficient sanitization of user-supplied data and may allow an attacker to carry out cross-site scripting and SQL injection attacks.

These issue reportedly affect Tutos 1.1.2004-04-14.

6. FreeRADIUS Access-Request Denial Of Service Vulnerability
BugTraq ID: 11222
Remote: Yes
Date Published: Sep 20 2004
Relevant URL: http://www.securityfocus.com/bid/11222
Summary:
Reportedly FreeRADIUS is affected by a remote denial of service vulnerability.  This issue is due to a failure of the application to handle malformed packets.

An attacker may leverage this issue to cause the affected server to crash, denying service to legitimate users.

7. Impressions Games Lords of the Realm III Nickname Remote Den...
BugTraq ID: 11223
Remote: Yes
Date Published: Sep 20 2004
Relevant URL: http://www.securityfocus.com/bid/11223
Summary:
A problem in the handling of nicknames is reported in the Lords of the Realm III server. Because of this, an attacker may be able to deny service to users of the game server.

The problem is in the handling of nicknames of excessive length.

It should be noted that this vulnerability only occurs when the server enters "lobby mode," which is a brief window of time before the initiation of a new game.

8. Getmail Local Symbolic Link Vulnerability
BugTraq ID: 11224
Remote: No
Date Published: Sep 20 2004
Relevant URL: http://www.securityfocus.com/bid/11224
Summary:
Reportedly getmail is affected by a local symbolic link vulnerability. This issue is due to a failure of the application to validate files prior to writing to them.

An attacker may leverage this issue to cause arbitrary files to be written to with the privileges of a user that sends messages to an attacker-controlled file.  This may facilitate privilege escalation or destruction of data.

9. Symantec ON Command CCM Remote Database Default Password Vul...
BugTraq ID: 11225
Remote: Yes
Date Published: Sep 21 2004
Relevant URL: http://www.securityfocus.com/bid/11225
Summary:
Reportedly Symantec ON Command CCM is affected by a remote default password vulnerability in the underlying database.  This issue is due to a design error in the application that provides a number of default usernames and passwords, some of which cannot be changed.

An attacker may exploit these issues to gain full access to the underlying database.  This will allow attackers to view plaintext user credentials as well as other sensitive data.

10. EmuLive Server4 Authentication Bypass And Denial Of Service ...
BugTraq ID: 11226
Remote: Yes
Date Published: Sep 21 2004
Relevant URL: http://www.securityfocus.com/bid/11226
Summary:
Reportedly EmuLive Server4 is affected by an authentication bypass vulnerability and a denial of service vulnerability.  These issues are due to an access validation issue and a failure to handle exceptional conditions.

An attacker may leverage the authentication bypass issue to gain unauthorized access to the administrator scripts of the affected application, facilitating manipulation of various server settings.  The denial of service issue may be exploited to cause the affected computer to freeze, denying service to legitimate users.

11. OpenBSD Radius Authentication Bypass Vulnerability
BugTraq ID: 11227
Remote: Yes
Date Published: Sep 21 2004
Relevant URL: http://www.securityfocus.com/bid/11227
Summary:
OpenBSD is reported prone to an authentication bypass vulnerability when using Radius authentication.  This issue can be leverage by spoofing traffic on a vulnerable network and carrying out a man-in-the-middle attack to gain unauthorized access to an OpenBSD computer.

This vulnerability arises if an OpenBSD computer is configured to use Radius authentication and may allow an attacker to gain unauthorized access to the OpenBSD computer.

The vulnerability is confirmed in OpenBSD 3.2 and OpenBSD 3.5.  Other versions may be vulnerable as well.

12. Virtual Programming VP-ASP Denial Of Service Vulnerability
BugTraq ID: 11228
Remote: Yes
Date Published: Sep 21 2004
Relevant URL: http://www.securityfocus.com/bid/11228
Summary:
It is reported that Virtual Programming VP-ASP is susceptible to a denial of service vulnerability.

This vulnerability allows an attacker to maintain connections to the database. It is conjectured that by exploiting this vulnerability multiple times, an attacker may be able to consume CPU resources, or possibly cause further database connections to fail. This will deny service to legitimate users.

This vulnerability is reported to affect version 5.0 of the package.

13. Computer Associates Unicenter Management Portal Username Dis...
BugTraq ID: 11229
Remote: Yes
Date Published: Sep 21 2004
Relevant URL: http://www.securityfocus.com/bid/11229
Summary:
Computer Associates Unicenter Management Portal has been reported vulnerable to an issue that may reveal valid usernames to an unauthenticated user.  The vulnerability exists in the "Forgot your Password?" link on the management portal interface.

14. LeadMind Pop Messenger Illegal Character Remote Denial Of Se...
BugTraq ID: 11230
Remote: Yes
Date Published: Sep 21 2004
Relevant URL: http://www.securityfocus.com/bid/11230
Summary:
LeadMind Pop Messenger is reported prone to a remote denial of service vulnerability. The issue exists because the messenger application fails to gracefully handle certain characters that are received.

A remote attacker may exploit this vulnerability to crash the LeadMind Pop Messenger client. Additionally, it is reported that an attacker may broadcast a malicious message to all clients on the connected local network segment and deny service to all of the clients at once.

15. Jabber Studio JabberD Remote Denial Of Service Vulnerability
BugTraq ID: 11231
Remote: Yes
Date Published: Sep 21 2004
Relevant URL: http://www.securityfocus.com/bid/11231
Summary:
Jabber Studio jabberd is reportedly affected by a remote denial of service vulnerability.  This issue is due to a failure of the application to properly handle malformed network messages.

An attacker may leverage this issue by causing the affected server to crash, denying service to legitimate users.

16. Pinnacle ShowCenter Web Interface Skin Denial Of Service Vul...
BugTraq ID: 11232
Remote: Yes
Date Published: Sep 21 2004
Relevant URL: http://www.securityfocus.com/bid/11232
Summary:
The Pinnacle Systems ShowCenter web-based interface is reported prone to a remote denial of service vulnerability. 

The issue exists due to a lack of sanity checks performed on the Skin parameter of a ShowCenter script.

It is reported that the affect of this attack will be persistent, any request for the ShowCenter web-based interface received subsequent to an attack will result in 'File or Folder not found' error message, as the interface fails to render.

A remote attacker may exploit this condition to persistently deny service to the ShowCenter web-based interface.

17. LaTeX2rtf Remote Buffer Overflow Vulnerability
BugTraq ID: 11233
Remote: Yes
Date Published: Sep 21 2004
Relevant URL: http://www.securityfocus.com/bid/11233
Summary:
It is reported that LaTeX2rtf is susceptible to a remote buffer overflow vulnerability when handling malformed files. This vulnerability may allow a remote attacker to execute arbitrary code on a vulnerable computer to gain unauthorized access. This issue is due to a failure of the application to perform proper bounds checks before copying data into a fixed sized memory buffer.

Version 1.9.15 of LaTeX2rtf is reported vulnerable to this issue. Other versions may also be affected.

18. AllWebScripts MySQLGuest HTML Injection Vulnerability
BugTraq ID: 11234
Remote: Yes
Date Published: Sep 22 2004
Relevant URL: http://www.securityfocus.com/bid/11234
Summary:
AllWebScripts MySQLGuest is reportedly affected by a remote HTML injection vulnerability.  This issue is due to a failure of the application to properly sanitize user-supplied input fields.

An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user, facilitating theft of cookie based authentication credentials as well as other attacks.

19. YaBB 1 Gold Multiple Input Validation Vulnerabilities
BugTraq ID: 11235
Remote: Yes
Date Published: Sep 22 2004
Relevant URL: http://www.securityfocus.com/bid/11235
Summary:
YaBB 1 Gold is affected by multiple input validation vulnerabilities.  These issues are due to a failure of the application to properly sanitize user-supplied input.

An attacker may leverage a cross-site scripting issue to execute arbitrary HTML and script code in the browser of an unsuspecting user in the context of the vulnerable site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

An attacker may exploit a HTTP response splitting issue to manipulate or misrepresent pages in the context of the vulnerable site, potentially facilitating phishing attacks.

20. Symantec Enterprise Firewall/VPN Appliance Multiple Remote V...
BugTraq ID: 11237
Remote: Yes
Date Published: Sep 22 2004
Relevant URL: http://www.securityfocus.com/bid/11237
Summary:
Symantec Enterprise Firewall/VPN Appliance is affected by multiple remote vulnerabilities.  These issues are due to a failure of the application to handle exceptional conditions, a default configuration issue exists as well.

An attacker can leverage a denial of service issue to cause the affected appliance to stop responding, requiring a power off to bring the device back to functionality.  A filter bypass issue allows an attacker to bypass the filters on the 'tftpd', 'snmpd', and 'isakmp' services.  An attacker can also read and write the community string of the affected device by default, facilitating disclosure and altering of the device's settings.

21. Alt-N MDaemon IMAP/SMTP Server Multiple Remote Buffer Overfl...
BugTraq ID: 11238
Remote: Yes
Date Published: Sep 22 2004
Relevant URL: http://www.securityfocus.com/bid/11238
Summary:
Alt-N MDaemon is reportedly prone to multiple remote buffer overflow vulnerabilities.  The vulnerabilities are likely due to a failure of the application to properly validate buffer sizes when processing command argument input.

By sending a large argument to certain SMTP commands or an IMAP command it is possible to cause this issue to present itself. Apparently, the application will not validate the size of the input before copying it into a finite buffer in process memory.

These issues can be leveraged to cause the affected process to crash, denying service to legitimate users.  It is conjectured that these issues can also be leveraged to execute arbitrary code with the privileges of the user running the server on an affected computer.

22. Apache Satisfy Directive Access Control Bypass Vulnerability
BugTraq ID: 11239
Remote: Yes
Date Published: Sep 23 2004
Relevant URL: http://www.securityfocus.com/bid/11239
Summary:
Apache Web Server is reportedly affected by an access control bypass vulnerability.  This issue presents itself due to an unspecified error in the merging of the 'Satisfy' directive.  As a result, a remote attacker may bypass access controls and gain unauthorized access to restricted resources.

It is reported that this issue only affects Apache 2.0.51.

Due to a lack of details, further information is not available at the moment.  This BID will be updated as more information becomes available.

23. Red Hat redhat-config-nfs Exported Shares Configuration Vuln...
BugTraq ID: 11240
Remote: Yes
Date Published: Sep 23 2004
Relevant URL: http://www.securityfocus.com/bid/11240
Summary:
Red Hat redhat-config-nfs is affected by an exported shares configuration vulnerability.  These issues are due to a failure of the application to apply proper settings to the affected network file system (NFS) shares.

This issue would cause some NFS option, such as 'all_squash' to fail to be applied, potentially giving administrators a false sense of security.

24. Motorola WR850G Wireless Router Remote Authentication Bypass...
BugTraq ID: 11241
Remote: Yes
Date Published: Sep 23 2004
Relevant URL: http://www.securityfocus.com/bid/11241
Summary:
Motorola WR850G wireless router is reported prone to a remote authentication bypass vulnerability.  This issue is caused by a design error and may allow an attacker to ultimately take complete control over the device.

A remote attacker can gain access to the Web interface of the affected device by periodically attempting to access restricted pages such as the 'ver.asp' script.

Motorola wireless router WR850G running firmware version 4.03 is reportedly affected by this issue.  It is possible that other models and firmware versions are affected as well.

25. Inkra Router Virtual Service Switch Remote Denial Of Service...
BugTraq ID: 11242
Remote: Yes
Date Published: Sep 23 2004
Relevant URL: http://www.securityfocus.com/bid/11242
Summary:
The Inkra Router Virtual Service Switch is affected by a remote denial of service vulnerability.  This issue is due to a failure of the application to handle exceptional network data.

An attacker may leverage this issue to cause the affected device to crash, denying service to legitimate users.

26. Subversion Mod_Authz_Svn Metadata Information Disclosure Vul...
BugTraq ID: 11243
Remote: Yes
Date Published: Sep 23 2004
Relevant URL: http://www.securityfocus.com/bid/11243
Summary:
It is reported that Subversions mod_authz_svn module is susceptible to an information disclosure vulnerability.

This vulnerability is presents itself when paths that are marked as unreadable are accessed by particular Subversion client commands. It is reportedly possible to disclose the existence of files that are inaccessible to users. Under certain circumstances it may also be possible to disclose commit log messages, or even the contents of files that are configured to be inaccessible to users.

This vulnerability is reported to exist in versions prior to 1.0.8 and 1.1.0-rc4.

27. ActivePost Messenger Multiple Remote Vulnerabilities
BugTraq ID: 11244
Remote: Yes
Date Published: Sep 23 2004
Relevant URL: http://www.securityfocus.com/bid/11244
Summary:
ActivePost Messenger is reportedly affected by multiple remote vulnerabilities.  These issues are due to a failure of the application to validate user-supplied input, a failure of the application to handle exceptional conditions, and a design error that fails to properly secure forum passwords.

The first issue is a denial of service issue.  An attacker may cause the affected server to crash with malformed network data, denying service to legitimate users.

The second issue will allow an attacker to upload files to arbitrary locations writable by the affected server application.

The final issue is due to a design error that transmits plaintext forum passwords across the network.

28. Macromedia JRun Multiple Remote Vulnerabilities
BugTraq ID: 11245
Remote: Yes
Date Published: Sep 24 2004
Relevant URL: http://www.securityfocus.com/bid/11245
Summary:
Multiple vulnerabilities have been reported in Macromedia JRun.

The first vulnerability is reported to exist in an insecure implementation of a session variable, 'JSESSIONID'. This vulnerability allows remote attackers to bypass authentication checks, and possibly allow them to gain administrative access to the web application.

The second issue is a source code disclosure vulnerability. This vulnerability allows attackers to retrieve the contents of potentially sensitive script files. This may aid them in further attacks.

The third issue is a buffer overflow vulnerability allowing remote attackers to reportedly crash affected servers.

Versions 3.0, 3.1, and 4.0 are reportedly affected by these vulnerabilities.

29. Full Revolution aspWebCalendar and aspWebAlbum Multiple SQL ...
BugTraq ID: 11246
Remote: Yes
Date Published: Sep 24 2004
Relevant URL: http://www.securityfocus.com/bid/11246
Summary:
Reportedly Full Revolution aspWebCalendar and aspWebAblum are affected by multiple SQL injection vulnerabilities.  These issues are due to a failure of the application to properly sanitize user-supplied input prior to including it in an SQL query.

An attacker may leverage these issues to manipulate SQL queries to the underlying database.  This may allow the attacker access to sensitive information, such as the administrator password, to corrupt data and to carry out other attacks.

30. Canon ImageRUNNER 5000 Printer Email Printing Vulnerability
BugTraq ID: 11247
Remote: Yes
Date Published: Sep 24 2004
Relevant URL: http://www.securityfocus.com/bid/11247
Summary:
The Canon imageRUNNER printer is a network based printer and photocopier designed to facilitate all small office printing requirements.

Canon imageRUNNER 5000 is reportedly vulnerable to an email printing vulnerability.  This issue is due to an access validation issue that fails to require authorization to have emails printed.

Reportedly it is impossible to disable the vulnerable email server feature.

An attacker may leverage this issue to print arbitrary text on an affected printer, potentially consuming resources and triggering a denial of service condition.

31. Zinf Malformed Playlist File Remote Buffer Overflow Vulnerab...
BugTraq ID: 11248
Remote: Yes
Date Published: Sep 24 2004
Relevant URL: http://www.securityfocus.com/bid/11248
Summary:
Zinf is reported prone to a remote buffer overflow vulnerability when processing malformed playlist files.  This issue exists due to insufficient boundary checks performed by the application and may allow an attacker to gain unauthorized access to a vulnerable computer.

Reportedly, this issue affects Zinf version 2.2.1 for Windows.  Zinf version 2.2.5 for Linux is reportedly fixed, however, this is not confirmed at the moment.

32. HP StorageWorks Command View XP Unspecified Access Restricti...
BugTraq ID: 11249
Remote: No
Date Published: Sep 24 2004
Relevant URL: http://www.securityfocus.com/bid/11249
Summary:
It is reported that HP StorageWorks Command View XP contains an access restriction bypass vulnerability. Specific details were not provided.

Reportedly, local attackers using the Command View XP software can bypass access restrictions to perform actions not authorized to them. This vulnerability is reported to only affect local use of the software from the management station, and not from either the web interface, or the command line interface.

All versions up to, and including version 1.8B of Command View XP on management stations included in the following devices are reported to be affected by this vulnerability:
- StorageWorks Disk Array XP48
- StorageWorks Disk Array XP128
- Surestore Disk Array XP256
- StorageWorks Disk Array XP1024

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. U.N. warns of nuclear cyber attack risk
By: Kevin Poulsen

The International Atomic Energy Agency warns of the possibility of plant sabotage by intruders and corrupt insiders.

http://www.securityfocus.com/news/9592

2. Feds invite comment on Internet wiretaps
By: Kevin Poulsen

U.S. regulators open a public comment period on a plan to wire broadband and VoIP systems for law enforcement surveillance.

http://www.securityfocus.com/news/9582

3. Bill would narrow intruder surveillance
By: Kevin Poulsen

Senate proposal would scale back a provision of the USA Patriot Act that lets the FBI monitor alleged computer trespassers without a warrant.
http://www.securityfocus.com/news/9565

4. House votes to make video cameras in movie theaters a federa...
By: Ted Bridis, The Associated Press

http://www.securityfocus.com/news/9599

5. Schwarzenegger signs bill banning paperless voting systems
By: Rachel Konrad, The Associated Press

http://www.securityfocus.com/news/9598

6. Terrorists grow fat on email scams
By: Jan Libbenga, The Register

Organisations such as al-Qaeda, ETA en PKK are copying Nigerian scams to fund terrorism, two Dutch experts told Dutch daily De Telegraaf this week.

http://www.securityfocus.com/news/9596

IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. ATK Plugin Creator 1.0
By: Nico 'Triplex' Spicher
Relevant URL: http://www.computec.ch/projekte/atk/
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary: 

This freeware for Windows provides a small and handy interface to create and enhance ATK plugins. This first public release is fully compatible with ATK 2.x but can also be used with ATK 1.x (some new fields are not fully supported in the first releases).

2. PlugAPOP 1.00
By: waffle soft
Relevant URL: http://www.wafflesoft.com/PlugAPOP/manual_en.html
Platforms: Windows XP
Summary: 

PlugAPOP is software to use APOP feature in Microsoft Outlook/Outlook Express which doesn't have APOP feature.

[Easy]
You can install and setup very easily. You can use APOP access immediately if you change the account name and server name field in your e-mail client. No special settings are needed in PlugAPOP.

[Tiny]
PlugAPOP doesn't waste a lot of CPU resource and memory, it doesn't effect to OS core and other application. PlugAPOP is implemented by using just SD

3. PIKT - Problem Informant/Killer Tool v1.17.0
By: Robert Osterlund, [email protected]
Relevant URL: http://pikt.org
Platforms: AIX, FreeBSD, HP-UX, IRIX, Linux, Solaris, SunOS
Summary: 

PIKT is a cross-categorical, multi-purpose toolkit to monitor and configure computer systems, organize system security, format documents, assist command-line work, and perform other common systems administration tasks.

PIKT's primary purpose is to report and fix problems, but its flexibility and extendibility evoke many other uses limited only by your imagination.

4. TX 1.0
By: Goldie Rejuven
Relevant URL: http://www.checksum.org/download/RX/
Platforms: Windows 2000, Windows NT, Windows XP
Summary: 

The Smallest VC++ Coded Universal Windows Reverse Shell for all versions of Windows NT/2K/XP/2003 with any service pack. But not for Windows 98/ME. A Tini app that connects back to the specified IP to a fixedport and uses a fixed source port on the source machine to evade the firewalls.

Default port from which it connects :443
Default port to which it connects is :8080
More on the readme.txt

5. EPX Crypting Software 2.1
By: EdronSoft
Relevant URL: http://www.edronsoft.com/epx_pro.php
Platforms: Windows XP
Summary: 

Protect your documents from others by encrypting them with DES and Triple DES strong algorithms. No need to remember passwords because you keep the key used for the decryption in a removable media device such as usb pen-drive (or floppy disk).
Wipe function to destroy data and full Drag'N Drop support.

6. Hacme Bank 1.0
By: Mark Curphey / Rudolph Araujo
Relevant URL: http://www.foundstone.com/s3i
Platforms: Windows XP
Summary: 

A web application security training application

V. SECURITYJOBS LIST SUMMARY
----------------------------
1. [SJ-JOB] Sales Engineer, Bay Area, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376696

2. [SJ-JOB] VP of Regional Sales, Bay Area, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376693

3. [SJ-JOB] Security Consultant, Kansas City, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376658

4. [SJ-JOB] Security Product Manager, Boston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376639

5. [SJ-JOB] Security Product Manager, Southern, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376633

6. [SJ-JOB] Security Engineer, Boston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376631

7. [SJ-JOB] Security Researcher, Santa Monica, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376619

8. [SJ-JOB] Management, New Haven, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376613

9. [SJ-JOB] Account Manager, New York, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376599

10. [SJ-JOB] Jr. Security Analyst, Montreal area, CA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376597

11. [SJ-JOB] Auditor, Montreal Region, CA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376593

12. [SJ-JOB] Application Security Engineer, Kansas City,... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376544

13. [SJ-JOB] Security Consultant, Montreal area, CA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376543

14. [SJ-JOB] Security Consultant, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376542

15. [SJ-JOB] Sr. Security Engineer, Kansas City, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376537

16. [SJ-JOB] Forensics Engineer, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376533

17. [SJ-JOB] Account Manager, Jacksonville, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376530

18. [SJ-JOB] Security Director, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376367

19. [SJ-JOB] Security Consultant, West Palm Beach, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376344

20. [SJ-JOB] Sales Engineer, Lexington, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376335

21. [SJ-JOB] Sr. Security Analyst, Herndon, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376243

22. [SJ-JOB] Account Manager, Anywhere, USA, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376236

23. [SJ-JOB] Sr. Security Engineer, Atlanta, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376228

24. [SJ-JOB] Security Consultant, Herndon, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376224

25. [SJ-JOB] Sr. Security Engineer, Boston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376219

26. [SJ-JOB] Security Architect, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376187

27. [SJ-JOB] Security Researcher, Boulder, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376185

28. [SJ-JOB] CHECK Team Leader, London and remote, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376157

29. [SJ-JOB] Evangelist, various locations, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376153

30. [SJ-JOB] Security Consultant, Seattle, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376136

31. [SJ-JOB] Sales Engineer, Framingham, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376135

32. [SJ-JOB] Security Researcher, Reston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376111

33. [SJ-JOB] Security Engineer, Herndon, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376096

34. [SJ-JOB] Quality Assurance, San Mateo, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376084

35. [SJ-JOB] Sales Engineer, Arlington, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376072

36. [SJ-JOB] Account Manager, San Francisco, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376068

37. [SJ-JOB] Security Engineer, Yardley, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376066

38. [SJ-JOB] Security Auditor, Phoenix, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376065

39. [SJ-JOB] Security Engineer, North East or DC Area, U... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376063

40. [SJ-JOB] Security Researcher, New York, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376059

41. [SJ-JOB] Jr. Security Analyst, Herndon, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376050

42. [SJ-JOB] Sales Engineer, Houston OR Dallas, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/376047

VI. INCIDENTS LIST SUMMARY
--------------------------
1. DoS/DDoS on port 1863(MSN protocol) (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/376641

2. Port 7000 (Apple File Share) DoS/DDoS underway (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/376146

3. Yahoo Account hacking (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/375937

VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Help on hardware flaws (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/376600

2. No body emails and Norton antivirus (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/376487

3. ALPHA2 C Source (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/376379

4. New XSS vulnerabilities in paFileDB 3.1 final (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/376376

5. Multiple Vulnerabilities in Symantec Enterprise Fire... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/376375

6. More problems with handling remote cmd.exe shell (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/375990

7. FreeBSD shellcode (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/375989

VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. Items within XP SP2 and Win2003 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/376680

2. VBScript to audit shares and share permissions (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/376653

3. Serious Security Issue in Windows XP SP2's Firewall (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/376510

4. Are MS Powerpoint's vulnerable to this JPEG Vuln? (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/376476

5. Change password shortcut (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/376472

6. Fw: Serious Security Issue in Windows XP SP2's Firew... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/376465

7. AW: Serious Security Issue in Windows XP SP2's Firew... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/376386

8. Application sniffer-next step (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/376364

9. Hardening Desktop (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/376286

10. How to Enforce Complex Password Policy for Selected ... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/376209

11. Restrict Anonymous (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/376181

12. Application sniffer (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/376106

13. Restrict Clinet IP address on Terminal Service (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/376085

14. SecurityFocus Microsoft Newsletter #207 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/376011

IX. SUN FOCUS LIST SUMMARY
--------------------------
1. Security Configuration Settings? (Thread)
Relevant URL:

http://www.securityfocus.com/archive/92/376532

X. LINUX FOCUS LIST SUMMARY
---------------------------
1. iptables & tcp wrappers (Thread)
Relevant URL:

http://www.securityfocus.com/archive/91/376739

2. Network "Change Management" (Thread)
Relevant URL:

http://www.securityfocus.com/archive/91/376456

XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.
    
XII. SPONSOR INFORMATION
-----------------------

This Issue is Sponsored By: SecurityFocus 

Want to keep up on the latest security vulnerabilities? Don't have time to
visit a myriad of mailing lists and websites to read the news? Just add the
new SecurityFocus RSS feeds to your freeware RSS reader, and see all the
latest posts for Bugtraq and the SF Vulnernability database in one
convenient place. Or, pull in the latest news, columnists and feature
articles in the SecurityFocus aggregated news feed, and stay on top of
what's happening in the community!

http://www.securityfocus.com/rss/index.shtml

------------------------------------------------------------------------