SecurityFocus Newsletter #152

John Boletta <[email protected]> Mon, 8 Jul 2002 11:59:38 -0600 (MDT)
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #152
-----------------------------

This Issue is Sponsored by: BlackHat

Black Hat Briefings & Training

Attend Black Hat Briefings & Training, July 29 - August 1, Las Vegas, the
world's premier technical security event! 8 tracks, 12 training sessions,
Richard Clarke keynote, 1500 delegates from 30 nations, with a near cult
following of both CSOs and "underground" security experts.  See for
yourself what the buzz is all about.

Visit us at: http://www.blackhat.com

-------------------------------------------------------------------------------

I. FRONT AND CENTER
     1. Clickwrap and Shrinkwrap Risks: The Security Concerns of...
     2. Twenty Don'ts for ASP Developers
     3. One of These Things is not Like the Others: The State of...
     4. Secure i-World
     5. Palladium holds Promise, and Peril
     6. Cyberwar is Hell
II. BUGTRAQ SUMMARY
     1. Macromedia ColdFusion MX jrun.dll Buffer Overflow Vulnerability
     2. Macromedia JRun Administrative Authentication Bypass Vulnerability
     3. Multiple Vendor WEB-INF Directory Contents Disclosure...
     4. Sendmail DNS Map TXT Record Buffer Overflow Vulnerability
     5. F2HTML.PL SQL Injection Vulnerability
     6. PHP Ticket Cross Site Scripting Vulnerability
     7. Bonobo EFSTool Commandline Argument Buffer Overflow Vulnerability
     8. Apple MacOS X World Readable Local.NIDump Encrypted Password...
     9. Simple WAIS Interface Arbitrary Command Execution Vulnerability
     10. E-Guest Guest Book Script Injection Vulnerability
     11. E-Guest Server Side Include Arbitrary Command Execution...
     12. Zap Book Server Side Include Arbitrary Command Execution...
     13. Zap Book Script Injection Vulnerability
     14. Macromedia Sitespring Database Engine Denial Of Service...
     15. Macromedia JRun Source Disclosure Vulnerabilities
     16. Betsie Parserl.PL Cross-Site Scripting Vulnerability
     17. OmniHTTPD Long Request Buffer Overflow Vulnerability
     18. Blackboard Cross-Site Scripting Vulnerability
     19. AnalogX Proxy Socks4A Buffer Overflow Vulnerability
     20. AnalogX Proxy Web Proxy Buffer Overflow Vulnerability
     21. Slashcode Paragraph Tag Script Injection Vulnerability
     22. PHPAuction Unauthorized Administrative Access Vulnerability
     23. HP-UX DCE Client IPv6 Denial of Service Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
     1. Fugitive DEA Agent Arrested in Mexico
     2. Yaha Worm Takes Out Pakistan Government's Site
     3. Mitnick Testifies Against Sprint in Vice Hack Case
     4. Gobbles Releases Apache Exploit
IV.SECURITYFOCUS TOP 6 TOOLS
     1. RADIUS module for Ruby v1.0.0
     2. netspeed_applet for gnome v0.1
     3. Pound v0.5
     4. Wireless Access Point Utilites for Unix v1.0.2
     5. SimpleFirewall v0.6-4
     6. conntrack viewer v1.1
V. SECURITYJOBS LIST SUMMARY
     1. Kentucky Location - Networking security Specialist (Thread)
     2. seeking bay area employment (Thread)
     3. Boston area Security Architect/CISSP looking for new position...
     4. Security Consultant / Security Architect role - South East UK...
     5. Need Some More Network Exploitation Analyst- Come on, Give it...
     6. Relocating to Washington, D.C./Baltimore area this weekend...
     7. Looking for work (Thread)
     8. Information Security Strategist - OR - $85K (Thread)
     9. Information Security Professional (Thread)
     10. Security Architect in OR ready to relocate (Thread)
     11. Looking for a Senior Security Position (Thread)
     12. Security Consultant - Baltimore, MD (Thread)
     13. Looking for Sec Oppty in VA-MD-DC-Metro or elsewhere (Thread)
VI. INCIDENTS LIST SUMMARY
     1. Closed thread- Anyone seen this before? (Thread)
     2. Additional- Anyone seen this before? (Thread)
     3. Anyone seen this before? (Thread)
     4. OpenSSH Attack? (Thread)
     5. ftp.bitchx.org's ircii-pana-1.0c19.tar.gz is backdoored (Thread)
     6. Honeynet Project - SotM and Reverse Challenge (Thread)
     7. Java Yahoo! Chat and disabled keyboards (Thread)
     8. EarlyBird for Other Attacks? (Thread)
     9. Textbook CodeRed v2 Caught By Snort (Thread)
     10. FW: 33 character encrypted passwords in /etc/shadow (Thread)
     11. spoofed packets to RFC 1918 addresses (Thread)
     12. FW: Apache worm in the wild (Thread)
     13. Someone looking for CodeRed infected boxes ? (Thread)
     14. 33 character encrypted passwords in /etc/shadow (Thread)
     15. win2k server issue (Thread)
     16. unexplained port 524 probes payload "cko" (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. Ports 0-1023? (Thread)
     2. WinNT and previously used passwords (Thread)
     3. nn format string exploit (Thread)
     4. UnBodyGuard a.k.a Bouncer (Solaris kernel function hijacking)...
     5. Possible flaw in XFree? (Thread)
     6. Hijacking the hashes : multiple windows mail clients...
     7. Hijacking the hashes : multiple windows mail clients...
     8. NEC's socks5 ( Foundstone Advisory - Buffer Overflow in...
     9. spying (deleted) file entries in other users' directories (Thread)
     10. Noguska Nola 1.1.1 [ Intranet Business Management Software ]...
     11. BufferOverflow in OmniHTTPd 2.09 (Thread)
     12. login yahoogroups. (Thread)
     13. Simple Wais 1.11 allows users to execute commands as SWAIS...
     14. FW: Possible flaw in XFree? (Thread)
     15. OpenSSh 3.4p1 PrivilegeSerparation experiment (Thread)
     16. possible stack flow in bash (Thread)
     17. Java and buffer overflows (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. Strange event showing up... (Thread)
     2. Replication on Sql Server 2k - Sql Server Agent Account (Thread)
     3. Can I shut down individual TCP connections? (Thread)
     4. SecurityFocus Microsoft Newsletter #93 (Thread)
IX. SUN FOCUS LIST SUMMARY
     1. Sun OpenSSH for Solaris 8? (Thread)
     2. Apache Worm Update (Thread)
     3. Sun statement on the OpenSSH Remote Challenge Vulnerability...
     4. Apache worm (Thread)
     5. Solaris security module needs some help (Thread)
X. LINUX FOCUS LIST SUMMARY
     1. OpenSSH 3.4 rpm spec file for redhat (Thread)
     2. Apache update from SuSE ?? (Thread)
     3. Worm update info (Thread)
     4. Apache worm (Thread)
XI. SPONSOR INFORMATION




I. FRONT AND CENTER
-------------------
1. Clickwrap and Shrinkwrap Risks: The Security Concerns of Licensing
Agreements
By Steven Robinson

This is the first of two articles that will discuss some security issues
surrounding software licenses and agreements for Web-based information
services. This article will discusses why security professionals need to
be particularly aware of some issues that these licensing agreements
present.

http://online.securityfocus.com/infocus/1602

2. Twenty Don'ts for ASP Developers
by Mark Burnett

Firewalls block hackers from directly connecting to your network shares.
Windows administrators keep their systems up-to-date with the latest
software patches to thwart worms such as Nimda and Code Red. And user
passwords are stronger than ever. But are we secure yet? While the
situation is much better than it was just a couple years ago, many
companies are still quite vulnerable to a number of attacks. Blocking
ports and installing patches has not stopped hackers, it has just forced
them to find new ways to break in. And chances are, the first place they
are going to look is your Web application.

http://online.securityfocus.com/infocus/1603

3.  One of These Things is not Like the Others: The State of Anomaly
Detection
by Matthew Tanase

"To some, our observations can be summarized succinctly as "bugs happen".
That certainly is not news. But dismissing our results so cavalierly
misses the point. Yes, bugs happen. But bugs can be fixed -if they are
detected. The Internet is, as a whole, working remarkably well. Huge
software packages (i.e., X11R5) can be distributed electronically.
Connections span the globe. But the very success of the Internet makes
some bugs invisible." - Steven Bellovin

http://online.securityfocus.com/infocus/1600

4. Secure i-World

August 19-21, 2002, San Diego, CA
Optional Workshops August 17, 18,  21, & 22
Vendor Expo August 19 & 20

WebSec 2002, Online Privacy Conference, Secure i-World ExpoÂ…two innovative
conferences and one outstanding expo, all in one blockbuster event.

Please visit us at: http://www.secureiworld.com/06/sw02nl18inf.html

5. Palladium holds Promise, and Peril
By Tim Mullen

The responses to the recent publication of Microsoft's "Palladium" project
are as varied as the putative sources of the initiative's namesake in
Greek Mythology.

http://online.securityfocus.com/columnists/93

6. Cyberwar is Hell
By George Smith

The campaign against cyber terrorism has at least one thing in common with
genuine conflicts... wartime profiteers.

http://online.securityfocus.com/columnists/92


II. BUGTRAQ SUMMARY
-------------------
1. Macromedia ColdFusion MX jrun.dll Buffer Overflow Vulnerability
BugTraq ID: 5121
Remote: Yes
Date Published: Jun 28 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5121
Summary:

Macromedia has reported a buffer overflow condition in ColdFusion MX
server when used with Microsoft IIS.

The condition is reportedly present in `jrun.dll' and may be triggered
when malformed HTTP requests are received.  The overflow occurs if a
request has HTTP header values exceeding 4096 bytes in length, or if a
template filename is greater than 8092 bytes in length.

At the very least, this condition may be exploited to cause a denial of
IIS service.  Macromedia has stated that exploitation may cause IIS to
become unresponsive until it is manually restarted.

It is not yet known if attackers can exploit this vulnerability to execute
arbitrary code.

2. Macromedia JRun Administrative Authentication Bypass Vulnerability
BugTraq ID: 5118
Remote: Yes
Date Published: Jun 28 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5118
Summary:

Macromedia JRun is a J2EE application server for use with IIS 4/5 on the
Microsoft Windows operating systems.

Macromedia JRun includes a web-based administrative console which listens
on TCP port 8000.  When this page is accessed, the user is prompted for an
administrative login.  However, by submitting a malformed request for this
page, authentication can be bypassed.

This may be exploited by adding an extraneous '/' to a request for the
administrative authentication page.  For this issue to be successfully
exploited, the attacker must make a properly formatted request for a
specific administrative function.  The links on the administrative page
will just direct the attacker to the login page.

3. Multiple Vendor WEB-INF Directory Contents Disclosure Vulnerability
BugTraq ID: 5119
Remote: Yes
Date Published: Jun 28 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5119
Summary:

An issue has been discovered in Sybase Enterprise Application Server,
Oracle9i Application Server with OC4J, Orion Server, Macromedia/Allaire
JRun, HP Application Server, Pramati Application Server and jo! Webserver.

The listed application servers reportedly do not adequately prevent access
to the WEB-INF directory.  As a result it is possible for remote users to
obtain access to restricted files residing in the WEB-INF directory.

The WEB-INF directory contains Java class files and detailed web
application configuration information.

Submitting a request for the WEB-INF directory, along with a known
resource, and appended with a '.' will successfully reveal the sensitive
content.

Obtaining information within this directory could result in the disclosure
of highly sensitive data that could be used to leverage further attacks
against the host.

4. Sendmail DNS Map TXT Record Buffer Overflow Vulnerability
BugTraq ID: 5122
Remote: Yes
Date Published: Jun 28 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5122
Summary:

Sendmail is a freely available, open source mail transport agent.  It is
available for most Unix and Linux operating systems.

A problem with Sendmail has been reported that may allow remote code
execution.  The problem is in the handling of some types of DNS records.

A buffer overflow in the DNS handling code of Sendmail has been
discovered.  Sendmail attempting to map an address using a TXT query type
does not properly check bounds on data returned from the nameserver.
Because of this, a malicious nameserver could send a string of arbitrary
length to the mail server, resulting in a buffer overflow, and potential
code execution.

It has been asserted by the Sendmail Consortium that there are no known
configurations that use this type of DNS mapping.  Because of this, the
likelihood of exploitation is considered to be low, and has been called
"theoretical" by the Sendmail Consortium.

If the vulnerability were to be exploited by a malicious nameserver, code
would be executed on the vulnerable system with the privileges of the
sendmail program.  As this program is typically a root-owned process, this
could result in root-level compromise of a vulnerable system.

5. F2HTML.PL SQL Injection Vulnerability
BugTraq ID: 5123
Remote: No
Date Published: Jun 28 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5123
Summary:

f2html.pl is a Perl script which searches recursively through directories
looking for certain types of files, and then creates a HTML page
containing directory listings.  It stores listings in a database.  It will
run on most Unix and Linux variants as well as Microsoft Windows operating
systems.

The f2html.pl script does not sufficiently validate filenames before
passing them into SQL queries.  In the instance that f2html.pl is used to
search a directory which may be accessible to untrusted local users, it
may be possible to launch a SQL injection attack via a maliciously crafted
filename.

An attacker may exploit this condition to modify the logic of SQL queries.

6. PHP Ticket Cross Site Scripting Vulnerability
BugTraq ID: 5124
Remote: Yes
Date Published: Jun 28 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5124
Summary:

PHP Ticket is a "To Do List" tracking system maintained by MrSpiff.

A cross site scripting vulnerability is present in PHP Ticket. The
application does not properly sanitize HTML before it is included in PHP
generated HTML pages.

Attackers may exploit this vulnerability by constructing a link to a
vulnerable script, passing malicious HTML code as a value for unsanitized
CGI parameters. If the link is sent to a PHP Ticket user and clicked on,
the attacker-supplied HTML code will run in the context of the site
running the vulnerable software.

This issue may be exploited to steal cookie-based authentication
credentials from legitimate users of PHP Ticket.

7. Bonobo EFSTool Commandline Argument Buffer Overflow Vulnerability
BugTraq ID: 5125
Remote: No
Date Published: Jun 29 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5125
Summary:

Bonobo is a set of tools and CORBA interfaces included as part of the
Gnome infrastructure.  It is designed for use on the Linux and Unix
operating systems.

A problem with the efstool component of Bonobo could make it possible for
a local user to gain elevated privileges.  The problem is in the handling
of long strings.

A boundry condition error has been discovered in the efstool program.
Due to improper bounds checking, it is possible for a user to supply a
long commandline argument to the efstool program, which would result in a
buffer overflow.  This problem could be exploited on the local system to
overwrite stack memory, including the return address, and execute attacker
supplied code.

It should be noted that recent versions of the efstool program are not
installed with setuid privileges.  However, older versions of the Bonobo
package install this program as a setuid root executable.  Due to the
default permissions of this program, an attacker could exploit this
program to execute code as root.

8. Apple MacOS X World Readable Local.NIDump Encrypted Password Recovery Vulnerability
BugTraq ID: 5126
Remote: No
Date Published: Jun 29 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5126
Summary:

MacOS X is an operating system distributed and maintained by Apple.

A problem with MacOS X could allow a user to gain access to other users
passwords.  The problem is in the setting of permissions on a file.

The local.nidump file is created by a cron job on OS X systems.  This file
is used as a backup to the NetInfo database.  The file contains encrypted
password hashes for all users on the system.

This could lead to a local user gaining read access to the encrypted
passwords hashes for all system users.  A user could take this file and
launch an offline brute force crack attack against this file to recover
the passwords for users, including the administrative user.

9. Simple WAIS Interface Arbitrary Command Execution Vulnerability
BugTraq ID: 5127
Remote: Yes
Date Published: Jun 29 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5127
Summary:

The Simple WAIS interface is an integrated interface to the WAIS system.
It is designed for use on Unix and Linux operating systems.

A problem with the interface could allow arbitrary command execution.
The problem is in the handling of some types of input.

The Simple WAIS interface does not properly handle some types of input.
Because of the insufficient santizing of user-supplied input, it is
possible for a user with access to the interface to execute arbitrary
commands with the privileges of the SWAIS daemon.

By passing a search to the interface with a pipe symbol (|) followed by a
command, a user could execute commands on the local system.

This problem could allow a remote attacker with access to the wais
interface to execute arbitrary commands, and potentially gain access to
the vulnerable host with the privileges of the SWAIS daemon.

10. E-Guest Guest Book Script Injection Vulnerability
BugTraq ID: 5128
Remote: Yes
Date Published: Jun 30 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5128
Summary:

E-Guest guest book is a freely available, open source guest book.  It is
designed for Unix and Linux operating systems.

A problem with the guest book could lead to the injection of script code.

E-Guest does not properly filter script code from some fields of the guest
book entries.  It is possible for a remote user to enter HTML and script
code in the name, email, homepage, and location fields.  Upon visiting the
page, this script code would be executed in browser of the visiting user.

This problem could make it possible for a remote attacker to execute
script code in the security context of an arbitrary site.

11. E-Guest Server Side Include Arbitrary Command Execution Vulnerability
BugTraq ID: 5129
Remote: Yes
Date Published: Jun 30 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5129
Summary:

E-Guest guest book is a freely available, open source guest book.  It is
designed for Unix and Linux operating systems.

A problem with the guest book could make it possible for a remote user to
execute arbitrary commands through a vulnerable implementation.

E-Guest does not adequately sanitize user-supplied input in guest book
entries.  Because of this, it is possible to pass along commands via
server-side includes that could allow a remote user to execute commands on
the local host.  This could result in a user gaining local access with the
privileges of the HTTP server.

12. Zap Book Server Side Include Arbitrary Command Execution Vulnerability
BugTraq ID: 5130
Remote: Yes
Date Published: Jun 30 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5130
Summary:

Zap Book is a freely available, open source guest book.  It is designed
for Unix and Linux operating systems.

A problem with the guest book could make it possible for a remote user to
execute arbitrary commands through a vulnerable implementation.

Zap Book does not adequately sanitize user-supplied input in guest book
entries.  Because of this, it is possible to pass along commands via
server-side includes that could allow a remote user to execute commands on
the local host.  This could result in a user gaining local access with the
privileges of the HTTP server.

13. Zap Book Script Injection Vulnerability
BugTraq ID: 5131
Remote: Yes
Date Published: Jun 30 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5131
Summary:

Zap Book is a freely available, open source guest book.  It is designed
for Unix and Linux operating systems.

A problem with the guest book could lead to the injection of script code.

Zap Book does not properly filter script code from some fields of the
guest book entries.  It is possible for a remote user to enter HTML and
script code in the name, email, homepage, and location fields.  Upon
visiting the page, this script code would be executed in browser of the
visiting user.

This problem could make it possible for a remote attacker to execute
script code in the security context of an arbitrary site.

14. Macromedia Sitespring Database Engine Denial Of Service Vulnerability
BugTraq ID: 5132
Remote: Yes
Date Published: Jul 01 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5132
Summary:

Macromedia Sitespring is a J2EE compliant website production management
solution.  The Macromedia Sitespring server runs on Microsoft Windows
operating systems.

A vulnerability has been reported in Macromedia Sitespring 1.2.0(277.1)
using Sybase runtime engine v7.0.2.1480.  It is possible to crash the
Sybase runtime engine and Sitespring web services by sending a malformed
request to the database engine.  The database engine is reported to crash
first when handling a malformed request, followed by the web services.
The database engine listens on TCP port 2500 by default.

Other versions may also be affected.

15. Macromedia JRun Source Disclosure Vulnerabilities
BugTraq ID: 5134
Remote: Yes
Date Published: Jul 01 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5134
Summary:

Macromedia JRun is a J2EE application server for use with IIS 4/5 on the
Microsoft Windows operating systems.  It is also available for Unix and
Linux variants.

Macromedia JRun is prone to a number of source code disclosure issues.
These issues are reportedly due to improper handling of null characters.
Malformed requests containing variations of null characters may cause JRun
to serve .JSP files uninterpreted.  One example of how this may be
exploited is to append a unicode null character to the end of a valid
request.

This may allow remote attackers to disclose the contents of arbitrary .JSP
files.  Remote attackers may exploit this issue to gain access to
sensitive information contained in source files (such as database
credentials).

16. Betsie Parserl.PL Cross-Site Scripting Vulnerability
BugTraq ID: 5135
Remote: Yes
Date Published: Jul 01 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5135
Summary:

Betsie (BBC Education Text to Speech Internet Enhancer) is a script to
supports users of text to speech systems for web browsing.  It is written
in Perl and will run on Microsoft Windows operating systems as well as
Unix and Linux variants.

Betsie is prone to a cross-site scripting vulnerability.  This issue
exists in the parserl.pl script.  The vulnerable script fails to sanitize
HTML tags from CGI parameters.

Attackers may exploit this condition via a malicious link to a site
running the vulnerable software.  Successful exploitation will enable an
attacker to cause script code to be executed in the web browser of a user
who visits the malicious link.  The attacker's script code will be
executed in the context of the site running the vulnerable software.

Attackers may exploit this condition to steal cookie-based authentication
credentials from legitimate users.

17. OmniHTTPD Long Request Buffer Overflow Vulnerability
BugTraq ID: 5136
Remote: Yes
Date Published: Jul 01 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5136
Summary:

OmniHTTPD is a webserver for Microsoft Windows operating systems.

OmniHTTPD is prone to a remotely exploitable buffer overflow condition.
This problem is in the handling of requests containing overly long
headers.  In particular, this issue may be exploited if an overly long
HTTP Version header is sent to the webserver.  The type of request does
not matter (GET, POST, etc.).  This condition is known to occur when 4096+
bytes are sent in the header field.

Exploitation of this issue may cause a denial of service condition or
result in execution of arbitrary attacker-supplied instructions with the
privileges of the webserver process.

OmniHTTPD normally runs with SYSTEM privileges.  If this issue is
successfully exploited by an attacker to execute arbitrary code, this may
result in a full compromise of the underlying host.

This issue was reported in version 2.09 of the software.  Other versions
may also be affected.

18. Blackboard Cross-Site Scripting Vulnerability
BugTraq ID: 5137
Remote: Yes
Date Published: Jul 01 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5137
Summary:

Blackboard is web-based learning software.

Blackboard is reportedly prone to cross-site scripting attacks.  This
issue was reported to be in the login.pl script.  The vulnerable script
fails to sanitize HTML tags from CGI parameters.

Attackers may exploit this condition via a malicious link to a site
running the vulnerable software.  Successful exploitation will enable an
attacker to cause script code to be executed in the web browser of a user
who visits the malicious link.  The attacker's script code will be
executed in the context of the site running the vulnerable software.

Attackers may exploit this condition to steal cookie-based authentication
credentials from legitimate users.

It has been reported that there other instances where Blackboard fails to
sanitize arbitrary HTML and script code.

19. AnalogX Proxy Socks4A Buffer Overflow Vulnerability
BugTraq ID: 5138
Remote: Yes
Date Published: Jul 01 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5138
Summary:

AnalogX Proxy is proxy server software for Microsoft Windows operating
systems.

AnalogX Proxy is prone to a buffer overflow condition when attempting to
handle malformed SOCKS4A requests (via TCP port 1080).  This condition is
due to insufficient bounds checking of the hostname and may be reproduced
by sending a malformed request with a hostname of 140 bytes or more.

This may be exploited to create a denial of service condition.  When the
malformed request is received by the proxy, an error message will appear
on the screen.  Multiple malformed requests may cause the service to stop
responding.  Additionally, it may be possible to exploit this issue to
execute arbitrary attacker-supplied instructions as the proxy server
process.

20. AnalogX Proxy Web Proxy Buffer Overflow Vulnerability
BugTraq ID: 5139
Remote: Yes
Date Published: Jul 01 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5139
Summary:

AnalogX Proxy is proxy server software for Microsoft Windows operating
systems.

AnalogX Proxy is prone to a buffer overflow condition when attempting to
handle malformed HTTP proxy requests (via TCP port 6588).  Requests must
be specially crafted to contain a space character followed by 320+
non-space characters, followed by 2 carriage-return linefeeds (CRLF).

This may be exploited to create a denial of service condition.  When the
malformed request is received by the proxy, an error message will appear
on the screen.  Multiple malformed requests may cause the service to stop
responding.  Additionally, it may be possible to exploit this issue to
execute arbitrary attacker-supplied instructions as the proxy server
process.

21. Slashcode Paragraph Tag Script Injection Vulnerability
BugTraq ID: 5140
Remote: Yes
Date Published: Jul 02 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5140
Summary:

SlashCode is a bulletin board, discussion and portal framework. It is
widely used, and is behind the popular Slashdot page.

Reportedly, a vulnerability exists only for sites that are running some
CVS versions of SlashCode. It may be possible for a malicious user of the
system to inject arbitrary HTML code into content generated by the
SlashCode system. When this content is viewed by a legitimate user of the
system, attacker supplied JavaScript code will execute within the context
of the SlashCode based site.

The attacker supplied code would be able to access cookie data, including
authentication credentials, and to take actions on the vulnerable site as
the currently authenticated user.

This issue has been reported to exist in the handling of the HTML
paragraph tag. The following partial exploit has been provided: <p &gt;
onMouseOver..insert javascript here...>

** It has been reported that this issue only exists in CVS versions of
SlashCode from between June 17 and July 1 2002.

22. PHPAuction Unauthorized Administrative Access Vulnerability
BugTraq ID: 5141
Remote: Yes
Date Published: Jul 02 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5141
Summary:

PhpAuction is a freely available web-based auction system. It is written
using PHP scripting language on a MySQL database engine.

A flaw has been reported in PHPAuction, which could allow any user to gain
administrative privileges.

Reportedly, the /admin/login.php script does not apply proper permissions
to created user accounts. Therefore, supplied username and password
information via login.php, is inserted in the admin users table. As a
result, the user can authenticate with administrative privileges.

Exploitation of this issue could lead to a compromise of the application
and may result in the disclosure of sensitive information.

23. HP-UX DCE Client IPv6 Denial of Service Vulnerability
BugTraq ID: 5143
Remote: No
Date Published: Jul 01 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5143
Summary:

HP-UX added IPv6 support to CDE in version 11.11.

A vulnerability exists that could cause a user to crash the DCE daemon
dced or rpcd by modifying internal data.  This will subsequently create a
denial of service condition.


III. SECURITYFOCUS NEWS AND COMMENTARY
--------------------------------------
1. Fugitive DEA Agent Arrested in Mexico
By  Kevin Poulsen

Former federal agent had skipped out on charges that he sold information
from law enforcement computers to a private investigations firm. ... >>

http://online.securityfocus.com/news/510

2. Yaha Worm Takes Out Pakistan Government's Site
By  Brian McWilliams

Virus uses victim computers as denial-of-service agents, and tries to
recruit Indian hackers into a cross-border cyber war ...

http://online.securityfocus.com/news/501

3. Mitnick Testifies Against Sprint in Vice Hack Case
By Kevin Poulsen

Since adult entertainment operator Eddie Munoz first told state regulators
in 1994 that mercenary hackers were crippling his business by diverting,
monitoring and blocking his phone calls, officials at local telephone
company Sprint of Nevada have maintained that, as far as they know, their
systems have never suffered a single intrusion.

http://online.securityfocus.com/news/497

4. Gobbles Releases Apache Exploit
By Brian McWilliams

In a move aimed at showing up other security researchers, Gobbles Security
on Wednesday released source code to a program that exploits a serious
security flaw in the popular Apache Web server.

http://online.securityfocus.com/news/493


IV.SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. RADIUS module for Ruby v1.0.0
by Rafael 'Dido' Sevilla
Relevant URL:
http://online.securityfocus.com/tools/2757
Platforms: Os Independent
Summary:

The RADIUS Ruby module provides an RFC 2138/2139-compliant interface to
RADIUS using Ruby. Its API is based somewhat on the Net::Radius module for
Perl, but with some changes made to reflect Ruby's features (such as
iterators).

2. netspeed_applet for gnome v0.1
by joergen scheibengruber
Relevant URL:
http://mfcn.ilo.de/netspeed_applet/
Platforms: N/A
Summary:

netspeed_applet is a little GNOME applet that shows the traffic on a
specified network device (for example eth0) in kbytes/s.

3. Pound v0.5
by roseg
Relevant URL:
http://www.apsis.ch/pound/
Platforms: Linux, OpenBSD, POSIX
Summary:

Pound is a reverse HTTP proxy, load balancer, and SSL wrapper. It proxies
client HTTPS requests to HTTP backend servers, distributes the requests
among several servers while keeping sessions, supports HTTP/1.1 requests
even if the backend server(s) are HTTP/1.0, and sanitizes requests.

4. Wireless Access Point Utilites for Unix v1.0.2
by roma
Relevant URL:
http://ap-utils.polesye.net/
Platforms: Linux, POSIX
Summary:

Wireless Access Point Utilites for Unix is a set of utilities to configure
and monitor Wireless Access Points under Unix.

5. SimpleFirewall v0.6-4
by Luis Wong [email protected]
Relevant URL:
http://www.sourceforge.net/projects/sfirewall/
Platforms: Linux, POSIX
Summary:

Simple Firewall is a easy tool for administration of users and access
control. It uses iptables for packet filtering, and saves rules with XML.
It can be run in bash and over the Web via webmin.

6. conntrack viewer v1.1
by patou
Relevant URL:
http://cv.intellos.net
Platforms: Linux, POSIX
Summary:

Conntrack Viewer is a Perl script to view the masquerading connection with
iptables, it uses /proc/net/ip_conntrack. With ipchains, it was extremely
easy to view the masquerading connection; 'netstat -M' or 'netstat --
masquerade' gave you the result right away. But since iptables, if you try
this you will get "netstat: no support for `ip_masquerade' on this
system.". With iptables, the information regarding the masquerading
connection are accesible via /proc/net/ip_conntrack, which is extremely
hard to read. This program makes it more legible.


V. SECURITY JOBS SUMMARY
------------------------
1. Kentucky Location - Networking security Specialist (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

2. seeking bay area employment (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

3. Boston area Security Architect/CISSP looking for new position (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/Pine.GSO.4.10.10207021329460.6090-100000@impunity

4. Security Consultant / Security Architect role - South East UK (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

5. Need Some More Network Exploitation Analyst- Come on, Give it Try (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

6. Relocating to Washington, D.C./Baltimore area this weekend and need employment (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

7. Looking for work (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

8. Information Security Strategist - OR - $85K (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/5544986F9407D611A5900008C70964061A649C@EXCHANGE

9. Information Security Professional (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

10. Security Architect in OR ready to relocate (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

11. Looking for a Senior Security Position (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

12. Security Consultant - Baltimore, MD (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

13. Looking for Sec Oppty in VA-MD-DC-Metro or elsewhere (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]


VI. INCIDENTS LIST SUMMARY
-------------------------
1. Closed thread- Anyone seen this before? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

2. Additional- Anyone seen this before? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

3. Anyone seen this before? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/0FFDB4FC5D8C1E4AA3F527E8C1802F3E019A7A58@roadrunner

4. OpenSSH Attack? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/000001c221f8$835c5e70$9365bccc@claptop

5. ftp.bitchx.org's ircii-pana-1.0c19.tar.gz is backdoored (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

6. Honeynet Project - SotM and Reverse Challenge (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

7. Java Yahoo! Chat and disabled keyboards (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

8. EarlyBird for Other Attacks? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/Pine.LNX.4.44.0206290906050.8182-100000@ultra1.hugo.vanderkooij.org

9. Textbook CodeRed v2 Caught By Snort (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

10. FW: 33 character encrypted passwords in /etc/shadow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

11. spoofed packets to RFC 1918 addresses (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

12. FW: Apache worm in the wild (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

13. Someone looking for CodeRed infected boxes ? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/0db201c21ecf$ace3d0b0$c864a8c0@maxime

14. 33 character encrypted passwords in /etc/shadow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

15. win2k server issue (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/BB7FD4FF9E440648A731452E5D341FB0C668BD@hitsexchange01.advance-med.com

16. unexplained port 524 probes payload "cko" (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/001401c21e98$6f57c300$0300a8c0@rich


VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. Ports 0-1023? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

2. WinNT and previously used passwords (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

3. nn format string exploit (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

4. UnBodyGuard a.k.a Bouncer (Solaris kernel function hijacking) (fwd) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

5. Possible flaw in XFree? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

6. Hijacking the hashes : multiple windows mail clients  vulnerability (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

7. Hijacking the hashes : multiple windows mail clients vulnerability (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

8. NEC's socks5 ( Foundstone Advisory - Buffer Overflow in AnalogX Proxy (fwd)) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

9. spying (deleted) file entries in other users' directories (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/0C5EECDCFE105C4BB8FC618DD243ED70029BE62C@excausy103.australia.unity

10. Noguska Nola 1.1.1 [ Intranet Business Management Software ] (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

11. BufferOverflow in OmniHTTPd 2.09 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

12. login yahoogroups. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

13. Simple Wais 1.11 allows users to execute commands as SWAIS deamon. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/008701c21fcc$6e6075c0$8f97c3d8@peach

14. FW: Possible flaw in XFree? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/002b01c21fc6$033732d0$1401a8c0@sandy

15. OpenSSh 3.4p1 PrivilegeSerparation experiment (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

16. possible stack flow in bash (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

17. Java and buffer overflows (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]


VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Strange event showing up... (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

2. Replication on Sql Server 2k - Sql Server Agent Account (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

3. Can I shut down individual TCP connections? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

4. SecurityFocus Microsoft Newsletter #93 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/6AA3020BB6C49E4EBDB055884742533201AA5F@dieppe.calgary.securityfocus.com


IX. SUN FOCUS LIST SUMMARY
----------------------------
1. Sun OpenSSH for Solaris 8? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]

2. Apache Worm Update (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]

3. Sun statement on the OpenSSH Remote Challenge Vulnerability (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]

4. Apache worm (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]

5. Solaris security module needs some help (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]


X. LINUX FOCUS LIST SUMMARY
---------------------------
1. OpenSSH 3.4 rpm spec file for redhat (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/Pine.LNX.4.44.0207041530330.14982-100000@xanadu.astro.Princeton.EDU

2. Apache update from SuSE ?? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/Pine.LNX.4.44.0207031519390.1923-100000@tinberg.wi.securepipe.com

3. Worm update info (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

4. Apache worm (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]


XI. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored by: BlackHat

Black Hat Briefings & Training

Attend Black Hat Briefings & Training, July 29 - August 1, Las Vegas, the
world's premier technical security event! 8 tracks, 12 training sessions,
Richard Clarke keynote, 1500 delegates from 30 nations, with a near cult
following of both CSOs and "underground" security experts.  See for
yourself what the buzz is all about.

Visit us at: http://www.blackhat.com

-------------------------------------------------------------------------------