SecurityFocus Newsletter #284
Peter Laborge <[email protected]> 18 Jan 2005 23:56:40 -0000
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #284
------------------------------
This Issue is Sponsored By: RSA
RSA Conference 2005
The RSA Conference is the most prestigious information security event of
the year! This is the authoritative source for uncovering new ways to
thwart cyber-criminals. Learn. Network. Grow. RSA Conference 2005 takes
place February 14 to 18, 2005 in San Francisco.
http://www.securityfocus.com/sponsor/RSA_sf-news_050118
------------------------------------------------------------------------
Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!
http://www.securityfocus.com/sponsor/Symantec_sf-news_041130
------------------------------------------------------------------------
I. FRONT AND CENTER
1. A New Tool In The Spam War
2. The Perils of Deep Packet Inspection
3. Apache 2 with SSL/TLS: Step-by-Step, Part 1
II. BUGTRAQ SUMMARY
1. WoltLab Burning Board Lite Form Mail Script Cross-Site Scrip...
2. Debian Liantian Insecure Temporary File Vulnerability
3. Dillo Interface Message Format String Vulnerability
4. Invision Community Blog EID Parameter SQL Injection Vulnerab...
5. Zeroboard DIR Parameter Remote File Include Vulnerabilities
6. PHPWind Board Remote File Include Vulnerability
7. Linux IPRoute2 Netbug Script Insecure Temporary File Creatio...
8. PRADO Page Parameter Remote File Include Vulnerability
9. JohnyTech Encrypted Messenger Plug-In Remote Denial Of Servi...
10. RhinoSoft Serv-U FTP Server Resource Exhaustion Denial Of Se...
11. WoltLab Burning Board Lite ADDENTRY.PHP SQL Injection Vulner...
12. BottomLine Webseries Payment Application Access Control Bypa...
13. Apache mod_auth_radius Malformed RADIUS Server Reply Integer...
14. MPG123 Layer 2 Frame Header Heap Overflow Vulnerability
15. VideoDB Unspecified SQL Injection Vulnerability
16. Squid Proxy Malformed NTLM Type 3 Message Remote Denial of S...
17. VideoDB Unspecified HTML Injection Vulnerability
18. SquirrelMail Vacation Plugin FTPFile Input Validation Vulner...
19. Microsoft Office Encrypted Documents RC4 Initialization Vect...
20. VideoDB Unauthorized Access Vulnerability
21. SCO UnixWare NFS Mountd Denial of Service Vulnerability
22. Gracebyte Network Assistant Remote Denial Of Service Vulnera...
23. HylaFAX Remote Access Control Bypass Vulnerability
24. Microsoft Windows Indexing Service Buffer Overflow Vulnerabi...
25. BMV Insecure Temporary File Vulnerability
26. Guestserver Path Disclosure Vulnerability
27. Bottomline Technologies WebSeries Design Error Vulnerabiliti...
28. Guestserver HTML Injection Vulnerability
29. Microsoft Windows User32.DLL ANI File Header Handling Stack-...
30. Mozilla/Netscape/Firefox Browser Modal Dialog Spoofing Vulne...
31. Spectrum Cash Receipting System Weak Local Password Encrypti...
32. eMotion MediaPartner Enterprise Multiple Vulnerabilities
33. Apple ITunes Playlist Buffer Overflow Vulnerability
34. Linux Kernel Multiple Unspecified Vulnerabilities
35. POP Password Changer Unauthorized Password Change Vulnerabil...
36. Deutsche Telekom Teledat 530 DSL Router Port 515 Remote Deni...
37. GNU Mailman Multiple Unspecified Remote Vulnerabilities
38. Linux Kernel Symmetrical Multiprocessing Page Fault Local Pr...
39. Nullsoft Winamp Multiple Unspecified Vulnerabilities
40. Dokeos Course Description Multiple Remote HTML Injection Vul...
41. Helvis Multiple Local Vulnerabilities
42. BiTBOARD IMG BBCode Tag JavaScript Injection Vulnerability
43. SGallery Module For PHPNuke SQL Injection Vulnerability
44. OpenBSD TCP Timestamp Remote Denial Of Service Vulnerability
45. OpenBSD HTTPD mod_include Local Buffer Overflow Vulnerabilit...
46. IlohaMail Insecure Default Installation Information Disclosu...
47. Vim TCLTags and VimSpell.sh Scripts Insecure Temporary File ...
48. University of Minnesota Gopher Multiple Remote Vulnerabiliti...
49. Horde Multiple Cross-Site Scripting Vulnerabilities
50. ForumKIT MEMBERS Parameter Cross-Site Scripting Vulnerabilit...
51. Zeroboard Multiple File Disclosure Vulnerabilities
52. Zeroboard Print_Category.PHP Remote File Include Vulnerabili...
53. SGI InPerson Local Privilege Escalation Vulnerability
54. Sun Solaris Management Console User Interface Insecure Accou...
55. Linux Kernel User Triggerable BUG() Unspecified Local Denial...
56. Brat Designs Breed Remote Denial of Service Vulnerability
57. Midnight Commander Multiple Unspecified Vulnerabilities
58. Microsoft Internet Explorer Dynamic IFRAME File Download Sec...
59. MySQL MaxDB WebAgent WebSQL Password Parameter Remote Buffer...
60. MPM Guestbook Header Input Validation Vulnerability
61. Siteman Page Parameter Cross-Site Scripting Vulnerability
62. Exim IP Address Command Line Argument Local Buffer Overflow ...
63. Multiple Vendor Anti-Virus Gateway Failure To Decode Base64 ...
III. SECURITYFOCUS NEWS ARTICLES
1. FBI retires its Carnivore
2. Hacker penetrates T-Mobile systems
3. Netizens eye Web-enabled surveillance cams
4. Symantec outlines plans for Veritas
5. Man charged with DDoS attacks after U.S.-British inquiry
6. Panix recovers from domain hijack
IV. SECURITYFOCUS TOP 6 TOOLS
1. Firestarter 1.0.0
2. Network Equipment Performance Monitor 2.2
3. Etherchange v1.0
4. BitDefender for qmail v1.5.5-2
5. Bilbo 0.11
6. IPFront 1.0
V. SECURITYJOBS LIST SUMMARY
1. [SJ-JOB] Sr. Security Analyst, Leeds, GB (Thread)
2. [SJ-JOB] CHECK Team Leader, London, GB (Thread)
3. [SJ-JOB] Management, Fremont, US (Thread)
4. [SJ-JOB] Sr. Security Engineer, Elgin, US (Thread)
5. [SJ-JOB] Developer, Boulder, US (Thread)
6. [SJ-JOB] Sales Engineer, Boston, US (Thread)
7. [SJ-JOB] Information Assurance Analyst, Newington, U... (Thread)
8. [SJ-JOB] Security Architect, Madison, US (Thread)
9. [SJ-JOB] Certification & Accreditation Engineer, Cha... (Thread)
10. [SJ-JOB] Sr. Security Analyst, Seattle, US (Thread)
11. [SJ-JOB] Sales Representative, Washington, US (Thread)
12. [SJ-JOB] Security Engineer, Arlington, US (Thread)
13. [SJ-JOB] Chief Security Strategist, Southwest suburb... (Thread)
14. [SJ-JOB] Security Consultant, UK Wide - ONLY EEC Nat... (Thread)
15. [SJ-JOB] Security Engineer, Boston, US (Thread)
16. [SJ-JOB] Channel / Business Development, Redwood Cit... (Thread)
17. [SJ-JOB] Channel / Business Development, Santa Clara... (Thread)
18. [SJ-JOB] Security Consultant, various south east and... (Thread)
19. [SJ-JOB] Security Consultant, Bangalore, IN (Thread)
20. [SJ-JOB] Security Engineer, Lyndhurst, US (Thread)
21. [SJ-JOB] Application Security Engineer, SF Bay Area,... (Thread)
22. [SJ-JOB] Security Consultant, Montreal, CA (Thread)
23. [SJ-JOB] CSO, Washington, US (Thread)
24. [SJ-JOB] Security Auditor, Saint Louis, US (Thread)
25. [SJ-JOB] Application Security Engineer, Toronto, CA (Thread)
26. [SJ-JOB] Security System Administrator, Baltimore, U... (Thread)
27. [SJ-JOB] Security Product Marketing Manager, Boston,... (Thread)
28. [SJ-JOB] Information Assurance Engineer, Clarksburg,... (Thread)
29. [SJ-JOB] VP of Regional Sales, Greater Boston Area, ... (Thread)
30. [SJ-JOB] Security Architect, Arlington, US (Thread)
31. [SJ-JOB] Sales Representative, Fremont, US (Thread)
32. [SJ-JOB] Instructor, Various Locations, US (Thread)
33. [SJ-JOB] Developer, McLean, US (Thread)
34. [SJ-JOB] Manager, Information Security, Seymour, US (Thread)
35. [SJ-JOB] Sales Engineer, London, GB (Thread)
36. [SJ-JOB] Security Consultant, Englewood, US (Thread)
37. [SJ-JOB] Application Security Engineer, London, GB (Thread)
38. [SJ-JOB] Forensics Engineer, McLean, US (Thread)
39. [SJ-JOB] Auditor, Washington, DC, US (Thread)
40. [SJ-JOB] Account Manager, Toronto, CA (Thread)
41. [SJ-JOB] Manager, Information Security, Hartford Are... (Thread)
42. [SJ-JOB] Sr. Security Analyst, Atlanta, US (Thread)
43. [SJ-JOB] Manager, Information Security, Jersey City,... (Thread)
44. [SJ-JOB] Security Engineer, Rockville , US (Thread)
45. [SJ-JOB] Developer, Seattle, US (Thread)
46. [SJ-JOB] Sr. Security Engineer, Jersey City, US (Thread)
47. [SJ-JOB] Security Architect, Santa Monica, US (Thread)
48. [SJ-JOB] Chief Security Strategist, Santa Monica, US (Thread)
49. [SJ-JOB] Sales Representative, NYC, US (Thread)
50. [SJ-JOB] Sr. Security Engineer, Phoenix, US (Thread)
VI. INCIDENTS LIST SUMMARY
1. DoS attack... what to do? (Thread)
2. IE Malware / Spyware Control Methods (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
NO NEW POSTS FOR THE WEEK 2005-01-11 to 2005-01-18.
VIII. MICROSOFT FOCUS LIST SUMMARY
1. local admin vs group policy and apps... (Thread)
2. IIS6 on W2k3 DCs (Thread)
3. PGP and Outlook (Thread)
4. Automatic Updates and Users/Power Users (Thread)
5. Anti-spyware Beta from Microsoft available (Thread)
6. NTFS Security (Thread)
7. XP SP2 Blind install (Thread)
8. SecurityFocus Microsoft Newsletter #223 (Thread)
9. suggestions for proxy server to run on w2003 box.. (Thread)
IX. SUN FOCUS LIST SUMMARY
NO NEW POSTS FOR THE WEEK 2005-01-11 to 2005-01-18.
X. LINUX FOCUS LIST SUMMARY
1. NMAP : Different interpretation of "filtered" ports ... (Thread)
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. A New Tool In The Spam War
Arbitration is part of the next wave of security measures, and can be
effective against spammers who illegally harvest email addresses from a
honeypot on your website.
http://www.securityfocus.com/columnists/291
2. The Perils of Deep Packet Inspection
By Dr. Thomas Porter
This paper looks at the evolution of firewall technology towards Deep
Packet Inspection, and then discusses some of the security issues with this
evolving technology.
http://www.securityfocus.com/infocus/1817
3. Apache 2 with SSL/TLS: Step-by-Step, Part 1
By Artrur Maj
This article begins a series of three articles dedicated to configuring
Apache 2.0 with SSL/TLS support, in order to ensure maximum security and
optimal performance of secure web communication. This part introduces key
aspects of SSL/TLS and then shows how to compile and configure Apache 2.0
with support for these protocols.
http://www.securityfocus.com/infocus/1818
II. BUGTRAQ SUMMARY
-------------------
1. WoltLab Burning Board Lite Form Mail Script Cross-Site Scrip...
BugTraq ID: 12199
Remote: Yes
Date Published: Jan 08 2005
Relevant URL: http://www.securityfocus.com/bid/12199
Summary:
WoltLab Burning Board Lite is prone to a cross-site scripting vulnerability. The cause of the vulnerability is that user-supplied data in the form of HTML and script code is not sufficiently sanitized before being output in dynamically generated Web pages.
An attacker could exploit this issue by enticing a Web user into following a malicious link that contains hostile HTML and script code. This may allow for theft of cookie-based authentication credentials or other attacks.
2. Debian Liantian Insecure Temporary File Vulnerability
BugTraq ID: 12202
Remote: No
Date Published: Jan 10 2005
Relevant URL: http://www.securityfocus.com/bid/12202
Summary:
The Debian lintian program creates temporary files in an insecure manner. A local attacker could exploit this condition to launch symbolic link attacks to cause arbitrary files to be deleted in the context of the user running the program.
3. Dillo Interface Message Format String Vulnerability
BugTraq ID: 12203
Remote: Yes
Date Published: Jan 09 2005
Relevant URL: http://www.securityfocus.com/bid/12203
Summary:
Dillo Web browser is prone to a format string vulnerability. This issue is exposed when the browser handles messages to the interface.
The vulnerability may be triggered when a user visits a malicious Web page. If successfully exploited, this will result in execution of arbitrary code in the context of the client user.
4. Invision Community Blog EID Parameter SQL Injection Vulnerab...
BugTraq ID: 12205
Remote: Yes
Date Published: Jan 09 2005
Relevant URL: http://www.securityfocus.com/bid/12205
Summary:
Invision Community Blog is reported prone to SQL injection attacks. User-supplied input supplied through the 'eid' URI parameter is used in a database query without sufficient sanitization.
An attacker may leverage this issue to manipulate SQL query strings and potentially carry out arbitrary database queries. This may facilitate the disclosure or corruption of sensitive database information.
All versions of Invision Community Blog are considered vulnerable to this issue.
5. Zeroboard DIR Parameter Remote File Include Vulnerabilities
BugTraq ID: 12206
Remote: Yes
Date Published: Jan 10 2005
Relevant URL: http://www.securityfocus.com/bid/12206
Summary:
Multiple remote file include vulnerabilities affect Zeroboard. These issues are due to a failure of the application to properly sanitize user-supplied input through the 'dir' parameter prior to using it in a PHP 'include()' function call.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
All versions of Zeroboard are considered vulnerable at the moment.
6. PHPWind Board Remote File Include Vulnerability
BugTraq ID: 12207
Remote: Yes
Date Published: Jan 09 2005
Relevant URL: http://www.securityfocus.com/bid/12207
Summary:
A remote file include vulnerability affects PHPWind Board. This issue is due to a failure of the application to properly sanitize user-supplied input prior to using it in a PHP 'include()' function call.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
PHPWind Board 1.3.6 and prior versions are vulnerable to this issue.
7. Linux IPRoute2 Netbug Script Insecure Temporary File Creatio...
BugTraq ID: 12208
Remote: No
Date Published: Jan 10 2005
Relevant URL: http://www.securityfocus.com/bid/12208
Summary:
iproute2 is distributed with a script named 'netbug'. The 'netbug' script is reported prone to an unspecified insecure temporary file creation vulnerability.
It is conjectured that the 'netbug' script creates a temporary file using a predictable filename in a world read-writeable location. This issue may be leveraged to corrupt arbitrary files with the privileges of a user that invokes the vulnerable script.
8. PRADO Page Parameter Remote File Include Vulnerability
BugTraq ID: 12209
Remote: Yes
Date Published: Jan 10 2005
Relevant URL: http://www.securityfocus.com/bid/12209
Summary:
A remote file include vulnerability affects PRADO. This issue is due to a failure of the application to properly sanitize user-supplied input prior to using it in a PHP 'include()' function call.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
9. JohnyTech Encrypted Messenger Plug-In Remote Denial Of Servi...
BugTraq ID: 12211
Remote: Yes
Date Published: Jan 10 2005
Relevant URL: http://www.securityfocus.com/bid/12211
Summary:
JohnyTech Encrypted Messenger Plug-in is reported prone to a remote denial of service vulnerability. The vulnerability presents itself when certain strings are processed by the vulnerable library.
A remote attacker may exploit this condition to deny service to legitimate users.
10. RhinoSoft Serv-U FTP Server Resource Exhaustion Denial Of Se...
BugTraq ID: 12213
Remote: Yes
Date Published: Jan 10 2005
Relevant URL: http://www.securityfocus.com/bid/12213
Summary:
Serv-U FTP Server is reported prone to a remote denial of service vulnerability. This issue may allow remote attackers to crash an affected server.
It is reported that the vulnerable service does not properly handle multiple connection attempts. Successful exploitation can deny service to legitimate users.
Serv-U FTP 2.5 is reported prone to this vulnerability.
11. WoltLab Burning Board Lite ADDENTRY.PHP SQL Injection Vulner...
BugTraq ID: 12214
Remote: Yes
Date Published: Jan 10 2005
Relevant URL: http://www.securityfocus.com/bid/12214
Summary:
WoltLab Burning Board Lite is reported prone to an SQL injection vulnerability. The vulnerability exists in the 'addentry.php' script.
An attacker may leverage this issue to manipulate SQL query strings and potentially carry out arbitrary database queries. This may facilitate the disclosure or corruption of sensitive database information.
This issue reportedly affects WoltLab Burning Board Lite 1.0 Gold and 1.1.1e. It is possible that other versions are affected as well.
12. BottomLine Webseries Payment Application Access Control Bypa...
BugTraq ID: 12216
Remote: Yes
Date Published: Jan 10 2005
Relevant URL: http://www.securityfocus.com/bid/12216
Summary:
BottomLine Webseries Payment Application is reported prone to an access control bypass vulnerability. It is reported that any authenticated user may access all of the privileged and restricted scripts by requesting the scripts directly using a URI.
13. Apache mod_auth_radius Malformed RADIUS Server Reply Integer...
BugTraq ID: 12217
Remote: Yes
Date Published: Jan 10 2005
Relevant URL: http://www.securityfocus.com/bid/12217
Summary:
mod_auth_radius is reported prone to an integer overflow vulnerability. This issue is due to an error in the application when handling server-supplied integer values before these values are employed as the size argument in a subsequent memory copy operation.
To exploit this vulnerability, an attacker must control a RADIUS server or intercept network traffic and send spoofed RADIUS replies to the Apache server. Successful exploitation may result in memory corruption and allow for arbitrary code execution.
All versions of mod_auth_radius are considered vulnerable at the moment.
14. MPG123 Layer 2 Frame Header Heap Overflow Vulnerability
BugTraq ID: 12218
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12218
Summary:
mpg123 is prone to a heap-based buffer overflow vulnerability related to handling of layer 2 streams. This issue is exposed when the player loads MP2/MP3 files with malformed header data.
This vulnerability could be exploited to execute arbitrary code in the context of the user running the player.
15. VideoDB Unspecified SQL Injection Vulnerability
BugTraq ID: 12219
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12219
Summary:
VideoDB is reportedly affected by an unspecified SQL injection vulnerability. This is due to the application failing to properly sanitize user-supplied input before being used in an SQL query.
Successful exploitation could result in compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
The vendor has not released very many details about the vulnerability except VideoDB versions 2.0.0 and prior are affected. They have also released VideoDB 2.0.2 which reportedly addresses the issue.
16. Squid Proxy Malformed NTLM Type 3 Message Remote Denial of S...
BugTraq ID: 12220
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12220
Summary:
Squid is reported to be susceptible to a denial of service vulnerability in its NTLM authentication module. This vulnerability presents itself when an attacker sends a malformed NTLM type 3 message to Squid.
Failure of NTLM authentication would result in the Squid application denying access to legitimate users of the proxy.
This vulnerability affects Squid 2.5.
17. VideoDB Unspecified HTML Injection Vulnerability
BugTraq ID: 12221
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12221
Summary:
VideoDB version 2.0.0 and earlier are reportedly affected by an unspecified HTML injection vulnerability. This is due to the application failing to properly sanitize user-supplied input prior to including it in dynamically generated content.
The attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user, other attacks are also possible.
18. SquirrelMail Vacation Plugin FTPFile Input Validation Vulner...
BugTraq ID: 12222
Remote: No
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12222
Summary:
The SquirrelMail Vacation plugin is prone to an input validation vulnerability. This issue exists in the 'ftpfile' binary, which is installed with setuid root privileges.
It is reported that 'ftpfile' may allow local attackers to execute commands or read files with superuser privileges.
19. Microsoft Office Encrypted Documents RC4 Initialization Vect...
BugTraq ID: 12223
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12223
Summary:
Microsoft Office Word and Excel applications are reported prone to a security vulnerability. It is reported that the functionality that provides for password protecting confidential documents is flawed; specifically the RC4 stream cipher that is employed to obfuscate protected documents is implemented incorrectly.
An attacker that can retrieve an original encrypted document and subsequent encrypted modifications of said document may employ cryptanalysis techniques to potentially reveal portions of the target document.
Information gathered by exploiting this vulnerability may be used to aid in further attacks launched against a target victim.
20. VideoDB Unauthorized Access Vulnerability
BugTraq ID: 12224
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12224
Summary:
VideoDB is reportedly affected by a vulnerability regarding unauthorized access during database editing. This is due to the application failing to properly verify user permissions.
The vendor has reported that VideoDB version 2.0.0 and earlier are vulnerable. They have also released VideoDB 2.0.2 addressing this issue.
21. SCO UnixWare NFS Mountd Denial of Service Vulnerability
BugTraq ID: 12225
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12225
Summary:
SCO UnixWare is reported prone to a denial of service vulnerability. This issue may allow an attacker to exhaust excessive resources on a vulnerable computer.
The vulnerability arises when the mountd service is registered in inetd.conf. A local or remote attacker may initiate a NFS mount service request to trigger this vulnerability.
This issue affects UnixWare 7.1.1, 7.1.3, and 7.1.4.
22. Gracebyte Network Assistant Remote Denial Of Service Vulnera...
BugTraq ID: 12226
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12226
Summary:
Network Assistant is reportedly affected by a remote denial of service vulnerability. This is due to the application failing to properly handle malformed UDP datagrams.
A malicious user could exploit this vulnerability to crash the vulnerable software. It is reported that exploitation of this vulnerability can only occur from a computer on the local network.
23. HylaFAX Remote Access Control Bypass Vulnerability
BugTraq ID: 12227
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12227
Summary:
The HylaFAX daemon is reported prone to a vulnerability that could allow unauthorized access to the HylaFAX service. It is reported that the issue presents itself due to the methods used to match a given username and hostname to an entry in the 'hosts.hfaxd' configuration file.
A remote attacker may exploit this vulnerability to gain unauthorized access to the affected service.
24. Microsoft Windows Indexing Service Buffer Overflow Vulnerabi...
BugTraq ID: 12228
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12228
Summary:
Microsoft Indexing Service is reported prone to a buffer overflow vulnerability. This issue results from insufficient boundary checks performed by the application when copying user-supplied data in to sensitive process buffers. A remote or local attacker may execute arbitrary code on a vulnerable computer, which could ultimately allow the attacker to gain unauthorized access to the computer or gain elevated privileges.
This issue can be exploited by sending a malformed query to the Indexing Service. It is reported that issue may be locally and remotely exploited, if Indexing Service is enabled on a vulnerable computer.
25. BMV Insecure Temporary File Vulnerability
BugTraq ID: 12229
Remote: No
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12229
Summary:
BMV creates temporary files in an insecure manner. A local attacker could take advantage of this issue to perform symbolic link attacks and corrupt files in the context of the user running the application.
It is not known if this vulnerability could be exploited to gain elevated privileges, though at the very least an attacker could cause critical files to be overwritten, causing loss of data or a denial of service condition.
26. Guestserver Path Disclosure Vulnerability
BugTraq ID: 12230
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12230
Summary:
Guestserver is reportedly affected by a path disclosure vulnerability. This issue would permit a malicious user to expose the root path of the affected application.
Guestserver version 5 is reported vulnerable; earlier versions may also be affected.
27. Bottomline Technologies WebSeries Design Error Vulnerabiliti...
BugTraq ID: 12231
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12231
Summary:
WebSeries is an enterprise payment system with web-based functionality that is produced by Bottomline Technologies.
It has been reported that WebSeries is affected by four security issues, all of which appear to be due to design oversights.
28. Guestserver HTML Injection Vulnerability
BugTraq ID: 12232
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12232
Summary:
Guestserver is reportedly vulnerable to an HTML injection vulnerability. This is due to the application failing to properly sanitize user-supplied input.
The attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user, other attacks are also possible.
29. Microsoft Windows User32.DLL ANI File Header Handling Stack-...
BugTraq ID: 12233
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12233
Summary:
A stack-based buffer overflow vulnerability is reported to affect the ANI (animated cursor files) handler on Microsoft Windows operating systems.
The vulnerability exists in the ANI file header handling routines contained in the 'user32.dll' library.
Ultimately the issue may be leveraged to force the execution of attacker-supplied instructions. It has been reported that this vulnerability affects any application that employs the vulnerable Internet Explorer component, for example:
Microsoft Internet Explorer, Word, Excel, PowerPoint, Outlook, Outlook Express and the Windows Shell.
Other applications are also affected.
30. Mozilla/Netscape/Firefox Browser Modal Dialog Spoofing Vulne...
BugTraq ID: 12234
Remote: Yes
Date Published: Jan 10 2005
Relevant URL: http://www.securityfocus.com/bid/12234
Summary:
Mozilla, Firefox, and Netscape Web browsers are reported prone to a vulnerability that may conceal modal dialogs by covering them with a pop-up window.
Download or security dialogs may be obscured by the use of JavaScript that places a specially crafted pop-up window that is directly placed on top of the dialog. This may induce a user into trusting the spoofed dialogs and taking further action based on this false sense of trust.
This issue was reported to affect Windows versions of the browsers.
31. Spectrum Cash Receipting System Weak Local Password Encrypti...
BugTraq ID: 12235
Remote: No
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12235
Summary:
The Spectrum Cash Receipting System stores passwords in a local file for offline access. Passwords stored in this file are encrypted using a weak algorithm. Passwords for all users of the system are also stored in this file, allowing enumeration of user accounts.
This issue was reported to affect Spectrum Cash Receipting System 6.406.08, however, other versions are likely affected.
32. eMotion MediaPartner Enterprise Multiple Vulnerabilities
BugTraq ID: 12236
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12236
Summary:
MediaPartner Enterprise Web server is reported prone to multiple vulnerabilities. These issues can allow remote attackers to disclose sensitive information, carry out directory traversal and cross-site scripting attacks, and gain administrative access to an affected server.
The following specific issues were identified:
An attacker can disclose sensitive scripts through the Web by sending a malformed HTTP GET request. This issue affects MediaPartner 5.0 and 5.1
An attacker can also disclose Web readable files by carrying out directory traversal attacks. This vulnerability is reported to affect MediaPartner 5.0. It may affect MediaPartner 5.1 as well, though this is not confirmed.
It is reported that an attacker can also execute arbitrary script code in a user's browser by carrying out cross-site scripting attacks. This vulnerability is reported to affect MediaPartner 5.0. It may affect MediaPartner 5.1 as well, though this is not confirmed.
The last vulnerability allows remote attackers to change users' password without proper authorization. This vulnerability is reported to affect MediaPartner 5.0. It may affect MediaPartner 5.1 as well, though this is not confirmed.
33. Apple ITunes Playlist Buffer Overflow Vulnerability
BugTraq ID: 12238
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12238
Summary:
Apple iTunes is prone to a buffer overflow vulnerability. This issue is exposed when the application parses 'm3u' and 'pls' playlist files. As these files may originate from an external source, this issue is considered remotely exploitable.
If the vulnerability is successfully exploited, it will result in execution of arbitrary code in the context of the user running the application.
34. Linux Kernel Multiple Unspecified Vulnerabilities
BugTraq ID: 12239
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12239
Summary:
It is reported that the Linux kernel version 2.6.9 is prone to multiple unspecified vulnerabilities. The issues are reported to exist in coda, xfs, network bridging, rose network protocol, and sdla wan drivers.
Details regarding the reported vulnerabilities are not currently available. It is conjectured that the issues are both local and remote in nature and result in a kernel panic when triggered. This is not confirmed.
This BID will be updated as soon as further details in regards to these vulnerabilities become available.
35. POP Password Changer Unauthorized Password Change Vulnerabil...
BugTraq ID: 12240
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12240
Summary:
poppassd_pam is reported prone to a vulnerability that may allow remote unauthorized users to change passwords. This issue can potentially allow an attacker to gain superuser privileges on a vulnerable computer.
Reportedly, the application does not check the validity of old passwords before changing a password.
poppassd_pam 1.0 is affected by this vulnerability.
36. Deutsche Telekom Teledat 530 DSL Router Port 515 Remote Deni...
BugTraq ID: 12241
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12241
Summary:
The Teledat 530 DSL router is reported prone to a remote denial of service vulnerability. The issue presents itself due to a failure to gracefully handle exceptional conditions. Specifically, it is reported that when the affected appliance handles unspecified character data on the service listening on port 515, the appliance will crash.
A remote attacker may exploit this vulnerability to deny service to legitimate users.
37. GNU Mailman Multiple Unspecified Remote Vulnerabilities
BugTraq ID: 12243
Remote: Yes
Date Published: Jan 11 2005
Relevant URL: http://www.securityfocus.com/bid/12243
Summary:
GNU Mailman is reported prone to multiple unspecified remote vulnerabilities. The following individual issues are reported:
It is reported that GNU Mailman package for Ubuntu and Debian Linux is affected by an information disclosure vulnerability.
Information that is harvested by exploiting this vulnerability may be used to aid in further attacks that are launched against a target user, or the computer that is hosting the vulnerable software.
A cross-site scripting vulnerability has been discovered in GNU Mailman. The issue occurs due to insufficient sanitization of user-supplied data.
It may be possible to exploit this issue in order to steal an unsuspecting user's cookie-based authentication credentials, as well as other sensitive information. Other attacks are also possible.
Finally, Mailman is reported prone to a weak auto-generated password vulnerability. It is reported that, when a user subscribes to a mailing list and a password is not specified, Mailman will auto-generate one. The password generation algorithm will generate a weak low entropy password. This password may potentially be brute forced by an attacker.
38. Linux Kernel Symmetrical Multiprocessing Page Fault Local Pr...
BugTraq ID: 12244
Remote: No
Date Published: Jan 12 2005
Relevant URL: http://www.securityfocus.com/bid/12244
Summary:
A local privilege escalation vulnerability affects the page fault handler of the Linux Kernel on symmetric multiprocessor (SMP) computers. This issue is due to a race condition error that may allow an attacker to gain superuser privileges.
A malicious local attacker may exploit this issue to gain superuser privileges on an the affected computer.
39. Nullsoft Winamp Multiple Unspecified Vulnerabilities
BugTraq ID: 12245
Remote: Yes
Date Published: Jan 12 2005
Relevant URL: http://www.securityfocus.com/bid/12245
Summary:
Winamp is a freely available media player from Nullsoft. It is available for the Microsoft Windows platform.
Multiple unspecified vulnerabilities affect Nullsoft's Winamp. The underlying causes of most of these issues are unknown, however one of the issues is due to a buffer overflow.
Further information surrounding these issues is not available. This BID will be updated immediately upon the release of more details.
It is likely that a remote attacker may leverage these issues by distributing malicious files and enticing unsuspecting users to process them. This may facilitate privilege escalation and unauthorized access.
40. Dokeos Course Description Multiple Remote HTML Injection Vul...
BugTraq ID: 12246
Remote: Yes
Date Published: Jan 12 2005
Relevant URL: http://www.securityfocus.com/bid/12246
Summary:
Multiple remote HTML injection vulnerabilities reportedly affect the course description functionality of Dokeos. These issues are due to a failure of the application to properly sanitize user-supplied form input prior to including it in dynamically generated Web content.
It should be noted that for an attacker to leverage this issue they must have privileges sufficient to add a course.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user; this may facilitate theft of cookie-based authentication credentials as well as other attacks.
41. Helvis Multiple Local Vulnerabilities
BugTraq ID: 12247
Remote: No
Date Published: Jan 12 2005
Relevant URL: http://www.securityfocus.com/bid/12247
Summary:
helvis is reported prone to multiple local vulnerabilities. The following individual issues are reported:
The 'elvprsv' utility is reported prone to an arbitrary file deletion vulnerability. It is reported that the 'elvprsv' utility is installed with setuid superuser privileges and therefore can be invoked by any user to delete arbitrary specified files on a vulnerable computer.
'elvprsv' is reported prone to a weak default permissions vulnerability on preserved emails that it generates. It is reported that emails preserved by the 'elvprsv' utility are written with insecure world readable permissions by default.
A local attacker may exploit this issue to disclose sensitive information that is contained in preserved files that are written by the affected utility.
Finally, it is reported that the helvis 'elvrec' utility may be used to disclose the contents of files that are preserved by 'elvprsv'.
A local attacker may exploit this issue to disclose sensitive information that is contained in preserved files that are written by the affected utility.
42. BiTBOARD IMG BBCode Tag JavaScript Injection Vulnerability
BugTraq ID: 12248
Remote: Yes
Date Published: Jan 12 2005
Relevant URL: http://www.securityfocus.com/bid/12248
Summary:
BiTBOARD is reported prone to a JavaScript injection vulnerability. It is reported that the BBCode 'IMG' tag is not sufficiently sanitized of malicious script content.
Injected code may be rendered in the web browser of a user who views vulnerable areas of the site. This would occur in the security context of the site hosting BiTBOARD.
43. SGallery Module For PHPNuke SQL Injection Vulnerability
BugTraq ID: 12249
Remote: Yes
Date Published: Jan 12 2005
Relevant URL: http://www.securityfocus.com/bid/12249
Summary:
SGallery is reported prone to SQL injection attacks. An attacker may leverage this issue to manipulate SQL query strings and potentially carry out arbitrary database queries. This may facilitate the disclosure or corruption of sensitive database information.
SGallery 1.01 is reported vulnerable to this issue.
44. OpenBSD TCP Timestamp Remote Denial Of Service Vulnerability
BugTraq ID: 12250
Remote: Yes
Date Published: Jan 13 2005
Relevant URL: http://www.securityfocus.com/bid/12250
Summary:
A remote denial of service vulnerability affects the TCP timestamp processing functionality of OpenBSD. This issue is due to a failure of the system to properly handle exceptional network data.
A remote attacker may leverage this issue to cause the kernel to panic on an affected computer, triggering a denial of service condition.
45. OpenBSD HTTPD mod_include Local Buffer Overflow Vulnerabilit...
BugTraq ID: 12251
Remote: No
Date Published: Jan 12 2005
Relevant URL: http://www.securityfocus.com/bid/12251
Summary:
OpenBSD httpd mod_include is reported prone to a local buffer overflow vulnerability. This issue arises because the application fails to perform boundary checks on user-supplied data before copying it in to sensitive process buffers. This issue may allow attackers to crash the server and potentially execute arbitrary code.
Specifically, this issue presents itself when a vulnerable server has the XBitHack directive or server-side includes functionality enabled.
A successful attack may result in a denial of service condition, however, it is conjectured that arbitrary code execution in the context of the httpd process may be possible as well.
46. IlohaMail Insecure Default Installation Information Disclosu...
BugTraq ID: 12252
Remote: Yes
Date Published: Jan 13 2005
Relevant URL: http://www.securityfocus.com/bid/12252
Summary:
An insecure default installation information disclosure issue affects IlohaMail. This issue is due to a failure of the application to install sensitive files securely.
An attacker may leverage this issue to gain access to sensitive information, potentially including user names and passwords. Sensitive information disclosed in this way may lead to a compromise of email accounts and other attacks.
47. Vim TCLTags and VimSpell.sh Scripts Insecure Temporary File ...
BugTraq ID: 12253
Remote: No
Date Published: Jan 13 2005
Relevant URL: http://www.securityfocus.com/bid/12253
Summary:
Multiple Vim scripts are reported prone to an insecure temporary file creation vulnerability. It is reported that the Vim 'tcltags' and 'vimspell.sh' scripts create temporary files in an insecure manner.
An attacker that has local interactive access to a system may exploit this issue to corrupt arbitrary files with the privileges of the user that is invoking the vulnerable application.
48. University of Minnesota Gopher Multiple Remote Vulnerabiliti...
BugTraq ID: 12254
Remote: Yes
Date Published: Jan 13 2005
Relevant URL: http://www.securityfocus.com/bid/12254
Summary:
Multiple remote vulnerabilities affect Gopher. These issues are due to a failure of the application to properly sanitize user-supplied data and a failure to verify input sizes.
The first issue is an integer overflow, the second issue is a format string vulnerability.
An attacker may leverage these issues to crash the affected daemon. These issues may also be leveraged to execute arbitrary code with the privileges of the gopherd process. This may facilitate unauthorized access.
49. Horde Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 12255
Remote: Yes
Date Published: Jan 13 2005
Relevant URL: http://www.securityfocus.com/bid/12255
Summary:
Multiple cross-site scripting vulnerabilities affect Horde. These issues are due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamically generated Web content.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
50. ForumKIT MEMBERS Parameter Cross-Site Scripting Vulnerabilit...
BugTraq ID: 12256
Remote: Yes
Date Published: Jan 13 2005
Relevant URL: http://www.securityfocus.com/bid/12256
Summary:
forumKIT is prone to a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input.
The problem presents itself when malicious HTML and script code is sent to the application through the 'members' parameter.
This vulnerability has been reported to exist in forumKIT 1.0.
51. Zeroboard Multiple File Disclosure Vulnerabilities
BugTraq ID: 12257
Remote: Yes
Date Published: Jan 13 2005
Relevant URL: http://www.securityfocus.com/bid/12257
Summary:
Zeroboard is reportedly affected by multiple file disclosure vulnerabilities. These issues are due to the application failing to properly sanitize user-supplied input to certain parameters. These issues could be exploited to retrieve sensitive information such as /etc/passwd. That information could then be used to enhance further attacks onto the underlying system.
52. Zeroboard Print_Category.PHP Remote File Include Vulnerabili...
BugTraq ID: 12258
Remote: Yes
Date Published: Jan 13 2005
Relevant URL: http://www.securityfocus.com/bid/12258
Summary:
Zeroboard is reportedly affected by a remote PHP file include vulnerability. This issue is due to the application failing to properly sanitize user-supplied input to 'print_category.php'.
Remote attackers could potentially exploit this issue via the 'dir' variable to include a remote malicious PHP script, which will be executed in the context of the Web server hosting the vulnerable software.
53. SGI InPerson Local Privilege Escalation Vulnerability
BugTraq ID: 12259
Remote: No
Date Published: Jan 14 2005
Relevant URL: http://www.securityfocus.com/bid/12259
Summary:
A local privilege escalation vulnerability affects SGI InPerson. This issue is due to a design error that causes the application to run with superuser privileges while trusting user-controlled environment variables.
An attacker may leverage this issue to gain superuser access to the affected computer.
54. Sun Solaris Management Console User Interface Insecure Accou...
BugTraq ID: 12260
Remote: Yes
Date Published: Jan 13 2005
Relevant URL: http://www.securityfocus.com/bid/12260
Summary:
An insecure account creation vulnerability affects the Sun Solaris Management Console (SMC) Graphical User Interface. This issue is due to a failure of the application to securely create accounts that have no password specified.
An attacker may exploit this issue to authenticate to an affected system using a user account configured for password aging that was created without a password using the affected tool.
55. Linux Kernel User Triggerable BUG() Unspecified Local Denial...
BugTraq ID: 12261
Remote: No
Date Published: Jan 13 2005
Relevant URL: http://www.securityfocus.com/bid/12261
Summary:
Linux Kernel is reported prone to a local denial of service vulnerability.
It is reported that this issue presents itself when a large Virtual Memory Area (VMA) is created by a user that overlaps with arg pages during the exec() system call.
Successful exploitation will lead to a denial of service condition in a vulnerable computer.
No further details are available at this time. This issue will be updated as more information becomes available.
56. Brat Designs Breed Remote Denial of Service Vulnerability
BugTraq ID: 12262
Remote: Yes
Date Published: Jan 13 2005
Relevant URL: http://www.securityfocus.com/bid/12262
Summary:
Breed is reported prone to a remote denial of service vulnerability.
It is reported that a game server may be crashed by sending an empty UDP packet.
All versions up to and including Breed patch 1 are reported prone to this issue.
57. Midnight Commander Multiple Unspecified Vulnerabilities
BugTraq ID: 12263
Remote: Unknown
Date Published: Jan 14 2005
Relevant URL: http://www.securityfocus.com/bid/12263
Summary:
It has been reported that Midnight Commander running on Debian operating systems is prone to multiple, unspecified vulnerabilities. These issues are due to various design and boundary condition errors.
These issues could be leveraged by an attacker to execute arbitrary code on an affected system, which may facilitate unauthorized access. It is also possible for an attacker to carry out symbolic link attacks against an affected system, potentially facilitating a system wide denial of service.
58. Microsoft Internet Explorer Dynamic IFRAME File Download Sec...
BugTraq ID: 12264
Remote: Yes
Date Published: Jan 13 2005
Relevant URL: http://www.securityfocus.com/bid/12264
Summary:
Microsoft Internet Explorer is reported prone to a file download security warning bypass weakness. This issue may be exploited to download a malicious file to the client system.
It is reported that this security warning can be bypassed by creating a document containing a specially crafted HTML BODY tag and a dynamic IFRAME.
By enticing a user to visit a site, the attacker can potentially plant malicious files on vulnerable systems in order to execute malicious code. It should be noted that although no security warning appears, the standard download confirmation widnow still appears and requires the user to confirm the download prior to any files being placed on the unsuspecting user's computer.
This vulnerability may be combined with other issues in the browser or the affected computer to aid in various attacks.
It should also be noted that Symantec has been unable to replicate this issue. Furthermore Microsoft has stated that this is not a vulnerability. This BID will be updated when further information becomes available.
Internet Explorer 6.0 running on Microsoft Windows XP SP2 is reported to be affected by this vulnerability. It is conjectured that other versions of Internet Explorer are vulnerable as well. This BID will be updated when more information about affected packages is available.
59. MySQL MaxDB WebAgent WebSQL Password Parameter Remote Buffer...
BugTraq ID: 12265
Remote: Yes
Date Published: Jan 14 2005
Relevant URL: http://www.securityfocus.com/bid/12265
Summary:
MySQL MaxDB WebAgent WebSQL is reported prone to a remote buffer overflow vulnerability. This issue results from insufficient boundary checks performed by the application when handling malformed user-supplied data. It is possible that an attacker may leverage this issue to execute arbitrary code on a vulnerable computer.
This issue can lead to a superuser compromise.
This issue is reported to affect MaxDB 7.5.00, however, it is likely that other versions prior to 7.5.00.18 are vulnerable.
60. MPM Guestbook Header Input Validation Vulnerability
BugTraq ID: 12266
Remote: Yes
Date Published: Jan 14 2005
Relevant URL: http://www.securityfocus.com/bid/12266
Summary:
MPM Guestbook is reported prone to an input validation vulnerability that may lead to remote command execution or arbitrary file content disclosure. The issue is due to a lack of sufficient sanitization performed on user-supplied 'header' URI parameter data.
An attacker may leverage this issue to execute arbitrary PHP code in the context of the web server process or disclose the contents of web server readable files.
It should be noted that although this vulnerability is reported to affect MPM Guestbook version 1.05, other versions might also be affected.
61. Siteman Page Parameter Cross-Site Scripting Vulnerability
BugTraq ID: 12267
Remote: Yes
Date Published: Jan 14 2005
Relevant URL: http://www.securityfocus.com/bid/12267
Summary:
Siteman is prone to a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input.
This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected Web site and may allow for theft of cookie-based authentication credentials or other attacks.
62. Exim IP Address Command Line Argument Local Buffer Overflow ...
BugTraq ID: 12268
Remote: No
Date Published: Jan 14 2005
Relevant URL: http://www.securityfocus.com/bid/12268
Summary:
A local buffer overflow vulnerability triggered by an excessively long command line argument affects Exim. This issue is due to a failure of the application to validate the length of user-supplied data prior to attempting to store it in process buffers.
An attacker may leverage this issue to execute arbitrary code with the privileges of the affected mailer application. As the application is a setuid application, it is possible that further privilege escalation may occur.
63. Multiple Vendor Anti-Virus Gateway Failure To Decode Base64 ...
BugTraq ID: 12269
Remote: Yes
Date Published: Jan 14 2005
Relevant URL: http://www.securityfocus.com/bid/12269
Summary:
Multiple vendor anti-virus gateway products are reported prone to a security weakness that could lead to a false sense of security. It is reported that the affected anti-virus gateways do not decode base64-encoded images that are contained in 'data' URIs.
A malicious image that is obfuscated in this manner will bypass the affected anti-virus scanner; the image will be rendered in the browser of a target user when the malicious page is viewed. It is reported that because Microsoft Internet Explorer does not support the 'data' URI, Internet Explorer cannot be used as an attack vector to exploit this weakness.
This weakness may lead to a false sense of security where a network administrator believes that the affected product will detect malicious images designed to trigger a target vulnerability. In reality, the images may be obfuscated by an attacker and may not be detected.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. FBI retires its Carnivore
By: Kevin Poulsen
Newly-released reports show the bureau embracing commercial solutions for Internet surveillance, in investigations ranging from providing material support to terrorists to making harassing telephone calls.
http://www.securityfocus.com/news/10307
2. Hacker penetrates T-Mobile systems
By: Kevin Poulsen
An intruder had access to customer records, Social Security numbers, and private e-mail for at least a year ending last October. Trophies included celebrity cell phone snapshots, and a trove of restricted Secret Service documents stored on an agent's Sidekick.
http://www.securityfocus.com/news/10271
3. Netizens eye Web-enabled surveillance cams
By: Kevin Poulsen
The whole world is watching.
http://www.securityfocus.com/news/10251
4. Symantec outlines plans for Veritas
By: John Oates, The Register
Symantec has hired PricewaterhouseCoopers to help it integrate recently-acquired Veritas.
http://www.securityfocus.com/news/10316
5. Man charged with DDoS attacks after U.S.-British inquiry
By: , The Associated Press
http://www.securityfocus.com/news/10312
6. Panix recovers from domain hijack
By: John Leyden, The Register
The hijack of its domain name on Friday (14 January) has thrown the operations of a New York ISP into turmoil.
http://www.securityfocus.com/news/10311
IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Firestarter 1.0.0
By: Tomas Junnonen
Relevant URL: http://www.fs-security.com/
Platforms: Linux
Summary:
Firestarter is graphical firewall tool for Linux. The program aims to combine
ease of use with powerful features, serving both desktop users and administrators.
2. Network Equipment Performance Monitor 2.2
By: Nova Software, Inc.
Relevant URL: http://www.nepm.net/
Platforms: AIX, FreeBSD, HP-UX, Linux, Solaris, True64 UNIX, UNIX, Windows 2000, Windows NT, Windows XP
Summary:
NEPM is a very general, highly configurable, two part software system that monitors any type of logged data from IP networked equipment and reports it via E-mail and web pages. Current conditions and history from systems based on Windows NT/2000 and UNIX can be tracked and reported. Most major server, switch and router systems can be monitored, without running agents on the target systems.
3. Etherchange v1.0
By: Arne Vidstrom
Relevant URL: http://www.ntsecurity.nu/toolbox/etherchange/
Platforms: Windows 2000, Windows XP
Summary:
EtherChange can change the Ethernet address of the network adapters in Windows 2000 / XP.
4. BitDefender for qmail v1.5.5-2
By: SOFTWIN <[email protected]>
Relevant URL: http://www.bitdefender.com/bd/site/products.php?p_id=10
Platforms: Linux
Summary:
BitDefender for qmail is a powerful antivirus software for Linux mail servers, which provides proactive protection of message traffic at the email server level, eliminating the risk to the entire network that could be caused by a negligent user. All messages, both sent and received, are scanned in real time, avoiding the possible infections and preventing anyone from sending an infected message. BitDefender claims 100% detection rate for all viruses in the wild (ITW) through its powerful scanning engines certified by the most prestigious testing labs (ICSA in February 2003, Virus Bulletin 100% in June 2003 and CheckMark in August 2003).
5. Bilbo 0.11
By: Bart Somers
Relevant URL: http://doornenburg.homelinux.net/scripts/bilbo/
Platforms: FreeBSD, Linux
Summary:
Bilbo is an automated, multithreaded nmap-scanner and reporter, capable of header fetching and matching the results against a database from previous scans.
6. IPFront 1.0
By: HernĂ¡n M. Racciatti
Relevant URL: http://www.hernanracciatti.com.ar/ipfront/
Platforms: Windows 2000
Summary:
IPFront is a small tool named which enables users to generate IPSec rules easily. It really speeds-up the process of hardening Windows 2000/2003 in Bastion Host Environment.
Additionally, it allows to set-up IPSec exceptions, and enables a couple of TCP/IP Stack protections against DoSes.
So, IPFront is nothing more than a small Frontend/GUI that writes small scripts that one can later execute from within IPFront, or externally, as simple script files, in other servers,
V. SECURITYJOBS LIST SUMMARY
----------------------------
1. [SJ-JOB] Sr. Security Analyst, Leeds, GB (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387250
2. [SJ-JOB] CHECK Team Leader, London, GB (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387249
3. [SJ-JOB] Management, Fremont, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387248
4. [SJ-JOB] Sr. Security Engineer, Elgin, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387247
5. [SJ-JOB] Developer, Boulder, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387246
6. [SJ-JOB] Sales Engineer, Boston, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387245
7. [SJ-JOB] Information Assurance Analyst, Newington, U... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387244
8. [SJ-JOB] Security Architect, Madison, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387236
9. [SJ-JOB] Certification & Accreditation Engineer, Cha... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387235
10. [SJ-JOB] Sr. Security Analyst, Seattle, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387234
11. [SJ-JOB] Sales Representative, Washington, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387233
12. [SJ-JOB] Security Engineer, Arlington, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387231
13. [SJ-JOB] Chief Security Strategist, Southwest suburb... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387225
14. [SJ-JOB] Security Consultant, UK Wide - ONLY EEC Nat... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387222
15. [SJ-JOB] Security Engineer, Boston, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387221
16. [SJ-JOB] Channel / Business Development, Redwood Cit... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387220
17. [SJ-JOB] Channel / Business Development, Santa Clara... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387219
18. [SJ-JOB] Security Consultant, various south east and... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387215
19. [SJ-JOB] Security Consultant, Bangalore, IN (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387214
20. [SJ-JOB] Security Engineer, Lyndhurst, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387211
21. [SJ-JOB] Application Security Engineer, SF Bay Area,... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387210
22. [SJ-JOB] Security Consultant, Montreal, CA (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387208
23. [SJ-JOB] CSO, Washington, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387207
24. [SJ-JOB] Security Auditor, Saint Louis, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387204
25. [SJ-JOB] Application Security Engineer, Toronto, CA (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387202
26. [SJ-JOB] Security System Administrator, Baltimore, U... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387201
27. [SJ-JOB] Security Product Marketing Manager, Boston,... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387200
28. [SJ-JOB] Information Assurance Engineer, Clarksburg,... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/387198
29. [SJ-JOB] VP of Regional Sales, Greater Boston Area, ... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386858
30. [SJ-JOB] Security Architect, Arlington, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386857
31. [SJ-JOB] Sales Representative, Fremont, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386856
32. [SJ-JOB] Instructor, Various Locations, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386855
33. [SJ-JOB] Developer, McLean, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386854
34. [SJ-JOB] Manager, Information Security, Seymour, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386853
35. [SJ-JOB] Sales Engineer, London, GB (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386852
36. [SJ-JOB] Security Consultant, Englewood, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386851
37. [SJ-JOB] Application Security Engineer, London, GB (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386850
38. [SJ-JOB] Forensics Engineer, McLean, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386849
39. [SJ-JOB] Auditor, Washington, DC, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386848
40. [SJ-JOB] Account Manager, Toronto, CA (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386847
41. [SJ-JOB] Manager, Information Security, Hartford Are... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386846
42. [SJ-JOB] Sr. Security Analyst, Atlanta, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386845
43. [SJ-JOB] Manager, Information Security, Jersey City,... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386844
44. [SJ-JOB] Security Engineer, Rockville , US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386843
45. [SJ-JOB] Developer, Seattle, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386842
46. [SJ-JOB] Sr. Security Engineer, Jersey City, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386841
47. [SJ-JOB] Security Architect, Santa Monica, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386840
48. [SJ-JOB] Chief Security Strategist, Santa Monica, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386839
49. [SJ-JOB] Sales Representative, NYC, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386838
50. [SJ-JOB] Sr. Security Engineer, Phoenix, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/386837
VI. INCIDENTS LIST SUMMARY
--------------------------
1. DoS attack... what to do? (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/387069
2. IE Malware / Spyware Control Methods (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/386879
VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
NO NEW POSTS FOR THE WEEK 2005-01-11 to 2005-01-18.
VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. local admin vs group policy and apps... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/387497
2. IIS6 on W2k3 DCs (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/387495
3. PGP and Outlook (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/387494
4. Automatic Updates and Users/Power Users (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/387224
5. Anti-spyware Beta from Microsoft available (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/387014
6. NTFS Security (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/387013
7. XP SP2 Blind install (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/386949
8. SecurityFocus Microsoft Newsletter #223 (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/386891
9. suggestions for proxy server to run on w2003 box.. (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/386882
IX. SUN FOCUS LIST SUMMARY
--------------------------
NO NEW POSTS FOR THE WEEK 2005-01-11 to 2005-01-18.
X. LINUX FOCUS LIST SUMMARY
---------------------------
1. NMAP : Different interpretation of "filtered" ports ... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/387004
XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XII. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored By: RSA
RSA Conference 2005
The RSA Conference is the most prestigious information security event of
the year! This is the authoritative source for uncovering new ways to
thwart cyber-criminals. Learn. Network. Grow. RSA Conference 2005 takes
place February 14 to 18, 2005 in San Francisco.
http://www.securityfocus.com/sponsor/RSA_sf-news_050118
------------------------------------------------------------------------
Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!
http://www.securityfocus.com/sponsor/Symantec_sf-news_041130
------------------------------------------------------------------------