SecurityFocus Newsletter #286

Peter Laborge <[email protected]> 1 Feb 2005 23:29:31 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #286
------------------------------

This Issue is Sponsored By: CrossTec

FREE Download - The Future in Desktop Firewalls is Available Now
NEW NetOp Desktop Firewall, the world's first driver-centric 
firewall software - protecting your laptops and corporate PCs at  
ring-zero! NetOp features sophisticated process & application
control, centralized management and multiple network user profiles -
NetOp is able to increase security when mobile users plug back 
into your network. Step into a more secure future - Try it FREE

http://www.securityfocus.com/sponsor/CrossTec_sf-news_050201

------------------------------------------------------------------------

Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041130

------------------------------------------------------------------------
I. FRONT AND CENTER
     1. Mobile Viruses
     2. Microsoft's Velvet Glove
     3. Apache 2 with SSL/TLS: Step-by-Step, Part 2
II. BUGTRAQ SUMMARY
     1. Golden FTP Server Remote Buffer Overflow Vulnerability
     2. Apple iSync mRouter Local Command Line Argument Buffer Overf...
     3. Xerox WorkCenter Pro ESS/ Network Controller Directory Trave...
     4. FireHOL Insecure Local Temporary File Creation Vulnerability
     5. SquirrelMail Multiple Remote Input Validation Vulnerabilitie...
     6. Linux Kernel Device Driver Virtual Memory Flags Unspecified ...
     7. Help Desk Reloaded Unspecified Remote Vulnerability
     8. Nokia Series 60 Embedded OS Automatic File Execution Vulnera...
     9. OpenH323 select() Bitmap Remote Buffer Overflow Vulnerabilit...
     10. FUNDUC Search and Replace Malformed ZIP File Remote Buffer O...
     11. ZHCon Unauthorized File Disclosure Vulnerability
     12. Citadel/UX select() Bitmap Remote Buffer Overflow Vulnerabil...
     13. RinetD select() Bit-Array Remote Buffer Overflow Vulnerabili...
     14. Jabber select() Bitmap Remote Buffer Overflow Vulnerability
     15. Blacklist Daemon BLD select() Bit-Array Remote Buffer Overfl...
     16. Inferno Nettverk Dante select() Bitmap Remote Buffer Overflo...
     17. NEC Socks5 select() Bit-Array Remote Buffer Overflow Vulnera...
     18. 3proxy select() Bitmap Remote Buffer Overflow Vulnerability
     19. W32Dasm Buffer Overflow Vulnerability
     20. DataRescue IDA Pro Malformed PE File Remote Buffer Overflow ...
     21. Novell Evolution Camel-Lock-Helper Application Remote Intege...
     22. PEiD Malformed PE File Remote Buffer Overflow Vulnerability
     23. VDR Daemon Unspecified Remote File Access Vulnerability
     24. Sun Solaris DHCP Utilities Unspecified Local Code Execution ...
     25. Exponent CMS Multiple Cross-Site Scripting Vulnerabilities
     26. MercuryBoard Multiple Input Validation Vulnerabilities
     27. Libdbi-perl Unspecified Insecure Temporary File Creation Vul...
     28. Bribble Unspecified Remote Authentication Bypass Vulnerabili...
     29. Comersus Cart Multiple Vulnerabilities
     30. PHPEventCalendar Multiple Remote HTML Injection Vulnerabilit...
     31. ISC BIND Q_UseDNS Remote Buffer Overflow Vulnerability
     32. BIND Validator Self Checking Remote Denial Of Service Vulner...
     33. Apple Mail EMail Message ID Header Information Disclosure Vu...
     34. Apple ColorSync ICC Header Remote Buffer Overflow Vulnerabil...
     35. Cisco IOS IPv6 Processing Remote Denial Of Service Vulnerabi...
     36. Cisco IOS Multi Protocol Label Switching Remote Denial Of Se...
     37. Cisco IOS Border Gateway Protocol Processing Remote Denial O...
     38. Berlios GPSD Remote Format String Vulnerability
     39. SCO scosession Local Command Line Buffer Overflow Vulnerabil...
     40. KDE Screensaver Lock Bypass Vulnerability
     41. BNC IRC Server Proxy select() Bit-Array Remote Buffer Overfl...
     42. Debian Pam Radius Auth File Information Disclosure Vulnerabi...
     43. X.org X Window Server Local Socket Hijacking Vulnerability
     44. Xelerance Corporation Openswan XAUTH/PAM Remote Buffer Overf...
     45. Novell iChain Mutual Authentication Certificate Remote Authe...
     46. Juniper Networks JUNOS Unspecified Remote Denial Of Service ...
     47. F2C Multiple Local Insecure Temporary File Creation Vulnerab...
     48. Nullsoft Winamp Variant IN_CDDA.dll Remote Buffer Overflow V...
     49. Comdev eCommerce INDEX.PHP Multiple Cross-Site Scripting Vul...
     50. Ingate Firewall Persistent PPTP Tunnel Vulnerability
     51. War FTP Daemon Remote Denial Of Service Vulnerability
     52. Sun Solaris UDP Processing Local Denial Of Service Vulnerabi...
     53. Ginp Java Preferences API Access Control Bypass Vulnerabilit...
     54. SnugServer FTP Service Directory Traversal Vulnerability
     55. Magic Winmail Server Multiple Vulnerabilities
     56. Threaded Read News Local Buffer Overflow Vulnerability
     57. Novell iChain OACINT Insecure Default Configuration Exposure
     58. University Of Washington IMAP Server CRAM-MD5 Remote Authent...
     59. CoolForum Multiple Input Validation Vulnerabilities
     60. VooDoo CIRCLE NET_SEND Unspecified Vulnerability
     61. WebWasher Classic HTTP CONNECT Unauthorized Access Weakness
     62. Alt-N WebAdmin Multiple Remote Vulnerabilities
     63. IceWarp Web Mail Multiple Remote Vulnerabilities
     64. ngIRCd Remote Buffer Overflow Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
     1. Clear skies for Area 51 hacker
     2. Feds aim to tighten nuclear cyber security
     3. FBI retires its Carnivore
     4. MSN Belgium to use eID cards for online checking
     5. 'Thiefproof' car key cracked
     6. Government computer blunders are common and expensive
IV. SECURITYFOCUS TOP 6 TOOLS
     1. DigSig 1.3.2
     2. msndump 1.4
     3. PE Explorer 1.96
     4. Firestarter 1.0.0
     5. Network Equipment Performance Monitor 2.2
     6. Etherchange v1.0
V. SECURITYJOBS LIST SUMMARY
     1. [SJ-JOB] Security Engineer, Vienna, US (Thread)
     2. [SJ-JOB] Channel / Business Development, London, GB (Thread)
     3. [SJ-JOB] Application Security Architect, Redwood Cit... (Thread)
     4. [SJ-JOB] Sales Engineer, Anycity, US (Thread)
     5. [SJ-JOB] Security Consultant, Toronto, CA (Thread)
     6. [SJ-JOB] Sales Engineer, DC, US (Thread)
     7. [SJ-JOB] Security Engineer, Washington, US (Thread)
     8. [SJ-JOB] Sales Engineer, IL, US (Thread)
     9. [SJ-JOB] Sales Engineer, Northern CA, US (Thread)
     10. [SJ-JOB] Developer, Cupertino, US (Thread)
     11. [SJ-JOB] Security Product Manager, Cupertino, US (Thread)
     12. [SJ-JOB] Security Engineer, Cupertino, US (Thread)
     13. [SJ-JOB] Security Director, florham park, US (Thread)
     14. [SJ-JOB] Sr. Security Engineer, Tysons Corner, US (Thread)
     15. [SJ-JOB] Sr. Security Engineer, New York (Brooklyn M... (Thread)
     16. [SJ-JOB] Sr. Security Engineer, Philadelphia, US (Thread)
     17. [SJ-JOB] Sr. Security Analyst, Boston, US (Thread)
     18. [SJ-JOB] Technology Risk Consultant, Shaumburg, US (Thread)
     19. [SJ-JOB] Sr. Security Engineer, Houston, US (Thread)
     20. [SJ-JOB] Security Engineer, Greenbelt, US (Thread)
     21. [SJ-JOB] VP / Dir / Mgr engineering, Chicago, US (Thread)
     22. [SJ-JOB] Sales Representative, Atlanta, US (Thread)
     23. [SJ-JOB] Forensics Engineer, London, GB (Thread)
     24. [SJ-JOB] Sales Representative, London, GB (Thread)
     25. [SJ-JOB] Sr. Security Analyst, Cambridge, US (Thread)
     26. [SJ-JOB] Security Engineer, San Diego, US (Thread)
     27. [SJ-JOB] Quality Assurance, San Diego, US (Thread)
     28. [SJ-JOB] Security Architect, Atlanta, US (Thread)
     29. [SJ-JOB] Quality Assurance, Seattle, US (Thread)
     30. [SJ-JOB] Manager, Information Security, Atlanta, US (Thread)
     31. [SJ-JOB] Sr. Security Analyst, Manhattan, US (Thread)
     32. [SJ-JOB] Security Architect, Washington, US (Thread)
     33. [SJ-JOB] Sales Representative, Columbia, US (Thread)
     34. [SJ-JOB] Security Engineer, Annapolis, US (Thread)
     35. [SJ-JOB] Application Security Engineer, North Englan... (Thread)
     36. [SJ-JOB] Security System Administrator, North Englan... (Thread)
     37. [SJ-JOB] Sr. Security Analyst, North England, GB (Thread)
     38. [SJ-JOB] CHECK Team Leader, North England ( UK NATIO... (Thread)
     39. [SJ-JOB] Application Security Architect, North Engla... (Thread)
     40. [SJ-JOB] Account Manager, New York, US (Thread)
     41. [SJ-JOB] Security Engineer, Redmond, US (Thread)
     42. [SJ-JOB] Director, Information Security, Detroit, US (Thread)
     43. [SJ-JOB] Sr. Security Analyst, Oklahoma City, US (Thread)
     44. [SJ-JOB] Technology Risk Consultant, Washington, US (Thread)
     45. [SJ-JOB] Security Consultant, Flemington, US (Thread)
     46. [SJ-JOB] VP of Regional Sales, Any Major Eastern Cit... (Thread)
     47. [SJ-JOB] Management, Redmond, US (Thread)
     48. [SJ-JOB] Security Researcher, Redmond, US (Thread)
     49. [SJ-JOB] Certification & Accreditation Engineer, Aus... (Thread)
     50. [SJ-JOB] Sr. Security Analyst, Oklahoma City, OK, US (Thread)
     51. [SJ-JOB] Security System Administrator, Redmond, US (Thread)
     52. [SJ-JOB] Application Security Engineer, Redwood City... (Thread)
     53. [SJ-JOB] Compliance Officer, Oklahoma City, OK, US (Thread)
     54. [SJ-JOB] Forensics Engineer, Oklahoma City, US (Thread)
     55. [SJ-JOB] Sr. Security Engineer, Redmond, US (Thread)
     56. [SJ-JOB] Regional Channel Manager, Birmingham, US (Thread)
     57. [SJ-JOB] Security Researcher, Boisbriand(Montreal Su... (Thread)
     58. [SJ-JOB] Security Architect, MacLean, US (Thread)
     59. [SJ-JOB] Security Auditor, San Antonio, US (Thread)
     60. [SJ-JOB] VP / Dir / Mgr engineering, Fredericton, CA (Thread)
     61. [SJ-JOB] Technical Support Engineer, Fredericton, CA (Thread)
     62. [SJ-JOB] Developer, Fredericton, CA (Thread)
VI. INCIDENTS LIST SUMMARY
     1. Attempted exploit for some web service. (Thread)
     2. Adminstrivia: SF article announcement: Blind Buffer ... (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. Fwd: MS05-002 xploit modification - connectback addi... (Thread)
     2. Format Strings nonexec heap/stack (Thread)
     3. HKLM locking (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. Domain logon without network connection + group poli... (Thread)
     2. Preventing multiple logins in 2003 (Thread)
     3. RESPONSE: Users "bypassing" Group Policy restriction... (Thread)
     4. Users "bypassing" Group Policy restrictions (Thread)
     5. Dhcp security (Thread)
     6. DSQuery on active directory (Thread)
     7. ISA server logs (Thread)
     8. SecurityFocus Microsoft Newsletter #225 (Thread)
IX. SUN FOCUS LIST SUMMARY
     NO NEW POSTS FOR THE WEEK 2005-01-25 to 2005-02-01.
X. LINUX FOCUS LIST SUMMARY
     1. Encrypted Filesystems (Thread)
XI. HTML NEWSLETTER
XII. UNSUBSCRIBE INSTRUCTIONS
XIII. SPONSOR INFORMATION

I. FRONT AND CENTER
-------------------
1. Mobile Viruses
By Kelly Martin
Mobile viruses that spread through mobile phones are starting to appear,
but the big mobile virus epidemic is still a long ways off.
http://www.securityfocus.com/columnists/294

2. Microsoft's Velvet Glove
By Mark Burnett
Redmond's plan to make you install Windows authentication software before
downloading vital security patches is a reasonable and gentle effort to
limit piracy.
http://www.securityfocus.com/columnists/295

3. Apache 2 with SSL/TLS: Step-by-Step, Part 2
By Artur Maj
This article is part two of a three part series dedicated to configuring
Apache 2.0 with SSL/TLS support, for maxiumum security and optimal
performance. This article offers mod_ssl recommendations and then discusses
three different ways to sign a certificate, including setting up a local
Certificate Authority using OpenSSL.
http://www.securityfocus.com/infocus/1820

II. BUGTRAQ SUMMARY
-------------------
1. Golden FTP Server Remote Buffer Overflow Vulnerability
BugTraq ID: 12333
Remote: Yes
Date Published: Jan 22 2005
Relevant URL: http://www.securityfocus.com/bid/12333
Summary:
Golden FTP Server is reported susceptible to a remote buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied input data prior to copying it to an insufficiently sized memory buffer.

This vulnerability allows remote attackers to execute arbitrary machine code in the context of the vulnerable server application.

Versions prior to 2.05b are reportedly affected by this vulnerability.

2. Apple iSync mRouter Local Command Line Argument Buffer Overf...
BugTraq ID: 12334
Remote: No
Date Published: Jan 22 2005
Relevant URL: http://www.securityfocus.com/bid/12334
Summary:
iSync's 'mRouter' binary is reportedly susceptible to a local command line argument buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied input data prior to copying it into an insufficiently sized memory buffer.

The 'mRouter' binary is installed by default with setuid superuser permissions. This vulnerability allows users with local interactive access to a computer with the affected application installed to gain superuser privileges.

3. Xerox WorkCenter Pro ESS/ Network Controller Directory Trave...
BugTraq ID: 12335
Remote: Yes
Date Published: Jan 24 2005
Relevant URL: http://www.securityfocus.com/bid/12335
Summary:
A remote directory traversal vulnerability affects Xerox WorkCenter Pro.  This issue is due to a failure of the application to properly sanitize user-supplied input.

An attacker may leverage this issue to gain access to sensitive files on the affected device, including the encrypted password file.

4. FireHOL Insecure Local Temporary File Creation Vulnerability
BugTraq ID: 12336
Remote: No
Date Published: Jan 24 2005
Relevant URL: http://www.securityfocus.com/bid/12336
Summary:
FireHOL is prone to a local insecure temporary file creation vulnerability.  This could allow arbitrary files to be overwritten.

5. SquirrelMail Multiple Remote Input Validation Vulnerabilitie...
BugTraq ID: 12337
Remote: Yes
Date Published: Jan 22 2005
Relevant URL: http://www.securityfocus.com/bid/12337
Summary:
SquirrelMail is reported prone to multiple vulnerabilities resulting from input validation errors.  These issues may allow an attacker to carry out cross-site scripting and file include attacks.  An attacker may also include arbitrary web pages in the SquirrelMail frameset to carry out phishing type attacks.

The following specific issues were identified:

SquirrelMail is reported prone to a cross-site scripting vulnerability.  Attacker-supplied code may be rendered in a user's browser facilitating theft of cookie-based authentication credentials and other attacks.

It is reported that an attacker may influence Web content through certain unspecified variables.  It is conjectured that this may allow attackers to misrepresent Web content and potentially carry out phishing type attacks.

The application is reported prone to a file include vulnerability as well.  Reportedly, an affected script can allow remote attackers to include local scripts.  This may eventually lead to unauthorized access in the context of the affected server.

6. Linux Kernel Device Driver Virtual Memory Flags Unspecified ...
BugTraq ID: 12338
Remote: No
Date Published: Jan 24 2005
Relevant URL: http://www.securityfocus.com/bid/12338
Summary:
An unspecified vulnerability affects unspecified Linux kernel device drivers.  This issue is due to a failure of certain unspecified drivers to implement all the required virtual memory access flags.

The potential impact of this issue is currently unknown, however it is likely that when successfully exploited it may give an attacker access to the virtual memory space of a device's I/O.

7. Help Desk Reloaded Unspecified Remote Vulnerability
BugTraq ID: 12339
Remote: Yes
Date Published: Jan 24 2005
Relevant URL: http://www.securityfocus.com/bid/12339
Summary:
A remote unspecified vulnerability affects Help Desk Reloaded.  Although the underlying issue causing this vulnerability is unknown, due to the nature of the affected software it is likely due to input validation failure. It may facilitate cross-site scripting, HTML injection, remote file include, or SQL injection attacks.  It should be noted that this is not confirmed.

This BID will be updated as more details are released.

8. Nokia Series 60 Embedded OS Automatic File Execution Vulnera...
BugTraq ID: 12340
Remote: Yes
Date Published: Jan 24 2005
Relevant URL: http://www.securityfocus.com/bid/12340
Summary:
A vulnerability is reported to affect the Series 60 OS on Nokia devices. It is reported that executable files that have a modified file extension will execute immediately when downloaded. The vendor reports that the user is prompted if the downloaded file is a 'sis' package, but it is not known whether other file types execute automatically and without a prompt.

This BID will be updated, as further information in regards to this vulnerability is made available.

9. OpenH323 select() Bitmap Remote Buffer Overflow Vulnerabilit...
BugTraq ID: 12341
Remote: Yes
Date Published: Jan 24 2005
Relevant URL: http://www.securityfocus.com/bid/12341
Summary:
OpenH323 Gatekeeper is prone to a remote buffer overflow due to implementation of the select() system call.  This issue could be exploited to cause a denial of service or potentially execute arbitrary code.

10. FUNDUC Search and Replace Malformed ZIP File Remote Buffer O...
BugTraq ID: 12342
Remote: Yes
Date Published: Jan 24 2005
Relevant URL: http://www.securityfocus.com/bid/12342
Summary:
Search and Replace is reported prone to a remote buffer overflow vulnerability.  This issue may allow a remote attacker to execute arbitrary code on a vulnerable computer to gain unauthorized access.

This vulnerability arises when the application handles malformed ZIP files.

A successful attack may facilitate unauthorized access to the affected computer.

Search and Replace 5.0 and prior versions are reported vulnerable to this issue.

11. ZHCon Unauthorized File Disclosure Vulnerability
BugTraq ID: 12343
Remote: No
Date Published: Jan 24 2005
Relevant URL: http://www.securityfocus.com/bid/12343
Summary:
zhcon is reportedly affected by a vulnerability allowing reading of arbitrary files with escalated privileges.  This could permit an unauthorized user to read arbitrary files owned by other users without authorization.  Disclosure of sensitive information may lead to a system compromise, or aid in other attacks.

This issue is reported to affect zhcon version 0.2.3; earlier versions may also be affected.

12. Citadel/UX select() Bitmap Remote Buffer Overflow Vulnerabil...
BugTraq ID: 12344
Remote: Yes
Date Published: Jan 24 2005
Relevant URL: http://www.securityfocus.com/bid/12344
Summary:
Citadel/UX is prone to a remote buffer overflow due to implementation of the select() system call.  This issue could be exploited to cause a denial of service or potentially execute arbitrary code.

This vulnerability is reported to affect Citadel/UX versions prior to 6.29.

13. RinetD select() Bit-Array Remote Buffer Overflow Vulnerabili...
BugTraq ID: 12345
Remote: Yes
Date Published: Jan 24 2005
Relevant URL: http://www.securityfocus.com/bid/12345
Summary:
rinetd is prone to a remote buffer overflow due to implementation of the 'select()' system call.  This issue could be exploited to cause a denial of service or potentially execute arbitrary code.

14. Jabber select() Bitmap Remote Buffer Overflow Vulnerability
BugTraq ID: 12346
Remote: Yes
Date Published: Jan 24 2005
Relevant URL: http://www.securityfocus.com/bid/12346
Summary:
Jabber is prone to a remote buffer overflow due to implementation of the select() system call.  This issue could be exploited to cause a denial of service or potentially execute arbitrary code.

15. Blacklist Daemon BLD select() Bit-Array Remote Buffer Overfl...
BugTraq ID: 12347
Remote: Yes
Date Published: Jan 24 2005
Relevant URL: http://www.securityfocus.com/bid/12347
Summary:
Blacklist Daemon BLD is prone to a remote buffer overflow due to implementation of the 'select()' system call.  This issue could be exploited to cause a denial of service or potentially execute arbitrary code.

16. Inferno Nettverk Dante select() Bitmap Remote Buffer Overflo...
BugTraq ID: 12349
Remote: Yes
Date Published: Jan 24 2005
Relevant URL: http://www.securityfocus.com/bid/12349
Summary:
Dante is prone to a remote buffer overflow due to implementation of the select() system call.  This issue could be exploited to cause a denial of service or potentially execute arbitrary code.

17. NEC Socks5 select() Bit-Array Remote Buffer Overflow Vulnera...
BugTraq ID: 12350
Remote: Yes
Date Published: Jan 24 2005
Relevant URL: http://www.securityfocus.com/bid/12350
Summary:
NEC Socks5 is prone to a remote buffer overflow due to implementation of the 'select()' system call.  This issue could be exploited to cause a denial of service or potentially execute arbitrary code.

18. 3proxy select() Bitmap Remote Buffer Overflow Vulnerability
BugTraq ID: 12351
Remote: Yes
Date Published: Jan 24 2005
Relevant URL: http://www.securityfocus.com/bid/12351
Summary:
3proxy is prone to a remote buffer overflow due to implementation of the select() system call.  This issue could be exploited to cause a denial of service or potentially execute arbitrary code.

19. W32Dasm Buffer Overflow Vulnerability
BugTraq ID: 12352
Remote: No
Date Published: Jan 24 2005
Relevant URL: http://www.securityfocus.com/bid/12352
Summary:
W32Dasm is reportedly affected by a buffer overflow vulnerability.  This issue is due to a failure of the application to properly validate the length of strings in a file loaded for debugging prior to copying them into static process buffers.

It is reported that this issue affects W32Dasm version 8.93; earlier versions may also be affected.

20. DataRescue IDA Pro Malformed PE File Remote Buffer Overflow ...
BugTraq ID: 12353
Remote: Yes
Date Published: Jan 24 2005
Relevant URL: http://www.securityfocus.com/bid/12353
Summary:
IDA Pro is reported prone to a remote buffer overflow vulnerability. This issue may allow a remote attacker to execute arbitrary code on a vulnerable computer to gain unauthorized access. 

An attacker can exploit this issue by crafting a PE file and enticing a user to process the file through IDA Pro.

A successful attack may facilitate unauthorized access to the affected computer. 

IDA Pro 4.6 SP 1 and 4.7 running on both Windows and Linux platforms are reported vulnerable to this issue.  It is possible that other versions are affected as well.

21. Novell Evolution Camel-Lock-Helper Application Remote Intege...
BugTraq ID: 12354
Remote: Yes
Date Published: Jan 24 2005
Relevant URL: http://www.securityfocus.com/bid/12354
Summary:
The Evolution camel-lock-helper application is reported prone to an integer overflow vulnerability. The issue is reported to exist in the main() function of the 'camel-lock-helper.c' source file.

A remote attacker may exploit this vulnerability to execute arbitrary code.

22. PEiD Malformed PE File Remote Buffer Overflow Vulnerability
BugTraq ID: 12355
Remote: Yes
Date Published: Jan 25 2005
Relevant URL: http://www.securityfocus.com/bid/12355
Summary:
A remote buffer overflow vulnerability reportedly affects PEiD. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.

An attacker who entices an unsuspecting user to load a maliciously crafted Portable Executable (PE) file with the affected utility may exploit this issue.

An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.

23. VDR Daemon Unspecified Remote File Access Vulnerability
BugTraq ID: 12356
Remote: Yes
Date Published: Jan 25 2005
Relevant URL: http://www.securityfocus.com/bid/12356
Summary:
An unspecified remote file access vulnerability affects the vdr daemon.  The underlying issue that causes this vulnerability is likely a failure to abide by file access restrictions, although this is unconfirmed.This BID will be updated as more details are released.

An attacker may leverage this issue to overwrite arbitrary files on an affected computer.  This can lead to a superuser compromise of the affected computer, corruption of data, as well as other attacks.

24. Sun Solaris DHCP Utilities Unspecified Local Code Execution ...
BugTraq ID: 12357
Remote: No
Date Published: Jan 25 2005
Relevant URL: http://www.securityfocus.com/bid/12357
Summary:
An unspecified local code execution vulnerability affects Sun Solaris DHCP utilities.  This issue is likely due to memory mismanagement leading to a buffer overflow condition, although this is currently unconfirmed.

An attacker may leverage this issue to execute arbitrary code with superuser privileges on the affected computer, facilitating privilege escalation.

25. Exponent CMS Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 12358
Remote: Yes
Date Published: Jan 25 2005
Relevant URL: http://www.securityfocus.com/bid/12358
Summary:
Exponent is reported prone to multiple cross-site scripting vulnerabilities.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user facilitating theft of cookie-based authentication credentials and other attacks. 

Exponent 0.95 is reported prone to these issues.  It is likely that previous versions are vulnerable as well.

26. MercuryBoard Multiple Input Validation Vulnerabilities
BugTraq ID: 12359
Remote: Yes
Date Published: Jan 25 2005
Relevant URL: http://www.securityfocus.com/bid/12359
Summary:
Multiple input validation vulnerabilities affect MercuryBoard.  These issues are due to a failure of the application to properly sanitize user-supplied input prior to using it in critical functionality.

An attacker may leverage these issues to execute arbitrary code in the browser of an unsuspecting user and manipulate SQL queries against the underlying database.  This may facilitate the theft of authentication credentials, destruction of data, and other attacks.

27. Libdbi-perl Unspecified Insecure Temporary File Creation Vul...
BugTraq ID: 12360
Remote: No
Date Published: Jan 25 2005
Relevant URL: http://www.securityfocus.com/bid/12360
Summary:
libdbi-perl is affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it. 

An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. 

Debian has reported that this vulnerability affects libdbi-perl 1.21 running on Debian GNU/Linux 3.0 alias woody.  It is possible that other versions are affected as well.

28. Bribble Unspecified Remote Authentication Bypass Vulnerabili...
BugTraq ID: 12361
Remote: Yes
Date Published: Jan 25 2005
Relevant URL: http://www.securityfocus.com/bid/12361
Summary:
An unspecified remote authentication bypass vulnerability affects Bribble.  The underlying issue is currently unknown, however it is likely due to a design error triggered during the authentication process.

An attacker can leverage this issue to gain administrator access to the affected chat server.

29. Comersus Cart Multiple Vulnerabilities
BugTraq ID: 12362
Remote: Yes
Date Published: Jan 25 2005
Relevant URL: http://www.securityfocus.com/bid/12362
Summary:
Comersus Cart is reportedly affected by multiple vulnerabilities.  There is a possiblity of gaining administrator access due to a failure of the application to remove an installation script after install.  There is the possiblity of SQL injection by passing a malicious HTTP referer header.  There are also some possible cross-site scripting issues.

The vendor has addressed these issues in Comersus Cart version 6.0.2; earlier version are reportedly vulnerable.

30. PHPEventCalendar Multiple Remote HTML Injection Vulnerabilit...
BugTraq ID: 12363
Remote: Yes
Date Published: Jan 25 2005
Relevant URL: http://www.securityfocus.com/bid/12363
Summary:
Multiple remote HTML injection vulnerabilities affect phpEventCalendar.  These issues are due to a failure of the application to sanitize user supplied input prior to including it in dynamically generated Web content.

An attacker may leverage these issues to execute arbitrary HTML and script code in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

31. ISC BIND Q_UseDNS Remote Buffer Overflow Vulnerability
BugTraq ID: 12364
Remote: Yes
Date Published: Jan 26 2005
Relevant URL: http://www.securityfocus.com/bid/12364
Summary:
A remote buffer overflow vulnerability affects BIND.  This issue is due to a failure of the application to properly validate the length of user-supplied input prior to copying it into static process buffers.

An attacker may leverage this issue to trigger a denial of service condition.  It should be noted that this issue may also facilitate code execution with the privileges of the affected utility, however this is not confirmed.

32. BIND Validator Self Checking Remote Denial Of Service Vulner...
BugTraq ID: 12365
Remote: Yes
Date Published: Jan 26 2005
Relevant URL: http://www.securityfocus.com/bid/12365
Summary:
A remote denial of service vulnerability affects BIND.  This issue is due to a failure of the application to handle exceptional network data.

It should be noted that this issue requires that DNSSEC validation is enabled, which is not the case by default.

A remote attacker may leverage this issue to cause the affected server to crash, denying service to legitimate users.

33. Apple Mail EMail Message ID Header Information Disclosure Vu...
BugTraq ID: 12366
Remote: Yes
Date Published: Jan 26 2005
Relevant URL: http://www.securityfocus.com/bid/12366
Summary:
An information disclosure vulnerability affects the email message ID generation of Apple Mail.  This issue is due to a design error that causes the application to insecurely generate email message IDs.

An attacker may leverage this issue to identify the specific computer that an email has been sent from, other attacks may also be possible.

34. Apple ColorSync ICC Header Remote Buffer Overflow Vulnerabil...
BugTraq ID: 12367
Remote: Yes
Date Published: Jan 26 2005
Relevant URL: http://www.securityfocus.com/bid/12367
Summary:
A remote buffer overflow vulnerability affects the International Color Consortium (ICC) color profile processing functionality of Apple ColorSync.  This issue is due to a failure of the application to properly validate user-supplied data prior to copying it into static process buffers.

An attacker may leverage this issue to execute arbitrary code in the context of the ColorSync utility; it is currently unknown whether the ColorSync utility runs with superuser privileges, although it is likely.

35. Cisco IOS IPv6 Processing Remote Denial Of Service Vulnerabi...
BugTraq ID: 12368
Remote: Yes
Date Published: Jan 26 2005
Relevant URL: http://www.securityfocus.com/bid/12368
Summary:
A remote denial of service vulnerability affects the IPv6 processing functionality of Cisco IOS.  This issue is due to a failure of the affected operating system to properly handle specially crafted network data.

It is possible for an attacker to produce a sustained denial of service condition against an affected device by continually sending the malicious network data.

An attacker may leverage this issue to cause an affected device to reload, denying service to legitimate users.

36. Cisco IOS Multi Protocol Label Switching Remote Denial Of Se...
BugTraq ID: 12369
Remote: Yes
Date Published: Jan 26 2005
Relevant URL: http://www.securityfocus.com/bid/12369
Summary:
Cisco IOS based routers that are configured with support for Multi Protocol Label Switching (MPLS) are reported prone to a remote denial of service vulnerability.

It is reported that the vulnerability presents itself when an affected router handles an unspecified malicious packet on a MPLS disabled interface.

A remote attacker that resides on the same network segment as the vulnerable router may exploit this vulnerability continuously to effectively deny network-based services to legitimate users.

37. Cisco IOS Border Gateway Protocol Processing Remote Denial O...
BugTraq ID: 12370
Remote: Yes
Date Published: Jan 26 2005
Relevant URL: http://www.securityfocus.com/bid/12370
Summary:
A remote denial of service vulnerability affects the Border Gateway Protocol (BGP) processing functionality of Cisco IOS.  This issue is due to a failure of the application to handle malformed network data.

An attacker may leverage this issue to trigger a denial of service condition in the affected device.  It is currently unknown whether the denial of service condition is persistent, although it is likely that it is.

38. Berlios GPSD Remote Format String Vulnerability
BugTraq ID: 12371
Remote: Yes
Date Published: Jan 26 2005
Relevant URL: http://www.securityfocus.com/bid/12371
Summary:
Multiple instances of format string handling bugs are reported to exist in gpsd, but only one of these issues is reported to be an exploitable vulnerability.

Ultimately this issue may be leveraged by a remote attacker to influence execution flow of the affected daemon and reliably execute arbitrary code.

39. SCO scosession Local Command Line Buffer Overflow Vulnerabil...
BugTraq ID: 12372
Remote: No
Date Published: Jan 26 2005
Relevant URL: http://www.securityfocus.com/bid/12372
Summary:
A local buffer overflow vulnerability affects SCO scosession.  This issue is due to a failure of the application to properly validate user-supplied input strings prior to copying them to finite process buffers.

A local attacker may leverage this issue to execute arbitrary code with the privileges of the superuser, facilitating privilege escalation.

40. KDE Screensaver Lock Bypass Vulnerability
BugTraq ID: 12373
Remote: No
Date Published: Jan 26 2005
Relevant URL: http://www.securityfocus.com/bid/12373
Summary:
Debian has reported that a vulnerability in the screensaver was discovered.  According to the report, a malicious user with console access (i.e. physical) can cause the screensaver to crash.  The feature will fail-open, allowing access to the desktop after it terminates.

41. BNC IRC Server Proxy select() Bit-Array Remote Buffer Overfl...
BugTraq ID: 12374
Remote: Yes
Date Published: Jan 24 2005
Relevant URL: http://www.securityfocus.com/bid/12374
Summary:
BNC IRC Server Proxy is prone to a remote buffer overflow due to implementation of the 'select()' system call.  This issue could be exploited to cause a denial of service or potentially execute arbitrary code.

42. Debian Pam Radius Auth File Information Disclosure Vulnerabi...
BugTraq ID: 12375
Remote: No
Date Published: Jan 26 2005
Relevant URL: http://www.securityfocus.com/bid/12375
Summary:
Debian Linux is reportedly affected by a local file information disclosure vulnerability.  This issue is due to the application setting a PAM radius configuration file as world-readable during the installation of the affected package. 

This issue is specific to Debian Linux.

43. X.org X Window Server Local Socket Hijacking Vulnerability
BugTraq ID: 12376
Remote: No
Date Published: Jan 26 2005
Relevant URL: http://www.securityfocus.com/bid/12376
Summary:
A local socket hijacking vulnerability affects X.org X Windows Server.  This issue is due to a failure of the application to securely create socket directories.

An attacker may leverage this issue to hijack socket sessions, potentially facilitating arbitrary read and write access with the privileges of the user that started the vulnerable server.

44. Xelerance Corporation Openswan XAUTH/PAM Remote Buffer Overf...
BugTraq ID: 12377
Remote: Yes
Date Published: Jan 26 2005
Relevant URL: http://www.securityfocus.com/bid/12377
Summary:
A remote buffer overflow vulnerability reportedly affects Xelerance Corporation Openswan.  This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into finite process buffers.

It should be noted that Openswan is only affected by this issue when it is compiled with XAUTH and PAM support, which is not the default configuration.

An attacker may leverage this issue to execute arbitrary code with the privileges of the affected application; this may facilitate unauthorized access or privilege escalation.

45. Novell iChain Mutual Authentication Certificate Remote Authe...
BugTraq ID: 12378
Remote: Yes
Date Published: Jan 26 2005
Relevant URL: http://www.securityfocus.com/bid/12378
Summary:
A remote authentication bypass vulnerability affects Novell iChain.  This issue is due to a failure of the application to properly implement security policies.

It should be noted that this issue is only present if auto-created SSL certificates are used, internally signed certificates are used, or externally signed SSL certificates are used while the affected appliance has imported the ICS_TREE Selfsigned Certificate to iChains TrustedRoot Store while certificate mapping matches an internal user.  It should also be noted that certificate matching can be achieved by an attacker with only an internal user's email address.

A remote attacker may leverage this issue to bypass iChain identity-based authentication, granting them access to any protected network resources.

46. Juniper Networks JUNOS Unspecified Remote Denial Of Service ...
BugTraq ID: 12379
Remote: Yes
Date Published: Jan 27 2005
Relevant URL: http://www.securityfocus.com/bid/12379
Summary:
Juniper Networks routers running JUNOS are reported prone to an unspecified remote denial of service vulnerability. It is reported that this vulnerability exists in all releases of Juniper JUNOS that were built prior to January 7th 2005.

A remote attacker may exploit this vulnerability to effectively deny network-based services to legitimate users.

This BID will be updated as soon as further information regarding this vulnerability is made public.

47. F2C Multiple Local Insecure Temporary File Creation Vulnerab...
BugTraq ID: 12380
Remote: No
Date Published: Jan 27 2005
Relevant URL: http://www.securityfocus.com/bid/12380
Summary:
Multiple local insecure temporary file creation vulnerabilities affect f2c.  These issues are due to a design error causing failure of the application to write to temporary files securely.

An attacker may leverage these issues to corrupt arbitrary files with the privileges of an unsuspecting user that executes the affected applications.

48. Nullsoft Winamp Variant IN_CDDA.dll Remote Buffer Overflow V...
BugTraq ID: 12381
Remote: Yes
Date Published: Jan 27 2005
Relevant URL: http://www.securityfocus.com/bid/12381
Summary:
A remote buffer overflow vulnerability affects the IN_CDDA.dll library of Nullsoft's Winamp. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into finite process buffers. It should be noted that this issue is not related to the issue outlined in BID 11730 (Nullsoft Winamp IN_CDDA.dll Remote Buffer Overflow Vulnerability).

This issue will facilitate remote exploitation as an attacker may distribute malicious play-list files and entice unsuspecting users to process them with the affected application.

It should be noted that this issue was originally reported in BID 12245 (Nullsoft Winamp Multiple Unspecified Vulnerabilities).  It has been assigned a new BID due to the release of more information.

An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application.

49. Comdev eCommerce INDEX.PHP Multiple Cross-Site Scripting Vul...
BugTraq ID: 12382
Remote: Yes
Date Published: Jan 27 2005
Relevant URL: http://www.securityfocus.com/bid/12382
Summary:
Comdev eCommerce is reported prone to multiple cross-site scripting vulnerabilities.  These may facilitate theft of cookie-based authentication credentials as well as other attacks. 

Comdev eCommerce 3.0 is reported prone to these issues. It is likely that previous versions are vulnerable as well.

50. Ingate Firewall Persistent PPTP Tunnel Vulnerability
BugTraq ID: 12383
Remote: Yes
Date Published: Jan 27 2005
Relevant URL: http://www.securityfocus.com/bid/12383
Summary:
Ingate Firewall does not remove PPTP tunnels created by a user that has been disabled by the firewall administrator.  Even if the user has been disabled, any PPTP tunnels they have created will persist.

51. War FTP Daemon Remote Denial Of Service Vulnerability
BugTraq ID: 12384
Remote: Yes
Date Published: Jan 27 2005
Relevant URL: http://www.securityfocus.com/bid/12384
Summary:
War FTP Daemon is reported prone to a remote denial of service vulnerability.  This issue arises because the application fails to handle exceptional conditions in a proper manner.

War FTP Daemon 1.82.00-RC9 is reported prone to this issue.  It is likely that previous versions are vulnerable as well.

52. Sun Solaris UDP Processing Local Denial Of Service Vulnerabi...
BugTraq ID: 12385
Remote: No
Date Published: Jan 27 2005
Relevant URL: http://www.securityfocus.com/bid/12385
Summary:
A local denial of service vulnerability reportedly affects the UDP endpoint handling of Sun Solaris.  This issue is due to a failure of the application to handle excessive UDP endpoint activity.

An attacker may leverage this issue to cause the affected kernel to panic, triggering a system-wide denial of service condition.

53. Ginp Java Preferences API Access Control Bypass Vulnerabilit...
BugTraq ID: 12386
Remote: Yes
Date Published: Jan 27 2005
Relevant URL: http://www.securityfocus.com/bid/12386
Summary:
ginp is reported prone to a remote access control bypass vulnerability. Reports indicate that in some cases preferences are not correctly saved, leading to an issue where users may gain access to images that are supposed to be restricted.

It is reported that this vulnerability affects ginp version 0.20, previous versions may also be affected.

54. SnugServer FTP Service Directory Traversal Vulnerability
BugTraq ID: 12387
Remote: Yes
Date Published: Jan 27 2005
Relevant URL: http://www.securityfocus.com/bid/12387
Summary:
It is reported that the SnugServer FTP Service is susceptible to a directory traversal vulnerability.

It is conjectured that this vulnerability allows a remote attacker to read and write files outside of the FTP document root directory. An attacker may read and write files with the privileges of the FTP server process.

55. Magic Winmail Server Multiple Vulnerabilities
BugTraq ID: 12388
Remote: Yes
Date Published: Jan 27 2005
Relevant URL: http://www.securityfocus.com/bid/12388
Summary:
Magic Winmail Server is reportedly affected by multiple vulnerabilities.  

There are two distinct directory traversal vulnerabilities in the Webmail interface allowing both arbitrary file downloads and uploads.  There is also a HTML injection vulnerability in the Webmail interface that could lead to the theft of the administrator's session cookie.

There are several directory traversal vulnerabilities in the IMAP service commands which could permit a malicious user to read arbitrary emails, create or delete arbitrary files on the server and possibly retrieve arbitrary files from the server.

Magic Winmail Server's FTP service also reportedly fails to properly verify the IP address supplied by a user in a PORT command.

Magic Winmail Server version 4.0 (Build 1112) is reportedly affected by these issues; earlier versions may also be vulnerable.

56. Threaded Read News Local Buffer Overflow Vulnerability
BugTraq ID: 12389
Remote: No
Date Published: Jan 27 2005
Relevant URL: http://www.securityfocus.com/bid/12389
Summary:
A local buffer overflow vulnerability reportedly affects trn.  This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into finite process buffers.

An attacker may leverage this issue to execute arbitrary code with superuser privileges, facilitating privilege escalation.

57. Novell iChain OACINT Insecure Default Configuration Exposure
BugTraq ID: 12390
Remote: Yes
Date Published: Jan 27 2005
Relevant URL: http://www.securityfocus.com/bid/12390
Summary:
It is reported that by default the Novell iChain OACINT service will bind to all available interfaces. This behavior has been modified, by default the service now binds to the loopback interface only. This eliminates the exposure of the service to potentially hostile networks.

58. University Of Washington IMAP Server CRAM-MD5 Remote Authent...
BugTraq ID: 12391
Remote: Yes
Date Published: Jan 28 2005
Relevant URL: http://www.securityfocus.com/bid/12391
Summary:
A remote authentication bypass vulnerability affects the CRAM-MD5 authentication functionality of the University of Washington IMAP server.  This issue is due to a logic error that fails to properly validate authentication attempts.

It should be noted that this issue only affects servers with CRAM-MD5 authentication enabled, which is not the case by default.

A remote attacker may leverage this issue to authenticate to the affected server as any user.

59. CoolForum Multiple Input Validation Vulnerabilities
BugTraq ID: 12392
Remote: Yes
Date Published: Jan 28 2005
Relevant URL: http://www.securityfocus.com/bid/12392
Summary:
CoolForum is reported prone to multiple vulnerabilities resulting from input validation errors.  These issues may allow an attacker to carry out HTML and SQL injection attacks.

The following specific issues were identified:

It has been reported that the application is prone to multiple SQL injection vulnerabilities that may allow a remote attacker to inject arbitrary SQL queries into the database used by CoolForum.

An HTML injection vulnerability may also affect the application.  This issue can allow for theft of cookie based authentication credentials and other attacks.

CoolForum 0.7.2 is reported prone to these issues.  It is likely that other versions are vulnerable as well.

60. VooDoo CIRCLE NET_SEND Unspecified Vulnerability
BugTraq ID: 12393
Remote: Yes
Date Published: Jan 28 2005
Relevant URL: http://www.securityfocus.com/bid/12393
Summary:
An unspecified vulnerability affects the NET_SEND command of VooDoo cIRCle.  The underlying issue causing this vulnerability is currently unknown.

The details available surrounding this issue are insufficient to provide a detailed technical description.  Furthermore the impact of this issue is also unknown.  This BID will be updated when more information is released.

61. WebWasher Classic HTTP CONNECT Unauthorized Access Weakness
BugTraq ID: 12394
Remote: Yes
Date Published: Jan 28 2005
Relevant URL: http://www.securityfocus.com/bid/12394
Summary:
It is reported that WebWasher Classic is prone to a weakness that may allow remote attackers to connect to arbitrary ports on a vulnerable computer.

This weakness may be combined with other attacks to exploit latent vulnerabilities.  An attacker can bypass access controls implemented by the application through this attack.

WebWasher Classic 3.3 and 2.2.1 are reported prone to this weakness.  Other versions may be affected as well.

62. Alt-N WebAdmin Multiple Remote Vulnerabilities
BugTraq ID: 12395
Remote: Yes
Date Published: Jan 28 2005
Relevant URL: http://www.securityfocus.com/bid/12395
Summary:
Alt-n WebAdmin is reportedly affected by multiple remote vulnerabilities.  

The application is affected by multiple cross-site scripting issues.  An attacker may leverage these issues to execute arbitrary HTML and script code in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

The application is reportedly also affected by an access validation vulnerability with regards to user accounts.  This issue could permit an attacker to modify various aspects of an existing users account.

The vendor has addressed these issues in Alt-N WebAdmin 3.03 and later; earlier versions are reportedly vulnerable.

63. IceWarp Web Mail Multiple Remote Vulnerabilities
BugTraq ID: 12396
Remote: Yes
Date Published: Jan 28 2005
Relevant URL: http://www.securityfocus.com/bid/12396
Summary:
Multiple remote vulnerabilities reportedly affect IceWarp Web Mail. The underlying issues are due to input and access validation errors.

Multiple cross-site scripting and HTML injection vulnerabilities affect the vulnerable software. The product is also vulnerable to a file creation with arbitrary data vulnerability. Finally it is possible for an authenticated attacker to move and read arbitrary files on an affected computer with the privileges of the affected application.

An attacker may leverage these issues to move arbitrary files with the privileges of the affected server, to carry out cross-site scripting and HTML injection attacks and to create a file with arbitrary content.  These issues may lead to system wide denial of service as well as other attacks.

64. ngIRCd Remote Buffer Overflow Vulnerability
BugTraq ID: 12397
Remote: Yes
Date Published: Jan 28 2005
Relevant URL: http://www.securityfocus.com/bid/12397
Summary:
ngIRCd is reported prone to a remote buffer overflow vulnerability.  This issue presents itself because the application fails to perform proper boundary checks before copying user-supplied data into process buffers.

A successful attack may allow the attacker to crash the server or gain unauthorized access to a vulnerable computer.

ngIRCd 0.8.1 and prior versions are affected by this vulnerability.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Clear skies for Area 51 hacker
By: Kevin Poulsen

Federal prosecutors dismiss a felony charge against a man who dug up government surveillance devices buried in the Nevada desert.
http://www.securityfocus.com/news/10373

2. Feds aim to tighten nuclear cyber security
By: Kevin Poulsen

Proposed standards would help shield nuclear reactor safety systems from hack attacks, but voluntary compliance leaves some experts without a warm glow.

http://www.securityfocus.com/news/10353

3. FBI retires its Carnivore
By: Kevin Poulsen

Newly-released reports show the bureau embracing commercial solutions for Internet surveillance, in investigations ranging from providing material support to terrorists to making harassing telephone calls. 
http://www.securityfocus.com/news/10307

4. MSN Belgium to use eID cards for online checking
By: Jan Libbenga, The Register

Microsoft will integrate the Belgian eID Card with MSN Messenger. Microsoft's Bill Gates and Belgian State Secretary for e-government Peter Vanvelthoven announced the alliance today in Brussels.
http://www.securityfocus.com/news/10392

5. 'Thiefproof' car key cracked
By: John Leyden, The Register

Researchers have discovered cryptographic vulnerabilities in the RFID technology used in high-security car keys and petrol pump payment systems.
http://www.securityfocus.com/news/10386

6. Government computer blunders are common and expensive
By: Ted Bridis, The Associated Press

http://www.securityfocus.com/news/10383

IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. DigSig 1.3.2
By: 
Relevant URL: http://sourceforge.net/projects/disec/
Platforms: Linux
Summary: 

DigSig Linux kernel load module checks the signature of a binary before running it.  It inserts digital signatures inside the ELF binary and verify this signature before loading the binary. Therefore, it improves the security of the system by avoiding a wide range of malicious binaries like viruses, worms, Torjan programs and backdoors from running on the system.

2. msndump 1.4
By: miscname
Relevant URL: http://miscname.com/public/msndump/
Platforms: Perl (any system supporting perl)
Summary: 

msndump - a quick msn messenger sniffer

$ perl msndump.pl                      
                                       
[ msndump - miscname.com ]
 Usage:
        -i rl0 || -r file.pcap
        -c X - capture X packets
        -w freshIMz.txt
        -v show all msn IM data

3. PE Explorer 1.96
By: Heaventools Software
Relevant URL: http://www.heaventools.com/overview.htm
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary: 

PE Explorer is a tool for inspecting and editing the inner workings of Windows 32-bit executable files. It offers a look at PE file structure and all of the resources in the file, and reports multiple details about a PE file (EXE, DLL, ActiveX controls, and several other Windows executable formats). Once inside, file structure can be analyzed and optimized, hostile code detected, spyware tracked down, problems diagnosed, changes made and resources repaired.

4. Firestarter 1.0.0
By: Tomas Junnonen
Relevant URL: http://www.fs-security.com/
Platforms: Linux
Summary: 

Firestarter is graphical firewall tool for Linux. The program aims to combine
ease of use with powerful features, serving both desktop users and administrators.

5. Network Equipment Performance Monitor 2.2
By: Nova Software, Inc.
Relevant URL: http://www.nepm.net/
Platforms: AIX, FreeBSD, HP-UX, Linux, Solaris, True64 UNIX, UNIX, Windows 2000, Windows NT, Windows XP
Summary: 

NEPM is a very general, highly configurable, two part software system that monitors any type of logged data from IP networked equipment and reports it via E-mail and web pages. Current conditions and history from systems based on Windows NT/2000 and UNIX can be tracked and reported. Most major server, switch and router systems can be monitored, without running agents on the target systems.

6. Etherchange v1.0
By: Arne Vidstrom
Relevant URL: http://www.ntsecurity.nu/toolbox/etherchange/
Platforms: Windows 2000, Windows XP
Summary: 

EtherChange can change the Ethernet address of the network adapters in Windows 2000 / XP.

V. SECURITYJOBS LIST SUMMARY
----------------------------
1. [SJ-JOB] Security Engineer, Vienna, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/389012

2. [SJ-JOB] Channel / Business Development, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/389001

3. [SJ-JOB] Application Security Architect, Redwood Cit... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/389000

4. [SJ-JOB] Sales Engineer, Anycity, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388987

5. [SJ-JOB] Security Consultant, Toronto, CA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388945

6. [SJ-JOB] Sales Engineer, DC, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388944

7. [SJ-JOB] Security Engineer, Washington, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388943

8. [SJ-JOB] Sales Engineer, IL, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388942

9. [SJ-JOB] Sales Engineer, Northern CA, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388941

10. [SJ-JOB] Developer, Cupertino, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388940

11. [SJ-JOB] Security Product Manager, Cupertino, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388939

12. [SJ-JOB] Security Engineer, Cupertino, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388938

13. [SJ-JOB] Security Director, florham park, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388830

14. [SJ-JOB] Sr. Security Engineer, Tysons Corner, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388821

15. [SJ-JOB] Sr. Security Engineer, New York (Brooklyn M... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388808

16. [SJ-JOB] Sr. Security Engineer, Philadelphia, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388801

17. [SJ-JOB] Sr. Security Analyst, Boston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388796

18. [SJ-JOB] Technology Risk Consultant, Shaumburg, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388788

19. [SJ-JOB] Sr. Security Engineer, Houston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388785

20. [SJ-JOB] Security Engineer, Greenbelt, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388784

21. [SJ-JOB] VP / Dir / Mgr engineering, Chicago, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388782

22. [SJ-JOB] Sales Representative, Atlanta, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388770

23. [SJ-JOB] Forensics Engineer, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388762

24. [SJ-JOB] Sales Representative, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388747

25. [SJ-JOB] Sr. Security Analyst, Cambridge, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388741

26. [SJ-JOB] Security Engineer, San Diego, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388735

27. [SJ-JOB] Quality Assurance, San Diego, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388734

28. [SJ-JOB] Security Architect, Atlanta, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388733

29. [SJ-JOB] Quality Assurance, Seattle, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388732

30. [SJ-JOB] Manager, Information Security, Atlanta, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388731

31. [SJ-JOB] Sr. Security Analyst, Manhattan, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388728

32. [SJ-JOB] Security Architect, Washington, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388727

33. [SJ-JOB] Sales Representative, Columbia, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388725

34. [SJ-JOB] Security Engineer, Annapolis, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388724

35. [SJ-JOB] Application Security Engineer, North Englan... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388722

36. [SJ-JOB] Security System Administrator, North Englan... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388719

37. [SJ-JOB] Sr. Security Analyst, North England, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388718

38. [SJ-JOB] CHECK Team Leader, North England ( UK NATIO... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388717

39. [SJ-JOB] Application Security Architect, North Engla... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388714

40. [SJ-JOB] Account Manager, New York, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388700

41. [SJ-JOB] Security Engineer, Redmond, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388621

42. [SJ-JOB] Director, Information Security, Detroit, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388608

43. [SJ-JOB] Sr. Security Analyst, Oklahoma City, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388582

44. [SJ-JOB] Technology Risk Consultant, Washington, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388573

45. [SJ-JOB] Security Consultant, Flemington, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388570

46. [SJ-JOB] VP of Regional Sales, Any Major Eastern Cit... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388558

47. [SJ-JOB] Management, Redmond, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388557

48. [SJ-JOB] Security Researcher, Redmond, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388556

49. [SJ-JOB] Certification & Accreditation Engineer, Aus... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388554

50. [SJ-JOB] Sr. Security Analyst, Oklahoma City, OK, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388553

51. [SJ-JOB] Security System Administrator, Redmond, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388550

52. [SJ-JOB] Application Security Engineer, Redwood City... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388546

53. [SJ-JOB] Compliance Officer, Oklahoma City, OK, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388545

54. [SJ-JOB] Forensics Engineer, Oklahoma City, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388544

55. [SJ-JOB] Sr. Security Engineer, Redmond, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388541

56. [SJ-JOB] Regional Channel Manager, Birmingham, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388540

57. [SJ-JOB] Security Researcher, Boisbriand(Montreal Su... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388537

58. [SJ-JOB] Security Architect, MacLean, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388536

59. [SJ-JOB] Security Auditor, San Antonio, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388534

60. [SJ-JOB] VP / Dir / Mgr engineering, Fredericton, CA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388436

61. [SJ-JOB] Technical Support Engineer, Fredericton, CA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388433

62. [SJ-JOB] Developer, Fredericton, CA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388431

VI. INCIDENTS LIST SUMMARY
--------------------------
1. Attempted exploit for some web service. (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/388576

2. Adminstrivia: SF article announcement: Blind Buffer ... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/388353

VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Fwd: MS05-002 xploit modification - connectback addi... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/388971

2. Format Strings nonexec heap/stack (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/388900

3. HKLM locking (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/388443

VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. Domain logon without network connection + group poli... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/389106

2. Preventing multiple logins in 2003 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/389010

3. RESPONSE: Users "bypassing" Group Policy restriction... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/389009

4. Users "bypassing" Group Policy restrictions (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/388879

5. Dhcp security (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/388871

6. DSQuery on active directory (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/388832

7. ISA server logs (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/388627

8. SecurityFocus Microsoft Newsletter #225 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/388596

IX. SUN FOCUS LIST SUMMARY
--------------------------
NO NEW POSTS FOR THE WEEK 2005-01-25 to 2005-02-01.

X. LINUX FOCUS LIST SUMMARY
---------------------------
1. Encrypted Filesystems (Thread)
Relevant URL:

http://www.securityfocus.com/archive/91/388422

XI. HTML NEWSLETTER
----------------------------
SecurityFocus is currently planning the launch of a refined HTML version of this newsletter. To subscribe, send a blank email to [email protected]

XII. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.
    
XIII. SPONSOR INFORMATION
-----------------------

This Issue is Sponsored By: CrossTec

FREE Download - The Future in Desktop Firewalls is Available Now
NEW NetOp Desktop Firewall, the world's first driver-centric 
firewall software - protecting your laptops and corporate PCs at  
ring-zero! NetOp features sophisticated process & application
control, centralized management and multiple network user profiles -
NetOp is able to increase security when mobile users plug back 
into your network. Step into a more secure future - Try it FREE

http://www.securityfocus.com/sponsor/CrossTec_sf-news_050201

------------------------------------------------------------------------

Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041130

------------------------------------------------------------------------