SecurityFocus Newsletter #276

Peter Laborge <[email protected]> 23 Nov 2004 18:21:21 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #276
------------------------------

This Issue is Sponsored By: Symantec

Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041123

------------------------------------------------------------------------
I. FRONT AND CENTER
     1. Detecting Rootkits And Kernel-level Compromises In Linux
     2. Bill Gates Is Right?
     3. SSH and ssh-agent
II. BUGTRAQ SUMMARY
     1. TWiki Search Shell Metacharacter Remote Arbitrary Command Ex...
     2. Ipswitch IMail Server Delete Command Remote Buffer Overflow ...
     3. Mark Zuckerberg Thefacebook Multiple Cross-Site Scripting Vu...
     4. AlShare Software NetNote Server Remote Denial of Service Vul...
     5. Samba QFILEPATHINFO Unicode Filename Remote Buffer Overflow ...
     6. 3DO Army Men Real Time Strategy Game Remote Format String Vu...
     7. Microsoft Internet Explorer Cookie Overwrite Vulnerability
     8. PowerPortal Remote SQL Injection Vulnerability
     9. Skype Technologies Skype CallTo URI Buffer Overrun Vulnerabi...
     10. New Media Generation Hired Team: Trial Multiple Remote Vulne...
     11. Fcron FCronTab/FCronSighUp Multiple Local Vulnerabilities
     12. 3Com OfficeConnect ADSL Wireless 11g Firewall Router Remote ...
     13. Microsoft Internet Explorer File Download Security Warning B...
     14. Fastream NetFile FTP/Web Server HEAD Request Denial Of Servi...
     15. MiniBB Remote SQL Injection Vulnerability
     16. NuKed-Klan Messaging System HTML Injection Vulnerability
     17. PHPScheduleIt Reservation.Class.PHP Unspecified Reservation ...
     18. Moodle Multiple Unspecified Input Validation Vulnerabilities
     19. Skype Technologies Skype Quick-Call Field Buffer Overrun Vul...
     20. Event Calendar Multiple Remote Vulnerabilities
     21. LibXPM Multiple Unspecified Vulnerabilities
     22. Linux Kernel SMBFS Multiple Remote Vulnerabilities
     23. ClickandBuild LISTPOS Parameter Cross-Site Scripting Vulnera...
     24. Cscope Insecure Temporary File Creation Vulnerabilities
     25. Gentoo GIMPS EBuild Insecure Default Permissions Vulnerabili...
     26. Gentoo SETI@home EBuild Insecure Default Permissions Vulnera...
     27. Gentoo ChessBrain EBuild Insecure Default Permissions Vulner...
     28. PHPBB Admin_cash.PHP Remote PHP File Include Vulnerability
     29. FreeBSD Fetch Remote Buffer Overflow Vulnerability
     30. Invision Power Board Index.PHP Post Action SQL Injection Vul...
     31. AppServ Open Project Remote Insecure Default Password Vulner...
     32. Digital Mappings Systems POP3 Server Remote Buffer Overrun V...
     33. Zone Labs ZoneAlarm Remote Ad-Blocking Denial Of Service Vul...
     34. PHPMyAdmin Multiple Remote Cross-Site Scripting Vulnerabilit...
     35. Mailtraq Administration Console Local Privilege Escalation V...
     36. Altiris Deployment Solution Client Service Local Privilege E...
     37. Danware NetOp Remote Control Information Disclosure Vulnerab...
     38. Microsoft Windows Logon Screensaver Local Privilege Escalati...
     39. Opera Web Browser Java Implementation Multiple Remote Vulner...
     40. PHPWishlist Unspecified Details.PHP Database Corruption Vuln...
     41. Netopia Timbuktu Server For Apple Mac OSX Remote Buffer Over...
     42. Linux Kernel AF_UNIX Arbitrary Kernel Memory Modification Vu...
III. SECURITYFOCUS NEWS ARTICLES
     1. Judge dismisses keylogger case
     2. Petco settles with FTC over cyber security gaffe
     3. Defendant: Microsoft source code sale was a setup
     4. Visa scammers hit UK phones
     5. Privacy advocates fret over electronic passports
     6. British online banking service resumes after e-mail scam thr...
IV. SECURITYFOCUS TOP 6 TOOLS
     1. Oscanner 1.0.0
     2. Dekart Private Disk 2.03
     3. Remote Process Watcher 1.0
     4. AutoScan b0.92 R6
     5. Rkdscan 1.0
     6. Spybot-S&D 1.3
V. SECURITYJOBS LIST SUMMARY
     1. [SJ-JOB] Security Consultant, Redmond, US (Thread)
     2. [SJ-JOB] Manager, Information Security, Bangalore, I... (Thread)
     3. [SJ-JOB] Security Engineer, San Jose, US (Thread)
     4. [SJ-JOB] Security Product Manager, San Francisco, US (Thread)
     5. [SJ-JOB] Developer, Annapolis, US (Thread)
     6. [SJ-JOB] Sales Engineer, new york, US (Thread)
     7. [SJ-JOB] Technical Support Engineer, Bangalore, IN (Thread)
     8. [SJ-JOB] Security Product Manager, Seattle, US (Thread)
     9. [SJ-JOB] Security Consultant, South San Francisco, U... (Thread)
     10. [SJ-JOB] Security Consultant, Scottsdale, US (Thread)
     11. [SJ-JOB] Technical Writer, Dublin, IE (Thread)
     12. [SJ-JOB] Security Consultant, Stamford, US (Thread)
     13. [SJ-JOB] Auditor, Los Angeles, US (Thread)
     14. [SJ-JOB] Security Architect, San Francisco, US (Thread)
     15. [SJ-JOB] Jr. Security Analyst, San Francisco, US (Thread)
     16. [SJ-JOB] Security Consultant, Framingham, US (Thread)
     17. [SJ-JOB] Security Engineer, Dublin, IE (Thread)
     18. [SJ-JOB] Quality Assurance, Dublin, IE (Thread)
     19. [SJ-JOB] Management, Herndon, US (Thread)
     20. [SJ-JOB] Security Consultant, Islandia, US (Thread)
     21. [SJ-JOB] Auditor, Memphis, US (Thread)
     22. [SJ-JOB] Management, Atlanta, US (Thread)
     23. [SJ-JOB] Application Security Engineer, Irvine, US (Thread)
     24. [SJ-JOB] Director of Privacy and Security, Philadelp... (Thread)
     25. [SJ-JOB] Auditor, Eastern Iowa, US (Thread)
     26. [SJ-JOB] Security Architect, Los Angeles, US (Thread)
     27. [SJ-JOB] Management, Boston, US (Thread)
     28. [SJ-JOB] Security Consultant, Santa Ana, US (Thread)
     29. [SJ-JOB] Management, Santa Clara, US (Thread)
     30. [SJ-JOB] Management, palo alto, US (Thread)
     31. [SJ-JOB] Security System Administrator, Denver, US (Thread)
     32. [SJ-JOB] CSO, London, GB (Thread)
     33. [SJ-JOB] Technical Marketing Engineer, Boston, US (Thread)
     34. [SJ-JOB] Manager, Information Security, Milton, CA (Thread)
     35. [SJ-JOB] Security Consultant, Reading, GB (Thread)
     36. [SJ-JOB] Security Researcher, Columbia, US (Thread)
     37. [SJ-JOB] Security Consultant, Vienna, US (Thread)
     38. [SJ-JOB] Developer, Boston, US (Thread)
     39. [SJ-JOB] Security Consultant, Longbeach, US (Thread)
     40. [SJ-JOB] Security Researcher, San Diego, US (Thread)
     41. [SJ-JOB] Security Product Marketing Manager, Palo Al... (Thread)
     42. [SJ-JOB] Security Consultant, Parsippany, US (Thread)
     43. [SJ-JOB] Sales Engineer, Dallas  or Northeast Territ... (Thread)
     44. [SJ-JOB] Auditor, San Francisco, US (Thread)
     45. [SJ-JOB] Certification & Accreditation Engineer, Bet... (Thread)
     46. [SJ-JOB] Auditor, New York City, US (Thread)
     47. [SJ-JOB] Compliance Officer, Rutherford, US (Thread)
     48. [SJ-JOB] Security Consultant, Boston, US (Thread)
     49. [SJ-JOB] Jr. Security Analyst, Minneapolis, US (Thread)
     50. [SJ-JOB] Security Engineer, Chicago, US (Thread)
     51. [SJ-JOB] Manager, Information Security, Charlotte, U... (Thread)
     52. [SJ-JOB] Security Engineer, Detroit, US (Thread)
     53. [SJ-JOB] Sales Representative, San Francisco, US (Thread)
VI. INCIDENTS LIST SUMMARY
     1. PHP injection attempt from 200.222.244.154 (Thread)
     2. is this a recon, or just some browser weirdness? (Thread)
     3. New article announcement: Detecting Rootkits And Ker... (Thread)
     4. CERT Software (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. Online Games Consoles and Security Implications (Thread)
     2. [Full-Disclosure] Re: New whitepaper: Writing IA32 R... (Thread)
     3. New whitepaper: Writing IA32 Restricted Instruction ... (Thread)
     4. 600 Oracle default usernames/passwords available (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. Microsoft rights management server alternatives (Thread)
     2. SecurityFocus Microsoft Newsletter #215 (Thread)
     3. Supported products in Windows Security Center (WSC) (Thread)
IX. SUN FOCUS LIST SUMMARY
     NO NEW POSTS FOR THE WEEK 2004-11-16 to 2004-11-23.
X. LINUX FOCUS LIST SUMMARY
     1. locking idle text consoles (Thread)
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION

I. FRONT AND CENTER
-------------------
1. Detecting Rootkits And Kernel-level Compromises In Linux
By Mariusz Burdach

This article outlines useful ways of detecting hidden modifications to a
Linux kernel. Often known as rootkits, these stealthy types of malware are
installed in the kernel and require special techniques by Incident handlers
and Linux system administrators to be detected.

http://www.securityfocus.com/infocus/1811


2. Bill Gates Is Right?
By Scott Granneman

Bill Gates is right about one thing: asking people to use a two-factor form
of authentication would go a long way toward alleviating a lot of the
password problems that plague computer security today.

http://www.securityfocus.com/columnists/277


3. SSH and ssh-agent
By Brian Hatch

This article discusses how to take SSH Identity/Pubkey trust relationships
to the next level, by using ssh-agent as a keymaster to manage a user's
authentication needs automatically.

http://www.securityfocus.com/infocus/1812

II. BUGTRAQ SUMMARY
-------------------
1. TWiki Search Shell Metacharacter Remote Arbitrary Command Ex...
BugTraq ID: 11674
Remote: Yes
Date Published: Nov 12 2004
Relevant URL: http://www.securityfocus.com/bid/11674
Summary:
TWiki is reported prone to a shell metacharacter remote command execution vulnerability.  This issue may allow an attacker gain unauthorized access to a vulnerable computer by executing arbitrary commands. 

TWiki 20030201 is reported vulnerable to this issue, however, it is likely that other versions are affected as well.

2. Ipswitch IMail Server Delete Command Remote Buffer Overflow ...
BugTraq ID: 11675
Remote: Yes
Date Published: Nov 13 2004
Relevant URL: http://www.securityfocus.com/bid/11675
Summary:
Ipswitch IMail is reported prone to a remote buffer overflow vulnerability.  This issue exists due to insufficient boundary checks performed by the application.  Exploitation of this issue can allow a remote attacker to execute arbitrary code on a vulnerable computer to gain unauthorized access.

Ipswitch IMail 8.13 is reported prone to this vulnerability.  It is possible that other versions are affected as well.

3. Mark Zuckerberg Thefacebook Multiple Cross-Site Scripting Vu...
BugTraq ID: 11676
Remote: Yes
Date Published: Nov 13 2004
Relevant URL: http://www.securityfocus.com/bid/11676
Summary:
It is reported that Thefacebook is affected by various cross-site scripting vulnerabilities.  These issues are due to a failure of the application to properly sanitize user-supplied URI input. 

These issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

4. AlShare Software NetNote Server Remote Denial of Service Vul...
BugTraq ID: 11677
Remote: Yes
Date Published: Nov 13 2004
Relevant URL: http://www.securityfocus.com/bid/11677
Summary:
NetNote server is reported prone to a remote denial of service vulnerability.  This issue occurs because the application does not handle exceptional conditions properly.

NetNote server 2.2 build 230 is reported vulnerable to this issue, however, it is likely that other versions are affected as well.

5. Samba QFILEPATHINFO Unicode Filename Remote Buffer Overflow ...
BugTraq ID: 11678
Remote: Yes
Date Published: Nov 15 2004
Relevant URL: http://www.securityfocus.com/bid/11678
Summary:
Samba is reported prone to a remote buffer overflow vulnerability.  This issue presents itself because the application does not perform proper boundary checks before copying user-supplied data into finite sized process buffers.  This issue can allow an attacker to execute arbitrary code on a vulnerable computer to gain unauthorized access.

This vulnerability is reported to affect Samba versions 3.0.0 to 3.0.7.

6. 3DO Army Men Real Time Strategy Game Remote Format String Vu...
BugTraq ID: 11679
Remote: Yes
Date Published: Nov 15 2004
Relevant URL: http://www.securityfocus.com/bid/11679
Summary:
Reportedly a remote format string vulnerability affects 3DO Army Men Real Time Strategy Game.  This issue is due to a failure of the application to properly sanitize user-supplied input prior to utilizing it in a formatted string function.

An attacker may leverage this issue to crash the affected server and execute arbitrary code with the privileges of the user that activated the vulnerable game server.

7. Microsoft Internet Explorer Cookie Overwrite Vulnerability
BugTraq ID: 11680
Remote: Yes
Date Published: Nov 15 2004
Relevant URL: http://www.securityfocus.com/bid/11680
Summary:
Microsoft Internet Explorer is reported prone to vulnerability that may allow a remote attacker overwrite existing cookies in the browser.

It is alleged that this issue can be exploited to hijack a user's Web session, however, it is not confirmed how this attack would be possible.  If a legitimate cookie is corrupted, it may be possible to cause a partial denial of service attack.

8. PowerPortal Remote SQL Injection Vulnerability
BugTraq ID: 11681
Remote: Yes
Date Published: Nov 14 2004
Relevant URL: http://www.securityfocus.com/bid/11681
Summary:
PowerPortal is reported vulnerable to remote SQL injection. This issue is due to a failure of the application to properly validate user-supplied input prior to including it in an SQL query. 

PowerPortal 1.3 is reported prone to this vulnerability, however, it is possible that other versions are affected as well.

9. Skype Technologies Skype CallTo URI Buffer Overrun Vulnerabi...
BugTraq ID: 11682
Remote: Yes
Date Published: Nov 12 2004
Relevant URL: http://www.securityfocus.com/bid/11682
Summary:
Skype is reported prone to a buffer overflow vulnerability.  This issue occurs due to a lack of bounds checking performed by the application.  This issue can be exploited through a malformed CallTo URI.

This issue exists in Skype 1.0.0.97 and prior versions.

10. New Media Generation Hired Team: Trial Multiple Remote Vulne...
BugTraq ID: 11683
Remote: Yes
Date Published: Nov 15 2004
Relevant URL: http://www.securityfocus.com/bid/11683
Summary:
Multiple remote vulnerabilities reportedly affect New Media Generation Hired Team: Trial.  These issues are due to failure to properly validate user-supplied input, handle exceptional conditions, and properly validate access credentials.

A remote attacker may leverage these issues to execute arbitrary code, carry out denial of service attacks and kick any player from the current game session.

11. Fcron FCronTab/FCronSighUp Multiple Local Vulnerabilities
BugTraq ID: 11684
Remote: No
Date Published: Nov 15 2004
Relevant URL: http://www.securityfocus.com/bid/11684
Summary:
Fcron is reported prone to multiple local vulnerabilities. The following issues are reported:

A local information disclosure vulnerability is reported to affect fcronsighup. It is reported that the affected utility will attempt to parse configuration files that are passed to the utility as a command line argument.

A local attacker may exploit this condition to reveal the contents of arbitrary files that are owned by the superuser. This vulnerability is assigned the following MITRE CVE identifier: CAN-2004-1030.

An access control bypass vulnerability is also reported to affect fcronsighup. It is reported that the issue exists due to a design error.

A local attacker may exploit this vulnerability to make configuration changes to fcronsighup. This vulnerability is assigned the following MITRE CVE identifier: CAN-2004-1031.

fcronsighup is reported prone to an arbitrary file deletion vulnerability. By exploiting the aforementioned access control bypass vulnerability, a local attacker may influence the fcronsighup configuration and may cause the application to overwrite arbitrary attacker specified files. This vulnerability is assigned the following MITRE CVE identifier: CAN-2004-1032.

Finally it is reported that the fcrontab component of Fcron leaks file descriptors. This can result in sensitive information disclosure. Specifically, fcrontab leaks the file descriptors of the '/etc/fcron.allow' and '/etc/fcron.deny' files. This vulnerability is assigned the following MITRE CVE identifier: CAN-2004-1033.

12. 3Com OfficeConnect ADSL Wireless 11g Firewall Router Remote ...
BugTraq ID: 11685
Remote: Yes
Date Published: Nov 16 2004
Relevant URL: http://www.securityfocus.com/bid/11685
Summary:
A remote denial of service vulnerability affects the 3Com OfficeConnect ADSL Wireless 11g Firewall Router.  This issue is due to a failure of the application to handle anomalous network traffic.

An attacker may leverage this issue to cause the affected router to crash, denying service to legitimate users.

13. Microsoft Internet Explorer File Download Security Warning B...
BugTraq ID: 11686
Remote: Yes
Date Published: Nov 16 2004
Relevant URL: http://www.securityfocus.com/bid/11686
Summary:
Microsoft Internet Explorer is reported prone to a file download security warning bypass vulnerability.  This issue may be exploited to download a malicious file to the client system. 

When a URI location is not found the user usually receives a 404 error message.  It is reported that this issue allows an attacker to create a custom HTTP 404 error message and use the 'execCommand' method to save a Web page to the local system.  

By enticing a user to follow a malicious link the attacker can plant malicious files on vulnerable systems in order to execute malicious code.

14. Fastream NetFile FTP/Web Server HEAD Request Denial Of Servi...
BugTraq ID: 11687
Remote: Yes
Date Published: Nov 16 2004
Relevant URL: http://www.securityfocus.com/bid/11687
Summary:
Fastream NetFile FTP/Web Server is reported susceptible to an HTTP HEAD request denial of service vulnerability.

This vulnerability allows remote attackers to create many simultaneous HTTP HEAD requests to the vulnerable server application. Once the attacker has created sufficient connections, further requests from legitimate users will reportedly be denied. Due to the failure of the application to close the previous connections, it is conjectured that attackers can indefinitely block further requests to the Web server.

Version 7.1 of Fastream NetFIle FTP/Web Server was reported susceptible to this vulnerability. Other versions are also likely affected.

15. MiniBB Remote SQL Injection Vulnerability
BugTraq ID: 11688
Remote: Yes
Date Published: Nov 16 2004
Relevant URL: http://www.securityfocus.com/bid/11688
Summary:
miniBB is reported vulnerable to remote SQL injection. This issue is due to a failure of the application to properly validate user-supplied input prior to including it in an SQL query. 

miniBB versions prior to 1.7f are reported prone to this issue.

16. NuKed-Klan Messaging System HTML Injection Vulnerability
BugTraq ID: 11689
Remote: Yes
Date Published: Nov 16 2004
Relevant URL: http://www.securityfocus.com/bid/11689
Summary:
NuKed-Klan messaging system is reported prone to a HTML injection vulnerability. It is reported that the issue exists due to a lack of sufficient input validation performed on a certain input field of the NuKed-Klan messaging form.

Attackers may potentially exploit this issue to manipulate web content or to steal cookie-based authentication credentials. It may also be possible to take arbitrary actions as the victim user.

17. PHPScheduleIt Reservation.Class.PHP Unspecified Reservation ...
BugTraq ID: 11690
Remote: Yes
Date Published: Nov 16 2004
Relevant URL: http://www.securityfocus.com/bid/11690
Summary:
phpScheduleIt is reported prone to an unspecified vulnerability. The issue is reported to exist in the 'Reservation.class.php' source file.

It is reported that a remote attacker may exploit this vulnerability to modify or delete phpScheduleIt reservation entries.

18. Moodle Multiple Unspecified Input Validation Vulnerabilities
BugTraq ID: 11691
Remote: Yes
Date Published: Nov 16 2004
Relevant URL: http://www.securityfocus.com/bid/11691
Summary:
Moodle is reported susceptible to multiple unspecified input validation vulnerabilities. These vulnerabilities are due to a failure of the application to properly sanitize user-supplied input data.

These unspecified issues may be cross-site scripting, HTML injection, or SQL injection vulnerabilities.

Cross-site scripting and HTML injection issues could permit a remote attacker to cause hostile HTML or script code to be rendered in the web browser of victim users. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

SQL injection issues may be exploited to manipulate SQL queries, potentially revealing or corrupting sensitive database data. SQL injection issues may also facilitate attacks against the underlying database software.

Versions prior to 1.4.2 are reported susceptible to these vulnerabilities.

19. Skype Technologies Skype Quick-Call Field Buffer Overrun Vul...
BugTraq ID: 11692
Remote: Yes
Date Published: Nov 16 2004
Relevant URL: http://www.securityfocus.com/bid/11692
Summary:
Skype is reported prone to a buffer overflow vulnerability. This issue occurs due to a lack of bounds checking performed by the application. 

This vulnerability may result in the corruption of sensitive regions of memory. Ultimately, this may be exploited to execute arbitrary code in the context of a user running Skype.

This issue exists in Skype 1.0.0.97 and prior versions.

20. Event Calendar Multiple Remote Vulnerabilities
BugTraq ID: 11693
Remote: Yes
Date Published: Nov 16 2004
Relevant URL: http://www.securityfocus.com/bid/11693
Summary:
Event Calendar is prone to multiple input validation vulnerabilities. These issues include HTML injection and cross-site scripting. The following specific vulnerabilities were reported:

A cross-site scripting vulnerability is exposed through certain NukeCalendar URI parameters.  This issue could be exploited via a malicious link to a site hosting the software to execute hostile HTML and script content in the browser of a victim user.

A HTML injection vulnerability is reported to affect the events comments input forms. This issue could be exploited when an unsuspecting user views a malicious event comment, this will result in attacker-supplied HTML and script content executing in the browser of the victim user.

An SQL injection vulnerability is also present through URI parameters of the affected software, which includes unsanitized user input in database queries. This may be exploited to extract sensitive information from the database.

21. LibXPM Multiple Unspecified Vulnerabilities
BugTraq ID: 11694
Remote: Yes
Date Published: Nov 17 2004
Relevant URL: http://www.securityfocus.com/bid/11694
Summary:
libXpm is reported prone to multiple vulnerabilities. These issues may be triggered when handling malformed XPM images. The following issues are reported:
Integer overflow vulnerabilities, out-of-bounds memory access vulnerabilities, a shell command execution vulnerability, a path traversal vulnerability, and endless loop vulnerabilities.

The details regarding each of these issues are not specified at the time of writing. However, this BID will be updated as further details regarding these vulnerabilities becomes available.

22. Linux Kernel SMBFS Multiple Remote Vulnerabilities
BugTraq ID: 11695
Remote: Yes
Date Published: Nov 17 2004
Relevant URL: http://www.securityfocus.com/bid/11695
Summary:
The Linux kernel is reported susceptible to multiple remote vulnerabilities in the SMBFS network file system.

These vulnerabilities may lead to the execution of attacker-supplied machine code, information disclosure of kernel memory, or kernel crashes, denying service to legitimate users.

Versions of the kernel in both the 2.4, and the 2.6 series are reported susceptible to various issues.

23. ClickandBuild LISTPOS Parameter Cross-Site Scripting Vulnera...
BugTraq ID: 11696
Remote: Yes
Date Published: Nov 17 2004
Relevant URL: http://www.securityfocus.com/bid/11696
Summary:
ClickandBuild is affected by a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input. 

All versions of ClickandBuild are considered vulnerable at the moment.

24. Cscope Insecure Temporary File Creation Vulnerabilities
BugTraq ID: 11697
Remote: No
Date Published: Nov 17 2004
Relevant URL: http://www.securityfocus.com/bid/11697
Summary:
Cscope is reportedly affected by insecure temporary file creation vulnerabilities. These issues are due to a design error that causes the application to fail to verify the existence of a file before writing to it.

It is reported that during execution the affected utility creates temporary files in the system's temporary directory, '/tmp', with predictable names. This allows attackers to create malicious symbolic links that will be written to by the vulnerable utility when an unsuspecting user executes it.

An attacker may leverage these issues to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.

Versions up to and including version 15.5 are reported vulnerable.

25. Gentoo GIMPS EBuild Insecure Default Permissions Vulnerabili...
BugTraq ID: 11698
Remote: No
Date Published: Nov 17 2004
Relevant URL: http://www.securityfocus.com/bid/11698
Summary:
The Gentoo GIMPS eBuild package is reported prone to a weak default permissions vulnerability.

A local attacker may exploit this vulnerability to escalate privileges.

26. Gentoo SETI@home EBuild Insecure Default Permissions Vulnera...
BugTraq ID: 11699
Remote: No
Date Published: Nov 17 2004
Relevant URL: http://www.securityfocus.com/bid/11699
Summary:
The Gentoo SETI@home eBuild package is reported prone to a weak default permissions vulnerability.

A local attacker may exploit this vulnerability to escalate privileges.

27. Gentoo ChessBrain EBuild Insecure Default Permissions Vulner...
BugTraq ID: 11700
Remote: No
Date Published: Nov 17 2004
Relevant URL: http://www.securityfocus.com/bid/11700
Summary:
The Gentoo ChessBrain eBuild package is reported prone to a weak default permissions vulnerability.

A local attacker may exploit this vulnerability to escalate privileges.

28. PHPBB Admin_cash.PHP Remote PHP File Include Vulnerability
BugTraq ID: 11701
Remote: Yes
Date Published: Nov 17 2004
Relevant URL: http://www.securityfocus.com/bid/11701
Summary:
A vulnerability is reported to exist in the phpBB Cash_Mod module that may allow an attacker to include malicious PHP files containing arbitrary code to be executed on a vulnerable system.

Remote attackers could potentially exploit this issue via a vulnerable variable to include a remote malicious PHP script, which will be executed in the context of the web server hosting the vulnerable software.

29. FreeBSD Fetch Remote Buffer Overflow Vulnerability
BugTraq ID: 11702
Remote: Yes
Date Published: Nov 18 2004
Relevant URL: http://www.securityfocus.com/bid/11702
Summary:
A remote buffer overflow vulnerability affects the FreeBSD fetch utility.  This issue is due to a failure of the application to carry out sufficient bounds checks of HTTP response header data prior to copying it into process buffers.

A malicious server may leverage this issue to execute arbitrary code on an affected computer with the privileges of a user executing the vulnerable client software.  This may facilitate unauthorized access or privilege escalation.

30. Invision Power Board Index.PHP Post Action SQL Injection Vul...
BugTraq ID: 11703
Remote: Yes
Date Published: Nov 18 2004
Relevant URL: http://www.securityfocus.com/bid/11703
Summary:
A remote SQL injection vulnerability affects Inivision Power Board.  This issue is due to a failure of the application to properly validate user-supplied input prior to using it in an SQL query.

An attacker may leverage this issue to manipulate SQL query strings and potentially carry out arbitrary database queries.  This may facilitate the disclosure or corruption of sensitive database information.

31. AppServ Open Project Remote Insecure Default Password Vulner...
BugTraq ID: 11704
Remote: Yes
Date Published: Nov 18 2004
Relevant URL: http://www.securityfocus.com/bid/11704
Summary:
A remote insecure default password vulnerability reportedly affects AppServ Open Project.  This issue is due to a failure of the application to securely create a default user account on the installed database.

An attacker may leverage this issue to gain access to the MySQL database  through the insecure user account installed by the affected application.  This may facilitate unauthorized access or privilege escalation.

32. Digital Mappings Systems POP3 Server Remote Buffer Overrun V...
BugTraq ID: 11705
Remote: Yes
Date Published: Nov 18 2004
Relevant URL: http://www.securityfocus.com/bid/11705
Summary:
It is reported that a boundary condition error exists in the Digital Mappings Systems POP3 server. A remote attacker sending a username of excessive length during the authentication process to the POP3 server may cause a buffer overrun that could result in execution of malicious instructions and system compromise.

This vulnerability could result in a remote attacker gaining unauthorized access to a vulnerable host with the POP3 server process privileges.

33. Zone Labs ZoneAlarm Remote Ad-Blocking Denial Of Service Vul...
BugTraq ID: 11706
Remote: Yes
Date Published: Nov 19 2004
Relevant URL: http://www.securityfocus.com/bid/11706
Summary:
A remote denial of service vulnerability affects Zone Labs ZoneAlarm.  The vulnerability exists in the ad-blocking feature.  This issue is due to a failure of the application to handle exceptional scripts embedded in Web sites.

It should be noted that the affected functionality is not enabled by default.  This issue only affects computers with the vulnerable component activated.

An attacker may leverage this issue to cause the affected computer to become unstable and lock, potentially denying service to legitimate users.

34. PHPMyAdmin Multiple Remote Cross-Site Scripting Vulnerabilit...
BugTraq ID: 11707
Remote: Yes
Date Published: Nov 19 2004
Relevant URL: http://www.securityfocus.com/bid/11707
Summary:
Multiple remote cross-site scripting vulnerabilities affect phpMyAdmin.  These issues are due to a failure of the application to perform proper sanitization prior to including user-supplied input in dynamically generated content.

An attacker may leverage these issues to execute arbitrary client side script code in the browser of an unsuspecting user.  This may potentially lead to theft of cookie-based authentication credentials as well as other attacks.

35. Mailtraq Administration Console Local Privilege Escalation V...
BugTraq ID: 11708
Remote: No
Date Published: Nov 19 2004
Relevant URL: http://www.securityfocus.com/bid/11708
Summary:
Mailtraq allows a user to activate the Mailtraq administration console software by easily launching the software from an icon in the Windows system tray. It is reported that a local user may exploit the administration console interface to escalate privileges.

36. Altiris Deployment Solution Client Service Local Privilege E...
BugTraq ID: 11709
Remote: No
Date Published: Nov 19 2004
Relevant URL: http://www.securityfocus.com/bid/11709
Summary:
Altiris Deployment Solution Client allows a user to activate the client interface by easily launching the software from an icon in the Windows system tray. It is reported that a local user may exploit the client interface to escalate privileges.

It should be noted that although this vulnerability is reported to exist in Altiris Deployment Solution version 5.6 SP1 (Hotfix E) other versions might also be affected.

37. Danware NetOp Remote Control Information Disclosure Vulnerab...
BugTraq ID: 11710
Remote: Yes
Date Published: Nov 19 2004
Relevant URL: http://www.securityfocus.com/bid/11710
Summary:
It is reported that NetOp Remote Control is susceptible to an information disclosure vulnerability.

This vulnerability reportedly allows remote attackers to discern the name of the user that is logged in and the internal IP address and hostname of the targeted computer. This information may aid malicious users in further attacks.

Versions prior to 7.65 build 2004278 are reported vulnerable to this issue.

38. Microsoft Windows Logon Screensaver Local Privilege Escalati...
BugTraq ID: 11711
Remote: No
Date Published: Nov 19 2004
Relevant URL: http://www.securityfocus.com/bid/11711
Summary:
The Microsoft Windows default logon screensaver is reported prone to a local privilege escalation vulnerability. It is reported that the screensaver is started with SYSTEM privileges on Microsoft Windows NT, 2000 and XP computers.

A local attacker that has sufficient privileges to modify or replace the default logon screensaver, or that had sufficient privileges to modify registry entries that relate to the logon screensaver, may exploit this vulnerability to attain local SYSTEM privileges.  The default configuration for the software may expose this vulnerability on affected platforms due to lax permissions on the screensaver executable.  This could vary depending on the host platform.

39. Opera Web Browser Java Implementation Multiple Remote Vulner...
BugTraq ID: 11712
Remote: Yes
Date Published: Nov 19 2004
Relevant URL: http://www.securityfocus.com/bid/11712
Summary:
Multiple remote vulnerabilities reportedly affect the Opera Web Browser Java implementation.  These issues are due to the insecure proprietary design of the Web browser's Java implementation.

These issues may allow an attacker to craft a Java applet that violate Sun's Java secure programming guidelines.

These issues may be leveraged to carry out a variety of unspecified attacks including sensitive information disclosure and denial of service attacks.  Any successful exploitation would take place with the privileges of the user running the affected browser application.

Although only version 7.54 is reportedly vulnerable, it is likely that earlier versions are vulnerable to these issues as well.

40. PHPWishlist Unspecified Details.PHP Database Corruption Vuln...
BugTraq ID: 11713
Remote: Yes
Date Published: Nov 19 2004
Relevant URL: http://www.securityfocus.com/bid/11713
Summary:
phpWishlist is reported prone to an unspecified vulnerability that exists in the 'details.php' script. It is reported that the vulnerability may be exploited so that any user may reset all database passwords.

41. Netopia Timbuktu Server For Apple Mac OSX Remote Buffer Over...
BugTraq ID: 11714
Remote: Yes
Date Published: Nov 19 2004
Relevant URL: http://www.securityfocus.com/bid/11714
Summary:
Netopia Timbuktu server component for Apple Mac OSX is reported prone to a remote unspecified buffer overflow vulnerability. This issue exists due to insufficient boundary checks performed by the application. 

This vulnerability can allow an attacker to corrupt process memory leading to a denial of service condition.  If an attacker is able to overwrite sensitive memory addresses and redirect process execution to attacker-supplied arbitrary code, this vulnerability may result in the attacker gaining unauthorized access to the computer.

42. Linux Kernel AF_UNIX Arbitrary Kernel Memory Modification Vu...
BugTraq ID: 11715
Remote: No
Date Published: Nov 19 2004
Relevant URL: http://www.securityfocus.com/bid/11715
Summary:
It is reported that a serialization error exists in the AF_UNIX address family that creates a race condition. This race condition reportedly allows local users to repeatedly increment arbitrary kernel memory locations.

This vulnerability allows local users to modify arbitrary kernel memory, facilitating privilege escalation, or possibly allowing code execution in the context of the kernel.

Versions prior to 2.4.28 are reportedly affected by this vulnerability.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Judge dismisses keylogger case
By: Kevin Poulsen

Covert use of a hardware keystroke logger does not violate federal wiretap law, court rules.
http://www.securityfocus.com/news/9978

2. Petco settles with FTC over cyber security gaffe
By: Kevin Poulsen

It's the fifth time regulators have taken action against a company for failing to protect consumer data -- and the second time the same California coder blew the whistle.
http://www.securityfocus.com/news/9957

3. Defendant: Microsoft source code sale was a setup
By: Kevin Poulsen

A Connecticut man facing economic espionage charges says he wasn't serious about selling already-leaked Microsoft source code, but an undercover investigator for the software giant was determined to pay him something.

http://www.securityfocus.com/news/9912

4. Visa scammers hit UK phones
By: John Leyden, The Register

Credit card fraudsters are trying to fleece UK punters by tricking them into revealing card security information over the phone.
http://www.securityfocus.com/news/9988

5. Privacy advocates fret over electronic passports
By: Ellen Simon, The Associated Press

http://www.securityfocus.com/news/9981

6. British online banking service resumes after e-mail scam thr...
By: , The Associated Press

http://www.securityfocus.com/news/9979

IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Oscanner 1.0.0
By: Patrik Karlsson
Relevant URL: http://www.cqure.net/tools.jsp?id=20
Platforms: Java
Summary: 

Oscanner is an Oracle assesment framework developed in Java. It has a plugin-based architecture and comes with a couple of plugins that currently do;

  - Sid Enumeration
  - Passwords tests (common & dictionary)
  - Enumerate Oracle version
  - Enumerate account roles
  - Enumerate account priveleges
  - Enumerate account hashes
  - Enumerate audit information
  - Enumerate password policies
  - Enumerate database links

The results are given in a graphical java tree.

2. Dekart Private Disk 2.03
By: Dekart
Relevant URL: http://www.private-disk.net/
Platforms: Windows XP
Summary: 

Private Disk - is an easy-to-use, reliable, user-friendly and smart program that lets you create encrypted disk partitions (drive letters) to keep your private and confidential data secure. Uses 256-bit AES encryption.

3. Remote Process Watcher 1.0
By: Fitsec Tmi
Relevant URL: http://www.fitsec.com/downloads
Platforms: Windows 2000, Windows NT, Windows XP
Summary: 

A Java based software that watches processes running on the computers inside a domain. Gives out warnings when it spots a process that it doesn't recognize or processes that have been marked on the warning list. It is also able to autokill processes marked as critical.

4. AutoScan b0.92 R6
By: Lagarde Thierry
Relevant URL: http://autoscan.free.fr/
Platforms: Linux
Summary: 

AutoScan is an application designed to explore and to manage your network. Entire subnets can be scanned simultaneously without human intervention. It features OS detection, automatic network discovery, a port scanner, a Samba share browser, and the ability to save the network state.

5. Rkdscan 1.0
By: Andres Tarasco - www.sia.es
Relevant URL: http://cyruxnet.org/download/rkdscan.rar
Platforms: Windows 2000
Summary: 

Rkdscan is able to remotely detect if NT based Computers are compromised With "Hacker Defender" Rootkit

6. Spybot-S&D 1.3
By: Patrick M. Kolla
Relevant URL: http://www.spybot.info/en/index.html
Platforms: Windows XP
Summary: 

Spybot - Search & Destroy can detect and remove spyware of different kinds
from your computer. Spyware is a relatively new kind of threat that
common anti-virus applications do not yet cover. If you see new toolbars in
your Internet Explorer that you didn't intentionally install, if your browser
crashes, or if you browser start page has changed without your knowing, you
most probably have spyware. But even if you don't see anything, you may be
infected.

V. SECURITYJOBS LIST SUMMARY
----------------------------
1. [SJ-JOB] Security Consultant, Redmond, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381901

2. [SJ-JOB] Manager, Information Security, Bangalore, I... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381875

3. [SJ-JOB] Security Engineer, San Jose, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381867

4. [SJ-JOB] Security Product Manager, San Francisco, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381850

5. [SJ-JOB] Developer, Annapolis, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381842

6. [SJ-JOB] Sales Engineer, new york, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381841

7. [SJ-JOB] Technical Support Engineer, Bangalore, IN (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381837

8. [SJ-JOB] Security Product Manager, Seattle, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381836

9. [SJ-JOB] Security Consultant, South San Francisco, U... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381724

10. [SJ-JOB] Security Consultant, Scottsdale, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381694

11. [SJ-JOB] Technical Writer, Dublin, IE (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381692

12. [SJ-JOB] Security Consultant, Stamford, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381691

13. [SJ-JOB] Auditor, Los Angeles, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381687

14. [SJ-JOB] Security Architect, San Francisco, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381685

15. [SJ-JOB] Jr. Security Analyst, San Francisco, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381682

16. [SJ-JOB] Security Consultant, Framingham, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381665

17. [SJ-JOB] Security Engineer, Dublin, IE (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381660

18. [SJ-JOB] Quality Assurance, Dublin, IE (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381658

19. [SJ-JOB] Management, Herndon, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381656

20. [SJ-JOB] Security Consultant, Islandia, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381654

21. [SJ-JOB] Auditor, Memphis, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381651

22. [SJ-JOB] Management, Atlanta, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381648

23. [SJ-JOB] Application Security Engineer, Irvine, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381644

24. [SJ-JOB] Director of Privacy and Security, Philadelp... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381603

25. [SJ-JOB] Auditor, Eastern Iowa, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381602

26. [SJ-JOB] Security Architect, Los Angeles, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381599

27. [SJ-JOB] Management, Boston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381593

28. [SJ-JOB] Security Consultant, Santa Ana, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381588

29. [SJ-JOB] Management, Santa Clara, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381586

30. [SJ-JOB] Management, palo alto, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381584

31. [SJ-JOB] Security System Administrator, Denver, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381583

32. [SJ-JOB] CSO, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381577

33. [SJ-JOB] Technical Marketing Engineer, Boston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381568

34. [SJ-JOB] Manager, Information Security, Milton, CA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381564

35. [SJ-JOB] Security Consultant, Reading, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381562

36. [SJ-JOB] Security Researcher, Columbia, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381553

37. [SJ-JOB] Security Consultant, Vienna, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381552

38. [SJ-JOB] Developer, Boston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381550

39. [SJ-JOB] Security Consultant, Longbeach, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381540

40. [SJ-JOB] Security Researcher, San Diego, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381539

41. [SJ-JOB] Security Product Marketing Manager, Palo Al... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381533

42. [SJ-JOB] Security Consultant, Parsippany, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381531

43. [SJ-JOB] Sales Engineer, Dallas  or Northeast Territ... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381529

44. [SJ-JOB] Auditor, San Francisco, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381527

45. [SJ-JOB] Certification & Accreditation Engineer, Bet... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381526

46. [SJ-JOB] Auditor, New York City, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381525

47. [SJ-JOB] Compliance Officer, Rutherford, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381319

48. [SJ-JOB] Security Consultant, Boston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381310

49. [SJ-JOB] Jr. Security Analyst, Minneapolis, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381308

50. [SJ-JOB] Security Engineer, Chicago, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381301

51. [SJ-JOB] Manager, Information Security, Charlotte, U... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381293

52. [SJ-JOB] Security Engineer, Detroit, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381291

53. [SJ-JOB] Sales Representative, San Francisco, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/381286

VI. INCIDENTS LIST SUMMARY
--------------------------
1. PHP injection attempt from 200.222.244.154 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/381937

2. is this a recon, or just some browser weirdness? (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/381626

3. New article announcement: Detecting Rootkits And Ker... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/381544

4. CERT Software (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/381405

VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Online Games Consoles and Security Implications (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/381693

2. [Full-Disclosure] Re: New whitepaper: Writing IA32 R... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/381499

3. New whitepaper: Writing IA32 Restricted Instruction ... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/381498

4. 600 Oracle default usernames/passwords available (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/381412

VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. Microsoft rights management server alternatives (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/381986

2. SecurityFocus Microsoft Newsletter #215 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/381367

3. Supported products in Windows Security Center (WSC) (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/381330

IX. SUN FOCUS LIST SUMMARY
--------------------------
NO NEW POSTS FOR THE WEEK 2004-11-16 to 2004-11-23.

X. LINUX FOCUS LIST SUMMARY
---------------------------
1. locking idle text consoles (Thread)
Relevant URL:

http://www.securityfocus.com/archive/91/381905

XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.
    
XII. SPONSOR INFORMATION
-----------------------

This Issue is Sponsored By: Symantec

Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041123

------------------------------------------------------------------------