SecurityFocus Newsletter #273

Peter Laborge <[email protected]> 2 Nov 2004 18:11:41 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #273
------------------------------

This Issue is Sponsored By: BindView

What questions should you be asking to improve internal security? Why are
firewalls not enough to protect you? What are some of the traditional
attack vectors? What are some of the biggest threats you face for attacks
against non-controlled assets? And how can you protect your environments
from these internal threats? During the BindView November 11 Webinar,
"Internal Security: Threat Identification and Remediation" security expert,
Mark "Simple Nomad" Loveless with the BindView RAZOR team, will provide you
with information to help you better secure your environment. 
Register at: 

http://www.securityfocus.com/sponsor/BindView_sf-news_041102

------------------------------------------------------------------------
I. FRONT AND CENTER
     1. Trends in Web Application Security
     2. Phishing For Savvy Users
II. BUGTRAQ SUMMARY
     1. DWC_Articles Multiple Unspecified SQL Injection Vulnerabilit...
     2. Microsoft Internet Explorer Malformed HTML Null Pointer Dere...
     3. Mozilla Bugzilla Multiple Authentication Bypass and Informat...
     4. Window Maker WMGLOBAL Font Specification Format String Vulne...
     5. SKForum My Wiki/Wiki Unspecified Vulnerability
     6. OpenWFE Remote Cross-Site Scripting And Connection Proxy Vul...
     7. Microsoft Internet Explorer Malformed IFRAME Remote Buffer O...
     8. MoniWiki Cross-Site Scripting Vulnerability
     9. LinuxStat Remote Directory Traversal Vulnerability
     10. IPplan Multiple Unspecified SQL Injection Vulnerabilities
     11. NetCaptor Cross-Domain Dialog Box Spoofing Vulnerability
     12. NetCaptor Cross-Domain Tab Window Form Field Focus Vulnerabi...
     13. Microsoft Internet Explorer HHCtrl ActiveX Control Cross-Dom...
     14. Mozilla Temporary File Insecure Permissions Information Disc...
     15. GD Graphics Library Remote Integer Overflow Vulnerability
     16. phpCodeGenie PHP Code Injection Vulnerability
     17. WVTFTP Server Remote Buffer Overflow Vulnerability
     18. Libxml2 Multiple Remote Stack Buffer Overflow Vulnerabilitie...
     19. InetUtils TFTP Client Remote Buffer Overflow Vulnerability
     20. Kaffeine Remote Buffer Overflow Vulnerability
     21. PostNuke Trojan Horse Vulnerability
     22. Slim Browser Cross-Domain Tab Window Form Field Focus Vulner...
     23. ICab Web Browser Cross-Domain Dialog Box Spoofing Vulnerabil...
     24. Slim Browser Cross-Domain Dialog Box Spoofing Vulnerability
     25. Linux Kernel ReiserFS File System Local Denial Of Service Vu...
     26. PPPD Remote Denial Of Service Vulnerability
     27. Tabs Laboratories MailCarrier Remote SMTP EHLO/HELO Buffer O...
     28. Microsoft Internet Explorer Font Tag Denial Of Service Vulne...
     29. Novell ZENworks System Tray Local Privilege Escalation Vulne...
     30. Phorum Unspecified Cross-Site Scripting and SQL Injection Vu...
     31. Hummingbird Connectivity INETD32 Privilege Escalation Vulner...
     32. SudoSH Undisclosed SHELL Environment Variable Vulnerability
     33. Google Desktop Search Remote Cross-Site Scripting Vulnerabil...
     34. Hummingbird Connectivity FTP Server Denial Of Service Vulner...
     35. Hawking Technology HAR11A DSL Router Unauthenticated Adminis...
     36. Omni Group OmniWeb Browser Cross-Domain Dialog Box Spoofing ...
     37. PHPList Multiple unspecified Vulnerabilities
     38. Horde Application Framework Help Window Unspecified Cross-Si...
     39. Mega Upload Progress Bar Unspecified File Upload Vulnerabili...
     40. PuTTY Remote SSH2_MSG_DEBUG Buffer Overflow Vulnerability
     41. Quicksilver Master of Orion III Multiple Remote Denial of Se...
     42. ID Software Quake II Server Multiple Remote Vulnerabilities
     43. KDE Konqueror IFRAME Cross-Domain Scripting Vulnerability
     44. Apple QuickTime Remote Integer Overflow Vulnerability
     45. Apple Remote Desktop Administrator Privilege Escalation Vuln...
     46. RealNetworks RealOne Player/RealPlayer Skin File Remote Stac...
     47. ZGV Image Viewer Multiple Remote Integer Overflow Vulnerabil...
     48. PHP cURL Open_Basedir Restriction Bypass Vulnerability
     49. Multiple Vendor Content Filtering Bypass Vulnerabilities
     50. Microsoft Internet Explorer TABLE Status Bar URI Obfuscation...
     51. Global Spy Software Cyber Web Filter IP Filter Bypass Vulner...
     52. Roaring Penguin Software MIMEDefang Multiple Unspecified Vul...
     53. Shadow Authentication Bypass Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
     1. New Caller I.D. spoofing site opens
     2. Report card day looms for federal agencies
     3. California reports massive data breach
     4. IE exploits top web security threat list
     5. Free training offer is latest spam scam
     6. Google blocks Gmail exploit
IV. SECURITYFOCUS TOP 6 TOOLS
     1. Maillog View  v1.03.3
     2. BullDog Firewall 20040918
     3. WapgGuihttp://workspaces.gotdotnet.com/wapggui 1.0
     4. antinat v0.81
     5. PopMessenger 1.60
     6. ByteShelter I 1.0
V. SECURITYJOBS LIST SUMMARY
     1. [SJ-JOB] Manager, Information Security, New York, US (Thread)
     2. [SJ-JOB] Sales Engineer, McLean, US (Thread)
     3. [SJ-JOB] Information Assurance Engineer, Rockford, U... (Thread)
     4. [SJ-JOB] Application Security Engineer, Battle Creek... (Thread)
     5. [SJ-JOB] Sales Representative, Chicago, US (Thread)
     6. [SJ-JOB] Sales Engineer, London, GB (Thread)
     7. [SJ-JOB] Security Architect, Woonsocket, US (Thread)
     8. [SJ-JOB] Account Manager, London, GB (Thread)
     9. [SJ-JOB] Security Engineer, Orlando, US (Thread)
     10. [SJ-JOB] Security Engineer, Mt. Laurel, US (Thread)
     11. [SJ-JOB] Sales Engineer, Dallas or Houston, NYC, and... (Thread)
     12. [SJ-JOB] Sales Representative, San Francisco, US (Thread)
     13. [SJ-JOB] Security Consultant, Zurich or Geneva/Lausa... (Thread)
     14. [SJ-JOB] Management, New York, US (Thread)
     15. [SJ-JOB] Account Manager, Any, US (Thread)
     16. [SJ-JOB] Account Manager, Home based - US wide role,... (Thread)
     17. [SJ-JOB] Security Auditor, Dublin, IE (Thread)
     18. [SJ-JOB] Account Manager, Home based - US wide, US (Thread)
     19. [SJ-JOB] Security Auditor, Brussels, BE (Thread)
     20. [SJ-JOB] Security Auditor, London and Bristol, GB (Thread)
     21. [SJ-JOB] Security Product Marketing Manager, Redwood... (Thread)
     22. [SJ-JOB] Security Researcher, Silicon Valley, US (Thread)
     23. [SJ-JOB] Compliance Officer, Jersey City, US (Thread)
     24. [SJ-JOB] Channel / Business Development, London, GB (Thread)
     25. [SJ-JOB] Developer, Sunnyvale, US (Thread)
     26. [SJ-JOB] Security System Administrator, Austin, US (Thread)
     27. [SJ-JOB] Sr. Security Analyst, Northern, US (Thread)
     28. [SJ-JOB] Director, Information Security, Philadelphi... (Thread)
     29. [SJ-JOB] Security Consultant, (North East ) NY/NJ - ... (Thread)
     30. [SJ-JOB] Application Security Engineer, Bethpage, US (Thread)
     31. [SJ-JOB] Director, Information Security, Santa Monic... (Thread)
     32. [SJ-JOB] Security Architect, Bedford, US (Thread)
     33. [SJ-JOB] Account Manager, San Diego, US (Thread)
     34. [SJ-JOB] Security Engineer, Manhattan, US (Thread)
     35. [SJ-JOB] Security System Administrator, Oklahoma Cit... (Thread)
     36. [SJ-JOB] Compliance Officer, Philadelphia, US (Thread)
     37. [SJ-JOB] Security Consultant, Based in any U.S. city... (Thread)
VI. INCIDENTS LIST SUMMARY
     1. Security Issues with Wake on Lan (WOL) (Thread)
     2. Strange FTP logs (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. Solaris/SPARC heap overflow examples (Thread)
     2. CanSecWest/core05 Call for Papers - May 4-6 2005 - D... (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. 802.1x Authentication (Thread)
     2. GPO that forces users to use a proxy server. (Thread)
     3. Remove "Shutdown" command from w2k PCs but enable re... (Thread)
     4. Notifying users of password expiration via e-mail` (Thread)
     5. RE: Can we really block users from installing applic... (Thread)
     6. SecurityFocus Microsoft Newsletter #212 (Thread)
IX. SUN FOCUS LIST SUMMARY
     NO NEW POSTS FOR THE WEEK 2004-10-26 to 2004-11-02.
X. LINUX FOCUS LIST SUMMARY
     1. Linux security compliance (Thread)
     2. Strange Attack On A Webserver I Work On (Thread)
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION

I. FRONT AND CENTER
-------------------
1. Trends in Web Application Security
By Kapil Raina

This article discusses current trends in penetration testing for web
application security, and in particular discusses a framework for selecting
the best tool or tools to use for these increasingly common type of
application. 

http://www.securityfocus.com/infocus/1809


2. Phishing For Savvy Users
By Scott Granneman

Recent "phishing" episodes are still often overlooked by tech-savvy users,
but a lesson in history shows how entire nations have been fooled.

http://www.securityfocus.com/columnists/274

II. BUGTRAQ SUMMARY
-------------------
1. DWC_Articles Multiple Unspecified SQL Injection Vulnerabilit...
BugTraq ID: 11509
Remote: Yes
Date Published: Oct 23 2004
Relevant URL: http://www.securityfocus.com/bid/11509
Summary:
Multiple SQL injection vulnerabilities are alleged to exist in DWC_Articles.  These issues are reported to be present in nearly all of the scripts associated with the software, though the individual who reported these issues has not published any further details about the specific vulnerabilities.

Successful exploitation could allow remote attackers to compromise the software or potentially compromise security properties of the underlying database.

2. Microsoft Internet Explorer Malformed HTML Null Pointer Dere...
BugTraq ID: 11510
Remote: Yes
Date Published: Oct 23 2004
Relevant URL: http://www.securityfocus.com/bid/11510
Summary:
Microsoft Internet Explorer is prone to a vulnerability that may permit malformed HTML to crash the browser.  The source of the crash is reportedly a null pointer dereference.

3. Mozilla Bugzilla Multiple Authentication Bypass and Informat...
BugTraq ID: 11511
Remote: Yes
Date Published: Oct 25 2004
Relevant URL: http://www.securityfocus.com/bid/11511
Summary:
Mozilla Bugzilla is affected by multiple authentication bypass and information disclosure vulnerabilities.  These issues are due to a failure of the application to properly validate access permissions of a user prior to revealing or altering information.

An attacker can leverage these issues to disclose bug details that are marked private as well as edit bug reports without requiring authorization.

4. Window Maker WMGLOBAL Font Specification Format String Vulne...
BugTraq ID: 11512
Remote: No
Date Published: Oct 25 2004
Relevant URL: http://www.securityfocus.com/bid/11512
Summary:
A format string vulnerability has been reported in Window Maker related to validation of font specifications in the WMGLOBAL configuration file.  A user could potentially include malicious format specifiers through font specifications in the WMGLOBAL configuration file.  

The vulnerability would be triggered when the configuration file is read by the program, potentially allowing arbitrary code execution in the context of the program.

5. SKForum My Wiki/Wiki Unspecified Vulnerability
BugTraq ID: 11513
Remote: Yes
Date Published: Oct 25 2004
Relevant URL: http://www.securityfocus.com/bid/11513
Summary:
An unspecified vulnerability exists in SKForum.  This issue is related to the "my wiki" and "wiki" features of the software.  Due to the nature of the software, this issue is likely remotely exploitable.

6. OpenWFE Remote Cross-Site Scripting And Connection Proxy Vul...
BugTraq ID: 11514
Remote: Yes
Date Published: Oct 25 2004
Relevant URL: http://www.securityfocus.com/bid/11514
Summary:
OpenWFE is affected by a cross-site scripting and connection proxy vulnerability.  These issues are due to a failure of the application to properly sanitize user-supplied input.

An attacker may leverage the cross-site scripting issue to steal cookie-based authentication credentials as well as carry out other attacks by executing client-based script code in an unsuspecting user's browser.  An attacker may leverage the connection proxy issue to scan arbitrary network computers anonymously, facilitating further attacks.

7. Microsoft Internet Explorer Malformed IFRAME Remote Buffer O...
BugTraq ID: 11515
Remote: Yes
Date Published: Oct 24 2004
Relevant URL: http://www.securityfocus.com/bid/11515
Summary:
Microsoft Internet Explorer is reported prone to a remote buffer overflow vulnerability.  This issue presents itself due to insufficient boundary checks performed by the application and results in a denial of service condition.  Arbitrary code execution may be possible as well.

This issue is reported to affect Microsoft Internet Explorer 6 running on a Windows 2000 SP4 platform.

8. MoniWiki Cross-Site Scripting Vulnerability
BugTraq ID: 11516
Remote: Yes
Date Published: Oct 25 2004
Relevant URL: http://www.securityfocus.com/bid/11516
Summary:
It is reported that MoniWiki is susceptible to a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input prior to including it in dynamic web page content.

This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

9. LinuxStat Remote Directory Traversal Vulnerability
BugTraq ID: 11517
Remote: Yes
Date Published: Oct 25 2004
Relevant URL: http://www.securityfocus.com/bid/11517
Summary:
It is reported that LinuxStat is vulnerable to a directory traversal vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input.

By including '../' directory traversal sequences in the affected URI argument, attackers may reportedly cause the contents of arbitrary, potentially sensitive web-server readable files to be included in the output of the requested page. The resulting information disclosure may aid malicious users in further attacks.

Versions prior to 2.3.1 are reported to be affected by this vulnerability.

10. IPplan Multiple Unspecified SQL Injection Vulnerabilities
BugTraq ID: 11518
Remote: Yes
Date Published: Oct 25 2004
Relevant URL: http://www.securityfocus.com/bid/11518
Summary:
It is reported that IPplan is susceptible to multiple unspecified SQL injection vulnerabilities. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in SQL queries.

Successful exploitation could result in the compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

Versions prior to 4.0 of this package are reported vulnerable to these issues.

This BID will be updated as further information about the specific vulnerabilities is disclosed.

11. NetCaptor Cross-Domain Dialog Box Spoofing Vulnerability
BugTraq ID: 11519
Remote: Yes
Date Published: Oct 25 2004
Relevant URL: http://www.securityfocus.com/bid/11519
Summary:
NetCaptor is reported prone to a cross-domain dialog box spoofing vulnerability.  This issue may allow a remote attacker to carry out phishing style attacks as an attacker may exploit this vulnerability to spoof an interface of a trusted web site.

12. NetCaptor Cross-Domain Tab Window Form Field Focus Vulnerabi...
BugTraq ID: 11520
Remote: Yes
Date Published: Oct 25 2004
Relevant URL: http://www.securityfocus.com/bid/11520
Summary:
A cross-domain tab window form field focus vulnerability reportedly affects NetCaptor.  This issue is due to an access validation error that allows a web page to gain access to form fields in other web pages rendered in different tabs of the same browser window.

This issue may be leveraged to facilitate convincing phishing style attacks designed to reveal sensitive information such as passwords and financial details.

13. Microsoft Internet Explorer HHCtrl ActiveX Control Cross-Dom...
BugTraq ID: 11521
Remote: Yes
Date Published: Oct 25 2004
Relevant URL: http://www.securityfocus.com/bid/11521
Summary:
Microsoft Internet Explorer is reported prone to a cross-domain scripting vulnerability.

The vulnerability is reported in the 'hhctrl' Internet Explorer ActiveX control and could allow an attacker to influence Internet Explorer into running script in the context of a foreign domain.

14. Mozilla Temporary File Insecure Permissions Information Disc...
BugTraq ID: 11522
Remote: No
Date Published: Oct 25 2004
Relevant URL: http://www.securityfocus.com/bid/11522
Summary:
Mozilla, Mozilla Firefox, and Mozilla Thunderbird are all reported susceptible to an information disclosure vulnerability. This issue is due to a failure of the applications to properly ensure secure file permissions on temporary files located in world-accessible locations.

This vulnerability allows local attackers to gain access to the contents of potentially sensitive files. This may aid them in further attacks.

15. GD Graphics Library Remote Integer Overflow Vulnerability
BugTraq ID: 11523
Remote: Yes
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11523
Summary:
The GD Graphics Library (gdlib) is affected by an integer overflow that facilitates a heap overflow.  This issue is due to a failure of the library to do proper sanity checking on size values contained within image format files.

An attacker may leverage this issue to manipulate process heap memory, potentially leading to code execution and compromise of the computer running the affected library.

16. phpCodeGenie PHP Code Injection Vulnerability
BugTraq ID: 11524
Remote: Yes
Date Published: Oct 22 2004
Relevant URL: http://www.securityfocus.com/bid/11524
Summary:
A vulnerability exists in phpCodeGenie that may permit remote attackers to execute arbitrary code in the context of the hosting Web server.  Reportedly, remote users may inject arbitrary PHP code into phpCodeGenie through header and footer input.

This code could then be executed by requesting a page that includes the injected code.

17. WVTFTP Server Remote Buffer Overflow Vulnerability
BugTraq ID: 11525
Remote: Yes
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11525
Summary:
A remote buffer overflow vulnerability affects WvTftp.  This issue is due to a failure of the application to properly to do proper sanity checking on string value pairs in TFTP packets.

An attacker may leverage this issue to corrupt process heap memory, facilitating code execution and a compromise of the affected computer.  It is also reported that the affected TFTP server runs with superuser privileges by default.

18. Libxml2 Multiple Remote Stack Buffer Overflow Vulnerabilitie...
BugTraq ID: 11526
Remote: Yes
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11526
Summary:
Libxml2 is reported prone to multiple remote stack buffer overflow vulnerabilities.  These issues occur due to insufficient boundary checks performed by the application and may allow remote attackers to execute arbitrary code on a vulnerable computer.

Multiple buffer overflow vulnerabilities exist in the URI parsing functionality of the application.  Multiple buffer overflow vulnerabilities also affect the DNS name resolving code of Libxml2.

Libxml2 versions between 2.6.12 and 2.6.14 are reported vulnerable. Other versions may also be affected.

19. InetUtils TFTP Client Remote Buffer Overflow Vulnerability
BugTraq ID: 11527
Remote: Yes
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11527
Summary:
InetUtils tftp client is reported prone to a remote buffer overflow vulnerability.  This issue presents itself due to the application failing to perform sufficient boundary checks on user-supplied data.

Successful exploitation of this vulnerability may result in process memory corruption, ultimately leading to a compromise.

InetUtils 1.4.2 is reported vulnerable to this issue, however, it is possible that other versions are affected as well.

20. Kaffeine Remote Buffer Overflow Vulnerability
BugTraq ID: 11528
Remote: Yes
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11528
Summary:
Kaffiene is reportedly affected by a remote buffer overflow vulnerability.  The problem presents itself due to insufficient boundary checks on user-supplied strings prior to copying them into finite stack-based buffers.

An attacker can leverage this issue remotely to execute arbitrary code on an affected computer with the privileges of an unsuspecting user that executed the vulnerable software.

21. PostNuke Trojan Horse Vulnerability
BugTraq ID: 11529
Remote: Yes
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11529
Summary:
It is reported that the server hosting PostNuke, www.postnuke.com, was compromised recently. Additionally, it is reported that the attacker modified the download address of the archive 'PostNuke-0.750.zip'. The new download location contained a trojaned version of the PostNuke archive.

It is reported that users that downloaded the PostNuke archive between Sunday the 24th of Oct 2004 at 23:50 GMT and Tuesday the 26th of Oct 2004 at 8:30 GMT are likely to be affected by this vulnerability.

22. Slim Browser Cross-Domain Tab Window Form Field Focus Vulner...
BugTraq ID: 11530
Remote: Yes
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11530
Summary:
A cross-domain tab window form field focus vulnerability reportedly affects Slim Browser.  This issue is due to an access validation error that allows a web page to gain access to form fields in other web pages rendered in different tabs of the same browser window.

This issue may be leveraged to facilitate convincing phishing style attacks designed to reveal sensitive information such as passwords and financial details.

23. ICab Web Browser Cross-Domain Dialog Box Spoofing Vulnerabil...
BugTraq ID: 11531
Remote: Yes
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11531
Summary:
iCab is reported prone to a cross-domain dialog box spoofing vulnerability. This issue may allow a remote attacker to carry out phishing style attacks. 

An attacker may exploit this vulnerability to spoof an interface of a trusted web site. This vulnerability may aid in phishing style attacks. 

iCab 2.9.8 is reported vulnerable to this issue. It is likely that other versions are affected as well.

24. Slim Browser Cross-Domain Dialog Box Spoofing Vulnerability
BugTraq ID: 11532
Remote: Yes
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11532
Summary:
Slim Browser is reported prone to a cross-domain dialog box spoofing vulnerability.  This issue may allow a remote attacker to carry out phishing style attacks as an attacker may exploit this vulnerability to spoof an interface of a trusted web site.

25. Linux Kernel ReiserFS File System Local Denial Of Service Vu...
BugTraq ID: 11533
Remote: No
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11533
Summary:
The Linux kernel is affected by a local denial of service vulnerability in its ReiserFS file system functionality.  This issue is due to a failure of the application to properly handle files under certain conditions.

An attacker may leverage this issue to trigger a livelock in the affected file system, forcing a user to restart the computer to return it to proper functionality.

26. PPPD Remote Denial Of Service Vulnerability
BugTraq ID: 11534
Remote: Yes
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11534
Summary:
It is reported that pppd is susceptible to a remote denial of service vulnerability. This is due to a failure of the application to properly handle invalid input.

Due to the nature of this design flaw, it is very likely that the application will crash when handed an invalid CBCP packet. This will result in the denial of service to legitimate users of the network application.

Version 2.4.1 of the package was reported vulnerable, but other versions may also be affected.

27. Tabs Laboratories MailCarrier Remote SMTP EHLO/HELO Buffer O...
BugTraq ID: 11535
Remote: Yes
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11535
Summary:
Tabs Laboratories MailCarrier is affected by a remote SMTP EHLO/HELO buffer overflow vulnerability.  This issue is due to a failure of the application to perform adequate bounds checking on network messages prior to copying them into process buffers.

A remote attacker may leverage this issue to execute arbitrary code on a computer running the affected software.  This will facilitate unauthorized access and privilege escalation.

28. Microsoft Internet Explorer Font Tag Denial Of Service Vulne...
BugTraq ID: 11536
Remote: Yes
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11536
Summary:
Microsoft Internet Explorer is reported prone to a remote denial of service vulnerability.

The issue presents itself due to a malfunction that occurs when certain font tags are encountered and rendered.

When a page that contains the malicious HTML code is viewed, Internet Explorer and all instances of Internet Explorer that are spawned from the instance used to view the malicious page, will crash.

29. Novell ZENworks System Tray Local Privilege Escalation Vulne...
BugTraq ID: 11537
Remote: No
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11537
Summary:
It is reported that ZENworks for Desktops contains a local privilege escalation vulnerability.

This vulnerability allows users with local interactive access to execute arbitrary application with administrative privileges.

Version 4.0.1 of the application is reported to be vulnerable to this issue.

30. Phorum Unspecified Cross-Site Scripting and SQL Injection Vu...
BugTraq ID: 11538
Remote: Yes
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11538
Summary:
It is reported that Phorum is prone to a cross-site scripting vulnerability and an SQL injection vulnerability. These issues are due to a failure of the application to properly sanitize user-supplied input.

The cross-site scripting issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

Successful exploitation of the SQL injection vulnerability could result in the compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

These vulnerabilities were reported to affect version 5.0.11, but other versions may also be affected.

31. Hummingbird Connectivity INETD32 Privilege Escalation Vulner...
BugTraq ID: 11539
Remote: No
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11539
Summary:
Hummingbird Connectivity is reported prone to a privilege escalation vulnerability in its inetd32 application.

This vulnerability allows users with local interactive access to execute arbitrary applications with administrative privileges.

Version 7.1 and 9.0 are reported vulnerable to this issue. Other versions are also likely affected.

32. SudoSH Undisclosed SHELL Environment Variable Vulnerability
BugTraq ID: 11540
Remote: No
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11540
Summary:
sudosh is reported prone to an undisclosed vulnerability. The issue is reported to present itself when sudosh handles the SHELL environment variable.

This BID will be updated as soon as further information regarding this vulnerability becomes available.

33. Google Desktop Search Remote Cross-Site Scripting Vulnerabil...
BugTraq ID: 11541
Remote: Yes
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11541
Summary:
Google Desktop Search is reportedly affected by a cross-site scripting vulnerability.  This issue is due to a failure of the application to properly sanitize HTML tag content.

An attacker may leverage this issue to execute arbitrary client-side script code in an unsuspecting user's browser, facilitating theft of cookie-based authentication credentials and other attacks.

34. Hummingbird Connectivity FTP Server Denial Of Service Vulner...
BugTraq ID: 11542
Remote: Yes
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11542
Summary:
Hummingbird Connectivity is reported prone to a denial of service vulnerability in its FTP server application.

This vulnerability allows remote attackers to crash the affected application, denying service to legitimate users.

Version 7.1 and 9.0 are reported vulnerable to this issue. Other versions are also likely affected.

35. Hawking Technology HAR11A DSL Router Unauthenticated Adminis...
BugTraq ID: 11543
Remote: Yes
Date Published: Oct 26 2004
Relevant URL: http://www.securityfocus.com/bid/11543
Summary:
HAR11A DSL routers are reported susceptible to an unauthenticated administrative console access vulnerability. This issue is due to a failure of the device to require authentication credentials prior to allowing administrative access to the devices CLI interface.

Remote attackers may possibly be able to gain administrative access to affected devices.

Due to code reuse among differing hardware, other devices may also be affected. This issue may also be related to BID 8855.

36. Omni Group OmniWeb Browser Cross-Domain Dialog Box Spoofing ...
BugTraq ID: 11544
Remote: Yes
Date Published: Oct 27 2004
Relevant URL: http://www.securityfocus.com/bid/11544
Summary:
OmniWeb is reported prone to a cross-domain dialog box spoofing vulnerability. This issue may allow a remote attacker to carry out phishing style attacks. 

An attacker may exploit this vulnerability to spoof an interface of a trusted web site. This vulnerability may aid in phishing style attacks. 

OmniWeb 5.0.1 is reported vulnerable to this issue. It is likely that other versions are affected as well.

37. PHPList Multiple unspecified Vulnerabilities
BugTraq ID: 11545
Remote: Yes
Date Published: Oct 27 2004
Relevant URL: http://www.securityfocus.com/bid/11545
Summary:
PHPList is affected by multiple unspecified vulnerabilities.  The underlying cause for these issues is currently unknown, however due to the nature of the application it is likely that they are due to input validation issues.

The impact of these issues is currently unknown, although due to the nature of the application they may facilitate unauthorized administrator access to the affected application.  This is not confirmed.

38. Horde Application Framework Help Window Unspecified Cross-Si...
BugTraq ID: 11546
Remote: Yes
Date Published: Oct 27 2004
Relevant URL: http://www.securityfocus.com/bid/11546
Summary:
Horde Application Framework is reported prone to an unspecified cross-site scripting vulnerability.  This issue arises due to insufficient sanitization of user-supplied data.  A remote attacker may exploit this vulnerability to execute arbitrary HTML and script code in the browser of a vulnerable user. 

This issue can facilitate attacks such as the theft of cookie-based authentication credentials. Other attacks are possible as well. 

Horde Application Framework versions 2.2.6 and prior are reported prone to this vulnerability.

39. Mega Upload Progress Bar Unspecified File Upload Vulnerabili...
BugTraq ID: 11547
Remote: Yes
Date Published: Oct 27 2004
Relevant URL: http://www.securityfocus.com/bid/11547
Summary:
Mega Upload Progress Bar is reported prone to an unspecified vulnerability.  The impact of this issue is currently unknown.  It is reported that this issue presents itself when a list of uploaded file names is passed from a Perl script to a PHP script of the application.  Apparently, this is carried out in an insecure manner, adversely affecting the security properties of the application.

Mega Upload Progress Bar versions 1.44 and prior are reported prone to this issue. 

This BID will be updated as more information becomes available.

40. PuTTY Remote SSH2_MSG_DEBUG Buffer Overflow Vulnerability
BugTraq ID: 11549
Remote: Yes
Date Published: Oct 27 2004
Relevant URL: http://www.securityfocus.com/bid/11549
Summary:
A remote SSH2_MSG_DEBUG buffer overflow vulnerability affects PuTTY.  This issue is due to insufficient bounds checking on network data prior to copying the data into process buffers.

An attacker may leverage this issue to execute arbitrary code on a computer running the affected software with the privileges of the user that activated it, facilitating unauthorized access.

41. Quicksilver Master of Orion III Multiple Remote Denial of Se...
BugTraq ID: 11550
Remote: Yes
Date Published: Oct 27 2004
Relevant URL: http://www.securityfocus.com/bid/11550
Summary:
Master of Orion III is reported prone to multiple remote denial of service vulnerabilities.  These issues occur because the application does not handle exceptional conditions in a proper manner.

Master of Orion III 1.2.5 and prior versions are reportedly affected by these issues.

42. ID Software Quake II Server Multiple Remote Vulnerabilities
BugTraq ID: 11551
Remote: Yes
Date Published: Oct 27 2004
Relevant URL: http://www.securityfocus.com/bid/11551
Summary:
Multiple remote vulnerabilities have been reported to affect Quake II.  These issues are due to boundary condition checking failures, access validation failures and failures to handle exceptional conditions.

An attacker may leverage these issues to trigger a denial of service condition, execute arbitrary code, gain access to sensitive server files and rejoin a server that they have been banned from.

43. KDE Konqueror IFRAME Cross-Domain Scripting Vulnerability
BugTraq ID: 11552
Remote: Yes
Date Published: Oct 27 2004
Relevant URL: http://www.securityfocus.com/bid/11552
Summary:
Konqueror is reported prone to a cross-domain scripting vulnerability. The issue is reported to exist because Konqueror fails to prevent JavaScript that is rendered in one frame from accessing properties of a site contained in an alternate frame.

This vulnerability may be exploited by a malicious web site to render JavaScript in the context of an alternate domain.

44. Apple QuickTime Remote Integer Overflow Vulnerability
BugTraq ID: 11553
Remote: Yes
Date Published: Oct 27 2004
Relevant URL: http://www.securityfocus.com/bid/11553
Summary:
A remote integer overflow vulnerability affects Apple QuickTime for the Microsoft Windows platform.  This issue is due to a failure of the application to properly validate integer signed-ness prior to using it to carry out critical operations.

An attacker may leverage this issue to cause the affected QuickTime client to crash, denying service to legitimate users.  It has been speculated that this issue may also facilitate code execution; any code execution would occur with the privileges of the user that activated the affected software.

45. Apple Remote Desktop Administrator Privilege Escalation Vuln...
BugTraq ID: 11554
Remote: No
Date Published: Oct 27 2004
Relevant URL: http://www.securityfocus.com/bid/11554
Summary:
A privilege escalation vulnerability affects Apple Remote Desktop Administrator.  The issue is due to a design error that fails to activate applications with the correct privileges.

This issue may allow a local attacker to gain superuser privileges on the affected computer.

46. RealNetworks RealOne Player/RealPlayer Skin File Remote Stac...
BugTraq ID: 11555
Remote: Yes
Date Published: Oct 27 2004
Relevant URL: http://www.securityfocus.com/bid/11555
Summary:
RealNetworks RealPlayer and RealOne Player are reported prone to a remote stack based buffer overflow vulnerability.

It is reported that the buffer overflow exists due to a lack of boundary checks performed on filenames contained in skin file archives.

A remote attacker may exploit this vulnerability to execute arbitrary instructions in the context of a user that visits a malicious website, or that applies a malicious skin file manually.

47. ZGV Image Viewer Multiple Remote Integer Overflow Vulnerabil...
BugTraq ID: 11556
Remote: Yes
Date Published: Oct 25 2004
Relevant URL: http://www.securityfocus.com/bid/11556
Summary:
zgv is reportedly affected by multiple remote integer overflow vulnerabilities.  These issues are due to a failure of the application to perform adequate sanity checking on image values prior to copying image data into process buffers.

An attacker may leverage these issues to execute arbitrary code on an affected computer with the privileges of the user running the vulnerable application.

48. PHP cURL Open_Basedir Restriction Bypass Vulnerability
BugTraq ID: 11557
Remote: Yes
Date Published: Oct 28 2004
Relevant URL: http://www.securityfocus.com/bid/11557
Summary:
It is reported that cURL allows malicious users to bypass 'open_basedir' restrictions in PHP scripts. This issue is due to a failure of the cURL module to properly enforce PHPs 'open_basedir' restriction.

Users with the ability to create or modify PHP scripts on a server computer hosting the vulnerable software can reportedly exploit this vulnerability to bypass the 'open_basedir' restriction, and access arbitrary files with the privileges of the web server. This may aid them in further attacks.

This vulnerability possibly results in a false sense of security, as administrators expect that the restrictions in place prevent malicious users from gaining access to sensitive information.

49. Multiple Vendor Content Filtering Bypass Vulnerabilities
BugTraq ID: 11558
Remote: Yes
Date Published: Oct 28 2004
Relevant URL: http://www.securityfocus.com/bid/11558
Summary:
It has been reported that several products are vulnerable to content filtering bypass issues.

These issues could allow a web client to access disallowed content from behind an affected product.  Bypassing the content filter could potentially allow malicious code to be executed on a client system thought to be protected.

Checkpoint VPN-1 and Firewall-1 and Agnitum Outpost Pro have been confirmed vulnerable to some or all of these issues.  Other products are likely vulnerable.

50. Microsoft Internet Explorer TABLE Status Bar URI Obfuscation...
BugTraq ID: 11561
Remote: Yes
Date Published: Oct 28 2004
Relevant URL: http://www.securityfocus.com/bid/11561
Summary:
Microsoft Internet Explorer is reported prone to a URI obfuscation weakness.

This issue may be leveraged by an attacker to display false information in the status bar of an unsuspecting user, allowing an attacker to present web pages to users that seem to originate from a trusted location.

This vulnerability is reported to affect Internet Explorer 6, other versions might also be affected.

Update: A report regarding this issue has been disclosed specifying that Internet Explorer version 6.0.2900.2180 may not be affected, or may be affected in a different manner. Symantec has confirmed that version 6.0.2800.1106 of Internet Explorer is vulnerable to this weakness.

NOTE: It has been reported that this issue does not affect Internet Explorer for Apple Mac OS X.

Update: Internet Explorer version 6.0.2900.2180 running on Windows XP SP2 is reportedly not vulnerable to this issue.

51. Global Spy Software Cyber Web Filter IP Filter Bypass Vulner...
BugTraq ID: 11562
Remote: Yes
Date Published: Oct 29 2004
Relevant URL: http://www.securityfocus.com/bid/11562
Summary:
Global Spy Software Cyber Web Filter is affected by an IP filter bypass vulnerability.  This issue is due to a failure of the application to properly handle exceptional HTTP requests.

An attacker may leverage this issue to bypass filters based on IP addresses, allowing an attacker to visit restricted Web sites.

52. Roaring Penguin Software MIMEDefang Multiple Unspecified Vul...
BugTraq ID: 11563
Remote: Yes
Date Published: Oct 29 2004
Relevant URL: http://www.securityfocus.com/bid/11563
Summary:
MIMEDefang is reported prone to multiple remote vulnerabilities.  The cause and impact of these issues is currently unknown.  It is conjectured that these issues are caused by insufficient sanitization of user-supplied data and may exist in 'mimedefang.pl.in' and 'mimedefang.c' files.

MIMEDefang 2.47 and prior versions are affected by these vulnerabilities.

This BID will be updated as more information becomes available.

53. Shadow Authentication Bypass Vulnerability
BugTraq ID: 11564
Remote: No
Date Published: Oct 29 2004
Relevant URL: http://www.securityfocus.com/bid/11564
Summary:
Shadow is reportedly affected by an authentication bypass vulnerability.  This issue is due to a failure of the application to properly sanitize user-supplied input.

An attacker may leverage this issue to bypass required authentication in order to alter or corrupt user account properties.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. New Caller I.D. spoofing site opens
By: Kevin Poulsen

Web-based caller I.D. fakery is back, and this time it's available to everyone.

http://www.securityfocus.com/news/9822

2. Report card day looms for federal agencies
By: Kevin Poulsen

Cyber security audits find improvement in some agencies, but viruses and worms still plague the halls of government.
 
http://www.securityfocus.com/news/9788

3. California reports massive data breach
By: Kevin Poulsen

An intruder who cracked a U.C. Berkeley research system in August had access to private data on 1.4 million caregivers and beneficiaries participating in a state social program. 

http://www.securityfocus.com/news/9758

4. IE exploits top web security threat list
By: John Leyden, The Register

Internet Explorer exploits posed the fastest growing web security threat to enterprises in the last quarter, according to web security services firm ScanSafe.

http://www.securityfocus.com/news/9846

5. Free training offer is latest spam scam
By: John Leyden, The Register

Surfers were yesterday urged to be wary of unsolicited emails offering training and well paid jobs in the financial sector.

http://www.securityfocus.com/news/9845

6. Google blocks Gmail exploit
By: John Leyden, The Register

Google has fixed a flaw in its high-profile webmail service, Gmail, which created a possible route for hackers to gain full access hackers full access to a user's email account simply by knowing their user name.

http://www.securityfocus.com/news/9843

IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Maillog View  v1.03.3
By: Angelo 'Archie' Amoruso
Relevant URL: http://www.netorbit.it/modules.html
Platforms: Linux
Summary: 

Maillog View is a Webmin module that allows you to easily view all your /var/log/maillog.* files. It features autorefresh, message size indication, ascending/descending view order, compressed file support, and a full statistics page. Sendmail, Postfix, Exim, and Qmail (partially) are supported. Courier MTA support is experimental.

2. BullDog Firewall 20040918
By: Robert APM Darin
Relevant URL: http://tanaya.net/BullDog
Platforms: Linux
Summary: 

Bulldog is a powerful but lightweight firewall for heavy use systems. With many features, this firewall can be used by anyone who wants to protect his/her systems.

This system allow dynamic and static rules sets for maximum protection and has several advance features.

This firewall will work for the hobbyist or a military base. Generation 7 is a complete rewrite and redesign from scratch.

Be prepared to spend some time setting this up.

3. WapgGuihttp://workspaces.gotdotnet.com/wapggui 1.0
By: William D. Bartholomew
Relevant URL: http://workspaces.gotdotnet.com/wapggui
Platforms: Windows 2000, Windows XP
Summary: 

A free, open-source, user-friendly interface to run the WAPG password generator. Supports generation of random and pronounceable passwords, specifying minimum and maximum length, specifying what character classes should or must be used, and much more.

4. antinat v0.81
By: Malcolm Smith
Relevant URL: http://yallara.cs.rmit.edu.au/~malsmith/products/antinat/
Platforms: MacOS, POSIX, Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary: 

The Antinat SOCKS Server is a multi-threaded, scalable SOCKS server with a client library for writing proxy-based applications. It supports SOCKS 4, SOCKS 5, authentication, firewalling, UDP, and name resolution.

5. PopMessenger 1.60
By: LeadMind Development
Relevant URL: http://www.leadmind.com
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary: 

Chat and send text messages and files to anyone on your LAN easily and securely!

6. ByteShelter I 1.0
By: MazZoft NDA
Relevant URL: http://www.mazzoft.com/bs1.zip
Platforms: Windows 2000, Windows 95/98
Summary: 

This steganography tools lets you conceal data in Outlook e-mail messages and .doc files.

V. SECURITYJOBS LIST SUMMARY
----------------------------
1. [SJ-JOB] Manager, Information Security, New York, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380106

2. [SJ-JOB] Sales Engineer, McLean, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380046

3. [SJ-JOB] Information Assurance Engineer, Rockford, U... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380040

4. [SJ-JOB] Application Security Engineer, Battle Creek... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/380037

5. [SJ-JOB] Sales Representative, Chicago, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379998

6. [SJ-JOB] Sales Engineer, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379996

7. [SJ-JOB] Security Architect, Woonsocket, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379993

8. [SJ-JOB] Account Manager, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379990

9. [SJ-JOB] Security Engineer, Orlando, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379989

10. [SJ-JOB] Security Engineer, Mt. Laurel, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379986

11. [SJ-JOB] Sales Engineer, Dallas or Houston, NYC, and... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379985

12. [SJ-JOB] Sales Representative, San Francisco, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379982

13. [SJ-JOB] Security Consultant, Zurich or Geneva/Lausa... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379979

14. [SJ-JOB] Management, New York, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379976

15. [SJ-JOB] Account Manager, Any, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379762

16. [SJ-JOB] Account Manager, Home based - US wide role,... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379723

17. [SJ-JOB] Security Auditor, Dublin, IE (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379721

18. [SJ-JOB] Account Manager, Home based - US wide, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379706

19. [SJ-JOB] Security Auditor, Brussels, BE (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379705

20. [SJ-JOB] Security Auditor, London and Bristol, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379704

21. [SJ-JOB] Security Product Marketing Manager, Redwood... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379688

22. [SJ-JOB] Security Researcher, Silicon Valley, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379684

23. [SJ-JOB] Compliance Officer, Jersey City, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379666

24. [SJ-JOB] Channel / Business Development, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379663

25. [SJ-JOB] Developer, Sunnyvale, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379662

26. [SJ-JOB] Security System Administrator, Austin, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379661

27. [SJ-JOB] Sr. Security Analyst, Northern, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379564

28. [SJ-JOB] Director, Information Security, Philadelphi... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379552

29. [SJ-JOB] Security Consultant, (North East ) NY/NJ - ... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379550

30. [SJ-JOB] Application Security Engineer, Bethpage, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379548

31. [SJ-JOB] Director, Information Security, Santa Monic... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379547

32. [SJ-JOB] Security Architect, Bedford, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379421

33. [SJ-JOB] Account Manager, San Diego, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379420

34. [SJ-JOB] Security Engineer, Manhattan, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379417

35. [SJ-JOB] Security System Administrator, Oklahoma Cit... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379416

36. [SJ-JOB] Compliance Officer, Philadelphia, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379413

37. [SJ-JOB] Security Consultant, Based in any U.S. city... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/379411

VI. INCIDENTS LIST SUMMARY
--------------------------
1. Security Issues with Wake on Lan (WOL) (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/380032

2. Strange FTP logs (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/380030

VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Solaris/SPARC heap overflow examples (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/380073

2. CanSecWest/core05 Call for Papers - May 4-6 2005 - D... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/379448

VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. 802.1x Authentication (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/380143

2. GPO that forces users to use a proxy server. (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/380142

3. Remove "Shutdown" command from w2k PCs but enable re... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/380140

4. Notifying users of password expiration via e-mail` (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/379796

5. RE: Can we really block users from installing applic... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/379731

6. SecurityFocus Microsoft Newsletter #212 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/379696

IX. SUN FOCUS LIST SUMMARY
--------------------------
NO NEW POSTS FOR THE WEEK 2004-10-26 to 2004-11-02.

X. LINUX FOCUS LIST SUMMARY
---------------------------
1. Linux security compliance (Thread)
Relevant URL:

http://www.securityfocus.com/archive/91/380078

2. Strange Attack On A Webserver I Work On (Thread)
Relevant URL:

http://www.securityfocus.com/archive/91/379937

XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.
    
XII. SPONSOR INFORMATION
-----------------------

This Issue is Sponsored By: BindView

What questions should you be asking to improve internal security? Why are
firewalls not enough to protect you? What are some of the traditional
attack vectors? What are some of the biggest threats you face for attacks
against non-controlled assets? And how can you protect your environments
from these internal threats? During the BindView November 11 Webinar,
"Internal Security: Threat Identification and Remediation" security expert,
Mark "Simple Nomad" Loveless with the BindView RAZOR team, will provide you
with information to help you better secure your environment. 
Register at: 

http://www.securityfocus.com/sponsor/BindView_sf-news_041102

------------------------------------------------------------------------