SecurityFocus Newsletter #287
Peter Laborge <[email protected]> 9 Feb 2005 17:56:41 -0000
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #287
------------------------------
This Issue is Sponsored By: RSA
RSA Conference 2005
The RSA Conference is the most prestigious information security event of
the year! This is the authoritative source for uncovering new ways to
thwart cyber-criminals. Learn. Network. Grow. RSA Conference 2005 takes
place February 14 to 18, 2005 in San Francisco.
http://www.securityfocus.com/sponsor/RSA_sf-news_050208
------------------------------------------------------------------------
Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!
http://www.securityfocus.com/sponsor/Symantec_sf-news_041130
------------------------------------------------------------------------
I. FRONT AND CENTER
1. Penetration Testing IPsec VPNs
2. Linux Kernel Security is Lacking
3. Apache 2 with SSL/TLS: Step-by-Step, Part 2
4. Of Dog Sniffs and Packet Sniffs
II. BUGTRAQ SUMMARY
1. phpPGAds HTTP Response Splitting Vulnerability
2. Captaris Infinite Mobile Delivery Webmail Path Disclosure Vu...
3. NCPFS Multiple Remote Vulnerabilities
4. CitrusDB Credit Card Data Remote Information Disclosure Vuln...
5. JShop E-Commerce Suite Product.PHP Cross-Site Scripting Vuln...
6. SmarterTools SmarterMail Cross-Site Scripting Vulnerability
7. Xoops Incontent Module Directory Traversal Vulnerability
8. Multiple Mozilla/Firefox/Thunderbird Vulnerabilities
9. Clam Anti-Virus ClamAV ZIP File Parsing Remote Denial Of Ser...
10. Techland XPand Rally Remote Denial Of Service Vulnerability
11. RealNetworks RealPlayer Drag And Drop Zone Bypass Vulnerabil...
12. PostgreSQL LOAD Extension Local Privilege Escalation Vulnera...
13. Squid Proxy Oversize HTTP Headers Unspecified Remote Vulnera...
14. SquirrelMail URL Remote Code Execution Vulnerability
15. Newsfetch SScanf Remote Buffer Overflow Vulnerability
16. IBM AIX NIS Client Unspecified Remote Code Execution Vulnera...
17. Eternal Lines Web Server Remote Denial Of Service Vulnerabil...
18. PostgreSQL Multiple Remote Vulnerabilities
19. Newspost Remote Buffer Overflow Vulnerability
20. ZipGenius Multiple Directory Traversal Vulnerabilities
21. Eurofull E-Commerce Mensresp.ASP Cross-Site Scripting Vulner...
22. Ventia DeskNow Mail And Collaboration Server Multiple Remote...
23. RARLAB WinRAR Directory Traversal Vulnerability
24. People Can Fly Painkiller Gamespy CD-Key Hash Remote Buffer ...
25. Cisco IP/VC Videoconferencing System SNMP Remote Default Com...
26. PHP-Fusion Forum_Search.PHP Information Disclosure Vulnerabi...
27. Perl SuidPerl Multiple Local Vulnerabilities
28. Microsoft Internet Explorer AddChannel Cross-Zone Scripting ...
29. Newsgrab Multiple Local And Remote Vulnerabilities
30. Savant Web Server Remote Buffer Overflow Vulnerability
31. Qualcomm Eudora Multiple Unspecified Vulnerabilities
32. Squid Proxy squid_ldap_auth Authentication Bypass Vulnerabil...
33. Squid Proxy WCCP recvfrom() Buffer Overflow Vulnerability
34. Squid Proxy Malformed HTTP Header Parsing Cache Poisoning Vu...
35. ngIRCd Remote Format String Vulnerability
36. D-BUS Session Bus Local Privilege Escalation Vulnerability
37. Mambo Open Source Global Variables Unauthorized Access Vulne...
38. Python SimpleXMLRPCServer Library Module Unauthorized Access...
39. SunShop Shopping Cart Cross-Site Scripting Vulnerability
40. LANChat Pro Revival UDP Processing Remote Denial Of Service ...
41. Microsoft Multiple Unspecified Security Vulnerabilities
42. Linux Kernel IPV6_Setsockopt IPV6_PKTOPTIONS Integer Overflo...
43. ht://Dig Unspecified Cross-Site Scripting Vulnerability
44. Linksys PSUS4 PrintServer Malformed HTTP POST Request Denial...
45. MediaWiki Unspecified Cross-Site Scripting Vulnerability
46. Postfix IPv6 Unauthorized Mail Relay Vulnerability
47. PowerDNS Unspecified Remote Denial of Service Vulnerability
48. Netgear DG834 ADSL Firewall Router Insecure Configuration Vu...
49. Claroline Add_Course.PHP Cross-Site Scripting Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
1. Shhhh. U.S. appeals USA PATRIOT loss
2. Supreme Court puts hacker sentences up for grabs
3. Clear skies for Area 51 hacker
4. Latest antivirus company purchase for Microsoft
5. Microsoft bolsters email security with Sybari acquisition
6. phpBB forum offline after defacement
IV. SECURITYFOCUS TOP 6 TOOLS
1. Secure Hive 1.0.0.1
2. SigupShield 3.0
3. DigSig 1.3.2
4. msndump 1.4
5. PE Explorer 1.96
6. Firestarter 1.0.0
V. SECURITYJOBS LIST SUMMARY
1. [SJ-JOB] Jr. Security Analyst, Dearborn, US (Thread)
2. [SJ-JOB] Sr. Security Engineer, Chicago, US (Thread)
3. [SJ-JOB] Security Consultant, Scottsdale, US (Thread)
4. [SJ-JOB] Jr. Security Analyst, Melbourne, US (Thread)
5. [SJ-JOB] Security System Administrator, Frederick, U... (Thread)
6. [SJ-JOB] Security Engineer, Dearborn, US (Thread)
7. [SJ-JOB] Security Consultant, Chicago, US (Thread)
8. [SJ-JOB] Forensics Engineer, Melbourne, US (Thread)
9. [SJ-JOB] VP of Regional Sales, London / South East, ... (Thread)
10. [SJ-JOB] Information Assurance Analyst, Melbourne, U... (Thread)
11. [SJ-JOB] Security System Administrator, Dearborn, US (Thread)
12. [SJ-JOB] Security Consultant, Alexandria, US (Thread)
13. [SJ-JOB] Information Assurance Analyst, San Francisc... (Thread)
14. [SJ-JOB] Sales Representative, San Diego, US (Thread)
15. [SJ-JOB] Security Consultant, London & throughout th... (Thread)
16. [SJ-JOB] Security Engineer, Champaign, US (Thread)
17. [SJ-JOB] Manager, Information Security, London, GB (Thread)
18. [SJ-JOB] Security Engineer, Any, DE (Thread)
19. [SJ-JOB] Security Consultant, County: Berkshire, GB (Thread)
20. [SJ-JOB] Account Manager, San Francisco, US (Thread)
21. [SJ-JOB] Security Consultant, London, GB (Thread)
22. [SJ-JOB] Security Engineer, Any, US (Thread)
23. [SJ-JOB] Security Engineer, Southern California, US (Thread)
24. [SJ-JOB] Security Consultant, Tallahassee, US (Thread)
25. [SJ-JOB] Security Engineer, Beltsville, US (Thread)
26. [SJ-JOB] Security Engineer, Bala Cynwyd, US (Thread)
27. [SJ-JOB] Security Consultant, London + UK wide, GB (Thread)
28. [SJ-JOB] Sr. Security Analyst, Bloomington, US (Thread)
29. [SJ-JOB] Security Engineer, Bloomington, US (Thread)
30. [SJ-JOB] Application Security Engineer, Bloomington,... (Thread)
31. [SJ-JOB] Jr. Security Analyst, Dallas, US (Thread)
32. [SJ-JOB] Security Consultant, Florham Park, US (Thread)
33. [SJ-JOB] Security Consultant, New York City, US (Thread)
34. [SJ-JOB] Security Consultant, Tampa, US (Thread)
35. [SJ-JOB] Security Consultant, Atlanta, US (Thread)
36. [SJ-JOB] VP, Information Security, Houston, US (Thread)
37. [SJ-JOB] VP, Information Security, London, GB (Thread)
38. [SJ-JOB] Security Consultant, Singapore, SG (Thread)
39. [SJ-JOB] Security Consultant, Houston, US (Thread)
40. [SJ-JOB] Sales Engineer, London, GB (Thread)
41. [SJ-JOB] Manager, Information Security, Jersey City,... (Thread)
42. [SJ-JOB] Security Engineer, Fremont, US (Thread)
43. [SJ-JOB] Sr. Security Engineer, San Diego, US (Thread)
44. [SJ-JOB] Application Security Architect, Milwaukee, ... (Thread)
45. [SJ-JOB] Security Researcher, Redmond, US (Thread)
46. [SJ-JOB] Sales Engineer, Portland, US (Thread)
47. [SJ-JOB] Security Consultant, Metro NY, US (Thread)
48. [SJ-JOB] Technical Support Engineer, London, GB (Thread)
49. [SJ-JOB] Security Consultant, New York, US (Thread)
50. [SJ-JOB] Security Architect, NY, US (Thread)
51. [SJ-JOB] Security Consultant, Chesterfield ( NORTH E... (Thread)
52. [SJ-JOB] Manager, Information Security, Minneapolis,... (Thread)
53. [SJ-JOB] Manager, Information Security, Los Angeles,... (Thread)
54. [SJ-JOB] Management, Dallas, US (Thread)
55. [SJ-JOB] Application Security Architect, Dublin, US (Thread)
56. [SJ-JOB] Security Architect, Atlanta, US (Thread)
VI. INCIDENTS LIST SUMMARY
1. SSH probe attack afoot? (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
1. problem in off by one overflow (Thread)
2. win2k, XP deletes somename_files when somename.html ... (Thread)
3. xml over https (Thread)
4. IE crash (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
1. active directory password policy (Thread)
2. disclosure the administrative password (Thread)
3. ISA Server/WWW Blacklist (Thread)
4. SecurityFocus Microsoft Newsletter #226 (Thread)
5. Wireless GPO (Thread)
6. Preventing multiple logins in 2003 (Thread)
7. Domain logon without network connection + group poli... (Thread)
IX. SUN FOCUS LIST SUMMARY
NO NEW POSTS FOR THE WEEK 2005-02-01 to 2005-02-08.
X. LINUX FOCUS LIST SUMMARY
NO NEW POSTS FOR THE WEEK 2005-02-01 to 2005-02-08.
XI. HTML NEWSLETTER
XII. UNSUBSCRIBE INSTRUCTIONS
XIII. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. Penetration Testing IPsec VPNs
By Rohyt Belani and K.K. Mookhey
This article discusses a methodology to assess the security posture of an
organization's IPsec based VPN architecture.
http://www.securityfocus.com/infocus/1821
2. Linux Kernel Security is Lacking
By Jason Miller
Recent events have shown that the way security in the Linux kernel is
handled is broken, and it needs to be fixed right now.
http://www.securityfocus.com/columnists/296
3. Apache 2 with SSL/TLS: Step-by-Step, Part 2
By Artur Maj
This article is part two of a three part series dedicated to configuring
Apache 2.0 with SSL/TLS support, for maxiumum security and optimal
performance. This article offers mod_ssl recommendations and then discusses
three different ways to sign a certificate, including setting up a local
Certificate Authority using OpenSSL.
http://www.securityfocus.com/infocus/1820
4. Of Dog Sniffs and Packet Sniffs
By Mark Rasch
Why a Supreme Court decision on canine-assisted roadside searches opens the door to a new regime of Internet surveillance.
http://www.securityfocus.com/columnists/297
II. BUGTRAQ SUMMARY
-------------------
1. phpPGAds HTTP Response Splitting Vulnerability
BugTraq ID: 12398
Remote: Yes
Date Published: Jan 29 2005
Relevant URL: http://www.securityfocus.com/bid/12398
Summary:
phpPgAds is affected by a remote HTTP response splitting vulnerability. This could be exploited to influence or misrepresent how web content is served, cached or interpreted.
2. Captaris Infinite Mobile Delivery Webmail Path Disclosure Vu...
BugTraq ID: 12399
Remote: Yes
Date Published: Jan 29 2005
Relevant URL: http://www.securityfocus.com/bid/12399
Summary:
Infinite Mobile Delivery Webmail is reportedly affected by a path disclosure vulnerability. This issue could permit a malicious user to expose the root path of the affected application.
3. NCPFS Multiple Remote Vulnerabilities
BugTraq ID: 12400
Remote: Yes
Date Published: Jan 31 2005
Relevant URL: http://www.securityfocus.com/bid/12400
Summary:
Multiple remote vulnerabilities affect ncpfs. These issues are due to a failure to manage access privileges securely and a failure to validate the length of user-supplied strings prior to copying them into finite process buffers.
The first issue is a remote buffer overflow vulnerability. The second issue is an access validation issue due to the setuid privileges of ncpfs utilities.
An attacker may leverage these issues to execute arbitrary code with the privileges of the affected application and to access arbitrary files with the escalated privileges.
4. CitrusDB Credit Card Data Remote Information Disclosure Vuln...
BugTraq ID: 12402
Remote: Yes
Date Published: Jan 31 2005
Relevant URL: http://www.securityfocus.com/bid/12402
Summary:
A remote information disclosure issue affects CitrusDB. This issue is due to a design problem that grants unauthorized users the ability to export sensitive data.
An attacker may leverage this issue to gain access to sensitive information including credit card data.
5. JShop E-Commerce Suite Product.PHP Cross-Site Scripting Vuln...
BugTraq ID: 12403
Remote: Yes
Date Published: Jan 31 2005
Relevant URL: http://www.securityfocus.com/bid/12403
Summary:
JShop E-Commerce Suite is affected by a cross-site scripting vulnerability in the 'product.php' script.
As a result of this vulnerability, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of an unsuspecting user when followed. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
6. SmarterTools SmarterMail Cross-Site Scripting Vulnerability
BugTraq ID: 12405
Remote: Yes
Date Published: Jan 31 2005
Relevant URL: http://www.securityfocus.com/bid/12405
Summary:
SmarterTools SmarterMail is reportedly affected by a cross-site scripting vulnerability. This issue is due to the application failing to properly sanitize user-supplied input.
The vendor has reportedly addressed this issue in SmarterMail 2.0.1837.
Smartermail version 2.0.1733 is reportedly affected; earlier versions may also be vulnerable.
7. Xoops Incontent Module Directory Traversal Vulnerability
BugTraq ID: 12406
Remote: Yes
Date Published: Jan 28 2005
Relevant URL: http://www.securityfocus.com/bid/12406
Summary:
Xoops Incontent module is reported prone to a directory traversal vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input.
A malicious user could issue a request containing directory traversal strings such as '../' to possibly view files outside the server root directory.
Incontent version 3.0 is reported to be susceptible to this vulnerability. Other versions may also be affected.
8. Multiple Mozilla/Firefox/Thunderbird Vulnerabilities
BugTraq ID: 12407
Remote: Yes
Date Published: Jan 31 2005
Relevant URL: http://www.securityfocus.com/bid/12407
Summary:
Mozilla, Firefox, and Thunderbird applications are reported prone to multiple vulnerabilities. The following specific issues are reported:
Mozilla and Firefox browsers are reported prone to an access control bypass vulnerability. Although unconfirmed it is conjectured that this vulnerability may be exploited to disclose information pertaining to a target filesystem, for example determining whether a file exists or not.
This vulnerability is reported to affect Mozilla Firefox versions prior to version 1.0 and Mozilla Suite versions prior to version 1.7.5.
Mozilla and Firefox browsers are reported prone to a status bar misrepresentation vulnerability. A remote attacker may exploit this vulnerability to aid in phishing style attacks; for example, the attacker may leverage this vulnerability to make a malicious site appear authentic.
This vulnerability is reported to affect Mozilla Firefox versions prior to version 1.0 and Mozilla Suite versions prior to version 1.7.5.
Mozilla and Firefox browsers are reported prone to another status bar misrepresentation vulnerability. Using JavaScript to automate the process a remote attacker may exploit this vulnerability to aid in phishing style attacks, for example, the attacker may leverage this vulnerability to make a malicious site appear authentic.
This vulnerability is reported to affect Mozilla Firefox versions prior to version 1.0 and Mozilla Suite versions prior to version 1.7.5.
Mozilla and Firefox browsers provide functionality (Alt-Click) to download files that are linked by URI's to the default download location without requiring a user prompt. Reports indicate that a malicious site may exploit this functionality to download a file to the default downloads location without user interaction.
This vulnerability is reported to affect Mozilla Firefox versions prior to version 1.0.
Mozilla and Firefox browsers are reported prone to a clipboard information disclosure vulnerability. A remote attacker may exploit this vulnerability to steal clipboard contents, this may reveal potentially sensitive information to a remote attacker.
This vulnerability is reported to affect Mozilla Firefox versions prior to version 1.0 and Mozilla Suite versions prior to version 1.7.5.
Mozilla and Firefox browsers are reported prone to an information disclosure vulnerability. A remote malicious server may invoke a request against a vulnerable browser and the browser will respond with proxy authentication credentials.
This vulnerability is reported to affect Mozilla Firefox versions prior to version 1.0 and Mozilla Suite versions prior to version 1.7.5.
It is reported that Mozilla Thunderbird erroneously responds to cookie requests that are contained in HTML based email. It is reported that this vulnerability may be exploited by a remote attacker to track emails to victim users.
This vulnerability is reported to affect Thunderbird versions 0.6 to 0.9 and Mozilla Suite 1.7 to 1.7.3.
Mozilla Firefox is reported prone to a local code execution vulnerability. The vulnerability exists in Livefeed bookmark functionality. It is reported that if for example 'about:config' was displayed when the Livefeed is updated then arbitrary code execution may occur on the affected computer.
This vulnerability is reported to affect Mozilla Firefox versions prior to version 1.0.
It is reported that Mozilla Thunderbird does not correctly handle 'javascript:' URI links. The affected application employs the default handler for 'javascript:' URIs that is registered on the host operating system. This is incorrect behavior and may result in exposure to latent vulnerabilities due to a false sense of security.
This vulnerability is reported to affect Mozilla Thunderbird versions prior to version 0.9.
This BID will be separated into individual BIDs as soon as further research into each of the vulnerabilities is completed.
9. Clam Anti-Virus ClamAV ZIP File Parsing Remote Denial Of Ser...
BugTraq ID: 12408
Remote: Yes
Date Published: Jan 31 2005
Relevant URL: http://www.securityfocus.com/bid/12408
Summary:
A remote denial of service vulnerability affects ClamAV. This issue is due to a failure of the application to properly handle malicious file content.
An attacker may leverage this issue to crash the Clam Anti-Virus daemon, potentially leaving an affected computer open to infection by malicious code.
10. Techland XPand Rally Remote Denial Of Service Vulnerability
BugTraq ID: 12409
Remote: Yes
Date Published: Jan 31 2005
Relevant URL: http://www.securityfocus.com/bid/12409
Summary:
Techland XPand Rally client and server are reported prone to a remote denial of service vulnerability.
It is reported that this vulnerability may be exploited by a malicious game server to crash all running instances of the game client because of the broadcast methods used to track game servers online.
A remote attacker may exploit this vulnerability to deny service to legitimate users.
11. RealNetworks RealPlayer Drag And Drop Zone Bypass Vulnerabil...
BugTraq ID: 12410
Remote: Yes
Date Published: Feb 01 2005
Relevant URL: http://www.securityfocus.com/bid/12410
Summary:
RealNetworks RealPlayer is reported susceptible to a security zone bypass vulnerability. This issue is due to a failure of the application to properly enforce security zones, potentially allowing remote attackers to execute HTML or script code in the Local Zone of affected client computers.
The embedded Internet Explorer engine in RealPlayer reportedly loads attacker-supplied files in the Local Zone, allowing attackers to execute malicious HTML and script code with potentially elevated privileges. This issue may be a variant, or be related to BIDs 10973, or 11466.
It is unclear at this time if a further vulnerability has been discovered by this disclosure. This BID will be updated as further analysis is completed.
12. PostgreSQL LOAD Extension Local Privilege Escalation Vulnera...
BugTraq ID: 12411
Remote: No
Date Published: Feb 01 2005
Relevant URL: http://www.securityfocus.com/bid/12411
Summary:
A local privilege escalation vulnerability affects PostgreSQL. This issue is due to a failure of the application to restrict critical functionality to privileged users.
An attacker may leverage this issue to execute arbitrary code with the privileges of the affected database, potentially facilitating privilege escalation.
13. Squid Proxy Oversize HTTP Headers Unspecified Remote Vulnera...
BugTraq ID: 12412
Remote: Yes
Date Published: Feb 01 2005
Relevant URL: http://www.securityfocus.com/bid/12412
Summary:
A remote unspecified vulnerability reportedly affects Squid Proxy. This issue is due to a failure of the application to properly handle malformed HTTP headers.
The impact of this issue is currently unknown. This BID will be updated when more information becomes available.
14. SquirrelMail URL Remote Code Execution Vulnerability
BugTraq ID: 12413
Remote: Yes
Date Published: Feb 01 2005
Relevant URL: http://www.securityfocus.com/bid/12413
Summary:
A remote code execution vulnerability affects SquirrelMail. Although unconfirmed, it is likely that this issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in functionality designed to carry out critical actions.
An attacker may leverage this issue to execute arbitrary code with the privileges of the 'www-data' user; this may facilitate privilege escalation and system compromise.
15. Newsfetch SScanf Remote Buffer Overflow Vulnerability
BugTraq ID: 12414
Remote: Yes
Date Published: Feb 01 2005
Relevant URL: http://www.securityfocus.com/bid/12414
Summary:
Newsfetch makes several insecure sscanf calls that could potentially result in a buffer overflow. This is a result of insufficient bounds checking when sscanf stores data in an internal buffer.
16. IBM AIX NIS Client Unspecified Remote Code Execution Vulnera...
BugTraq ID: 12415
Remote: Yes
Date Published: Feb 01 2005
Relevant URL: http://www.securityfocus.com/bid/12415
Summary:
IBM AIX NIS client is reported prone to a remote arbitrary code execution vulnerability. This issue may allow remote attackers to gain unauthorized access to a vulnerable computer in the context of the user running the affected application.
IBM AIX 5.3 is reported vulnerable to this issue.
This BID will be updated when more information is available.
17. Eternal Lines Web Server Remote Denial Of Service Vulnerabil...
BugTraq ID: 12416
Remote: Yes
Date Published: Feb 01 2005
Relevant URL: http://www.securityfocus.com/bid/12416
Summary:
Eternal Lines Web Server is reported prone to a remote denial of service vulnerability. It is reported that the issue presents itself when the web service handles 70 or more simultaneous connections from a remote host.
A remote attacker may exploit this vulnerability to deny service to legitimate users.
18. PostgreSQL Multiple Remote Vulnerabilities
BugTraq ID: 12417
Remote: Yes
Date Published: Feb 01 2005
Relevant URL: http://www.securityfocus.com/bid/12417
Summary:
Multiple remote vulnerabilities affect PostgreSQL. These issues are due to design errors, buffer mismanagement errors, and issues that are currently unspecified.
The first issue is a failure of the application to ensure function permissions are enforced. The second issue is a buffer overflow triggered when cursor declaration occurs. The final vulnerability is an unspecified security issue that exists in 'contrib/intagg'. The information currently available is not sufficient to provide a more in-depth technical description. This BID will be updated with the release of further details.
An attacker may leverage these issues to execute arbitrary code with the privileges of the vulnerable database process and to execute functions without requiring permission. Other attacks are also possible.
19. Newspost Remote Buffer Overflow Vulnerability
BugTraq ID: 12418
Remote: Yes
Date Published: Feb 01 2005
Relevant URL: http://www.securityfocus.com/bid/12418
Summary:
Newspost is prone to a remote buffer overflow vulnerability due to an unbounded memory copy operation.
The problem occurs in the 'socket_getline()' function of 'socket.c' when the vulnerable client handles NNTP server responses.
Successful exploitation of this issue could potentially lead to arbitrary code execution.
This issue was reported to affect Newspost 2.1.1 and prior, however, other versions may be vulnerable.
20. ZipGenius Multiple Directory Traversal Vulnerabilities
BugTraq ID: 12419
Remote: Yes
Date Published: Feb 02 2005
Relevant URL: http://www.securityfocus.com/bid/12419
Summary:
ZipGenius is prone to multiple vulnerabilities that may allow an attacker to create files in arbitrary locations on a vulnerable computer. These issues result from insufficient sanitization of user-supplied data.
These issues present themselves when a file name containing directory traversal sequences is processed by the application.
ZipGenius 5.5 and prior versions are reported vulnerable to these issues.
21. Eurofull E-Commerce Mensresp.ASP Cross-Site Scripting Vulner...
BugTraq ID: 12420
Remote: Yes
Date Published: Feb 02 2005
Relevant URL: http://www.securityfocus.com/bid/12420
Summary:
Reportedly Eurofull E-Commerce is affected by a cross-site scripting vulnerability in the 'mensresp.asp' script. This issue is due to a failure of the application to properly sanitize user-supplied input.
As a result of this vulnerability, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of an unsuspecting user when followed.
22. Ventia DeskNow Mail And Collaboration Server Multiple Remote...
BugTraq ID: 12421
Remote: Yes
Date Published: Feb 02 2005
Relevant URL: http://www.securityfocus.com/bid/12421
Summary:
Multiple remote directory traversal vulnerabilities affect Ventia DeskNow Mail And Collaboration Server. These issues are due to a failure of the application to sanitize user-supplied input prior to using it to write and erase files.
The first issue affects the email attachment file upload functionality. The second issue surrounds the file delete functionality of the document repository feature.
An attacker may leverage this issue to delete and create arbitrary files on an affected computer. This may lead to code execution with the privileges of the affected server process as well as system wide denial of service attacks.
23. RARLAB WinRAR Directory Traversal Vulnerability
BugTraq ID: 12422
Remote: Yes
Date Published: Feb 02 2005
Relevant URL: http://www.securityfocus.com/bid/12422
Summary:
WinRAR is prone to a vulnerability that may allow an attacker to create files in arbitrary locations on a vulnerable computer.
This issue arises when a user right clicks on a file and attempts to decompress it.
WinRAR 3.42 and prior versions are reported vulnerable to this issue.
24. People Can Fly Painkiller Gamespy CD-Key Hash Remote Buffer ...
BugTraq ID: 12423
Remote: Yes
Date Published: Feb 02 2005
Relevant URL: http://www.securityfocus.com/bid/12423
Summary:
Painkiller is reported prone to a remote buffer overflow vulnerability. This issue presents itself due to insufficient boundary checks performed by the application during server-side authorization of a Gamespy cd-key hash.
Painkiller versions 1.35 and prior are reported vulnerable to this issue.
25. Cisco IP/VC Videoconferencing System SNMP Remote Default Com...
BugTraq ID: 12424
Remote: Yes
Date Published: Feb 02 2005
Relevant URL: http://www.securityfocus.com/bid/12424
Summary:
A default community string vulnerability affects Cisco IP/VC Videoconferencing System devices. This issue is due to a design flaw where hard-coded community strings are stored on the device.
This issue may be leveraged to gain unauthorized administrator access to affected devices. This would allow an attacker to create new services, terminate or affect existing sessions, and redirect traffic to a different destination, among other attacks.
26. PHP-Fusion Forum_Search.PHP Information Disclosure Vulnerabi...
BugTraq ID: 12425
Remote: Yes
Date Published: Feb 02 2005
Relevant URL: http://www.securityfocus.com/bid/12425
Summary:
PHP-Fusion is affected by an information disclosure vulnerability. This issue is due to the application failing to properly handle user-supplied input used in an SQL query.
This issue was reported to affect PHP-Fusion 4.01; earlier versions may also be vulnerable.
27. Perl SuidPerl Multiple Local Vulnerabilities
BugTraq ID: 12426
Remote: No
Date Published: Feb 02 2005
Relevant URL: http://www.securityfocus.com/bid/12426
Summary:
SuidPerl is reported prone to multiple vulnerabilities. The following individual issues are reported:
It is reported that the 'PERLIO_DEBUG' SuidPerl environment variable may be employed to corrupt arbitrary files.
A local unprivileged attacker may exploit this vulnerability to corrupt arbitrary files with superuser privileges. This may ultimately lead to a denial of service for legitimate users or privilege escalation.
SuidPerl is reported prone to a local buffer overflow vulnerability as well. This buffer overflow vulnerability may be exploited by a local attacker to gain superuser privileges. This issue is also exploited through the 'PERLIO_DEBUG' variable.
28. Microsoft Internet Explorer AddChannel Cross-Zone Scripting ...
BugTraq ID: 12427
Remote: Yes
Date Published: Feb 02 2005
Relevant URL: http://www.securityfocus.com/bid/12427
Summary:
A vulnerability has been reported in Microsoft Internet Explorer that could enable unauthorized access by malicious scripts and Active Content to document properties across different Security Zones and foreign domains.
This issue is exposed when a remote site uses the 'AddChannel' method to add a channel.
Exploitation of this issue could allow various attacks, such as cookie-theft from an arbitrary domain. Other issues may also facilitate execution of arbitrary code on a vulnerable client system by causing malicious content to be stored on the victim system and then referenced.
29. Newsgrab Multiple Local And Remote Vulnerabilities
BugTraq ID: 12428
Remote: Yes
Date Published: Feb 02 2005
Relevant URL: http://www.securityfocus.com/bid/12428
Summary:
Newsgrab is reported prone to multiple vulnerabilities. The following individual issues are reported:
Newsgrab is reported prone to a directory traversal vulnerability. This vulnerability exists because the software does not sufficiently sanitize directory traversal sequences from filenames before the filename is employed to store the file onto disk.
A remote attacker may exploit this vulnerability by supplying a malicious file to a target victim. This vulnerability has been assigned the CVE identifier CAN-2005-0153.
Newsgrab is reported prone to an unspecified insecure permissions vulnerability.
A local attacker may exploit this vulnerability to disclose potentially sensitive information that is contained in files that were downloaded using newsgrab. This vulnerability has been assigned the CVE identifier CAN-2005-0154.
30. Savant Web Server Remote Buffer Overflow Vulnerability
BugTraq ID: 12429
Remote: Yes
Date Published: Feb 02 2005
Relevant URL: http://www.securityfocus.com/bid/12429
Summary:
A remote buffer overflow vulnerability reportedly affects Savant Web Server. This issue is due to a failure of the application to validate the length of user-supplied strings prior to copying them into finite process buffers.
An attacker may leverage this issue remotely to execute arbitrary code with the privileges of the affected web server. This issue may facilitate unauthorized access or privilege escalation.
31. Qualcomm Eudora Multiple Unspecified Vulnerabilities
BugTraq ID: 12430
Remote: Yes
Date Published: Feb 02 2005
Relevant URL: http://www.securityfocus.com/bid/12430
Summary:
Eudora is reported prone to multiple unspecified vulnerabilities. It is reported that these issues may be leveraged by a remote attacker to execute arbitrary code.
Reports indicate that these issues may be triggered when a specially crafted email is previewed or opened and when a specially crafted stationary or mailbox file is opened.
These issues are reported to affect Eudora versions prior to 6.2.1 for Microsoft Windows platforms only.
32. Squid Proxy squid_ldap_auth Authentication Bypass Vulnerabil...
BugTraq ID: 12431
Remote: Yes
Date Published: Feb 02 2005
Relevant URL: http://www.securityfocus.com/bid/12431
Summary:
Squid Proxy is reported prone to an authentication bypass vulnerability. This issue seems to result of insufficient input validation.
It is reported that the 'squid_ldap_auth' module is affected by this issue. A remote attacker may gain unauthorized access or gain elevated privileges from bypassing access controls.
Squid versions 2.5 and earlier are reported prone to this vulnerability.
33. Squid Proxy WCCP recvfrom() Buffer Overflow Vulnerability
BugTraq ID: 12432
Remote: Yes
Date Published: Feb 02 2005
Relevant URL: http://www.securityfocus.com/bid/12432
Summary:
The Squid proxy server is vulnerable to a remotely exploitable buffer overflow vulnerability. The vulnerability is in its implementation of WCCP (web cache communication protocol), a UDP based web cache management protocol. The condition is triggered when it reads a packet from the network that is larger than the size of the buffer allocated to store it. This can occur because recvfrom() is passed an incorrect value for its "len" argument.
34. Squid Proxy Malformed HTTP Header Parsing Cache Poisoning Vu...
BugTraq ID: 12433
Remote: Yes
Date Published: Feb 02 2005
Relevant URL: http://www.securityfocus.com/bid/12433
Summary:
Squid Proxy is reported prone to a cache poisoning vulnerability when processing malformed HTTP requests and responses. This issue results from insufficient sanitzation of user-supplied data.
Squid versions 2.5 and earlier are reported prone to this issue.
35. ngIRCd Remote Format String Vulnerability
BugTraq ID: 12434
Remote: Yes
Date Published: Feb 03 2005
Relevant URL: http://www.securityfocus.com/bid/12434
Summary:
ngIRCd is reported prone to a remote format string vulnerability. This issue presents itself because the application fails to properly sanitize user-supplied input prior to passing it as the format specifier to a formatted printing function.
A remote attacker may leverage this issue to write to arbitrary process memory, facilitating code execution. Any code execution would take place with superuser privileges.
ngIRCd 0.8.2 and prior versions are reported vulnerable to this issue.
36. D-BUS Session Bus Local Privilege Escalation Vulnerability
BugTraq ID: 12435
Remote: No
Date Published: Feb 03 2005
Relevant URL: http://www.securityfocus.com/bid/12435
Summary:
A local privilege escalation vulnerability affects D-BUS. This issue is due to a failure of the application to properly secure message bus sessions.
An attacker may leverage this issue to send messages to the message bus of an unsuspecting user. This may facilitate command execution with the privileges of the unsuspecting user, ultimately leading to privilege escalation.
37. Mambo Open Source Global Variables Unauthorized Access Vulne...
BugTraq ID: 12436
Remote: Yes
Date Published: Feb 02 2005
Relevant URL: http://www.securityfocus.com/bid/12436
Summary:
Mambo Open Source is reported prone to a vulnerability that can allow remote attackers to gain complete unauthorized access to an affected Web site or the database used by the application.
It is reported that this issue results from improper implementation of global variables.
All versions of Mambo Open Source prior to and including 4.5.1 are reported vulnerable to this issue.
38. Python SimpleXMLRPCServer Library Module Unauthorized Access...
BugTraq ID: 12437
Remote: Yes
Date Published: Feb 03 2005
Relevant URL: http://www.securityfocus.com/bid/12437
Summary:
A remote unauthorized access vulnerability affects Python. This issue is due to a failure of the API to properly secure access to sensitive internal data or functionality of registered objects and modules.
A remote attacker may leverage this issue to gain unauthorized access to an affected computer. Other attacks are also possible.
39. SunShop Shopping Cart Cross-Site Scripting Vulnerability
BugTraq ID: 12438
Remote: Yes
Date Published: Feb 03 2005
Relevant URL: http://www.securityfocus.com/bid/12438
Summary:
SunShop Shopping Cart is reportedly affected by a cross-site scripting vulnerability. This issue is due to the application failing to properly sanitize user-supplied input.
This issue is reported to affect SunShop Shopping Cart version 3.4RC1; earlier versions may also be affected.
40. LANChat Pro Revival UDP Processing Remote Denial Of Service ...
BugTraq ID: 12439
Remote: Yes
Date Published: Feb 03 2005
Relevant URL: http://www.securityfocus.com/bid/12439
Summary:
LANChat Pro Revival is reported prone to a remote denial of service vulnerability. It is reported that the issue presents itself when the vulnerable client processes a malformed UDP datagram.
A remote attacker may exploit this vulnerability to crash the affected application effectively denying service to legitimate users.
41. Microsoft Multiple Unspecified Security Vulnerabilities
BugTraq ID: 12440
Remote: Unknown
Date Published: Feb 03 2005
Relevant URL: http://www.securityfocus.com/bid/12440
Summary:
Microsoft has released advanced notification that they will be releasing three security bulletins for Windows on February 8th, 2005. The vendor has not enumerated how many vulnerabilities will be addressed by these security bulletins, nor what specific components or platforms may be affected.
The maximum severity rating of any of these bulletins is 'Critical'.
42. Linux Kernel IPV6_Setsockopt IPV6_PKTOPTIONS Integer Overflo...
BugTraq ID: 12441
Remote: No
Date Published: Feb 03 2005
Relevant URL: http://www.securityfocus.com/bid/12441
Summary:
An integer overflow vulnerability is reported in the Linux kernel 'ipv6_setsockopt()' system call. This issue is related to the code for handling the IPV6_PKTOPTIONS socket option, which is used to provide the kernel with IPv6 options for a designation socket.
This issue may be exploited by a local user to compromise the system. Exploitation could also result in a denial of service. It should be noted that this type of vulnerability might provide a generic means of privilege escalation across Linux distributions once a remote attacker has gained unauthorized access as a lower privileged user.
**Update: Conflicting reports suggest that this issue is not in fact a vulnerability. It is reported that the 'optlen' value is sanitized in 'linux/net/socket.c' before reaching the code that is reported vulnerable.
43. ht://Dig Unspecified Cross-Site Scripting Vulnerability
BugTraq ID: 12442
Remote: Yes
Date Published: Feb 03 2005
Relevant URL: http://www.securityfocus.com/bid/12442
Summary:
ht://Dig is reported prone to an unspecified cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI data prior to including it in dynamically generated Web page content.
All versions of ht://Dig are considered vulnerable at the moment.
This BID will be updated when more information becomes available.
44. Linksys PSUS4 PrintServer Malformed HTTP POST Request Denial...
BugTraq ID: 12443
Remote: Yes
Date Published: Feb 03 2005
Relevant URL: http://www.securityfocus.com/bid/12443
Summary:
Linksys PSUS4 PrintServer is reported prone to a remote denial of service vulnerability while handling certain HTTP POST requests received on TCP port 80.
An attacker may exploit this condition to deny service to the affected PrintServer.
45. MediaWiki Unspecified Cross-Site Scripting Vulnerability
BugTraq ID: 12444
Remote: Yes
Date Published: Feb 04 2005
Relevant URL: http://www.securityfocus.com/bid/12444
Summary:
An unspecified remote cross-site scripting vulnerability affects MediaWiki. This issue is due to a failure of the application to properly sanitize user-supplied input prior to using it in dynamically generated Web page content.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
46. Postfix IPv6 Unauthorized Mail Relay Vulnerability
BugTraq ID: 12445
Remote: Yes
Date Published: Feb 04 2005
Relevant URL: http://www.securityfocus.com/bid/12445
Summary:
Postfix is prone to a vulnerability that allows the application to be abused as a mail relay.
Arbitrary mail may be sent to any MX host with an IPv6 address. This could be exploited by spammers or other malicious parties.
Postfix 2.1.3 is reported prone to this issue. It is possible that other versions are affected as well.
47. PowerDNS Unspecified Remote Denial of Service Vulnerability
BugTraq ID: 12446
Remote: Yes
Date Published: Feb 04 2005
Relevant URL: http://www.securityfocus.com/bid/12446
Summary:
PowerDNS is reported prone to an unspecified remote denial of service vulnerability. It is conjectured that this issue likely results from the failure of the application to handle exceptional conditions.
PowerDNS versions prior to 2.9.17 are reported vulnerable to this issue.
48. Netgear DG834 ADSL Firewall Router Insecure Configuration Vu...
BugTraq ID: 12447
Remote: Yes
Date Published: Feb 04 2005
Relevant URL: http://www.securityfocus.com/bid/12447
Summary:
The Netgear DG834 ADSL Firewall Router is reported prone to a firewall insecure configuration vulnerability. It is reported that when the affected appliance is configured so that NAT (Network Address Translation) is disabled the firewall becomes ineffective.
This vulnerability will result in a false sense of security where a user may believe that their network and appliance is protected when it is not.
49. Claroline Add_Course.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 12449
Remote: Yes
Date Published: Feb 04 2005
Relevant URL: http://www.securityfocus.com/bid/12449
Summary:
Reportedly Claroline is affected by a cross-site scripting vulnerability in the 'add_course.php' script. This issue is due to a failure of the application to properly sanitize user-supplied input.
As a result of this vulnerability, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of an unsuspecting user when followed. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Shhhh. U.S. appeals USA PATRIOT loss
By: Kevin Poulsen
The Justice Department has appealed a court ruling that revoked the FBI's power to issue secret orders for customer ISP records. Just don't tell anyone.
http://www.securityfocus.com/news/10432
2. Supreme Court puts hacker sentences up for grabs
By: Kevin Poulsen
Experts say a January decision giving judges discretion in setting federal sentences will change the way computer crime cases are argued.
http://www.securityfocus.com/news/10404
3. Clear skies for Area 51 hacker
By: Kevin Poulsen
Federal prosecutors dismiss a felony charge against a man who dug up government surveillance devices buried in the Nevada desert.
http://www.securityfocus.com/news/10373
4. Latest antivirus company purchase for Microsoft
By: Allison Linn, The Associated Press
http://www.securityfocus.com/news/10444
5. Microsoft bolsters email security with Sybari acquisition
By: John Oates, The Register
Microsoft is strengthening its security expertise with the purchase of Sybari Software for an undisclosed amount.
http://www.securityfocus.com/news/10443
6. phpBB forum offline after defacement
By: John Leyden, The Register
The popular phpBB forum has been taken offline after hackers cracked into its server and defaced its website yesterday.
http://www.securityfocus.com/news/10442
IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Secure Hive 1.0.0.1
By: Secure Hive
Relevant URL: http://www.securehive.com/Secure%20Hive.htm
Platforms: Windows 2000, Windows NT, Windows XP
Summary:
What Does Secure Hive Enterprise Offer?
Encryption of part, or entire, Word documents, Excel worksheets or PowerPoint presentations through Secure Hive's integration with Microsoft Office.
Encryption of part, or entire, content of common documents (such as Notepad, WordPad), email messages and instant messages, including mixed text and graphics, with Secure Hive's Clipboard Encryption feature.
2. SigupShield 3.0
By: Protecteer, LLC
Relevant URL: http://www.protecteer.com/install3/full/sus.exe
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
A fraud alert (Anti-Phishing) software integrated with a full life-cycle password manager & form filler. SignupShield generates unlimited number of unique passwords and disposable email addresses for signing-up to web sites.
It fills sign-up forms and encrypts passwords and email addresses for later use during sign-in.
3. DigSig 1.3.2
By:
Relevant URL: http://sourceforge.net/projects/disec/
Platforms: Linux
Summary:
DigSig Linux kernel load module checks the signature of a binary before running it. It inserts digital signatures inside the ELF binary and verify this signature before loading the binary. Therefore, it improves the security of the system by avoiding a wide range of malicious binaries like viruses, worms, Torjan programs and backdoors from running on the system.
4. msndump 1.4
By: miscname
Relevant URL: http://miscname.com/public/msndump/
Platforms: Perl (any system supporting perl)
Summary:
msndump - a quick msn messenger sniffer
$ perl msndump.pl
[ msndump - miscname.com ]
Usage:
-i rl0 || -r file.pcap
-c X - capture X packets
-w freshIMz.txt
-v show all msn IM data
5. PE Explorer 1.96
By: Heaventools Software
Relevant URL: http://www.heaventools.com/overview.htm
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
PE Explorer is a tool for inspecting and editing the inner workings of Windows 32-bit executable files. It offers a look at PE file structure and all of the resources in the file, and reports multiple details about a PE file (EXE, DLL, ActiveX controls, and several other Windows executable formats). Once inside, file structure can be analyzed and optimized, hostile code detected, spyware tracked down, problems diagnosed, changes made and resources repaired.
6. Firestarter 1.0.0
By: Tomas Junnonen
Relevant URL: http://www.fs-security.com/
Platforms: Linux
Summary:
Firestarter is graphical firewall tool for Linux. The program aims to combine
ease of use with powerful features, serving both desktop users and administrators.
V. SECURITYJOBS LIST SUMMARY
----------------------------
1. [SJ-JOB] Jr. Security Analyst, Dearborn, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389703
2. [SJ-JOB] Sr. Security Engineer, Chicago, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389700
3. [SJ-JOB] Security Consultant, Scottsdale, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389663
4. [SJ-JOB] Jr. Security Analyst, Melbourne, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389662
5. [SJ-JOB] Security System Administrator, Frederick, U... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389661
6. [SJ-JOB] Security Engineer, Dearborn, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389656
7. [SJ-JOB] Security Consultant, Chicago, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389655
8. [SJ-JOB] Forensics Engineer, Melbourne, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389649
9. [SJ-JOB] VP of Regional Sales, London / South East, ... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389648
10. [SJ-JOB] Information Assurance Analyst, Melbourne, U... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389647
11. [SJ-JOB] Security System Administrator, Dearborn, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389645
12. [SJ-JOB] Security Consultant, Alexandria, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389644
13. [SJ-JOB] Information Assurance Analyst, San Francisc... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389643
14. [SJ-JOB] Sales Representative, San Diego, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389642
15. [SJ-JOB] Security Consultant, London & throughout th... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389640
16. [SJ-JOB] Security Engineer, Champaign, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389414
17. [SJ-JOB] Manager, Information Security, London, GB (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389411
18. [SJ-JOB] Security Engineer, Any, DE (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389409
19. [SJ-JOB] Security Consultant, County: Berkshire, GB (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389408
20. [SJ-JOB] Account Manager, San Francisco, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389407
21. [SJ-JOB] Security Consultant, London, GB (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389406
22. [SJ-JOB] Security Engineer, Any, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389405
23. [SJ-JOB] Security Engineer, Southern California, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389404
24. [SJ-JOB] Security Consultant, Tallahassee, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389380
25. [SJ-JOB] Security Engineer, Beltsville, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389379
26. [SJ-JOB] Security Engineer, Bala Cynwyd, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389378
27. [SJ-JOB] Security Consultant, London + UK wide, GB (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389377
28. [SJ-JOB] Sr. Security Analyst, Bloomington, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389376
29. [SJ-JOB] Security Engineer, Bloomington, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389375
30. [SJ-JOB] Application Security Engineer, Bloomington,... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389373
31. [SJ-JOB] Jr. Security Analyst, Dallas, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389372
32. [SJ-JOB] Security Consultant, Florham Park, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389371
33. [SJ-JOB] Security Consultant, New York City, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389370
34. [SJ-JOB] Security Consultant, Tampa, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389369
35. [SJ-JOB] Security Consultant, Atlanta, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389368
36. [SJ-JOB] VP, Information Security, Houston, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389367
37. [SJ-JOB] VP, Information Security, London, GB (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389366
38. [SJ-JOB] Security Consultant, Singapore, SG (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389365
39. [SJ-JOB] Security Consultant, Houston, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389364
40. [SJ-JOB] Sales Engineer, London, GB (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389275
41. [SJ-JOB] Manager, Information Security, Jersey City,... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389274
42. [SJ-JOB] Security Engineer, Fremont, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389273
43. [SJ-JOB] Sr. Security Engineer, San Diego, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389136
44. [SJ-JOB] Application Security Architect, Milwaukee, ... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389135
45. [SJ-JOB] Security Researcher, Redmond, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389134
46. [SJ-JOB] Sales Engineer, Portland, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389133
47. [SJ-JOB] Security Consultant, Metro NY, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389132
48. [SJ-JOB] Technical Support Engineer, London, GB (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389091
49. [SJ-JOB] Security Consultant, New York, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389090
50. [SJ-JOB] Security Architect, NY, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389089
51. [SJ-JOB] Security Consultant, Chesterfield ( NORTH E... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389088
52. [SJ-JOB] Manager, Information Security, Minneapolis,... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389087
53. [SJ-JOB] Manager, Information Security, Los Angeles,... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389086
54. [SJ-JOB] Management, Dallas, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389051
55. [SJ-JOB] Application Security Architect, Dublin, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389048
56. [SJ-JOB] Security Architect, Atlanta, US (Thread)
Relevant URL:
http://www.securityfocus.com/archive/77/389041
VI. INCIDENTS LIST SUMMARY
--------------------------
1. SSH probe attack afoot? (Thread)
Relevant URL:
http://www.securityfocus.com/archive/75/389721
VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. problem in off by one overflow (Thread)
Relevant URL:
http://www.securityfocus.com/archive/82/389683
2. win2k, XP deletes somename_files when somename.html ... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/82/389681
3. xml over https (Thread)
Relevant URL:
http://www.securityfocus.com/archive/82/389591
4. IE crash (Thread)
Relevant URL:
http://www.securityfocus.com/archive/82/389298
VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. active directory password policy (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/389755
2. disclosure the administrative password (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/389639
3. ISA Server/WWW Blacklist (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/389600
4. SecurityFocus Microsoft Newsletter #226 (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/389599
5. Wireless GPO (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/389174
6. Preventing multiple logins in 2003 (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/389108
7. Domain logon without network connection + group poli... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/389107
IX. SUN FOCUS LIST SUMMARY
--------------------------
NO NEW POSTS FOR THE WEEK 2005-02-01 to 2005-02-08.
X. LINUX FOCUS LIST SUMMARY
---------------------------
NO NEW POSTS FOR THE WEEK 2005-02-01 to 2005-02-08.
XI. HTML NEWSLETTER
----------------------------
SecurityFocus is currently planning the launch of a refined HTML version of this newsletter. To subscribe, send a blank email to [email protected]
XII. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XIII. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored By: RSA
RSA Conference 2005
The RSA Conference is the most prestigious information security event of
the year! This is the authoritative source for uncovering new ways to
thwart cyber-criminals. Learn. Network. Grow. RSA Conference 2005 takes
place February 14 to 18, 2005 in San Francisco.
http://www.securityfocus.com/sponsor/RSA_sf-news_050208
------------------------------------------------------------------------
Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!
http://www.securityfocus.com/sponsor/Symantec_sf-news_041130
------------------------------------------------------------------------