SecurityFocus Newsletter #269
Peter Laborge <[email protected]> 5 Oct 2004 17:29:22 -0000
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #269
------------------------------
This Issue is Sponsored By: SecurityFocus
Stay up to date. All the latest news, columns, jobs and more in a
convenient html newsletter - Even a glimpse of upcoming columns and feature
articles! Sign up today!
http://www.securityfocus.com/htmlnewsletter/subscribe
------------------------------------------------------------------------
I. FRONT AND CENTER
1. Lessons Learned from Virus Infections
2. Strike One!
II. BUGTRAQ SUMMARY
1. BroadBoard Message Board Multiple SQL Injection Vulnerabilit...
2. Microsoft GDI+ Library Malformed JPEG Handling Unspecified D...
3. Baal Systems Portal Software Authentication Bypass Vulnerabi...
4. PD9 Software MegaBBS Multiple Vulnerabilities
5. MyWebServer Multiple Remote Vulnerabilities
6. Slava Astashonok Fprobe Unspecified Local Vulnerability
7. YahooPOPS! Multiple Remote Buffer Overflow Vulnerabilities
8. Nettica Corporation INTELLIPEER Email Server User Account En...
9. Multiple Vendor TCP Packet Fragmentation Handling Denial Of ...
10. Symantec Norton AntiVirus Malformed EMail Denial Of Service ...
11. @lexPHPTeam @lex Guestbook Remote PHP File Include Vulnerabi...
12. MySQL Bounded Parameter Statement Execution Remote Buffer Ov...
13. Debian GNU/Linux Sendmail Package Default SASL Password Vuln...
14. Virtual Projects Chatma Denial Of Service Vulnerability
15. IBM CTSTRTCASD Utility Local File Corruption Vulnerability
16. Microsoft SQL Server Remote Denial Of Service Vulnerability
17. Illustrate dBpowerAMP Music Converter and Audio Player Buffe...
18. Vignette Application Portal Remote Information Disclosure Vu...
19. Wordpress Multiple Cross-Site Scripting Vulnerabilities
20. Serendipity Multiple Input Validation Vulnerabilities
21. XMLStarlet Command Line XML Toolkit Multiple Unspecified Buf...
22. Icecast Server HTTP Header Buffer Overflow Vulnerability
23. ParaChat Directory Traversal Vulnerability
24. PeopleSoft Human Resources Management System Cross-Site Scri...
25. SGI IRIX T_Bind/T_UnBind Undisclosed Vulnerability
26. Computer Associates Unicenter Common Services Plaintext Pass...
27. SGI IRIX Undisclosed ARP Handling Vulnerability
28. Playlogic Alpha Black Zero Remote Denial Of Service Vulnerab...
29. Freenet6 Client Default Installation Configuration File Perm...
30. Samba Remote Arbitrary File Access Vulnerability
31. GNU GetText Unspecified Insecure Temporary File Creation Vul...
32. W-Agora Multiple Remote Input Validation Vulnerabilities
33. Silent-Storm Portal Multiple Input Validation Vulnerabilitie...
34. GhostScript Unspecified Insecure Temporary File Creation Vul...
35. GNU GLibC Unspecified Insecure Temporary File Creation Vulne...
36. GNU Troff (Groff) Unspecified Insecure Temporary File Creati...
37. GNU GZip Unspecified Insecure Temporary File Creation Vulner...
38. MIT Kerberos 5 Unspecified Insecure Temporary File Creation ...
39. Trustix LVM Utilities Unspecified Insecure Temporary File Cr...
40. MySQL Unspecified Insecure Temporary File Creation Vulnerabi...
41. NetaTalk Unspecified Insecure Temporary File Creation Vulner...
42. OpenSSL Unspecified Insecure Temporary File Creation Vulnera...
43. Perl Unspecified Insecure Temporary File Creation Vulnerabil...
44. PostgreSQL Unspecified Insecure Temporary File Creation Vuln...
45. PHP-Fusion Multiple SQL and HTML Injection Vulnerabilities
46. HP LaserJet 4200/4300 Printer Arbitrary Firmware Upgrade Vul...
47. GNU Sharutils Multiple Buffer Overflow Vulnerabilities
48. Proxytunnel Local Proxy Credential Disclosure Vulnerability
49. Kerio MailServer Unspecified Vulnerability
50. AJ-Fork Insecure Default Permissions Vulnerability
51. MediaWiki Raw Page Cross-Site Scripting Vulnerability
52. BBlog RSS.PHP SQL Injection Vulnerability
53. Real Estate Management Software Multiple Unspecified Vulnera...
54. Online-Bookmarks Authentication Bypass Vulnerability
55. Recruitment Agency Software Unspecified Security Vulnerabili...
56. RealNetworks RealOne Player And RealPlayer Unspecified Web P...
57. RealNetworks RealOne Player And RealPlayer Unspecified File ...
58. RealNetworks RealOne Player And RealPlayer PNen3260.DLL Remo...
59. VyPRESS Messenger Remote Buffer Overflow Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
1. Warspammer guilty under new federal law
2. U.N. warns of nuclear cyber attack risk
3. Feds invite comment on Internet wiretaps
4. Hackers attack Dutch government Web sites
5. McAfee in BitDefender virus slur spat
6. WorldPay struggles under DDoS attack (again)
IV. SECURITYFOCUS TOP 6 TOOLS
1. XArp 0.1.5
2. Extreme Editor: 5.2.2
3. ATK Plugin Creator 1.0
4. PlugAPOP 1.00
5. PIKT - Problem Informant/Killer Tool v1.17.0
6. TX 1.0
V. SECURITYJOBS LIST SUMMARY
1. [SJ-JOB] Management, Baltimore, US (Thread)
2. [SJ-JOB] VP of Marketing, Baltimore, US (Thread)
3. [SJ-JOB] Technical Writer, Washington, DC, US (Thread)
4. [SJ-JOB] Security Architect, New York, US (Thread)
5. [SJ-JOB] Security Engineer, New York, US (Thread)
6. [SJ-JOB] Auditor, Chicago, US (Thread)
7. [SJ-JOB] Manager, Information Security, Greenville, ... (Thread)
8. [SJ-JOB] Certification & Accreditation Engineer, Gai... (Thread)
9. [SJ-JOB] Sr. Security Analyst, Minneapolis, US (Thread)
10. [SJ-JOB] Sr. Security Analyst, Gaithersburg, US (Thread)
11. [SJ-JOB] Security Auditor, San Antonio, US (Thread)
12. [SJ-JOB] Security Consultant, Paramus and/or Asbury ... (Thread)
13. [SJ-JOB] Sr. Security Engineer, Bay Area, US (Thread)
14. [SJ-JOB] Security Consultant, Parsippany, US (Thread)
15. [SJ-JOB] Account Manager, Cincinnati, US (Thread)
16. [SJ-JOB] Quality Assurance, Santa Monica, US (Thread)
17. [SJ-JOB] Quality Assurance, Redwood City (650), US (Thread)
18. [SJ-JOB] Management, London, GB (Thread)
19. [SJ-JOB] Sales Engineer, DC, US (Thread)
20. [SJ-JOB] Account Manager, fort lauderdale, US (Thread)
21. [SJ-JOB] Sr. Security Engineer, Hillsboro, US (Thread)
22. [SJ-JOB] Sr. Product Manager, Redwood City, US (Thread)
23. [SJ-JOB] Security System Administrator, Fort Lauderd... (Thread)
24. [SJ-JOB] Sr. Security Analyst, Indianapolis, US (Thread)
25. [SJ-JOB] Security Architect, Saint Louis, US (Thread)
26. [SJ-JOB] Sr. Security Engineer, Saint Louis, US (Thread)
27. [SJ-JOB] Account Manager, Atlanta, US (Thread)
28. [SJ-JOB] Security Engineer, Sacramento, US (Thread)
29. [SJ-JOB] Account Manager, Redwood City, US (Thread)
30. [SJ-JOB] Sales Engineer, Chicago, US (Thread)
VI. INCIDENTS LIST SUMMARY
1. Data Cha0s PHP script attempt (Thread)
2. DllTrojan ? (Thread)
3. Localhost packets on WAN (Thread)
4. data payload in SYN ( DoS/DDoS on port 1863(MSN prot... (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
1. Kaspersky AntiVirus Window Caption GUI Bypass Vulner... (Thread)
2. Help on hardware flaws (Thread)
3. No body emails and Norton antivirus (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
1. MS ISA activeX Filtering (Thread)
2. Tool for removing LANMAN hashes from registry (Thread)
3. Items within XP SP2 and Win2003 (Thread)
4. Application sniffer-next step (Thread)
5. Fw: Serious Security Issue in Windows XP SP2's Firew... (Thread)
6. SecurityFocus Microsoft Newsletter #208 (Thread)
7. VBScript to audit shares and share permissions (Thread)
8. Hardening Desktop (Thread)
9. Serious Security Issue in Windows XP SP2's Firewall (Thread)
10. Win2k3 IIS6.0 Port 4531 (Thread)
IX. SUN FOCUS LIST SUMMARY
1. Security Configuration Settings? (Thread)
X. LINUX FOCUS LIST SUMMARY
1. iptables & tcp wrappers (Thread)
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. Lessons Learned from Virus Infections
By Jason Gordon
This article discusses how a virus outbreak will produce a few unique
opportunities to examine the health of an organization's network -- and
learn ways to further harden the network from future automated attacks.
http://www.securityfocus.com/infocus/1804
2. Strike One!
By Mark Rasch
A New York judge did the right thing last week when he threw out a
USA-PATRIOT Act provision that forced ISPs to secretly cooperate with the
FBI, and gave them no obvious avenue for appeal.
http://www.securityfocus.com/columnists/270
II. BUGTRAQ SUMMARY
-------------------
1. BroadBoard Message Board Multiple SQL Injection Vulnerabilit...
BugTraq ID: 11250
Remote: Yes
Date Published: Sep 27 2004
Relevant URL: http://www.securityfocus.com/bid/11250
Summary:
Reportedly BroadBoard Message Board is affected by multiple SQL injection vulnerabilities. These issues are due to a failure of the application to properly sanitize user supplied URI input prior to using it in an SQL query.
An attacker may exploit these issues to manipulate SQL queries, potentially revealing or corrupting sensitive database data. These issues may also facilitate attacks against the underlying database software.
2. Microsoft GDI+ Library Malformed JPEG Handling Unspecified D...
BugTraq ID: 11251
Remote: Yes
Date Published: Sep 27 2004
Relevant URL: http://www.securityfocus.com/bid/11251
Summary:
The Microsoft (Graphics Device Interface) GDI+ library is reported prone to an unspecified denial of service vulnerability when handling malformed JPEG files.
This issue is reported to present itself due to the dereferencing of a NULL pointer.
Due to a lack of details, further information is not available at the moment. This BID will be updated as more information becomes available.
3. Baal Systems Portal Software Authentication Bypass Vulnerabi...
BugTraq ID: 11252
Remote: Yes
Date Published: Sep 27 2004
Relevant URL: http://www.securityfocus.com/bid/11252
Summary:
Reportedly Baal Systems Portal Software is affected by a remote authentication bypass vulnerability. This issue is due to a failure of the application to properly manage administrator account creation.
This issue will allow an attacker to register a new administrator user, giving the attacker full admin access to the affected application.
4. PD9 Software MegaBBS Multiple Vulnerabilities
BugTraq ID: 11253
Remote: Yes
Date Published: Sep 27 2004
Relevant URL: http://www.securityfocus.com/bid/11253
Summary:
MegaBBS is reported prone to multiple vulnerabilities. These issues exist due to insufficient sanitization of user-supplied data and may allow an attacker to carry out HTTP response splitting and SQL injection attacks.
MegaBBS versions 2.0 and 2.1 are reported prone to these issues.
5. MyWebServer Multiple Remote Vulnerabilities
BugTraq ID: 11254
Remote: Yes
Date Published: Sep 27 2004
Relevant URL: http://www.securityfocus.com/bid/11254
Summary:
MyWebServer is reported prone to multiple remote vulnerabilities. These issues include a remote denial of service condition and administrative access to the server.
MyWebServer 1.0.3 is reported to be affected by these issues. It is possible that other versions are vulnerable as well.
6. Slava Astashonok Fprobe Unspecified Local Vulnerability
BugTraq ID: 11255
Remote: No
Date Published: Sep 27 2004
Relevant URL: http://www.securityfocus.com/bid/11255
Summary:
fprobe is reported prone to an unspecified local vulnerability. This issue exists in the 'change user' feature of the application. Further details are not available at the moment. This BID will be updated as more information becomes available.
fprobe 1.0.5 and prior versions are reported to be affected.
7. YahooPOPS! Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 11256
Remote: Yes
Date Published: Sep 27 2004
Relevant URL: http://www.securityfocus.com/bid/11256
Summary:
It is reported that YahooPOPS! contains multiple buffer overflow vulnerabilities. These vulnerabilities are due to a failure of the application to properly bounds check user-supplied input data before copying it into finite sized memory buffers. This allows attackers to overwrite adjacent memory, potentially overwriting critical memory structures and altering the flow of execution. This will likely allow for remote code execution in the context of the affected application.
Versions of YahooPOPS! from 0.4 through to, and including 0.6 are reportedly affected by these vulnerabilities.
8. Nettica Corporation INTELLIPEER Email Server User Account En...
BugTraq ID: 11257
Remote: Yes
Date Published: Sep 27 2004
Relevant URL: http://www.securityfocus.com/bid/11257
Summary:
Intellipeer email server is reported prone to a user account enumeration vulnerability. An attacker can disclose valid user accounts and then carry out other attacks against vulnerable users.
Intellipeer email server version 1.01 is reported to be affected by this issue.
9. Multiple Vendor TCP Packet Fragmentation Handling Denial Of ...
BugTraq ID: 11258
Remote: Yes
Date Published: Sep 27 2004
Relevant URL: http://www.securityfocus.com/bid/11258
Summary:
Multiple vendor implementations of the TCP stack are reported prone to a remote denial of service vulnerability.
The issue is reported to present itself due to inefficiencies present when handling fragmented TCP packets.
The discoverer of this issue has dubbed the attack style the "New Dawn attack", it is a variation of a previously reported attack that was named the "Rose Attack".
This vulnerability may aid a remote attacker in impacting resources on an affected computer. Specifically, a remote attacker may exploit this vulnerability to deny service to a vulnerable computer.
Microsoft Windows 2000/XP, Linux kernel 2.4 tree and undisclosed Cisco systems are reported prone to this vulnerability other products may also be affected.
10. Symantec Norton AntiVirus Malformed EMail Denial Of Service ...
BugTraq ID: 11259
Remote: Yes
Date Published: Sep 27 2004
Relevant URL: http://www.securityfocus.com/bid/11259
Summary:
It is alleged that Symantec Norton AntiVirus is prone to a denial of service vulnerability.
The discoverer of this issue reports that when a malformed email is received through Microsoft Outlook and Norton AntiVirus attempts to process this email, the Norton AntiVirus application will crash.
Symantec is currently investigating this report; this BID will be updated as soon as this investigation is complete. It should also be noted that the discoverer of the issue has not provided any details about which versions may be affected by this issue, version information will be updated appropriately when this issue is investigated further.
11. @lexPHPTeam @lex Guestbook Remote PHP File Include Vulnerabi...
BugTraq ID: 11260
Remote: Yes
Date Published: Sep 27 2004
Relevant URL: http://www.securityfocus.com/bid/11260
Summary:
A vulnerability is reported to exist in the @lexPHPTeam @lex Guestbook software that may allow an attacker to include malicious PHP files containing arbitrary code to be executed on a vulnerable system. The issue exists due to improper validation of user-supplied data.
Remote attackers could potentially exploit this issue via a vulnerable variable to include a remote malicious PHP script, which will be executed in the context of the web server hosting the vulnerable software.
12. MySQL Bounded Parameter Statement Execution Remote Buffer Ov...
BugTraq ID: 11261
Remote: Yes
Date Published: Sep 27 2004
Relevant URL: http://www.securityfocus.com/bid/11261
Summary:
It is reported that MySQL is susceptible to a buffer overflow vulnerability. This issue is due to a failure of the application to properly ensure the size of a buffer is sufficient to handle user-supplied input data before performing operations that may overflow into adjacent memory regions.
This vulnerability reportedly allows for remote attackers to crash affected servers. It is unconfirmed, but there may be a possibility of remote code execution in the context of the affected server. It would likely require a complex exploit, in order to take advantage of overwriting memory contents with NULL bytes. Attackers may be able to take advantage of the structured, predictable nature of the memory operations in order to control the flow of execution of the application.
MySQL versions 4.1.3-beta and 4.1.4 are reported vulnerable, but other versions are also likely affected.
13. Debian GNU/Linux Sendmail Package Default SASL Password Vuln...
BugTraq ID: 11262
Remote: Yes
Date Published: Sep 27 2004
Relevant URL: http://www.securityfocus.com/bid/11262
Summary:
It is reported that the Sendmail package contained in the Debian GNU/Linux operating system is prone to a default password vulnerability, potentially allowing unauthorized use of the Sendmail MTA. This would likely facilitate UCE (Unsolicited Commercial Email, or SPAM) message relaying through affected installations.
Versions of the Debian Sendmail packages prior to 8.12.3-7.1 for Debian stable (woody), and versions prior to 8.13.1-13 for Debian unstable (sid) are reported vulnerable.
14. Virtual Projects Chatma Denial Of Service Vulnerability
BugTraq ID: 11263
Remote: Yes
Date Published: Sep 27 2004
Relevant URL: http://www.securityfocus.com/bid/11263
Summary:
Virtual Projects Chatman is affected by a denial of service vulnerability. This issue is due to a failure of the application to handle exceptional conditions.
An attacker can leverage this issue to cause the affected application to crash, denying service to legitimate users.
15. IBM CTSTRTCASD Utility Local File Corruption Vulnerability
BugTraq ID: 11264
Remote: No
Date Published: Sep 27 2004
Relevant URL: http://www.securityfocus.com/bid/11264
Summary:
It is reported that IBMs 'ctstrtcasd' utility is susceptible to a local file corruption vulnerability. This issue is due to a failure of the application to properly validate the permissions of the invoking user before overwriting a file specified by the user. This utility is setuid to the superuser, allowing for the overwriting of any file on affected computers, or the creation of files in any location.
As this vulnerability allows attackers to overwrite arbitrary files with superuser privileges, attackers have the ability to destroy data, or cause the computer to fail in such a manner that it will have to be reinstalled from backups. This will deny service to legitimate users.
RSCT versions 2.3.0.0 and higher running on AIX 5.2 and 5.3 on pSeries, AIX on i5/OS (iSeries), Linux (pSeries, xSeries, zSeries), and pSeries/iSeries Hardware Management Console are reported vulnerable.
16. Microsoft SQL Server Remote Denial Of Service Vulnerability
BugTraq ID: 11265
Remote: Yes
Date Published: Sep 28 2004
Relevant URL: http://www.securityfocus.com/bid/11265
Summary:
Reportedly Microsoft SQL Server is affected by a remote denial of service vulnerability. This issue is due to a failure of the application to handle irregular network communications.
An attacker may leverage this issue to cause the affected server to crash, denying service to legitimate users.
17. Illustrate dBpowerAMP Music Converter and Audio Player Buffe...
BugTraq ID: 11266
Remote: Yes
Date Published: Sep 28 2004
Relevant URL: http://www.securityfocus.com/bid/11266
Summary:
dBpowerAMP Music Converter and Audio Player reported prone to remote buffer overflow vulnerabilities when processing malformed audio and playlist files. This issues exists due to insufficient boundary checks performed by the applications and may allow an attacker to gain unauthorized access to a vulnerable computer.
Reportedly, these issues affect dBPowerAmp Music Converter 10.0 and Audio Player 2.0. Other versions may be vulnerable as well.
18. Vignette Application Portal Remote Information Disclosure Vu...
BugTraq ID: 11267
Remote: Yes
Date Published: Sep 28 2004
Relevant URL: http://www.securityfocus.com/bid/11267
Summary:
Vignette Application Portal is affected by a remote information disclosure vulnerability. This issue is due to a design error that facilitates unauthorized access to sensitive information.
An attacker can leverage this issue to reveal sensitive information such as operating system version, application version, database connection parameters, and various other application portal related setting details.
19. Wordpress Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 11268
Remote: Yes
Date Published: Sep 28 2004
Relevant URL: http://www.securityfocus.com/bid/11268
Summary:
It is reported that Wordpress is affected by various cross-site scripting vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied URI input.
Wordpress 1.2 is reported vulnerable, however, other versions may be affected as well.
20. Serendipity Multiple Input Validation Vulnerabilities
BugTraq ID: 11269
Remote: Yes
Date Published: Sep 28 2004
Relevant URL: http://www.securityfocus.com/bid/11269
Summary:
It is reported that Serendipity is susceptible to multiple cross-site scripting and SQL injection vulnerabilities.
The cross-site scripting issues present themselves in certain parameters of the 'Comment.php' script. An attacker can exploit these issues by creating a malicious link containing HTML and script code and send this link to a vulnerable user.
SQL injection issues exist in the application as well. These issues affect the parameters of the 'exit.php' and 'comment.php' scripts. Due to this, attackers may supply malicious parameters to manipulate the structure and logic of SQL queries.
These vulnerabilities were reported in Serendipity 0.7-beta1. Other versions may also be affected.
21. XMLStarlet Command Line XML Toolkit Multiple Unspecified Buf...
BugTraq ID: 11270
Remote: Yes
Date Published: Sep 28 2004
Relevant URL: http://www.securityfocus.com/bid/11270
Summary:
XMLStarlet command line XML toolkit is affected by multiple unspecified buffer overflow vulnerabilities. These issues are caused by a failure of the application to validate the lengths of user-supplied strings prior to copying them into finite process buffers.
An attacker may leverage this issue to manipulate process memory, potentially facilitating arbitrary code execution.
22. Icecast Server HTTP Header Buffer Overflow Vulnerability
BugTraq ID: 11271
Remote: Yes
Date Published: Sep 28 2004
Relevant URL: http://www.securityfocus.com/bid/11271
Summary:
It is reported that the Icecast server is susceptible to a buffer overflow vulnerability. This issue is due to a failure of the application to properly enforce boundary conditions when dealing with user-supplied input data.
This vulnerability allows for remote code execution in the context of the Icecast server.
It is reported that this vulnerability is only exploitable to execute remote code on Microsoft Windows platforms. This buffer overflow affects all platforms, however it is only exploitable if a sensitive address is located adjacent to the affected buffer. On other platforms, denial of service or code execution may be possible, but this has not been confirmed.
Verions 2.x up to 2.0.1 are reported vulnerable to this issue.
23. ParaChat Directory Traversal Vulnerability
BugTraq ID: 11272
Remote: Yes
Date Published: Sep 28 2004
Relevant URL: http://www.securityfocus.com/bid/11272
Summary:
It is reported that ParaChat is susceptible to a directory traversal vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input data.
This vulnerability allows remote attackers to retrieve the contents of arbitrary, potentially sensitive files located on the serving computer with the credentials of the ParaChat server process.
Version 5.5 is reported susceptible to this vulnerability. Other versions may also be affected.
24. PeopleSoft Human Resources Management System Cross-Site Scri...
BugTraq ID: 11275
Remote: Yes
Date Published: Sep 29 2004
Relevant URL: http://www.securityfocus.com/bid/11275
Summary:
PeopleSoft Human Resources Management System (HRMS) is reported prone to a cross-site scripting vulnerability. This issue exists due to insufficient sanitization of user-supplied data and may allow a remote attacker to execute arbitrary script code in a vulnerable user's browser.
This issue presents itself in some unspecified debugging and utility scripts that are supplied with the default installation. It is reported that successful exploitation of this issue can disclose sensitive data to an attacker.
This vulnerability is reported to affect HRMS version 7.0, however, it is possible that other versions are affected as well.
25. SGI IRIX T_Bind/T_UnBind Undisclosed Vulnerability
BugTraq ID: 11276
Remote: Yes
Date Published: Sep 29 2004
Relevant URL: http://www.securityfocus.com/bid/11276
Summary:
An undisclosed vulnerability is reported to affect SGI IRX, and may affect other versions of BSD, although this is not confirmed. The vulnerability is reported to present itself because t_unbind() modifies the expected behavior of t_bind(). The consequences of the vulnerability are not known. Very few details are actually known in regards to this vulnerability at the time of writing.
This BID will be updated as soon as further information in regards to this issue is made public.
26. Computer Associates Unicenter Common Services Plaintext Pass...
BugTraq ID: 11277
Remote: No
Date Published: Sep 29 2004
Relevant URL: http://www.securityfocus.com/bid/11277
Summary:
Computer Associates Unicenter Common Services is reported prone to a plaintext password storage vulnerability. It is reported that the database Server Admin password is stored in plaintext in the certain installation batch files.
A local attacker may exploit this vulnerability, if they have read access to the batch files in question.
27. SGI IRIX Undisclosed ARP Handling Vulnerability
BugTraq ID: 11278
Remote: Yes
Date Published: Sep 29 2004
Relevant URL: http://www.securityfocus.com/bid/11278
Summary:
SGI IRIX is reported prone to an undisclosed ARP handling vulnerability. This issue might be related to the issue that is described in BID 265 (NetBSD Static ARP Vulnerability) although this is not confirmed.
It is conjectured that this vulnerability may be exploited to overwrite static ARP entries that exist in the ARP cache of a vulnerable host.
This BID will be updated, as more information regarding this vulnerability is made public.
28. Playlogic Alpha Black Zero Remote Denial Of Service Vulnerab...
BugTraq ID: 11279
Remote: Yes
Date Published: Sep 29 2004
Relevant URL: http://www.securityfocus.com/bid/11279
Summary:
It is reported that Alpha Black Zero is susceptible to a remote denial of service venerability. This issue is due to a failure of the game server software to handle many simultaneous connections.
This vulnerability allows remote attackers to crash the affected application, denying service to legitimate users.
Versions of Alpha Black Zero up to, and including version 1.04 are reported to be affected by this vulnerability.
29. Freenet6 Client Default Installation Configuration File Perm...
BugTraq ID: 11280
Remote: No
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11280
Summary:
Freenet6 is affected by a default install configuration file permission vulnerability. This issue is due to a default configuration error..
An attacker may leverage this issue to steal authentication information from the configuration file that is by default set as world readable.
30. Samba Remote Arbitrary File Access Vulnerability
BugTraq ID: 11281
Remote: Yes
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11281
Summary:
Samba is affected by a remote arbitrary file access vulnerability. This issue is due to a failure of the application to properly validate user-supplied file names.
An attacker may leverage this issue to gain access to files outside of a Samba share's path on a vulnerable computer. Information gained in this way may reveal sensitive information aiding in further attacker against the computer.
31. GNU GetText Unspecified Insecure Temporary File Creation Vul...
BugTraq ID: 11282
Remote: No
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11282
Summary:
GNU gettext is affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existance of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. Reportedly this issue is unlikely to facilitate privilege escalation.
32. W-Agora Multiple Remote Input Validation Vulnerabilities
BugTraq ID: 11283
Remote: Yes
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11283
Summary:
Multiple vulnerabilities are reported to affect the application. These issues arise due to insufficient sanitization of user-supplied data. A remote attacker may leverage these vulnerabilities to carry out SQL injection, cross-site scripting, and HTTP response splitting attacks.
These issues were identified in W-Agora 4.1.6a, however, it is possible that other versions are also affected.
33. Silent-Storm Portal Multiple Input Validation Vulnerabilitie...
BugTraq ID: 11284
Remote: Yes
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11284
Summary:
Silent-Storm Portal is reported prone to multiple vulnerabilities. The issues result from insufficient sanitization of user-supplied data. The following specific issues are reported to affect the application:
Silent-Storm Portal is reported prone to a cross-site scripting vulnerability.
This cross-site scripting issue can permit a remote attacker to create a malicious URI link to the vulnerable portal that includes hostile HTML and script code. This attack can allow for theft of cookie-based authentication credentials and other attacks.
Silent-Storm Portal is reported prone to an input validation vulnerability that results in the corruption of the Silent-Storm Portal database.
It is demonstrated that a remote attacker may exploit this vulnerability to gain administrative access by adding a malicious user level database field.
34. GhostScript Unspecified Insecure Temporary File Creation Vul...
BugTraq ID: 11285
Remote: No
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11285
Summary:
Ghostscript is affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. Reportedly this issue is unlikely to facilitate privilege escalation.
35. GNU GLibC Unspecified Insecure Temporary File Creation Vulne...
BugTraq ID: 11286
Remote: No
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11286
Summary:
GNU glibc is affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. Reportedly this issue is unlikely to facilitate privilege escalation.
36. GNU Troff (Groff) Unspecified Insecure Temporary File Creati...
BugTraq ID: 11287
Remote: No
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11287
Summary:
GNU Troff (groff) is affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existance of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. Reportedly this issue is unlikely to facilitate privilege escalation.
37. GNU GZip Unspecified Insecure Temporary File Creation Vulner...
BugTraq ID: 11288
Remote: No
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11288
Summary:
GNU gzip is affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. Reportedly this issue is unlikely to facilitate privilege escalation.
38. MIT Kerberos 5 Unspecified Insecure Temporary File Creation ...
BugTraq ID: 11289
Remote: No
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11289
Summary:
MIT Kerberos 5 is affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. Reportedly this issue is unlikely to facilitate privilege escalation.
39. Trustix LVM Utilities Unspecified Insecure Temporary File Cr...
BugTraq ID: 11290
Remote: No
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11290
Summary:
Trustix LVM Utilities are affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify a files existence before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. Reportedly this issue is unlikely to facilitate privilege escalation.
40. MySQL Unspecified Insecure Temporary File Creation Vulnerabi...
BugTraq ID: 11291
Remote: No
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11291
Summary:
MySQL is affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existance of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. Reportedly this issue is unlikely to facilitate privilege escalation.
41. NetaTalk Unspecified Insecure Temporary File Creation Vulner...
BugTraq ID: 11292
Remote: No
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11292
Summary:
Netatalk is affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existance of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. Reportedly this issue is unlikely to facilitate privilege escalation.
42. OpenSSL Unspecified Insecure Temporary File Creation Vulnera...
BugTraq ID: 11293
Remote: No
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11293
Summary:
OpenSSL is affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existance of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. Reportedly this issue is unlikely to facilitate privilege escalation.
43. Perl Unspecified Insecure Temporary File Creation Vulnerabil...
BugTraq ID: 11294
Remote: No
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11294
Summary:
Perl is affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existance of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. Reportedly this issue is unlikely to facilitate privilege escalation.
44. PostgreSQL Unspecified Insecure Temporary File Creation Vuln...
BugTraq ID: 11295
Remote: No
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11295
Summary:
PostgreSQL is affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existance of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. Reportedly this issue is unlikely to facilitate privilege escalation.
45. PHP-Fusion Multiple SQL and HTML Injection Vulnerabilities
BugTraq ID: 11296
Remote: Yes
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11296
Summary:
It is reported that PHP-Fusion is susceptible to HTML and SQL injection vulnerabilities. These vulnerabilities are due to a failure of the application to properly sanitize user-supplied input data.
An attacker may leverage the SQL injection issues to manipulate SQL queries to the underlying database. This may allow the attacker access to sensitive information, such as the administrator password, to corrupt data, and to carry out other attacks.
The HTML injection vulnerabilities may allow an attacker to inject malicious HTML and script code into the vulnerable application. An unsuspecting user viewing the resulting pages will have the attacker-supplied script code executed within their browser in the context of the vulnerable web site.
These vulnerabilities are reported to exist in version 4.01 of PHP-Fusion. Other versions may also be affected.
46. HP LaserJet 4200/4300 Printer Arbitrary Firmware Upgrade Vul...
BugTraq ID: 11297
Remote: Yes
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11297
Summary:
It is reported that HP LaserJet 4200 and 4300 printers are susceptible to an arbitrary firmware upgrade vulnerability.
This vulnerability is due to the method of upgrading the firmware on affected devices. According to HP upgrade documentation, these printers can upgrade their firmware by sending them specially formatted print jobs. This allows for firmware upgrades to be initiated by unauthenticated FTP access, copying firmware files to the printer via CIFS, or possibly other means as well.
It is unclear at this time what strength the in place measures are to ensure that firmware files contain legitimate firmware data for the printer. Simple CRC-32 checksums, or other similar means may allow attackers to create firmware files containing data sufficient to pass the printers built-in validity checks.
If an attacker can upgrade affected printers with arbitrary firmware files, they may be able to either crash affected machines, replace the firmware code with malicious executable code, or possibly render the printer useless until the firmware is repaired or replaced. Attackers would be able to perform this upgrade without authentication, via the network.
Other printers may also be affected.
47. GNU Sharutils Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 11298
Remote: Yes
Date Published: Oct 01 2004
Relevant URL: http://www.securityfocus.com/bid/11298
Summary:
GNU Sharutils are affected by multiple buffer overflow vulnerabilities. These issues are due to a failure of the affected application to verify the length of user-supplied strings prior to copying them into finite process buffers.
Successful exploitation would immediately produce a denial of service condition in the affected process. This issue may also be leveraged to execute code on the affected system with the privileges of the user that invoked the vulnerable application.
48. Proxytunnel Local Proxy Credential Disclosure Vulnerability
BugTraq ID: 11299
Remote: No
Date Published: Oct 01 2004
Relevant URL: http://www.securityfocus.com/bid/11299
Summary:
A vulnerability exists in proxytunnel that has the potential to expose proxy credentials to other local users. Reportedly proxyuser/proxypass data is not passed to the program in a secure manner, potentially exposing this data to other users on the computer.
49. Kerio MailServer Unspecified Vulnerability
BugTraq ID: 11300
Remote: Yes
Date Published: Oct 01 2004
Relevant URL: http://www.securityfocus.com/bid/11300
Summary:
Kerio MailServer version 6.0.3 has been released. This release addresses a potential security vulnerability in the Kerio MailServer application. The cause and impact of this issue is currently unknown, however this BID will be updated as more information becomes available.
All versions of Kerio MailServer prior to 6.0.3 are considered vulnerable.
50. AJ-Fork Insecure Default Permissions Vulnerability
BugTraq ID: 11301
Remote: Yes
Date Published: Oct 01 2004
Relevant URL: http://www.securityfocus.com/bid/11301
Summary:
AJ-Fork is reported prone to an insecure default file permissions vulnerability. This issue arises due to a configuration error and may allow an attacker to read and write to arbitrary Web accessible files.
AJ-Fork version 167 is reported prone to this vulnerability. It is likely that other versions are affected as well.
It is reported that AJ-Fork is based on CuteNews by Cutephp. Due to code similarities all versions of CuteNews are considered vulnerable to this issue as well.
51. MediaWiki Raw Page Cross-Site Scripting Vulnerability
BugTraq ID: 11302
Remote: Yes
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11302
Summary:
MediaWiki is reported prone to a cross-site scripting vulnerability. This issue arises due to insufficient sanitization of user-supplied data. A remote attacker may exploit this vulnerability to execute arbitrary HTML and script code in the browser of a vulnerable user.
MediaWiki versions 1.3.4 and prior are affected by this vulnerability.
52. BBlog RSS.PHP SQL Injection Vulnerability
BugTraq ID: 11303
Remote: Yes
Date Published: Oct 01 2004
Relevant URL: http://www.securityfocus.com/bid/11303
Summary:
It is reported that bBlog is prone to an SQL injection vulnerability. This issue is due to a failure of the application to properly validate user supplied URI input.
Because of this, a malicious user may influence database queries in order to view or modify sensitive information, potentially compromising the software or the database. It may be possible for an attacker to disclose the administrator password hash by exploiting this issue.
53. Real Estate Management Software Multiple Unspecified Vulnera...
BugTraq ID: 11304
Remote: Yes
Date Published: Sep 30 2004
Relevant URL: http://www.securityfocus.com/bid/11304
Summary:
Real Estate Management Software is reported prone to multiple unspecified vulnerabilities. The vendor reported these issues and specified that these vulnerabilities exist in Real Estate Management Software version 1.0. The cause and impact of these issues is currently unknown. It is conjectured that due to the nature of the application these vulnerabilities may be remotely exploitable.
Due to lack of details, further information is not available at the moment. This BID will be updated as more information becomes available.
54. Online-Bookmarks Authentication Bypass Vulnerability
BugTraq ID: 11305
Remote: Yes
Date Published: Oct 01 2004
Relevant URL: http://www.securityfocus.com/bid/11305
Summary:
online-bookmarks is affected by an authentication bypass vulnerability. This issue is due to a failure of the application to properly manage unauthorized access to sensitive scripts.
An attacker may leverage these issues to gain unauthorized access to an unsuspecting user's bookmarks, allowing them to view, edit, and delete arbitrary entries.
55. Recruitment Agency Software Unspecified Security Vulnerabili...
BugTraq ID: 11306
Remote: Yes
Date Published: Oct 01 2004
Relevant URL: http://www.securityfocus.com/bid/11306
Summary:
Recruitment Agency Software is reported prone to an unspecified security vulnerability. The cause and impact of this issue are currently unknown as very few details are available.
Recruitment Agency Software version 1.0 is reported to be affected by this issue.
56. RealNetworks RealOne Player And RealPlayer Unspecified Web P...
BugTraq ID: 11307
Remote: Yes
Date Published: Sep 29 2004
Relevant URL: http://www.securityfocus.com/bid/11307
Summary:
RealOne Player and RealPlayer are affected by an unspecified vulnerability. This issue may reportedly be exploited by a malicious Web page to execute arbitrary code in the context of the software.
This issue was originally described in BID 11273 (RealNetworks RealOne Player And RealPlayer Remote Vulnerabilities) and is now being assigned its own BID.
57. RealNetworks RealOne Player And RealPlayer Unspecified File ...
BugTraq ID: 11308
Remote: Yes
Date Published: Sep 29 2004
Relevant URL: http://www.securityfocus.com/bid/11308
Summary:
RealPlayer and RealOne Player are prone to a vulnerability that may allow an attacker to delete files on the client computer. The attacker must know the path to the file that is targeted.
This issue was originally described in BID 11273 (RealNetworks RealOne Player And RealPlayer Remote Vulnerabilities) and is now being assigned its own BID.
58. RealNetworks RealOne Player And RealPlayer PNen3260.DLL Remo...
BugTraq ID: 11309
Remote: Yes
Date Published: Sep 29 2004
Relevant URL: http://www.securityfocus.com/bid/11309
Summary:
RealPlayer and RealOne Player are prone to a remote integer overflow vulnerability. It is reported that the vulnerability exists in the 'pnen3260.dll' linked library of both RealPlayer and RealOne Player for Microsoft Windows, Linux, and Mac OS platforms. The 'pnen3260.dll' library is responsible for processing real-media '.rm' files.
The overflow will cause the corruption of heap-based memory management structures. Ultimately this may permit an attacker to write to an arbitrary location in the memory of the active process and in doing so control execution flow.
A remote attacker may therefore exploit this vulnerability to execute arbitrary attacker-supplied instructions in the context of a user that is running a vulnerable version of the software.
This issue was originally described in BID 11273 (RealNetworks RealOne Player And RealPlayer Remote Vulnerabilities) and is now being assigned its own BID.
59. VyPRESS Messenger Remote Buffer Overflow Vulnerability
BugTraq ID: 11310
Remote: Yes
Date Published: Oct 01 2004
Relevant URL: http://www.securityfocus.com/bid/11310
Summary:
VyPRESS Messenger is affected by a remote buffer overflow vulnerability. This issue is due to a failure of the application to verify the length of user-supplied strings prior to copying them into finite process buffers.
An attacker may leverage this issue to remotely execute arbitrary machine code on an affected computer with the privileges of the user running the affected application. It is possible to exploit all hosts on a local area network by sending a message to a broadcast address.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Warspammer guilty under new federal law
By: Kevin Poulsen
A Los Angeles man who spewed electronic porn advertisements from his car likely faces up to six months in jail.
http://www.securityfocus.com/news/9606
2. U.N. warns of nuclear cyber attack risk
By: Kevin Poulsen
The International Atomic Energy Agency warns of the possibility of plant sabotage by intruders and corrupt insiders.
http://www.securityfocus.com/news/9592
3. Feds invite comment on Internet wiretaps
By: Kevin Poulsen
U.S. regulators open a public comment period on a plan to wire broadband and VoIP systems for law enforcement surveillance.
http://www.securityfocus.com/news/9582
4. Hackers attack Dutch government Web sites
By: , The Associated Press
http://www.securityfocus.com/news/9642
5. McAfee in BitDefender virus slur spat
By: John Leyden, The Register
McAfee has distanced itself from slurs against rival AV firm BitDefender contained in sponsored ad links on Google.com.
http://www.securityfocus.com/news/9633
6. WorldPay struggles under DDoS attack (again)
By: John Leyden, The Register
WorldPay, the Royal Bank of Scotland's internet payment transaction outfit, is continuing to fight a sustained internet attack which has left its services largely unavailable for a third successive day.
http://www.securityfocus.com/news/9632
IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. XArp 0.1.5
By: Christoph Mayer
Relevant URL: http://www.chrismc.de
Platforms: Windows 2000, Windows XP
Summary:
XArp is a graphical tool to monitor the ARP cache. It periodically requests the local ARP cache and reports changes in the IP to MAC mapping. Thus it can be used to recognize ARP poisoning which is used to prepare 'man in the middle' attacks on switched networks.
2. Extreme Editor: 5.2.2
By: Uri Fridman
Relevant URL: http://www.geocities.com/urifrid/soft.html
Platforms: Windows 2000, Windows NT, Windows XP
Summary:
multi-tabbed ASCII editor with encryption capabilities. Encryption of edited text and clipboard using Twofish.
3. ATK Plugin Creator 1.0
By: Nico 'Triplex' Spicher
Relevant URL: http://www.computec.ch/projekte/atk/
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
This freeware for Windows provides a small and handy interface to create and enhance ATK plugins. This first public release is fully compatible with ATK 2.x but can also be used with ATK 1.x (some new fields are not fully supported in the first releases).
4. PlugAPOP 1.00
By: waffle soft
Relevant URL: http://www.wafflesoft.com/PlugAPOP/manual_en.html
Platforms: Windows XP
Summary:
PlugAPOP is software to use APOP feature in Microsoft Outlook/Outlook Express which doesn't have APOP feature.
[Easy]
You can install and setup very easily. You can use APOP access immediately if you change the account name and server name field in your e-mail client. No special settings are needed in PlugAPOP.
[Tiny]
PlugAPOP doesn't waste a lot of CPU resource and memory, it doesn't effect to OS core and other application. PlugAPOP is implemented by using just SD
5. PIKT - Problem Informant/Killer Tool v1.17.0
By: Robert Osterlund, [email protected]
Relevant URL: http://pikt.org
Platforms: AIX, FreeBSD, HP-UX, IRIX, Linux, Solaris, SunOS
Summary:
PIKT is a cross-categorical, multi-purpose toolkit to monitor and configure computer systems, organize system security, format documents, assist command-line work, and perform other common systems administration tasks.
PIKT's primary purpose is to report and fix problems, but its flexibility and extendibility evoke many other uses limited only by your imagination.
6. TX 1.0
By: Goldie Rejuven
Relevant URL: http://www.checksum.org/download/RX/
Platforms: Windows 2000, Windows NT, Windows XP
Summary:
The Smallest VC++ Coded Universal Windows Reverse Shell for all versions of Windows NT/2K/XP/2003 with any service pack. But not for Windows 98/ME. A Tini app that connects back to the specified IP to a fixedport and uses a fixed source port on the source machine to evade the firewalls.
Default port from which it connects :443
Default port to which it connects is :8080
More on the readme.txt
V. SECURITYJOBS LIST SUMMARY
----------------------------
1. [SJ-JOB] Management, Baltimore, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/377527
2. [SJ-JOB] VP of Marketing, Baltimore, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/377525
3. [SJ-JOB] Technical Writer, Washington, DC, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/377520
4. [SJ-JOB] Security Architect, New York, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/377510
5. [SJ-JOB] Security Engineer, New York, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/377506
6. [SJ-JOB] Auditor, Chicago, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/377505
7. [SJ-JOB] Manager, Information Security, Greenville, ... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/377504
8. [SJ-JOB] Certification & Accreditation Engineer, Gai... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/377503
9. [SJ-JOB] Sr. Security Analyst, Minneapolis, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/377501
10. [SJ-JOB] Sr. Security Analyst, Gaithersburg, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/377500
11. [SJ-JOB] Security Auditor, San Antonio, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/377498
12. [SJ-JOB] Security Consultant, Paramus and/or Asbury ... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/377497
13. [SJ-JOB] Sr. Security Engineer, Bay Area, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/377496
14. [SJ-JOB] Security Consultant, Parsippany, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/377495
15. [SJ-JOB] Account Manager, Cincinnati, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/377494
16. [SJ-JOB] Quality Assurance, Santa Monica, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/377270
17. [SJ-JOB] Quality Assurance, Redwood City (650), US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/377269
18. [SJ-JOB] Management, London, GB (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/376959
19. [SJ-JOB] Sales Engineer, DC, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/376958
20. [SJ-JOB] Account Manager, fort lauderdale, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/376955
21. [SJ-JOB] Sr. Security Engineer, Hillsboro, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/376952
22. [SJ-JOB] Sr. Product Manager, Redwood City, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/376951
23. [SJ-JOB] Security System Administrator, Fort Lauderd... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/376949
24. [SJ-JOB] Sr. Security Analyst, Indianapolis, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/376948
25. [SJ-JOB] Security Architect, Saint Louis, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/376938
26. [SJ-JOB] Sr. Security Engineer, Saint Louis, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/376937
27. [SJ-JOB] Account Manager, Atlanta, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/376931
28. [SJ-JOB] Security Engineer, Sacramento, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/376919
29. [SJ-JOB] Account Manager, Redwood City, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/376774
30. [SJ-JOB] Sales Engineer, Chicago, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/376773
VI. INCIDENTS LIST SUMMARY
--------------------------
1. Data Cha0s PHP script attempt (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/377421
2. DllTrojan ? (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/377405
3. Localhost packets on WAN (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/377403
4. data payload in SYN ( DoS/DDoS on port 1863(MSN prot... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/376880
VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Kaspersky AntiVirus Window Caption GUI Bypass Vulner... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/82/377288
2. Help on hardware flaws (Thread)
Relevant URL:
http://www.securityfocus.com/archive/82/377061
3. No body emails and Norton antivirus (Thread)
Relevant URL:
http://www.securityfocus.com/archive/82/377049
VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. MS ISA activeX Filtering (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/377560
2. Tool for removing LANMAN hashes from registry (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/377524
3. Items within XP SP2 and Win2003 (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/377410
4. Application sniffer-next step (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/377408
5. Fw: Serious Security Issue in Windows XP SP2's Firew... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/377407
6. SecurityFocus Microsoft Newsletter #208 (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/376839
7. VBScript to audit shares and share permissions (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/376778
8. Hardening Desktop (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/376763
9. Serious Security Issue in Windows XP SP2's Firewall (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/376752
10. Win2k3 IIS6.0 Port 4531 (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/376706
IX. SUN FOCUS LIST SUMMARY
--------------------------
1. Security Configuration Settings? (Thread)
Relevant URL:
http://www.securityfocus.com/archive/92/376908
X. LINUX FOCUS LIST SUMMARY
---------------------------
1. iptables & tcp wrappers (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/377415
XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XII. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored By: SecurityFocus
Stay up to date. All the latest news, columns, jobs and more in a
convenient html newsletter - Even a glimpse of upcoming columns and feature
articles! Sign up today!
http://www.securityfocus.com/htmlnewsletter/subscribe
------------------------------------------------------------------------