SecurityFocus Newsletter #150
John Boletta <[email protected]> Mon, 24 Jun 2002 13:12:57 -0600 (MDT)
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #150
--------------------------------
This Issue is Sponsored by: Blackhat
Attend Black Hat Briefings & Training, July 29 - August 1, Las Vegas, the
world's premier technical security event! 8 tracks, 12 training sessions,
Richard Clarke keynote, 1500 delegates from 30 nations, with a near cult
following of both CSOs and "underground" security experts. See for
yourself what the buzz is all about.
Visit us at: http://www.blackhat.com
-------------------------------------------------------------------------------
I. FRONT AND CENTER
1. Secure Coding
2. Implementing Networks Taps with Network Intrusion Detection...
3. Filtering E-Mail with Postfix and Procmail, Part One
4. Alexis de Tocqueville Serves Up a Red Herring
5. Cutting-Edge High Tech Crime Fighting
II. BUGTRAQ SUMMARY
1. MIT CGIEmail Arbitrary Recipient Mail Relay Vulnerability
2. Microsoft SQL Server 2000 PWDEncrypt Buffer Overflow Vulnerability
3. Seunghyun Seo MSN666 Remote Buffer Overflow Vulnerability
4. Lumigent Log Explorer XP_LogAttach_StartProf Buffer Overflow...
5. Lumigent Log Explorer XP_LogAttach_SetPort Buffer Overflow...
6. Lumigent Log Explorer XP_LogAttach Buffer Overflow Vulnerability
7. Digi-Net Technologies DigiChat User IP Information Disclosure...
8. Multiple Vendor Spoofed IGMP Report Denial Of Service...
9. Mewsoft NetAuction Cross Site Scripting Vulnerability
10. PHP Classifieds Cross-Site Scripting Vulnerability
11. PHPEventCalendar Remote Command Execution Vulnerability
12. nCipher ConsoleCallBack Class With JRE 1.4.0 Smart Card...
13. Cisco Secure ACS Cross-site Scripting Vulnerability
14. Xitami GSL Template Vulnerabilities
15. Microsoft Internet Explorer CSSText Bold Font Denial Of...
16. Zeroboard PHP Include File Arbitrary Command Execution...
17. My Postcards MagicCard.CGI Arbitrary File Disclosure...
18. Caucho Technology Resin Server View_Source.JSP Arbitrary File...
19. Caucho Technology Resin Server Denial Of Service Vulnerability
20. Apache Chunked-Encoding Memory Corruption Vulnerability
21. Wolfram Research webMathematica File Disclosure Vulnerability
22. Zyxel Prestige 642R Malformed Packet Denial Of Service...
23. NetGear RP114 Administrative Access Via External Interface...
24. PHPBB2 Install.PHP Remote File Include Vulnerability
25. Solaris 8 dtscreen Authentication Bypass Vulnerability
26. OSCommerce Remote File Include Vulnerability
27. PHP-Address Remote File Include Vulnerability
28. Cisco uBR7200 / uBR7100 Universal Broadband Routers DOCSIS...
29. MetaLinks MetaCart2.SQL Database Disclosure Vulnerability
30. HP MPE/iX Malformed SNMP Vulnerability...
31. Interbase GDS_Drop Interbase Environment Variable Buffer...
32. Interbase GDS_Lock_MGR Interbase Environment Variable Buffer...
33. WebScripts WebBBS Remote Command Execution Vulnerability
34. DeepMetrix LiveStats HTML Report Script Injection Vulnerability
35. 4D WebServer Long HTTP Request Buffer Overflow Vulnerability
36. phpShare Arbitrary Remote PHP File Include Vulnerability
37. Mandrake 8.2 Msec Insecure Default Permissions Vulnerability
38. UnixWare / Open UNIX ppptalk Local Privilege Escalation...
39. Apache Tomcat Web Root Path Disclosure Vulnerability
40. IRSSI Long Malformed Topic Denial Of Service Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
1. Gobbles Releases Apache Exploit
2. Game Consoles -- the Next Hacker Target?
3. Court Bars Student Suit Under U.S. Privacy Law
4. MS to pull Java in 2004 - why you knew this already
IV.SECURITYFOCUS TOP 6 TOOLS
1. Apache Chunked Scanner v1.0.0
2. Roxy Proxy v1.0.0
3. FireDisk
4. Ganglia Cluster Toolkit - Gmetad Web Frontend branch v0.1.0
5. amavis-notify-parser v0.2
6. Tiger security tool v3.0
V. SECURITYJOBS LIST SUMMARY
1. Security Specialist in OR looking for possible relocation (Thread)
2. Application Security Architect - Greythorn (Thread)
3. Available for Security work -- PART TIME - (Thread)
4. Information Security Manager - Central NJ - $110k (Thread)
5. Seeking Security/Forensic Analyst Position in NY (Thread)
6. I T Risk Assessment Manager in Kansa City (Thread)
7. Solaris/Raptor Position (Thread)
8. Security Architect positions in Chicago area (Thread)
9. Sales Engineer-Distributed firewalls/network solutions-CA (Thread)
10. SWE security for SW and Web Services-Immediate in CA (Thread)
11. W2K Security Professional (Thread)
12. Jr./Intermediate Vulnerability Analyst Position (Thread)
13. Chief Information Security Officer - OH - #701 (Thread)
14. PKI Senior Pre-sales Consultant EMEA (Thread)
15. Director of Information Technology Position in Chicago and...
16. Microsoft Exploit/Countermeasure Research and Development...
17. Security Professional seeking a new opportunity (Thread)
VI. INCIDENTS LIST SUMMARY
1. Worm1800.exe on UnderNet? (Thread)
2. Port 4927 traffic spike (Thread)
3. Strange web vulnerability scanner (Thread)
4. automatic hacking tool for IIS? (Thread)
5. ICMP Destination Unreachable in SNORT (Thread)
6. New script-kiddie looking scan (Thread)
7. DOS by Flooding a Network (Thread)
8. Distributed ICMP/UDP scan or attack? (Thread)
9. remote openssh probe or crack?. (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
1. Re[2]: Apache Exploit (Thread)
2. Apache Exploit (Thread)
3. apache chunked encoding (Thread)
4. procmail heap overflow (Thread)
5. Re: apache chunked encoding (Thread)
6. Apache Worm? (Thread)
7. ISS Advisory: Remote Compromise Vulnerability in Apache HTTP...
8. FW: ISS Advisory: Remote Compromise Vulnerability in Apache...
9. Shoutcast Admin password bruteforce tool (Thread)
10. Vulnerability Coordination (Thread)
11. CERT Advisory CA-2002-17 Apache Web Server Chunk Handling...
12. Wellenreiter-v1.4 introduces ESSID-bruteforcing (Thread)
13. DOS in Win2k/XP in LAN (Thread)
14. Interbase 6.0 malloc() issues (Thread)
15. This is not a BUG but an Issue in MS02-18: Why Ms02-18 "...
16. Recent "rumors" (Thread)
17. Re [BUGTRAQ] : ZyXEL 642R(-11) AJ.6 SYN-ACK, SYN-FIN DoS (Thread)
18. m64config (Thread)
19. openbse rumours (Thread)
20. Clarification - IE gopher cross site scripting (Thread)
21. DNS zone transfer (Thread)
22. [Fwd: IE gopher cross site scripting] (Thread)
23. /_vti_bin/_vti_aut/dvwssr.ddl (Thread)
24. Best Buy re-activates WLANs (fwd) (Thread)
25. Windows Buffer Overflows (Thread)
26. Another cgiemail bug (Thread)
27. wireless issues (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
1. Null session and Exchange2K (Thread)
2. MS02-29 breaks PPTP connections for non-Admin users? (Thread)
3. SecurityFocus Microsoft Newsletter #91 (Thread)
4. backing up IE config (Thread)
5. xcacls and a service account (Thread)
IX. SUN FOCUS LIST SUMMARY
1. ssh help (Thread)
X. LINUX FOCUS LIST SUMMARY
1. Have I been kitted? (Thread)
2. Web filtering? (Thread)
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. Secure Coding
By David Wong
It's virtually impossible to build bug-free, vulnerability-free software.
This article will provide a brief overview of some of the key issues of
secure coding, including some common software development mistakes, a list
of best practices for secure coding, and a list of resources that will aid
in your quest to build more secure software.
http://online.securityfocus.com/infocus/1596
2. Implementing Networks Taps with Network Intrusion Detection Systems
by Nathan Einwechter, Senior Research Scientist Fate Research Labs
Over the past decade or so, the use of switches to replace hubs has
increased substantially. This is largely due to the increased size of
networks, and the requirement for increasingly faster and more efficient
networks. On most networks, the data must now be dependable and timely.
This transition from hubs to switches, however, has generated a conflict
with already deployed and designed network intrusion detection systems.
http://online.securityfocus.com/infocus/1594
3. Filtering E-Mail with Postfix and Procmail, Part One
by Brian Hatch
Most folks dislike spam in their e-mail. Spam takes up our network, disk,
and cpu resources. It requires that we weed through unwanted messages to
find the ones that we requested. (I'm not going to try to convince you
that spam is not good, you can check out some of the anti-spam resources
listed in the relevant links section below, if you're interested.)
http://online.securityfocus.com/infocus/1593
4. Alexis de Tocqueville Serves Up a Red Herring
By Richard Forno
The press release announcing the Alexis de Tocqueville Institution's
recent white paper proclaims that open source software is a threat to
national security. However, there is much in the document that the press
release conveniently overlooks.
http://online.securityfocus.com/columnists/89
5. Tech Crime Fighting: Best Practices in Computer Forensics
June 17-18, 2002
American Management Association, Washington, DC
Walk away able to perform computer forensic examinations that will not
only yield sound evidence but will also hold up in a court of law! Learn
to find, collect and preserve digital evidence, and present the evidence
in court. Also learn to successfully combine private and public computer
forensics forces to investigate computer crimes. Keynote speech by
Microsoft's Chief Security Strategist Scott Charney. Public sector
employee discounts available.
For more information, call 800-280-8440, or visit www.frallc.com (see
InfoTech events).
II. BUGTRAQ SUMMARY
-------------------
1. MIT CGIEmail Arbitrary Recipient Mail Relay Vulnerability
BugTraq ID: 5013
Remote: Yes
Date Published: Jun 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5013
Summary:
MIT cgiemail is designed to take the input of web forms and convert it to
an e-mail format defined by the author of the form. It was written for use
on UNIX and Linux variant operating systems.
A vulnerability has been reported for cgiemail that allows cgiemail to act
as an open relay for email. The vulnerability is due to failure of proper
santization of user supplied values. In particular the new line code "%0a"
is not filtered properly.
cgiemail uses templates when generating emails. To exploit this issue, an
attacker must know the exact path of a template file that cgiemail uses.
As well, the attacker must know of the fields that will be included in the
generated email.
As a result, a malicious user may trivially specify any email address,
effectively using the script as an open mail relay. This technique is well
known, and commonly used for sending unsolicited email.
2. Microsoft SQL Server 2000 PWDEncrypt Buffer Overflow Vulnerability
BugTraq ID: 5014
Remote: No
Date Published: Jun 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5014
Summary:
SQL Server 2000 is a commercially available enterprise level database
product from Microsoft.
A buffer overflow has been discovered in Microsoft SQL Server 2000. This
vulnerability is due to insufficient bounds checking of data supplied to
the built-in pwdencrypt() hashing function. This issue is reported to be
a heap overflow and may be exploited to execute arbitrary
attacker-supplied instructions as the SQL Server.
The attacker must be able to execute a database query using the
pwdencrypt() function to exploit this vulnerability, which implies that
the attacker must either have legitimate access to the database server or
obtain unauthorized access through some other means. For example, it may
be possible to exploit this issue via a SQL injection attack in another
application.
This issue may be related to the vulnerabilities reported in Bugtraq ID
4847.
3. Seunghyun Seo MSN666 Remote Buffer Overflow Vulnerability
BugTraq ID: 5015
Remote: Yes
Date Published: Jun 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5015
Summary:
MSN666 is a utility for sniffing MSN Messenger traffic on a local network,
implemented by Seunghyun Seo. A vulnerability has been reported in some
versions of MSN666.
MSN666 may not properly handle malformed MSN traffic. Under some
conditions, remotely supplied data is copied to a fixed width buffer.
Longer data may overflow this buffer, overwriting adjacent memory. It is
possible to modify sensitive information stored on the stack, including
return addresses. Successful exploitation may, in turn, lead to the
execution of arbitrary code as the MSN666 process.
It is possible that this vulnerability is related to parsing of the
operation code from an MSN message.
4. Lumigent Log Explorer XP_LogAttach_StartProf Buffer Overflow Vulnerability
BugTraq ID: 5016
Remote: No
Date Published: Jun 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5016
Summary:
Lumigent Log Explorer is a transaction log explorer for Microsoft SQL
Server 7/2000.
A buffer overflow vulnerability in xp_logattach.dll has been reported for
Lumigent Log Explorer 3.01. The DLL, xp_logattach.dll, contains extended
stored procedures (XPs). XPs are procedures written in a language such as
C that perform high level functions in SQL Server. Specifically, this
issue is known to affect the xp_logattach_StartProf stored procedure.
If this condition is successfully exploited, it is possible for locations
in memory to be overwritten with attacker-supplied instructions, allowing
for code execution as the SQL server process. By default, SQL Server runs
as a non-privileged user.
It should be noted that extended stored procedures can be run only by the
dbo user by default.
5. Lumigent Log Explorer XP_LogAttach_SetPort Buffer Overflow Vulnerability
BugTraq ID: 5017
Remote: No
Date Published: Jun 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5017
Summary:
Lumigent Log Explorer is a transaction log explorer for Microsoft SQL
Server 7/2000.
A buffer overflow vulnerability in xp_logattach.dll has been reported for
Lumigent Log Explorer 3.01. The DLL, xp_logattach.dll, contains extended
stored procedures (XPs). XPs are procedures written in a language such as
C that perform high level functions in SQL Server. Specifically, this
issue is known to affect the xp_logattach_setport stored procedure.
If this condition is successfully exploited, it is possible for locations
in memory to be overwritten with attacker-supplied instructions, allowing
for code execution as the SQL server process. By default, SQL Server runs
as a non-privileged user.
It should be noted that extended stored procedures can be run only by the
dbo user by default.
6. Lumigent Log Explorer XP_LogAttach Buffer Overflow Vulnerability
BugTraq ID: 5018
Remote: No
Date Published: Jun 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5018
Summary:
Lumigent Log Explorer is a transaction log explorer for Microsoft SQL
Server 7/2000.
A buffer overflow vulnerability in xp_logattach.dll has been reported for
Lumigent Log Explorer 3.01. The DLL, xp_logattach.dll, contains extended
stored procedures (XPs). XPs are procedures written in a language such as
C that perform high level functions in SQL Server. Specifically, this
issue is known to affect the xp_logattach stored procedure.
If this condition is successfully exploited, it is possible for locations
in memory to be overwritten with attacker-supplied instructions, allowing
for code execution as the SQL server process. By default, SQL Server runs
as a non-privileged user.
It should be noted that extended stored procedures can be run only by the
dbo user by default.
7. Digi-Net Technologies DigiChat User IP Information Disclosure Vulnerability
BugTraq ID: 5019
Remote: Yes
Date Published: Jun 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5019
Summary:
DigiChat is a web based chat application maintained by Digi-Net. DigiChat
runs on most Microsoft Windows and UNIX platforms.
It is possible for chat users to obtain sensitive information about other
chat visitors.
By design, only ChatMasters are able to resolve the IP address of visiting
chat users. However, it is reportedly possible for users to obtain the IP
address of chat visitors by including '<Param Name="Showip"Value="True">'
in the chat applet. As a result, IP address information is disclosed when
viewing the information details of visitors.
An attacker may exploit this flaw to gain unauthorized access to sensitive
information about site users.
This issue has been reported in DigiChat 3.5, however other versions may
also be affected by this.
8. Multiple Vendor Spoofed IGMP Report Denial Of Service Vulnerability
BugTraq ID: 5020
Remote: Yes
Date Published: Jun 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5020
Summary:
Internet Group Management Protocol (IGMP) is the specified guidelines for
the management of Internet Multicast Routing management.
A problem with the implementation of the protocol in some operating
systems could lead to a denial of service.
It is possible for an arbitrary host to deny service to a system on the
same segment of network. In a situation where a multicast router sends a
membership report request, a host sending a unicast membership report
response to the primary responder can prevent the responder from sending a
message to the multicast router. In doing so, the router will not receive
a response from any host, and thus the transmission will time out and
cease.
This problem could result in an attacker launching a denial of service
against an affected host, and could additionally be used to deny service
to a range of vulnerable hosts on a subnet.
This vulnerability may additionally affect other operating systems, though
it is currently unknown which implementations may be vulnerable.
9. Mewsoft NetAuction Cross Site Scripting Vulnerability
BugTraq ID: 5023
Remote: Yes
Date Published: Jun 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5023
Summary:
Mewsoft NetAuction is designed for users to create auction sites. It is
developed for use with Microsoft Windows and Linux operating environments.
NetAuction does not filter script code from URI parameters, making it
prone to cross-site scripting attacks. Attacker-supplied HTML code may be
included in a malicious link to 'auction.cgi' via the 'terms' parameter.
The supplied HTML code will be executed in the browser of a web user who
visits this link, in the security context of the host running NetAuction.
Such a link might be included in a HTML e-mail or on a malicious webpage.
This may enable a remote attacker to steal cookie-based authentication
credentials from legitimate users of a host running NetAuction.
This issue has been reported in version 3.0, other versions may also be
vulnerable.
10. PHP Classifieds Cross-Site Scripting Vulnerability
BugTraq ID: 5022
Remote: Yes
Date Published: Jun 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5022
Summary:
PHP Classifieds is web-based classifieds software. It will run on most
Unix and Linux variants.
PHP Classifieds has been reported to be prone to cross-site scripting
attacks. This issue results from the failure of the 'latestwap.php' to
sanitize user-supplied input. Attackers may inject arbitrary HTML or
script code into the 'url' URI parameter via a malicious link. When the
malicious link is visited, the attacker's script code will be executed in
the web client of the user browsing the link, in the security context of
the website hosting the vulnerable software.
This may potentially be exploited to steal cookie-based authentication
credentials from legitimate users of the site hosting the software.
11. PHPEventCalendar Remote Command Execution Vulnerability
BugTraq ID: 5021
Remote: Yes
Date Published: Jun 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5021
Summary:
PHPEventCalendar is a web based calendar. It is implemented in PHP and
should be supported on UNIX and Linux variants as well as Microsoft
Windows operating environments.
A vulnerability has been reported in phpEventCalendar that may allow a
user of phpEventCalendar to execute commands on a vulnerable host.
The vulnerability exists in the 'index.php' file. The user supplied value
to the 'userfile' parameter is not properly sanitized.
Commands executed via this method will be executed with the privileges of
the user running the web server process. This could potentially lead to a
denial of service, or a remote attacker gaining elevated privileges.
12. nCipher ConsoleCallBack Class With JRE 1.4.0 Smart Card Passphrase Leak Vulnerability
BugTraq ID: 5024
Remote: No
Date Published: Jun 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5024
Summary:
nCipher produces a range of hardware and software security products.
nCipher also provides development support, including Java classes. An
issue has been reported which could cause the nCipher ConsoleCallBack
class, on Windows NT and 2000, to leak smart card passphrases to shell
users.
This issue is the result of the interaction between the class
com.ncipher.km.nfkm.ConsoleCallBack and version 1.4.0 of the Java Runtime
Environment on Windows. Programs which use this class may be vulnerable.
This issue will arise when a program using the ConsoleCallBack class in
conjunction with the JRE 1.4.0 reads a passphrase from the console in
order to access a card set. Under these conditions, the calling program
will become nonresponsive when the user submits their passphrase.
If the user then presses Control-C to kill the process, the passphrase
will be passed to the console as a command. If history tracking is enabled
in the user's command shell, the history file will contain the entered
passphrase.
It should be noted that this issue only affects a host in which the
ConsoleCallBack is running on. An attacker able to gain access to a
sufficient number of smart cards through observing passphrases, may gain
unauthorized access to application keys. This risk is greater in the event
that the compromised smart cards are for an Administrator card set.
This issue has also been known to exist in the Java version of nCipher's
`TrustedCodeTool'.
13. Cisco Secure ACS Cross-site Scripting Vulnerability
BugTraq ID: 5026
Remote: Yes
Date Published: Jun 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5026
Summary:
Cisco Secure ACS is an access control and accounting server system. It is
distributed and maintained by Cisco, and in this vulnerability affects
implementations on the Microsoft Windows NT platform.
A problem has been discovered in the Secure ACS server that could lead to
the circumvention of browser security.
It has been discovered that the web server component of the Cisco Secure
ACS package allows an attacker to execute cross-site scripting attacks.
A malicious link could be crafted including the specific port of the
Secure ACS web server and arbitrary HTML or script code. When this link
is visited, the attacker-supplied HTML or script code could be executed in
the browser of a user, provided the user has authenticated to the Secure
ACS server.
The attacker-supplied code will be executed in the context of the Secure
ACS server.
14. Xitami GSL Template Vulnerabilities
BugTraq ID: 5025
Remote: Yes
Date Published: Jun 14 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5025
Summary:
Xitami is a webserver for Microsoft Windows operating systems.
A number of vulnerabilities have been reported in Xitami 2.5 Beta versions
GSL Templates. GSL is a server-side scripting language. These issues
appear to be present in an error script. The exact nature of these issues
is not known at this time.
Further technical details will be added as they become available.
Reports indicate that non-beta versions of the software may also be
affected by these issues.
15. Microsoft Internet Explorer CSSText Bold Font Denial Of Service Vulnerability
BugTraq ID: 5027
Remote: Yes
Date Published: Jun 15 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5027
Summary:
A problem with Microsoft Internet Explorer may make it possible to deny
service to users of the browser. The problem is in the handling of
certain types of stylesheet input.
Under some circumstances, it may be possible to crash IE. When IE
encounters a style sheet with the p{cssText} element declared, and a font
weight of bold is specified, the browser becomes unstable, and reacts
unpredictably. This problem has been reported to cause a browser crash in
both IE 5.5 and IE 6.0.
This problem could allow an attacker to crash a vulnerable browser. This
vulnerability is known to affect the 5.5 browser on Windows 98, and 6.0
browser on Windows XP.
16. Zeroboard PHP Include File Arbitrary Command Execution Vulnerability
BugTraq ID: 5028
Remote: Yes
Date Published: Jun 15 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5028
Summary:
Zeroboard is a PHP web board package available for the Linux and Unix
platforms.
A problem with Zeroboard could make it possible for remote users to
execute arbitrary commands.
Under some circumstances, it may be possible to include arbitrary PHP
files. The _head.php file does not sufficiently check or sanitize input.
When the "allow_url_fopen" variable and the "register_globals" variable in
php.ini are set to "On," it is possible to load a PHP include file from a
remote URL via the _head.php script.
Upon loading the arbitrary include file, commands embedded in the file
would be executed on the vulnerable server with the privileges of the HTTP
process. This problem could allow an attacker to execute arbitrary
commands on the vulnerable system.
17. My Postcards MagicCard.CGI Arbitrary File Disclosure Vulnerability
BugTraq ID: 5029
Remote: Yes
Date Published: Jun 15 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5029
Summary:
My Postcards is a commercial available eletronic postcard system. It is
available for Unix and Linux Operating Systems.
A problem with My Postcards could make it possible for a remote attacker
to disclose the contents of arbitrary files.
The magiccard.cgi script does not properly handle some types of input.
As a result, it may be possible for a remote user to specify the location
of a specific file on the system hosting the My Postcards software. Upon
specifying the location of a file that is readable by the web server
process, the user could disclose the contents of the specified file.
This problem could lead to a remote user gaining access to sensitive
information on a system. This could include information such as access
control passwords, or other information stored on the server not meant for
public access.
18. Caucho Technology Resin Server View_Source.JSP Arbitrary File Disclosure Vulnerability
BugTraq ID: 5031
Remote: Yes
Date Published: Jun 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5031
Summary:
Caucho Technology Resin is a servlet and JSP (Java Server Pages) engine
that supports java and javascript. It is built for Unix and Linux variants
as well as Microsoft Windows operating environments.
A vulnerability has been reported in Resin Server 2.1.2, deployed on a
Microsoft Windows platform, that may allow remote attackers to view
contents of arbitrary files.
The 'view_source.jsp' script, found in an example folder as part of the
Resin Server installation, may allow remote attackers access to files
readable by the web server.
The vulnerability occurs when parsing requests for directory traversal.
The 'view_source.jsp' script prevents directory traversal via '/../'
sequences. However, an attacker attempting directory traversal via '\..\'
sequences will succeed. This may allow an attacker to request any files on
the vulnerable system readable by the web server.
This problem could lead to a remote user gaining access to sensitive
information on a system. This could include information such as access
control passwords, or other information stored on the server not meant for
public access.
19. Caucho Technology Resin Server Denial Of Service Vulnerability
BugTraq ID: 5032
Remote: Yes
Date Published: Jun 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5032
Summary:
Caucho Technology Resin is a servlet and JSP (Java Server Pages) engine
that supports java and javascript. It is built for Unix and Linux variants
as well as Microsoft Windows operating environments.
A vulnerability has been reported in Resin Server 2.1.1, deployed on a
Microsoft Windows platform, that may cause Resin Server to cease
functioning properly leading to a denial of service condition.
The vulnerability occurs when a client accesses non-existent resources.
If large variables are defined for such requests, parts (if not all) of
Resin will cease to be fully operational. A denial of service condition
may result.
An attacker may take advantage of this vulnerability to deny service to
legitimate users.
20. Apache Chunked-Encoding Memory Corruption Vulnerability
BugTraq ID: 5033
Remote: Yes
Date Published: Jun 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5033
Summary:
Apache is a freely available webserver for Unix and Linux variants, as
well as Microsoft operating systems.
The HTTP protocol specifies a method of data coding called 'Chunked
Encoding', designed to facilitate fragmentation of HTTP requests in
transit. A vulnerability has been discovered in the Apache implementation
of 'Chunked Encoding'.
When processing requests coded with the 'Chunked Encoding' mechanism,
Apache fails to properly calculate required buffer sizes. This may be due
to improper (signed) interpretation of an unsigned integer value.
Consequently, several conditions may occur that have security
implications. It has been reported that a buffer overrun and signal race
condition occur. Exploitation of these conditions may result in the
execution of arbitrary code.
On Windows and Netware platforms, Apache uses threads within a single
server process to handle concurrent connections. Causing the server
process to crash on these platforms may result in a denial of service.
It has been confirmed that this vulnerability may be exploited to execute
arbitrary code on both Win32 and UNIX platforms.
Note: Products which use or bundle Apache such as Oracle 9iAS or IBM
Websphere may also be affected.
21. Wolfram Research webMathematica File Disclosure Vulnerability
BugTraq ID: 5035
Remote: Yes
Date Published: Jun 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5035
Summary:
Wolfram Research's webMathematica is a Java based product which allows the
inclusion of Mathematica content in a web environment. It includes CGI
programs which generate image content based on user supplied input.
A file disclosure vulnerability has been reported with the MSP CGI
program. MSP is capable of redirecting a HTTP request to a dynamically
generated image, and accepts the filename as a CGI parameter. The user
supplied file name is not properly validated before the file is displayed.
An attacker may include "../" characters in the specified filename, and
escape the specified web root. Arbitrary system files may be disclosed to
the remote user. The disclosure of sensitive system information may aid in
further attacks against the vulnerable system.
22. Zyxel Prestige 642R Malformed Packet Denial Of Service Vulnerability
BugTraq ID: 5034
Remote: Yes
Date Published: Jun 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5034
Summary:
ZyXEL 642R routers have difficulties handling packets with certain TCP
options enabled. In particular, it is possible to deny services by
sending a vulnerable router a SYN-ACK packet. This type of malformed
packet will create a denial of service which can only be remedied by
restarting the device. To a lesser degree, the router also encounters
difficulties when handling SYN-FIN packets. SYN-FIN packets have been
reported to deny service for the duration of a few minutes. This issue
has also been reproduced with other types of malformed packets.
In both instances, some services provided by the router (telnet, FTP and
DHCP) will be denied, however, the device will continue to route network
traffic.
ZyXEL 642R-11 routers are reportedly affected by this vulnerability. It
is possible that other ZyNOS-based routers are also affected by this
vulnerability. ZxXEL 643 ADSL routers do not appear to be prone to this
issue.
This issue may be exploited in combination with the vulnerability
described in Bugtraq ID 3346.
23. NetGear RP114 Administrative Access Via External Interface Vulnerability
BugTraq ID: 5036
Remote: Yes
Date Published: Jun 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5036
Summary:
The NetGear RP114 router includes administrative support through a variety
of mechanisms, including telnet and HTTP. Access to administration tools
is granted to systems with the address 192.168.0.1, reserved for use on
internal networks.
Reportedly, the RP114 router will accept traffic from addresses in the
192.168.x.x range on it's external interface. An attacker external to the
router may be able to connect to the device from this IP, and access the
administrative interface. An attacker may be able to gain access to
sensitive information, or to create a denial of service condition for
legitimate users of the router.
Authentication is still required, however the device has a commonly known
default username of 'admin' with the password '1234'.
Other related devices may share this vulnerability, this has not however
been confirmed.
24. PHPBB2 Install.PHP Remote File Include Vulnerability
BugTraq ID: 5038
Remote: Yes
Date Published: Jun 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5038
Summary:
phpBB2 is an open-source web forum application that is written in PHP and
backended by a number of database products. It will run on most Unix and
Linux variants, as well as Microsoft Windows operating systems.
A problem has been discovered in phpBB2 which may enable an attacker to
include an arbitrary attacker-supplied file which is located on a remote
host.
The problem is that an arbitrary path can be specified as a value for the
'phpbb_root_path' URL parameter. This issue exists in the 'install.php'
script. An attacker may exploit this vulnerability by supplying the
location of a remote file as the value for the 'phpbb_root_path' URL
parameter.
In the case that the remote file is a PHP script, this may allow commands
to be executed remotely with the privileges of the webserver. Successful
exploitation will allow a remote attacker to gain local, interactive
access to a host running the vulnerable software. This is especially a
concern for hosts running Microsoft Windows operating systems, as
webservers are generally run with SYSTEM privileges on these platforms.
25. Solaris 8 dtscreen Authentication Bypass Vulnerability
BugTraq ID: 5040
Remote: No
Date Published: Jun 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5040
Summary:
Solaris 8 ships with CDE utilities, including dtscreen which provides
screen saver functionality, and dtsession which may lock the terminal when
invoking dtscreen.
An issue has been reported in this version of dtscreen. A physically local
user may be able to cause the dtscreen process to crash and access the
terminal, bypassing the need to authenticate in order to unlock the
session.
Allegedly, this can be accomplished by a local user rapidly and repeatedly
pressing the 'Return' and 'Shift' keys. Under some conditions, the
dtscreen process will crash and dump core, leaving the machine
unprotected.
An attacker may be able to exploit this vulnerability to gain access to an
unattended workstation as the currently logged in user.
It is not currently known if this is an issue in dtsession or in dtscreen.
Other versions or operating systems may share this vulnerability, in the
event that it reflects an underlying weakness in CDE. This has not,
however, been confirmed.
26. OSCommerce Remote File Include Vulnerability
BugTraq ID: 5037
Remote: Yes
Date Published: Jun 16 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5037
Summary:
osCommerce is open-source e-commerce software written in PHP. osCommerce
will run on most Unix and Linux variants as well as Microsoft Windows
operating systems.
osCommerce is prone to an issue which may allow remote attackers to
include arbitrary files located on remote servers. This issue is present
in the 'include_once.php'. An attacker may exploit this by supplying a
path to a file on a remote host as a value for the 'include_file'
parameter.
If the remote file is a PHP script, this may allow for execution of
attacker-supplied PHP code with the privileges of the webserver.
Successful exploitation may gain the attacker local access on the affected
host.
27. PHP-Address Remote File Include Vulnerability
BugTraq ID: 5039
Remote: Yes
Date Published: Jun 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5039
Summary:
PHP-Address is an open-source web-based address database written in PHP.
PHP-Address is prone to an issue which may allow remote attackers to
include arbitrary files located on remote servers. This issue is present
in the 'globals.php3' script. An attacker may exploit this by supplying a
path to a file on a remote host as a value for the 'LangCookie' parameter.
If the remote file is a PHP script, this may allow for execution of
attacker-supplied PHP code with the privileges of the webserver.
Successful exploitation may provide local access to the attacker.
28. Cisco uBR7200 / uBR7100 Universal Broadband Routers DOCSIS MIC Bypass Vulnerability
BugTraq ID: 5041
Remote: Yes
Date Published: Jun 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5041
Summary:
A vulnerability has been announced which affects Cisco uBR7200 series and
uBR7100 series Universal Broadband Routers under some versions of IOS.
It is possible to sign DOCSIS configuration files with a Message Integrity
Check (MIC) signature. Based on MD5, this provides a cryptographically
secure signing of the configuration file. It is possible for networks to
reject cable modem devices which do not have a properly signed file.
It is possible to create an invalid DOCSIS file which is truncated and
does not include a MIC signature. Vulnerable routers may nonetheless
accept the configuration file as valid, allowing access to the network.
Malicious cable modem users may create DOCSIS files with arbitrary
configurations, possibly allowing them to bypass limitations such as
bandwith consumption restrictions. Exploitation of this vulnerability may
allow these configuration files to be accepted by the network.
This issue is documented as Cisco Defect number CSCdx72740.
29. MetaLinks MetaCart2.SQL Database Disclosure Vulnerability
BugTraq ID: 5042
Remote: Yes
Date Published: Jun 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5042
Summary:
MetaLinks MetaCart2.sql is a shopping cart application written using ASP
(Active Server Pages). It is intended for use with a Microsoft Windows
operating environment.
A vulnerability has been reported in MetaCart2.sql that will allow remote
attackers to obtain the contents of the user database being used by
MetaCart2.sql.
The vulnerability is a result of MetaCart2.sql storing its user database
in a web accessible directory without any access prevention controls. As
such, a remote attacker is able to request the user database via URL.
This problem could lead to a remote user gaining access to sensitive
information on a system. This could include information such as passwords,
credit card information, or other information stored on the server not
meant for public access.
30. HP MPE/iX Malformed SNMP Vulnerability
BugTraq ID: 5043
Remote: Yes
Date Published: Jun 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5043
Summary:
MPE/iX is an Internet-ready operating system for the HP e3000 class
servers.
A problem with MPE/iX may allow remote attackers to exploit the SNMP
protocol implementation.
Multiple vulnerabilities have been discovered in a number of SNMP
implementations. This vulnerability entry is for the HP MPE/iX
implementation, identifying the "Multiple Vendor SNMP Trap Handling
Vulnerabilities" described in BID 4088, and "Multiple Vendor SNMP Request
Handling Vulnerabilities" discussed in BID 4089.
Among the possible consequences are denial of service and allowing
attackers to compromise target systems.
31. Interbase GDS_Drop Interbase Environment Variable Buffer Overflow Vulnerability
BugTraq ID: 5044
Remote: No
Date Published: Jun 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5044
Summary:
Interbase is a database distributed and maintained by Borland. It is
available for Unix and Linux operating systems.
A problem with Interbase could make it possible for a local user to gain
elevated privileges.
A buffer overflow has been discovered in the setuid root gds_drop program
packaged with Interbase. This problem could allow a local user to execute
the program with strings of arbitrary length. By using a custom crafted
string, the attacker could overwrite stack memory, including the return
address of a function, and potentially execute arbitrary code as root.
The vulnerability occurs in the INTERBASE environment variable. When the
gds_drop program is executed with a string of arbitrary length (typically
500 or more characters) in the INTERBASE environment variable, the result
in an exploitable buffer overflow.
This could make it possible for a local user to gain administrative
access.
32. Interbase GDS_Lock_MGR Interbase Environment Variable Buffer Overflow Vulnerability
BugTraq ID: 5046
Remote: No
Date Published: Jun 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5046
Summary:
Interbase is a database distributed and maintained by Borland. It is
available for Unix and Linux operating systems.
A problem with Interbase could make it possible for a local user to gain
elevated privileges.
A buffer overflow has been discovered in the setuid root program
gds_lock_mgr, packaged with Interbase. This problem could allow a local
user to execute the program with strings of arbitrary length. By using a
custom crafted string, the attacker could overwrite stack memory,
including the return address of a function, and potentially execute
arbitrary code as root.
The vulnerability occurs in the INTERBASE environment variable. When the
gds_lock_mgr program is executed with a string of arbitrary length
(typically 500 or more bytes) in the INTERBASE environment variable, the
result in an exploitable buffer overflow.
This could make it possible for a local user to gain administrative
access.
33. WebScripts WebBBS Remote Command Execution Vulnerability
BugTraq ID: 5048
Remote: Yes
Date Published: Jun 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5048
Summary:
WebBBS is web-based BBS software, written in Perl. WebBBS was designed to
run on Unix and Linux variants.
WebBBS does not sufficiently filter shell metacharacters from CGI
parameters. As a result, remote attackers may execute arbitrary commands
on the underlying shell of the system hosting the vulnerable software.
This issue is known to exist in the 'webbbs_post.pl' script and is due to
insufficient filtering of the 'followup' CGI variable.
Remote attackers may gain local, interactive access to the host with the
privileges of the webserver process as a result of successful
exploitation.
34. DeepMetrix LiveStats HTML Report Script Injection Vulnerability
BugTraq ID: 5047
Remote: Yes
Date Published: Jun 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5047
Summary:
LiveStats parses web server log files into an SQL database, enabling a
user to generate reports defining site traffic. The HTML generated reports
are viewed through the LiveStats web browser interface. LiveStats runs on
Microsoft Windows and is maintained by DeepMetrix, formerly known as
MediaHouse Software.
LiveStats does not filter HTML tags when generating reports. As a result,
it is possible for an attacker to cause arbitrary script code to be
included in HTML reports generated by LiveStats. When a user views the
report page via the browser interface, the script code will be executed in
their browser, in the context of the LiveStats host.
Reportedly, LiveStats displays the browser-tag and referer strings in the
HTML generated reports. Therefore, including script code in the
HTTP_Referer header when submitting a web request for a page being
monitored by LiveStats, will result in the execution of the embedded
script code.
This issue might be exploited to steal cookie-based authentication
credentials from a legitimate user of the software.
This issue has been reported in 6.2, prior versions may also be affected
by this issue.
35. 4D WebServer Long HTTP Request Buffer Overflow Vulnerability
BugTraq ID: 5045
Remote: Yes
Date Published: Jun 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5045
Summary:
4D WebServer is a client/server database management system with integrated
web development and serving. It runs on Microsoft Windows and MacOS
operating systems.
Due to insufficient bounds checking of HTTP requests, 4D WebServer is
prone to a buffer overflow condition. It is possible to overwrite stack
variables such as the return address by overflowing either of these
fields. This may enable a remote attacker to cause a denial of service or
execute attacker-supplied instructions.
It should be noted that the software will run in the SYSTEM context on
multi-user Windows operating systems, so successful exploitation may
result in a full compromise of the host.
This issue may be similar to the vulnerability discussed in BID 4665, 4D
WebServer Authentication Buffer Overflow.
This issue was reported for 4D WebServer version 6.7.3, earlier versions
may also be affected.
36. phpShare Arbitrary Remote PHP File Include Vulnerability
BugTraq ID: 5049
Remote: Yes
Date Published: Jun 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5049
Summary:
phpShare provides upload and download functionality via a web interface.
phpShare is a freely available and is maintained by Drak0n.
phpShare is prone to an issue which may allow remote attackers to include
arbitrary files located on remote servers. This issue is present in the
'phpshare.php' script.
If the remote file is a PHP script, this may allow for execution of
attacker-supplied PHP code with the privileges of the webserver.
Successful exploitation may provide local access to the attacker.
37. Mandrake 8.2 Msec Insecure Default Permissions Vulnerability
BugTraq ID: 5050
Remote: No
Date Published: Jun 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5050
Summary:
Mandrake ships with an interface for setting and maintaining system-wide
security policy during an install of the operating system. This
functionality is provided by the Mandrake-Security package (msec).
Various settings provide differing levels of security.
The Mandrake 8.2 version of msec installs home directories with
world-readable permissions on the Standard security setting. This is
misleading as the Standard (msec level 2) security setting is intended to
be ideal for systems which have multiple local users. This may expose
contents of home directories to other local users. Additionally, msec
will proactively reset the permissions of home directories if they are
changed from the default world-readable permissions.
msec is a mandatory component of Mandrake 8.2 and may not be deselected
during an install of the operating system.
It should be noted that it is still possible to ensure more secure home
directory permissions by using a more restrictive msec setting.
38. UnixWare / Open UNIX ppptalk Local Privilege Escalation Vulnerability
BugTraq ID: 5051
Remote: No
Date Published: Jun 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5051
Summary:
UnixWare and Open UNIX are operating systems maintained by Caldera
Systems.
The ppptalk utility is used to configure the UnixWare/Open UNIX PPP
subsystem. It is installed setuid root by default.
A vulnerability has been reported in the version of ppptalk included with
some versions of Caldera UnixWare and Open UNIX. A malicious local user
may be able to exploit this vulnerability to gain elevated privileges on
the vulnerable system.
The technical nature of this vulnerability is not currently known.
39. Apache Tomcat Web Root Path Disclosure Vulnerability
BugTraq ID: 5054
Remote: Yes
Date Published: Jun 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5054
Summary:
Apache Tomcat is a freely available, open source web server maintained by
the Apache Foundation. It is available for use on Unix and Linux variants
as well as Microsoft Windows operating environments.
A vulnerability has been reported for Apache Tomcat 4.0.3 on a Microsoft
Windows platform. Reportedly, it is possible for a remote attacker to make
requests that will result in Apache Tomcat returning an error page
containing information that includes the absolute path to the server's web
root.
For example, submitting a request for LPT9 to Tomcat will result in the
following error message: "java.io.FileNotFoundException: C:\Program
Files\Apache Tomcat 4.0\webapps\ROOT\lpt9 (The system cannot find the file
specified)"
Gaining knowledge of path information could assist an attacker in further
attacks against the host.
40. IRSSI Long Malformed Topic Denial Of Service Vulnerability
BugTraq ID: 5055
Remote: Yes
Date Published: Jun 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5055
Summary:
irssi is a freely available, open source irc client. irssi is available
for the Linux and Unix operating systems.
irssi version 0.8.4 is prone to a denial of service condition when a user
joins a channel with a long, malformed topic. The vulnerability occurs
when a user attempts to join a channel that has an overly long topic
description. When the string, "\x1b\x5b\x30\x6d\x0d\x0a", is appended to
the topic, irssi will crash resulting in a denial of service.
An attacker can cause irssi clients to crash by changing the topic of a
channel while users are still online or by enticing users to join channels
with malformed topic descriptions.
An attacker may take advantage of this vulnerability to deny service to
legitimate users.
III. SECURITYFOCUS NEWS AND COMMENTARY
------------------------------------------
1. Gobbles Releases Apache Exploit
By Brian McWilliams
Tool makes it easy to hack vulnerable Apache servers under OpenBSD.
http://online.securityfocus.com/news/493
2. Game Consoles -- the Next Hacker Target?
By Alex Handy
Xbox and Playstation 2 decks are coming to the Internet in droves this
fall. How will they stand up against the legions of hackers waiting for
them there?
http://online.securityfocus.com/news/490
4. Court Bars Student Suit Under U.S. Privacy Law
By , Washington Technology
The Supreme Court yesterday barred students from using federal privacy law
to sue schools that divulge their personal information.
http://online.securityfocus.com/news/494
5. MS to pull Java in 2004 - why you knew this already
By John Lettice, The Register
Microsoft, you may have heard from many sources in the past couple of
days, is to stop shipping Java in 2004. Shocking, eh? But you've known
that for well over a year, really.
http://online.securityfocus.com/news/492
IV.SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Apache Chunked Scanner v1.0.0
Relevant URL:
by eEye Digital Security
http://www.eeye.com/html/Research/Tools/apachechunked.html
Platforms: N/A
Summary:
The Retina Apache Chunked Scanner is a tool created by eEye that is able
to scan up to 254 IP addresses at once and determine if any are vulnerable
to the recent Apache Chunked Encoding overflow. If an IP address is found
to be vulnerable to the Apache Chunked Encoding attack, then the Retina
Apache Chunked Scanner will flag the IP address. Administrators can then
double-click on the IP address to be taken to a website with information
on how to fix the vulnerability.
2. Roxy Proxy v1.0.0
by Robert Rose
Relevant URL:
http://www.roxyproxy.com/download/
Platforms: HP-UX, Linux, MacOS, Solaris
Summary:
roxy proxy is a Web proxy load balancer. it is a "proxy for proxies" that
load-balances incoming requests between proxy servers, detects faults, and
measures the performance of its proxy servers.
3. FireDisk
by v0.2
Relevant URL:
http://www.linuxiceberg.com/FireDisk/
Platforms: Linux
Summary:
FireDisk is a firewall-on-a-floppy implementation using iptables. It uses
C code to do the startup and spwans iptables to apply filters to the
2.4.18 kernel.
4. Ganglia Cluster Toolkit - Gmetad Web Frontend branch v0.1.0
by Matt Massie
http://ganglia.sourceforge.net/
Platforms: Linux
Summary:
Ganglia provides a complete real-time monitoring and execution environment
that is in use by hundreds of universities, private and government
laboratories, and commercial cluster implementors around the world.
Ganglia is as simple to install and use on a 16-node cluster as it is to
use on a 512-node cluster, as has been proven by its use on multiple 500+
node clusters.
5. amavis-notify-parser v0.2
by Martin List-Petersen
Relevant URL:
http://sourceforge.net/projects/amavis-n-parser/
Platforms: Os Independent
Summary:
amavis-notify-parser analyzes hostmaster notifications from Amavis and
writes a logfile which records the type and origin of the viruses
detected. It requires only a piped mail alias, a PHP4 CGI binary, and
Amavis. McAfee uvscan is supported as the virus scanner. The logfile may
be output in qmail's logfile format.
6. Tiger security tool v3.0
by Javier Fernández-Sanguino Peña
Relevant URL:
http://savannah.gnu.org/projects/tiger/
Platforms: UNIX
Summary:
TIGER is a set of Bourne shell scripts, C programs, and data files which
are used to perform a security audit of Unix systems. The security audit
results are useful both for system analysis (security auditing) and for
real-time, host-based intrusion detection.
V. SECURITY JOBS SUMMARY
------------------------
1. Security Specialist in OR looking for possible relocation (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
2. Application Security Architect - Greythorn (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/5544986F9407D611A5900008C70964061A6396@EXCHANGE
3. Available for Security work -- PART TIME - (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
4. Information Security Manager - Central NJ - $110k (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
5. Seeking Security/Forensic Analyst Position in NY (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/FB1F64412FB78D46A1630FE40D483EAFEA2E7E@mitnoc01n2
6. I T Risk Assessment Manager in Kansa City (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
7. Solaris/Raptor Position (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
8. Security Architect positions in Chicago area (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
9. Sales Engineer-Distributed firewalls/network solutions-CA (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
10. SWE security for SW and Web Services-Immediate in CA (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
11. W2K Security Professional (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
12. Jr./Intermediate Vulnerability Analyst Position (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
13. Chief Information Security Officer - OH - #701 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
14. PKI Senior Pre-sales Consultant EMEA (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/D1DC442B7557D611A3C50050BAAED8181C0E@ERA01
15. Director of Information Technology Position in Chicago and other Network Security Positions (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
16. Microsoft Exploit/Countermeasure Research and Development Engineer (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
17. Security Professional seeking a new opportunity (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
VI. INCIDENTS LIST SUMMARY
-------------------------
1. Worm1800.exe on UnderNet? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/Pine.GSO.4.21.0206201554300.3844-100000@andromeda.sd.us.am.ericsson.se
2. Port 4927 traffic spike (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
3. Strange web vulnerability scanner (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
4. automatic hacking tool for IIS? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
5. ICMP Destination Unreachable in SNORT (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/20C62FD75D71F74786A0036B35A6CFF91854D2@newsub506.Int.Synapsegroupinc.com
6. New script-kiddie looking scan (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
7. DOS by Flooding a Network (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
8. Distributed ICMP/UDP scan or attack? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
9. remote openssh probe or crack?. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. Re[2]: Apache Exploit (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
2. Apache Exploit (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
3. apache chunked encoding (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
4. procmail heap overflow (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
5. Re: apache chunked encoding (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
6. Apache Worm? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/Pine.GSO.3.96.1020619130011.22344A-100000@crypto
7. ISS Advisory: Remote Compromise Vulnerability in Apache HTTP Server (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/75C025AE395F374B81F6416B1D4BDEFB7D2AD0@MTV-CORPMAIL
8. FW: ISS Advisory: Remote Compromise Vulnerability in Apache HTTP Server (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
9. Shoutcast Admin password bruteforce tool (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
10. Vulnerability Coordination (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
11. CERT Advisory CA-2002-17 Apache Web Server Chunk Handling Vulnerability... (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
12. Wellenreiter-v1.4 introduces ESSID-bruteforcing (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
13. DOS in Win2k/XP in LAN (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
14. Interbase 6.0 malloc() issues (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
15. This is not a BUG but an Issue in MS02-18: Why Ms02-18 " Q319733_W2K_SP3_X86_EN.exe" contain one file that belong to IIS 4.0 ? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
16. Recent "rumors" (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
17. Re [BUGTRAQ] : ZyXEL 642R(-11) AJ.6 SYN-ACK, SYN-FIN DoS (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
18. m64config (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/Pine.LNX.4.44.0206171119270.2669-100000@mail
19. openbse rumours (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
20. Clarification - IE gopher cross site scripting (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
21. DNS zone transfer (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
22. [Fwd: IE gopher cross site scripting] (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
23. /_vti_bin/_vti_aut/dvwssr.ddl (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
24. Best Buy re-activates WLANs (fwd) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/DB8542C86AAED411B29100B0D03ECFB1D82EB9@HQEXCHANGE01
25. Windows Buffer Overflows (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/001001c21502$a18bb240$6301a8c0@visp
26. Another cgiemail bug (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/Pine.GSO.4.44.0206141115280.12770-100000@westnet
27. wireless issues (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Null session and Exchange2K (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/D503BBD92FE9D2118A010008C75F644814FB9C35@usnssexc20.us.kworld.kpmg.com
2. MS02-29 breaks PPTP connections for non-Admin users? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
3. SecurityFocus Microsoft Newsletter #91 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
4. backing up IE config (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/94BE36C72683404F84258BBFEE6A826004668621@dua-msg-01.middleeast.corp.microsoft.com
5. xcacls and a service account (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
IX. SUN FOCUS LIST SUMMARY
----------------------------
1. ssh help (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/Pine.LNX.4.21.0206141137580.32143-100000@simpleinfo.simpleinfo.co.uk
X. LINUX FOCUS LIST SUMMARY
---------------------------
1. Have I been kitted? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/[email protected]
2. Web filtering? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/Pine.BSO.4.44.0206131728060.9397-100000@paperboy.websocietyinc.com
XI. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored by: Blackhat
Attend Black Hat Briefings & Training, July 29 - August 1, Las Vegas, the
world's premier technical security event! 8 tracks, 12 training sessions,
Richard Clarke keynote, 1500 delegates from 30 nations, with a near cult
following of both CSOs and "underground" security experts. See for
yourself what the buzz is all about.
Visit us at: http://www.blackhat.com
-------------------------------------------------------------------------------