SecurityFocus Newsletter #155
John Boletta <[email protected]> Mon, 29 Jul 2002 10:15:13 -0600 (MDT)
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #155
-----------------------------
This Issue is sponsored by: Stratum8 Networks, Inc.
Free Webinar: Securing Web Servers Today - Featuring Hurwitz Group. Web
servers and Web-based applications are the single most commonly exploited
technologies in corporate security breaches today. Learn how to
permanently secure these dangerous security holes in a free one hour
webinar featuring Hurwitz Group and sponsored by Stratum8 Networks.
Find out more about this educational opportunity now by visiting us at:
http://www.stratum8.com/news_events/webinars/hurwitz8.shtml
-------------------------------------------------------------------------------
I. FRONT AND CENTER
1. Filtering E-Mail with Postfix and Procmail, Part Four
2. Detecting and Removing Malicious Code
3. High-Flying Schmidt
4. Black Hat Briefings & Training
5. Secure i-World
6. SecurityFocus DPP Program
II. BUGTRAQ SUMMARY
1. Geeklog HTML Attribute Cross Site Scripting Vulnerability
2. Geeklog Email Composition CRLF Injection Vulnerability
3. Tru64 SU Command Line Buffer Overflow Vulnerability
4. Adobe eBook Reader File Restoration Privilege Escalation...
5. Microsoft Outlook Express SMTP Over TLS Information Disclosure...
6. Working Resources BadBlue HTTP 302 Message Cross-Site Scrpting...
7. Working Resources BadBlue Administrative Interface Arbitrary...
8. Microsoft Outlook Express Spoofable File Extensions Vulnerability
9. PHP HTTP POST Incorrect MIME Header Parsing Vulnerability
11. PHP Interpreter Direct Invocation Denial Of Service Vulnerability
12. Sun PC NetLink Backup Restoration ACL Permissions Vulnerability
13. Pablo Software Solutions FTP Server File/Directory Disclosure...
15. SmartMax MailMax Popmax Buffer Overflow Vulnerability
16. Sun Fire Unauthorized Environmental Monitoring Subsystem...
17. SecureCRT SSH1 Identifier String Buffer Overflow Vulnerability
18. Multiple Vendor Web Browser JavaScript Modifier Keypress Event...
19. DansGuardian Hex Encoding URL Content Filter Bypass Vulnerability
20. Zyxel Prestige 642R Router Malformed TCP Packet Denial Of...
21. Mozilla JavaScript URL Host Spoofing Arbitrary Cookie Access...
22. VMWare GSX Server Authentication Server Buffer Overflow...
III. SECURITYFOCUS NEWS ARTICLES
1. Find a Bug? Don't E-Mail Microsoft
2. GAO: U.S. Cyber Security Efforts are Uncoordinated
3. Big software pushes hard for national Gestapo
4. Congress blasts Feds on cyber-terror FOIA games
IV.SECURITYFOCUS TOP 6 TOOLS
1. Pachyderm-fw v0.91
2. Mixmaster v2.9b33
3. Maillog View v1.02.6
4. echolot-pinger v 2.0beta18
5. Linux Firewall v2.0rc2
6. Mailcrypt v3.5.7
V. SECURITYJOBS LIST SUMMARY
1. resume of an ethical hacker (Thread)
2. Wireless Security Engineer Position in Washington DC (Thread)
3. Security Engineer Positions in Washington DC (Cryptographic...
4. C++ Engineer (Thread)
5. Internship/Coop Candidate. (Thread)
6. Security Analyst Position with Bristol-Myers Squibb (Thread)
7. Seeking infosec engineering position(FullTime/PartTime)...
8. Jr. Sales Executives - East Coast (South Florida) (Thread)
9. Seeking a career in IT security in Singapore,Asia pacific[GSEC...
10. Security Positions in Mississippi (Thread)
11. *UPDATE* Network Engineer - Secure Systems (Thread)
12. Experienced Wireless Security Architect position (Thread)
13. Senior Project Manager (Security) - NYC (Thread)
14. Security Auditor Position in NY City (Thread)
15. Seeking Network Security Job in Germany (Thread)
16. INSIDE SALES TOP PERFORMER (Thread)
17. Looking for someone with DEC VAX/VMS Security experience (Thread)
18. Opportunity for an Information Security Engineer in Reston...
19. Network Security/Information Assurance positions (Thread)
20. Willing to relocate for a position (Thread)
21. Unix/Net/Sec Engineer with CISSP,CCNA,MCSE Seeking position in...
22. Network Engineer - Secure Systems (Thread)
23. Director of Quality Assurance for Qualys (Network Security)...
24. Red team for hire (Thread)
25. Network Security Positions (Thread)
26. Experienced Security Manager in NYC area seeking opportunity...
27. Information Security/Assurance Opportunity in Northern VA...
28. WireX Immunix Adversary, DefCon Games (Thread)
29. Job for a CISSP, Chartered Accountant, ISA, Grad CWA - 20...
VI. INCIDENTS LIST SUMMARY
1. Surge of attacks on ports 61127 & 61134 (Thread)
2. Anyone know this rootkit (rootkits?) (Thread)
3. Bind 9.2.X exploit??? (Thread)
4. FireDaemon exploit - part 2 (Thread)
5. Increasing compromises of NT servers with Serv-U and Unicode...
6. Dead Thread: China Experience? (Thread)
7. China Experience ? (Thread)
8. Re: China Experience ? (Thread)
9. Scanning Port UDP 4668 (Thread)
10. Unicode exploits with Serv-U (Thread)
11. diagnose compromise on NT (Thread)
12. Odd scan (Thread)
13. Can anyone identify this backdoor? (Thread)
14. FireDeamon exploit (Thread)
15. TCP 1025 scanning worm? (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
1. SQL Server 2000 Buffer Overflows and SQL Inyection...
2. Does MSN Messenger Bypass Group Policy? (Thread)
3. UPDATE: Re: REFRESH: EUDORA MAIL 5.1.1 (Thread)
4. REFRESH: EUDORA MAIL 5.1.1 (Thread)
5. confixx (remote access) (Thread)
6. More Buffer Overphlow Questions (Thread)
7. Denial of Service bug in Pine 4.44 (Thread)
8. Nanog traceroute format string exploit. (Thread)
9. bash 2.05.0(1)-release/it.map.gz Slackware 8.0 default and...
10. cached logon credentials (Thread)
11. Arcserve (Thread)
12. Vulnerability found: Adobe Acrobat eBook Reader and Content...
13. SSH Protocol Trick (Thread)
14. PHRACK 59 OFFICIAL RELEASE (Thread)
15. XSS at www.internic.com (Thread)
16. Announcement: injectso-0.2 (Thread)
17. SPIKE Proxy 1.1 Released (Thread)
18. Dave Barry on network security policies (Thread)
19. ass the attack spoofing shell (Thread)
20. Bind recursive queries quota. (Thread)
21. Lindows Issues (Thread)
22. WireX Immunix Adversary, DefCon (Thread)
23. Smashing the Stack? (Thread)
24. Linux kernel setgid implementation flaw (Thread)
25. [VulnWatch] wp-02-0001: GoAhead Web Server Directory Traversa...
26. Assembler/C References (Thread)
27. PHP : eval() ? (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
1. need help with ActiveX remote counters (Thread)
2. Exporting GPOs from Active Directory (Thread)
3. Securing IIS Using, MS Security Tool Kit & Scripting (Thread)
4. Problems with IIS and Certification Services (Thread)
5. SecurityFocus Microsoft Newsletter #96 (Thread)
6. Make all directories reinherrit ACLs (Thread)
7. write permissions for IIS (Thread)
8. Terminal Services Auditing not working (Thread)
9. local security policy (Thread)
10. Need security proposal for Win2K upgrade... (Thread)
IX. SUN FOCUS LIST SUMMARY
1. tty sniffer. (Thread)
2. Jass + Solaris9 + Fixmodes (Thread)
3. Summary: Proving OpenSSH 3.4p1 is using /dev/urandom (Solari...
4. Proving OpenSSH 3.4p1 is using /dev/urandom (Solaris 9 ossh Vs...
X. LINUX FOCUS LIST SUMMARY
1. Security by hiding processes (Thread)
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. Filtering E-Mail with Postfix and Procmail, Part Four
By Brian Hatch
This is the fourth and final installment in a series on filtering e-mail
with Postfix and Procmail. This installment will discuss two tools that
are available for use with Procmail: Razor, an automated spam tagging and
filtering tool, and SpamAssassin, a mail filter that contains hundreds of
different spam tests.
http://online.securityfocus.com/infocus/1611
2. Detecting and Removing Malicious Code
by Matthew Tanase
Has it happened yet? The phone call, the e-mail, the page, or maybe you
discovered it yourself. Something wasn't right: sluggish performance, too
much network activity, a missing file. After a little investigating, the
realization - you've been cracked. If this isn't familiar to you yet, odds
are it will be in the future. Crackers have access to countless variations
of malicious code: automated rootkits, trojans, viruses and specific
exploits, all designed to breach your security. Detecting and removing
these programs can be a daunting task, with little room for wasted time or
error. In this article, I'll explain techniques readers can use to get
their system back on-line and prevent it from happening again.
http://online.securityfocus.com/infocus/1610
3. High-Flying Schmidt
By George Smith
Unstoppable viruses, massive blackouts, hacked pacemakers? The
government's number two cyber security guy wasn't this apocalyptic when he
worked for Microsoft.
http://online.securityfocus.com/columnists/97
4. Black Hat Briefings & Training
Attend Black Hat Briefings & Training, July 29 - August 1, Las Vegas, the
world's premier technical security event! 8 tracks, 12 training sessions,
Richard Clarke keynote, 1500 delegates from 30 nations, with a near cult
following of both CSOs and "underground" security experts. See for
yourself what the buzz is all about.
Visit us at: http://www.blackhat.com
5. WebSec 2002, the Online Privacy Conference
MIS Training Institute presents Secure i-World, featuring WebSec 2002, the
Online Privacy Conference, and Secure i-World Expo -- two innovative
conferences and an outstanding expo, all in one blockbuster event.
Secure i-World will be held in San Diego, CA on August 19-21, 2002, with
optional workshops August 17, 18, 21, and 22. The vendor expo will be
August 19 and 20.
For more information and to register for the industry's premier security
event visit http://www.secureiworld.com/07/sw02nl21inf.html.
6. SecurityFocus DPP Program
Attention Non-profit Organizations and Universities!!
Sign-up now for preferred pricing on the only global early-warning system
for cyber attacks - SecurityFocus DeepSight Threat Management System.
Click here for more information:
http://www.securityfocus.com/corporate/products/dpsection.shtml
II. BUGTRAQ SUMMARY
-------------------
1. Geeklog HTML Attribute Cross Site Scripting Vulnerability
BugTraq ID: 5270
Remote: Yes
Date Published: Jul 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5270
Summary:
Geeklog is freely available, open-source weblog software. It is written in
PHP and will run on most Unix and Linux variants, as well as Microsoft
Windows NT/2000. Geeklog is backended by MySQL.
A cross site scripting vulnerability has been reported for Geeklog
1.3.5sr1. Reportedly, Geeklog does not properly sanitize user supplied
input before being included when posting comments or writing stories.
Geeklog makes efforts to sanitize some malicious user supplied input by
stripping out HTML elements that are used for scripting. However, Geeklog
does not properly remove HTML attributes that are used for the same
purpose.
It is possible for an attacker to include malicious HTML code using the
HTML attributes. As an example, if an attacker were to supply malicious
HTML code as part of an onMouseOver JavaScript event, the malicious code
would not be properly sanitized.
An attacker may construct a link containing dangerous HTML code and send
it to a vulnerable user. If a user of the site follows this link, the
script code will be rendered, and execute within the context of the
vulnerable site. It may be possible to access sensitive data such as
authentication credentials, or to take actions as a validated user on the
hosted forum.
This issue may potentially be exploited to hijack web content or steal
cookie-based authentication credentials from legitimate users.
2. Geeklog Email Composition CRLF Injection Vulnerability
BugTraq ID: 5271
Remote: Yes
Date Published: Jul 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5271
Summary:
Geeklog is freely available, open-source weblog software. It is written in
PHP and will run on most Unix and Linux variants, as well as Microsoft
Windows NT/2000. Geeklog is backended by MySQL.
A vulnerability has been reported for Geeklog that may allow an attacker
to include extra email headers when composing email to other Geeklog
users.
Geeklog prevents the disclosure of a user's real email address for privacy
reasons. However an attacker is able to obtain a user's real email address
by including extra headers when composing an email using Geeklog's 'Send
Email' facility.
It is possible for an attacker to include extra email header fields when
composing an email. An attacker does this by appending a CRLF sequence
followed by an email header field to the subject field.
An attacker can use this method to obtain a user's real email address.
3. Tru64 SU Command Line Buffer Overflow Vulnerability
BugTraq ID: 5272
Remote: No
Date Published: Jul 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5272
Summary:
Tru64 is a Unix variant. su is a utility that can be used by a user to
change user-identity while logged in.
The su utility on Tru64 Unix systems is prone to a locally exploitable
buffer overflow condition. This is due to insufficient bounds checking of
input passed via the command line. It is possible to cause memory
corruption, including overwriting stack variables such as the return
address, by supplying an overly long string on the command line when
running su.
The su utility is setuid root, so it is possible for a local attacker to
exploit this condition to execute arbitrary instructions as root.
4. Adobe eBook Reader File Restoration Privilege Escalation Vulnerability
BugTraq ID: 5273
Remote: No
Date Published: Jul 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5273
Summary:
Adobe eBook Reader is a client side application which is able to view
Adobe eBooks, available for Microsoft Windows and Macintosh OS 9. eBooks
are electronic books which provide some protection for content. Users may
be able to view a book, but have limited publisher defined privileges to
copy content. It is possible to define quotas, such as only allowing a
user to print or copy a specific number of pages within a given time
period.
It has been reported possible to bypass some quota restrictions. eBook
maintains some information about the past actions of the local user for a
given book in a number of local files. These files may be copied and later
restored from these copies. Restoration will effectively restore the eBook
data to it's original state, without any loss in functionality.
A user may thus backup specific local files, print or copy protected
content, and then restore the local files. There will be no record of the
printing or copying actions, and any non-zero quota may be effectively
bypassed entirely.
This vulnerability has been reported in versions of eBook Reader for
Microsoft Windows. It may, however, exist on other platforms.
5. Microsoft Outlook Express SMTP Over TLS Information Disclosure Vulnerability
BugTraq ID: 5274
Remote: Yes
Date Published: Jul 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5274
Summary:
Microsoft Outlook Express is a mail client for the Microsoft Windows
operating system. Outlook Express includes support for secure SMTP
communications using TLS, as defined in RFC 2487.
Under TLS, it is possible for a client and server to successfully
negotiate an encrypted connection without authentication. In this case,
transmitted data will be properly encrypted, but the identity of the
client and server are not securely defined.
Reportedly, Outlook Express will allow this condition to occur with no
further warning to the end user. This may prevent the detection of a
malicious mail server when TLS authentication is expected. If this
happens, the client may send additional sensitive information through SMTP
to the server. In particular, SMTP AUTH authentication information may be
communicated to the unknown server.
The malicious server may be able to use this information to perform a
man-in-the-middle attack, monitoring or subverting SMTP traffic with the
legitimate SMTP server.
This behavior has been reported in Outlook Express. It is possible,
however, that additional SMTP clients share this behavior.
6. Working Resources BadBlue HTTP 302 Message Cross-Site Scrpting Vulnerability
BugTraq ID: 5275
Remote: Yes
Date Published: Jul 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5275
Summary:
BadBlue is a P2P file sharing application distributed by Working
Resources. It is available for Microsoft Windows operating systems.
A problem with BadBlue could make it possible for users to launch
cross-site scripting attacks.
Upon passing a vulnerable BadBlue server a request for a either a file
path that does not exist or a directory that does exist, both of which are
not appended with a slash (/), BadBlue returns an HTTP 302 (found)
response.
BadBlue does not sufficiently sanitize input when returning a 302
response. When a user sends a request to the server that illicits a 302
response, any HTML contained within the response is returned to the user.
This could make it possible to launch cross-site scripting attacks that
would allow execution of code in the security context of the vulnerable
BadBlue server.
7. Working Resources BadBlue Administrative Interface Arbitrary File Access Vulnerability
BugTraq ID: 5276
Remote: Yes
Date Published: Jul 20 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5276
Summary:
BadBlue is a P2P file sharing application distributed by Working
Resources. It is available for Microsoft Windows operating systems.
A problem with BadBlue could make it possible for a remote user to gain
access to sensitive files.
BadBlue Enterprise Edition is administered via a web interface. Access to
this web interface is restricted to the system the BadBlue server is
installed on. This access control is enforced by the administrative
server listening only on the loopback interface.
BadBlue does not sufficiently control access to the administrative
interface. It is possible to remotely add the entire drive of a system
running a vulnerable BadBlue implementation via a maliciously crafted web
page containing a form POST method. This would allow remote users to via
the contents of the drive with the privileges of the BadBlue server.
8. Microsoft Outlook Express Spoofable File Extensions Vulnerability
BugTraq ID: 5277
Remote: Yes
Date Published: Jul 20 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5277
Summary:
Microsoft Outlook Express is prone to an issue which when successfully
exploited may cause an unsuspecting web user to execute files of an
entirely different type than they appear to be.
It is possible for a malicious user, sending email via a mail agent
capable of manipulating the MIME headers, to spoof file extensions for
users of Outlook Express. For example, an .exe file can be made to look
like a .txt (or other seemingly harmless file type) file in the attachment
list.
When including a certain strings of characters between the filename and
the actual file extension, Outlook Express will display the specified
misleading file extension type. The source of this issue is that Outlook
Express trusts the filename in the MIME Header, as opposed to relying upon
the Header Content-Type for information about what type of file it is.
The end result is that an attacker is able to entice a user to open or
save files of arbitrary types to their local system. It should be noted
that this vulnerability could be used to bypass file type filters, change
the attachment icon to the default icon, spoof the size of the attachment,
or spoof the file extension of the attachment when opened.
It is also worth mention that this vulnerability is similar in nature to
both Bugtraq ID 3597 and Bugtraq ID 4087, and may be related to the same
component.
9. PHP HTTP POST Incorrect MIME Header Parsing Vulnerability
BugTraq ID: 5278
Remote: Yes
Date Published: Jul 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5278
Summary:
PHP is a general purpose scripting language that is used for Web
development. It is available for various platforms including Linux and
Unix variants as well as Microsoft Windows operating systems.
A vulnerability has been reported for PHP versions 4.2.0 and 4.2.1. It is
possible for a remote attacker to cause the PHP interpreter to crash the
web server on a vulnerable system and execute malicious, attacker supplied
code.
The vulnerability is the result of the PHP interpreter incorrectly parsing
MIME headers when HTTP POST commands are received. When PHP receives a
malformed POST request, it generates an error condition that is improperly
handled.
When a HTTP POST command is received, a memory structure is appended to a
linked list of MIME headers. The memory allocated for this structure is
freed when the POST command is successful. When a malformed POST request
is made, an uninitialised memory structure is appended to the list of MIME
headers. Attempting to free this memory will have negative consequences
for a vulnerable system.
This vulnerability has different effects on different architectures. It
has been reported that PHP will crash when it tries to free the memory
structure on an IA32 (x86) architecture. The IA32 architecture has been
verified to be safe from the execution of arbitrary code. However, it is
still possible to crash PHP as well as the web server on vulnerable
systems.
It has also been reported that on Sparc architectures, an attacker may
have greater control about how memory is freed. Arbitrary code execution
on the Sparc architecture is possible.
An attacker may take advantage of this vulnerability to cause the PHP
interpreter to crash leading to a denial of service or cause the
vulnerable web server to execute malicious, attacker supplied code. It may
also be possible for the attacker to gain elevated privileges.
10. Pyramid BenHur Default Firewall Weakness
BugTraq ID: 5279
Remote: Yes
Date Published: Jul 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5279
Summary:
Pyramid BenHur is a firewall appliance. It is based on Debian Linux using
Linux kernel 2.2.x and ipchains firewalling capabilites.
A vulnerability has been reported for the BenHur device. Reportedly, the
device has a weak default firewall configuration ruleset. It is possible
for an attacker to connect to any port between 1024 and 65096 on the
device provided the source port is TCP port 20. This is due to a poorly
designed rule that was put in place to support FTP data connections.
Attackers may exploit this vulnerability to connect to potentially
sensitive/vulnerable ports on the device such as the administration port
(8888) or the the web proxy server.
11. PHP Interpreter Direct Invocation Denial Of Service Vulnerability
BugTraq ID: 5280
Remote: Yes
Date Published: Jul 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5280
Summary:
It is possible, under some circumstances, for remote attackers to invoke
the PHP interpreter from the web.
When PHP is installed with Apache, an alias/virtual path is created for
the PHP interpreter and this alias is used internally when a CGI path is
resolved. To prevent the interpreter from being invoked remotely for
malicious purposes the cgi.force_redirect directive was introduced, and it
is enabled by default. However, it is still possible to invoke the
interpreter by name without command line arguments from the web despite
the cgi.force_redirect directive.
When the interpreter is invoked with no command line options, it will
hang. Attackers may repeatedly request the PHP interpreter to cause a
denial of service via resource exhaustion.
This is reported to be a problem with PHP and Apache on Microsoft Windows
platforms. It may be possible to reproduce this condition in other
environments as well.
12. Sun PC NetLink Backup Restoration ACL Permissions Vulnerability
BugTraq ID: 5281
Remote: No
Date Published: Jul 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5281
Summary:
Sun PC NetLink is a server software package designed to provide a number
of services to Microsoft Window's based machines. PC NetLink is able to
perform network backup operations.
An issue has been reported with Access Control List (ACL) permissions
applied to files which are restored from backup. Under some conditions,
file permissions will be reset to default values instead of the values
possessed before backup. As a result, files which are restored from backup
may have weaker access restrictions than anticipated.
This condition is related to symbolic links. This behavior may occur when
processing files which are symbolic links, or which reside within a
directory which is a symbolic link, or which reside on a share which is a
symbolic link.
If ACL permissions are modified by this vulnerability, malicious local
users may gain access to sensitive files.
13. Pablo Software Solutions FTP Server File/Directory Disclosure Vulnerability
BugTraq ID: 5283
Remote: Yes
Date Published: Jul 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5283
Summary:
Pablo Software Solutions FTP Server is freely available software for
Microsoft Windows operating systems.
Pablo Software Solutions FTP Server is prone to directory traversal
attacks, potentially resulting in disclosure of the contents of
directories and files on the host running the software.
An attacker may exploit this condition to escape the FTP root directory
using normal FTP commands and browse the contents of arbitrary directories
and files (provided they are readable by the FTP server). A remote
attacker must have anonymous access or a user account with the FTP server
to exploit this issue.
Since the software typically runs with SYSTEM privileges (or the
equivalent of SYSTEM privileges on Microsoft Windows 9x platforms), this
vulnerability may expose sensitive system files to remote attackers.
14. Multiple SSH Client Protocol Change Default Warning Weakness
BugTraq ID: 5284
Remote: Yes
Date Published: Jul 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5284
Summary:
A weakness has been reported in multiple SSH clients which may allow a
man-in-the-middle attack to occur. SSH servers commonly support
compatibility mode, which allows negotiation between the protocols SSH1
and SSH2 with a client when a connection is initiated.
SSH communication with a given server normally occurs using a given
protocol such as SSH2. A given client will record the server's public key.
If a new key is ever reported, the client software will report to the end
user that the event should be viewed with extreme suspicion.
However, if the server negotiates an SSH connection with a protocol such
as SSH1 which has not previously been used with a given client, the
displayed message will only report that a new key is being presented. The
fact that the host is already associated with a specific key under a
different protocol is not mentioned. The end user can not be expected to
understand the security implications of this event.
This may allow a man-in-the-middle attack to pass undetected by the client
user.
A similar attack may be possible based on the SSH2 negotiation for a MAC
algorithm. In this case, choosing an unusual algorithm may again fail to
produce a warning on the client system, allowing a man-in-the-middle
attack.
15. SmartMax MailMax Popmax Buffer Overflow Vulnerability
BugTraq ID: 5285
Remote: Yes
Date Published: Jul 23 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5285
Summary:
Smartmax MailMax is an email server for Microsoft Windows operating
systems.
Reportedly, MailMax 4.8 is vulnerable to buffer overflow attacks against
its POP3 (Post Office Protocol 3) daemon, popmax. The vulnerability occurs
due to improper bounds checking of the 'USER' argument.
It is possible for an attacker to cause the buffer overflow condition in
popmax by submitting an overly large value for the 'USER' argument. This
will cause popmax to crash and execute attacker supplied code.
As popmax is an email server, it will typically run with SYSTEM
privileges. Total system compromise is possible.
16. Sun Fire Unauthorized Environmental Monitoring Subsystem Modification Vulnerability
BugTraq ID: 5288
Remote: No
Date Published: Jul 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5288
Summary:
Sun Fire products are general purpose server hardware platforms which can
be used for a variety of applications. Some Sun Fire systems include an
environmental monitoring subsystem which provides feedback on the device.
A vulnerability has been reported in some Sun Fire models. It may be
possible for a malicious local user to issue commands to the environmental
monitoring system. An attacker may be able to leverage this ability to
create a denial of service condition where the system is no longer
available. Reportedly, this vulnerability may be exploited by an
unprivileged local user.
This vulnerability has been reported in Sun Fire 280R, V880, and V480
systems used with Solaris 8. Reportedly, Solaris 9 does not suffer from
this issue.
17. SecureCRT SSH1 Identifier String Buffer Overflow Vulnerability
BugTraq ID: 5287
Remote: Yes
Date Published: Jul 23 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5287
Summary:
SecureCRT is a commercial SSH client for Microsoft Windows operating
systems.
The SecureCRT client is prone to a buffer overflow condition when
attempting to handle an overly long SSH1 protocol identifier string. The
vulnerability is apparently due to insufficient bounds checking in the
error-handling code when the client processes the SSH1 protocol identifier
string. This issue reportedly may allow a malicious server to cause
memory corruption on the client system, potentially overwriting stack
variables with attacker-supplied data.
Exploitation of this issue may allow an attacker to execute arbitrary code
or may cause the client to crash.
This issue was reported in versions 3.4.x and 4.0 beta. SecurityFocus
analysis has determined that this issue may not be present in earlier
versions.
18. Multiple Vendor Web Browser JavaScript Modifier Keypress Event Subversion Vulnerability
BugTraq ID: 5290
Remote: Yes
Date Published: Jul 23 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5290
Summary:
An issue has been reported with the JavaScript implementation of multiple
web browsers, including Microsoft Internet Explorer and Opera. Malicious
JavaScript may subvert some keypress events, with consequences including
the disclosure of arbitrary local files to a remote server.
Through JavaScript, it is possible to define an event handler for the
'onkeydown' event, which fires when a key is pressed by the end user. It
is possible to have this event recognize the usage of the 'Control'
modifier key.
When this condition occurs, malicious script code may modify the event
property indicating which primary key has been pressed. By changing this
key to 'V', it is possible to create the 'Ctrl-V' key combination,
normally associated with the paste operation.
As the script also has control over the clipboard contents for the page,
and the document element with current focus, it is possible to further
subvert the event and place arbitrary content in an HTML form element. In
particular, an arbitrary local filename may be pasted into a file upload
form field.
If the form is then submitted through JavaScript, the attacker specified
file will be uploaded to the specified server without further user
interaction.
Exploitation of this vulnerability may result in the disclosure of
sensitive information to a remote attacker.
It may also be possible to discover the full path of the temporary file
directory used by Internet Explorer, by downloading the file
'..\LOCALS~1\TEMPOR~1\CONTENT.IE5\index.dat'. In this case, the
information may be used in conjunction with the issues discussed in BID
3867 to execute arbitrary code as the vulnerable user.
Other attacks based on script interaction with the cut and paste
functionality of Windows may also be possible.
It has been reported that it is also possible to recognize and subvert
keypress events based on the 'Shift' key. In particular, Shift-Ins is a
common keyboard shortcut for the paste operation. This may simplify the
social engineering aspect of this vulnerability by exploiting a more
commonly used key. It is likely that modifiers such as 'Alt' may also be
intercepted.
It has been reported that the Opera Web Browser 6.0.1 is also vulnerable
to this issue. It is possible that other versions of Opera share this
vulnerability, this has not however been confirmed.
19. DansGuardian Hex Encoding URL Content Filter Bypass Vulnerability
BugTraq ID: 5291
Remote: Yes
Date Published: Jul 23 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5291
Summary:
DansGuardian is a web content filter based on the Squid HTTP proxy server.
It is available for various Unix based operating systems, including Linux.
A vulnerability in DansGuardian may allow malicious users to bypass some
filter rules. URLs which contain hex encoded characers are not processed
before the URL is checked against patterns. A user may specify a URL
including several such characters in an attempt to bypass restrictions
impossed by DansGuardian.
Under some installations, this may violate security policy, or allow users
to inadvertantly access malicious web content.
20. Zyxel Prestige 642R Router Malformed TCP Packet Denial Of Service Vulnerability
BugTraq ID: 5292
Remote: Yes
Date Published: Jul 24 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5292
Summary:
ZyXEL 642R and Prestige 310 routers have difficulties handling TCP packets
that are malformed. Reportedly, when ZyXEL routers receive a single
specially malformed packet, they stop responding for exactly 30 seconds.
An attacker can take advantage of this vulnerability to cause ZyXEL
Prestige 642R routers to stop responding. An attacker sending specially
malformed packets every 30 seconds is able to prevent the ZyXEL router
from responding indefinitely thus causing a denial of service.
ZyXEL 642R and Prestige 310 routers are reportedly affected by this
vulnerability. It is possible that other ZyNOS-based routers are also
affected by this vulnerability
21. Mozilla JavaScript URL Host Spoofing Arbitrary Cookie Access Vulnerability
BugTraq ID: 5293
Remote: Yes
Date Published: Jul 24 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5293
Summary:
Mozilla is an open source web browser available for a number of platforms,
including Microsoft Windows and Linux. An issue has been reported in the
Mozilla web browser which may allow script code to access cookie data
associated with arbitrary domains.
Mozilla supports javascript: URLs, which can be used to execute JavaScript
functions directly. Normally the domain of such functions is restricted,
and cookie data associated with other sites may not be accessed.
It has been reported possible to create a javascript: URL which appears to
start with a valid domain. Malicious script code may specify an arbitrary
domain, and will be able to access cookie data associated with that
domain.
It is possible to exploit this vulnerability by creating a javascript: URL
which starts with a javascript comment of the form '//host\n', followed by
arbitrary script code. Other avenues of exploitation may, however, be
possible.
Exploitation of this vulnerability may result in a remote attacker gaining
access to sensitive cookie data, including authentication credentials.
22. VMWare GSX Server Authentication Server Buffer Overflow Vulnerability
BugTraq ID: 5294
Remote: Yes
Date Published: Jul 24 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5294
Summary:
VMWare GSX Server is virtualization software that allows for multiple
virtual servers to run on a single host.
GSX Server ships with an authentication server. The server implements
checks to ensure that client-supplied strings do not cause overflow
conditions. This is allegedly done by checking the length of supplied
strings against internally specified maximum-length values before using
them in sensitive operations.
It has been reported that an error exists in the implementation of this
mechanism for the argument to the "GLOBAL" command. The internal maximum
length value is greater than the size of the buffer allocated to store the
value. As a result, attackers may cause an overflow condition without
exceeding the maximum-length value and causing an error.
It is believed that the "GLOBAL" command can only be executed after
authentication. This may prevent attackers without valid credentials from
exploiting this vulnerability; however this is unconfirmed. It is not
known if there are any default or guest accounts.
This condition may be exploited to execute arbitrary code on the GSX
server host. The code likely executes on the underlying, native system
and may compromise the host entirely (including all virtual systems).
III. SECURITYFOCUS NEWS AND COMMENTARY
--------------------------------------
1. Find a Bug? Don't E-Mail Microsoft
By Brian McWilliams
It may be the most-used vendor bug reporting address in history. This week
Redmond put "[email protected]" out to pasture in favor of a handy Web
form.
http://online.securityfocus.com/news/545
2. GAO: U.S. Cyber Security Efforts are Uncoordinated
By Kevin Poulsen
Congressional investigators uncover a rat's nest of 50 federal
organizations overseeing the nation's cyber security, which still suffers.
http://online.securityfocus.com/news/542
3. Big software pushes hard for national Gestapo
By Thomas C. Greene, The Register
I was puzzled last month when industry lobby the Business Software
Alliance (BSA) released a cyberterror FUD bomb. Or, rather, a FUD dud -- a
laughably meaningless survey of the opinions of so-called "IT pros" all
laboring under the delusion that a deadly national catastrophe by
electronic means is just around the corner.
http://online.securityfocus.com/news/551
4. Congress blasts Feds on cyber-terror FOIA games
By Thomas C. Greene, The Register
There was a fabulous explosion Wednesday during an otherwise typical
cyberterror dog-and-pony show on the Hill when House Government Reform
Subcommittee Ranking Member Jan Schakowsky (Democrat, Illinois) lost her
composure during a discussion of new Freedom of Information Act (FOIA)
modifications proposed by the GB Junior Administration as part of its
Homeland Defense initiative.
http://online.securityfocus.com/news/550
IV.SECURITYFOCUS TOP 6 TOOLS
----------------------------
1. Pachyderm-fw v0.91
by Pachyderm Firewall Management Software
Relevant URL:
http://pachyderm-fw.sourceforge.net
Platforms: Linux
Sumnmary:
Pachyderm is graphical firewall management software for ipchains. It is
based on MySQL and PHP, easy to use, and has lots of configuration
abilities.
2. Mixmaster v2.9b33
by Mixmaster Developers [email protected]
Relevant URL:
http://freshmeat.net/projects/mixmaster/?topic_id=28%2C87%2C44
Platforms: UNIX
Summary:
Mixmaster is an anonymous remailer. Remailers provide protection against
traffic analysis and allow sending email mail anonymously or
pseudonymously. Mixmaster consists of both client and server
installations.
3. Maillog View v1.02.6
by Angelo 'Archie' Amoruso
Relevant URL:
http://cdrecwebmin.sf.net/
Platforms: Linux
Summary:
Maillog View is a Webmin module that allows you to easily view all your
/var/log/maillog.* files. It features autorefresh, message size
indication, ascending/descending view order, compressed file support, and
a full statistics page. Sendmail, Postfix, and Exim are supported
4. echolot-pinger v 2.0beta18
by Peter Palfrader [email protected]
Relevant URL:
http://www.palfrader.org/echolot/
Platforms: Os Independent
Summary:
Echolot-pinger is a pinger for anonymous remailers, which works by
regularly sending messages through remailers to check their reliability.
It then calculates reliability statistics which are used by remailer
clients to choose the chain of remailers to use. Additionally, it collects
configuration parameters and the keys of all remailers, and offers them in
a format readable by remailer clients.
5. Linux Firewall v2.0rc2
by Scott Bartlett
Relevant URL:
http://projectfiles.com/firewall/
Platforms: Linux
Summary:
Projectfiles.com Linux Firewall is a robust, well-designed firewall for
Linux 2.4 based on netfilter/iptables. It supports advanced features for
both servers and routers such as port forwarding and connection logging.
It has verbose success and failure messages, and is easy to install and
configure.
6. Mailcrypt v3.5.7
by Brian Warner
Relevant URL:
http://mailcrypt.sourceforge.net/
Platforms: N/A
Summary:
Mailcrypt is an Emacs Lisp package which provides a simple interface to
public key cryptography with PGP/GPG. Mailcrypt makes strong cryptography
a fully integrated part of your normal mail and news handling environment.
V. SECURITY JOBS SUMMARY
------------------------
1. resume of an ethical hacker (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/284323
2. Wireless Security Engineer Position in Washington DC (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/284328
3. Security Engineer Positions in Washington DC (Cryptographic Modules & PKI) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/284327
4. C++ Engineer (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/284326
5. Internship/Coop Candidate. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/284325
6. Security Analyst Position with Bristol-Myers Squibb (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/284322
7. Seeking infosec engineering position(FullTime/PartTime) in Northern VA, DC, MD (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/284321
8. Jr. Sales Executives - East Coast (South Florida) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/284320
9. Seeking a career in IT security in Singapore,Asia pacific[GSEC,CC NP,CCNA,B.A.Sc(Comp Eng)] (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283982
10. Security Positions in Mississippi (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283877
11. *UPDATE* Network Engineer - Secure Systems (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283874
12. Experienced Wireless Security Architect position (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283853
13. Senior Project Manager (Security) - NYC (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283852
14. Security Auditor Position in NY City (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283774
15. Seeking Network Security Job in Germany (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283778
16. INSIDE SALES TOP PERFORMER (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283776
17. Looking for someone with DEC VAX/VMS Security experience (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283781
18. Opportunity for an Information Security Engineer in Reston or Crystal City, VA (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283674
19. Network Security/Information Assurance positions (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283670
20. Willing to relocate for a position (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283470
21. Unix/Net/Sec Engineer with CISSP,CCNA,MCSE Seeking position in NY/NJ/DC (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283469
22. Network Engineer - Secure Systems (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283349
23. Director of Quality Assurance for Qualys (Network Security) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283350
24. Red team for hire (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283296
25. Network Security Positions (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283273
26. Experienced Security Manager in NYC area seeking opportunity (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283231
27. Information Security/Assurance Opportunity in Northern VA (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283215
28. WireX Immunix Adversary, DefCon Games (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283217
29. Job for a CISSP, Chartered Accountant, ISA, Grad CWA - 20 years experience... Taken CISA exam (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/283216
VI. INCIDENTS LIST SUMMARY
-------------------------
1. Surge of attacks on ports 61127 & 61134 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/284313
2. Anyone know this rootkit (rootkits?) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/284287
3. Bind 9.2.X exploit??? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/284289
4. FireDaemon exploit - part 2 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/284258
5. Increasing compromises of NT servers with Serv-U and Unicode ? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/284233
6. Dead Thread: China Experience? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/284054
7. China Experience ? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/284083
8. Re: China Experience ? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/284077
9. Scanning Port UDP 4668 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/283841
10. Unicode exploits with Serv-U (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/283787
11. diagnose compromise on NT (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/283641
12. Odd scan (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/283589
13. Can anyone identify this backdoor? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/283582
14. FireDeamon exploit (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/283317
15. TCP 1025 scanning worm? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/283228
VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. SQL Server 2000 Buffer Overflows and SQL Inyection vulnerabilities. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/284385
2. Does MSN Messenger Bypass Group Policy? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/284281
3. UPDATE: Re: REFRESH: EUDORA MAIL 5.1.1 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/284265
4. REFRESH: EUDORA MAIL 5.1.1 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/284259
5. confixx (remote access) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/284267
6. More Buffer Overphlow Questions (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/284182
7. Denial of Service bug in Pine 4.44 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/284146
8. Nanog traceroute format string exploit. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/284091
9. bash 2.05.0(1)-release/it.map.gz Slackware 8.0 default and Debian (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/283887
10. cached logon credentials (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/283836
11. Arcserve (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/283821
12. Vulnerability found: Adobe Acrobat eBook Reader and Content Server (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/283819
13. SSH Protocol Trick (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/283816
14. PHRACK 59 OFFICIAL RELEASE (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/283820
15. XSS at www.internic.com (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/283724
16. Announcement: injectso-0.2 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/283708
17. SPIKE Proxy 1.1 Released (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/283657
18. Dave Barry on network security policies (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/283651
19. ass the attack spoofing shell (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/283594
20. Bind recursive queries quota. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/283563
21. Lindows Issues (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/283474
22. WireX Immunix Adversary, DefCon (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/283420
23. Smashing the Stack? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/283417
24. Linux kernel setgid implementation flaw (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/283312
25. [VulnWatch] wp-02-0001: GoAhead Web Server Directory Traversal + Cross Site Scripting (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/283237
26. Assembler/C References (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/283234
27. PHP : eval() ? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/283164
VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. need help with ActiveX remote counters (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/284316
2. Exporting GPOs from Active Directory (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/284057
3. Securing IIS Using, MS Security Tool Kit & Scripting (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/283838
4. Problems with IIS and Certification Services (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/283825
5. SecurityFocus Microsoft Newsletter #96 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/283629
6. Make all directories reinherrit ACLs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/283614
7. write permissions for IIS (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/283559
8. Terminal Services Auditing not working (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/283323
9. local security policy (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/283321
10. Need security proposal for Win2K upgrade... (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/283269
IX. SUN FOCUS LIST SUMMARY
----------------------------
1. tty sniffer. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/284120
2. Jass + Solaris9 + Fixmodes (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/284119
3. Summary: Proving OpenSSH 3.4p1 is using /dev/urandom (Solaris 9 ossh Vs OpenBSD ossh) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/283876
4. Proving OpenSSH 3.4p1 is using /dev/urandom (Solaris 9 ossh Vs OpenBSD ossh) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/283704
X. LINUX FOCUS LIST SUMMARY
---------------------------
1. Security by hiding processes (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/283872
XI. SPONSOR INFORMATION
-----------------------
This Issue is sponsored by: Stratum8 Networks, Inc.
Free Webinar: Securing Web Servers Today - Featuring Hurwitz Group. Web
servers and Web-based applications are the single most commonly exploited
technologies in corporate security breaches today. Learn how to
permanently secure these dangerous security holes in a free one hour
webinar featuring Hurwitz Group and sponsored by Stratum8 Networks.
Find out more about this educational opportunity now by visiting us at:
http://www.stratum8.com/news_events/webinars/hurwitz8.shtml
-------------------------------------------------------------------------------