SecurityFocus Newsletter #154

John Boletta <[email protected]> Mon, 22 Jul 2002 11:28:02 -0600 (MDT)
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #154
-----------------------------

This newsletter is sponsored by: PoliVec, Inc.

***FREE Trial License of PoliVec Scanner***

Automate your security policies and reduce administrative time and
configuration errors. Stay current with Patches and Hotfixes. Ensure that
your systems meet configuration requirements. Remotely change system
configurations, registry settings and services that are enabled. Manage
NTFS and Active Directory Servers. Identify insecure passwords, schedule
audits, develop reports for comparison, oh, and did we mention, with
PoliVec Scanner there are No Agents to install?

For a FREE trial license of PoliVec Scanner, please visit
http://www.polivec.com/scanner1 or call us toll-free at 1.866.POLIVEC.

-------------------------------------------------------------------------------

I. FRONT AND CENTER
     1. Justifying the Expense of IDS, Part One: An Overview of ROIs...
     2. Assessing Internet Security Risk, Part Two: an Internet...
     3. The Devil And The Deep Blue Sea
     4. Crypto Controls are Spreading Internationally
     5. The Realities of Disclosure
     6. Black Hat Briefings & Training
     7. SecurityFocus DPP Program
II. BUGTRAQ SUMMARY
     1. Working Resources BadBlue Null Byte File Disclosure Vulnerability
     2. Working Resources BadBlue Plain Text Password Storage...
     3. Hosting Controller Hidden Field Password Changing Vulnerability
     4. Novell NetMail ModWeb Buffer Overflow Vulnerability
     5. Novell NetMail WebAdmin Buffer Overflow Vulnerability
     6. IBM Tivoli Management Framework ManagedNode Buffer...
     7. Novell NetMail IMAP Agent Denial Of Service Vulnerability
     8. IBM Tivoli Management Framework Endpoint Buffer Overflow...
     9. Symantec Norton Personal Firewall/Internet Security 2001...
     10. IMHO Webmail Account Hijacking Vulnerability
     11. NewsX NNTP SysLog Format String Vulnerability
     12. Mirabilis ICQ Sound Scheme Remote Configuration Modification...
     13. e-Zone FuseTalk Search Results Cross Site Scripting Vulnerability
     14. Tru64 IPCS Buffer Overflow Vulnerability
     15. Tru64 InetD Denial Of Service Vulnerability
     16. Thorsten Korner 123tkShop SQL Injection Vulnerability
     17. Thorsten Korner 123tkShop Arbitrary File Include Vulnerability
     18. AOL Instant Messenger Unauthorized Actions Vulnerability
     19. Mirabilis ICQ Sound Scheme Predictable File Location...
     20. Oddsock Song Requester WinAmp Plugin Denial Of Service...
     21. Macromedia Sitespring Default Error Page Cross Site Scripting...
     22. Caucho Technology Resin Server Device Name Path Disclosure...
     23. Microsoft IIS SMTP Service Encapsulated SMTP Address...
     24. ATPhttpd Buffer Overflow Vulnerabilities
     25. Pingtel Expressa Default Blank Administrator Password...
     26. CARE 2002 Multiple SQL Injection Vulnerabilities
     29. Pingtel Expressa Web Server Cross-Site Scripting Vulnerability
     30. Pingtel Expressa Admin Account Login Session Timeout...
     31. Pingtel Expressa Arbitrary Firmware Upgrade Vulnerability
     32. Pingtel Expressa Arbitrary Application Installation Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
     1. H2K2 Hackers Say They Want a Revolution
     2. More EBook Hacking Tricks From Embattled Elcomsoft
     3. HP confirms 150 suspended in email porn probe
     4. Team demos 'first quantum crypto prototype machine'
     5. Alliance Sets Standards on Computer Security
IV.SECURITYFOCUS TOP 6 TOOLS
     1. SQL Server Password Auditing Tool v1.0.1
     2. Inzider 1.2
     3. SQLLHF v1.3
     4. Network Access Control System
     5. Simp (Secway's Instant Messenger Privacy) v1.1.0
     6. Tiny Honeypot v0.4.3
V. SECURITYJOBS LIST SUMMARY
     1. Seeking position in the Philadelphia area - CISSP (Thread)
     2. Status Of The IT Talent Pool - Dead Thread (Thread)
     3. Sales Executive #722 - NY; DC; San Francisco; Chicago; Dallas...
     4. Hit by the IT Blues (Thread)
     5. Sr. Security Sales Engineer position w/ Qualys for New York...
     6. Status Of The IT Talent Pool (Thread)
     7. Looking for pen-testing position in London (Thread)
     8. Resume (Thread)
     9. Security Auditor - South Bay Area, CA - Greythorn (Thread)
     10. Sr. Security Architect/Engineer (Linux) position at Qualys...
     11. Sr. Product Manager position at Qualys (Thread)
     12. Looking for employment (Thread)
     13. Security Application Deployment Consultant - New York (Thread)
     14. Anti-Virus Position - Chicago - Greythorn (Thread)
     15. Network Security Professional with active Secret or Top Secret...
     16. New York/New Jersey Sales Engineer needed (Thread)
     17. Seeking for Security Jobs Work with DOE (Thread)
     18. We are hiring Sr. System Engineers and  Senior Level Sales...
     19. Intrusion Detection and Forensic Position in NJ (Thread)
     20. Senior Sales Executives - East Coast (New York Tri-State Area...
VI. INCIDENTS LIST SUMMARY
     1. re: TCP 1025 scanning worm? (Thread)
     2. Vacation Troller, Please Ignore. (Thread)
     3. Announcement (Thread)
     4. OpenBSD rootkit (Thread)
     5. Frethem.K virus (Thread)
     6. Ideas? Port 21 SYNs, slow (Thread)
     7. Unknown/Weird Traffic? (Thread)
     8. Another odd scan... (Thread)
     9. TCP port 139 probes (Thread)
     10. Conclusion: TCP port 139 probes (Thread)
     11. Code Red and other anomalous activity from 1433 (Thread)
     12. Can anyone identify this backdoor? (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. PHP : eval() ? (Thread)
     2. Lindows Issues (Thread)
     3. nsmail XSS hole (was  double decoding filter bypass (Hotmail)...
     4. double decoding filter bypass (Hotmail) + challenge for you...
     5. SQL Injection Legalities (Thread)
     6. Smashing the Stack? (Thread)
     7. Operation TIPS (Thread)
     8. Badware update through P2P? (Thread)
     9. Announcement (Thread)
     10. Query (Thread)
     11. [VulnWatch] wp-02-0001: GoAhead Web Server Directory Traversal...
     12. Remote ICQ Sound Desactivation (Thread)
     13. Assembler/C References (Thread)
     14. VANED LABS: icecast filesystem disclosure (Thread)
     15. Insecure Online Update with quicktime? (Thread)
     16. CSS(Cross-Site Scripting) at digitalid.verisign.com...
     17. [7.8.2002 44916] Notice of Copyright Infringement] (Thread)
     18. VU#197395 (Thread)
     19. XSS in lycos htmlgear guestbook (Thread)
     20. MSNBC Article        [7.8.2002 44916] Notice of Copyright...
     21. hi (Thread)
     22. Follow-up to Malware Repository Request (Thread)
     23. Hosting Controller Vulnerability (Thread)
     24. [7.8.2002 44916] Notice of Copyright Infringement (Thread)
     25. IE without Images (Thread)
     26. Lessons Learned from the MPAA's use of DCMA (Thread)
     27. Looking for a repository of worms/trojans/ddos tools (Thread)
     28. FW: [7.8.2002 44916] Notice of Copyright Infringement (Thread)
     29. [Fwd: Re: Windows fuzz] (Thread)
     30. Vulnerability found: The Adobe eBook Library (Thread)
     31. various architectures well known numbers (Thread)
     32. IIS Microsoft SMTP Service Encapsulated SMTP Address...
     33. Remote DoS Against A Given Chat Client With the !seen Service...
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. Exchange Information Store Replication (Thread)
     2. write permissions for IIS (Thread)
     3. Need security proposal for Win2K upgrade... (Thread)
     4. Announcement (Thread)
     5. Win32 Apache service not run as System... (Thread)
     6. Exchange 2000 ms02-025 hotfix Q320436 caused SA to hang on...
     7. SecurityFocus Microsoft Newsletter #95 (Thread)
     8. Exchange 2000 ms02-025 hotfix Q320436 caused SA to hang on...
     9. Exchange2K/DMZ (Thread)
IX. SUN FOCUS LIST SUMMARY
     1. Announcement (Thread)
     2. My solution for preventing xhost + (Thread)
     3. dtlogin and secure access control (Thread)
X. LINUX FOCUS LIST SUMMARY
     1. Announcement (Thread)
     2. Forward ftp request to another server (Thread)
     3. amanda backups and firewalling (Thread)
     4. Forward ftp request another server (Thread)
XI. SPONSOR INFORMATION




I. FRONT AND CENTER
-------------------
1. Justifying the Expense of IDS, Part One: An Overview of ROIs for IDS
By Kevin Timm

A positive return on investment (ROI) of intrusion detection systems (IDS)
is dependent upon an organization's deployment strategy and how well the
successful implementation and management of the technology helps the
organization achieve the tactical and strategic objectives it has
established. For organizations interested in quantifying the IDS's value
prior to deploying it, their investment decision will hinge on their
ability to demonstrate a positive ROI.

http://online.securityfocus.com/infocus/1608

2. Assessing Internet Security Risk, Part Two: an Internet Assessment
Methodology
by Charl van der Walt

This article is the second in a series that is designed to help readers to
assess the risk that their Internet-connected systems are exposed to. In
the first installment, we established the reasons for doing a technical
risk assessment. In this installment, we'll start discussing the
methodology that we follow in performing this kind of assessment.

http://online.securityfocus.com/infocus/1607

3. The Devil And The Deep Blue Sea
By Jon Lasser

Why Microsoft's Palladium project threatens to send Linux and open-source
into exile.

http://online.securityfocus.com/columnists/96

4. Crypto Controls are Spreading Internationally
By David Banisar

Five years ago, when the Organization for Economic Cooperation and
Development (OECD) released their guidelines for cryptography policy,
crypto advocates cheered and declared victory. After a hard fought battle,
we had forced the OECD to back away from the U.S. government's efforts to
restrict encryption worldwide. After the guidelines, countries around the
world issued crypto policies that called for the free and unfettered use
of encryption products to promote e-commerce and protect privacy.
Eventually, even the U.S. gave up anddropped most export controls. In the
last EPIC Cryptography and Privacy survey, written in 2000, there were
only a handful of nations that still restricted crypto, like Burma,
Belarus, and Russia -- countries you really didn't want to go to anyway.

http://online.securityfocus.com/columnists/95

5. The Realities of Disclosure
by Michael Morgenstern, Tom Parker

Four months ago, we published a SecurityFocus guest feature entitled It's
Time to be Responsible (March 1, 2002) calling for greater consensus in
the computer security arena on policies of vulnerability disclosure. Since
that time little positive movement has occurred, to the detriment of all
involved parties. Microsoft's consortium remains a black hole;
vulnerabilities (and exploits) continue to be released without control;
and everyone suffers - vendors and users included. Thankfully, not all
movement has been entirely negative. Unfortunately, Steve Christey and
Chris Wysopol's RFC of February 2002 was only tepidly received, despite
calling for positive and proactive measures. We surmise that no concrete
movement has occurred due mostly to the segregated computer communities
and the lack of any consensus on these matters. It is high time the
computer cognoscenti finally comes together and advocates responsible
disclosure practices.

http://online.securityfocus.com/guest/14155

6. Black Hat Briefings & Training

Attend Black Hat Briefings & Training, July 29 - August 1, Las Vegas, the
world's premier technical security event! 8 tracks, 12 training sessions,
Richard Clarke keynote, 1500 delegates from 30 nations, with a near cult
following of both CSOs and "underground" security experts.  See for
yourself what the buzz is all about.

Visit us at: http://www.blackhat.com

7. SecurityFocus DPP Program

Attention Non-profit Organizations and Universities!!
Sign-up now for preferred pricing on the only global early-warning system
for cyber attacks - SecurityFocus DeepSight Threat Management System.

Click here for more information:
http://www.securityfocus.com/corporate/products/dpsection.shtml


II. BUGTRAQ SUMMARY
-------------------
1. Working Resources BadBlue Null Byte File Disclosure Vulnerability
BugTraq ID: 5226
Remote: Yes
Date Published: Jul 13 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5226
Summary:

BadBlue is a P2P file sharing application distributed by Working
Resources. It is available for Microsoft Windows operating systems.

Working Resources BadBlue may disclose the contents of restricted files.

Under some circumstances, it may be possible to pass a null byte request
to a BadBlue server.  By creating a request that contains a null byte at
the end of a file name, and including white space between certain elements
of the file name, it is possible to bypass the filtering imposed by the
server.

It has been discovered that a request passed to a BadBlue server
containing a null byte at the end of a file name will return the contents
of the file.  This type of request can be applied to gain access to
sensitive information, such as the BadBlue configuration file.

This problem can allow a user to gain access to sensitive files, including
the BadBlue configuration file.

2. Working Resources BadBlue Plain Text Password Storage Vulnerability
BugTraq ID: 5228
Remote: No
Date Published: Jul 13 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5228
Summary:

BadBlue is a P2P file sharing application distributed by Working
Resources. It is available for Microsoft Windows operating systems.

A problem with BadBlue may make it possible for local users to gain access
to sensitive information.

BadBlue does not cryptographically protect stored passwords.  Passwords
contained in the configuration file are stored in plain text.  They may be
read by simply viewing the file.

This problem could allow a local user with read access to the BadBlue
configuration file to gain access to user passwords, and the passwords to
protected resources.  This problem is compounded by the vulnerability
described in Bugtraq ID 5226.

3. Hosting Controller Hidden Field Password Changing Vulnerability
BugTraq ID: 5229
Remote: Yes
Date Published: Jul 13 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5229
Summary:

Hosting Controller is an application which consolidates all hosting tasks
into one interface. Hosting Controller runs on Microsoft Windows operating
systems.

A problem with Hosting Controller may make it possible for a user to
change arbitrary passwords.

A problem has been discovered that could allow users with valid accounts
via Hosting Controller to change arbitrary passwords.  Hosting Controller
uses a hidden field to specify the username when a password change is
performed.  By changing the name of the user specified in the hidden
field, it is possible to change the password for that respective user.
This function is performed with the /accounts/updateuserdesc.asp script.

This problem could make it possible for an attacker to change a password
for any user.  This includes Administrator, and could allow a remote user
to gain administrative access to a vulnerable Hosting Controller system.

4. Novell NetMail ModWeb Buffer Overflow Vulnerability
BugTraq ID: 5230
Remote: Yes
Date Published: Jul 15 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5230
Summary:

Novell NetMail is an e-mail and calendaring system for use with Microsoft
Windows and Linux and Unix variant operating systems.

A vulnerability has been reported for Novell Netmail versions 3.1 and
3.0.3. A buffer overflow condition exists in the vulnerable versions of
the software that may allow a remote attacker to obtain root privileges.

The vulnerabilty exists in the ModWeb module of Netmail. When certain data
is received by the ModWeb module, the buffer overflow condition is
triggered. This may allow, under certain circumstances, for an attacker to
supply malicious code that may be executed by the vulnerable process.

In situations like this, it is possible for a remote attacker to obtain
root privileges.

5. Novell NetMail WebAdmin Buffer Overflow Vulnerability
BugTraq ID: 5231
Remote: Yes
Date Published: Jul 15 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5231
Summary:

Novell NetMail is an e-mail and calendaring system for use with Microsoft
Windows and Linux and Unix variant operating systems.

A vulnerability has been reported for Novell Netmail versions 3.1 and
3.0.3. A buffer overflow condition exists in the vulnerable versions of
the software that may allow a remote attacker to obtain root privileges.

The vulnerabilty exists in the WebAdmin module of Netmail. WebAdmin is
used by administrators of Netmail to configure and change parameters
necessary for operation. When certain data is received by the WebAdmin
module, the buffer overflow condition is triggered. This may allow, under
certain circumstances, for an attacker to supply malicious code that may
be executed by the vulnerable process.

In situations like this, it is possible for a remote attacker to obtain
root privileges.

6. IBM Tivoli Management Framework ManagedNode Buffer Overrun Vulnerability
BugTraq ID: 5233
Remote: Yes
Date Published: Jul 15 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5233
Summary:

The Tivoli Management Framework includes a HTTP server installed on
ManagedNode hosts by default.

It has been reported that this server is susceptible to a buffer overrun
condition when GET commands of excessive length are issued by clients.
It is believed that the overrun is stack-based and may result in
corruption of the stack frame.  This condition can be exploited to execute
arbitrary code with the privileges of the webserver process.  The server
runs with root and SYSTEM privileges on Unix and NT respectively.

Remote attackers may exploit this condition to remotely compromise the
target host.  This vulnerability may also be leveraged by malicious
clients to crash the service, resulting in a denial of HTTP service.

Versions 3.6.x to (and including) 3.7.1 are vulnerable.

7. Novell NetMail IMAP Agent Denial Of Service Vulnerability
BugTraq ID: 5232
Remote: Yes
Date Published: Jul 15 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5232
Summary:

Novell NetMail is an e-mail and calendaring system for use with Microsoft
Windows and Linux and Unix variant operating systems.

A vulnerability has been reported for Novell Netmail versions 3.1 and
3.0.3. The IMAP (Internet Message Access Protocol) Agent is prone to a
denial of service condition when certain malformed data is received.

When certain data is received by the IMAP Agent, the Agent may crash. This
leads to a denial of service condition. Repeated attacks against a
vulnerable system will cause the server to reboot in a Novell NetWare
environment.

A manual restart of the IMAP Agent is required for services to resume.

It has been reported that this issue is the result of a buffer overflow
condition. If that is the case, it may prove possible to exploit this
vulnerability to execute arbitrary code as the IMAP Agent process. This
possibility has not, however, been confirmed.

8. IBM Tivoli Management Framework Endpoint Buffer Overflow Vulnerability
BugTraq ID: 5235
Remote: Yes
Date Published: Jul 15 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5235
Summary:

The Tivoli Management Framework includes a HTTP server installed on
endpoint hosts by default.

It has been reported that this server is susceptible to a buffer overrun
condition when GET commands of excessive length are issued by clients.
It is believed that the overrun is stack-based and may result in
corruption of the stack frame of the affected function.  The overrun can
be exploited to execute arbitrary code with the privileges of the
webserver process.  The server runs with root and SYSTEM privileges on
Unix and NT respectively.

Remote attackers may exploit this condition to remotely compromise the
target host.  This vulnerability may also be leveraged by malicious
clients to crash the service, resulting in a denial of HTTP service.

Versions 3.6.x to (and including) 3.7.1 are vulnerable.

9. Symantec Norton Personal Firewall/Internet Security 2001 Buffer Overflow Vulnerability
BugTraq ID: 5237
Remote: Yes
Date Published: Jul 15 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5237
Summary:

Symantec Norton Personal Firewall 2001 is a firewall for home and small
office machines based on some versions of the Microsoft Windows operating
systems.  Norton Internet Security 2001 is a suite of Norton security
utilities including Norton Personal Firewall and Norton Antivirus.

It has been reported that Norton Personal Firewall and Norton Internet
Security are vulnerable to a buffer overflow condition in the HTTP proxy.
The condition is reportedly due to an inability to handle large requests.
When such a request is processed, 3 bytes of a 32-bit word stored in the
EDI register are overwritten by client-supplied data.  Control over this
value may result in the ability to execute code within the kernel.

The vulnerability may be exploited by malicious users behind the proxy
server.  Attackers outside of the proxy server may also be able to exploit
this vulnerability by placing a maliciously constructed link on a website.
If the victim user behind the proxy server is enticed into clicking on the
link, the overflow will be triggered.

The overflow occurs in kernel memory.  It may be possible to execute
arbitrary code in this context to compromise the system.

10. IMHO Webmail Account Hijacking Vulnerability
BugTraq ID: 5238
Remote: Yes
Date Published: Jul 15 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5238
Summary:

IMHO is a webmail module for Roxen webserver.  It will run on any
operating system Roxen is compatible with, including Linux and Unix
variants as well as Microsoft Windows.

A vulnerability has been reported in the IMHO Roxen webmail module which
may enable a malicious user of the webmail system to gain access to the
account of another user.  This issue is in part due to a Roxen
configuration error which may cause potentially sensitive information to
be leaked in error pages.  In this instance, the REFERER may be leaked to
an attacker, which the attacker may use to access another webmail account.

11. NewsX NNTP SysLog Format String Vulnerability
BugTraq ID: 5240
Remote: Unknown
Date Published: Jul 15 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5240
Summary:

newsx is a NNTP client for Unix-based operating systems.

newsx is prone to a format string vulnerability.  This problem is due to
incorrect use of the syslog() function to log error messages.  It is
possible to corrupt memory by passing format strings through the
vulnerable logging function.  This may potentially be exploited to
overwrite arbitrary locations in memory with attacker-specified values.

It appears that this issue may be local in nature, however, there is a
possibility that this issue may be remotely exploitable.  Successful
exploitation of this issue may allow the attacker to execute arbitrary
instructions with the privileges of the NNTP client.

If this issue proves to be local, it would likely only be a security risk
if the NNTP client is installed setuid/setgid.  If this issue is remote in
nature, then it is likely that it would be exploitable by a malicious NNTP
server.

12. Mirabilis ICQ Sound Scheme Remote Configuration Modification Vulnerability
BugTraq ID: 5239
Remote: Yes
Date Published: Jul 15 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5239
Summary:

ICQ is an instant messenger client for Microsoft Windows systems. ICQ
includes support for sound schemes. ICQ sound scheme files are generally
given the .scm extension.

It is possible for a remote user to make some modifications to the
configuration of some versions of ICQ. Reportedly, it is possible to
modify sounds by forcing a vulnerable user to access a .scm file. This may
be accomplished by sending the vulnerable user an HTML formatted email or
enticing the user into viewing a malicious HTML page.

The HTML content must reference an available .scm file within an IFRAME
tag. If the HTML is then viewed, the sound scheme will be automatically
loaded, modifying the ICQ configuration.

It is not currently known if any other ICQ configuration settings can be
modified in this fashion.

13. e-Zone FuseTalk Search Results Cross Site Scripting Vulnerability
BugTraq ID: 5236
Remote: Yes
Date Published: Jul 15 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5236
Summary:

e-Zone Media FuseTalk is a web-based forum package that allows users to
build interactive communities. FuseTalk is developed for ColdFusion based
servers.

A cross site scripting vulnerability has been reported in some versions of
FuseTalk. User supplied data is not properly sanitized before being
included in a search result page.

A malicious party may construct a link to the search result page which
includes JavaScript code. If a user of the site follows this link, the
script code will be rendered, and execute within the context of the
vulnerable site. It may be possible to access sensitive data such as
authentication credentials, or to take actions as a validated user on the
hosted forum.

By default, the search form is submitted as an HTTP POST request. Even if
the server is not configured to handle GET requests, this restriction has
a minimal impact on an attacker. A malicious form activated by either a
form submission button or a JavaScript link will be sufficient to exploit
this issue.

14. Tru64 IPCS Buffer Overflow Vulnerability
BugTraq ID: 5241
Remote: No
Date Published: Jul 16 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5241
Summary:

Tru64 is a Unix variant.

The ipcs utility for Tru64 Unix is prone to a buffer overflow condition.
ipcs is used to report the status on inter-process communications.  ipcs
is installed with setuid privileges.

This condition to due to insufficient bounds checking of
externally-supplied data.  Local attackers may exploit this issue to cause
memory to be corrupted and overwritten with attacker-supplied
instructions.

Successful exploitation will enable an attacker to execute code as root.

15. Tru64 InetD Denial Of Service Vulnerability
BugTraq ID: 5242
Remote: Yes
Date Published: Jul 16 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5242
Summary:

Tru64 is a Unix variant.

Tru64 Unix inetd is prone to a remote denial of service condition.
Successful exploitation will enable a remote attacker to deny access to
services that are managed by the inet daemon.

No further details about the technical nature of this vulnerability are
known.

16. Thorsten Korner 123tkShop SQL Injection Vulnerability
BugTraq ID: 5244
Remote: Yes
Date Published: Jul 16 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5244
Summary:

123tkShop is a a freely available, open source e-business application
written using PHP. It will run on most Linux and Unix variants, in
addition to Microsoft Windows operating systems.

A vulnerability has been reported for 123tkShop. Reportedly, 123tkShop
suffers from a SQL injection vulnerability. User supplied data is used to
construct SQL statements, and special characters such as ''' and '"' are
not properly escaped. An attacker may be able to pass malicious data to
the system which modifies SQL queries.

If 'magic_quotes_gcp' is disabled in PHP configuration file, php.ini, it
is possible for an intruder to inject malicious SQL code into queries to
123tkShop.

This may be exploited by the attacker to view or modify the contents of
sensitive database files.

17. Thorsten Korner 123tkShop Arbitrary File Include Vulnerability
BugTraq ID: 5243
Remote: Yes
Date Published: Jul 16 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5243
Summary:

123tkShop is a a freely available, open source e-business application
written using PHP. It will run on most Linux and Unix variants, in
addition to Microsoft Windows operating systems.

A vulnerability has been reported for 123tkShop for versions prior to
0.3.1. Reportedly, an attacker may be able to read arbitrary files on the
vulnerable system with the privilege level of the 123tkShop process.

Almost all PHP files distributed with 123tkShop include other files
dynamically. Most of them are included with a statement like:
include("path/$var/file.inc.php");

If 'register_globals' is enabled in the local PHP configuration file, a
remote attacker may be able to subvert the contents of the variable
interpolated into the include statement. Through the usage of '../'
character sequences, an arbitrary file location may be specified.

If the 'magic_quotes_gcp' configuration parameter is disabled, the
attacker may additionally include a null character in this variable,
terminating the string and allow the specification of an arbitrary system
file. This file will then be disclosed to the remote user.

18. AOL Instant Messenger Unauthorized Actions Vulnerability
BugTraq ID: 5246
Remote: Yes
Date Published: Jul 16 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5246
Summary:

AIM (AOL Instant Messenger) is an instant messenging client for Microsoft
Windows, MacOS, and other platforms.

AIM is prone to an issue which may allow maliciously crafted HTML to
perform unauthorized actions on behalf of a user of the vulnerable client.

AIM installs a handler for "aim:" URIs.  The "aim:" URIs can be used to
perform configuration changes and other actions specific to the AIM
client.  Actions that may be performed include adding entries to the buddy
list, adding a new group, etc.  Once the handler is invoked, the specified
action will be carried out without prompting or notifying the user.

The attacker may exploit this vulnerability by obscuring a "aim:" link and
enticing the victim to click on it.  More dangerously, it has been
reported that this can be exploited automatically once a victim visits a
website if the attacker uses HTTP REFRESH to reload pages as "aim:" URIs.

This issue was reported for versions of AIM running on Microsoft Windows
and MacOS.  The Linux version of the client is not affected by this
vulnerability.

19. Mirabilis ICQ Sound Scheme Predictable File Location Vulnerability
BugTraq ID: 5247
Remote: Yes
Date Published: Jul 16 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5247
Summary:

ICQ is an instant messenger client for Microsoft Windows systems. ICQ
includes support for sound schemes. ICQ sound scheme files are generally
given the .scm extension.

When installed, a sound scheme places a number of wav sound files in a
predictable location within the installation directory of ICQ. An attacker
may exploit this vulnerability to place malicious content in a known
location. A URL reference to the file may then cause malicious content or
code to be executed within local context.

It has been demonstrated that a .mht file may be renamed as a .wav file
and deposited in this way. If referenced through some browsers with the
protocol specified as mhtml, attached executable content may be
automatically dropped to a defined directory on the local system, and then
referenced in turn.

The ability to plant a file on the victim filesystem may also be leveraged
in conjunction with other vulnerabilities such as that described by
Bugtraq ID 3867.

20. Oddsock Song Requester WinAmp Plugin Denial Of Service Vulnerability
BugTraq ID: 5248
Remote: Yes
Date Published: Jul 16 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5248
Summary:

Oddsock Song Requester is a WinAmp plugin that is used to allow listeners
to make requests for their songs.

A vulnerability has been reported for Oddsock Song Requester 2.1.
Reportedly, Song Requester is prone to a denial of service condition when
malformed requests are made.

The vulnerability occurs when an attacker makes a request to 'request.cgi'
using a long value for the 'listpos' parameter.  When this occurs, Song
Requester and WinAmp will crash.

This will prevent legitimate users from using the Song Requester service.
As this condition may be due to a buffer overflow, code execution should
be considered a possibility.  This vulnerability was tested with Song
Requester 2.1 and WinAmp 2.80. It is not known whether other versions of
Song Requester are vulnerable.

Note: it was reported that the value for the 'psearch' parameter also
causes a crash, however this could not be reproduced by SecurityFocus.

21. Macromedia Sitespring Default Error Page Cross Site Scripting Vulnerability
BugTraq ID: 5249
Remote: Yes
Date Published: Jul 17 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5249
Summary:

Macromedia Sitespring is a J2EE compliant website production management
solution. The Macromedia Sitespring server runs on Microsoft Windows
operating systems.

A cross site scripting issue has been reported in the default error page
used by Sitespring. When an HTTP 500 error is returned, some user supplied
data is included in the generated HTML. This data is not properly
sanitized, and it is possible to include arbitrary HTML, include
JavaScript.

An attacker may create a malicious link to a vulnerable site, including
arbitrary JavaScript commands. If a user of the site is enticed into
following this link, the malicious script code will execute within the
context of the Sitespring site. Script code may take actions as an
authenticated user, or disclose sensitive information to an attacker,
including cookie data.

22. Caucho Technology Resin Server Device Name Path Disclosure Vulnerability
BugTraq ID: 5252
Remote: Yes
Date Published: Jul 17 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5252
Summary:

Resin is a XML-based application server.  It is available for Microsoft
Windows operating systems, in addition to Linux and Unix variants.

Resin discloses sensitive information when handling malformed web
requests.  When a request for certain MS-DOS device names is made, the
server will respond with an error page that contains the absolute path to
the webroot directory.

This type of sensitive information may be used in further attacks on the
host.

This issue has been reported in Resin running on Microsoft Windows
platforms.

23. Microsoft IIS SMTP Service Encapsulated SMTP Address Vulnerability
BugTraq ID: 5213
Remote: Yes
Date Published: Jul 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5213
Summary:

Microsoft Exchange 5.5 and the SMTP (Simple Mail Transfer Protocol)
service included with IIS (Internet Information Services) 4.0 and 5.0 are
vulnerable to an encapsulated SMTP address vulnerability.

The vulnerability was originally announced in Microsoft Security Bulletin
MS99-027 and reported to affect Exchange Server 5.5. Microsoft released a
patch to fix the vulnerability for Exchange Server 5.5 only.  It has been
recently reported that this vulnerability also affects the SMTP service
included with Microsoft IIS 4.0 and 5.0.  There exists no patch for the
IIS SMTP service.

It is possible for a remote attacker to perform mail relaying via an
Exchange server that is configured to act as a gateway for other Exchange
sites, using the Internet Messaging Service. Mail-relaying is a practice
where remote attackers cause an email server to forward email from the
attacker, as though the server were the sender of the mail. Open mail
relays are used primarily by "spammers" to obscure the origin of
unsolicited email.

Microsoft Exchange Server implements security features designed to defeat
email relaying. However, a vulnerability exists in this feature that would
allow an attacker to circumvent the anti-relaying features of the Exchange
Server.

The vulnerability is a result of the way that site-to-site relaying is
performed via SMTP. Any SMTP addresses that are encapsulated can be used
to send mail to any desired e-mail address.

24. ATPhttpd Buffer Overflow Vulnerabilities
BugTraq ID: 5215
Remote: Yes
Date Published: Jul 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5215
Summary:

ATPhttpd is a small webserver designed for high-performance.  It was
developed by Yann Ramin.

There exist several exploitable buffer overflow conditions in ATPhttpd.
Remote attackers may levarage these vulnerabilities to gain access on
affected servers.

The vulnerabilities are due to use of unbounded string copy operations and
off-by-one errors.  One such condition is when errors are output due to
invalid data supplied by a client:

(void) sprintf(buffer, "The following error occurred while trying to
examine the garbage that you sent this poor webserver:
<br><b>%s</b><br><br>\n", text );

The insecure construction of this string using externally supplied data
may be exploited to overwrite data beyond the boundaries of 'buffer'.

25. Pingtel Expressa Default Blank Administrator Password Vulnerability
BugTraq ID: 5214
Remote: Yes
Date Published: Jul 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5214
Summary:

Expressa is the Java-Based Voice-Over-IP phone developed and distributed
by Pingtel.

A problem with Expressa phones could make it possible for a user to gain
administrative access to a vulnerable phone.

It has been discovered that Pingtel Expressa phones do not require the
setting of an administrator password by default.  The default password set
for Expressa phones is a NULL value, which allows access to administrative
functions without authentication whatsoever.  A phone without the
administrative password set could be accessed remotely by an attacker via
the web interface.

This problem could allow a user with either local, physical access, or
access to the phone across a network medium to gain administrative access
to the vulnerable device.

26. CARE 2002 Multiple SQL Injection Vulnerabilities
BugTraq ID: 5219
Remote: Yes
Date Published: Jul 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5219
Summary:

CARE 2002 is software designed to integrate various systems in the health
care industry. It provides a web interface, and is implemented in PHP.

Reportedly, CARE 2002 suffers from multiple SQL injection issues. User
supplied data is used to construct SQL statements, and special characters
such as ''' and '"' are not properly escaped. An attacker may be able to
pass malicious data to the system which modifies SQL queries.

Exploitation of this issue may result in the disclosure of sensitive
information, modification of sensitive information, or privilege
escalation. Full details on the nature of these vulnerabilities are not
currently available.

27. CARE 2002 Unsafe File Include Input Validation Error
BugTraq ID: 5218
Remote: Yes
Date Published: Jul 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5218
Summary:

CARE 2002 is software designed to integrate various systems in the health
care industry. It provides a web interface, and is implemented in PHP.

An input validation error has been reported in CARE 2002 which may result
in the disclosure of sensitive locale files.

Reportely, under some conditions user supplied input is used in an unsafe
manner as part of an include() call. A malicious party able to influence
this data may use '../' character sequences to exit the web root, and
specify an arbitrary file as the parameter to included. Under some
scripts, the specified file will be displayed to the remote user.

Additionally, the null character 0x00 may be used to terminate the string
passed to include(), eliminating any file extension restrictions on which
files may be viewed.

Exploitation of this vulnerability requires that the PHP parameter
'register_globals' is set to 'on'.

28. Real Networks RealJukebox/RealOne Player Gold Skinfile Buffer Overflow
BugTraq ID: 5217
Remote: Yes
Date Published: Jul 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5217
Summary:

RealJukebox and RealOne Player Gold are multimedia applications for
Microsoft Windows operating systems.

Real Software has announced a vulnerability in RealJukebox2 and Real
Player Gold.

A buffer overflow condition exists due to insufficient bounds checking of
fields in skinfiles.  Skinfiles are archives comprised of a number of
files containing skin data.  One of the files, "skin.ini", contains
information about how the skin is to be displayed.  There is an unchecked
buffer for the "CONTROLnImage" field of this file.  By supplying an overly
long filename as a value for this field, it is possible to overwrite stack
variables.  An attacker may exploit this condition to overwrite the return
address with a pointer to embedded attacker-supplied instructions.

To exploit this issue the attacker must transmit the maliciously
constructed skinfile to a victim of the attack.  This may be done via a
webpage or HTML e-mail.  Exploitation of this issue may result in
execution of attacker-supplied instructions with the privileges of the
user opening the malicious skinfile.

29. Pingtel Expressa Web Server Cross-Site Scripting Vulnerability
BugTraq ID: 5220
Remote: Yes
Date Published: Jul 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5220
Summary:

Expressa is the Java-Based Voice-Over-IP phone developed and distributed
by Pingtel.

A problem with the phone firmware could make it possible for a user to
launch a cross-site scripting attack.

It has been discovered that the configuration web server included with
Expressa phones does not sanitize HTML from some fields (such as the
MESSAGE parameter of the SIP dialing facility).

This problem could result in a user sending a malicious URL to user of the
phone that has authenticated to the web interface.  When the URL is
accessed by the Expressa user, any script code or arbitrary HTML contained
in it would be executed in the security context of the Expressa web
server.

30. Pingtel Expressa Admin Account Login Session Timeout Vulnerability
BugTraq ID: 5221
Remote: No
Date Published: Jul 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5221
Summary:

Expressa is the Java-Based Voice-Over-IP phone developed and distributed
by Pingtel.

A problem with Expressa phones could make it possible for a user to gain
unintended administrative access to a vulnerable phone.

The admin login of Expressa phones does not time out sessions.  If an
admin logs into the phone via the keypad, the admin will stay logged in to
the phone until the admin either selects "ok" or "cancel."  As a result,
an admin that logs in and forgets to log out leaves the phone admin
accessible to any user with physical access to the phone.

This could result in unintended users gaining administrative access to the
phone.

31. Pingtel Expressa Arbitrary Firmware Upgrade Vulnerability
BugTraq ID: 5223
Remote: No
Date Published: Jul 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5223
Summary:

Expressa is the Java-Based Voice-Over-IP phone developed and distributed
by Pingtel.

A problem with Expressa phones could make it possible for a user change
the firmware revision on a vulnerable phone.

It has been discovered that users may be able to arbitrarily upgrade phone
firmware.  Expressa phones allow users to upgrade firmware without first
authenticating as an administrator.  This problem could allow a user to
load a malicious version of phone firmware.

This problem makes it possible for an attacker to upgrade phone firmware,
and potentially load a malicious firmware.

32. Pingtel Expressa Arbitrary Application Installation Vulnerability
BugTraq ID: 5224
Remote: Yes
Date Published: Jul 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5224
Summary:

Expressa is the Java-Based Voice-Over-IP phone developed and distributed
by Pingtel.

A problem with the application software download functionality of the
phone could allow a remote user to install arbitrary packages.

A vulnerability has been reported in Expressa phones where an attacker may
use a shortcoming in the application installation process to install
malicious software on the vulnerable system. Expressa application installs
use HTTP without any authentication to obtain applications.  Any updated
packages are installed on the system as the phone user.

In order to exploit this vulnerability, the attacker must control the
machine configured as the application download server, from the
perspective of the vulnerable client. It may be possible to create this
condition through some known techniques, including DNS cache poisoning and
DNS spoofing.

It should be noted that this issue could be eliminated by using digital
signatures.


III. SECURITYFOCUS NEWS AND COMMENTARY
------------------------------------------
1. H2K2 Hackers Say They Want a Revolution
By  Kevin Poulsen

But some charge that dot-com greed robbed the computer underground of its
soul.

http://online.securityfocus.com/news/533

2. More EBook Hacking Tricks From Embattled Elcomsoft
By  Brian McWilliams

Russian software company says Adobe's copy protection system is built from
clay and straw.

http://online.securityfocus.com/news/530

3. HP confirms 150 suspended in email porn probe
By John Leyden, The Register

HP has officially confirmed that it has suspended 150 staff as part of its
investigation into the misuse of corporate email system in distributing
"inappropriate material". Around 60 permanent and 90 contractors are under
investigation.

http://online.securityfocus.com/news/540

4. Team demos 'first quantum crypto prototype machine'
By John Leyden, The Register

Boffins have moved one step closer to a practical implementation of the
Holy Grail of encryption - quantum cryptography - by exchanging keys
across a 67km fibre optic network.

http://online.securityfocus.com/news/539

5. Alliance Sets Standards on Computer Security
By Shannon Henry, Washington Post

In a high-tech, high-powered version of a neighborhood watch, a group of
government agencies and private businesses plan to announce today a common
set of standards and software to fight computer hacking.

http://online.securityfocus.com/news/538


IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. SQL Server Password Auditing Tool v1.0.1
by Patrik Karlsson
Relevant URL:
http://www.cqure.net/tools10.html
Platforms: Linux, UNIX, Windows 2000, Windows 95/98, Windows NT, Windows
XP
Summary:

This tool should be used to audit the strength of Microsoft SQL Server
passwords offline. The tool can be used either in BruteForce mode or in
Dictionary attack mode. The performance on a 1 Ghz pentium (256mb) is
around 750 000 guesses/sec.

To be able to perform an audit one needs the password hashes that are
stored in the sysxlogins table int the master database. The program needs
to have them formated in a textfile accordingly (look at the included file
hashes.txt)

2. Inzider 1.2
by Arne Vidstrom
Relevant URL:
http://ntsecurity.nu/toolbox/inzider/
Platforms: Windows 95/98, Windows NT
Summary:

This is a very useful tool that lists the current processes in your
Windows system and which ports they listen on. It is written to work on
Windows NT and Windows 9x. There have been some stability problems on
Windows 9x, but they seem to have been solved now. On Windows NT, inzider
is unable to check processes that are started as services.

3. SQLLHF v1.3
by Matt Wagenknecht
Relevant URL:
http://www.sqlsecurity.com/DesktopDefault.aspx?tabindex=4&tabid=7
Platforms: N/A
Summary:

SQL Server Brute Forcing tool featuring a scriptable command-line
interface, scans networks larger than class C, and IP list support. by
Matthew Wagenknecht

4. Network Access Control System
by Marc Schöchlin
Relevant URL:
http://www.256bit.org/nacs.html
Platforms: Java
Summary:

NACS provides you a comfortable and secure way to provide untrusted
computers access to your TCP/IP-based (v4) LAN/WAN. The system guarantees
that only registered users are able to use network resources. In contrast
to other solutions, like PPTP or IPsec, it is not necessary to install
program-specific client software. The client machines only need a DHCP
client (automated networkconfiguration) and an SSL capable Web browser.
The server needs a 2.4 kernel, Jakarta-Tomcat Servlet Engine, JDK 1.3/JDK
1.4, Apache, MySQL, and firewall which secures your network in general.
NACS gets its login and password data from a normal Linux-style passwd
file. This implementation supports the integration of other authentication
mechanisms (such as LDAP).

5. Simp (Secway's Instant Messenger Privacy) v1.1.0
by Secway
Relevant URL:
http://www.secway.com/lab/simp.php?PARAM=us,ie#download
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:

Simp (Secway's Instant Messenger Privacy) is a tool developed by Secway to
secure your online MSN Messenger conversations. Simp works by encrypting
messages before they are sent over the Internet and decrypting them when
they arrive at your contacts. Once installed on your and your friends
computer, Simp will prevent anyone from reading your conversations.

6. Tiny Honeypot v0.4.3
by George Bakos
Relevant URL:
http://alpinista.dyndns.org/files/thp/
Platforms: Linux, POSIX
Summary:

Tiny Honeypot (thp) is a simple honey pot program based on iptables
redirects and an xinetd listener. It listens on every TCP port not
currently in use, logging all activity and providing some feedback to the
attacker. The responders are entirely written in Perl, and provide just
enough interaction to fool most automated attack tools, as well as quite a
few humans, at least for a little while. With appropriate limits
(default), thp can reside on production hosts with negligible impact on
performance.


V. SECURITY JOBS SUMMARY
------------------------
1. Seeking position in the Philadelphia area - CISSP (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

2. Status Of The IT Talent Pool - Dead Thread (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

3. Sales Executive #722 - NY; DC; San Francisco; Chicago; Dallas (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

4. Hit by the IT Blues (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

5. Sr. Security Sales Engineer position w/ Qualys for New York, NY (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

6. Status Of The IT Talent Pool (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

7. Looking for pen-testing position in London (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

8. Resume (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

9. Security Auditor - South Bay Area, CA - Greythorn (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/5544986F9407D611A5900008C70964061A663B@EXCHANGE

10. Sr. Security Architect/Engineer (Linux) position at Qualys (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

11. Sr. Product Manager position at Qualys (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

12. Looking for employment (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

13. Security Application Deployment Consultant - New York (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

14. Anti-Virus Position - Chicago - Greythorn (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/5544986F9407D611A5900008C70964061A661D@EXCHANGE

15. Network Security Professional with active Secret or Top Secret clearances (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

16. New York/New Jersey Sales Engineer needed (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

17. Seeking for Security Jobs Work with DOE (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

18. We are hiring Sr. System Engineers and  Senior Level Sales people (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

19. Intrusion Detection and Forensic Position in NJ (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

20. Senior Sales Executives - East Coast (New York Tri-State Area) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/008101c2293b$44fe4900$6401a8c0@hacknspam01


VI. INCIDENTS LIST SUMMARY
-------------------------
1. re: TCP 1025 scanning worm? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

2. Vacation Troller, Please Ignore. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

3. Announcement (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

4. OpenBSD rootkit (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

5. Frethem.K virus (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

6. Ideas? Port 21 SYNs, slow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/010201c22bc6$409300d0$0200a8c0@backstreet

7. Unknown/Weird Traffic? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

8. Another odd scan... (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

9. TCP port 139 probes (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

10. Conclusion: TCP port 139 probes (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

11. Code Red and other anomalous activity from 1433 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/3D2EBD8A.3116.3CA4AAA@localhost

12. Can anyone identify this backdoor? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]


VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. PHP : eval() ? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

2. Lindows Issues (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/02071818170101.19230@vito

3. nsmail XSS hole (was  double decoding filter bypass (Hotmail) + challenge for you) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

4. double decoding filter bypass (Hotmail) + challenge for you (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

5. SQL Injection Legalities (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

6. Smashing the Stack? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

7. Operation TIPS (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

8. Badware update through P2P? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

9. Announcement (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

10. Query (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/21905E09B270D111815400C0DFAA1533AFB3CE@tgb-mailhost.portcullis-security.com

11. [VulnWatch] wp-02-0001: GoAhead Web Server Directory Traversal + Cross Site Scripting (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

12. Remote ICQ Sound Desactivation (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

13. Assembler/C References (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/Pine.SOL.4.30.0207170004580.26566-100000@grosse.mdstud.chalmers.se

14. VANED LABS: icecast filesystem disclosure (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

15. Insecure Online Update with quicktime? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

16. CSS(Cross-Site Scripting) at digitalid.verisign.com, www.bbb.org    & www.truste.org. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

17. [7.8.2002 44916] Notice of Copyright Infringement] (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

18. VU#197395 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

19. XSS in lycos htmlgear guestbook (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/02071514322403.01106@Holmes

20. MSNBC Article        [7.8.2002 44916] Notice of Copyright Infringement] (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

21. hi (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/21905E09B270D111815400C0DFAA1533AFB3AC@tgb-mailhost.portcullis-security.com

22. Follow-up to Malware Repository Request (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

23. Hosting Controller Vulnerability (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

24. [7.8.2002 44916] Notice of Copyright Infringement (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

25. IE without Images (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

26. Lessons Learned from the MPAA's use of DCMA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/6B333F1FBA3CD41198FA00508BDF58C80211A52C@emss52m03.kan.lmcda.lmco.com

27. Looking for a repository of worms/trojans/ddos tools (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/004a01c229ce$d87456a0$0200a8c0@thefes5cez1537

28. FW: [7.8.2002 44916] Notice of Copyright Infringement (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

29. [Fwd: Re: Windows fuzz] (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

30. Vulnerability found: The Adobe eBook Library (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

31. various architectures well known numbers (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

32. IIS Microsoft SMTP Service Encapsulated SMTP Address Vulnerability (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/21905E09B270D111815400C0DFAA1533AFB3A5@tgb-mailhost.portcullis-security.com

33. Remote DoS Against A Given Chat Client With the !seen Service (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]


VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Exchange Information Store Replication (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

2. write permissions for IIS (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/8BD7226E07DDFF49AF5EF4030ACE0B7E0613E8A5@red-msg-06.redmond.corp.microsoft.com

3. Need security proposal for Win2K upgrade... (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

4. Announcement (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

5. Win32 Apache service not run as System... (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/BFCC17728801D311A6A90001FA7EA13610881B58@xcem-aztem-04.wellsfargo.com

6. Exchange 2000 ms02-025 hotfix Q320436 caused SA to hang on restart[Scanned] (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

7. SecurityFocus Microsoft Newsletter #95 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/6AA3020BB6C49E4EBDB05588474253321B63F9@dieppe.calgary.securityfocus.com

8. Exchange 2000 ms02-025 hotfix Q320436 caused SA to hang on restart (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

9. Exchange2K/DMZ (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/010801c22b5b$9750fa00$32f4450a@deth


IX. SUN FOCUS LIST SUMMARY
----------------------------
1. Announcement (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]

2. My solution for preventing xhost + (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]

3. dtlogin and secure access control (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]


X. LINUX FOCUS LIST SUMMARY
---------------------------
1. Announcement (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

2. Forward ftp request to another server (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

3. amanda backups and firewalling (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected] (added by vader.se.ilan.cogent.net)

4. Forward ftp request another server (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/1026885075.9341.19.camel@elendil


XI. SPONSOR INFORMATION
-----------------------
This newsletter is sponsored by: PoliVec, Inc.

***FREE Trial License of PoliVec Scanner***

Automate your security policies and reduce administrative time and
configuration errors. Stay current with Patches and Hotfixes. Ensure that
your systems meet configuration requirements. Remotely change system
configurations, registry settings and services that are enabled. Manage
NTFS and Active Directory Servers. Identify insecure passwords, schedule
audits, develop reports for comparison, oh, and did we mention, with
PoliVec Scanner there are No Agents to install?

For a FREE trial license of PoliVec Scanner, please visit
http://www.polivec.com/scanner1 or call us toll-free at 1.866.POLIVEC.

-------------------------------------------------------------------------------