SecurityFocus Newsletter #278

Peter Laborge <[email protected]> 7 Dec 2004 21:47:52 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #278
------------------------------

This Issue is Sponsored By: RSA

RSA Conference 2005
The RSA Conference is the most prestigious information security event of
the year!  This is the authoritative source for uncovering new ways to
thwart cyber-criminals.  Learn.  Network.  Grow.  RSA Conference 2005 takes
place February 14 to 18, 2005 in San Francisco.  Register before January
15, 2005 and save $500 off the Full Conference rate.

http://www.securityfocus.com/sponsor/RSA_sf-news_041207

------------------------------------------------------------------------

Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041130

------------------------------------------------------------------------
I. FRONT AND CENTER
     1. Detecting Complex Viruses
     2. Lycos Goes Straight
     3. Closed Source Hardware
II. BUGTRAQ SUMMARY
     1. Microsoft Internet Explorer Drag and Drop Vulnerability
     2. File ELF Header Unspecified Buffer Overflow Vulnerability
     3. Ipswitch WS_FTP Multiple Remote Buffer Overflow Vulnerabilit...
     4. Groupmax World Wide Web Cross-Site Scripting And Directory T...
     5. 21-6 Productions Orbz Remote Buffer Overflow Vulnerability
     6. Mercury Mail Multiple Remote IMAP Stack Buffer Overflow Vuln...
     7. GlobalScape CuteFTP Multiple Command Response Buffer Overflo...
     8. EnergyMech IRC Bot Unspecified Buffer Overflow Vulnerability
     9. FreeImage Interleaved Bitmap Image Buffer Overflow Vulnerabi...
     10. IPCop Web Administration Interface Proxy Log HTML Injection ...
     11. JanaServer 2 Multiple Remote Denial Of Service Vulnerabiliti...
     12. OpenSSH-portable PAM Authentication Remote Information Discl...
     13. Sun Solaris Ping Local Buffer Overflow Vulnerability
     14. SuSE Linux Enterprise Server NFS Unspecified Denial Of Servi...
     15. SuSE Linux Kernel Unauthorized SCSI Command Vulnerability
     16. Linux NFS RPC.STATD Remote Denial Of Service Vulnerability
     17. ACPID Proxy Unspecified Local Denial Of Service Vulnerabilit...
     18. gnubiff Multiple Remote Denial Of Service Vulnerabilities
     19. Mercury Mail Multiple Remote IMAP Buffer Overflow Vulnerabil...
     20. FreeBSD Linux ProcFS Local Kernel Denial Of Service And Info...
     21. S9Y Serendipity Remote Cross-Site Scripting Vulnerability
     22. SCPOnly Remote Arbitrary Command Execution Vulnerability
     23. RSSH Remote Arbitrary Command Execution Vulnerability
     24. Cisco CNS Network Registrar DNS and DHCP Server Remote Denia...
     25. Linux Kernel Unspecified Local TSS Vulnerability For AMD64 A...
     26. Blog Torrent Remote Directory Traversal Vulnerability
     27. Global Moxie Big Medium Unspecified Remote Script Code Execu...
     28. PHProjekt Unspecified Authentication Bypass Vulnerability
     29. Advanced Guestbook Cross-Site Scripting Vulnerability
     30. Burut Kreed Game Server Multiple Remote Vulnerabilities
     31. HP HPSOCKD Unspecified Remote Buffer Overflow Vulnerability
     32. IBM AIX Multiple Local Vulnerabilities
     33. Apple Mac OS X Multiple Remote And Local Vulnerabilities
     34. Apache Jakarta Results.JSP Remote Cross-Site Scripting Vulne...
     35. Computer Associates Unicenter Remote Control Remote Authenti...
     36. Sandino Flores Moreno Gaim Festival Plug-in Remote Denial Of...
III. SECURITYFOCUS NEWS ARTICLES
     1. Berkeley Hack Sparks Legislative Backlash
     2. Hacking tool reportedly draws FBI subpoenas
     3. Judge dismisses keylogger case
     4. Police drop investigation of roulette hackers
     5. Fake Lycos screensaver harbours Trojan
     6. High-school drop-out to become Homeland Security Czar
IV. SECURITYFOCUS TOP 6 TOOLS
     1. Sherpa 0.1.8
     2. IDS Policy Manager v1.5
     3. PatchLink Update 6.01.78
     4. Oscanner 1.0.0
     5. Dekart Private Disk 2.03
     6. Remote Process Watcher 1.0
V. SECURITYJOBS LIST SUMMARY
     1. [SJ-JOB] Security Consultant, Seattle, US (Thread)
     2. [SJ-JOB] Technical Writer, San Jose, US (Thread)
     3. [SJ-JOB] Security Consultant, Any US location, US (Thread)
     4. Administrivia - Status of the list (fwd) (Thread)
     5. [SJ-JOB] Security Product Manager, San Jose, US (Thread)
     6. [SJ-JOB] Security Consultant, Whitehouse Station, US (Thread)
     7. [SJ-JOB] Sales Representative, Chicago, US (Thread)
     8. [SJ-JOB] Sales Engineer, Bay Area, US (Thread)
     9. [SJ-JOB] Sales Representative, Toronto, CA (Thread)
     10. [SJ-JOB] Jr. Security Analyst, Whitehouse Station, U... (Thread)
     11. [SJ-JOB] Account Manager, San Francisco, US (Thread)
     12. [SJ-JOB] Developer, San Jose, US (Thread)
     13. [SJ-JOB] Sales Representative, Detroit, US (Thread)
     14. [SJ-JOB] Security Engineer, North Brunswick, US (Thread)
     15. [SJ-JOB] Management, Boulder, US (Thread)
     16. [SJ-JOB] Security Researcher, Boulder, US (Thread)
     17. [SJ-JOB] Developer, Boulder, US (Thread)
     18. [SJ-JOB] Application Security Engineer, Seattle, US (Thread)
     19. [SJ-JOB] Account Manager, Dallas, US (Thread)
     20. [SJ-JOB] Developer, Dallas, US (Thread)
     21. [SJ-JOB] Management, New York City, US (Thread)
     22. [SJ-JOB] Application Security Engineer, San Mateo, U... (Thread)
     23. [SJ-JOB] Security Engineer, San Mateo, US (Thread)
     24. [SJ-JOB] Security Product Marketing Manager, Souther... (Thread)
     25. [SJ-JOB] Sr. Security Engineer, Bethesda, US (Thread)
     26. [SJ-JOB] Security Product Marketing Manager, San Die... (Thread)
     27. [SJ-JOB] VP of Regional Sales, London, GB (Thread)
     28. [SJ-JOB] Director of Privacy and Security, Monroe, U... (Thread)
     29. [SJ-JOB] Sales Representative, Fort Worth, US (Thread)
     30. [SJ-JOB] Account Manager, Philadelphia, US (Thread)
     31. [SJ-JOB] Security Engineer, Austin, US (Thread)
     32. [SJ-JOB] Management, Washington, US (Thread)
     33. [SJ-JOB] Security Consultant, Ft Lee, US (Thread)
     34. [SJ-JOB] Security Consultant, Austin, US (Thread)
     35. [SJ-JOB] Sales Representative, Bay Area, US (Thread)
     36. [SJ-JOB] Sales Representative, New York, US (Thread)
     37. [SJ-JOB] Forensics Engineer, Liberty Corner 07059, U... (Thread)
     38. [SJ-JOB] Quality Assurance, Bay Area, US (Thread)
     39. [SJ-JOB] Security Consultant, London/M4 Corridor, GB (Thread)
     40. [SJ-JOB] Security Engineer, Charlotte, US (Thread)
     41. [SJ-JOB] Sales Engineer, New York, US (Thread)
     42. [SJ-JOB] Sales Representative, santa clara, US (Thread)
     43. [SJ-JOB] Security Auditor, UKwide, GB (Thread)
     44. [SJ-JOB] Security Consultant, Various, GB (Thread)
     45. [SJ-JOB] Sr. Security Engineer, Bay Area, US (Thread)
     46. [SJ-JOB] Manager, Information Security, Bay Area, US (Thread)
     47. [SJ-JOB] Channel / Business Development, Bay Area, N... (Thread)
     48. [SJ-JOB] Manager, Information Security, Houston, US (Thread)
VI. INCIDENTS LIST SUMMARY
     1. PHP injection attempt from 200.222.244.154 (Thread)
     2. SIP based attacks?? (Thread)
     3. Odd addresses on my wireless network (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. trusted solaris pen testing (Thread)
     2. Winamp - Buffer Overflow In IN_CDDA.dll [ Patch Rele... (Thread)
     3. IRFTP possible woes (Thread)
     4. More Browser on Macosx flaws: nested array sort() lo... (Thread)
     5. [Full-Disclosure] FIREFOX flaws: nested array sort()... (Thread)
     6. Black Hat CFPs now open: Europe and Asia (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. Disable Network ID and Change button (Thread)
     2. XP SP2 & GPO controlled firewall gets activated for ... (Thread)
     3. SecurityFocus Microsoft Newsletter #217 (Thread)
IX. SUN FOCUS LIST SUMMARY
     NO NEW POSTS FOR THE WEEK 2004-11-30 to 2004-12-07.
X. LINUX FOCUS LIST SUMMARY
     1. LIDS 1.2.2 for Linux kernel 2.4.28 released (Thread)
     2. which distribution to choose (Thread)
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION

I. FRONT AND CENTER
-------------------
1. Detecting Complex Viruses
By Peter Ferrie and Frederic Perriot

The purpose of this paper is to examine the difficulties of detecting
complex viruses, including polymorphic, metamorphic and entry-point
obscuring viruses. Whether or not an anti-virus (AV) technology can detect
these viruses can be a useful metric to consider when evaluating AV products.

http://www.securityfocus.com/infocus/1813


2. Lycos Goes Straight
By Mark Rasch

After a week of well-deserved criticism, Lycos is abandoning its scheme to
launch denial-of-service attacks against spammy websites. Did the company
reform in time to avoid criminal prosecution?

http://www.securityfocus.com/columnists/282


3. Closed Source Hardware
By Jason Miller

Trust with hardware vendors for open source systems is becoming a one-way
street, where in exchange for support they offer a closed source binary
solution with no provision to audit security.

http://www.securityfocus.com/columnists/281

II. BUGTRAQ SUMMARY
-------------------
1. Microsoft Internet Explorer Drag and Drop Vulnerability
BugTraq ID: 11770
Remote: Yes
Date Published: Nov 28 2004
Relevant URL: http://www.securityfocus.com/bid/11770
Summary:
A security researcher has reported a simpler variant of the vulnerability described in BID 11466.  In that vulnerability, it was theoretically possible for external and untrustworthy HTML / script code to be executed if a maliciously constructed file were "dragged and dropped" and then clicked on.  This process involved the victim user manually clicking the file to open it.  The author of this report has stated that the new variant removes the step of manually clicking the file.  This may allow for automatic compromise if the user will "drag and drop" a malicious file.

2. File ELF Header Unspecified Buffer Overflow Vulnerability
BugTraq ID: 11771
Remote: Yes
Date Published: Nov 29 2004
Relevant URL: http://www.securityfocus.com/bid/11771
Summary:
The file command is affected by a buffer overflow vulnerability.  This issue is due to a failure of the application to properly validate string lengths in the affected file prior to copying them into static process buffers.

An attacker may leverage this issue to execute arbitrary code with the privileges of a user that processes the malicious file with the affected utility.  This may be leveraged to escalate privileges or to gain unauthorized access.

3. Ipswitch WS_FTP Multiple Remote Buffer Overflow Vulnerabilit...
BugTraq ID: 11772
Remote: Yes
Date Published: Nov 29 2004
Relevant URL: http://www.securityfocus.com/bid/11772
Summary:
Multiple remote buffer overflow vulnerabilities are reported in the Ipswitch WS_FTP server.  These issues are due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into finite process buffers.

An attacker may exploit these issues to cause the affected server to crash.  It is likely that execution of arbitrary code with the privileges of the user who activated the vulnerable application is also possible.

4. Groupmax World Wide Web Cross-Site Scripting And Directory T...
BugTraq ID: 11773
Remote: Yes
Date Published: Nov 29 2004
Relevant URL: http://www.securityfocus.com/bid/11773
Summary:
It is reported that Groupmax World Wide Web is susceptible to both a cross-site scripting vulnerability and a directory traversal vulnerability. These vulnerabilities are due to a failure of the application to properly sanitize user-supplied input.

The cross-site scripting issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

The directory traversal vulnerability allows remote attackers to retrieve the contents of potentially sensitive files with the privileges of the web server. Reportedly, only files with an 'html' extension are retrievable.

Both of these vulnerabilities reportedly require attackers to successfully authenticate to the server prior to exploitation.

5. 21-6 Productions Orbz Remote Buffer Overflow Vulnerability
BugTraq ID: 11774
Remote: Yes
Date Published: Nov 29 2004
Relevant URL: http://www.securityfocus.com/bid/11774
Summary:
A remote buffer overflow vulnerability has been reported in 21-6 Productions Orbz. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into finite process buffers.

An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.

6. Mercury Mail Multiple Remote IMAP Stack Buffer Overflow Vuln...
BugTraq ID: 11775
Remote: Yes
Date Published: Nov 29 2004
Relevant URL: http://www.securityfocus.com/bid/11775
Summary:
Mercury Mail is reported susceptible to multiple stack-based buffer overflow vulnerabilities in its IMAP server implementation. These issues are due to a failure of the application to properly bounds check user-supplied input prior to copying it to a finite-sized memory buffer.

These vulnerabilities allow authenticated, remote attackers to execute arbitrary machine code in the context of the affected server process.

Versions prior to 4.01a of Mercury Mail is reportedly affected by these vulnerabilities. Other versions may also be affected.

Note: BID 11788 has been consolidated with this BID. It is determined that they actually represent the same issues.

7. GlobalScape CuteFTP Multiple Command Response Buffer Overflo...
BugTraq ID: 11776
Remote: Yes
Date Published: Nov 30 2004
Relevant URL: http://www.securityfocus.com/bid/11776
Summary:
Multiple remote buffer overflow vulnerabilities reportedly affect the command response functionality of GlobalScape CuteFTP. These issues are due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into finite process buffers.

A remote attacker may leverage these issues to cause the affected client to crash; code execution may also be possible.  Any code execution would take place with the privileges of the user that activated the vulnerable application.

8. EnergyMech IRC Bot Unspecified Buffer Overflow Vulnerability
BugTraq ID: 11777
Remote: Unknown
Date Published: Nov 30 2004
Relevant URL: http://www.securityfocus.com/bid/11777
Summary:
An unspecified buffer overflow vulnerability affects EnergyMech. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into finite process buffers.

Although the impact of this issue is currently unknown, it is likely that an attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.

9. FreeImage Interleaved Bitmap Image Buffer Overflow Vulnerabi...
BugTraq ID: 11778
Remote: Yes
Date Published: Nov 26 2004
Relevant URL: http://www.securityfocus.com/bid/11778
Summary:
A buffer overflow vulnerability exists in FreeImage.  This issue is due to a boundary condition error that is presented when the library handles malformed Interleaved Bitmap (ILBM) images.

This issue could potentially be exploited to execute arbitrary code in the context of an application that uses the library.

10. IPCop Web Administration Interface Proxy Log HTML Injection ...
BugTraq ID: 11779
Remote: Yes
Date Published: Nov 30 2004
Relevant URL: http://www.securityfocus.com/bid/11779
Summary:
IPCop is reported susceptible to an HTML injection vulnerability in its proxy log viewer. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamically generated web pages.

This vulnerability allows remote, attacker-supplied malicious HTML or script code to be displayed to administrative users. This code would be executed in the context of the affected Web application. It is conjectured that it may be possible for attackers to cause administrative actions to be executed on their behalf when an administrator views the Squid logs. Theft of cookie-based authentication credentials and other attacks are also likely.

Version 1.4.1 of IPCop is reportedly vulnerable. Other versions may also be affected.

11. JanaServer 2 Multiple Remote Denial Of Service Vulnerabiliti...
BugTraq ID: 11780
Remote: Yes
Date Published: Nov 30 2004
Relevant URL: http://www.securityfocus.com/bid/11780
Summary:
JanaServer 2 is a commercially available proxy server designed for the Microsoft Windows platform. It contains support for services such as HTTP, FTP, email, and RealPlayer streaming.

Multiple remote denial of service vulnerabilities affect JanaServer 2. These issues are due to a failure of the application to handle malformed network communications.

The first issue presents itself when malformed HTTP requests are made to the affected application.  The second issue presents itself when the application attempts to process malformed RealPlayer streaming data.

An attacker may leverage these issues to cause the affected proxy server to hang, effectively denying service to legitimate users.

12. OpenSSH-portable PAM Authentication Remote Information Discl...
BugTraq ID: 11781
Remote: Yes
Date Published: Nov 30 2004
Relevant URL: http://www.securityfocus.com/bid/11781
Summary:
It is reported that OpenSSH contains an information disclosure vulnerability. This issue exists in the portable version of OpenSSH. The portable version is the version that is distributed for operating systems other than its native OpenBSD platform.

This issue is related to BID 7467. It is reported that the previous fix for BID 7476 was insufficient to completely fix the issue. It is not confirmed at this time, but this current issue may involve differing code paths in PAM, resulting in a new vulnerability.

This vulnerability allows remote users to test for the existence of valid usernames. Knowledge of usernames may aid them in further attacks.

13. Sun Solaris Ping Local Buffer Overflow Vulnerability
BugTraq ID: 11782
Remote: No
Date Published: Dec 01 2004
Relevant URL: http://www.securityfocus.com/bid/11782
Summary:
A local buffer overflow in the ping utility affects Sun Solaris. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into finite process buffers.

An attacker may exploit this issue to execute arbitrary code with the privileges of the superuser; this will facilitate privilege escalation.

14. SuSE Linux Enterprise Server NFS Unspecified Denial Of Servi...
BugTraq ID: 11783
Remote: Yes
Date Published: Dec 01 2004
Relevant URL: http://www.securityfocus.com/bid/11783
Summary:
A remote denial of service and storage corruption vulnerability affects SuSE Linux enterprise Server.  This underlying nature of this issue is currently unknown; this BID will be updated as further details are released.

An attacker may leverage this issue to cause the affected server to crash, denying service to legitimate users.  It has also been reported that this issue may be exploited to corrupt data stored on disk.

15. SuSE Linux Kernel Unauthorized SCSI Command Vulnerability
BugTraq ID: 11784
Remote: No
Date Published: Dec 01 2004
Relevant URL: http://www.securityfocus.com/bid/11784
Summary:
SuSE Linux is reported susceptible to an unauthorized SCSI command vulnerability.

Malicious users may be able to send commands to SCSI devices that result in the overwriting of their firmware. This potentially results in the failure of the targeted device to further operate. This may result in the permanent, unrecoverable destruction of SCSI devices, requiring that they be sent to the vendor for service or replacement.

SuSE Linux 9.1, and SuSE Linux Enterprise Server 9 are reported to be vulnerable to this issue. Other versions, and other distributions of Linux are also potentially affected.

16. Linux NFS RPC.STATD Remote Denial Of Service Vulnerability
BugTraq ID: 11785
Remote: Yes
Date Published: Dec 01 2004
Relevant URL: http://www.securityfocus.com/bid/11785
Summary:
It is reported that rpc.statd is vulnerable to a remote denial of service vulnerability.

This vulnerability allows remote attackers to crash the affected application. This may result in the failure to cleanup NFS network locks, possibly resulting in denied access to files, as they may be considered permanently locked.

Verion 1.0.6 of nfs-utils is reported vulnerable to this issue. Other versions may also be affected.

17. ACPID Proxy Unspecified Local Denial Of Service Vulnerabilit...
BugTraq ID: 11786
Remote: No
Date Published: Dec 01 2004
Relevant URL: http://www.securityfocus.com/bid/11786
Summary:
An unspecified local denial of service vulnerability affected acpid_proxy.  The underlying issue causing this vulnerability is currently unknown, this BID will be updated as more details are released.

A local attacker may leverage this issue to cause the affected computer to crash, denying service to legitimate users.

18. gnubiff Multiple Remote Denial Of Service Vulnerabilities
BugTraq ID: 11787
Remote: Yes
Date Published: Dec 01 2004
Relevant URL: http://www.securityfocus.com/bid/11787
Summary:
It is reported that gnubiff contains multiple remote denial of service vulnerabilities.

gnubiff is reportedly unable to properly handle unterminated responses to certain IMAP and POP commands.

These vulnerabilities reportedly affect versions prior to 2.0.2 for cleartext connections, and versions prior to 2.0.3 for SSL connections.

19. Mercury Mail Multiple Remote IMAP Buffer Overflow Vulnerabil...
BugTraq ID: 11788
Remote: Yes
Date Published: Dec 01 2004
Relevant URL: http://www.securityfocus.com/bid/11788
Summary:
Mercury Mail is reported susceptible to multiple buffer overflow vulnerabilities in its IMAP server implementation. These issues are due to a failure of the application to properly bounds check user-supplied input prior to copying it to a finite-sized memory buffer.

These vulnerabilities allow authenticated, remote attackers to deny service to legitimate users. It is also conjectured that they may be able to execute arbitrary machine code in the context of the affected server process.

Version 4.01 of Mercury Mail is reportedly affected by these vulnerabilities. Other versions may also be affected.

Note: This BID has been consolidated to BID 11775, as it has been determined that this BID is a duplicate. This BID will be retired shortly.

20. FreeBSD Linux ProcFS Local Kernel Denial Of Service And Info...
BugTraq ID: 11789
Remote: No
Date Published: Dec 02 2004
Relevant URL: http://www.securityfocus.com/bid/11789
Summary:
A local denial of service and information disclosure vulnerability affects the procfs and linprocfs implementation on FreeBSD.  This issue is due to a design error that causes the mismanagement of memory references.

An attacker may leverage this issue to cause a kernel panic on an affected computer, denying service to legitimate users.  It is also possible to leverage this issue to disclose kernel memory, potentially facilitating access to sensitive information in kernel buffers.

21. S9Y Serendipity Remote Cross-Site Scripting Vulnerability
BugTraq ID: 11790
Remote: Yes
Date Published: Dec 02 2004
Relevant URL: http://www.securityfocus.com/bid/11790
Summary:
A cross-site scripting vulnerability affects S9Y Serendipity.  This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamically generated Web content. 

An attacker may leverage this issue to have arbitrary HTML and script code rendered and executed in the browser of an unsuspecting user.  This may facilitate theft of cookie-based authentication credentials as well as other attacks.

22. SCPOnly Remote Arbitrary Command Execution Vulnerability
BugTraq ID: 11791
Remote: Yes
Date Published: Dec 02 2004
Relevant URL: http://www.securityfocus.com/bid/11791
Summary:
scponly is reported prone to a remote arbitrary command execution vulnerability.  This issue may allow a remote attacker to execute commands and scripts on a vulnerable computer and eventually allow an attacker to gain elevated privileges on a vulnerable computer.

Versions prior to 4.0 are reported susceptible to this issue.

23. RSSH Remote Arbitrary Command Execution Vulnerability
BugTraq ID: 11792
Remote: Yes
Date Published: Dec 02 2004
Relevant URL: http://www.securityfocus.com/bid/11792
Summary:
rssh is reported prone to a remote arbitrary command execution vulnerability. This issue may allow a remote attacker to execute commands and scripts on a vulnerable computer and eventually allow an attacker to gain elevated privileges on a vulnerable computer.

All versions of rssh are considered vulnerable at the moment.

24. Cisco CNS Network Registrar DNS and DHCP Server Remote Denia...
BugTraq ID: 11793
Remote: Yes
Date Published: Dec 02 2004
Relevant URL: http://www.securityfocus.com/bid/11793
Summary:
Cisco CNS Network Registrar is a DNS/DHCP server offered by Cisco.  It is available for Microsoft Windows, UNIX, and Linux platforms.

Cisco CNS Network Registrar is reported prone to multiple remote denial of service vulnerabilities.  These issues affect the Domain Name Service and Dynamic Host Configuration Protocol server components of the CNS Network Registrar.  It is reported that an attacker may cause a crash by sending a specially crafted packet sequence to an affected server.

These vulnerabilities only affect Cisco CNS Network Registrar for the Microsoft Windows platform.  The first issue affects CNS Network Registrar versions 6.0 upto and including 6.1.1.3 and the second issue affects all versions including 6.1.1.3.

25. Linux Kernel Unspecified Local TSS Vulnerability For AMD64 A...
BugTraq ID: 11794
Remote: No
Date Published: Dec 02 2004
Relevant URL: http://www.securityfocus.com/bid/11794
Summary:
The Linux kernel is reported prone to an unspecified local TSS-related (Task State Segment) vulnerability. This vulnerability reportedly only affects the AMD64, and the EMT64T CPU architectures.

This vulnerability reportedly allows local attackers to crash the kernel, or possibly gain elevated privileges.

It is reported that Linux kernels prior to version 2.4.23 are susceptible to this vulnerability.

26. Blog Torrent Remote Directory Traversal Vulnerability
BugTraq ID: 11795
Remote: Yes
Date Published: Dec 02 2004
Relevant URL: http://www.securityfocus.com/bid/11795
Summary:
It is reported that Blog Torrent is prone to a remote directory traversal vulnerability. This issue is due to a failure of the server process to properly filter user supplied input. 

Blog Torrent preview 0.8 version is affected by this vulnerability.

27. Global Moxie Big Medium Unspecified Remote Script Code Execu...
BugTraq ID: 11796
Remote: Yes
Date Published: Dec 02 2004
Relevant URL: http://www.securityfocus.com/bid/11796
Summary:
Global Moxie Big Medium is reported prone to a remote unspecified code execution vulnerability. It is reported that this vulnerability may be exploited to allow a remote user to upload arbitrary files into the Big Medium "web" directory.

28. PHProjekt Unspecified Authentication Bypass Vulnerability
BugTraq ID: 11797
Remote: Yes
Date Published: Dec 02 2004
Relevant URL: http://www.securityfocus.com/bid/11797
Summary:
PHPProject is reported prone to an unspecified authentication bypass vulnerability. Reports indicate that the vulnerability is present in the 'setup.php' source file and may be exploited by a remote attacker to gain access to the 'setup.php' file without requiring authentication.

29. Advanced Guestbook Cross-Site Scripting Vulnerability
BugTraq ID: 11798
Remote: Yes
Date Published: Dec 02 2004
Relevant URL: http://www.securityfocus.com/bid/11798
Summary:
It is reported that Advanced Guestbook is affected by a cross-site scripting vulnerability.  This issue is due to a failure of the application to properly sanitize user-supplied URI input.

This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

This vulnerability is reported to exist in version 2.3.1 of Advanced Guestbook. Other versions may also be affected.

30. Burut Kreed Game Server Multiple Remote Vulnerabilities
BugTraq ID: 11799
Remote: Yes
Date Published: Dec 02 2004
Relevant URL: http://www.securityfocus.com/bid/11799
Summary:
Kreed game server is reported prone to multiple vulnerabilities. The following individual issues are reported:

It is reported that the game server is prone to a format string handling vulnerability. This vulnerability may potentially be exploited by a remote attacker to write to arbitrary locations in process memory potentially resulting in remote code execution.

The second reported issue, a denial of service, is reported to affect the Kreed game server. Reports indicate that when a large UDP datagram is handled, the server will crash. A remote attacker may exploit this vulnerability to deny service to legitimate users.

Finally, a denial of service is reported in the Kreed server scripts. It is reported that a malicious nickname or model type will trigger the vulnerability. A remote attacker may exploit this vulnerability to deny service to legitimate users.

31. HP HPSOCKD Unspecified Remote Buffer Overflow Vulnerability
BugTraq ID: 11800
Remote: Yes
Date Published: Dec 03 2004
Relevant URL: http://www.securityfocus.com/bid/11800
Summary:
hpsockd is reported prone to an unspecified remote buffer overflow vulnerability.  This issue exists due to improper boundary checks performed by the application when handling user-supplied data.  It is reported that this vulnerability can be exploited to cause a denial of service condition in the application.

It may be possible to leverage this issue to execute arbitrary code on a vulnerable computer, however, this has not been confirmed.  

hpsockd versions 0.5 and prior are reported prone to this vulnerability.

32. IBM AIX Multiple Local Vulnerabilities
BugTraq ID: 11801
Remote: No
Date Published: Dec 02 2004
Relevant URL: http://www.securityfocus.com/bid/11801
Summary:
IBM AIX is reported prone to multiple local vulnerabilities.  These vulnerabilities can allow an attacker to corrupt system data and cause a denial of service vulnerability.

IBM AIX 5.1, 5.2 and 5.3 are affected by these issues.

33. Apple Mac OS X Multiple Remote And Local Vulnerabilities
BugTraq ID: 11802
Remote: Yes
Date Published: Dec 03 2004
Relevant URL: http://www.securityfocus.com/bid/11802
Summary:
Multiple security vulnerabilities are reported to affect Apple Mac OS X.  These issues were disclosed in the referenced vendor advisory.

The first issue affects Apple's Apache configuration.  Apparently Apple's default Apache configuration fails to properly block access to certain files. This issue has been assigned the CVE ID CAN-2004-1083 and is resolved in the attached Apple security update.

The second issue reported in the referenced advisory affects the Apache web server on Mac OS X.  This issue arises due to a failure of the affected server to properly handle HFS+ files system file resources. This issue has been assigned the CVE ID CAN-2004-1084 and is resolved in the attached Apple security update.

The third issue affects Apple's windowing system and development kit (Appkit).  This issue will allow and attacker to capture keyboard input that is supposed to be secure. This issue has been assigned the CVE ID CAN-2004-1081 and is resolved in the attached security update.

The fourth issue surrounds the Cyrus IMAP server implementation when working with Kerberos authentication and may facilitate authentication bypass attacks.  It should be noted that this issue only affects Mac OS X Server 10.3.X and earlier. This issue has been assigned CVE ID CAN-2004-1089 and is resolved in the attached security update.

The fifth issue surrounds the HIToolBox.  It affects only Mac OS X, and Mac OS X Server 10.3.X, the 10.2.X systems are not affected.  This issue may allow an attacker to kill applications when running in kiosk mode. This issue has been assigned CVE ID CAN-2004-1085 and is resolved in the attached security update.

The sixth issue affects the Postfix functionality on Mac OS X 10.3.X desktop and server.  This issue may allow an attacker to send mail without requiring authentication. This issue has been assigned CVE ID CAN-2004-1088 and is resolved in the attached security update.

The seventh issue surrounds the PSNormalizer utilities on Mac OS X 10.3.X desktop and server.  This issue may allow an attacker to execute arbitrary code in the context of a user running a vulnerable version of the operating system. This issue has been assigned the CVE ID CAN-2004-1086 and is resolved in the attached security update.

The eighth issue affects the QuickTime Streaming Server. An attacker may leverage this issue to trigger a denial of service condition in the affected server. This issue has been assigned the CVE ID CAN-2004-1123 and is resolved in the attached security update.

Finally, a vulnerability affects Apple's Terminal application.  This issue may lead to a false sense of security as the affected application may report that the 'Secure Keyboard Entry' functionality is active when it is not. This issue has been assigned the CVE ID CAN-2004-1087 and is resolved in the attached security update.

An attacker may leverage these issues to carry out information disclosure, authentication bypass, code execution, privilege escalation, a false sense of security, and denial of service attacks.

34. Apache Jakarta Results.JSP Remote Cross-Site Scripting Vulne...
BugTraq ID: 11803
Remote: Yes
Date Published: Dec 03 2004
Relevant URL: http://www.securityfocus.com/bid/11803
Summary:
It is reported that Jakarta Lucene is affected by a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input.

This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link is followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

This vulnerability is reported to exist in version 1.4.2 and previous of Jakarta Lucene. Other versions may also be affected.

35. Computer Associates Unicenter Remote Control Remote Authenti...
BugTraq ID: 11804
Remote: Yes
Date Published: Dec 03 2004
Relevant URL: http://www.securityfocus.com/bid/11804
Summary:
It is reported that URC may allow a remote attacker to gain unauthorized access to a URC management server.  This can result in a remote attacker gaining administrative access to server.

A successful attack may allow an attacker to compromise computers that are managed by Unicenter Remote Control Enterprise.

36. Sandino Flores Moreno Gaim Festival Plug-in Remote Denial Of...
BugTraq ID: 11805
Remote: Yes
Date Published: Dec 03 2004
Relevant URL: http://www.securityfocus.com/bid/11805
Summary:
The Gaim Festival Plug-in is reported prone to a remote denial of service vulnerability. Reports indicate that the plug-in does not handle certain characters correctly and will crash if these characters are parsed from an incoming message.

A remote attacker may exploit this condition to deny service to legitimate users. Further attacks may also be possible.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Berkeley Hack Sparks Legislative Backlash
By: Kevin Poulsen

An intrusion into a university research computer housing information on 1.4 million people leads to a proposed law that would cut researchers off from sensitive data. Opponents say important work would be hobbled in the process.
http://www.securityfocus.com/news/10053

2. Hacking tool reportedly draws FBI subpoenas
By: Kevin Poulsen

Law enforcement has sought to identify some users of the Nmap freeware port scanner, the author says.
http://www.securityfocus.com/news/10011

3. Judge dismisses keylogger case
By: Kevin Poulsen

Covert use of a hardware keystroke logger does not violate federal wiretap law, court rules.
http://www.securityfocus.com/news/9978

4. Police drop investigation of roulette hackers
By: The Associated Press, The Associated Press

http://www.securityfocus.com/news/10073

5. Fake Lycos screensaver harbours Trojan
By: John Leyden, The Register

Virus writers have begun distributing their wares in emails that pose as Lycos's abandoned "Make love not spam" screensaver.
http://www.securityfocus.com/news/10070

6. High-school drop-out to become Homeland Security Czar
By: Thomas C. Greene, The Register

President George W. Bush has nominated former New York City Police Commissioner Bernard Kerik to replace Tom Ridge as Homeland Security Secretary, marking a significant departure from his tendency to choose educated, Patrician types for his Cabinet.
http://www.securityfocus.com/news/10065

IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Sherpa 0.1.8
By: Rick Crelia, [email protected]
Relevant URL: http://sherpa.lavamonkeys.com/
Platforms: Perl (any system supporting perl)
Summary: 

Sherpa is a tool for configuring and then checking system security via the console. Written in perl, it allows an admin to maintain a custom database of file and directory permissions and ownership attributes as local needs dictate. Any changes from the prescribed layout will be detected each time Sherpa is run. Also, Sherpa does some basic system checks (world-writable files, .rhosts and hosts.equiv files, etc.) that help the busy admin keep on top of a system.

2. IDS Policy Manager v1.5
By: ActiveWorx
Relevant URL: http://www.activeworx.org
Platforms: Windows 2000, Windows NT, Windows XP
Summary: 

IDS Policy Manager was designed to manage Snort IDS sensors in a distributed environment. This is done by having the ability to take the textconfiguration and rule files and allow you to modify them with an easy touse graphical interface. With the added ability to merge new rule sets,manage preprocessors, control output modules and scp rules to sensors, thistool makes managing snort easy for most security professionals.

3. PatchLink Update 6.01.78
By: PatchLink Corporation
Relevant URL: http://www.patchlink.com/products_services/plu_evaluationrequest.html
Platforms: AIX, DG-UX, Digital UNIX/Alpha, DOS, HP-UX, Java, Linux, MacOS, Net, NetBSD, Netware, OpenVMS, PalmOS, POSIX, SecureBSD, SINIX, Solaris, SunOS, True64 UN, True64 UNIX, Ultrix, UNICOS, UNIX, Unixware, Windows 2000, Windows 95/98, Windows CE, Windows NT, Windows XP
Summary: 

With PATCHLINK UPDATE, patch management is the secure, proactive, and preventative process it should be. PATCHLINK UPDATE scans networks for security holes and closes them with the click of a mouse, no matter the operating system, the vendor applications, the mix, or the size of the environment. From 5K nodes to 20+K nodes, PATCHLINK UPDATE works quickly, accurately and safely to ensure desktops and servers are patched correctly and completely the first time around.

4. Oscanner 1.0.0
By: Patrik Karlsson
Relevant URL: http://www.cqure.net/tools.jsp?id=20
Platforms: Java
Summary: 

Oscanner is an Oracle assesment framework developed in Java. It has a plugin-based architecture and comes with a couple of plugins that currently do;

  - Sid Enumeration
  - Passwords tests (common & dictionary)
  - Enumerate Oracle version
  - Enumerate account roles
  - Enumerate account priveleges
  - Enumerate account hashes
  - Enumerate audit information
  - Enumerate password policies
  - Enumerate database links

The results are given in a graphical java tree.

5. Dekart Private Disk 2.03
By: Dekart
Relevant URL: http://www.private-disk.net/
Platforms: Windows XP
Summary: 

Private Disk - is an easy-to-use, reliable, user-friendly and smart program that lets you create encrypted disk partitions (drive letters) to keep your private and confidential data secure. Uses 256-bit AES encryption.

6. Remote Process Watcher 1.0
By: Fitsec Tmi
Relevant URL: http://www.fitsec.com/downloads
Platforms: Windows 2000, Windows NT, Windows XP
Summary: 

A Java based software that watches processes running on the computers inside a domain. Gives out warnings when it spots a process that it doesn't recognize or processes that have been marked on the warning list. It is also able to autokill processes marked as critical.

V. SECURITYJOBS LIST SUMMARY
----------------------------
1. [SJ-JOB] Security Consultant, Seattle, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383495

2. [SJ-JOB] Technical Writer, San Jose, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383494

3. [SJ-JOB] Security Consultant, Any US location, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383481

4. Administrivia - Status of the list (fwd) (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383470

5. [SJ-JOB] Security Product Manager, San Jose, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383462

6. [SJ-JOB] Security Consultant, Whitehouse Station, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383451

7. [SJ-JOB] Sales Representative, Chicago, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383450

8. [SJ-JOB] Sales Engineer, Bay Area, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383445

9. [SJ-JOB] Sales Representative, Toronto, CA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383444

10. [SJ-JOB] Jr. Security Analyst, Whitehouse Station, U... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383436

11. [SJ-JOB] Account Manager, San Francisco, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383435

12. [SJ-JOB] Developer, San Jose, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383429

13. [SJ-JOB] Sales Representative, Detroit, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383427

14. [SJ-JOB] Security Engineer, North Brunswick, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383426

15. [SJ-JOB] Management, Boulder, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383421

16. [SJ-JOB] Security Researcher, Boulder, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383416

17. [SJ-JOB] Developer, Boulder, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383408

18. [SJ-JOB] Application Security Engineer, Seattle, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383407

19. [SJ-JOB] Account Manager, Dallas, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383224

20. [SJ-JOB] Developer, Dallas, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383222

21. [SJ-JOB] Management, New York City, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383221

22. [SJ-JOB] Application Security Engineer, San Mateo, U... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383220

23. [SJ-JOB] Security Engineer, San Mateo, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383219

24. [SJ-JOB] Security Product Marketing Manager, Souther... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383218

25. [SJ-JOB] Sr. Security Engineer, Bethesda, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383217

26. [SJ-JOB] Security Product Marketing Manager, San Die... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383216

27. [SJ-JOB] VP of Regional Sales, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/383068

28. [SJ-JOB] Director of Privacy and Security, Monroe, U... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382955

29. [SJ-JOB] Sales Representative, Fort Worth, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382953

30. [SJ-JOB] Account Manager, Philadelphia, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382948

31. [SJ-JOB] Security Engineer, Austin, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382945

32. [SJ-JOB] Management, Washington, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382944

33. [SJ-JOB] Security Consultant, Ft Lee, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382943

34. [SJ-JOB] Security Consultant, Austin, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382771

35. [SJ-JOB] Sales Representative, Bay Area, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382770

36. [SJ-JOB] Sales Representative, New York, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382768

37. [SJ-JOB] Forensics Engineer, Liberty Corner 07059, U... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382765

38. [SJ-JOB] Quality Assurance, Bay Area, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382764

39. [SJ-JOB] Security Consultant, London/M4 Corridor, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382762

40. [SJ-JOB] Security Engineer, Charlotte, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382761

41. [SJ-JOB] Sales Engineer, New York, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382758

42. [SJ-JOB] Sales Representative, santa clara, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382757

43. [SJ-JOB] Security Auditor, UKwide, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382755

44. [SJ-JOB] Security Consultant, Various, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382754

45. [SJ-JOB] Sr. Security Engineer, Bay Area, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382753

46. [SJ-JOB] Manager, Information Security, Bay Area, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382752

47. [SJ-JOB] Channel / Business Development, Bay Area, N... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382751

48. [SJ-JOB] Manager, Information Security, Houston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/382748

VI. INCIDENTS LIST SUMMARY
--------------------------
1. PHP injection attempt from 200.222.244.154 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/383453

2. SIP based attacks?? (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/383253

3. Odd addresses on my wireless network (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/382925

VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. trusted solaris pen testing (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/383497

2. Winamp - Buffer Overflow In IN_CDDA.dll [ Patch Rele... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/383467

3. IRFTP possible woes (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/383192

4. More Browser on Macosx flaws: nested array sort() lo... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/383132

5. [Full-Disclosure] FIREFOX flaws: nested array sort()... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/383037

6. Black Hat CFPs now open: Europe and Asia (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/383033

VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. Disable Network ID and Change button (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/383559

2. XP SP2 & GPO controlled firewall gets activated for ... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/383417

3. SecurityFocus Microsoft Newsletter #217 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/382844

IX. SUN FOCUS LIST SUMMARY
--------------------------
NO NEW POSTS FOR THE WEEK 2004-11-30 to 2004-12-07.

X. LINUX FOCUS LIST SUMMARY
---------------------------
1. LIDS 1.2.2 for Linux kernel 2.4.28 released (Thread)
Relevant URL:

http://www.securityfocus.com/archive/91/383376

2. which distribution to choose (Thread)
Relevant URL:

http://www.securityfocus.com/archive/91/383368

XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.
    
XII. SPONSOR INFORMATION
-----------------------

This Issue is Sponsored By: RSA

RSA Conference 2005
The RSA Conference is the most prestigious information security event of
the year!  This is the authoritative source for uncovering new ways to
thwart cyber-criminals.  Learn.  Network.  Grow.  RSA Conference 2005 takes
place February 14 to 18, 2005 in San Francisco.  Register before January
15, 2005 and save $500 off the Full Conference rate.

http://www.securityfocus.com/sponsor/RSA_sf-news_041207

------------------------------------------------------------------------

Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041130

------------------------------------------------------------------------