SecurityFocus Newsletter #151

John Boletta <[email protected]> Mon, 1 Jul 2002 11:50:31 -0600 (MDT)
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #151
--------------------------------

This newsletter is sponsored by: SecurityFocus DeepSight Threat Management
System

From June 24th - August 31st, 2002, SecurityFocus announces a FREE
two-week trial of the DeepSight Threat Management System: the only early
warning system providing customizable and comprehensive early warning of
cyber attacks and bulletproof countermeasures to prevent attacks before
they hit your network.

With the DeepSight Threat Management System, you can focus on proactively
deploying prioritized and specific patches to protect your systems from
attacks, rather than reactively searching dozens of Web sites or hundreds
of emails frantically trying to gather information on the attack and how
to recover from it.

Sign up today!

http://www.securityfocus.com/corporate/products/promo/tmstrial-sf.shtml

-------------------------------------------------------------------------------


I. FRONT AND CENTER
     1. Black Hat Briefings & Training
     2. Filtering E-Mail with Postfix and Procmail, Part Two
     3. No Stone Unturned, Part Five
     4. Irresponsible Disclosure
     5. The Domestic Spying Renaissance
II. BUGTRAQ SUMMARY
     1. Mod_SSL Off-By-One HTAccess Buffer Overflow Vulnerability
     2. Sun Solaris RCP Command Line Argument Buffer Overflow...
     3. Working Resources BadBlue EXT.DLL Cross Site Scripting...
     4. SalesCart Shop.MDB Customer Database Disclosure Vulnerability
     5. HP CIFSLogin Buffer Overflow Vulnerability
     6. BEA Systems WebLogic Access Controls Bypass Vulnerability
     7. PHPSquidPass Index.PHP Unauthorized User Deletion Vulnerability
     8. SGI NetVisualyzer Arbitrary File Write Vulnerability
     9. ht://Dig htsearch Cross Site Scripting Vulnerability
     10. OpenSSH Challenge-Response Buffer Overflow Vulnerabilities
     11. Microsoft Internet Explorer CLASSID Denial of Service
     12. Caucho Technology Resin Server Example Servlet Path Disclosure...
     13. Novell Netware DHCP Server Denial of Service Vulnerablity
     14. Novell Netware NWFTPD Username Format String Vulnerability
     15. Multiple Vendor BSD libc DNS Lookup Buffer Overflow Vulnerability
     16. YaBB Invalid Topic Error Page Cross Site Scripting Vulnerability
     17. Pirch IRC Client Malformed Link Denial of Service Vulnerability
     18. GameCheats Advanced Web Server Malformed HTTP Request Denial...
     19. DPGS Form Field Input Validation Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
     1. Yaha Worm Takes Out Pakistan Government's Site
     2. Mitnick Testifies Against Sprint in Vice Hack Case
     3. GamesSpy and KaZaA infected by viruses
     4. MS Media Player gives up your box
     5. OpenSSH hits the fan
IV.SECURITYFOCUS TOP 6 TOOLS
     1. Toolkit for OpenSSH Key Administration v0.5 beta
     2. XLNT Procguard v1.0
     3. CanIt v1.2
     4. CRM v20020626
     5. The SpamBouncer v1.5-Jun22
     6. nstalker-chunked.c v1.0b
V. SECURITYJOBS LIST SUMMARY
     1. Full-time position - Delivery Manager/Managing Consultant (Thread)
     2. Security Application Deployment Consultant - New York (Thread)
     3. Recruiting "AVP Security Infrastructure" - HCA - Nashville, TN
     4. Can I get a Cleared IPD Exploitation Analyst in Columbia, MD?
     5. AVP Security Infrastructure - HCA - Nashville, TN (Thread)
     6. Security Sales Position in Maryland (Thread)
     7. UK based Entrust PKI 3rd Line Support Technician (Thread)
     8. We are hiring Sr. System Engineers and Sales people (Thread)
     9. checkpoint engineer needed ASAP (Thread)
     10. Availability of Security Analyst MCSE/CSA w/Five Years Experience
     11. Network/UNIX security consultant available for telecommuting
     12. Network Security Manager Position in Chicago (Thread)
     13. Sr. Security Architect Position in Florida Available (Thread)
     14. Wireless Security Consultant Needed (Thread)
VI. INCIDENTS LIST SUMMARY
     1. Fw: spoofed packets to RFC 1918 addresses (Thread)
     2. Apache goes berserk (Thread)
     3. win2k server issue (Thread)
     4. Ending a few arguments with one simple attachment. (Thread)
     5. spoofed packets to RFC 1918 addresses (Thread)
     6. Am i compromised? (Thread)
     7. Fw: [PHP-DEV] Fw: PHP content-disposition vuln (Thread)
     8. PHP content-disposition vuln (Thread)
     9. Someone looking for CodeRed infected boxes ? (Thread)
     10. URGENT! gamespy download infected with Nimda (Thread)
     11. Dead Thread - Backdoor (Thread)
     12. UAAC Protocol ? (Thread)
     13. Unusual proxy port scan (Thread)
     14. [incidents]  backdoor (Thread)
     15. backdoor (Thread)
     16. zero tcp offset  packets sent to a honeypot (Thread)
     17. Broken mailservers (Thread)
     18. Honeynet Project - The Reverse Challenge (Thread)
     19. ZOMBIES_HTTP_GET (Thread)
     20. SQL port probe repeats (Thread)
     21. port 32814 (Thread)
     22. Worm1800.exe on UnderNet (Thread)
     23. Analyse Worm18000 (Thread)
     24. ICMP type 12 packets (Thread)
     25. FollowUp: Worm1800.exe on UnderNet? (Thread)
     26. Worm1800.exe on UnderNet? (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. DoS_Browser (Thread)
     2. Noguska Nola 1.1.1 [ Intranet Business Management Software ]
     3. Java and buffer overflows (Thread)
     4. Remote buffer overflow in resolver code of libc (Thread)
     5. csh/tcsh vulnerability (Thread)
     6. Cluestick Advisory #001 (Thread)
     7. JNI and buffer overflows (was java and buffer overflows) (Thread)
     8. Cluestick Advisory #000 (Thread)
     9. OpenSSH Vulns (new?) Priv seperation (Thread)
     10. Apache vulnerability checking (Thread)
     11. VS: Apache vulnerability checking (Thread)
     12. OpenSSH advisory (Thread)
     13. Windows .lnk Files (Thread)
     14. Another flaw in Apache? (Thread)
     15. Apache chunked encoding and Solaris/Sparc (Thread)
     16. (Fwd)  Java and buffer overflows (Thread)
     17. login yahoogroups. (Thread)
     18. spying (deleted) file entries in other users' directories
     19. Apache Exploit (Thread)
     20. Formatstring Vulnerability in decfingerd 0.7 (Thread)
     21. Re[2]: Apache Exploit (Thread)
     22. [BUGTRAQ] : ZyXEL 642R(-11) AJ.6 SYN-ACK, SYN-FIN DoS (Thread)
     23. Added Speakers !, Homeland Outlook Conf, - USCG, NGB, FEMA, OSD,
     24. solaris 9 sparc rcp (Thread)
     25. Apache Worm? (Thread)
     26. Cyberguard 4.3 smtp proxy? (Thread)
     27. apache chunked encoding (Thread)
     28. procmail heap overflow (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. secedit.sdb behavior in W2K (Thread)
     2. SecurityFocus Microsoft Newsletter #92 (Thread)
     3. Null session and Exchange2K (Thread)
     4. Locking Down Windows 2000 Workstation (Thread)
     5. Microsoft Software Update Services (Thread)
IX. SUN FOCUS LIST SUMMARY
     1. Solaris 8 username contingency (Thread)
     2. "Sun SSH" vulnerable to OpenSSH 2.9.9-3.3 exploit ? (Thread)
     3. Solaris 9 SSH: HostbasedAuthentication? (Thread)
     4. Sunscreen 3.2 + Solaris8? (Thread)
X. LINUX FOCUS LIST SUMMARY
     1. Have I been kitted? (Thread)
XI. SPONSOR INFORMATION



I. FRONT AND CENTER
-------------------
1. Black Hat Briefings & Training

Attend Black Hat Briefings & Training, July 29 - August 1, Las Vegas, the
world's premier technical security event! 8 tracks, 12 training sessions,
Richard Clarke keynote, 1500 delegates from 30 nations, with a near cult
following of both CSOs and "underground" security experts.  See for
yourself what the buzz is all about.

Visit us at: http://www.blackhat.com

2. Filtering E-Mail with Postfix and Procmail, Part Two
By Brian Hatch

This article is the second of three articles that will help systems
administrators configure SMTP daemons and local mail delivery agents to
filter out unwanted e-mails before they arrive in the end-users' in-box.
In this part, we will look at sender/recipient restrictions, restriction
ordering, and map file naming conventions before moving on to Procmail in
the final article.

http://online.securityfocus.com/infocus/1598

3. No Stone Unturned, Part Five
by H. Carvey

This is the fifth and final installment of a five-part series describing
the (mis)adventures of a sysadmin named Eliot and his haphazard journey in
discovering "The Way" of incident response. As we left off last time,
Eliot had started putting together a toolkit to help with incident
response and analysis. He had had an opportunity to give the kit a quick
test and had been satisfied with the results, but the toolkit was not
quite finished.

http://online.securityfocus.com/infocus/1597

4. Irresponsible Disclosure
By Jon Lasser

Internet Security Systems violated community standards and common sense
with its surprise Apache bug announcement.

http://online.securityfocus.com/columnists/91

5. The Domestic Spying Renaissance
By Mark Rasch

Earlier this month, Attorney General Ashcroft announced that he was
essentially removing the shackles from the FBI, and permitting agents to
engage in surveillance -- including certain Internet surveillance -- of
political, social or ethnic groups, without either probable cause or
reasonable suspicion that any of these groups had been or were likely to
be engaged in any form of criminal activity.

http://online.securityfocus.com/columnists/90


II. BUGTRAQ SUMMARY
-------------------
1. Mod_SSL Off-By-One HTAccess Buffer Overflow Vulnerability
BugTraq ID: 5084
Remote: No
Date Published: Jun 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5084
Summary:

mod_ssl is a freely available, open source cryptography package designed
for the Apache Web Server.  It is available for the Unix and Linux
operating systems.

A problem with mod_ssl may make it possible to execute code on a
vulnerable web server with the privileges of the HTTP user.

An off-by-one issue exists in mod_ssl that affects Apache when handling
certain types of long entries in an .htaccess file.  Though this
capability within the web server is not enabled by default, it is popular
as it allows non-privileged users to create web access control schemes for
hosted sites, and is enabled through the "AllowOverride" configuration
variable in Apache.  A .htaccess file with 10000 or more bytes set into
the variable DATE_LOCALE will result in a buffer overflow within the web
server process handling the request.

This is an exploitable buffer overflow.  In the event that for a user is
able to upload or create a malicious .htaccess file, it would be possible
to execute code with the privileges of the HTTP server child process
handling the request.  This could make it possible for a user to gain
access to a shell in an environment where the user isn't authorized
regular shell access, or execute code to perform other actions as the HTTP
user.

It should be noted that Apache 1.3.26 servers compiled without the mod_ssl
package are not vulnerable to this issue.  Additionally, systems that have
an installed version of mod_ssl compiled without backward compatibility
enabled are also not vulnerable.  The default compilation of mod_ssl
enables backwards compatibility.

2. Sun Solaris RCP Command Line Argument Buffer Overflow Vulnerability
BugTraq ID: 5085
Remote: No
Date Published: Jun 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5085
Summary:

Solaris 9 is the freely available Unix operating system distributed by Sun
Microsystems.

A problem in Solaris 9 may make it possible for a local user to gain
elevated privileges.  The problem is in the rcp program.

rcp is the remote file copy program.  It is designed to allow the copying
of files from one system to another across a TCP/IP network.  It is also
designed to be syntactically similar to the cp program, and uses port
514/TCP on the server side of the connection.

It has been reported that a memory corruption issue exists in rcp.  By
executing rcp on a local system with excessively long command-line
arguments, a user may produce a segmentation fault.  An attacker must
execute rcp with 10000 bytes in each of the fields for the file name,
destination host name, and destination file.

This is potentially an exploitable buffer overflow.  In the case of an
exploitable buffer overflow, it may be possible for a local attacker to
execute arbitrary code.  As the rcp program is setuid root, an attacker
may be able to execute code with administrative privileges.

3. Working Resources BadBlue EXT.DLL Cross Site Scripting Vulnerability
BugTraq ID: 5086
Remote: Yes
Date Published: Jun 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5086
Summary:

BadBlue is a P2P file sharing application distributed by Working
Resources.  It is designed for use on Microsoft Windows operating systems.

A problem with the application could make it possible to launch a
cross-site scripting attack.

When started, BadBlue launches a web server on a client system.  When a
user executes a search using the search interface provided with BadBlue,
the ext.dll library is used by BadBlue to handle the request.  This
interface may be reached by users of the local system, as well as remote
users.

The ext.dll library does not sufficiently sanitize input.  Because of
this, it is possible for a user to create a custom URL containing script
code that, when viewed in a browser by another user, will result in the
execution of the script code.  This could allow for the execution of
malicious javascript in the context of a trusted site.

This problem makes it possible to execute javascript in the context of an
arbitrary BadBlue server.

4. SalesCart Shop.MDB Customer Database Disclosure Vulnerability
BugTraq ID: 5087
Remote: Yes
Date Published: Jun 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5087
Summary:

SalesCart is an E-Commerce package designed to integrate Microsoft
FrontPage with an online shopping cart system.  It is available for
Microsoft operating systems.

A problem with SalesCart could lead to the disclosure of sensitive
information.

SalesCart does not sufficiently secure customer information.  When a user
accesses the site and enters personal information, the data is stored in
the shop.mdb file.  This file may be accessed by remote users.

This problem could result in a disclosure of sensitive information, such
as name, company name, address, e-mail address, phone number, and credit
card number.  This data has been discovered to be stored in the following
locations accessible from the web:

http://www.example.com/fpdb/shop.mdb
http://www.example.com/shoponline/fpdb/shop.mdb

5. HP CIFSLogin Buffer Overflow Vulnerability
BugTraq ID: 5088
Remote: No
Date Published: Jun 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5088
Summary:

CIFS/9000 client is the HP implementation of the Samba file sharing
software based upon a modified version of Sharity.  This product enables
HP-UX users to mount shares from Windows servers using the Common Internet
File System (CIFS) protocol.  It is distributed and maintained by HP.

A vulnerability has been reported in the /opt/cifsclient/bin/cifslogin
utility distributed with CIFS/9000. The utility is prone to several buffer
overflow conditions and may lead to root compromise.

The vulnerability occurs due to the lack of bounds checking when accepting
user input for various commandline options. Specifically, the utility
fails to check for excessively long arguments to the following commandline
options: '-U', '-D', '-P', '-S', '-N', and '-u'.

A local user may overflow the buffers by providing cifslogin with
excessively long arguments to the above commandline options which may
result in the overwriting of stack memory, and the potential execution of
attacker supplied instructions. Since cifslogin is setuid root,
exploitation of this issue may result in execution of arbitrary
attacker-supplied instructions as root.

6. BEA Systems WebLogic Access Controls Bypass Vulnerability
BugTraq ID: 5089
Remote: Yes
Date Published: Jun 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5089
Summary:

BEA Systems WebLogic Server is a web and wireless application server for
Microsoft Windows and most Unix and Linux distributions.

A vulnerability has been announced in WebLogic. A remote attacker may
bypass access control measures, and view restricted resources. This may be
accomplished by submitting a maliciously constructed URL for the resource
in question to the WebLogic server.

Access control measures may be bypassed if the URL requested contains
multiple forward slashes (/) immediately before the protected resource.
Exploitation of this vulnerability may allow a remote attacker access to
sensitive JSP or servlet pages.

7. PHPSquidPass Index.PHP Unauthorized User Deletion Vulnerability
BugTraq ID: 5090
Remote: Yes
Date Published: Jun 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5090
Summary:

phpSquidPass is a tool designed for users to change user authentication
files for the squid web proxy. It is implemented in PHP and should be
available for use with Unix and Linux variants as well as Microsoft
Windows operating environments.

phpSquidPass may allow a malicious user of the system to overwrite
additional accounts. When a password is updated, the proxy_users file is
searched for the provided username, and that account is updated. Due to an
error in the program, usernames ending with the supplied username will
also be modified. In this case, both the username and password are
overwritten.

This effectively deletes the additional account. A malicious user may be
able to take advantage of this vulnerability to create a denial of service
condition for other users of the system. The ability to exploit this
vulnerability is, however, dependant on the possession of a valid user
account which is a substring of another username.

8. SGI NetVisualyzer Arbitrary File Write Vulnerability
BugTraq ID: 5092
Remote: No
Date Published: Jun 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5092
Summary:

A vulnerability has been reported in NetVisualyzer Data Station Software
for IRIX. It may be possible for a local attacker to exploit the nveventd
binary in order to write data to arbitrary system files. nveventd is
installed suid root by default.

It may be possible to exploit this vulnerability to create a denial of
service condition by corrupting sensitive system configuration files or
binaries. It may additionally be possible to gain elevated privileges on
the system by, for example, appending attacker specified data to
/etc/passwd, or by trojaning additional system binaries.

The vulnerable binary is installed as part of the option NetVisualyzer
package, and is not installed by default with IRIX.

Full technical details and consequences of exploitation are not currently
available.

9. ht://Dig htsearch Cross Site Scripting Vulnerability
BugTraq ID: 5091
Remote: Yes
Date Published: Jun 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5091
Summary:

ht://Dig is a freely available, open source search engine. It is developed
and maintained by the ht://Dig project, and functions on the Unix and
Linux operating systems.

When a user submits a search request using ht://Dig, the htsearch CGI
program executes. It is possible for an attacker to create a custom URL to
htsearch.cgi which contains malicious script code. User supplied input is
not sufficiently sanitized by ht://Dig before being included in the
generated page. If such a URL is viewed by a user, the script code will
execute within the context of the vulnerable site.

Successful exploitation of this vulnerability could enable an attacker to
execute code in the security context of a trusted site. This vulnerability
may be exploited to steal cookie-based authentication credentials from
legitimate users.

10. OpenSSH Challenge-Response Buffer Overflow Vulnerabilities
BugTraq ID: 5093
Remote: Yes
Date Published: Jun 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5093
Summary:

The OpenSSH team has reported that vulnerabilities exist in OpenSSH.  The
vulnerabilities are remotely exploitable and may allow for unauthenticated
attackers to obtain root privileges.

The conditions are related to the OpenSSH SSH2 challenge-response
mechanism.  They are present when the OpenSSH server is configured at
compile-time to support BSD_AUTH or SKEY.  OpenBSD 3.0 and later ship with
OpenSSH built to support BSD_AUTH.  Systems are vulnerable when either of
the following configuration options are enabled:

PAMAuthenticationViaKbdInt

ChallengeResponseAuthentication

It is possible for attackers to exploit the vulnerabilities by
constructing a malicious response.  As this occurs before the
authentication process completes, it may be exploited by remote attackers
without valid credentials.  Successful exploitation may result in the
execution of shellcode or a denial of service.

OpenSSH 3.4 has been released.  Upgrading to this version will eliminate
the vulnerability.  If this is not possible, administrators should upgrade
to version 3.3 and enable the privilege separation feature.

Privilege separation may be enabled by modifying the sshd configuration
file, found at (on many systems, configuration may differ):

/etc/ssh/sshd_config

The configuration option 'UsePrivilegeSeparation' should be set to 'Yes':

UsePrivilegeSeparation yes

Once this is done, the file should be saved and the service should be
restarted completely.

Administrators of systems using OpenSSH versions prior to 3.3 are urged to
upgrade immediately and follow the instructions listed above.  If
privilege separation does not work or the version of OpenSSH cannot be
upgraded, the following workaround is prescribed:

disable ChallengeResponseAuthentication in sshd_config.

and

disable PAMAuthenticationViaKbdInt in sshd_config.

Note: It has been reported that hackers may be developing, or have
functional exploit code.  Users are advised to upgrade immediately.

11. Microsoft Internet Explorer CLASSID Denial of Service Vulnerability
BugTraq ID: 5094
Remote: Yes
Date Published: Jun 25 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5094
Summary:

Microsoft Internet Explorer contains a vulnerability that may allow for
malicious webmasters to cause a visitor's web browser to stop responding.

A CLASSID is a unique identifier that provides information to the default
COM handler. It is possible to include a CLASSID value as part of an
OBJECT tag under some versions of Internet Explorer.

If a web page contains a specific CLASSID value and an IE user attempts to
view the page, IE has been reported to crash. The reported offending
CLASSID is CLSID:00022613-0000-0000-C000-000000000046, however there may
be other CLASSID values which could exploit this issue.

This issue has been reported to occur when vulnerable versions of Internet
Explorer are running under Windows 2000 or XP. It is not currently known
if this issue is related to properties of the underlying operating system.

A restart of the browser may be required in order to regain normal
functionality.

12. Caucho Technology Resin Server Example Servlet Path Disclosure Vulnerability
BugTraq ID: 5095
Remote: Yes
Date Published: Jun 25 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5095
Summary:

A vulnerability has been reported in Resin Server, deployed on a Microsoft
Windows platform, that may allow remote attackers to view sensitive path
information.

Caucho Technology's Resin ships with a number of java servlets which may
reveal sensitive path information. Submitting a HTTP request for some
servlets, will return a page revealing the absolute path to the servlet
installation. This behavior has been reported in the HelloServlet servlet,
included in the examples directory.

This information will give the attacker filesystem structure information
of the host running Resin. Disclosure of this type of sensitive
information may aid in further attacks against the host running the
vulnerable software.

This issue has been reported in Resin 2.0.5 - 2.1.2.

13. Novell Netware DHCP Server Denial of Service Vulnerablity
BugTraq ID: 5097
Remote: Yes
Date Published: Jun 25 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5097
Summary:

An issue has been reported in the DHCP (Dynamic Host Configuration
Protocol) server included with some versions of Novell Netware.
Reportedly, it is possible to cause the Netware server to reboot.

This may be accomplished by sending the server a single, malformed DHCP
request. Further technical details for this vulnerability are not
currently available.

Exploitation of this issue may disrupt other services provided by the
Netware server, leading to a denial of service condition. Repeated
exploitation may effectively block all service to legitimate users for the
duration of the attack.

This issue has been reported in Novell Netware 6.0 SP1. Other versions of
Netware may share this vulnerability, this has not however been confirmed.

14. Novell Netware NWFTPD Username Format String Vulnerability
BugTraq ID: 5099
Remote: Yes
Date Published: Jun 25 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5099
Summary:

Netware is a commercially available operating system distributed by
Novell.

A problem with NWFTPD could make it possible for users to deny service to
legitimate users of the service.

Under some circumstances, it may be possible to remotely crash a NWFTPD
server.  NWFTPD reacts unpredictably when it receives format strings in
the form of usernames.  This could ultimately result in users of the FTP
server being unable to access data stored on the server.

It is unknown whether this format string vulnerability could be exploited
to gain elevated privileges.  In the event of an exploitable format
string, an attacker could take advantage of this vulnerability to execute
arbitrary code.  This code would be executed with the privileges of the
NWFTPD server, and could result in an attacker gaining remote access to
the system with comparable privileges.  This problem may affect previous
versions of the software.

15. Multiple Vendor BSD libc DNS Lookup Buffer Overflow Vulnerability
BugTraq ID: 5100
Remote: Yes
Date Published: Jun 26 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5100
Summary:

The libc library includes functions which perform DNS lookups. A buffer
overflow vulnerability has been reported in versions of libc used by some
operating systems. In particular, FreeBSD, NetBSD and OpenBSD have been
reported to suffer from this issue.

The vulnerable code is related to DNS queries. Under some conditions, a
buffer size is miscalculated when message padding is not taken into
consideration. Subsequent parsing of related DNS messages may result in
this buffer being overrun, corrupting adjacent memory.

In particular, it has been reported possible for this error to be
triggered through usage of the gethostbyname() function. In this case, it
may be possible for a malicious DNS server to provide a response which
will exploit this condition. Other libc functions may trigger this
vulnerability under some conditions. The names of vulnerable functions may
vary between distributions.

The consequences of this vulnerability will be highly dependant on the
details of individual applications using libc. It is likely that
exploitation will allow a malicious DNS server to execute arbitrary code
as the vulnerable process. Under some conditions, this may grant an
attacker local access, possibly as a privileged user.

This vulnerability has been reported in recent versions of FreeBSD, NetBSD
and OpenBSD. It is likely that earlier versions share this vulnerability.

CERT/CC has reported that vulnerable code exists in the libbind library
included with BIND 4 and BIND 8. It is not, however, believed that the
BIND named daemon utilizes the vulnerable functions.

16. YaBB Invalid Topic Error Page Cross Site Scripting Vulnerability
BugTraq ID: 5078
Remote: Yes
Date Published: Jun 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5078
Summary:

YaBB (Yet Another Bulletin Board) is freely available web forum software
that is written in Perl. YaBB will run on most Unix/Linux variants, MacOS,
and Microsoft Windows 9x/ME/NT/2000/XP platforms.

It is possible for attackers to construct a URL that will cause scripting
code to be embedded in error pages.

YaBB fails to check URLs for the presence of script commands when
generating error pages, allowing attacker supplied code to execute. As a
result, when an innocent user follows such a link, the script code will
execute within the context of the hosted site.

Successful exploitation of this vulnerability could enable an attacker to
execute code in the security context of a trusted site. This vulnerability
may be exploited to steal cookie-based authentication credentials from
legitimate users of YaBB.

It should be noted that this issue was tested on YaBB 1 Gold SP1, other
versions may also be affected by this issue.

17. Pirch IRC Client Malformed Link Denial of Service Vulnerability
BugTraq ID: 5079
Remote: Yes
Date Published: Jun 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5079
Summary:

Pirch IRC is an internet relay chat client designed for Microsoft Windows
environments. Pirch is subject to a denial of service.

Reportedly, this issue results due to the way Pirch handles malformed
links.

If a link containing arbitrary data is sent to an IRC user using Pirch,
upon accessing the link, it is possible that the client will stop
responding. This issue may be the result of an unchecked buffer. If this
is the case, there is a possibility that arbitrary code may be executed on
the vulnerable target. However, this has not yet been confirmed.

It should be noted that malicious links used to exploit this issue could
be links to other IRC channels, websites etc.

In addition, this condition has been reported to arise when links with a
large number of elements are processed. For example, a long sequence of
channel names may be transmitted in a channel, or as part of a private
conversation. Further technical details are not available at this time.

This issue was reported to exist in Pirch 98, earlier versions may also be
susceptible to this issue.

18. GameCheats Advanced Web Server Malformed HTTP Request Denial Of Service Vulnerability
BugTraq ID: 5080
Remote: Yes
Date Published: Jun 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5080
Summary:

Advanced Web Server Professional is a web server developed by GameCheats.
It is freely available for use on the Microsoft Windows operating
environment.

Reportedly, version 1.030000 of the web server is prone to a denial of
service condition when servicing malformed requests. The vulnerability
occurs when various invalid HTTP requests are made to the web server.

A remote attacker needs to make approximately 100 invalid HTTP requests to
the web server. This will exhaust all available threads for Tomcat leading
to the denial of service condition.

Reportedly, requests consisting of only a single carriage return / line
feed sequence are sufficient to exploit this vulnerability.

An attacker may take advantage of this vulnerability to deny service to
legitimate users.

19. DPGS Form Field Input Validation Vulnerability
BugTraq ID: 5081
Remote: Yes
Date Published: Jun 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5081
Summary:

Duma Photo Gallery System (DPGS) is web-based software for managing
photographs.  It is written in Perl and will run on most Unix and Linux
variants as well as Microsoft Windows operating systems.

DPGS does not sufficiently validate form field input.  Specifically, this
vulnerability is due to insufficient filtering of input supplied to the
Perl open() function.  This may allow remote attackers to disclose the
contents of arbitrary web-readable files via directory traversals.
Requesting a web-readable file by supplying a relative path to the file
using dot-dot-slash sequences (../) is all that is required to exploit
this issue.

It has also been reported that this lack of sufficient input validation
may also be exploited to overwrite any files which are writeable by the
webserver process.  This is due to insufficient filtering of null
characters (\0) from the same form fields that are affected by the file
disclosure issue.

Exploitation of this vulnerability may be extended to affect arbitrary
system files on some webservers running under Microsoft Windows, if the
webserver is run with SYSTEM privileges.

It should be noted that DPGS is no longer being maintained, so a
vendor-supplied fix is unlikely.


III. SECURITYFOCUS NEWS AND COMMENTARY
--------------------------------------
1. Yaha Worm Takes Out Pakistan Government's Site
By  Brian McWilliams

Virus uses victim computers as denial-of-service agents, and tries to
recruit Indian hackers into a cross-border cyber war ...

http://online.securityfocus.com/news/501

2. Mitnick Testifies Against Sprint in Vice Hack Case
By  Kevin Poulsen

The ex-hacker details his past control of Las Vegas' telecom network, and
raids his old storage locker to produce the evidence.

http://online.securityfocus.com/news/497

3. GamesSpy and KaZaA infected by viruses
By John Leyden, The Register

Nimda has found its way onto online gaming site GameSpy.com. In an email
to users, GameSpy admitted that its GameSpy Arcade Installer had become
infected with the Nimda-E virus. It has now replaced the infected file
with a virus-free version of the installer.

http://online.securityfocus.com/news/506

4. MS Media Player gives up your box
By Thomas C. Greene, The Register

If there's one thing that occasionally tempts me to miss Windows, it's the
mediocre multimedia support in Linux. But then again, my media player
doesn't allow remote attackers to own my box. It's a trade-off, I'll
allow.

http://online.securityfocus.com/news/505

5. OpenSSH hits the fan
By John Leyden, The Register

A serious vulnerability in default installation of OpenSSH on the OpenBSD
operating system has come to light. A vulnerability exists within the
"challenge-response" authentication mechanism in the OpenSSH daemon
(sshd), according to an alert issued today by Internet Security Systems.

http://online.securityfocus.com/news/503


IV.SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Toolkit for OpenSSH Key Administration v0.5 beta
by Gianugo Rabellino
Relevant URL:
http://toska.sourceforge.net
Platforms: Os Independent
Summary:

TOSKA (Toolkit for OpenSSH Key Administration) provides a way for network
administrators to centralize their SSH key management. It can manage a
database of public keys via a GUI (and an upcoming command line
interface), dynamically enabling on a per-key, per-user, and per-host
basis.

2. XLNT Procguard v1.0
by Adrianus Warmenhoven
Relevant URL:
http://www.xlnt-software.com/procguard_dl.html
Platforms: FreeBSD, Linux, Solaris
Summary:

XLNT Procguard monitors a basic Unix daemon. It uses the fastest timer
available and restarts the daemon if it dies. It can join a running daemon
or it can be used in a startup script.

3. CanIt v1.2
by David F. Skoll
Relevant URL:
http://www.roaringpenguin.com/mimedefang/canit/
Platforms: POSIX, UNIX
Summary:

CanIt is a server-based spam-control system built around SpamAssassin,
MIMEDefang, Apache, and PostgreSQL. It features sophisticated
spam-handling techniques which minimize the amount of spam you receive
while guaranteeing that you'll never lose a valid email. CanIt achieves
extraordinarily accurate discrimination through human intervention, and
includes mechanisms to minimize the amount of human intervention required.

4. CRM v20020626
by Crah the Merciless
Relevant URL:
http://crm114.sourceforge.net/
Platforms: Linux, POSIX
Summary:

CRM is a very powerful filtering and mutilation language based on regex
operations. It is capable of classifying mail messages, syslogs, firewall
logs, and other incoming streams of unbounded length. It has a very
powerful sparse-spectral learning capability; given examples of multiple
classes (say, business email, jokes, and spam), it can learn to
discriminate the classes.

5. The SpamBouncer v1.5-Jun22
by Catherine A. Hampton [email protected]
Relevant URL:
http://www.spambouncer.org/
Platforms: UNIX
Summary:

The SpamBouncer is a set of procmail instructions that search the headers
and text of your incoming email to see if it meets one or more of a list
of conditions for probable spam. It will then either tag the suspected
spam and return it to your main incoming mailbox, tag the suspected spam,
delete spam from known spam sources, and file suspected spam in a separate
folder, send a simulated MAILER-DAEMON daemon "bounce", complain to the
"upstream providers" of known spammers or spam sites/domains, etc.

6. nstalker-chunked.c v1.0b
by N-Stalker
Relevant URL:
http://www.nstalker.com/util.php
Platforms: UNIX
Summary:

nstalker-chunked.c is free and open-source, so try it out. The program
uses a sophisticated method to find susceptible servers - not just banner
checking.


V. SECURITY JOBS SUMMARY
------------------------
1. Full-time position - Delivery Manager/Managing Consultant (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

2. Security Application Deployment Consultant - New York (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

3. Recruiting "AVP Security Infrastructure" - HCA - Nashville, TN (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

4. Can I get a Cleared IPD Exploitation Analyst in Columbia, MD? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

5. AVP Security Infrastructure - HCA - Nashville, TN (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

6. Security Sales Position in Maryland (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

7. UK based Entrust PKI 3rd Line Support Technician (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

8. We are hiring Sr. System Engineers and Sales people (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

9. checkpoint engineer needed ASAP (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

10. Availability of Security Analyst MCSE/CSA w/Five Years Experience (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

11. Network/UNIX security consultant available for telecommuting (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

12. Network Security Manager Position in Chicago (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

13. Sr. Security Architect Position in Florida Available (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

14. Wireless Security Consultant Needed (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]


VI. INCIDENTS LIST SUMMARY
-------------------------
1. Fw: spoofed packets to RFC 1918 addresses (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/000c01c21e26$b2d99670$3264a8c0@local

2. Apache goes berserk (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

3. win2k server issue (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

4. Ending a few arguments with one simple attachment. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/003501c21e1a$4cc35d50$0201000a@k7ezizjvt9gjdv

5. spoofed packets to RFC 1918 addresses (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/000d01c21e03$9af99be0$0103a8c0@HUNDLEY0012K

6. Am i compromised? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

7. Fw: [PHP-DEV] Fw: PHP content-disposition vuln (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/017101c21dcd$4e3e1d70$7101a8c0@pc26c

8. PHP content-disposition vuln (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

9. Someone looking for CodeRed infected boxes ? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

10. URGENT! gamespy download infected with Nimda (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

11. Dead Thread - Backdoor (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

12. UAAC Protocol ? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

13. Unusual proxy port scan (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

14. [incidents]  backdoor (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

15. backdoor (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

16. zero tcp offset  packets sent to a honeypot (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/000801c21c1d$8f8d32e0$8724e98f@asterix

17. Broken mailservers (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/Pine.LNX.4.44.0206241956580.20696-100000@ultra1.hugo.vanderkooij.org

18. Honeynet Project - The Reverse Challenge (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

19. ZOMBIES_HTTP_GET (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

20. SQL port probe repeats (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/017e01c21ac9$e0d99620$db09fea9@hal900

21. port 32814 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

22. Worm1800.exe on UnderNet (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

23. Analyse Worm18000 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

24. ICMP type 12 packets (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

25. FollowUp: Worm1800.exe on UnderNet? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

26. Worm1800.exe on UnderNet? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/000501c218b7$e2022b70$c8022a18@AP000324


VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. DoS_Browser (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

2. Noguska Nola 1.1.1 [ Intranet Business Management Software ] (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/1025194477.10339.9.camel@com-bedroom

3. Java and buffer overflows (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

4. Remote buffer overflow in resolver code of libc (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/B9407C44.D869%[email protected]

5. csh/tcsh vulnerability (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

6. Cluestick Advisory #001 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

7. JNI and buffer overflows (was java and buffer overflows) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

8. Cluestick Advisory #000 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

9. OpenSSH Vulns (new?) Priv seperation (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

10. Apache vulnerability checking (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/014401c21d5f$2363b1f0$0901a8c0@mendark

11. VS: Apache vulnerability checking (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

12. OpenSSH advisory (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

13. Windows .lnk Files (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

14. Another flaw in Apache? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

15. Apache chunked encoding and Solaris/Sparc (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/20C62FD75D71F74786A0036B35A6CFF9185506@newsub506.Int.Synapsegroupinc.com

16. (Fwd)  Java and buffer overflows (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/3D18E1A6.13239.3399BB@localhost

17. login yahoogroups. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

18. spying (deleted) file entries in other users' directories (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

19. Apache Exploit (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

20. Formatstring Vulnerability in decfingerd 0.7 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/5.1.1.6.2.20020625030621.00b39a38@localhost

21. Re[2]: Apache Exploit (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

22. [BUGTRAQ] : ZyXEL 642R(-11) AJ.6 SYN-ACK, SYN-FIN DoS (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

23. Added Speakers !, Homeland Outlook Conf, - USCG, NGB, FEMA, OSD, DoD/NCS, Army (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/4122-22002662292829790@cp134514-a

24. solaris 9 sparc rcp (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/Pine.LNX.4.44.0206211338280.5205-100000@mail

25. Apache Worm? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

26. Cyberguard 4.3 smtp proxy? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

27. apache chunked encoding (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

28. procmail heap overflow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]


VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. secedit.sdb behavior in W2K (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

2. SecurityFocus Microsoft Newsletter #92 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/6AA3020BB6C49E4EBDB055884742533201AA14@dieppe.calgary.securityfocus.com

3. Null session and Exchange2K (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/7DDAF43D1E128F45A30CB40978B67948D9D0AE@pgamh02.venturipartners.com

4. Locking Down Windows 2000 Workstation (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAAEMtrQbCw6UWlUXn1i/[email protected]

5. Microsoft Software Update Services (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]


IX. SUN FOCUS LIST SUMMARY
----------------------------
1. Solaris 8 username contingency (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]

2. "Sun SSH" vulnerable to OpenSSH 2.9.9-3.3 exploit ? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]

3. Solaris 9 SSH: HostbasedAuthentication? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]

4. Sunscreen 3.2 + Solaris8? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]


X. LINUX FOCUS LIST SUMMARY
---------------------------
1. Have I been kitted? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]


XI. SPONSOR INFORMATION
-----------------------
This newsletter is sponsored by: SecurityFocus DeepSight Threat Management
System

From June 24th - August 31st, 2002, SecurityFocus announces a FREE
two-week trial of the DeepSight Threat Management System: the only early
warning system providing customizable and comprehensive early warning of
cyber attacks and bulletproof countermeasures to prevent attacks before
they hit your network.

With the DeepSight Threat Management System, you can focus on proactively
deploying prioritized and specific patches to protect your systems from
attacks, rather than reactively searching dozens of Web sites or hundreds
of emails frantically trying to gather information on the attack and how
to recover from it.

Sign up today!

http://www.securityfocus.com/corporate/products/promo/tmstrial-sf.shtml

-------------------------------------------------------------------------------