SecurityFocus Newsletter #274
Peter Laborge <[email protected]> 9 Nov 2004 17:48:11 -0000
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #274
------------------------------
This Issue is Sponsored By: Datakey
NEED TO LEARN HOW TO STRENGTHEN & SIMPLIFY SECURITY?
Do you know who is accessing your facilities and networks?
Download Datakey's White Paper, Strengthen and Simplify Security
See how we can help create your strategy for stronger security:
http://www.securityfocus.com/sponsor/Datakey_sf-news_041109
------------------------------------------------------------------------
I. FRONT AND CENTER
1. The Cost of Security Training
2. SSH User Identities
3. Trends in Web Application Security
4. Phishing For Savvy Users
II. BUGTRAQ SUMMARY
1. Microsoft Internet Explorer HTML Form Malformed A Tag Status...
2. Sun Java System Web Proxy Server Multiple Unspecified Buffer...
3. Caudium Remote Denial Of Service Vulnerability
4. Bogofilter EMail Filter Remote Quoted Printable Decoder Deni...
5. Land Down Under Multiple Remote SQL Injection Vulnerabilitie...
6. Linux Kernel IPTables Initialization Failure Vulnerability
7. HTML::Merge Template Parameter File Disclosure Vulnerability
8. QwikMail Remote Format String Vulnerability
9. Apple Safari Web Browser TABLE Status Bar URI Obfuscation We...
10. Cherokee HTTPD Auth_Pam Authentication Remote Format String ...
11. PostgreSQL Unspecified RPM Initialization Script Vulnerabili...
12. HP OpenView Operations Remote Privilege Escalation Vulnerabi...
13. Cisco Secure Access Control Server Remote Authentication Byp...
14. MailEnable Professional Webmail Unspecified Vulnerability
15. Haserl Local Environment Variable Manipulation Vulnerability
16. NetGear ProSafe Dual Band Wireless VPN Firewall Default SNMP...
17. RARLAB WinRAR Repair Archive Undisclosed Vulnerability
18. Chesapeake TFTP Server Remote Directory Traversal Vulnerabil...
19. Allied Telesyn TFTP Daemon Multiple Remote Vulnerabilities
20. WebHost Automation Helm Control Panel Multiple Input Validat...
21. Goollery Multiple Cross-Site Scripting Vulnerabilities
22. ArGoSoft FTP Server Shortcut File Upload Vulnerability
23. Microsoft Internet Explorer IFRAME Status Bar URI Obfuscatio...
24. ISC DHCPD Remote Format String Vulnerability
25. Proxytunnel Remote Format String Vulnerability
26. Sun Java System Web And Application Servers Remote Denial Of...
27. FsPHPGallery Multiple Input Validation Vulnerabilities
28. TIPS MailPost Remote Debug Mode Information Disclosure Vulne...
29. TIPS MailPost APPEND Variable Cross-Site Scripting Vulnerabi...
30. yChat Unspecified Remote Denial Of Service Vulnerability
31. TIPS MailPost Error Message Cross-Site Scripting Vulnerabili...
32. TIPS MailPost Remote File Enumeration Vulnerability
33. F-Secure Anti-Virus For Microsoft Exchange Password Protecte...
34. Gbook MX Multiple Unspecified SQL Injection Vulnerabilities
35. Gallery Unspecified Remote HTML Injection Vulnerability
36. Info-ZIP Zip Remote Recursive Directory Compression Buffer O...
37. Sun Java System Application Server HTTP TRACE Information Di...
38. Microsoft ISA Server Unspecified Vulnerability
39. Symantec LiveUpdate Directory Traversal Vulnerability
40. Sophos MailMonitor for SMTP Unspecified Email Handling Vulne...
41. Moodle Remote Glossary Module SQL Injection Vulnerability
42. Zile Multiple Unspecified Vulnerabilities
43. Monolith Lithtech Game Engine Multiple Remote Format String ...
44. IceWarp Web Mail Multiple Remote Vulnerabilities
45. Trend Micro ScanMail for Domino Remote File Disclosure Vulne...
46. AntiBoard Unspecified SQL Injection Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
1. Alleged DDoS kingpin joins most wanted list
2. Online fraud tutorials... from the Secret Service?
3. New Caller I.D. spoofing site opens
4. Boom times ahead for IT security profession
5. Trojan infects PCs to generate SMS spam
6. Aussie 419 ringleader jailed for four years
IV. SECURITYFOCUS TOP 6 TOOLS
1. creddump
2. Maillog View v1.03.3
3. BullDog Firewall 20040918
4. WapgGuihttp://workspaces.gotdotnet.com/wapggui 1.0
5. antinat v0.81
6. PopMessenger 1.60
V. SECURITYJOBS LIST SUMMARY
1. [SJ-JOB] Account Manager, Philadelphia, US (Thread)
2. [SJ-JOB] Evangelist, Various US locations, US (Thread)
3. [SJ-JOB] VP of Regional Sales, East, GB (Thread)
4. [SJ-JOB] Director, Information Security, Geneva, CH (Thread)
5. [SJ-JOB] Sales Representative, Chicago or Vicinity, ... (Thread)
6. [SJ-JOB] Sales Representative, Boston or Vicinity, U... (Thread)
7. [SJ-JOB] Sr. Security Analyst, Austin, US (Thread)
8. [SJ-JOB] Manager, Information Security, Saint Louis,... (Thread)
9. [SJ-JOB] Security Product Marketing Manager, Redwood... (Thread)
10. [SJ-JOB] Channel / Business Development, Washington,... (Thread)
11. [SJ-JOB] Sales Representative, Atlanta, US (Thread)
12. [SJ-JOB] Sales Representative, Washington, US (Thread)
13. [SJ-JOB] Jr. Security Analyst, Addison, US (Thread)
14. [SJ-JOB] Management, Santa Clara, US (Thread)
15. [SJ-JOB] Security Architect, Annapolis, US (Thread)
16. [SJ-JOB] Developer, Jersey City, US (Thread)
17. [SJ-JOB] Sr. Security Analyst, Arlington, US (Thread)
18. [SJ-JOB] Security System Administrator, Mannheim, DE (Thread)
19. [SJ-JOB] Application Security Engineer, Jersey City,... (Thread)
20. [SJ-JOB] Management, Dallas, US (Thread)
21. [SJ-JOB] Security Engineer, Little Rock, US (Thread)
22. [SJ-JOB] Auditor, Houston, US (Thread)
23. [SJ-JOB] Quality Assurance, Santa Clara, US (Thread)
24. [SJ-JOB] Sr. Security Engineer, Boston, US (Thread)
25. [SJ-JOB] Sr. Security Engineer, North Brunswick, US (Thread)
26. [SJ-JOB] Compliance Officer, New York, US (Thread)
27. [SJ-JOB] Sales Engineer, Boston, US (Thread)
28. [SJ-JOB] Sales Engineer, New York, US (Thread)
29. [SJ-JOB] Sr. Security Engineer, Stamford, US (Thread)
30. [SJ-JOB] Security Architect, Westerville, US (Thread)
31. [SJ-JOB] Security Consultant, Dallas, US (Thread)
32. [SJ-JOB] Security Engineer, San Jose, US (Thread)
33. [SJ-JOB] Security Consultant, North Brunswick, US (Thread)
34. [SJ-JOB] Customer Support, San Francisco, US (Thread)
35. [SJ-JOB] Sr. Security Engineer, Waltham, US (Thread)
36. [SJ-JOB] Security System Administrator, DC, US (Thread)
37. [SJ-JOB] Security Consultant, New York, US (Thread)
38. [SJ-JOB] Application Security Engineer, Seattle, US (Thread)
39. [SJ-JOB] VP, Information Security, Boston, US (Thread)
40. [SJ-JOB] Security Consultant, Bay Area, US (Thread)
41. [SJ-JOB] Manager, Information Security, New York, US (Thread)
42. [SJ-JOB] Security Consultant, Boston, US (Thread)
VI. INCIDENTS LIST SUMMARY
1. Vulnerability Scan 200.127.113.193, 69.93.128.17 (Thread)
2. Maintaining a "watch list" (Thread)
3. Security Issues with Wake on Lan (WOL) (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
1. Retina Vuln Scanner Problems. (Thread)
2. DIMVA 2005 - Call for Papers (Thread)
3. Microsoft ISA Server Authentication Bypassing (Thread)
4. Windows 2000 SP4 + IE (fully patched) - restrictions... (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
1. root_drv.sys rootkit (Thread)
2. SecurityFocus Microsoft Newsletter #213 (Thread)
3. Event Log - Controling critical files and folders. (Thread)
4. Notifying users of password expiration via e-mail` (Thread)
5. AW: Remove "Shutdown" command from w2k PCs but enabl... (Thread)
6. GPO that forces users to use a proxy server. (Thread)
IX. SUN FOCUS LIST SUMMARY
NO NEW POSTS FOR THE WEEK 2004-11-02 to 2004-11-09.
X. LINUX FOCUS LIST SUMMARY
1. Linux security compliance (Thread)
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. The Cost of Security Training
By Don Parker
The cost of providing security training to your staff may be high, but what
is the cost of not providing any training at all?
http://www.securityfocus.com/columnists/275
2. SSH User Identities
By Brian Hatch
This article shows how to improve SSH security using public key
authentication instead of, or in addition to, password authentication.
http://www.securityfocus.com/infocus/1810
3. Trends in Web Application Security
By Kapil Raina
This article discusses current trends in penetration testing for web
application security, and in particular discusses a framework for selecting
the best tool or tools to use for this increasingly common type of application.
http://www.securityfocus.com/infocus/1809
4. Phishing For Savvy Users
By Scott Granneman
Recent "phishing" episodes are still often overlooked by tech-savvy users,
but a lesson in history shows how entire nations have been fooled.
http://www.securityfocus.com/columnists/274
II. BUGTRAQ SUMMARY
-------------------
1. Microsoft Internet Explorer HTML Form Malformed A Tag Status...
BugTraq ID: 11565
Remote: Yes
Date Published: Oct 30 2004
Relevant URL: http://www.securityfocus.com/bid/11565
Summary:
Microsoft Internet Explorer is reported prone to a URI obfuscation weakness.
This issue may be leveraged by an attacker to display false information in the status bar of an unsuspecting user, allowing an attacker to present web pages to users that seem to originate from a trusted location.
This vulnerability is reported to affect Internet Explorer 6 SP2, other versions might also be affected.
This issue is similar to BID 10023.
2. Sun Java System Web Proxy Server Multiple Unspecified Buffer...
BugTraq ID: 11566
Remote: Yes
Date Published: Oct 30 2004
Relevant URL: http://www.securityfocus.com/bid/11566
Summary:
It is reported that Sun Java System Web Proxy Server, and its Administration Server application are susceptible to multiple unspecified buffer overflow vulnerabilities. These issues are due to a failure of the application to properly perform bounds checks prior to copying user-supplied data into memory buffers.
These vulnerabilities reportedly allow remote attackers to execute arbitrary code in the context of the affected application. Unsuccessful attempts to exploit these vulnerabilities will likely result in the application crashing, denying service to legitimate users.
The Web proxy server is configured to run as 'nobody' by default, and the Administration Server is configured to run as 'root'. By exploiting vulnerabilities in the Administration Server, attackers may execute arbitrary code with superuser privileges.
3. Caudium Remote Denial Of Service Vulnerability
BugTraq ID: 11567
Remote: Yes
Date Published: Oct 30 2004
Relevant URL: http://www.securityfocus.com/bid/11567
Summary:
Caudium is reported prone to a remote denial of service vulnerability.
Remote attackers may exploit this vulnerability to crash affected Web servers, denying service to legitimate users.
Versions of Caudium prior to 1.4.4 RC2 are reported susceptible to this vulnerability.
4. Bogofilter EMail Filter Remote Quoted Printable Decoder Deni...
BugTraq ID: 11568
Remote: Yes
Date Published: Nov 01 2004
Relevant URL: http://www.securityfocus.com/bid/11568
Summary:
A remote quoted printable decoder denial of service vulnerability reportedly affects Bogofilter. This issue is due to a failure of the application to handle malformed email headers.
An attacker can leverage this issue to cause the affected email filter to crash, denying service to all legitimate users.
5. Land Down Under Multiple Remote SQL Injection Vulnerabilitie...
BugTraq ID: 11569
Remote: Yes
Date Published: Nov 01 2004
Relevant URL: http://www.securityfocus.com/bid/11569
Summary:
Land Down Under is reportedly affected by multiple SQL injection vulnerabilities. These issues are due to a failure of the application to properly validate user-supplied input prior to including it in SQL queries.
An attacker may leverage this issue to reveal or corrupt arbitrary database data. This may facilitate unauthorized access or denial of service.
6. Linux Kernel IPTables Initialization Failure Vulnerability
BugTraq ID: 11570
Remote: No
Date Published: Nov 01 2004
Relevant URL: http://www.securityfocus.com/bid/11570
Summary:
Linux kernel iptables is reportedly affected by an initialization error vulnerability. This issue is due to a design error within the application.
This issue causes the affected utility to initialize improperly, leading to a false sense of security as all of the firewall rules may not always be loaded.
7. HTML::Merge Template Parameter File Disclosure Vulnerability
BugTraq ID: 11571
Remote: Yes
Date Published: Nov 01 2004
Relevant URL: http://www.securityfocus.com/bid/11571
Summary:
HTML::Merge is reported prone to a remote file disclosure vulnerability. The vulnerability presents itself due to a lack of sufficient sanitization performed on user-supplied data that is passed to the 'printsource.pl' script.
It is reported that this vulnerability may be exploited by a remote attacker to specify an arbitrary web server readable file and have that file served to the attacker.
8. QwikMail Remote Format String Vulnerability
BugTraq ID: 11572
Remote: Yes
Date Published: Nov 01 2004
Relevant URL: http://www.securityfocus.com/bid/11572
Summary:
It is reported that QwikMail is susceptible to a remote format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before using it as the format specifier in a formatted printing function.
This vulnerability reportedly allows remote attackers to execute arbitrary code in the context of the affected daemon process.
Version 0.3 was reported susceptible to this vulnerability. Other versions may also be affected.
9. Apple Safari Web Browser TABLE Status Bar URI Obfuscation We...
BugTraq ID: 11573
Remote: Yes
Date Published: Nov 01 2004
Relevant URL: http://www.securityfocus.com/bid/11573
Summary:
A URI obfuscation weakness reportedly affects the Apple Safari Web Browser.
This issue may be leveraged by an attacker to display false information in the status bar of an unsuspecting user, allowing an attacker to present web pages to users that seem to originate from a trusted location.
10. Cherokee HTTPD Auth_Pam Authentication Remote Format String ...
BugTraq ID: 11574
Remote: Yes
Date Published: Nov 01 2004
Relevant URL: http://www.securityfocus.com/bid/11574
Summary:
It is reported that Cherokee is susceptible to a remote format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before using it as the format specifier in a formatted printing function.
A remote attacker may exploit this vulnerability to execute arbitrary code in the context of the affected service.
11. PostgreSQL Unspecified RPM Initialization Script Vulnerabili...
BugTraq ID: 11575
Remote: Unknown
Date Published: Nov 01 2004
Relevant URL: http://www.securityfocus.com/bid/11575
Summary:
An unspecified RPM initialization script vulnerability affects PostgreSQL. The underlying issue causing this vulnerability is currently unknown.
The impact of this issue is currently unknown. This BID will be updated immediately upon the release of more information.
12. HP OpenView Operations Remote Privilege Escalation Vulnerabi...
BugTraq ID: 11576
Remote: Yes
Date Published: Nov 01 2004
Relevant URL: http://www.securityfocus.com/bid/11576
Summary:
HP OpenView Operations (OVO) is reported prone to a remote privilege escalation vulnerability. Due to an unspecified vulnerability, an administrator without sufficient privileges may carry out privileged actions on a remote computer.
It is conjectured that this vulnerability results from insufficient verification of access rights.
13. Cisco Secure Access Control Server Remote Authentication Byp...
BugTraq ID: 11577
Remote: Yes
Date Published: Nov 02 2004
Relevant URL: http://www.securityfocus.com/bid/11577
Summary:
Cisco Secure Access Control Server is affected by a remote authentication bypass vulnerability. This issue is due to a failure of the software to properly validate user credentials prior to granting access.
The problem presents itself when an attacker attempts to authenticate to the affected server. Apparently the application will grant access to any attacker that presents a valid user name and a certificate that is cryptographically correct.
An attacker can leverage this issue to gain unauthorized remote access to any devices or networks that rely on the affected software for access control.
14. MailEnable Professional Webmail Unspecified Vulnerability
BugTraq ID: 11578
Remote: Yes
Date Published: Nov 02 2004
Relevant URL: http://www.securityfocus.com/bid/11578
Summary:
MailEnable Professional Webmail is reported prone to an unspecified potential security vulnerability. The cause and impact of this issue is currently unknown. Due to the nature of the software, this issue is likely remotely exploitable.
MailEnable Professional 1.5 and prior versions are affected by this vulnerability.
15. Haserl Local Environment Variable Manipulation Vulnerability
BugTraq ID: 11579
Remote: No
Date Published: Nov 02 2004
Relevant URL: http://www.securityfocus.com/bid/11579
Summary:
Haserl is reportedly affected by a local environment variable manipulation vulnerability. This issue is due to a design error that allows local users to manipulate environment variables.
An attacker may leverage this issue to arbitrarily corrupt or update environment variables with the privileges of the affected web server.
16. NetGear ProSafe Dual Band Wireless VPN Firewall Default SNMP...
BugTraq ID: 11580
Remote: Yes
Date Published: Nov 02 2004
Relevant URL: http://www.securityfocus.com/bid/11580
Summary:
ProSafe Dual Band Wireless VPN Firewall is reported prone to a vulnerability that can allow remote attackers to gain sensitive information about a network protected by the device.
This issue presents itself because the appliance uses a default community string for SNMP.
NetGear ProSafe Dual Band Wireless VPN Firewall model FWAG114 is reported prone to this issue.
17. RARLAB WinRAR Repair Archive Undisclosed Vulnerability
BugTraq ID: 11581
Remote: No
Date Published: Nov 02 2004
Relevant URL: http://www.securityfocus.com/bid/11581
Summary:
RARLAB WinRAR is reported prone to an undisclosed vulnerability. The issue is reported to exist in the 'Repair Archive' functionality of WinRAR.
The details of this vulnerability are not known; this BID will be updated as further information in regards to this vulnerability becomes available.
18. Chesapeake TFTP Server Remote Directory Traversal Vulnerabil...
BugTraq ID: 11582
Remote: Yes
Date Published: Oct 30 2004
Relevant URL: http://www.securityfocus.com/bid/11582
Summary:
Chesapeake TFTP Server is reported susceptible to a directory traversal vulnerability. This vulnerability allows remote attackers to retrieve the contents of arbitrary, potentially sensitive files located on the serving computer with the credentials of the TFTP server process.
Chesapeake TFTP Server version 1.0 is reported prone to this issue.
19. Allied Telesyn TFTP Daemon Multiple Remote Vulnerabilities
BugTraq ID: 11584
Remote: Yes
Date Published: Nov 02 2004
Relevant URL: http://www.securityfocus.com/bid/11584
Summary:
The Allied Telesyn TFTP service is reported prone to multiple vulnerabilities. The following specific issues are reported:
Allied Telesyn TFTP Server is reported susceptible to a directory traversal vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input data.
This vulnerability allows remote attackers to retrieve or overwrite the contents of arbitrary potentially sensitive files located on the serving appliance with the privileges of the TFTP server process.
Additionally, Allied Telesyn TFTP Server is reported prone to a remote buffer overflow vulnerability.
This vulnerability may be exploited by a remote attacker to crash the affected service.
20. WebHost Automation Helm Control Panel Multiple Input Validat...
BugTraq ID: 11586
Remote: Yes
Date Published: Nov 02 2004
Relevant URL: http://www.securityfocus.com/bid/11586
Summary:
Helm Control Panel is reported prone to multiple vulnerabilities. These include an SQL injection issue and an HTML injection vulnerability. A remote attacker can execute arbitrary HTML and script code in a user's browser. Manipulation of SQL queries to reveal or corrupt sensitive database data is possible as well.
Helm Control Panel versions 3.1.19 and prior are reported vulnerable to these issues.
21. Goollery Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 11587
Remote: Yes
Date Published: Nov 02 2004
Relevant URL: http://www.securityfocus.com/bid/11587
Summary:
It is reported that Goollery is affected by various cross-site scripting vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied URI input.
These problems present themselves when malicious HTML and script code is sent to the application through the 'page' parameter of several scripts.
These issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user.
22. ArGoSoft FTP Server Shortcut File Upload Vulnerability
BugTraq ID: 11589
Remote: Yes
Date Published: Nov 02 2004
Relevant URL: http://www.securityfocus.com/bid/11589
Summary:
ArGoSoft FTP server is reported prone to a vulnerability that allows users to upload shortcut (.lnk) files to the server. Further details were not provided about this issue.
It is conjectured that this issue is related to BID 2961 (ArGoSoft FTP Server .lnk Directory Traversal Vulnerability), which allows users with write permission to any directory to create and upload a .lnk file that points to the directory of their choice. They will then have read and write access to that directory and any files therein.
ArGoSoft FTP server 1.4.2.1 and prior versions are reportedly affected by this issue.
23. Microsoft Internet Explorer IFRAME Status Bar URI Obfuscatio...
BugTraq ID: 11590
Remote: Yes
Date Published: Nov 02 2004
Relevant URL: http://www.securityfocus.com/bid/11590
Summary:
Microsoft Internet Explorer is reported prone to a URI obfuscation weakness.
This issue may be leveraged by an attacker to display false information in the status bar of an unsuspecting user, allowing an attacker to present web pages to users that seem to originate from a trusted location.
This vulnerability is reported to affect Internet Explorer 6, other versions might also be affected.
24. ISC DHCPD Remote Format String Vulnerability
BugTraq ID: 11591
Remote: Yes
Date Published: Nov 02 2004
Relevant URL: http://www.securityfocus.com/bid/11591
Summary:
A remote format string vulnerability is reported in the ISC DHCPD server package. User supplied data is logged in an unsafe fashion. Exploitation of this vulnerability may result in arbitrary code being executed by the DHCP server. Although unconfirmed it is conjectured that this issue may only be exploitable when debugging functionality is enabled.
25. Proxytunnel Remote Format String Vulnerability
BugTraq ID: 11592
Remote: Yes
Date Published: Nov 03 2004
Relevant URL: http://www.securityfocus.com/bid/11592
Summary:
Proxytunnel is prone to a remotely exploitable format string vulnerability. This vulnerability is exposed when the proxy server handles malicious input from another remote server. This issue occurs when the software is run in daemon mode.
Successful exploitation of this vulnerability may allow for execution of arbitrary code in the context of the proxy server.
26. Sun Java System Web And Application Servers Remote Denial Of...
BugTraq ID: 11593
Remote: Yes
Date Published: Nov 03 2004
Relevant URL: http://www.securityfocus.com/bid/11593
Summary:
A remote denial of service vulnerability affects the Sun Java Web Server and the Sun Java Application Server. This issue is due to a failure of the server applications to process malformed data.
An attacker may exploit this issue to cause the affected server to crash, denying service to legitimate users.
27. FsPHPGallery Multiple Input Validation Vulnerabilities
BugTraq ID: 11594
Remote: Yes
Date Published: Nov 03 2004
Relevant URL: http://www.securityfocus.com/bid/11594
Summary:
FsPHPGallery is reported prone to multiple input validation vulnerabilities. The following specific issues are reported:
FsPHPGallery is reported prone to a denial of service vulnerability. The issue presents itself due to a failure to sufficiently sanitize user-supplied image size attribute values.
A remote attacker may exploit this vulnerability to deny service for legitimate users.
Additionally FsPHPGallery is reported prone to an information disclosure vulnerability.
A remote attacker may exploit this issue to list contents of arbitrary directories that are readable by the web server process.
28. TIPS MailPost Remote Debug Mode Information Disclosure Vulne...
BugTraq ID: 11595
Remote: Yes
Date Published: Nov 03 2004
Relevant URL: http://www.securityfocus.com/bid/11595
Summary:
TIPS MailPost is affected by a remote debug mode information disclosure vulnerability. This issue is due to a design error that allows for the disclosure of sensitive information.
An attacker may leverage this issue to gain knowledge of sensitive information such as the server Web root directory and the Web server versions. Information disclosed in this way may facilitate further attacks.
29. TIPS MailPost APPEND Variable Cross-Site Scripting Vulnerabi...
BugTraq ID: 11596
Remote: Yes
Date Published: Nov 03 2004
Relevant URL: http://www.securityfocus.com/bid/11596
Summary:
MailPost is reported prone to a cross-site scripting vulnerability. This issue presents itself due to insufficient sanitization of user-supplied data and can allow an attacker to execute arbitrary HTML and script code in a user's browser.
This vulnerability may allow for theft of cookie-based authentication credentials or other attacks.
MailPost 5.1.1sv is reported prone to this issue. It is possible that other versions are affected as well.
30. yChat Unspecified Remote Denial Of Service Vulnerability
BugTraq ID: 11597
Remote: Yes
Date Published: Nov 03 2004
Relevant URL: http://www.securityfocus.com/bid/11597
Summary:
It is reported that yChat is susceptible to an unspecified remote denial of service vulnerability. Reportedly, yChat contains an unspecified flaw in its handling of HTTP connections.
Remote attackers are reportedly able to crash the affected package, denying service to legitimate users.
This BID will be updated if further information is disclosed.
Versions prior to 0.7 are reported susceptible to this vulnerability.
31. TIPS MailPost Error Message Cross-Site Scripting Vulnerabili...
BugTraq ID: 11598
Remote: Yes
Date Published: Nov 03 2004
Relevant URL: http://www.securityfocus.com/bid/11598
Summary:
MailPost is reported prone to a cross-site scripting vulnerability. This issue presents itself due to insufficient sanitization of user-supplied data and can allow an attacker to execute arbitrary HTML and script code in a user's browser through a malicious error message returned from the application.
This attack would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.
MailPost 5.1.1sv is reported prone to this issue. It is possible that other versions are affected as well.
32. TIPS MailPost Remote File Enumeration Vulnerability
BugTraq ID: 11599
Remote: Yes
Date Published: Nov 03 2004
Relevant URL: http://www.securityfocus.com/bid/11599
Summary:
TIPS MailPost is affected by a remote file enumeration vulnerability. This issue is due to a failure to properly sanitize user requests.
An attacker may leverage this issue to gain knowledge of the existence of files outside the Web root directory. Information disclosed in this way may facilitate further attacks.
33. F-Secure Anti-Virus For Microsoft Exchange Password Protecte...
BugTraq ID: 11600
Remote: Yes
Date Published: Nov 03 2004
Relevant URL: http://www.securityfocus.com/bid/11600
Summary:
F-Secure Anti-Virus for Microsoft Exchange is reported prone to a scanner bypass vulnerability. It is reported that a specially crafted archive that is nested within another archive is sufficient to trigger this vulnerability. Such an archive may contain malicious applications and will not be detected and quarantined at the email gateway.
34. Gbook MX Multiple Unspecified SQL Injection Vulnerabilities
BugTraq ID: 11601
Remote: Yes
Date Published: Nov 03 2004
Relevant URL: http://www.securityfocus.com/bid/11601
Summary:
It is reported that Gbook MX is susceptible to multiple unspecified SQL injection vulnerabilities. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in SQL queries.
Successful exploitation could result in the compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
35. Gallery Unspecified Remote HTML Injection Vulnerability
BugTraq ID: 11602
Remote: Yes
Date Published: Nov 03 2004
Relevant URL: http://www.securityfocus.com/bid/11602
Summary:
An unspecified HTML injection vulnerability reportedly affects Gallery. This issue is due to a failure of the application to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
36. Info-ZIP Zip Remote Recursive Directory Compression Buffer O...
BugTraq ID: 11603
Remote: Yes
Date Published: Nov 04 2004
Relevant URL: http://www.securityfocus.com/bid/11603
Summary:
A remote recursive directory compression buffer overflow vulnerability reportedly affects Info-ZIP Zip. This issue is due to insufficient buffer boundary verification prior to copying user-supplied data.
Successful exploitation of this issue would allow an attacker to execute arbitrary code on the affected computer with the privileges of a user running the affected application. This issue would likely facilitate unauthorized access or privilege escalation.
37. Sun Java System Application Server HTTP TRACE Information Di...
BugTraq ID: 11604
Remote: Yes
Date Published: Nov 03 2004
Relevant URL: http://www.securityfocus.com/bid/11604
Summary:
Sun Java System Application Server is reported prone to a vulnerability that may allow a remote attacker to steal sensitive information such as cookie-based authentication credentials. This issue exists in the processing of HTTP TRACE requests.
38. Microsoft ISA Server Unspecified Vulnerability
BugTraq ID: 11605
Remote: Unknown
Date Published: Nov 04 2004
Relevant URL: http://www.securityfocus.com/bid/11605
Summary:
Microsoft has published advance notification that they will be releasing a security update for Internet Security and Acceleration (ISA) Server. Fixes are pending release on November 9th, 2004. No further details are known.
39. Symantec LiveUpdate Directory Traversal Vulnerability
BugTraq ID: 11606
Remote: Yes
Date Published: Nov 05 2004
Relevant URL: http://www.securityfocus.com/bid/11606
Summary:
Symantec LiveUpdate is reported prone to a directory traversal vulnerability. It is reported that the application decompresses a directory tree without sufficient validation of directory names.
To carry out this attack, the attacker must establish a malicious server and then carry out a redirection type attack such as DNS cache poisoning to force LiveUpdate to download malicious archives from the attacker's server. It should also be noted that it is not reportedly possible to overwrite existing files on a vulnerable computer through this vulnerability.
LiveUpdate versions 1.80.19.0 and 2.5.56.0 were reportedly affected by this issue. It is likely that other versions are affected as well.
40. Sophos MailMonitor for SMTP Unspecified Email Handling Vulne...
BugTraq ID: 11607
Remote: Yes
Date Published: Nov 05 2004
Relevant URL: http://www.securityfocus.com/bid/11607
Summary:
Sophos MailMonitor for SMTP is reported prone to an unspecified vulnerability. It is reported that this issue presents itself when the application handles malformed email messages. The impact of this issue was not specified.
Sophos MailMonitor for SMTP version 2.1 is reportedly vulnerable. It is possible that other versions may be affected as well.
41. Moodle Remote Glossary Module SQL Injection Vulnerability
BugTraq ID: 11608
Remote: Yes
Date Published: Nov 05 2004
Relevant URL: http://www.securityfocus.com/bid/11608
Summary:
Moodle is affected by a remote SQL injection vulnerability in its glossary module. This issue is due to a failure of the application to properly sanitize user-supplier input.
An attacker may leverage this issue to execute arbitrary SQL queries against the underlying database, potentially facilitating disclosure or corruption of sensitive data. Other attacks are also possible.
42. Zile Multiple Unspecified Vulnerabilities
BugTraq ID: 11609
Remote: Yes
Date Published: Nov 05 2004
Relevant URL: http://www.securityfocus.com/bid/11609
Summary:
Zile is affected by multiple unspecified security vulnerabilities. The underlying cause or causes for these issues is currently unknown. This BID will be updated when more information becomes available.
It is possible these issue could be exploited to gain unauthorized access or privilege escalation. It should be noted however that this is entirely speculation and cannot be verified.
43. Monolith Lithtech Game Engine Multiple Remote Format String ...
BugTraq ID: 11610
Remote: Yes
Date Published: Nov 05 2004
Relevant URL: http://www.securityfocus.com/bid/11610
Summary:
Lithtech game engine is prone to multiple remote format string vulnerabilities. The source of the problems is incorrect usage of printf() type functions, allowing format specifiers to be supplied directly to vulnerable functions from external data.
A denial of service condition arises when a vulnerable server handles a malformed request.
These issues may also allow an attacker to write to arbitrary process memory and potentially execute code. Any code executed through this vulnerability could potentially be carried out with the privileges of the server.
44. IceWarp Web Mail Multiple Remote Vulnerabilities
BugTraq ID: 11611
Remote: Yes
Date Published: Nov 05 2004
Relevant URL: http://www.securityfocus.com/bid/11611
Summary:
Reportedly, multiple remote vulnerabilities affect IceWarp Web Mail. These issues are due to access validation and design errors.
An attacker may leverage these issues to populate a file on an affected computer, in a known location and potentially reveal a user's authentication credentials. These issues may aid in further attacks.
45. Trend Micro ScanMail for Domino Remote File Disclosure Vulne...
BugTraq ID: 11612
Remote: Yes
Date Published: Nov 05 2004
Relevant URL: http://www.securityfocus.com/bid/11612
Summary:
ScanMail for Domino is reported prone to a vulnerability that may allow sensitive configuration files to be disclosed to remote attackers.
A successful attack may allow an attacker to disclose sensitive information and allow the attacker to disable antivirus protection on a gateway allowing potentially malicious email messages to reach internal users. It is conjectured that as malicious emails are delivered to client mail applications that are seemingly protected by the gateway application, a user may be inclined to open the message due to a false sense of security. This issue may result in a malicious code infection.
All versions of ScanMail for Domino are considered to be vulnerable at the moment.
46. AntiBoard Unspecified SQL Injection Vulnerability
BugTraq ID: 11613
Remote: Yes
Date Published: Nov 05 2004
Relevant URL: http://www.securityfocus.com/bid/11613
Summary:
An unspecified SQL injection vulnerability reportedly affects AntiBoard. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in an SQL query.
Successful exploitation could result in compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Alleged DDoS kingpin joins most wanted list
By: Kevin Poulsen
The feds turn up the heat on a corporate executive who went on the lam after being charged with paying hackers to take down the competition.
http://www.securityfocus.com/news/9870
2. Online fraud tutorials... from the Secret Service?
By: Kevin Poulsen
U.S. law enforcement closed down the thriving criminal marketplace Shadowcrew.com last week, but left its database of forbidden knowledge open to the public.
http://www.securityfocus.com/news/9866
3. New Caller I.D. spoofing site opens
By: Kevin Poulsen
Web-based caller I.D. fakery is back, and this time it's available to everyone.
http://www.securityfocus.com/news/9822
4. Boom times ahead for IT security profession
By: John Leyden, The Register
Boom times are ahead for security pros. The information security workforce will expand by an estimated 13.7 per cent annually to reach 2.1m workers by 2008.
http://www.securityfocus.com/news/9887
5. Trojan infects PCs to generate SMS spam
By: John Leyden, The Register
A Trojan which uses infected PCs to send spam messages to mobile phone users has been discovered.
http://www.securityfocus.com/news/9886
6. Aussie 419 ringleader jailed for four years
By: Lester Haines, The Register
An Australian 419 fraudster who conned AU$5m from his victims was today jailed for four years on 10 counts of fraud and one of perverting the course of justice by the NSW District Court theage.com.au reports.
http://www.securityfocus.com/news/9877
IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. creddump
By: Massimiliano Montoro
Relevant URL: http://www.oxid.it/downloads/creddump.zip
Platforms: Windows XP
Summary:
Credential Manager is a new SSO solution that Microsoft offers in Windows Server 2003 and Windows XP to provide a secured store for credential information. It and allows you to input user name and passwords for various network resources and applications once, and then have the system automatically supply that information for subsequent visits to those resources without your intervention.
2. Maillog View v1.03.3
By: Angelo 'Archie' Amoruso
Relevant URL: http://www.netorbit.it/modules.html
Platforms: Linux
Summary:
Maillog View is a Webmin module that allows you to easily view all your /var/log/maillog.* files. It features autorefresh, message size indication, ascending/descending view order, compressed file support, and a full statistics page. Sendmail, Postfix, Exim, and Qmail (partially) are supported. Courier MTA support is experimental.
3. BullDog Firewall 20040918
By: Robert APM Darin
Relevant URL: http://tanaya.net/BullDog
Platforms: Linux
Summary:
Bulldog is a powerful but lightweight firewall for heavy use systems. With many features, this firewall can be used by anyone who wants to protect his/her systems.
This system allow dynamic and static rules sets for maximum protection and has several advance features.
This firewall will work for the hobbyist or a military base. Generation 7 is a complete rewrite and redesign from scratch.
Be prepared to spend some time setting this up.
4. WapgGuihttp://workspaces.gotdotnet.com/wapggui 1.0
By: William D. Bartholomew
Relevant URL: http://workspaces.gotdotnet.com/wapggui
Platforms: Windows 2000, Windows XP
Summary:
A free, open-source, user-friendly interface to run the WAPG password generator. Supports generation of random and pronounceable passwords, specifying minimum and maximum length, specifying what character classes should or must be used, and much more.
5. antinat v0.81
By: Malcolm Smith
Relevant URL: http://yallara.cs.rmit.edu.au/~malsmith/products/antinat/
Platforms: MacOS, POSIX, Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
The Antinat SOCKS Server is a multi-threaded, scalable SOCKS server with a client library for writing proxy-based applications. It supports SOCKS 4, SOCKS 5, authentication, firewalling, UDP, and name resolution.
6. PopMessenger 1.60
By: LeadMind Development
Relevant URL: http://www.leadmind.com
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
Chat and send text messages and files to anyone on your LAN easily and securely!
V. SECURITYJOBS LIST SUMMARY
----------------------------
1. [SJ-JOB] Account Manager, Philadelphia, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380561
2. [SJ-JOB] Evangelist, Various US locations, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380560
3. [SJ-JOB] VP of Regional Sales, East, GB (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380559
4. [SJ-JOB] Director, Information Security, Geneva, CH (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380558
5. [SJ-JOB] Sales Representative, Chicago or Vicinity, ... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380557
6. [SJ-JOB] Sales Representative, Boston or Vicinity, U... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380556
7. [SJ-JOB] Sr. Security Analyst, Austin, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380555
8. [SJ-JOB] Manager, Information Security, Saint Louis,... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380554
9. [SJ-JOB] Security Product Marketing Manager, Redwood... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380553
10. [SJ-JOB] Channel / Business Development, Washington,... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380552
11. [SJ-JOB] Sales Representative, Atlanta, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380437
12. [SJ-JOB] Sales Representative, Washington, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380434
13. [SJ-JOB] Jr. Security Analyst, Addison, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380433
14. [SJ-JOB] Management, Santa Clara, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380432
15. [SJ-JOB] Security Architect, Annapolis, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380431
16. [SJ-JOB] Developer, Jersey City, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380430
17. [SJ-JOB] Sr. Security Analyst, Arlington, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380429
18. [SJ-JOB] Security System Administrator, Mannheim, DE (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380400
19. [SJ-JOB] Application Security Engineer, Jersey City,... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380397
20. [SJ-JOB] Management, Dallas, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380394
21. [SJ-JOB] Security Engineer, Little Rock, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380393
22. [SJ-JOB] Auditor, Houston, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380392
23. [SJ-JOB] Quality Assurance, Santa Clara, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380391
24. [SJ-JOB] Sr. Security Engineer, Boston, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380390
25. [SJ-JOB] Sr. Security Engineer, North Brunswick, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380389
26. [SJ-JOB] Compliance Officer, New York, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380387
27. [SJ-JOB] Sales Engineer, Boston, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380386
28. [SJ-JOB] Sales Engineer, New York, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380385
29. [SJ-JOB] Sr. Security Engineer, Stamford, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380300
30. [SJ-JOB] Security Architect, Westerville, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380299
31. [SJ-JOB] Security Consultant, Dallas, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380285
32. [SJ-JOB] Security Engineer, San Jose, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380284
33. [SJ-JOB] Security Consultant, North Brunswick, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380282
34. [SJ-JOB] Customer Support, San Francisco, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380281
35. [SJ-JOB] Sr. Security Engineer, Waltham, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380280
36. [SJ-JOB] Security System Administrator, DC, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380277
37. [SJ-JOB] Security Consultant, New York, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380276
38. [SJ-JOB] Application Security Engineer, Seattle, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380275
39. [SJ-JOB] VP, Information Security, Boston, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380274
40. [SJ-JOB] Security Consultant, Bay Area, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380200
41. [SJ-JOB] Manager, Information Security, New York, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380199
42. [SJ-JOB] Security Consultant, Boston, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/380196
VI. INCIDENTS LIST SUMMARY
--------------------------
1. Vulnerability Scan 200.127.113.193, 69.93.128.17 (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/380420
2. Maintaining a "watch list" (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/380419
3. Security Issues with Wake on Lan (WOL) (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/380191
VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Retina Vuln Scanner Problems. (Thread)
Relevant URL:
http://www.securityfocus.com/archive/82/380535
2. DIMVA 2005 - Call for Papers (Thread)
Relevant URL:
http://www.securityfocus.com/archive/82/380534
3. Microsoft ISA Server Authentication Bypassing (Thread)
Relevant URL:
http://www.securityfocus.com/archive/82/380238
4. Windows 2000 SP4 + IE (fully patched) - restrictions... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/82/380185
VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. root_drv.sys rootkit (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/380625
2. SecurityFocus Microsoft Newsletter #213 (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/380236
3. Event Log - Controling critical files and folders. (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/380235
4. Notifying users of password expiration via e-mail` (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/380203
5. AW: Remove "Shutdown" command from w2k PCs but enabl... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/380158
6. GPO that forces users to use a proxy server. (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/380147
IX. SUN FOCUS LIST SUMMARY
--------------------------
NO NEW POSTS FOR THE WEEK 2004-11-02 to 2004-11-09.
X. LINUX FOCUS LIST SUMMARY
---------------------------
1. Linux security compliance (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/380267
XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XII. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored By: Datakey
NEED TO LEARN HOW TO STRENGTHEN & SIMPLIFY SECURITY?
Do you know who is accessing your facilities and networks?
Download Datakey's White Paper, Strengthen and Simplify Security
See how we can help create your strategy for stronger security:
http://www.securityfocus.com/sponsor/Datakey_sf-news_041109
------------------------------------------------------------------------