SecurityFocus Newsletter #271

Peter Laborge <[email protected]> 19 Oct 2004 23:10:35 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #271
------------------------------

This Issue is Sponsored By: Check Point

Your internal network is vulnerable and must be protected from worms,
Trojan horses, spyware and other threats.
Download a free, fact-filled Internal Security Information Kit to learn
how. Includes new META Group white paper, Flash demo, and much more.
Download now -- free!

http://www.securityfocus.com/sponsor/CheckPoint_sf-news_041019

------------------------------------------------------------------------
I. FRONT AND CENTER
     1. Securing Exchange With ISA Server 2004
     2. SSH Host Key Protection
II. BUGTRAQ SUMMARY
     1. BNC  sbuf_getmsg() Buffer Overflow Vulnerability
     2. MySQL Multiple Local Vulnerabilities
     3. Turbo Traffic Trader PHP Multiple Input Validation Vulnerabi...
     4. CJOverkill Multiple Cross-Site Scripting Vulnerabilities
     5. Apache mod_ssl SSLCipherSuite Access Validation Vulnerabilit...
     6. Go Smart Inc GoSmart Message Board Multiple Input Validation...
     7. Zanfi CMS Lite Remote File Include Vulnerability
     8. DUware Software Multiple Remote Vulnerabilities
     9. Macromedia ColdFusion MX CreateObject And CFOBJECT Java Exte...
     10. Microsoft Windows Kernel Local Denial of Service Vulnerabili...
     11. Microsoft Internet Explorer Install Engine ActiveX Control B...
     12. Microsoft Internet Explorer Heartbeat ActiveX Control Unspec...
     13. OCPortal Content Management System Remote File Include Vulne...
     14. Microsoft Windows Kernel Virtual DOS Machine Privilege Escal...
     15. ASN.1 Compiler Multiple Unspecified Vulnerabilities
     16. IceWarp Web Mail Multiple Unspecified Remote Input Validatio...
     17. Microsoft Windows NetDDE Remote Buffer Overflow Vulnerabilit...
     18. Microsoft Excel File Handler Buffer Overflow Vulnerability
     19. Microsoft SMTP Service and Exchange Routing Engine Buffer Ov...
     20. Microsoft Windows WMF/EMF Image Format Rendering Remote Buff...
     21. Microsoft CABARC Directory Traversal Vulnerability
     22. Microsoft Internet Explorer Double Byte Character Set Handli...
     23. Microsoft Window Management API Local Privilege Escalation V...
     24. Microsoft NNTP Component Heap Overflow Vulnerability
     25. Microsoft RPC Runtime Library Remote Denial Of Service And I...
     26. Microsoft Internet Explorer Plug-in Navigations Handling Add...
     27. Microsoft Windows Compressed (zipped) Folder Buffer Overflow...
     28. Microsoft Internet Explorer Secure Sockets Layer Caching Vul...
     29. Microsoft IIS Server WebDAV XML Requests Denial of Service V...
     30. Squid Proxy SNMP ASN.1 Parser Denial Of Service Vulnerabilit...
     31. Adobe Acrobat Reader Remote Access Validation Vulnerability
     32. Microsoft Windows 2003 Services Default SACL Access Right We...
     33. Microsoft Internet Explorer Unspecified showHelp Zone Bypass...
     34. Research In Motion Blackberry Remote Denial of Service Vulne...
     35. phpMyAdmin Remote Command Execution Vulnerability
     36. SCT Campus Pipeline Render.UserLayoutRootNode.uP Cross-Site ...
     37. FuseTalk Forum IMG Tag HTML Injection Vulnerability
     38. LibTIFF Multiple Buffer Overflow Vulnerabilities
     39. FuseTalk Forum Multiple Cross-Site Scripting Vulnerabilities
     40. 3Com 3CRADSL72 ADSL Wireless Router Information Disclosure a...
     41. ShixxNOTE 6.net Remote Buffer Overflow Vulnerability
     42. Microsoft Windows XP Weak Default Configuration Vulnerabilit...
     43. Macromedia JRun Management Console HTML Injection Vulnerabil...
     44. Microsoft Frontpage Asycpict.DLL JPEG Handling Remote Denial...
     45. Macromedia JRun Session ID Cookie HTTP Response Splitting Vu...
     46. Macromedia JRun Management Console Administrative Session Fi...
     47. Pinnacle Systems ShowCenter SettingsBase.PHP Cross-Site Scri...
     48. MediaWiki Multiple Remote Input Validation Vulnerabilities
     49. Unzoo Undisclosed Directory Traversal Vulnerability
     50. MailEnable Multiple Remote Denial Of Service Vulnerabilities
     51. KDocker Unspecified Vulnerability
     52. Federico David Sacerdoti Ansel Insecure Default Permissions ...
     53. Veritas Cluster Server Superuser Compromise Vulnerability
     54. 3Com OfficeConnect ADSL Wireless 11g Firewall Router Multipl...
     55. NatterChat Unspecified SQL Injection Vulnerability
     56. Ideal Science IdealBB Multiple Unspecified Remote Input Vali...
     57. CyberStrong eShop ASP Shopping Cart Unspecified Cross-Site S...
     58. Express-Web Content Management System Unspecified Cross-Site...
     59. AliveSites Forum Multiple Unspecified Remote Input Validatio...
     60. DevoyBB Forum Multiple Unspecified Remote Input Validation V...
     61. WowBB Forum Multiple Unspecified Remote Input Validation Vul...
     62. ProFTPD Authentication Delay Username Enumeration Vulnerabil...
     63. WeHelpBUS Undisclosed Remote Command Execution Vulnerability
     64. Yak! Chat Client FTP Server Directory Traversal Vulnerabilit...
     65. DMXReady Site Chassis Manager Cross-Site Scripting And SQL I...
III. SECURITYFOCUS NEWS ARTICLES
     1. U.S. Air Traffic Control Found Vulnerable
     2. Patriot Act tour carried a hefty price tag
     3. Shifting cyber threats menace factory floors
     4. 419ers take Aussie financial advisor for AU$1m
     5. New Google tool for searching computers a privacy risk on sh...
     6. Watch out, there's a scammer about
IV. SECURITYFOCUS TOP 6 TOOLS
     1. ByteShelter I 1.0
     2. MobileJavaScanner 1.0
     3. JavaCallTester 1.0
     4. DiskInternals Uneraser 2.01
     5. DiskInternals NTFS Reader 1.01
     6. Airscanner Mobile Firewall 1.0
V. SECURITYJOBS LIST SUMMARY
     1. [SJ-JOB] Sr. Security Analyst, Washgton, DC, US (Thread)
     2. [SJ-JOB] Technical Writer, Washington, DC, US (Thread)
     3. [SJ-JOB] VP, Information Security, chennai, IN (Thread)
     4. [SJ-JOB] Manager, Information Security, Houston, US (Thread)
     5. [SJ-JOB] Sr. Security Analyst, Washington, DC, US (Thread)
     6. [SJ-JOB] Information Assurance Analyst, Washington, ... (Thread)
     7. [SJ-JOB] Sr. Product Manager, San Diege, US (Thread)
     8. [SJ-JOB] Security Auditor, Warren, US (Thread)
     9. [SJ-JOB] Auditor, Toledo, US (Thread)
     10. [SJ-JOB] Security Researcher, Dallas / Fort Worth, U... (Thread)
     11. [SJ-JOB] Management, San Bruno, US (Thread)
     12. [SJ-JOB] Management, Denver, US (Thread)
     13. [SJ-JOB] Account Manager, London (Sutton), GB (Thread)
     14. [SJ-JOB] Security Engineer, San Francisco, US (Thread)
     15. [SJ-JOB] Account Manager, Chicago, US (Thread)
     16. [SJ-JOB] Security Architect, Washington, US (Thread)
     17. [SJ-JOB] CHECK Team Leader, London, GB (Thread)
     18. [SJ-JOB] Quality Assurance, Santa Monica, US (Thread)
     19. [SJ-JOB] Security Consultant, Mountain View, US (Thread)
     20. [SJ-JOB] Security Consultant, Manhattan, US (Thread)
     21. [SJ-JOB] Security Consultant, New York, US (Thread)
VI. INCIDENTS LIST SUMMARY
     NO NEW POSTS FOR THE WEEK 2004-10-12 to 2004-10-19.
VII. VULN-DEV RESEARCH LIST SUMMARY
     NO NEW POSTS FOR THE WEEK 2004-10-12 to 2004-10-19.
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. Remote connections (Thread)
     2. Remove domain user from local administrators group (Thread)
     3. Can we really block users from installing applicatio... (Thread)
IX. SUN FOCUS LIST SUMMARY
     1. non crypt() password problems (Thread)
X. LINUX FOCUS LIST SUMMARY
     NO NEW POSTS FOR THE WEEK 2004-10-12 to 2004-10-19.
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION

I. FRONT AND CENTER
-------------------
1. Securing Exchange With ISA Server 2004
By Jonathan Hassell

This article will highlight the security issues involved with providing
Outlook Web Access or full Outlook client connections over the Internet,
and then discuss how Microsoft's new ISA Server 2004 can be configured to
mitigate these threats.

http://www.securityfocus.com/infocus/1807


2. SSH Host Key Protection
By Brian Hatch

This is the first in a series of articles on SSH in-depth. We start with
looking at standard SSH host keys by examining the verification process to
ensure you have not been the victim of an attack.

http://www.securityfocus.com/infocus/1806

II. BUGTRAQ SUMMARY
-------------------
1. BNC  sbuf_getmsg() Buffer Overflow Vulnerability
BugTraq ID: 11355
Remote: Yes
Date Published: Oct 09 2004
Relevant URL: http://www.securityfocus.com/bid/11355
Summary:
A boundary condition error in BNC that is potentially a vulnerability has been discovered and corrected.  The overflow occurs in procedure sbuf_getmsg().  Prior to version 2.8.9, BNC attempted to support "backspace" byte values found in the raw network data by using a pointer decrement to "erase" the previous byte of the destination buffer in a copy loop.  This was done without checks to ensure that the pointer to the destination buffer did not point to a location beyond the boundary of the destination buffer space.  This has created a potential buffer overflow condition that can be triggered remotely by untrusted data.  The data would likely come from an IRC server.  

The overflow occurs in the BSS region, exploitability has not been confirmed.

2. MySQL Multiple Local Vulnerabilities
BugTraq ID: 11357
Remote: No
Date Published: Oct 11 2004
Relevant URL: http://www.securityfocus.com/bid/11357
Summary:
MySQL is reported prone to multiple local vulnerabilities.  These issues may allow an attacker to bypass security restrictions or cause a denial of service condition in the application.

It is reported that an attacker can bypass certain security restrictions and gain access to and corrupt potentially sensitive data due to an error in 'ALTER TABLE ... RENAME' operations.

A denial of service condition presents itself when multiple threads ALTER MERGE tables to change the UNION.

Due to a lack of details, further information is not available at the moment.  This BID will be updated as more information becomes available.

3. Turbo Traffic Trader PHP Multiple Input Validation Vulnerabi...
BugTraq ID: 11358
Remote: Yes
Date Published: Oct 11 2004
Relevant URL: http://www.securityfocus.com/bid/11358
Summary:
Turbo Traffic Trader PHP is reported prone to multiple input validation vulnerabilities.  These issues may allow a remote attacker to carry out cross-site scripting and SQL injection attacks.

Turbo Traffic Trader PHP version 1.0 is reported prone to these vulnerabilities.  It is possible that other versions are affected as well.

4. CJOverkill Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 11359
Remote: Yes
Date Published: Oct 11 2004
Relevant URL: http://www.securityfocus.com/bid/11359
Summary:
It is reported that CJOverkill is affected by various cross-site scripting vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied URI input. 

CJOverkill version 4.0.3 is reported prone to these issues.  It is possible that other versions are affected as well.

5. Apache mod_ssl SSLCipherSuite Access Validation Vulnerabilit...
BugTraq ID: 11360
Remote: Yes
Date Published: Oct 11 2004
Relevant URL: http://www.securityfocus.com/bid/11360
Summary:
Apache 2.x mod_ssl is reported prone to an access validation vulnerability.  This issue presents itself when mod_ssl is configured to be used with the 'SSLCipherSuite' directive.  It is reported that this vulnerability allows a client to use any cipher suite allowed by the virtual host configuration regardless of cipher suites specified for a specific directory.  This can allow an attacker to bypass security policies and access potentially sensitive data.

Apache versions 2.0.35 to 2.0.52 are reported vulnerable to this issue.

6. Go Smart Inc GoSmart Message Board Multiple Input Validation...
BugTraq ID: 11361
Remote: Yes
Date Published: Oct 11 2004
Relevant URL: http://www.securityfocus.com/bid/11361
Summary:
GoSmart Message Board is reported prone to multiple input validation vulnerabilities. These issues may allow a remote attacker to carry out cross-site scripting and SQL injection attacks.  The cause of these issue is insufficient sanitization of user-supplied data.

7. Zanfi CMS Lite Remote File Include Vulnerability
BugTraq ID: 11362
Remote: Yes
Date Published: Oct 11 2004
Relevant URL: http://www.securityfocus.com/bid/11362
Summary:
Zanfi CMS Lite is reported prone to a remote file include vulnerability.  This issue presents itself because the application fails to sanitize user-supplied data properly. This issue may allow an attacker to include malicious files containing arbitrary script code to be executed on a vulnerable computer. 

Zanfi CMS Lite 1.1 is reported prone to this vulnerability. It is possible that other versions are affected as well.

8. DUware Software Multiple Remote Vulnerabilities
BugTraq ID: 11363
Remote: Yes
Date Published: Oct 11 2004
Relevant URL: http://www.securityfocus.com/bid/11363
Summary:
Multiple vulnerabilities have been identified in the software that may allow a remote attacker to carry out SQL injection and HTML injection attacks.  An attacker may also gain unauthorized access to a user's account.

DUclassmate may allow unauthorized remote attackers to gain access to a computer.

DUclassified is reported prone to multiple SQL injection vulnerabilities.

SQL injection issues also affect DUforum.

DUclassified and DUforum are also reported vulnerable to various unspecified HTML injection vulnerabilities.

9. Macromedia ColdFusion MX CreateObject And CFOBJECT Java Exte...
BugTraq ID: 11364
Remote: Yes
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11364
Summary:
It is reported that ColdFusion MX contains a weakness that allows all developers to utilize the CFOBJECT tag and the CreateObject function to execute potentially malicious code in the context of the affected application server.

This weakness allows malicious developers to execute code that is not appropriate for a shared server environment, or to perform administrative actions in the context of the affected application server. Malicious developers may possibly exploit this weakness to aid them in further application or system attacks.

Versions 6.0 and 6.1 of Macromedia ColdFusion MX are reported to be affected by this weakness.

10. Microsoft Windows Kernel Local Denial of Service Vulnerabili...
BugTraq ID: 11365
Remote: No
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11365
Summary:
The Microsoft Windows kernel is prone to a denial of service vulnerability.  This issue can allow a local attacker to cause a vulnerable computer to stop responding and restart.  This can effectively deny service to legitimate users.

This issue does not pose a privilege escalation threat.

11. Microsoft Internet Explorer Install Engine ActiveX Control B...
BugTraq ID: 11366
Remote: Yes
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11366
Summary:
A remotely exploitable buffer overflow vulnerability exists in the Microsoft Internet Explorer Install Engine ActiveX control.  This vulnerability is caused by insufficient bounds checking of arguments passed to the control.  

The vulnerability may be exploited to execute arbitrary code in the context of the client user.

** Update: NGSSoftware has released a preliminary advisory for this issue announcing that technical details will be withheld until January 19th, 2005.

12. Microsoft Internet Explorer Heartbeat ActiveX Control Unspec...
BugTraq ID: 11367
Remote: Yes
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11367
Summary:
An unspecified vulnerability exists in the Microsoft Internet Explorer Heartbeat MSN gaming ActiveX control (heartbeat.ocx).

13. OCPortal Content Management System Remote File Include Vulne...
BugTraq ID: 11368
Remote: Yes
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11368
Summary:
Reportedly ocPortal is affected by a remote file include vulnerability.  This issue is due to a failure of the application to sanitize user supplied URI input.

An attacker might leverage this issue to run arbitrary server side script code on a vulnerable computer with the privileges of the web server process.  This may potentially result in a compromise of the vulnerable computer as well as other attacks.

14. Microsoft Windows Kernel Virtual DOS Machine Privilege Escal...
BugTraq ID: 11369
Remote: No
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11369
Summary:
Microsoft Windows Kernel Virtual DOS Machine is reported prone to a local privilege escalation vulnerability.

The Microsoft Virtual DOS Machine (VDM) is a protected environment that emulates MS-DOS on Windows NT-based operating systems.  This issue arises due to an access validation error.  A local attacker can exploit this vulnerability to gain elevated privileges on a vulnerable computer.

15. ASN.1 Compiler Multiple Unspecified Vulnerabilities
BugTraq ID: 11370
Remote: Yes
Date Published: Oct 11 2004
Relevant URL: http://www.securityfocus.com/bid/11370
Summary:
ASN.1 Compiler is reported prone to multiple unspecified vulnerabilities.  The following issues were reported by the vendor:

An issues affecting ASN.1 Compiler presents itself during explicitly tagged ANY type encoding and decoding.

Another security issue involves indefinite length structures appearing in the extensions in CHOICE code.

ASN.1 Compiler versions 0.9.4 is reported prone to these issues.  It is probable that other versions are affected as well.

16. IceWarp Web Mail Multiple Unspecified Remote Input Validatio...
BugTraq ID: 11371
Remote: Yes
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11371
Summary:
Multiple unspecified remote input validation vulnerabilities reportedly affect IceWarp Web Mail.  These issues are due to a failure of the application to validate or filter user-supplied input.

Although the impact of all of these issues is currently unknown, it is known that an attacker can exploit some of these issues to carry out cross-site scripting attacks.

17. Microsoft Windows NetDDE Remote Buffer Overflow Vulnerabilit...
BugTraq ID: 11372
Remote: Yes
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11372
Summary:
Microsoft Windows NetDDE is affected by a remote buffer overflow vulnerability.  This issue is due to a failure of the application to properly verify the lengths of strings contained within unspecified network messages prior to copying them into finite buffers.

It should be noted that NetDDE is not activated by default on Windows computers.

An attacker may leverage this issue to execute arbitrary code on an affected computer with SYSTEM privileges. It is also noted that in some circumstances, where NetDDE services have been installed but not started, local attackers might exploit this issue to gain elevated privileges since it may be possible for an unprivileged user to start the services.

** Update: NGSSoftware has released a preliminary advisory for this issue announcing that technical details will be withheld until January 19th, 2005.

** Update: Immunity Research has reported that a remote attacker may require authentication prior to the exploitation of this vulnerability. Further details of this report can be found in the referenced message "ms04-031 pre-auth ??".

18. Microsoft Excel File Handler Buffer Overflow Vulnerability
BugTraq ID: 11373
Remote: Yes
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11373
Summary:
Microsoft Excel is reported prone to an buffer overflow vulnerability. The issue presents itself when the vulnerable software handles a malicious Excel file. 

Ultimately a remote attacker may exploit this vulnerability to execute arbitrary code. Code execution will occur in the context of a user that is using a vulnerable version of Excel to view a malicious Excel spreadsheet.

19. Microsoft SMTP Service and Exchange Routing Engine Buffer Ov...
BugTraq ID: 11374
Remote: Yes
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11374
Summary:
The Microsoft Windows 2003 SMTP Service and Exchange Routing Engine have been reported prone to a buffer overflow.  This occurs during the processing responses to DNS lookups.  Successful exploitation could allow for remote code execution in the context of the vulnerable service.

20. Microsoft Windows WMF/EMF Image Format Rendering Remote Buff...
BugTraq ID: 11375
Remote: Yes
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11375
Summary:
Microsoft Windows WMF/EMF image rendering library is affected by a remote buffer overflow vulnerability.  This issue is due to a failure of the affected library to properly verify the lengths of strings contained within an affected image file prior to copying them into finite buffers.

Any code execution that occurs will take place with SYSTEM privileges due to the nature of the affected library. This will also permit local privilege escalation attacks.

21. Microsoft CABARC Directory Traversal Vulnerability
BugTraq ID: 11376
Remote: No
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11376
Summary:
CABARC is reported prone to a directory traversal vulnerability.  This issue may allow a local attacker to gain access to potentially sensitive files on a vulnerable computer.

It is reported that an attacker can escape the path by supplying '../' character sequences.

22. Microsoft Internet Explorer Double Byte Character Set Handli...
BugTraq ID: 11377
Remote: Yes
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11377
Summary:
It is reported that Microsoft Internet Explorer is prone to a vulnerability that may allow a malicious Web page to spoof the address bar of the browser. This vulnerability presents itself due to a malfunction that occurs when certain double byte characters are encountered. As a result, this vulnerability will only affect computers that are configured to employ double byte character sets.  

This could be used to lure Web users into a false sense of trust since a malicious or spoofed site may pose as a site that is trusted by the user.

23. Microsoft Window Management API Local Privilege Escalation V...
BugTraq ID: 11378
Remote: No
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11378
Summary:
Microsoft has reported that several unspecified Window Management API functions can allow a local attacker to change the attributes of an application with higher level of privileges.  This can allow the attacker to gain elevated privileges on a vulnerable computer.

This issue represents a fundamental design flaw, as certain messages used to communicate between windows on a desktop may adversely affect the operation of a receiving process.  By altering various properties of window components running with higher privileges, an attacker can create circumstances where attacks such as buffer overflows and potential arbitrary code execution are possible.

This issue likely affects some native Windows applications but other third-party applications may also provide an opportunity for exploitation.

24. Microsoft NNTP Component Heap Overflow Vulnerability
BugTraq ID: 11379
Remote: Yes
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11379
Summary:
The Microsoft Network News Transfer Protocol (NNTP) Component is prone to a buffer overflow condition.  Successful exploitation of this vulnerability could allow remote code execution in the context of the process accessing the vulnerable component.

25. Microsoft RPC Runtime Library Remote Denial Of Service And I...
BugTraq ID: 11380
Remote: Yes
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11380
Summary:
Microsoft RPC Runtime Library is affected by a remote denial of service and information disclosure vulnerability.  This issue is due to a failure of the library to properly handle exceptional network traffic.

An attacker may leverage this issue to disclose potentially sensitive information and to cause the affected application to crash, denying service to legitimate users.

26. Microsoft Internet Explorer Plug-in Navigations Handling Add...
BugTraq ID: 11381
Remote: Yes
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11381
Summary:
It is reported that Microsoft Internet Explorer is prone to a vulnerability that may allow a malicious Web page containing embedded flash multimedia to spoof the address bar of the browser.
 
This could be used to lure Web users into a false sense of trust since a malicious or spoofed site may pose as a site that is trusted by the user.

27. Microsoft Windows Compressed (zipped) Folder Buffer Overflow...
BugTraq ID: 11382
Remote: Yes
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11382
Summary:
Microsoft Windows contains a buffer overflow in the Compressed (zipped) Folders feature.  A maliciously crafted compressed file could overrun an internal buffer causing arbitrary code to be executed in the security context of the current user.

28. Microsoft Internet Explorer Secure Sockets Layer Caching Vul...
BugTraq ID: 11383
Remote: Yes
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11383
Summary:
Microsoft Internet Explorer is reported prone to a Secure Sockets Layer caching vulnerability.

It is reported that arbitrary content may be cached to the computer that is viewing a malicious site when this vulnerability is exploited. This cached content will be rendered in the context of a legitimate site when a legitimate site is viewed.

29. Microsoft IIS Server WebDAV XML Requests Denial of Service V...
BugTraq ID: 11384
Remote: Yes
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11384
Summary:
Microsoft IIS Server is prone to a remote denial of service vulnerability when handling malformed WebDAV requests.  The vulnerability exists in the Microsoft XML Parser component and can be exploited through the WebDAV XML message handler.  

It is reported that this issue requires a remote attacker to create specially crafted WebDAV requests and send them to a vulnerable server over TCP port 80.  There is a possibility of increased CPU resource and memory consumption as the IIS server attempts to process these requests.   This can eventually lead to a denial of service condition in the server.  A reboot is required to restore normal functionality.

This vulnerability can also be exploited through other applications that rely on Microsoft XML Parser to process XML messages.

30. Squid Proxy SNMP ASN.1 Parser Denial Of Service Vulnerabilit...
BugTraq ID: 11385
Remote: Yes
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11385
Summary:
It is reported that Squid is susceptible to a denial of service vulnerability in its SNMP ASN.1 parser. SNMP support is not enabled by default as provided by the vendor. It may be enabled by default when Squid is included as a binary application in certain unconfirmed operating systems.

This vulnerability allows remote attackers to crash affected Squid proxies with single UDP datagrams that may be spoofed. Squid will attempt to restart itself automatically, but an attacker sending repeated malicious SNMP packets can effectively deny service to legitimate users.

Squid versions 2.5-STABLE6 and earlier, as well as 3.0-PRE3-20040702 are reported vulnerable to this issue.

31. Adobe Acrobat Reader Remote Access Validation Vulnerability
BugTraq ID: 11386
Remote: Yes
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11386
Summary:
An access validation vulnerability affects Adobe Acrobat Reader.  This issue is due to a design error that allows a malicious file to be embedded inside a Portable Document Format (PDF) file.

An attacker may leverage this issue to disclose files that are readable by the unsuspecting user who activates a malicious PDF file.  Information disclosed in this way may facilitate further attacks against the affected computer.

32. Microsoft Windows 2003 Services Default SACL Access Right We...
BugTraq ID: 11387
Remote: No
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11387
Summary:
It is reported that the default SACL access right settings for multiple Microsoft Windows 2003 services are weak.

Reports indicate that several services have lax permissions that will allow unprivileged local users to start them.

Because any user can start these services, an administrator may be under a false sense of security.

33. Microsoft Internet Explorer Unspecified showHelp Zone Bypass...
BugTraq ID: 11388
Remote: Yes
Date Published: Oct 12 2004
Relevant URL: http://www.securityfocus.com/bid/11388
Summary:
Microsoft Security Bulletin MS04-038 includes fixes to address an unspecified vulnerability in Internet Explorer that may permit elevation of zone privileges by bypassing from the Internet Zone to the Local Zone.  

The vendor has stated that additional security verifications have been added to prevent the showHelp DHTML method from being abused by a malicious Web site to load HTML Help files in the context of the Local Zone.  It is unclear at this point whether they mean HTML Help files that already exist on the system or HTML Help files that originate from a remote source.

Although unconfirmed, this could be related to the following unspecified vulnerability that was addressed in Windows XP SP2/BID 10897 (  	 Microsoft Windows XP SP2 Released - Multiple Vulnerabilities Fixed):

- HTML Help Update to Limit Functionality When It Is Invoked with the window.showHelp( ) Method

This is likely similar to earlier issues that have been reported in showHelp, such as BID 9320.  Microsoft has not released further details about this vulnerability.

34. Research In Motion Blackberry Remote Denial of Service Vulne...
BugTraq ID: 11389
Remote: Yes
Date Published: Oct 13 2004
Relevant URL: http://www.securityfocus.com/bid/11389
Summary:
The Research In Motion Blackberry 7230 is affected by a remote denial of service vulnerability.  This issue is due to the device attempting to copy a  long message in to flash memory.

An attacker may leverage this issue to cause the affected device to restart, causing a loss of all email messages saved on the device.

Update:  This issue was originally identified as a buffer overflow vulnerability.  New information suggests that it is only a remote denial of service condition.  This BID is being updated to reflect this information.

35. phpMyAdmin Remote Command Execution Vulnerability
BugTraq ID: 11391
Remote: Yes
Date Published: Oct 13 2004
Relevant URL: http://www.securityfocus.com/bid/11391
Summary:
phpMyAdmin is reported prone to a remote command execution vulnerability.  This vulnerability likely arises due to insufficient sanitization of user-supplied data.

A successful attack may allow an attacker to execute arbitrary commands on a vulnerable server resulting in a compromise of the server.

phpMyAdmin 2.6.0-pl1 and prior versions are affected by this issue.

36. SCT Campus Pipeline Render.UserLayoutRootNode.uP Cross-Site ...
BugTraq ID: 11392
Remote: Yes
Date Published: Oct 13 2004
Relevant URL: http://www.securityfocus.com/bid/11392
Summary:
Campus Pipeline is affected by a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input. 

This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

37. FuseTalk Forum IMG Tag HTML Injection Vulnerability
BugTraq ID: 11393
Remote: Yes
Date Published: Oct 13 2004
Relevant URL: http://www.securityfocus.com/bid/11393
Summary:
FuseTalk Forum is prone to an HTML injection vulnerability. This is because the script that processes posts does not sufficiently sanitize user input, allowing attackers to embed HTML and script commands within the post.

The attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user.

38. LibTIFF Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 11406
Remote: Yes
Date Published: Oct 13 2004
Relevant URL: http://www.securityfocus.com/bid/11406
Summary:
LibTIFF is affected by multiple buffer overflow vulnerabilities. This issue is due to a failure of the application to properly perform boundary checks prior to copying user-supplied strings into finite process buffers.

An attacker may leverage these issues to execute arbitrary code on a vulnerable computer with the privileges of the user running the vulnerable application, facilitating unauthorized access.  These issues may also be leveraged to cause an affected application to crash.

39. FuseTalk Forum Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 11407
Remote: Yes
Date Published: Oct 13 2004
Relevant URL: http://www.securityfocus.com/bid/11407
Summary:
FuseTalk Forum is reported prone to multiple input validation vulnerabilities. These issues may allow a remote attacker to carry out cross-site scripting attacks. The cause of these issues is insufficient sanitization of user-supplied data.

The first issue is reported to exist because the software echoes unsanitized request data as part of an error page to the origin of the request. This makes it possible for an attacker to a construct a malicious link containing HTML or script code, the attacker-supplied code will be rendered as part of an error message if a target user follows the malicious URI link.

FuseTalk Forum is reported prone to an additional cross-site scripting vulnerability.

The problem presents itself when malicious HTML and script code is sent to the 'tombstone.cfm' script through a URI parameter.

This may allow for theft of cookie-based authentication credentials or other attacks.

40. 3Com 3CRADSL72 ADSL Wireless Router Information Disclosure a...
BugTraq ID: 11408
Remote: Yes
Date Published: Oct 13 2004
Relevant URL: http://www.securityfocus.com/bid/11408
Summary:
3Com 3CRADSL72 is reported prone to an information disclosure, and an authentication bypass vulnerability.  This issue can allow a remote attacker to disclose sensitive information such as the router name, primary and secondary DNS servers, default gateway. Attackers could also reportedly gain administrative access to the router.

If successful, these vulnerabilities can be used to the launch of other attacks against the device and other users on the vulnerable network.

41. ShixxNOTE 6.net Remote Buffer Overflow Vulnerability
BugTraq ID: 11409
Remote: Yes
Date Published: Oct 13 2004
Relevant URL: http://www.securityfocus.com/bid/11409
Summary:
ShixxNOTE 6.net is reported susceptible to a remote buffer overflow vulnerability. This issue is due to a failure of the application to properly perform boundary checks prior to copying user-supplied strings into finite process buffers.

An attacker may leverage this issue to execute arbitrary code on a vulnerable computer with the privileges of the user running the vulnerable application.

42. Microsoft Windows XP Weak Default Configuration Vulnerabilit...
BugTraq ID: 11410
Remote: No
Date Published: Oct 13 2004
Relevant URL: http://www.securityfocus.com/bid/11410
Summary:
Microsoft Windows XP Service Pack 2 is reported prone to a weak default configuration vulnerability. Internet Connection Firewall (ICF) includes functionality that controls what binaries are permitted to listen for incoming connections.

It is reported that one of the executables that is permitted to listen for incoming network connections may provide a conduit to bypass ICF access controls. Due to a configuration weakness, this executable is accessible for all users.

A local attacker may exploit this vulnerability to create a listening port to provide remote access to a vulnerable computer.

43. Macromedia JRun Management Console HTML Injection Vulnerabil...
BugTraq ID: 11411
Remote: Yes
Date Published: Oct 14 2004
Relevant URL: http://www.securityfocus.com/bid/11411
Summary:
Macromedia JRun is prone to an HTML injection vulnerability.  This issue exists in the Management Console and may allow hijacking of administrative sessions.

44. Microsoft Frontpage Asycpict.DLL JPEG Handling Remote Denial...
BugTraq ID: 11412
Remote: Yes
Date Published: Oct 14 2004
Relevant URL: http://www.securityfocus.com/bid/11412
Summary:
Microsoft Frontpage is reported prone to multiple remote denial of service vulnerabilities when handling malformed JPEG files.  These issues exist due to insufficient verification performed by the 'asycpict.dll' module.

Reportedly, these issues can only cause a denial of service condition, however, it may be possible to execute arbitrary code on a vulnerable computer as well.  This has not been confirmed at the moment.

It should be noted that in an initial advisory these vulnerabilities were reported to affect the 'asycpict.dll' library. In the report it is mentioned that this library is shipped with all versions of Microsoft Windows XP, however, conflicting reports indicate that this is not accurate. These conflicting reports indicate that this library is in fact shipped with Microsoft Front Page 97 and 98. Additionally, one of these reports indicated that the library was also shipped with Microsoft Internet Explorer version 3.01. This is not confirmed.

Due to a lack of details, further information is not available at the moment. This BID will be updated as more information becomes available.

45. Macromedia JRun Session ID Cookie HTTP Response Splitting Vu...
BugTraq ID: 11413
Remote: Yes
Date Published: Oct 14 2004
Relevant URL: http://www.securityfocus.com/bid/11413
Summary:
An HTTP response splitting vulnerability affects Macromedia JRun due to Session ID handling.  This issue is due to a failure of the application to properly handle how POST requests are processed.

A remote attacker may exploit this vulnerability to influence or misrepresent how web content is served, cached or interpreted. This could aid in various attacks, which try to entice client users into a false sense of trust.

46. Macromedia JRun Management Console Administrative Session Fi...
BugTraq ID: 11414
Remote: Yes
Date Published: Oct 14 2004
Relevant URL: http://www.securityfocus.com/bid/11414
Summary:
Macromedia JRun is prone to session fixation vulnerability.  This issue exists in the Management Console. 

The application is reported prone to session fixation vulnerability.  This attack can allow an attacker to set a session ID in a user's browser and hijack the user's session upon authentication to JRun.

This issue can allow remote attackers to bypass authentication checks, and possibly allow them to gain administrative access to the web application. 

This issue was originally reported in BID 11245 (Macromedia JRun Multiple Remote Vulnerabilities).  It is now being separated and assigned a new BID.

47. Pinnacle Systems ShowCenter SettingsBase.PHP Cross-Site Scri...
BugTraq ID: 11415
Remote: Yes
Date Published: Oct 14 2004
Relevant URL: http://www.securityfocus.com/bid/11415
Summary:
Pinnacle Systems ShowCenter is affected by a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input. 

This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user.

48. MediaWiki Multiple Remote Input Validation Vulnerabilities
BugTraq ID: 11416
Remote: Yes
Date Published: Oct 14 2004
Relevant URL: http://www.securityfocus.com/bid/11416
Summary:
MediaWiki is reported prone to multiple cross-site scripting, HTML injection, and SQL injection vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied input data.

HTML injection, and cross-site scripting vulnerabilities allow for attacker-supplied HTML and script code to be executed in the victims browser in the context of the affected site.

SQL injection vulnerabilities allow attackers to manipulate SQL queries, potentially revealing or corrupting sensitive database data. This issue may also facilitate attacks against the underlying database software.

These vulnerabilities are reported to exist in MediaWiki version 1.3.5, but other versions are also possibly affected.

49. Unzoo Undisclosed Directory Traversal Vulnerability
BugTraq ID: 11417
Remote: No
Date Published: Oct 14 2004
Relevant URL: http://www.securityfocus.com/bid/11417
Summary:
The unzoo utility is reported prone to an undisclosed directory traversal vulnerability. It is conjectured that this issue may exist due to a lack of sufficient sanitization performed on the filenames of members contained in a zoo archive.

This BID will be updated when further information regarding this vulnerability is released.

50. MailEnable Multiple Remote Denial Of Service Vulnerabilities
BugTraq ID: 11418
Remote: Yes
Date Published: Oct 14 2004
Relevant URL: http://www.securityfocus.com/bid/11418
Summary:
MailEnable is affected by multiple remote denial of service vulnerabilities.  These issues are due to a failure of the application to handle malformed requests.

An attacker may leverage these issues to cause the IMAP and SNMP services to crash, denying service to legitimate users.

51. KDocker Unspecified Vulnerability
BugTraq ID: 11419
Remote: No
Date Published: Oct 14 2004
Relevant URL: http://www.securityfocus.com/bid/11419
Summary:
KDocker is reported prone to an unspecified vulnerability.  The vendor reported this issue in KDocker versions 0.8 and prior.  The cause and impact of this issue are currently unknown.  It is conjectured that due to the nature of this issue, it may allow a local attacker to gain elevated privileges or compromise a computer locally.

Due to a lack of details, further information is not available at the moment.  This BID will be updated as more information becomes available.

52. Federico David Sacerdoti Ansel Insecure Default Permissions ...
BugTraq ID: 11420
Remote: Yes
Date Published: Oct 14 2004
Relevant URL: http://www.securityfocus.com/bid/11420
Summary:
Ansel is reported prone to an insecure default permissions vulnerability.  It is reported that the application creates picture albums with insecure permissions.  This can allow remote attackers to gain unauthorized access to Web readable directories.

Ansel versions 2.0 and prior are reported prone to this issue.

53. Veritas Cluster Server Superuser Compromise Vulnerability
BugTraq ID: 11421
Remote: Unknown
Date Published: Oct 15 2004
Relevant URL: http://www.securityfocus.com/bid/11421
Summary:
Veritas Cluster Server is affected by a superuser compromise vulnerability.  The underlying cause for this issue is currently unknown.

An attacker can leverage this issue to gain superuser access to an affected computer, facilitating privileged unauthorized access.  It is currently not known if this issue is remotely or locally exploitable; this BID will be updated as more details are released.

54. 3Com OfficeConnect ADSL Wireless 11g Firewall Router Multipl...
BugTraq ID: 11422
Remote: Yes
Date Published: Oct 15 2004
Relevant URL: http://www.securityfocus.com/bid/11422
Summary:
3Com OfficeConnect ADSL Wireless 11g Firewall Router is reported prone to multiple unspecified vulnerabilities.  The following issues were reported:

An unspecified issue affects the DHCP service.

Another issue is related to displaying two duplicate login IPs.

An unspecified denial of service vulnerability may allow remote attackers to restart the device.  This issue occurs due to insufficient boundary checks performed by the application.

3Com OfficeConnect ADSL Wireless 11g Firewall Router firmware versions prior to 1.27 are vulnerable to these issues.

**UPDATE: it should be noted that the issue described as an error in displaying two duplicate IPs has been assigned it own BID as more information has become available.  Please see '3Com OfficeConnect ADSL Wireless 11g Firewall Router Authentication Bypass Vulnerability' (BID 11438) for more information.

55. NatterChat Unspecified SQL Injection Vulnerability
BugTraq ID: 11423
Remote: Yes
Date Published: Oct 14 2004
Relevant URL: http://www.securityfocus.com/bid/11423
Summary:
An unspecified SQL injection vulnerability is identified in the application that may allow attackers to pass malicious input to database queries, resulting in the modification of query logic or other attacks. 

This vulnerability exists due to insufficient sanitization of user-supplied input. It may be possible for a remote user to inject arbitrary SQL queries into the underlying database used by the application. This could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks. 

Successful exploitation could result in compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation. 

This issue is reported to exist in NatterChat 1.12. Other versions may be affected as well.

56. Ideal Science IdealBB Multiple Unspecified Remote Input Vali...
BugTraq ID: 11424
Remote: Yes
Date Published: Oct 15 2004
Relevant URL: http://www.securityfocus.com/bid/11424
Summary:
Ideal Science IdealBB is reported prone to multiple unspecified input validation vulnerabilities.  These issues result from insufficient sanitization of user-supplied data.

It is reported that the application is affected by SQL injection, cross-site scripting and HTTP response splitting vulnerabilities.

All versions of IdealBB are considered vulnerable at the moment.

57. CyberStrong eShop ASP Shopping Cart Unspecified Cross-Site S...
BugTraq ID: 11425
Remote: Yes
Date Published: Oct 15 2004
Relevant URL: http://www.securityfocus.com/bid/11425
Summary:
An unspecified cross-site scripting vulnerability exists in CyberStrong eShop ASP Shopping Cart.  This could potentially be exploited to steal cookie-based authentication credentials or launch other attacks.

58. Express-Web Content Management System Unspecified Cross-Site...
BugTraq ID: 11426
Remote: Yes
Date Published: Oct 15 2004
Relevant URL: http://www.securityfocus.com/bid/11426
Summary:
An unspecified cross-site scripting vulnerability exists in Express-Web Content Management System.  This could potentially be exploited to steal cookie-based authentication credentials or launch other attacks.

59. AliveSites Forum Multiple Unspecified Remote Input Validatio...
BugTraq ID: 11427
Remote: Yes
Date Published: Oct 15 2004
Relevant URL: http://www.securityfocus.com/bid/11427
Summary:
Alivesites Forum is reported prone to multiple unspecified input validation vulnerabilities. These issues result from insufficient sanitization of user-supplied data.

It is reported that the application is affected by SQL injection and cross-site scripting vulnerabilities. 

AliveSites Forum 2.0 may be affected by these issues.

60. DevoyBB Forum Multiple Unspecified Remote Input Validation V...
BugTraq ID: 11428
Remote: Yes
Date Published: Oct 15 2004
Relevant URL: http://www.securityfocus.com/bid/11428
Summary:
DevoyBB is reportedly affected by multiple input validation vulnerabilities.  These issues are due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamic web content and SQL database queries.

An attacker can leverage these issues to manipulate or reveal database contents through SQL injection attacks as well as carry out other attacks and steal cookie-based authentication credentials through cross-site scripting attacks.

61. WowBB Forum Multiple Unspecified Remote Input Validation Vul...
BugTraq ID: 11429
Remote: Yes
Date Published: Oct 15 2004
Relevant URL: http://www.securityfocus.com/bid/11429
Summary:
WowBB is reportedly affected by multiple input validation vulnerabilities.  These issues are due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamic web content and SQL database queries.

An attacker can leverage these issues to manipulate or reveal database contents through SQL injection attacks as well as carry out other attacks and steal cookie-based authentication credentials through cross-site scripting attacks.

62. ProFTPD Authentication Delay Username Enumeration Vulnerabil...
BugTraq ID: 11430
Remote: Yes
Date Published: Oct 15 2004
Relevant URL: http://www.securityfocus.com/bid/11430
Summary:
A timing attack is described in ProFTPD that could assist a remote user in enumerating usernames.

A remote attacker may exploit this vulnerability to determine what usernames are valid, privileged, or do not exist on the remote system.

63. WeHelpBUS Undisclosed Remote Command Execution Vulnerability
BugTraq ID: 11431
Remote: Yes
Date Published: Oct 15 2004
Relevant URL: http://www.securityfocus.com/bid/11431
Summary:
WeHelpBUS is reported prone to an undisclosed command execution vulnerability. 

An attacker could leverage this issue to execute arbitrary shell commands on a vulnerable computer with the privileges of the web server process.

This BID will be updated as soon as further information regarding this issue is made available.

64. Yak! Chat Client FTP Server Directory Traversal Vulnerabilit...
BugTraq ID: 11433
Remote: Yes
Date Published: Oct 15 2004
Relevant URL: http://www.securityfocus.com/bid/11433
Summary:
Yak! Chat Client FTP server is reported prone to a remote directory traversal vulnerability.  This issue presents itself due to insufficient sanitization of user-supplied data.

This issue can ultimately allow an attacker to compromise a computer by placing malicious files on the system and executing these files through other means.

Yak! 2.1.2 and prior versions are reported vulnerable to this issue.

65. DMXReady Site Chassis Manager Cross-Site Scripting And SQL I...
BugTraq ID: 11434
Remote: Yes
Date Published: Oct 15 2004
Relevant URL: http://www.securityfocus.com/bid/11434
Summary:
It is reported that DMXReady Site Chassis Manager is susceptible to two remotely exploitable input validation vulnerabilities. These vulnerabilities are due to a failure of the application to properly sanitize user-supplied data.

The first issue is an unspecified cross-site scripting vulnerability. This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

The second issue is an unspecified SQL injection vulnerability. It may be possible for a remote user to inject arbitrary SQL queries into the underlying database used by the application. This could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.

Successful exploitation could result in compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. U.S. Air Traffic Control Found Vulnerable
By: Kevin Poulsen

In the wake of last month's air traffic communications failure, investigators report that computer security issues haunt the FAA's most critical systems.

http://www.securityfocus.com/news/9729

2. Patriot Act tour carried a hefty price tag
By: Kevin Poulsen

U.S. Attorney General Ashcroft spent $200,000 of taxpayer money promoting the embattled surveillance law coast-to-coast. 

http://www.securityfocus.com/news/9703

3. Shifting cyber threats menace factory floors
By: Kevin Poulsen

A new report says that external attackers have overtaken insiders as the most likely cyber threat to remote-controlled factory equipment. 
http://www.securityfocus.com/news/9671

4. 419ers take Aussie financial advisor for AU$1m
By: Lester Haines, The Register

A Melbourne financial manager faces a hefty prison sentence after stealing AU$1m from his clients and handing it over to Nigerian advance fee fraudsters.

http://www.securityfocus.com/news/9753

5. New Google tool for searching computers a privacy risk on sh...
By: Anick Jesdanun, The Associated Press

http://www.securityfocus.com/news/9745

6. Watch out, there's a scammer about
By: Tim Richardson, The Register

The British government has unveiled a new website to help punters "wise up to scams".

http://www.securityfocus.com/news/9742

IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. ByteShelter I 1.0
By: MazZoft NDA
Relevant URL: http://www.mazzoft.com/bs1.zip
Platforms: Windows 2000, Windows 95/98
Summary: 

This steganography tools lets you conceal data in Outlook e-mail messages and .doc files.

2. MobileJavaScanner 1.0
By: Arne Vidstrom
Relevant URL: http://vidstrom.net/stools/mobilejavascanner/
Platforms: Java
Summary: 

MobileJavaScanner is a TCP port scanner MIDlet (Java program for cellular phones).

3. JavaCallTester 1.0
By: Arne Vidstrom
Relevant URL: http://www.vidstrom.net/stools/javacalltester/
Platforms: Java
Summary: 

JavaCallTester is a MIDlet (Java program for cellular phones) that tries to make a phone call. You can use JavaCallTester to test if your mobile phone implements the correct security policy for MIDlets or not.

4. DiskInternals Uneraser 2.01
By: Alexey Babenko
Relevant URL: http://diskinternals.com/download/Uneraser_Setup.zip
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary: 

DiskInternals Uneraser can recover any deleted file, including documents, photos, mp3 and zip files, or even folders and damaged disks. In addition to HDD, the program supports any type of storage media (music sticks, cameras, flash drives, USB drives, etc)! It works with encrypted files and helps you undelete file lost because of a virus attack or an employee's malicious behavior. No special skills needed; 100% free to try.

5. DiskInternals NTFS Reader 1.01
By: Alexey Babenko
Relevant URL: http://diskinternals.com/download/NTFS_Reader_Setup.zip
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary: 

Provides read access to NTFS disks from Windows 95, 98 and Me. Allows you to save any files to any disk visible on the system or on the network. Supports saving compressed or encrypted files.

While saving, it ignores file security policies. It means that it is possible to access absolutely any file on a NTFS disk from Windows 9x.

6. Airscanner Mobile Firewall 1.0
By: Airscanner Corp
Relevant URL: http://www.airscanner.com/downloads/fw/amfw.exe
Platforms: Windows CE
Summary: 

A Full-Strength Personal Firewall for Your Windows Mobile/Pocket PC handheld.

Airscanner Mobile Firewall for Windows Mobile Pocket PC is a low-level, bi-directional, packet filtering firewall that examines all incoming and outgoing TCP/IP traffic.

This personal firewall ensures that data is permitted based on access control lists that you select from a set of predefined filters, or from filters that you create yourself.

The firewall parses packets as they come in (or go out)

V. SECURITYJOBS LIST SUMMARY
----------------------------
1. [SJ-JOB] Sr. Security Analyst, Washgton, DC, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378271

2. [SJ-JOB] Technical Writer, Washington, DC, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378270

3. [SJ-JOB] VP, Information Security, chennai, IN (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378268

4. [SJ-JOB] Manager, Information Security, Houston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378266

5. [SJ-JOB] Sr. Security Analyst, Washington, DC, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378263

6. [SJ-JOB] Information Assurance Analyst, Washington, ... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378258

7. [SJ-JOB] Sr. Product Manager, San Diege, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378218

8. [SJ-JOB] Security Auditor, Warren, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378217

9. [SJ-JOB] Auditor, Toledo, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378216

10. [SJ-JOB] Security Researcher, Dallas / Fort Worth, U... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378156

11. [SJ-JOB] Management, San Bruno, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378154

12. [SJ-JOB] Management, Denver, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378152

13. [SJ-JOB] Account Manager, London (Sutton), GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378149

14. [SJ-JOB] Security Engineer, San Francisco, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378148

15. [SJ-JOB] Account Manager, Chicago, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378147

16. [SJ-JOB] Security Architect, Washington, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378144

17. [SJ-JOB] CHECK Team Leader, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378137

18. [SJ-JOB] Quality Assurance, Santa Monica, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378116

19. [SJ-JOB] Security Consultant, Mountain View, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378115

20. [SJ-JOB] Security Consultant, Manhattan, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378114

21. [SJ-JOB] Security Consultant, New York, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/378111

VI. INCIDENTS LIST SUMMARY
--------------------------
NO NEW POSTS FOR THE WEEK 2004-10-12 to 2004-10-19.

VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
NO NEW POSTS FOR THE WEEK 2004-10-12 to 2004-10-19.

VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. Remote connections (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/378293

2. Remove domain user from local administrators group (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/378282

3. Can we really block users from installing applicatio... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/378246

IX. SUN FOCUS LIST SUMMARY
--------------------------
1. non crypt() password problems (Thread)
Relevant URL:

http://www.securityfocus.com/archive/92/378161

X. LINUX FOCUS LIST SUMMARY
---------------------------
NO NEW POSTS FOR THE WEEK 2004-10-12 to 2004-10-19.

XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.
    
XII. SPONSOR INFORMATION
-----------------------

This Issue is Sponsored By: Check Point

Your internal network is vulnerable and must be protected from worms,
Trojan horses, spyware and other threats.
Download a free, fact-filled Internal Security Information Kit to learn
how. Includes new META Group white paper, Flash demo, and much more.
Download now -- free!

http://www.securityfocus.com/sponsor/CheckPoint_sf-news_041019

------------------------------------------------------------------------