SecurityFocus Newsletter #283
Peter Laborge <[email protected]> 11 Jan 2005 21:15:46 -0000
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #283
------------------------------
This Issue is Sponsored By: SPI Dynamics
ALERT: ARE YOU VULNERABLE TO A 'SQL INJECTION' ATTACK?-FREE Product Trial
Firewalls, IDS and Access Controls don't stop these attacks because hackers
using the web application layer are NOT seen as intruders. Test your web
application for over 4,100 vulnerabilities and attack methodologies with
our FREE WebInspect 15 day download trial!
http://www.securityfocus.com/sponsor/SPIDynamics_sf-news_050111
------------------------------------------------------------------------
Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!
http://www.securityfocus.com/sponsor/Symantec_sf-news_041130
------------------------------------------------------------------------
I. FRONT AND CENTER
1. Microsoft Anti-Spyware?
2. The Perils of Deep Packet Inspection
3. SSH Port Forwarding
4. Stamping Passport
II. BUGTRAQ SUMMARY
1. Joe Lumbroso FormMail.php Arbitrary Remote File Access Vulne...
2. HTML Headline Temporary File Symbolic Link Vulnerabilities
3. GFI MailEssentials and MailSecurity HTML Email Remote Denial...
4. SIR GNUBoard File Upload Extension Restriction Bypass Vulner...
5. FlatNuke Form Submission Input Validation Vulnerability
6. Apple AirPort Wireless Distribution System Remote Denial of ...
7. Mozilla/Firefox File Download Dialog Spoofing Vulnerability
8. Bugzilla Internal Error Cross-Site Scripting Vulnerability
9. 3Com 3CDaemon Multiple Remote Vulnerabilities
10. All Enthusiast PhotoPost Classifieds Multiple Input Validati...
11. All Enthusiast PhotoPost PHP Pro Multiple Cross-Site Scripti...
12. All Enthusiast ReviewPost PHP Pro Multiple Input Validation ...
13. MyBulletinBoard MEMBER.PHP SQL Injection Vulnerability
14. Soldner Secret Wars Multiple Remote Vulnerabilities
15. QwikiWiki Remote Directory Traversal Vulnerability
16. Multiple Vendor Bluetooth Device Unauthorized Serial Command...
17. Linux Kernel SYSENTER Thread Information Pointer Local Infor...
18. Linux Kernel Local File Descriptor Passing Security Module B...
19. IBM DB2 XML Function Unauthorized File Creation and Disclosu...
20. LibTIFF TIFFDUMP Heap Corruption Integer Overflow Vulnerabil...
21. Symantec CcErrDsp.ErrorDisplay.1 ActiveX Remote Denial Of Se...
22. WinHKI Multiple Remote Vulnerabilities
23. Winace Remote Directory Traversal Vulnerability
24. Virtual Hosting Control System SQL.PHP Remote File Include V...
25. b2evolution INDEX.PHP SQL Injection Vulnerability
26. Mod_DOSEvasive Apache Module Local Insecure Temporary File C...
27. Noah Grey Greymatter Password Disclosure Vulnerability
28. Jeuce Personal Web Server Directory Traversal And Denial Of ...
29. Noah Grey Greymatter GM-CPLog.CGI HTML Injection Vulnerabili...
30. Exim Illegal IPv6 Address Buffer Overflow Vulnerability
31. Microsoft Multiple Unspecified Security Vulnerabilities
32. Amphora Gate Unauthorized Access Vulnerability
33. Exim SPA Authentication Remote Buffer Overflow Vulnerability
34. Noah Grey Greymatter GM-Comments.CGI HTML Injection Vulnerab...
35. Linux kernel Uselib() Local Privilege Escalation Vulnerabili...
36. SugarCRM/SugarSales Remote File Include Vulnerability
37. Amp II 3D Game Engine Remote Denial Of Service Vulnerability
38. Simple PHP Blog Remote Directory Traversal Vulnerabilities
39. Novell GroupWise WebAccess Potential Information Disclosure ...
40. Linux Kernel Multiple Local MOXA Serial Driver Buffer Overfl...
41. Linux Kernel Random Poolsize SysCTL Handler Integer Overflow...
42. Linux Kernel Local RLIMIT_MEMLOCK Bypass Denial Of Service V...
43. Linux Kernel SCSI IOCTL Integer Overflow Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
1. Netizens eye Web-enabled surveillance cams
2. Sims 2 hacks spread like viruses
3. Groups fight Internet wiretap push
4. MS virus clean-up tool sparks controversy
5. Vital Files Exposed In GMU Hacking
6. Exploit code attacks unpatched IE bug
IV. SECURITYFOCUS TOP 6 TOOLS
1. Azure Web Log 1.5
2. Interface Traffic Indicator 1.2.3
3. Colasoft Capsa 4.05
4. Attack Tool Kit (ATK) 3.0
5. One-Time Password Generator 1.0
6. tenshi 0.3.2
V. SECURITYJOBS LIST SUMMARY
1. [SJ-JOB] Security Engineer, Bethesda, US (Thread)
2. [SJ-JOB] Security Engineer, Fairfax, US (Thread)
3. [SJ-JOB] MOD CLAS Consultant, Surrey, GB (Thread)
4. [SJ-JOB] Jr. Security Analyst, Centreville, US (Thread)
5. [SJ-JOB] Auditor, Detroit, US (Thread)
6. [SJ-JOB] Auditor, Cleveland, US (Thread)
7. [SJ-JOB] Channel / Business Development, New York (E... (Thread)
8. [SJ-JOB] Forensics Engineer, London, GB (Thread)
9. [SJ-JOB] Sales Engineer, St. Louis, US (Thread)
10. [SJ-JOB] Security Researcher, Atlanta, US (Thread)
11. [SJ-JOB] Sales Engineer, Parsippany, US (Thread)
12. [SJ-JOB] Application Security Engineer, Seattle, US (Thread)
13. [SJ-JOB] Account Manager, Chicago- Mid West, US (Thread)
14. [SJ-JOB] Management, Palm Beach, US (Thread)
15. [SJ-JOB] Incident Handler, Jersey City, US (Thread)
16. [SJ-JOB] Compliance Officer, Miami, US (Thread)
17. [SJ-JOB] Account Manager, Long Island City, NYC, US (Thread)
18. [SJ-JOB] Account Manager, Washington, US (Thread)
19. [SJ-JOB] Security Engineer, Pompano Beach, US (Thread)
20. [SJ-JOB] Manager, Information Security, Boca Raton, ... (Thread)
21. [SJ-JOB] Manager, Information Security, Jersey City,... (Thread)
22. [SJ-JOB] Application Security Engineer, Amsterdam, N... (Thread)
23. [SJ-JOB] Regional Channel Manager, London, GB (Thread)
24. [SJ-JOB] Application Security Engineer, Zurich or Be... (Thread)
25. [SJ-JOB] Sr. Product Manager, Sunnyvale, US (Thread)
26. [SJ-JOB] Security Consultant, Munich or Frankfurt, D... (Thread)
27. [SJ-JOB] Developer, San Antonio, US (Thread)
28. [SJ-JOB] Security Engineer, Mountain View, US (Thread)
29. [SJ-JOB] Sales Engineer, New York City, US (Thread)
30. [SJ-JOB] Security Consultant, Amsterdam, NL (Thread)
31. [SJ-JOB] Regional Channel Manager, Tokyo, JP (Thread)
32. [SJ-JOB] Sales Representative, New York City, US (Thread)
33. [SJ-JOB] Technical Support Engineer, Seattle, US (Thread)
34. [SJ-JOB] Regional Channel Manager, Brasilia, BR (Thread)
35. [SJ-JOB] Security Consultant, Charlotte, US (Thread)
36. [SJ-JOB] Regional Channel Manager, Sarmiento, AR (Thread)
37. [SJ-JOB] Security Auditor, Milwaukee, US (Thread)
38. [SJ-JOB] Channel / Business Development, Suburbs of ... (Thread)
39. [SJ-JOB] Jr. Security Analyst, Reston, US (Thread)
40. [SJ-JOB] Evangelist, palo alto, US (Thread)
41. [SJ-JOB] Information Assurance Engineer, Mountain Vi... (Thread)
42. [SJ-JOB] Security System Administrator, Mountain Vie... (Thread)
43. [SJ-JOB] Sr. Product Manager, San Diego, US (Thread)
44. [SJ-JOB] Sr. Product Manager, San Jose, US (Thread)
VI. INCIDENTS LIST SUMMARY
1. IE Malware / Spyware Control Methods (Thread)
2. analysis of Troj/Winser-A (Thread)
3. DoS attack... what to do? (Thread)
4. SQL injection worm ? (Thread)
5. Botnet is back, and some info FYI. (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
1. Run-time errors and JIT debuggers (Thread)
2. NetDDE (Thread)
3. Contest for a trip to CanSecWest/core05 (Thread)
4. ndisasm bad opcodes interpretation (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
1. Anti-spyware Beta from Microsoft available (Thread)
2. suggestions for proxy server to run on w2003 box.. ... (Thread)
3. suggestions for proxy server to run on w2003 box.. ... (Thread)
4. suggestions for proxy server to run on w2003 box.. (Thread)
5. Windows Update Services (Thread)
6. XP SP2 Blind install (Thread)
7. services running in windows domain (winXP clients) (Thread)
8. SecurityFocus Microsoft Newsletter #222 (Thread)
IX. SUN FOCUS LIST SUMMARY
NO NEW POSTS FOR THE WEEK 2005-01-04 to 2005-01-11.
X. LINUX FOCUS LIST SUMMARY
1. NMAP : Different interpretation of "filtered" ports ... (Thread)
2. ipv6, again (Thread)
3. CAN-2004-1137 (Thread)
4. firewall 1.4 (Thread)
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. Microsoft Anti-Spyware?
By Kelly Martin
Microsoft has jumped into the anti-spyware market, but is this a new
approach to thwarting bugs, or are they gearing up to profit from a dubious
industry they helped create?
http://www.securityfocus.com/columnists/289
2. The Perils of Deep Packet Inspection
By Dr. Thomas Porter
This paper looks at the evolution of firewall technology towards Deep
Packet Inspection, and then discusses some of the security issues with this
evolving technology.
http://www.securityfocus.com/infocus/1817
3. SSH Port Forwarding
By Brian Hatch
In this article we look at SSH Port Forwarding in detail, as it is a very
useful but often misunderstood technology. SSH Port Forwarding can be used
for secure communications in a myriad of different ways.
http://www.securityfocus.com/infocus/1816
4. Stamping Passport
By Mark Burnett
Microsoft can save its ailing authentication service, but only by scaling
back its expectations on what kind of accounts and services it's fit to secure.
http://www.securityfocus.com/columnists/290
II. BUGTRAQ SUMMARY
-------------------
1. Joe Lumbroso FormMail.php Arbitrary Remote File Access Vulne...
BugTraq ID: 12145
Remote: Yes
Date Published: Jan 01 2005
Relevant URL: http://www.securityfocus.com/bid/12145
Summary:
It has been reported that it is possible for a remote attacker to obtain any file on the filesystem that is readable by the webserver process corresponding to their session. The "ar_file" variable specifies a file to be included in the outgoing e-mail message. It is possible for an attacker to specify any file by using its relative path. As the recipient of the e-mail message is specified by the client, any file on the filesystem accessible to the server process can be sent to any remote e-mail address.
2. HTML Headline Temporary File Symbolic Link Vulnerabilities
BugTraq ID: 12147
Remote: No
Date Published: Jan 03 2005
Relevant URL: http://www.securityfocus.com/bid/12147
Summary:
It has been reported that there are numerous instances in HtmlHeadline where insecure temporary files are used. According to the report, it is possible for at least some of these instances to be exploited to corrupt files on the filesystem. It is likely that HtmlHeadline creates and writes to temporary files in the world writeable "/tmp" with predictable filenames.
3. GFI MailEssentials and MailSecurity HTML Email Remote Denial...
BugTraq ID: 12148
Remote: Yes
Date Published: Jan 03 2005
Relevant URL: http://www.securityfocus.com/bid/12148
Summary:
GFI MailEssentials and MailSecurity are prone to a remote denial of service vulnerability. This issue occurs when a specifically malformed HTML email message is processed. Rebooting the server or restarting the service will not resolve the issue.
4. SIR GNUBoard File Upload Extension Restriction Bypass Vulner...
BugTraq ID: 12149
Remote: Yes
Date Published: Jan 03 2005
Relevant URL: http://www.securityfocus.com/bid/12149
Summary:
SIR GNUBoard does not properly validate file extensions of uploaded files. This could allow a remote user to upload malicious script files to the Web site running GNUBoard. These scripts could potentially be executed in the browser of a user visiting the site.
5. FlatNuke Form Submission Input Validation Vulnerability
BugTraq ID: 12150
Remote: Yes
Date Published: Jan 03 2005
Relevant URL: http://www.securityfocus.com/bid/12150
Summary:
FlatNuke is prone to an input validation vulnerability that could allow a remote user to create an administrator account on the site or inject arbitrary script code. This issue exists in the forum registration process.
FlatNuke 2.5.1 was reported to be vulnerable to this issue, however, earlier versions may also be affected.
6. Apple AirPort Wireless Distribution System Remote Denial of ...
BugTraq ID: 12152
Remote: Yes
Date Published: Jan 03 2005
Relevant URL: http://www.securityfocus.com/bid/12152
Summary:
Apple AirPort Extreme and AirPort Express wireless base stations are prone to a denial of service vulnerability when used in Wireless Distribution System (WDS) mode. This issue could allow a remote attacker to cause the base station to stop processing traffic.
7. Mozilla/Firefox File Download Dialog Spoofing Vulnerability
BugTraq ID: 12153
Remote: Yes
Date Published: Jan 04 2005
Relevant URL: http://www.securityfocus.com/bid/12153
Summary:
Mozilla and Firefox are prone to a vulnerability that may permit a malicious Web page to spoof the source of a download.
This may be used in a social engineering attack that entices a user to download a malicious file under the assumption that it is coming from a trusted source.
8. Bugzilla Internal Error Cross-Site Scripting Vulnerability
BugTraq ID: 12154
Remote: Yes
Date Published: Jan 04 2005
Relevant URL: http://www.securityfocus.com/bid/12154
Summary:
Bugzilla is prone to a cross-site scripting vulnerability. The issue is exposed when the software renders internal errors that include user-supplied input.
This issue may be exploited by enticing a user into following a link that will cause hostile HTML and script code to be rendered in an internal error page. Exploitation may allow for theft of cookie-based authentication credentials or other attacks.
9. 3Com 3CDaemon Multiple Remote Vulnerabilities
BugTraq ID: 12155
Remote: Yes
Date Published: Jan 04 2005
Relevant URL: http://www.securityfocus.com/bid/12155
Summary:
3CDaemon is reportedly prone to multiple vulnerabilities. These issues may allow an attacker to crash the application, disclose sensitive information, and potentially execute arbitrary code on a vulnerable computer.
The following specific issues were identified:
Multiple format string vulnerabilities are reported to affect the application. These issues may allow an attacker to cause a denial of service condition or write to arbitrary process memory and potentially execute code.
Multiple buffer overflow vulnerabilities affect the application as well. These issues may allow remote attackers to execute arbitrary code on a vulnerable computer or crash the application.
3CDaemon also discloses sensitive information when a request for certain MS-DOS device names is carried out. This type of sensitive information may be used in further attacks against the computer.
3CDaemon 2.0 revision 10 is reported prone to these vulnerabilities, however, other versions may also be affected.
10. All Enthusiast PhotoPost Classifieds Multiple Input Validati...
BugTraq ID: 12156
Remote: Yes
Date Published: Jan 03 2005
Relevant URL: http://www.securityfocus.com/bid/12156
Summary:
PhotoPost Classifieds is reported to be prone to multiple vulnerabilities resulting from improper input validation. Remote attacks can carry out SQL injection, cross-site scripting attacks as well as upload arbitrary files to a vulnerable server.
All versions of PhotoPost Classifieds are reported prone to these issues.
11. All Enthusiast PhotoPost PHP Pro Multiple Cross-Site Scripti...
BugTraq ID: 12157
Remote: Yes
Date Published: Jan 04 2005
Relevant URL: http://www.securityfocus.com/bid/12157
Summary:
PhotoPost PHP Pro is reported prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamically generated content.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate theft of cookie-based authentication credentials as well as other attacks.
PhotoPost PHP Pro 4.8.1 is reported prone to these issues, however, it is likely that other versions are affected as well.
12. All Enthusiast ReviewPost PHP Pro Multiple Input Validation ...
BugTraq ID: 12159
Remote: Yes
Date Published: Jan 04 2005
Relevant URL: http://www.securityfocus.com/bid/12159
Summary:
ReviewPost PHP Pro is reported to be prone to multiple vulnerabilities resulting from improper input validation. Remote attacks can carry out SQL injection, cross-site scripting attacks as well as upload arbitrary files to a vulnerable server.
All versions of ReviewPost PHP Pro are reported prone to these issues.
13. MyBulletinBoard MEMBER.PHP SQL Injection Vulnerability
BugTraq ID: 12161
Remote: Yes
Date Published: Jan 04 2005
Relevant URL: http://www.securityfocus.com/bid/12161
Summary:
A remote SQL injection vulnerability reportedly affects MyBulletinBoard. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in an SQL query.
An attacker may leverage this issue to manipulate SQL query strings and potentially carry out arbitrary database queries. This may facilitate the disclosure or corruption of sensitive database information. Reportedly, a successful attack can disclose the administrator password hash to an attacker.
All versions of MyBulletinBoard are considered vulnerable to this issue.
14. Soldner Secret Wars Multiple Remote Vulnerabilities
BugTraq ID: 12162
Remote: Yes
Date Published: Jan 04 2005
Relevant URL: http://www.securityfocus.com/bid/12162
Summary:
Secret Wars is reported prone to multiple vulnerabilities. These issues can allow an attacker to cause a denial of service condition in the server, potentially execute arbitrary code and carry out HTML injection attacks through the administrative Web interface.
Secret Wars 30830 and prior versions are affected by this vulnerability.
15. QwikiWiki Remote Directory Traversal Vulnerability
BugTraq ID: 12163
Remote: Yes
Date Published: Jan 04 2005
Relevant URL: http://www.securityfocus.com/bid/12163
Summary:
QwikiWiki is reportedly susceptible to a remote directory traversal vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input.
A malicious user could issue a request containing directory traversal strings such as '..' to possibly view files outside the server root directory or the Web mail user's normal access rights. This would be in the context of the server, so only files that would normally be accessible to the server would be exposed. This could lead to a loss of integrity and/or confidentiality. Information gathered could also be used to enhance other avenues of attack on the underlying system.
Version 1.4.1 of QwikiWiki is reported to be susceptible. Other versions may also be affected.
16. Multiple Vendor Bluetooth Device Unauthorized Serial Command...
BugTraq ID: 12166
Remote: Yes
Date Published: Jan 04 2005
Relevant URL: http://www.securityfocus.com/bid/12166
Summary:
Multiple vendors of Bluetooth devices are reported susceptible to an unauthorized access vulnerability.
This vulnerability allows remote users to utilize the mobile device to act as a modem. Once connected, remote users may exploit the simulated modem to initiate calls, download potentially sensitive information from the mobile device, monitor conversations, divert calls, or connect to data services such as the Internet. Other attacks are also likely possible.
It should be noted that this vulnerability is likely present in the application layer, and not in the actual Bluetooth protocol layer.
17. Linux Kernel SYSENTER Thread Information Pointer Local Infor...
BugTraq ID: 12167
Remote: No
Date Published: Jan 05 2005
Relevant URL: http://www.securityfocus.com/bid/12167
Summary:
The Linux kernel is reported susceptible to a local information disclosure vulnerability.
This vulnerability may allow local attackers to gain access to potentially sensitive information that may aid them in further attacks.
There is insufficient information at this time to elaborate further. This BID will be updated as more information is disclosed.
This vulnerability is reported to exist in the Linux kernel in the 2.6 series, in versions prior to 2.6.10.
18. Linux Kernel Local File Descriptor Passing Security Module B...
BugTraq ID: 12168
Remote: No
Date Published: Jan 05 2005
Relevant URL: http://www.securityfocus.com/bid/12168
Summary:
It is reported that in certain cases, the Linux kernel fails to properly call defined security module functions in its SCM system.
This vulnerability may allow local attackers to bypass the expected security measures when passing file descriptors. The exact results of this vulnerability depend on the implementation of applications that utilize file descriptor passing. It is conjectured that this may result in open file descriptors being passed to processes that would not normally be able to access them. This may lead to attackers gaining access to read or modify files that would normally be denied to them.
This vulnerability is reported to exist in the Linux kernel in the 2.6 series, in versions prior to 2.6.10.
19. IBM DB2 XML Function Unauthorized File Creation and Disclosu...
BugTraq ID: 12170
Remote: Yes
Date Published: Jan 05 2005
Relevant URL: http://www.securityfocus.com/bid/12170
Summary:
IBM DB2 is reported prone to a vulnerability allowing attackers to create and disclose arbitrary files on an affected computer. This issue may allow an attacker to corrupt data, disclose sensitive information and ultimately execute arbitrary code on a vulnerable computer.
It is reported that this issue can be exploited by employing XML functions supplied with DB2 that allow users to create, overwrite, and disclose arbitrary files with the permissions of the DB2 server.
The attacker must have a database connection to exploit this issue. A successful attack can result in a complete compromise of the computer or the database.
This issue appears to correspond to one of the unspecified vulnerabilities announced in BID 11327.
20. LibTIFF TIFFDUMP Heap Corruption Integer Overflow Vulnerabil...
BugTraq ID: 12173
Remote: Yes
Date Published: Jan 05 2005
Relevant URL: http://www.securityfocus.com/bid/12173
Summary:
It has been reported that 'tiffdump' is affected by a heap corruption vulnerability due to an integer overflow error that can be triggered when malicious or malformed image files are processed. Theoretically, an attacker can exploit this vulnerability to execute arbitrary code in the context of the affected application when TIFF image data is processed. Because image data is frequently external in origin, these vulnerabilities are considered remotely exploitable.
21. Symantec CcErrDsp.ErrorDisplay.1 ActiveX Remote Denial Of Se...
BugTraq ID: 12175
Remote: Yes
Date Published: Jan 06 2005
Relevant URL: http://www.securityfocus.com/bid/12175
Summary:
The Symantec CcErrDsp.ErrorDisplay.1 ActiveX object is reported prone to a stack-memory exhaustion denial of service vulnerability. This ActiveX object is installed with Norton AntiVirus.
The researcher who discovered the vulnerability has stated that they do not believe the condition to be exploitable to corrupt process memory. If the vulnerability were successfully exploited, this would result in a denial of service due to a runtime error in the affected module that causes the running instance of the client application that the object is invoked through (typically Internet Explorer) to crash.
Norton AntiVirus 2004 ships with a vulnerable version of the object. Other versions and products may also be affected, such as Norton Internet Security. Symantec is currently investigating this vulnerability.
22. WinHKI Multiple Remote Vulnerabilities
BugTraq ID: 12176
Remote: Yes
Date Published: Jan 06 2005
Relevant URL: http://www.securityfocus.com/bid/12176
Summary:
WinHKI is reportedly prone to multiple remote vulnerabilities. These issues may allow an attacker to carry out denial of service and directory traversal attacks to place files in arbitrary locations on a vulnerable computer.
The following specific issues were identified:
The first two issues may allow remote attackers to carry out denial of service attacks. An attacker can craft a malicious BH or LHA file and send it to a user to be processed through WinHKI. If successful, this may result in a crash or a hang.
An attacker can also carry out directory traversal type attacks to place malicious files in arbitrary locations. These issues present themselves when the application processes malformed BH, CAB, and ZIP compressed files. This can allow the attacker to place potentially malicious files and corrupt data on a computer, which can aid in various attacks.
WinHKI 1.4d is reported prone to these vulnerabilities. It is possible that other versions are affected as well.
23. Winace Remote Directory Traversal Vulnerability
BugTraq ID: 12177
Remote: Yes
Date Published: Jan 06 2005
Relevant URL: http://www.securityfocus.com/bid/12177
Summary:
Reportedly, an attacker can carry out directory traversal type attacks. These issues present themselves when the application processes malformed compressed files.
A successful attack can allow the attacker to place potentially malicious files and overwrite files on a computer, which can aid in various attacks.
All versions of Winace are considered vulnerable at the present.
24. Virtual Hosting Control System SQL.PHP Remote File Include V...
BugTraq ID: 12178
Remote: Yes
Date Published: Jan 06 2005
Relevant URL: http://www.securityfocus.com/bid/12178
Summary:
Virtual Hosting Control System is prone to a remote PHP file include vulnerability. This issue may allow a remote user to include a PHP script that originates from a remote server.
Exploitation of the issue would allow execution of malicious PHP code in the context of the Web server hosting the application.
25. b2evolution INDEX.PHP SQL Injection Vulnerability
BugTraq ID: 12179
Remote: Yes
Date Published: Jan 06 2005
Relevant URL: http://www.securityfocus.com/bid/12179
Summary:
A remote SQL injection vulnerability reportedly affects the 'index.php' script of b2evolution. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in an SQL query.
An attacker may leverage this issue to manipulate SQL query strings and potentially carry out arbitrary database queries. This may facilitate the disclosure or corruption of sensitive database information.
All versions of b2evolution are considered vulnerable to this issue.
26. Mod_DOSEvasive Apache Module Local Insecure Temporary File C...
BugTraq ID: 12181
Remote: No
Date Published: Jan 06 2005
Relevant URL: http://www.securityfocus.com/bid/12181
Summary:
A local temporary file creation vulnerability reportedly affects mod_dosevasive. This issue is due to a failure of the module to create and write to temporary files in a secure manner.
An attacker may leverage this issue to write to arbitrary files on the affected computer with the privileges of the web server utilizing the affected module.
27. Noah Grey Greymatter Password Disclosure Vulnerability
BugTraq ID: 12182
Remote: Yes
Date Published: Jan 06 2005
Relevant URL: http://www.securityfocus.com/bid/12182
Summary:
Noah Grey greymatter 3.1 is reportedly affected by a password disclosure vulnerability. This issue is due to the application creating a temporary file, which includes the username and plaintext password of a user when greymatter rebuilds a 'main entry pages' section.
28. Jeuce Personal Web Server Directory Traversal And Denial Of ...
BugTraq ID: 12183
Remote: Yes
Date Published: Jan 06 2005
Relevant URL: http://www.securityfocus.com/bid/12183
Summary:
It is reported that Jeuce Personal Web Server is susceptible to remote directory traversal and denial of service vulnerabilities.
The directory traversal vulnerability is due to a failure of the application to properly sanitize user-supplied input data. This vulnerability reportedly allows remote attackers to retrieve the contents of arbitrary, potentially sensitive files located on the serving computer with the credentials of the affected server process.
The denial of service vulnerability reportedly allows remote attackers to cause the affected application to either crash, or refuse to service further requests.
Version 2.13 of Jeuce Personal Web Server is reportedly affected by these vulnerabilities. Other versions may also be affected.
29. Noah Grey Greymatter GM-CPLog.CGI HTML Injection Vulnerabili...
BugTraq ID: 12184
Remote: Yes
Date Published: Jan 06 2005
Relevant URL: http://www.securityfocus.com/bid/12184
Summary:
Noah Grey Greymatter is reportedly affected by an HTML injection vulnerability. This issue is due to the application failing to properly sanitize user-supplied input during login.
The attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user.
30. Exim Illegal IPv6 Address Buffer Overflow Vulnerability
BugTraq ID: 12185
Remote: Unknown
Date Published: Jan 06 2005
Relevant URL: http://www.securityfocus.com/bid/12185
Summary:
Exim is reported susceptible to a buffer overflow vulnerability when attempting to parse illegal IPv6 addresses. This issue is due to a failure of the application to properly bounds check user-supplied input prior to copying it to a fixed-size memory buffer.
The original reporter suggested that this vulnerability may be exploited to gain elevated privileges via calling Exim with unspecified command line arguments. Gaining elevated privileges would only be possible where the Exim binary is installed with setuid privileges.
It is conjectured that code paths other than those pertaining to command line processing may result in remotely exploitable buffer overflow vulnerabilities, but this is not confirmed at the present time.
31. Microsoft Multiple Unspecified Security Vulnerabilities
BugTraq ID: 12186
Remote: Unknown
Date Published: Jan 06 2005
Relevant URL: http://www.securityfocus.com/bid/12186
Summary:
Microsoft has released advanced notification that they will be releasing three security bulletins for Windows on January 11th, 2005. The vendor has not enumerated how many vulnerabilities will be addressed by these security bulletins, nor what specific components or platforms may be affected.
The maximum severity rating of any of these bulletins is 'Critical'.
32. Amphora Gate Unauthorized Access Vulnerability
BugTraq ID: 12187
Remote: Yes
Date Published: Jan 06 2005
Relevant URL: http://www.securityfocus.com/bid/12187
Summary:
Amphora Gate is reported prone to an unauthorized access vulnerability. This issue may allow remote attackers to access sensitive administration scripts without supplying proper authentication credentials.
It is conjectured that an attacker may gain administrative access to a vulnerable server.
Further information is not currently available. This BID will be updated when more information becomes available.
33. Exim SPA Authentication Remote Buffer Overflow Vulnerability
BugTraq ID: 12188
Remote: Yes
Date Published: Jan 06 2005
Relevant URL: http://www.securityfocus.com/bid/12188
Summary:
Exim is reported susceptible to a buffer overflow vulnerability when attempting to authenticate remote users via SPA. This issue is due to a failure of the application to properly bounds check user-supplied input prior to copying it to a fixed-size memory buffer.
This vulnerability reportedly allows remote attackers to execute arbitrary code in the context of the affected server application. This issue is only exploitable if SPA authentication is configured to be used. SPA authentication is not enabled by default.
34. Noah Grey Greymatter GM-Comments.CGI HTML Injection Vulnerab...
BugTraq ID: 12189
Remote: Yes
Date Published: Jan 06 2005
Relevant URL: http://www.securityfocus.com/bid/12189
Summary:
Greymatter is reportedly affected by an HTML injection vulnerability. This issue is due to the application failing to properly sanitize user-supplied input to 'gm-comments.cgi'.
The attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user, other attacks are also possible.
35. Linux kernel Uselib() Local Privilege Escalation Vulnerabili...
BugTraq ID: 12190
Remote: No
Date Published: Jan 07 2005
Relevant URL: http://www.securityfocus.com/bid/12190
Summary:
Linux kernel is reported prone to a local privilege escalation vulnerability. This issue arises in the 'uselib()' functions of the Linux binary format loader as a result of a race condition. Successful exploitation of this vulnerability can allow a local attacker to gain elevated privileges on a vulnerable computer.
The ELF and a.out loaders are reportedly affected by this vulnerability.
36. SugarCRM/SugarSales Remote File Include Vulnerability
BugTraq ID: 12191
Remote: Yes
Date Published: Jan 07 2005
Relevant URL: http://www.securityfocus.com/bid/12191
Summary:
SUgarCRM and SugarSales are reported prone to a vulnerability that may allow attackers to influence the include path for external files.
This vulnerability allows arbitrary script code to be executed in the context of the web server hosting the affected software. In the case of including local files, this may expose sensitive information. In the case of including remote files, it is possible to include a malicious PHP script from a remote source.
37. Amp II 3D Game Engine Remote Denial Of Service Vulnerability
BugTraq ID: 12192
Remote: Yes
Date Published: Jan 07 2005
Relevant URL: http://www.securityfocus.com/bid/12192
Summary:
Amp II 3D game engine is reported prone to a remote denial of service vulnerability. The vulnerability presents itself due to a failure to handle exceptional conditions.
It is reported that socket handling code of the Amp II 3D game engine does not handle all potential exceptional conditions correctly.
A remote attacker may exploit this vulnerability to deny service for legitimate users.
38. Simple PHP Blog Remote Directory Traversal Vulnerabilities
BugTraq ID: 12193
Remote: Yes
Date Published: Jan 07 2005
Relevant URL: http://www.securityfocus.com/bid/12193
Summary:
It is reported that Simple PHP Blog is susceptible to two remote directory traversal vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied input data.
The first vulnerability reportedly allows remote attackers to retrieve the contents of arbitrary, potentially sensitive files located on the serving computer with the credentials of the affected server process.
The second vulnerability reportedly allows remote attackers to create directories in arbitrary locations on the serving computer with the credentials of the affected server process.
These vulnerabilities are reported to exist in version 0.3.7c of Simple PHP Blog. Other versions may also be affected.
39. Novell GroupWise WebAccess Potential Information Disclosure ...
BugTraq ID: 12194
Remote: Yes
Date Published: Jan 07 2005
Relevant URL: http://www.securityfocus.com/bid/12194
Summary:
GroupWise WebAccess component is reported prone to a potential information disclosure vulnerability. This issue may allow remote attackers to gather sensitive data that may be used to mount further attacks against a vulnerable computer.
It should be noted that this issue is not confirmed at the moment. Exploitation of this issue may require valid authentication credentials. Further details will be provided when more information becomes available.
All versions of GroupWise are considered to be vulnerable at the moment.
40. Linux Kernel Multiple Local MOXA Serial Driver Buffer Overfl...
BugTraq ID: 12195
Remote: No
Date Published: Jan 07 2005
Relevant URL: http://www.securityfocus.com/bid/12195
Summary:
The MOXA serial port driver in the Linux kernel is reported susceptible to multiple buffer overflow vulnerabilities. These issues are due to a failure of the driver to perform proper bounds checks prior to copying user-supplied data to fixed-size memory buffers.
These vulnerabilities exist in the 'drivers/char/moxa.c' file.
The vulnerable functions perform a 'copy_from_user()' function call to copy user-supplied, user-space data to a fixed-size, static kernel memory buffer (moxaBuff) of 10240 bytes in length while utilizing the user-supplied length argument as passed from 'MoxaDriverIoctl()'. This reportedly results in improperly bounded operations, potentially resulting in locally exploitable buffer overflows.
Linux kernels from 2.2, through 2.4, and 2.6 are all reportedly susceptible to these vulnerabilities.
41. Linux Kernel Random Poolsize SysCTL Handler Integer Overflow...
BugTraq ID: 12196
Remote: No
Date Published: Jan 07 2005
Relevant URL: http://www.securityfocus.com/bid/12196
Summary:
The Linux Kernel is reported prone to a local integer overflow vulnerability. The issue occurs in the 'poolsize_strategy' function of the 'random.c' kernel driver.
The vulnerability exists due to a lack of sufficient sanitization performed on integer values before these values are employed as the size argument of a user-land to kernel memory copy operation.
This vulnerability may be leveraged to corrupt kernel memory and ultimately execute arbitrary code with ring-0 privileges. Alternatively, the issue may be exploited to trigger a kernel panic.
It is reported that a user must have UID 0 to exploit this issue, however the user does not require superuser privileges. This may hinder exploitability.
42. Linux Kernel Local RLIMIT_MEMLOCK Bypass Denial Of Service V...
BugTraq ID: 12197
Remote: No
Date Published: Jan 07 2005
Relevant URL: http://www.securityfocus.com/bid/12197
Summary:
The Linux kernel contains the capability to lock allocated memory. This capability is used by certain applications to ensure that memory is not swapped out of main memory and onto disk.
The Linux kernel is reported susceptible to a local denial of service vulnerability when handling locked memory pages. This issue is due to a failure of the kernel to properly enforce defined limits to the 'mlockall()' system call.
This vulnerability is reported to exist in versions 2.6.9 and 2.6.10 of the Linux kernel.
43. Linux Kernel SCSI IOCTL Integer Overflow Vulnerability
BugTraq ID: 12198
Remote: No
Date Published: Jan 07 2005
Relevant URL: http://www.securityfocus.com/bid/12198
Summary:
The Linux Kernel is reported prone to a local integer overflow vulnerability. The issue occurs in the 'sg_scsi_ioctl' function of the 'scsi_ioctl.c' kernel driver.
The vulnerability exists due to a lack of sufficient sanitization performed on user-controlled integer values before these values are employed as the size argument of a user-land to kernel memory copy operation.
This vulnerability may be leveraged to corrupt kernel memory and ultimately execute arbitrary code with ring-0 privileges. Alternatively, the issue may be exploited to trigger a kernel panic or to disclose contents of kernel memory.
It is reported that a user must have access to the respective SCSI devices in order to exploit this issue. This may hinder exploitability.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Netizens eye Web-enabled surveillance cams
By: Kevin Poulsen
The whole world is watching.
http://www.securityfocus.com/news/10251
2. Sims 2 hacks spread like viruses
By: Kevin Poulsen
If kitchen appliances and other household objects are exhibiting strange behavior in your virtual home, you may have unknowingly picked up hacked code from the official Sims 2 website. What's more, you may have spread it.
http://www.securityfocus.com/news/10232
3. Groups fight Internet wiretap push
By: Kevin Poulsen
Industry and advocacy groups challenge the FBI to prove it's having problems spying on broadband and VoIP users.
http://www.securityfocus.com/news/10192
4. MS virus clean-up tool sparks controversy
By: John Leyden, The Register
Microsoft debuts a malicious software removal tool today. It represents the first tangible fruits of Microsoft's June 2003 acquisition of Romanian anti-virus firm GeCAD Software.
http://www.securityfocus.com/news/10261
5. Vital Files Exposed In GMU Hacking
By: Jonathan Krim, Washington Post
http://www.securityfocus.com/news/10259
6. Exploit code attacks unpatched IE bug
By: John Leyden, The Register
Code which exploits a vulnerability in the HTML Help control of Internet Explorer has been released onto the net.
http://www.securityfocus.com/news/10254
IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Azure Web Log 1.5
By: Azure Desktop
Relevant URL: http://www.azuredesktop.com/download/awlog.zip
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
Log analyzer tells you all you want about your web site: What are the most popular pages and files on your site? How many visitors are there and where are they from? What browsers and OS they use? What is your sites traffic? Special features:Statistics for a year. Separate statistics for every page or file - daily hits for two last months, monthly hits for a year, referring site for particular page or file. Multiple site statistics support.
2. Interface Traffic Indicator 1.2.3
By: Carsten Schmidt
Relevant URL: http://software.ccschmidt.de/#inftraffic
Platforms: Windows 2000, Windows NT, Windows XP
Summary:
Interface Traffic Indicator, a graph utility to measure incoming and outgoing traffic on an interface in bits/sec, bytes/sec or utilization. Works on all SNMP-capable devices (computers, NICs, switches, routers, etc.) with adjustable poll intervall down to three seconds. You can use this programm in a professional network environment to monitor selected network interfaces (even backplane ports if the device provides the information) or you can monitor your home network or
3. Colasoft Capsa 4.05
By: Roy Luo
Relevant URL: http://www.colasoft.com/
Platforms: Windows 2000, Windows 95/98, Windows XP
Summary:
Capsa is a powerful but easy to use network monitor and analyzer designed for packet decoding and network diagnosis. With the abilities of real time monitoring and data analyzing, you can capture and decode network traffic transmitted over local host and local network. Capsa has Packet Analysis Module and three advanced analysis modules: Email Analysis Module, Web Analysis Module and Transaction Analysis Module.
4. Attack Tool Kit (ATK) 3.0
By: Marc Ruef
Relevant URL: http://www.computec.ch/projekte/atk/
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
The Attack Tool Kit (ATK) is an open-source utility to realize penetration tests and enhance security audits. The most important changes in ATK 3.0 are the introduction of a dedicated exploiting routine and the Plugin AutoUpdate (over HTTP).
5. One-Time Password Generator 1.0
By: Marcin Simonides
Relevant URL: http://marcin.studio4plus.com/en/otpgen/
Platforms: Java
Summary:
A One-Time Password Generator for Java-enabled mobile phones. The interface has been designed to minimize the number of necessary keypresses.
6. tenshi 0.3.2
By: Andrea Barisani
Relevant URL: http://tenshi.gentoo.org/
Platforms: Perl (any system supporting perl)
Summary:
tenshi is a log monitoring program, designed to watch a log file for lines matching user defined regular expressions and report on the matches. The regular expressions are assigned to queues which have an alert interval and a list of mail recipients.
Queues can be set to send a notification as soon as there is a log line assigned to it, or to send periodic reports.
V. SECURITYJOBS LIST SUMMARY
----------------------------
1. [SJ-JOB] Security Engineer, Bethesda, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386412
2. [SJ-JOB] Security Engineer, Fairfax, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386367
3. [SJ-JOB] MOD CLAS Consultant, Surrey, GB (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386365
4. [SJ-JOB] Jr. Security Analyst, Centreville, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386361
5. [SJ-JOB] Auditor, Detroit, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386356
6. [SJ-JOB] Auditor, Cleveland, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386353
7. [SJ-JOB] Channel / Business Development, New York (E... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386352
8. [SJ-JOB] Forensics Engineer, London, GB (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386351
9. [SJ-JOB] Sales Engineer, St. Louis, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386273
10. [SJ-JOB] Security Researcher, Atlanta, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386271
11. [SJ-JOB] Sales Engineer, Parsippany, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386268
12. [SJ-JOB] Application Security Engineer, Seattle, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386265
13. [SJ-JOB] Account Manager, Chicago- Mid West, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386257
14. [SJ-JOB] Management, Palm Beach, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386183
15. [SJ-JOB] Incident Handler, Jersey City, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386182
16. [SJ-JOB] Compliance Officer, Miami, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386181
17. [SJ-JOB] Account Manager, Long Island City, NYC, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386180
18. [SJ-JOB] Account Manager, Washington, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386179
19. [SJ-JOB] Security Engineer, Pompano Beach, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386173
20. [SJ-JOB] Manager, Information Security, Boca Raton, ... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386172
21. [SJ-JOB] Manager, Information Security, Jersey City,... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386171
22. [SJ-JOB] Application Security Engineer, Amsterdam, N... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386080
23. [SJ-JOB] Regional Channel Manager, London, GB (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386079
24. [SJ-JOB] Application Security Engineer, Zurich or Be... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386076
25. [SJ-JOB] Sr. Product Manager, Sunnyvale, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386075
26. [SJ-JOB] Security Consultant, Munich or Frankfurt, D... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386074
27. [SJ-JOB] Developer, San Antonio, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386073
28. [SJ-JOB] Security Engineer, Mountain View, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386071
29. [SJ-JOB] Sales Engineer, New York City, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386069
30. [SJ-JOB] Security Consultant, Amsterdam, NL (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386068
31. [SJ-JOB] Regional Channel Manager, Tokyo, JP (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386066
32. [SJ-JOB] Sales Representative, New York City, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386065
33. [SJ-JOB] Technical Support Engineer, Seattle, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386000
34. [SJ-JOB] Regional Channel Manager, Brasilia, BR (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/385993
35. [SJ-JOB] Security Consultant, Charlotte, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/385992
36. [SJ-JOB] Regional Channel Manager, Sarmiento, AR (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/385990
37. [SJ-JOB] Security Auditor, Milwaukee, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/385989
38. [SJ-JOB] Channel / Business Development, Suburbs of ... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/385988
39. [SJ-JOB] Jr. Security Analyst, Reston, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/385987
40. [SJ-JOB] Evangelist, palo alto, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/385986
41. [SJ-JOB] Information Assurance Engineer, Mountain Vi... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/385985
42. [SJ-JOB] Security System Administrator, Mountain Vie... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/385984
43. [SJ-JOB] Sr. Product Manager, San Diego, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/385983
44. [SJ-JOB] Sr. Product Manager, San Jose, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/385982
VI. INCIDENTS LIST SUMMARY
--------------------------
1. IE Malware / Spyware Control Methods (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/386609
2. analysis of Troj/Winser-A (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/386337
3. DoS attack... what to do? (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/386336
4. SQL injection worm ? (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/386170
5. Botnet is back, and some info FYI. (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/386160
VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Run-time errors and JIT debuggers (Thread)
Relevant URL:
http://www.securityfocus.com/archive/82/386489
2. NetDDE (Thread)
Relevant URL:
http://www.securityfocus.com/archive/82/386488
3. Contest for a trip to CanSecWest/core05 (Thread)
Relevant URL:
http://www.securityfocus.com/archive/82/386487
4. ndisasm bad opcodes interpretation (Thread)
Relevant URL:
http://www.securityfocus.com/archive/82/386440
VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. Anti-spyware Beta from Microsoft available (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/386667
2. suggestions for proxy server to run on w2003 box.. ... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/386655
3. suggestions for proxy server to run on w2003 box.. ... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/386647
4. suggestions for proxy server to run on w2003 box.. (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/386613
5. Windows Update Services (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/386423
6. XP SP2 Blind install (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/386398
7. services running in windows domain (winXP clients) (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/386094
8. SecurityFocus Microsoft Newsletter #222 (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/386034
IX. SUN FOCUS LIST SUMMARY
--------------------------
NO NEW POSTS FOR THE WEEK 2005-01-04 to 2005-01-11.
X. LINUX FOCUS LIST SUMMARY
---------------------------
1. NMAP : Different interpretation of "filtered" ports ... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/386668
2. ipv6, again (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/386225
3. CAN-2004-1137 (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/386222
4. firewall 1.4 (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/386064
XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XII. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored By: SPI Dynamics
ALERT: ARE YOU VULNERABLE TO A 'SQL INJECTION' ATTACK?-FREE Product Trial
Firewalls, IDS and Access Controls don't stop these attacks because hackers
using the web application layer are NOT seen as intruders. Test your web
application for over 4,100 vulnerabilities and attack methodologies with
our FREE WebInspect 15 day download trial!
http://www.securityfocus.com/sponsor/SPIDynamics_sf-news_050111
------------------------------------------------------------------------
Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!
http://www.securityfocus.com/sponsor/Symantec_sf-news_041130
------------------------------------------------------------------------