SecurityFocus Newsletter #281

Peter Laborge <[email protected]> 28 Dec 2004 20:32:23 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #281
------------------------------

Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041130

------------------------------------------------------------------------
I. FRONT AND CENTER
     1. Spam Punishment Doesn't Fit the Crime
     2. Why Open Source Solaris?
II. BUGTRAQ SUMMARY
     1. Windows Media Player ActiveX Control Media File Attribute Co...
     2. Windows Media Player ActiveX Control File Enumeration Weakne...
     3. Kayako ESupport Multiple Cross-Site Scripting and SQL Inject...
     4. Crystal Art Crystal FTP Remote Client-Side Buffer Overflow V...
     5. HTGET URI Buffer Overflow Vulnerability
     6. IMG2ASCII Unauthorized File Upload Vulnerability
     7. IBM AIX Diag Local Privilege Escalation Vulnerabilities
     8. PHPFormMail HTML Output Function HTML Injection Vulnerabilit...
     9. IBM AIX PAGINIT Local Buffer Overflow Vulnerability
     10. ArGoSoft Mail Server HTML Injection Vulnerability
     11. PHP Shared Memory Module Offset Memory Corruption Vulnerabil...
     12. KDE Konqueror Multiple Remote Java Sandbox Bypass Vulnerabil...
     13. PHPFormMail Alias Hidden Field HTML Injection Vulnerability
     14. EScripts Software E_Board Directory Traversal Vulnerability
     15. Ultrix DXTerm Setup Parameter Local Buffer Overflow Vulnerab...
     16. Tlen.pl Instant Messenger Remote Script Execution Vulnerabil...
     17. Email Sanitizer MIME Type Parsing Remote Denial Of Service V...
     18. Google Desktop Search Remote Information Disclosure Vulnerab...
     19. WorkBoard PHP-Nuke Module Multiple Cross-Site Scripting Vuln...
     20. CHPOX Unspecified Vulnerability
     21. Microsoft Windows XP Firewall ACL Bypass Vulnerability
     22. GNU Troff (Groff) Insecure Temporary File Creation Vulnerabi...
     23. MIT Kerberos 5 Administration Library Add_To_History Heap-Ba...
     24. IBM AIX CHCOD Local Privilege Escalation Vulnerability
     25. IBM AIX LSVPD Local Privilege Escalation Vulnerability
     26. Symantec Brightmail AntiSpam Quarantine Multiple Remote Deni...
     27. Webroot Software My Firewall Plus Local Privilege Escalation...
     28. Webroot Software Spy Sweeper Enterprise Local Privilege Esca...
     29. Wordpress Multiple Cross-Site Scripting and SQL Injection Vu...
     30. LibVNCServer Multiple Unspecified Vulnerabilities
     31. PHPAuction Administrative Interface Authentication Bypass Vu...
     32. XPDF DoImage Remote Buffer Overflow Vulnerability
     33. Rosiello Security RFTPD Multiple Remote And Local Vulnerabil...
     34. Perl RMTree Local Race Condition Vulnerability
     35. Rosiello Security RPF Multiple Remote And Local Vulnerabilit...
     36. libTIFF Heap Corruption Integer Overflow Vulnerabilities
     37. MPlayer And Xine PNM_Get_Chunk Multiple Remote Client-Side B...
     38. HP-UX FTP Server Debug Logging Mode Buffer Overflow Vulnerab...
     39. Debian Debmake Local Insecure Temporary File Creation Vulner...
     40. Linux Kernel 32 Bit Compatibility System Call Handler AMD64 ...
     41. Sybase Adaptive Server Enterprise Multiple Unspecified Vulne...
     42. Skype Technologies Skype Internet Telephony Insecure Default...
     43. 2BGal Remote SQL Injection Vulnerability
     44. Snort DecodeTCPOptions Remote Denial Of Service Vulnerabilit...
     45. SSLTelnetd Unspecified Format String Vulnerability
     46. NetWin SurgeMail Webmail Unspecified Vulnerability
     47. Docbook-To-Man Insecure Temporary File Creation Vulnerabilit...
     48. LPRNG LPRNG_CERTS.SH Local Insecure Temporary File Creation ...
     49. PsychoStats Login Parameter Cross-Site Scripting Vulnerabili...
     50. Microsoft Windows winhlp32 Phrase Integer Overflow Vulnerabi...
     51. Microsoft Windows winhlp32 Phrase Heap Overflow Vulnerabilit...
     52. Linux Security Modules Process Capabilities Design Error
     53. Microsoft Windows ANI File Denial of Service Attack
     54. Microsoft Windows LoadImage API Function Integer Overflow Vu...
     55. Nullsoft SHOUTcast File Request Format String Vulnerability
     56. Wirtualna Polska WPKontakt Remote Script Execution Vulnerabi...
     57. HP-UX System Administration Manager Privilege Escalation Vul...
     58. HP-UX Netscape Directory Server With LDAP Remote Buffer Over...
     59. Debian Tetex-Bin Xdvizilla Insecure Temporary File Creation ...
     60. Linux Kernel ELF Binary Loading Denial Of Service Vulnerabil...
     61. ZeroBoard Multiple Remote Script Injection And Cross-Site Sc...
     62. YACY Peer-To-Peer Search Engine Multiple Cross-Site Scriptin...
III. SECURITYFOCUS NEWS ARTICLES
     1. Groups fight Internet wiretap push
     2. Report: DHS cyber security lagging
     3. Long prison term for Lowe's wi-fi hacker
     4. 'Metal Gear' Trojan targets Symbian phones
     5. Popular BitTorrent site shuts down after flurry of suits
     6. NASA hacker jailed for six months
IV. SECURITYFOCUS TOP 6 TOOLS
     1. Interface Traffic Indicator 1.2.3
     2. Colasoft Capsa 4.05
     3. Attack Tool Kit (ATK) 3.0
     4. One-Time Password Generator 1.0
     5. tenshi 0.3.2
     6. pasmal 1.5
V. SECURITYJOBS LIST SUMMARY
     1. [SJ-JOB] Sales Representative, San Diego, US (Thread)
     2. [SJ-JOB] Sr. Security Engineer, Sunnyvale, US (Thread)
     3. [SJ-JOB] Account Manager, Houston, US (Thread)
     4. [SJ-JOB] Application Security Engineer, San Francisc... (Thread)
     5. [SJ-JOB] Manager, Information Security, Alpharetta, ... (Thread)
     6. [SJ-JOB] Manager, Information Security, Anaheim, US (Thread)
     7. [SJ-JOB] Account Manager, Atlanta, US (Thread)
     8. [SJ-JOB] Sales Representative, Northern CA, US (Thread)
     9. [SJ-JOB] Information Assurance Analyst, Bedford, US (Thread)
     10. [SJ-JOB] Security Engineer, San Francisco, US (Thread)
     11. [SJ-JOB] Account Manager, New York, US (Thread)
     12. [SJ-JOB] Information Assurance Engineer, Dearborn, M... (Thread)
     13. [SJ-JOB] Application Security Engineer, Irvine, US (Thread)
     14. [SJ-JOB] Channel / Business Development, Dallas, US (Thread)
VI. INCIDENTS LIST SUMMARY
     1. [Full-Disclosure] RE: Worm hitting PHPbb2 Forums (Thread)
     2. Worm hitting PHPbb2 Forums (Thread)
     3. SSH scans... (Thread)
     4. Strange command histories in hacked shell server (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. Exploiting network services question (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. services running in windows domain (winXP clients) (Thread)
     2. Microsoft Vulnerabilities ARE being reported to Micr... (Thread)
     3. port 411 remote MT protocol? (Thread)
     4. Secondary Storage Device Policy (Thread)
     5. KB824145 with SUS (Thread)
     6. port 411 remote MT protocol? (Solved) (Thread)
     7. Modifying default behaviour of MS VPN client (Thread)
IX. SUN FOCUS LIST SUMMARY
     NO NEW POSTS FOR THE WEEK 2004-12-21 to 2004-12-28.
X. LINUX FOCUS LIST SUMMARY
     1. Honeynet KYE paper (Thread)
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION

I. FRONT AND CENTER
-------------------
1. Spam Punishment Doesn't Fit the Crime
By Mark Rasch

When spammers are treated more harshly than those who commit war crimes in
Rwanda, and are fined more than companies that destroy the environment,
it's time to revisit our strategy.

http://www.securityfocus.com/columnists/287


2. Why Open Source Solaris?
By Daniel Hanson

Sun is getting into the open-source business with Solaris, but will this
automatically translate into better sales?

http://www.securityfocus.com/columnists/286

II. BUGTRAQ SUMMARY
-------------------
1. Windows Media Player ActiveX Control Media File Attribute Co...
BugTraq ID: 12031
Remote: Yes
Date Published: Dec 18 2004
Relevant URL: http://www.securityfocus.com/bid/12031
Summary:
The Windows Media Player ActiveX control is prone to a security weakness.  The issue is that the control may be abused by a Web page to change attributes of media files (such as MP3).  An attacker can influence attributes such as the artist, song name, or album name.  

It is possible to exploit this weakness to inject malicious script code into these attributes.  If this issue was combined with a vulnerability that could force Internet Explorer to interpret the injected script code, it may be possible to execute malicious script code in the Local Zone.  Such an attack would lead to execution of arbitrary code on computers that do not have this Zone locked down.

This issue is reported to affect Windows Media Player 9.  It reportedly does not work on computers running Windows XP SP2 when the attack is executed from a remote source.  This is likely due to additional browser security measures in Windows XP SP2.

2. Windows Media Player ActiveX Control File Enumeration Weakne...
BugTraq ID: 12032
Remote: Yes
Date Published: Dec 18 2004
Relevant URL: http://www.securityfocus.com/bid/12032
Summary:
The Windows Media Player ActiveX control is prone to a security weakness that may allow a malicious Web page to enumerate files that exist on the client computer.

This could aid in further attacks.

This issue is reported to affect Windows Media Player 9.  It reportedly does not work on computers running Windows XP SP2 when the attack is executed from a remote source.  This is likely due to additional browser security measures in Windows XP SP2.

3. Kayako ESupport Multiple Cross-Site Scripting and SQL Inject...
BugTraq ID: 12037
Remote: Yes
Date Published: Dec 18 2004
Relevant URL: http://www.securityfocus.com/bid/12037
Summary:
Kayako eSupport is prone to multiple input validation vulnerabilities.  One cross-site scripting and six SQL injection vulnerabilities.  

These issues may collectively threaten compromise of software and database security properties.  Possible attacks include theft of cookie-based authentication credentials, exposure or modification of database information, and a potential for attacks against the underlying database implementation.

4. Crystal Art Crystal FTP Remote Client-Side Buffer Overflow V...
BugTraq ID: 12038
Remote: Yes
Date Published: Dec 20 2004
Relevant URL: http://www.securityfocus.com/bid/12038
Summary:
A remote, client-side buffer overflow vulnerability reportedly affects Crystal Art Crystal FTP. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.

An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.

5. HTGET URI Buffer Overflow Vulnerability
BugTraq ID: 12039
Remote: Yes
Date Published: Dec 20 2004
Relevant URL: http://www.securityfocus.com/bid/12039
Summary:
HTGET is prone to a buffer overflow vulnerability.  This vulnerability is exposed when the software handles a malformed URI.

Successful exploitation may result in execution of arbitrary code in the context of the client user.

6. IMG2ASCII Unauthorized File Upload Vulnerability
BugTraq ID: 12040
Remote: Yes
Date Published: Dec 18 2004
Relevant URL: http://www.securityfocus.com/bid/12040
Summary:
IMG2ASCII may allow remote users to upload arbitrary files.  If a malicious PHP script is uploaded to the vulnerable computer, it may be possible to request the script remotely and cause its contents to be executed.  This would occur in the context of the Web server hosting the application.

The vendor has not released any further information about this vulnerability except to state that it has been addressed with the release of IMG2ASCII 1.17.

7. IBM AIX Diag Local Privilege Escalation Vulnerabilities
BugTraq ID: 12041
Remote: No
Date Published: Dec 20 2004
Relevant URL: http://www.securityfocus.com/bid/12041
Summary:
diag is reported prone to a local privilege escalation vulnerability.  This issue is due to a failure of certain diag applications to properly implement security controls when executing an application specified by the 'DIAGNOSTICS' environment variable. 

A local attacker may leverage this issue to gain superuser privileges on a computer running the affected software.

8. PHPFormMail HTML Output Function HTML Injection Vulnerabilit...
BugTraq ID: 12042
Remote: Yes
Date Published: Dec 19 2004
Relevant URL: http://www.securityfocus.com/bid/12042
Summary:
PHPFormMail is prone to an HTML injection vulnerability.  This issue exists in a function that is designed to output HTML from form input.  

This vulnerability could allow for various attacks, although the software does not appear to use cookies or support user sessions, so session hijacking may not be possible.

9. IBM AIX PAGINIT Local Buffer Overflow Vulnerability
BugTraq ID: 12043
Remote: No
Date Published: Dec 20 2004
Relevant URL: http://www.securityfocus.com/bid/12043
Summary:
paginit is reported prone to a local buffer overflow vulnerability.  This issue presents itself because the application fails to carry out boundary checks on user-supplied data from the command line.  It is reported that this issue may allow a local attacker to gain elevated privileges on a vulnerable computer.

An attacker can exploit this to gain elevated privileges by supplying replacement memory addresses and shellcode through the affected argument.

10. ArGoSoft Mail Server HTML Injection Vulnerability
BugTraq ID: 12044
Remote: Yes
Date Published: Dec 17 2004
Relevant URL: http://www.securityfocus.com/bid/12044
Summary:
ArGoSoft Mail Server is reported prone to an HTML injection vulnerability.  This issue presents itself due to insufficient sanitization of user-supplied data.  

A remote attacker could potentially exploit this condition to steal cookie-based authentication credentials from a legitimate user of the Web mail system. 

ArGoSoft Mail Server 1.8.6.9 and prior versions are affected by this issue.

11. PHP Shared Memory Module Offset Memory Corruption Vulnerabil...
BugTraq ID: 12045
Remote: No
Date Published: Dec 20 2004
Relevant URL: http://www.securityfocus.com/bid/12045
Summary:
PHP shared memory module (shmop) is reported prone to an integer handling vulnerability. The issue exists in the PHP_FUNCTION(shmop_write) function and is as a result of a lack of sufficient sanitization performed on 'offset' data.

This vulnerability may be exploited to make an almost arbitrary write into process memory. It is reported that the vulnerability may be leveraged to disable PHP 'safe mode', this may result in further compromise in a shared-server environment.

12. KDE Konqueror Multiple Remote Java Sandbox Bypass Vulnerabil...
BugTraq ID: 12046
Remote: Yes
Date Published: Dec 20 2004
Relevant URL: http://www.securityfocus.com/bid/12046
Summary:
KDE Konqueror is a freely available, open source web browser distributed and maintained by the KDE project. It is available for the UNIX and Linux operating systems.

Multiple remote Java sandbox bypass vulnerabilities affect KDE Konqueror.  These issues are due to a failure of the application to properly secure the Java web plug-in.

The first issue is a failure of the application to restrict access to sensitive Java classes from the Java browser plug-in.  The second issue is a failure of the application to restrict access to sensitive Java classes from JavaScript scripts.

These issues may be leveraged to carry out a variety of unspecified attacks including sensitive information disclosure and denial of service attacks. Any successful exploitation would take place with the privileges of the user running the affected browser application.

13. PHPFormMail Alias Hidden Field HTML Injection Vulnerability
BugTraq ID: 12047
Remote: Yes
Date Published: Dec 19 2004
Relevant URL: http://www.securityfocus.com/bid/12047
Summary:
PHPFormMail is prone to an HTML injection vulnerability.  This issue is due to an input validation error related to a hidden field for field aliases.

This vulnerability could allow for various attacks, although the software does not appear to use cookies or support user sessions, so session hijacking may not be possible.

14. EScripts Software E_Board Directory Traversal Vulnerability
BugTraq ID: 12048
Remote: Yes
Date Published: Dec 20 2004
Relevant URL: http://www.securityfocus.com/bid/12048
Summary:
It is reported that e_Board is vulnerable to a directory traversal vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input.

By including '../' directory traversal sequences and a NULL (%00) in the affected URI argument, attackers may reportedly cause the contents of arbitrary, potentially sensitive web-server readable files to be included in the output of the requested page.

15. Ultrix DXTerm Setup Parameter Local Buffer Overflow Vulnerab...
BugTraq ID: 12049
Remote: No
Date Published: Dec 20 2004
Relevant URL: http://www.securityfocus.com/bid/12049
Summary:
Ultrix dxterm is reported to be prone to a buffer overflow vulnerability. The issue presents itself when dxterm handles a superfluous 'setup' command line argument.

Because variables that are crucial to controlling program execution flow for dxterm are stored adjacent to the affected buffer, an attacker may corrupt these values and influence dxterm program execution flow into attacker-controlled memory.

16. Tlen.pl Instant Messenger Remote Script Execution Vulnerabil...
BugTraq ID: 12050
Remote: Yes
Date Published: Dec 20 2004
Relevant URL: http://www.securityfocus.com/bid/12050
Summary:
Tlen.pl is reported prone to a potential script execution vulnerability.  It is reported that this issue may allow remote attackers to execute arbitrary script code on a vulnerable computer, which may lead to various attacks.

Tlen.pl 5.23.4.1 and prior versions are affected by this vulnerability.

17. Email Sanitizer MIME Type Parsing Remote Denial Of Service V...
BugTraq ID: 12051
Remote: Yes
Date Published: Dec 20 2004
Relevant URL: http://www.securityfocus.com/bid/12051
Summary:
A remote denial of service vulnerability affects the MIME type parsing functionality of Email Sanitizer.  This issue is due to a failure of the application to properly handle malformed MIME type specifiers.

An attacker may leverage this issue to cause the affected sanitizer to hang and stop responding, effectively denying service to legitimate users.

18. Google Desktop Search Remote Information Disclosure Vulnerab...
BugTraq ID: 12052
Remote: Yes
Date Published: Dec 20 2004
Relevant URL: http://www.securityfocus.com/bid/12052
Summary:
Google Desktop Search is reported prone to a remote vulnerability that may allow an attacker to disclose a user's search results from the local computer. 

The attacker entices a user to visit the site and creates a Java applet to leverage this vulnerability.  When the Java applet is loaded by the user, it can send queries to the attacker's server that appear to be Google queries to the Desktop Search application.  

The Desktop Search application integrates local search results with the queries and this information is sent to the remote server controlled by the attacker.

19. WorkBoard PHP-Nuke Module Multiple Cross-Site Scripting Vuln...
BugTraq ID: 12054
Remote: Yes
Date Published: Dec 20 2004
Relevant URL: http://www.securityfocus.com/bid/12054
Summary:
It is reported that WorkBoard is affected by various cross-site scripting vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied URI input. 

These issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials

20. CHPOX Unspecified Vulnerability
BugTraq ID: 12055
Remote: Unknown
Date Published: Dec 20 2004
Relevant URL: http://www.securityfocus.com/bid/12055
Summary:
chpox is affected by an unspecified vulnerability; it is not known if this issue is local or remote.  The underlying cause of this issue is currently unknown.

The potential impact of this issue is also unknown.  Users are advised to upgrade to the latest version of the affected software.

More information is not currently available.  This BID will be updated as more details are released.

21. Microsoft Windows XP Firewall ACL Bypass Vulnerability
BugTraq ID: 12057
Remote: Yes
Date Published: Dec 20 2004
Relevant URL: http://www.securityfocus.com/bid/12057
Summary:
Microsoft Windows XP Firewall is reported prone to an ACL bypass vulnerability. Reports indicate that the vulnerability presents itself when the Windows XP Firewall is configured to block access to Microsoft File and Printer Sharing on a dial-up interface.

This vulnerability may leave a computer user that is connected to the Internet using a dial-up connection under a false sense of security. The user may believe that the firewall is protecting them from malicious attacks and as a result may employ lax user credentials or share confidential data openly.

22. GNU Troff (Groff) Insecure Temporary File Creation Vulnerabi...
BugTraq ID: 12058
Remote: No
Date Published: Dec 20 2004
Relevant URL: http://www.securityfocus.com/bid/12058
Summary:
GNU Troff (groff) is affected by multiple insecure temporary file creation vulnerabilities.  These issues are due to a design error that causes the application to fail to verify the existence of a file before writing to it. 

An attacker may leverage these issues to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. 

GNU Troff (groff) 1.18 is reported vulnerable to these issues.  Other versions are likely to be vulnerable as well.  This BID will be updated when more information becomes available.

23. MIT Kerberos 5 Administration Library Add_To_History Heap-Ba...
BugTraq ID: 12059
Remote: No
Date Published: Dec 20 2004
Relevant URL: http://www.securityfocus.com/bid/12059
Summary:
It is reported that the MIT Kerberos 5 administration library is affected by a heap-based buffer overflow vulnerability. The vulnerability presents itself in the 'add_to_history()' function of the  'svr_principal.c' source file. The vulnerability exists due to an indexing error that occurs under certain circumstances. 

An authenticated attacker may potentially exploit this vulnerability on a Key Distribution Center (KDC) to execute arbitrary code in the context of the vulnerable service, ultimately resulting in the compromise of an entire Kerberos realm.

24. IBM AIX CHCOD Local Privilege Escalation Vulnerability
BugTraq ID: 12060
Remote: No
Date Published: Dec 21 2004
Relevant URL: http://www.securityfocus.com/bid/12060
Summary:
The AIX 'chcod' utility is reported prone to a local privilege escalation vulnerability. The vendor describes that this vulnerability results from an insecure path handling issue.

Reports indicate that this issue may be exploited by a local user that is a member of the 'system' group to run arbitrary code as the superuser.

25. IBM AIX LSVPD Local Privilege Escalation Vulnerability
BugTraq ID: 12061
Remote: No
Date Published: Dec 21 2004
Relevant URL: http://www.securityfocus.com/bid/12061
Summary:
The AIX 'lsvpd' utility is reported prone to an unspecified local privilege escalation vulnerability. The vendor describes that this vulnerability results from an insecure path handling issue.

Reports indicate that this issue may be exploited by any local user through the 'invscout' utility.

26. Symantec Brightmail AntiSpam Quarantine Multiple Remote Deni...
BugTraq ID: 12063
Remote: Yes
Date Published: Dec 21 2004
Relevant URL: http://www.securityfocus.com/bid/12063
Summary:
Multiple remote denial of service vulnerabilities affect the Quarantine component of Symantec's Brightmail AntiSpam.  These issues are due to a failure of the application to properly handle quarantined mail notifications and exceptional conditions in message processing.

The first issue arises when an excessively large number of spam messages are held in a user's Quarantine folder.  The second issue presents itself when the Notifier encounters SMTP errors during notifications.

An attacker may leverage these issues to cause the affected component to crash, disabling spam notifications and potentially allowing spam to bypass the filtering process.

27. Webroot Software My Firewall Plus Local Privilege Escalation...
BugTraq ID: 12064
Remote: No
Date Published: Dec 21 2004
Relevant URL: http://www.securityfocus.com/bid/12064
Summary:
My Firewall Plus is reported prone to a local privilege escalation vulnerability.  This vulnerability arises due to a design error causing the software to launch a help application with SYSTEM privileges.

My Firewall Plus 5.0 is reported vulnerable to this issue, however, it is possible that other versions are affected as well.

28. Webroot Software Spy Sweeper Enterprise Local Privilege Esca...
BugTraq ID: 12065
Remote: No
Date Published: Dec 21 2004
Relevant URL: http://www.securityfocus.com/bid/12065
Summary:
Spy Sweeper Enterprise is reported prone to a local privilege escalation vulnerability. This vulnerability arises due to a design error causing the software to launch a help application with SYSTEM privileges. 

Spy Sweeper Enterprise 1.5.1 is reported vulnerable to this issue, however, it is possible that other versions are affected as well.

29. Wordpress Multiple Cross-Site Scripting and SQL Injection Vu...
BugTraq ID: 12066
Remote: Yes
Date Published: Dec 21 2004
Relevant URL: http://www.securityfocus.com/bid/12066
Summary:
Wordpress is reported prone to multiple cross-site scripting and SQL injection vulnerabilities.  These issues arise due to insufficient sanitization of user-supplied data.  

These issues were previously reported in Wordpress Multiple Cross-Site Scripting, HTML Injection, And SQL Injection Vulnerabilities (BID 11984).  Subsequent to the release of BID 11984, the vendor released Wordpress 1.2.2 to address the issues.  

It is reported that Wordpress 1.2.2 does not address all the issues specified in that BID and it is still vulnerable to some cross-site scripting and SQL injection issues.

30. LibVNCServer Multiple Unspecified Vulnerabilities
BugTraq ID: 12068
Remote: Yes
Date Published: Dec 21 2004
Relevant URL: http://www.securityfocus.com/bid/12068
Summary:
Multiple, unspecified vulnerabilities reportedly affect LibVNCServer.  The underlying cause of these issues is currently unknown.

The potential impacts of these issues are unknown.  Due to the nature of the affected software it is possible that these issues may be leveraged to conduct denial of service and even system compromise, although this is not confirmed.

31. PHPAuction Administrative Interface Authentication Bypass Vu...
BugTraq ID: 12069
Remote: Yes
Date Published: Dec 21 2004
Relevant URL: http://www.securityfocus.com/bid/12069
Summary:
PhpAuction is reported prone to an authentication bypass vulnerability. It is reported that this vulnerability exists due to a weak design of the system used to control access to the PhpAuction administrative interface.

By simply editing a session cookie value an attacker may bypass the PhpAuction authentication system and gain access to the administrative interface.

32. XPDF DoImage Remote Buffer Overflow Vulnerability
BugTraq ID: 12070
Remote: Yes
Date Published: Dec 21 2004
Relevant URL: http://www.securityfocus.com/bid/12070
Summary:
xpdf is reported prone to a remote buffer overflow vulnerability.  This issue exists because the applications fails to perform proper boundary checks before copying user-supplied data in to process buffers.  A remote attacker may execute arbitrary code in the context of a user running the application.  This can result in the attacker gaining unauthorized access to the vulnerable computer.

An attacker can exploit this issue by enticing a vulnerable user to open a malformed PDF file.  If the application is configured as the default handler for PDF files, this could present a viable Web or email attack vector as when the PDF is clicked from an appropriate client application, xpdf will automatically be invoked.

This issue is reported to affect xpdf 3.00, however, it is likely that earlier versions are prone to this vulnerability as well.  Applications using embedded xpdf code may be vulnerable to these issues as well.

33. Rosiello Security RFTPD Multiple Remote And Local Vulnerabil...
BugTraq ID: 12071
Remote: Yes
Date Published: Dec 21 2004
Relevant URL: http://www.securityfocus.com/bid/12071
Summary:
Multiple remote vulnerabilities reportedly affect Rosiello Security's rftpd.  These issues are due to buffer mismanagement and failures to handle certain network data.

The first issue is a failure of the application to properly implement an authentication scheme. Multiple information leaks reportedly affects the application due to a failure to properly NULL terminate strings created with the 'strncpy()' function. Multiple remote buffer overflows are reported to affect various commands of the affected server application. A local buffer overflow exists in the processing of the Message Of The Day (MOTD) file. Finally, the affected application is affected by an access validation vulnerability.

These issues may be exploited to gain unauthorized access to the FTP server, reveal potentially sensitive memory, trigger a denial of service condition, bypass file and directory permissions, and execute arbitrary code with the privilege of the affected server process.

34. Perl RMTree Local Race Condition Vulnerability
BugTraq ID: 12072
Remote: No
Date Published: Dec 21 2004
Relevant URL: http://www.securityfocus.com/bid/12072
Summary:
Perl is reported prone to a local race condition. The vulnerability is present in the 'rmtree()' function provided by the 'File::Path' module.

A local attacker may exploit this condition to disclose potentially sensitive data, or to launch other attacks against an application that employs the vulnerable function.

35. Rosiello Security RPF Multiple Remote And Local Vulnerabilit...
BugTraq ID: 12073
Remote: Yes
Date Published: Dec 21 2004
Relevant URL: http://www.securityfocus.com/bid/12073
Summary:
A remote buffer overflow and a local symbolic link vulnerability reportedly affect Rosiello Security rpf.  These issues are due to a failure of the application to properly validate user-supplied string lengths and a design error facilitating local symbolic link attacks.

The buffer overflow will allow a remote attacker execute arbitrary code with the privileges of a user running the vulnerable application, facilitating unauthorized access and privilege escalation. An attacker may leverage the symbolic link issue to corrupt arbitrary files with the privileges of the user that activated the affected application.

36. libTIFF Heap Corruption Integer Overflow Vulnerabilities
BugTraq ID: 12075
Remote: Yes
Date Published: Dec 21 2004
Relevant URL: http://www.securityfocus.com/bid/12075
Summary:
It has been reported that libtiff is affected by two heap corruption vulnerabilities due to integer overflow errors that can be triggered when malicious or malformed image files are processed.  Theoretically, an attacker can exploit the vulnerabilities to execute arbitrary code in the context of an application linked to the library, when TIFF image data is processed (i.e. displayed).  Because image data is frequently external in origin, these vulnerabilities are considered remotely exploitable.

37. MPlayer And Xine PNM_Get_Chunk Multiple Remote Client-Side B...
BugTraq ID: 12076
Remote: Yes
Date Published: Dec 21 2004
Relevant URL: http://www.securityfocus.com/bid/12076
Summary:
Multiple buffer overflow vulnerabilities are reported to exist in the xine and MPlayer utilities. The following issues are reported:

Several buffer overflow vulnerabilities are reported to exist in the 'pnm_get_chunk()' function.

Reports indicate that the vulnerabilities present themselves in the RMF_TAG, DATA_TAG, PROP_TAG, MDPR_TAG and CONT_TAG handling code of 'pnm_get_chunk()'.

A remote attacker may potentially leverage this memory corruption to execute arbitrary code in the context of a user that uses the vulnerable utility to connect to a malicious PNM server.

An additional buffer overflow vulnerability is reported to exist in the PNA_TAG handling code of the 'pnm_get_chunk()' function. 

It is reported that supplied PNA_TAG data is copied into a finite buffer without sufficient boundary checks. This results in memory corruption. A remote attacker may potentially leverage this memory corruption to execute arbitrary code in the context of a user that uses the vulnerable utility to connect to a malicious PNM server.

38. HP-UX FTP Server Debug Logging Mode Buffer Overflow Vulnerab...
BugTraq ID: 12077
Remote: Yes
Date Published: Dec 22 2004
Relevant URL: http://www.securityfocus.com/bid/12077
Summary:
It has been reported that the FTP server included with HP-UX is vulnerable to a remotely exploitable pre-authentication buffer overflow if configured to log debug output.  This is not a default configuration.  An administrator at some point would had to have configured inetd to invoke the ftpd server process with the "-v" parameter.  Remote attackers can exploit this vulnerability to gain root privileges on the affected host.

39. Debian Debmake Local Insecure Temporary File Creation Vulner...
BugTraq ID: 12078
Remote: No
Date Published: Dec 22 2004
Relevant URL: http://www.securityfocus.com/bid/12078
Summary:
A local insecure file creation vulnerability affects Debian's debmake.  This issue is due to a design error that causes the affected application to create temporary files insecurely.

An attacker may leverage this issue to corrupt arbitrary files with the privileges of the user that activates the affected application.

40. Linux Kernel 32 Bit Compatibility System Call Handler AMD64 ...
BugTraq ID: 12079
Remote: No
Date Published: Dec 22 2004
Relevant URL: http://www.securityfocus.com/bid/12079
Summary:
Linux Kernel is reported prone to a local privilege escalation vulnerability.  This issue may allow an attacker to gain elevated privileges leading to a complete compromise of a vulnerable computer.

It is reported that this issue arises as the 32 bit compatibility system call handler fails to verify an unspecified argument properly.  This vulnerability only presents itself on the AMD64 platform.

This issue reportedly affects 2.4.x versions of the kernel.

Further details about this issue are currently unavailable.  This BID will be updated if more information is released.

41. Sybase Adaptive Server Enterprise Multiple Unspecified Vulne...
BugTraq ID: 12080
Remote: Yes
Date Published: Dec 22 2004
Relevant URL: http://www.securityfocus.com/bid/12080
Summary:
Sybase Adaptive Server Enterprise is reported prone to multiple unspecified vulnerabilities.  The cause and impact of these issues are currently unknown.  It is conjectured that these issues may facilitate local and remote attack vectors.  The researchers responsible for discovering these vulnerabilities have considered these issues as having a high-risk security impact.  Specific details about these issues will not be released until March 2005.

Sybase Adaptive Server Enterprise versions 12.5.2 and prior are reported vulnerable to these issues.

This BID will be updated and specific BIDs for individual issues will be created when more information becomes available.

42. Skype Technologies Skype Internet Telephony Insecure Default...
BugTraq ID: 12081
Remote: No
Date Published: Dec 22 2004
Relevant URL: http://www.securityfocus.com/bid/12081
Summary:
An insecure default installation vulnerability reportedly affects Skype Technologies Skype. This issue is due to a failure of the application to properly secure files and directories that are installed.

This issue is only reported to affect Skype for the Linux platform.

An attacker may leverage this issue to create, delete, and write to arbitrary files and create files in the insecure directory.

43. 2BGal Remote SQL Injection Vulnerability
BugTraq ID: 12083
Remote: Yes
Date Published: Dec 22 2004
Relevant URL: http://www.securityfocus.com/bid/12083
Summary:
A remote SQL injection vulnerability reportedly affects 2Bgal.  This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in an SQL query.

An attacker may leverage this issue to manipulate SQL query strings and potentially carry out arbitrary database queries. This may facilitate the disclosure or corruption of sensitive database information.

44. Snort DecodeTCPOptions Remote Denial Of Service Vulnerabilit...
BugTraq ID: 12084
Remote: Yes
Date Published: Dec 22 2004
Relevant URL: http://www.securityfocus.com/bid/12084
Summary:
Snort is reported prone to a remote denial of service vulnerability. The vulnerability is reported to exist in the DecodeTCPOptions() function of 'decode.c', and is as a result of a failure to sufficiently handle malicious TCP packets.

A remote attacker may trigger this vulnerability to crash a remote Snort server and in doing so may prevent subsequent malicious attacks from being detected.

45. SSLTelnetd Unspecified Format String Vulnerability
BugTraq ID: 12085
Remote: Yes
Date Published: Dec 23 2004
Relevant URL: http://www.securityfocus.com/bid/12085
Summary:
Reportedly SSLTelnetd is affected by an unspecified format string vulnerability.  This issue is due to an improper implementation of a formatted string function. 

Specific technical details about this issue were not disclosed.  It is conjectured that due to the nature of the affected application, this issue is remotely exploitable.

This vulnerability is reported to affect Linux Netkit netkit-telnet-ssl 0.17.17, however, it is likely that other versions are affected as well.

This BID will be updated when more information becomes available.

46. NetWin SurgeMail Webmail Unspecified Vulnerability
BugTraq ID: 12086
Remote: Yes
Date Published: Dec 23 2004
Relevant URL: http://www.securityfocus.com/bid/12086
Summary:
SurgeMail is reported prone to an unspecified vulnerability.  This issue affects the Webmail functionality of the SurgeMail server.  Further details were not released in the report by the vendor.  It is conjectured that due to the nature of this application, this vulnerability may result from an input validation error.  Although unconfirmed, this issue is considered to be remotely exploitable.

SurgeMail releases prior to 2.2c9 are affected by this vulnerability.

Due to a lack of details, further information is not available at the moment.  This BID will be updated when more information becomes available.

47. Docbook-To-Man Insecure Temporary File Creation Vulnerabilit...
BugTraq ID: 12087
Remote: No
Date Published: Dec 23 2004
Relevant URL: http://www.securityfocus.com/bid/12087
Summary:
A temporary file creation vulnerability reportedly affects Docbook-To-Man.  This issue is due to a design error that causes the affected application to insecurely create files on affected computers.

An attacker may leverage this issue to corrupt arbitrary files with the privileges of an unsuspecting user that activates the affected application.

48. LPRNG LPRNG_CERTS.SH Local Insecure Temporary File Creation ...
BugTraq ID: 12088
Remote: No
Date Published: Dec 23 2004
Relevant URL: http://www.securityfocus.com/bid/12088
Summary:
A temporary file creation vulnerability reportedly affects the 'lprng_certs.sh' script of LPRng.  This issue is due to a design error that causes the affected application to insecurely create files on affected computers.

An attacker may leverage this issue to corrupt arbitrary files with the privileges of an unsuspecting user that activates the affected application.

49. PsychoStats Login Parameter Cross-Site Scripting Vulnerabili...
BugTraq ID: 12089
Remote: Yes
Date Published: Dec 22 2004
Relevant URL: http://www.securityfocus.com/bid/12089
Summary:
PsychoStats is reported prone to a cross-site scripting vulnerability.  This issue is due to a failure of the application to properly sanitize user-supplied URI input. 

The problem presents itself when malicious HTML and script code is sent to the application through the 'login' parameter.

This vulnerability may allow for theft of cookie-based authentication credentials or other attacks. 

This vulnerability is reported to exist in PsychoStats 2.2.4 Beta and prior versions.

50. Microsoft Windows winhlp32 Phrase Integer Overflow Vulnerabi...
BugTraq ID: 12091
Remote: Yes
Date Published: Dec 23 2004
Relevant URL: http://www.securityfocus.com/bid/12091
Summary:
Microsoft Windows is prone to an integer overflow vulnerability.  This issue exists in 'winhlp32.exe' and is exposed when a malformed phrase compressed Windows Help file (.hlp) is processed by the program.

Successful exploitation may allow execution of arbitrary code in the context of the user that opens the malicious Help file.  The Help file may originate from an external or untrusted source, so this vulnerability is considered remote in nature.

51. Microsoft Windows winhlp32 Phrase Heap Overflow Vulnerabilit...
BugTraq ID: 12092
Remote: Yes
Date Published: Dec 23 2004
Relevant URL: http://www.securityfocus.com/bid/12092
Summary:
Microsoft Windows is prone to a heap-based buffer overflow vulnerability.  This issue exists in 'winhlp32.exe' and is exposed when a malformed phrase compressed Windows Help file (.hlp) is processed by the program.

Successful exploitation may allow execution of arbitrary code in the context of the user that opens the malicious Help file.  The Help file may originate from an external or untrusted source, so this vulnerability is considered remote in nature.

52. Linux Security Modules Process Capabilities Design Error
BugTraq ID: 12093
Remote: No
Date Published: Dec 23 2004
Relevant URL: http://www.securityfocus.com/bid/12093
Summary:
It has been reported that Linux Security Modules suffers from a design error that could result in host compromise.  According to the report, when LSM is loaded as a kernel module, existing processes on the system will be granted unauthorized capabilities.  This includes non-root processes.  A malicious user on the system at this time will have effectively gained administrative access.

Reported affected are versions of LSM for Linux kernels 2.5.x and 2.6.x.  LSM on Linux 2.4.x is reportedly not vulnerable.

53. Microsoft Windows ANI File Denial of Service Attack
BugTraq ID: 12094
Remote: Yes
Date Published: Dec 23 2004
Relevant URL: http://www.securityfocus.com/bid/12094
Summary:
It is reportd that Microsoft Windows is prone to a denial of service condition when processing specially formed ANI files. The Microsoft Windows kernel does not perform proper sanitization on the frame or rate number set in the ANI file header, which may result in a system crash.

54. Microsoft Windows LoadImage API Function Integer Overflow Vu...
BugTraq ID: 12095
Remote: Yes
Date Published: Dec 20 2004
Relevant URL: http://www.securityfocus.com/bid/12095
Summary:
Microsoft Windows is reported prone to a remote integer overflow vulnerability.  This issue is due to a failure of the application to properly ensure that user-supplied input does not result in the overflowing of integer values.  This may result in data being copied past the end of a memory buffer.

It is reported that this issue exists in the 'LoadImage' function of the USER32 library.  An attacker can exploit this condition by sending a malformed file to a user.  If the user opens this file, the integer overflow condition may be triggered.  A successful attack would occur in the context of the vulnerable user and may lead to the attacker gaining unauthorized access to an affected computer.

55. Nullsoft SHOUTcast File Request Format String Vulnerability
BugTraq ID: 12096
Remote: Yes
Date Published: Dec 23 2004
Relevant URL: http://www.securityfocus.com/bid/12096
Summary:
Nullsoft SHOUTcast is prone to a remotely exploitable format string vulnerability.  The vulnerability is exposed when the server attempts to handle a client request for a file.

Successful exploitation may allow execution of arbitrary code in the context of the server process.  This could also be exploited to crash the server and, possibly, to read process memory (which could increase reliability of an exploit).

This issue was reported to exist in version 1.9.4 on Linux.  It is likely that versions for other platforms are also affected by the vulnerability, though it is not known to what degree they are exploitable.  Earlier versions of the software are also likely affected.

56. Wirtualna Polska WPKontakt Remote Script Execution Vulnerabi...
BugTraq ID: 12097
Remote: Yes
Date Published: Dec 23 2004
Relevant URL: http://www.securityfocus.com/bid/12097
Summary:
WPKontakt is reported prone to a potential script execution vulnerability. It is reported that this issue may allow remote attackers to execute arbitrary script code on a vulnerable computer, which may lead to various attacks. Arbitrary script code may be executed on a target system in the event that a specially message containing a specially malformed email address containing a JavaScript URI is received.

57. HP-UX System Administration Manager Privilege Escalation Vul...
BugTraq ID: 12098
Remote: No
Date Published: Dec 23 2004
Relevant URL: http://www.securityfocus.com/bid/12098
Summary:
HP has announced a vulnerability affecting the SAM component of HP-UX.  The details of the vulnerability are not yet clear.  It is reportedly possible for a local user to gain unauthorized privileges.  This alert will be updated as further technical details emerge.

58. HP-UX Netscape Directory Server With LDAP Remote Buffer Over...
BugTraq ID: 12099
Remote: Yes
Date Published: Dec 22 2004
Relevant URL: http://www.securityfocus.com/bid/12099
Summary:
HP-UX is reported prone to a remote buffer overflow vulnerability.  This issue may occur when Netscape Directory Server is deployed on a HP-UX computer using LDAP.

This vulnerability arises because the application does not perfrom proper boundary checks before copying user-supplied data in to process buffers.  As a result an attacker can supply a payload containing excessive string data to overflow static buffers leading to memory corruption.

This issue was disclosed by the vendor, however, further details were not released.  This BID will be updated when more information is available.

59. Debian Tetex-Bin Xdvizilla Insecure Temporary File Creation ...
BugTraq ID: 12100
Remote: No
Date Published: Dec 23 2004
Relevant URL: http://www.securityfocus.com/bid/12100
Summary:
xdvizilla is a script that integrates DVI file viewing in Mozilla-based browsers.  It is implemented with Debian tetex-bin package.

xdvizilla is reported prone to an insecure temporary file creation vulnerability.  This issue is due to a design error that causes the application to fail to verify the existence of a file before writing to it. 

An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. 

tetex-bin 2.0.2 is reported prone to this issue.  It is likely that other versions are affected as well.

60. Linux Kernel ELF Binary Loading Denial Of Service Vulnerabil...
BugTraq ID: 12101
Remote: Yes
Date Published: Dec 24 2004
Relevant URL: http://www.securityfocus.com/bid/12101
Summary:
The Linux kernel is affected by an ELF binary loading vulnerability.  This issue is due to a failure of the affected kernel to properly handle malformed ELF binaries.

An attacker may leverage this issue to cause the affected kernel to crash, denying service to legitimate users.

61. ZeroBoard Multiple Remote Script Injection And Cross-Site Sc...
BugTraq ID: 12103
Remote: Yes
Date Published: Dec 24 2004
Relevant URL: http://www.securityfocus.com/bid/12103
Summary:
Multiple script injection and cross-site scripting vulnerabilities reportedly affect ZeroBoard.  These issues are due to a failure of the application to properly sanitize user-supplied input.

An attacker may leverage these issues to execute arbitrary server-side scripts and carry out cross-site scripting attacks against unsuspecting users. This may facilitate a compromise of the host computer, as well as theft of cookie-based authentication credentials.  Other attacks are also possible.

62. YACY Peer-To-Peer Search Engine Multiple Cross-Site Scriptin...
BugTraq ID: 12104
Remote: Yes
Date Published: Dec 24 2004
Relevant URL: http://www.securityfocus.com/bid/12104
Summary:
Multiple cross-site scripting vulnerabilities affect YACY.  These issues are due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamically generated content.
 
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user.  This may facilitate theft of cookie-based authentication credentials as well as other attacks.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Groups fight Internet wiretap push
By: Kevin Poulsen

Industry and advocacy groups challenge the FBI to prove it's having problems spying on broadband and VoIP users.

http://www.securityfocus.com/news/10192

2. Report: DHS cyber security lagging
By: Kevin Poulsen

Inspectors find weak passwords, buffer overflows and mystery modems at the Department of Homeland Security.
http://www.securityfocus.com/news/10148

3. Long prison term for Lowe's wi-fi hacker
By: Kevin Poulsen

A 21-year-old Michigan man who tried to steal credit card numbers from a national hardware store chain is sentenced to nine years in federal prison.
http://www.securityfocus.com/news/10138

4. 'Metal Gear' Trojan targets Symbian phones
By: Tony Smith, The Register

Symbian OS/Series 60 UI malware Skulls has been put to further use, this time masquerading as a version of the game Metal Gear Solid.
http://www.securityfocus.com/news/10185

5. Popular BitTorrent site shuts down after flurry of suits
By: Peter Svensson, The Associated Press

http://www.securityfocus.com/news/10166

6. NASA hacker jailed for six months
By: John Leyden, The Register

A US man has been jailed for six months for a 2001 attack on the web systems of space agency NASA which cost $200,000 to fix.
http://www.securityfocus.com/news/10164

IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Interface Traffic Indicator 1.2.3
By: Carsten Schmidt
Relevant URL: http://software.ccschmidt.de/#inftraffic
Platforms: Windows 2000, Windows NT, Windows XP
Summary: 

Interface Traffic Indicator, a graph utility to measure incoming and outgoing traffic on an interface in bits/sec, bytes/sec or utilization. Works on all SNMP-capable devices (computers, NICs, switches, routers, etc.) with adjustable poll intervall down to three seconds. You can use this programm in a professional network environment to monitor selected network interfaces (even backplane ports if the device provides the information) or you can monitor your home network or

2. Colasoft Capsa 4.05
By: Roy Luo
Relevant URL: http://www.colasoft.com/
Platforms: Windows 2000, Windows 95/98, Windows XP
Summary: 

Capsa is a powerful but easy to use network monitor and analyzer designed for packet decoding and network diagnosis. With the abilities of real time monitoring and data analyzing, you can capture and decode network traffic transmitted over local host and local network. Capsa has Packet Analysis Module and three advanced analysis modules: Email Analysis Module, Web Analysis Module and Transaction Analysis Module.

3. Attack Tool Kit (ATK) 3.0
By: Marc Ruef
Relevant URL: http://www.computec.ch/projekte/atk/
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary: 

The Attack Tool Kit (ATK) is an open-source utility to realize penetration tests and enhance security audits. The most important changes in ATK 3.0 are the introduction of a dedicated exploiting routine and the Plugin AutoUpdate (over HTTP).

4. One-Time Password Generator 1.0
By: Marcin Simonides
Relevant URL: http://marcin.studio4plus.com/en/otpgen/
Platforms: Java
Summary: 

A One-Time Password Generator for Java-enabled mobile phones. The interface has been designed to minimize the number of necessary keypresses.

5. tenshi 0.3.2
By: Andrea Barisani
Relevant URL: http://tenshi.gentoo.org/
Platforms: Perl (any system supporting perl)
Summary: 

tenshi is a log monitoring program, designed to watch a log file for lines matching user defined regular expressions and report on the matches. The regular expressions are assigned to queues which have an alert interval and a list of mail recipients.

Queues can be set to send a notification as soon as there is a log line assigned to it, or to send periodic reports.

6. pasmal 1.5
By: James Meehan
Relevant URL: http://www.elitelabs.org/
Platforms: Linux
Summary: 

pasmal 1.5 is a port knocking authentification system using simple or encrypted tcp/udp/icmp packets. pasmal can be used with iptables/ipchains (firewall purposes) or any other program (remote shell, reboot, etc)It is packaged with a php web admin, a command line client pasmal.client, start/stop rc.d scripts.pasmal 1.5 also feature an intrusion/attempts detection system due to its sniffers capabilities, running with syslogd and custom log files.

V. SECURITYJOBS LIST SUMMARY
----------------------------
1. [SJ-JOB] Sales Representative, San Diego, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/385357

2. [SJ-JOB] Sr. Security Engineer, Sunnyvale, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/385349

3. [SJ-JOB] Account Manager, Houston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/385348

4. [SJ-JOB] Application Security Engineer, San Francisc... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/385346

5. [SJ-JOB] Manager, Information Security, Alpharetta, ... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/385344

6. [SJ-JOB] Manager, Information Security, Anaheim, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/385343

7. [SJ-JOB] Account Manager, Atlanta, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/385339

8. [SJ-JOB] Sales Representative, Northern CA, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/385337

9. [SJ-JOB] Information Assurance Analyst, Bedford, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/385336

10. [SJ-JOB] Security Engineer, San Francisco, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/385335

11. [SJ-JOB] Account Manager, New York, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/385083

12. [SJ-JOB] Information Assurance Engineer, Dearborn, M... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/385077

13. [SJ-JOB] Application Security Engineer, Irvine, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/385072

14. [SJ-JOB] Channel / Business Development, Dallas, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/385071

VI. INCIDENTS LIST SUMMARY
--------------------------
1. [Full-Disclosure] RE: Worm hitting PHPbb2 Forums (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/385550

2. Worm hitting PHPbb2 Forums (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/385276

3. SSH scans... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/385234

4. Strange command histories in hacked shell server (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/385233

VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Exploiting network services question (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/385511

VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. services running in windows domain (winXP clients) (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/385546

2. Microsoft Vulnerabilities ARE being reported to Micr... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/385368

3. port 411 remote MT protocol? (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/385242

4. Secondary Storage Device Policy (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/385225

5. KB824145 with SUS (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/385101

6. port 411 remote MT protocol? (Solved) (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/385099

7. Modifying default behaviour of MS VPN client (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/385070

IX. SUN FOCUS LIST SUMMARY
--------------------------
NO NEW POSTS FOR THE WEEK 2004-12-21 to 2004-12-28.

X. LINUX FOCUS LIST SUMMARY
---------------------------
1. Honeynet KYE paper (Thread)
Relevant URL:

http://www.securityfocus.com/archive/91/385316

XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.
    
XII. SPONSOR INFORMATION
-----------------------

Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041130
------------------------------------------------------------------------