SecurityFocus Newsletter #156

John Boletta <[email protected]> Mon, 5 Aug 2002 09:36:48 -0600 (MDT)
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #156
-----------------------------

This Newsletter is Sponsored by: Qualys

Bulletproof Your Network: FREE Guide

Existing security products -- firewalls, anti-virus and IDS -- are simply
no longer enough to ensure your networks are safe against sophisticated
attacks and worms such as Code Red and Nimda. FREE Guide shows you how to
ensure TOTAL security for your network. Get it now.

Visit us at: https://www.qualys.com/forms/guide_220.php

-------------------------------------------------------------------------------

I. FRONT AND CENTER
     1. Advanced Log Processing
     2. Assessing Internet Security Risk, Part Three: an Internet...
     3. Copyright, Security, and the Hollywood Hacking Bill
     4. The Right to Defend
     5. SecurityFocus DPP Program
II. BUGTRAQ SUMMARY
     1. T. Hauck Jana Server SOCKS5 Proxy Server Authentication Buffer...
     2. T. Hauck Jana Server POP3 Gateway Server Response Buffer...
     3. IPSwitch IMail Web Messaging HTTP Get Buffer Overflow...
     4. T. Hauck Jana Server SMTP Gateway Server Response Buffer...
     5. T. Hauck Jana Server FTP Server PASV Mode Port Exhaustion...
     6. T. Hauck Jana Server POP3 Gateway Username Enumeration...
     7. T. Hauck Jana Server POP3 Invalid Message Index Denial Of...
     8. Cisco IOS TFTP Server Long File Name Buffer Overflow Vulnerability
     9. SEH IC9 Pocket Print Server Web Administrative Interface...
     10. D-Link Print Server Long Post Request Denial Of Service...
     11. HP JetDirect Printers SNMP Get Administrative Password...
     12. HP ChaiVM ChaiServer Arbitrary Service Modification Vulnerability
     13. HP ChaiVM EZLoader Arbitrary JAR Loading Vulnerability
     14. Lucent Brick Spoofed Address Communication Denial Of Service...
     15. Lucent Brick ARP Traffic Forwarding Vulnerability
     16. Lucent Access Point IP Services Router Long HTTP Request...
     17. Multiple Lucent Router UDP Port 9 Information Disclosure...
     18. HP ProCurve Switch SNMP Write Denial Of Service Vulnerability
     19. Brother NC-3100H Denial Of Service Vulnerability
     20. Ben Chivers Easy Homepage Creator File Modification Vulnerability
     21. Ben Chivers Easy Guestbook Administrative Access Vulnerability
     22. phpBB2 Gender Mod Remote SQL Injection Vulnerability
     23. Util-linux File Locking Race Condition Vulnerability
     24. Multiple Browser Vendor Same Origin Policy Design Error...
     25. Abyss Web Server HTTP GET Request Directory Contents...
     26. DotProject User Cookie Authentication Bypass Vulnerability
     27. Hylafax Incoming TSI Format String Denial Of Service...
     28. Hylafax Oversized Scan Line Remote Buffer Overflow Vulnerability
     29. Microsoft Outlook Express XML File Attachment Script Execution...
     30. Fake Identd Client Query Remote Buffer Overflow Vulnerability
     31. MM Shared Memory Library Temporary File Privilege Escalation...
     32. Multiple OpenSSL Remote Buffer Overflow Vulnerabilities
     33. Multiple Vendor BSD pppd Arbitrary File Permission...
     34. Multiple Vendor Sun RPC xdr_array Buffer Overflow Vulnerability
     35. ShoutBox Form Field HTML Injection Vulnerability
     36. Adobe eBook Reader File Transfer Authorization Voucher Weak...
     37. Microsoft Windows Media Player Filename Buffer Overflow...
     38. Microsoft Office XP/Internet Explorer OWC File Creation...
     39. Sympoll File Disclosure Vulnerability
     40. OpenSSL Kerberos Enabled SSLv3 Master Key Exchange Buffer...
     41. OpenSSL SSLv3 Session ID Buffer Overflow Vulnerability
     42. OpenSSL SSLv2 Malformed Client Key Remote Buffer Overflow...
     43. OpenSSL ASCII Representation Of Integers Buffer Overflow...
     44. OpenSSL ASN.1 Parsing Error Denial Of Service Vulnerability
     45. IPSwitch IMail Web Calendaring Incomplete Post Denial Of...
     46. William Deich Super SysLog Format String Vulnerability
     47. HP JetDirect Embedded Web Server Password Handling Vulnerability
     48. T. Hauck Jana Server HTTP Server Request Logging Buffer...
     49. T. Hauck Jana Server HTTP Proxy Server Request Logging Buffer...
III. SECURITYFOCUS NEWS ARTICLES
     1. When Dreamcasts Attack
     2. Wi-Fi Honeypots a New Hacker Trap
     3. OpenSSH trojaned!
     4. Multiple virus scanning needed, says multiple scanning firm
IV.SECURITYFOCUS TOP 6 TOOLS
     1. Snort Alert Monitor v2002-07-31
     2. IMAPScrape v0.1
     3. DansGuardian Anti-Virus Scanner v1.0rc1
     4. ACiD alpha
     5. tcptraceroute v1.4
     6. FCheck 2.07.59
V. SECURITYJOBS LIST SUMMARY
     1. Software Engineer - Anti-Virus Research (Thread)
     2. Computer and Network Security Officer Job Vacancy (Thread)
     3. (2) Information Security Scientist roles for Risk Assessments...
     4. Looking for a Job. (Thread)
     5. Information Security Architect (Thread)
     6. Info Security Opportunity - Northbrook, IL (Thread)
     7. Security System Engineers in the MA/Cambridge Area needed...
     8. Exciting opportunity for a Crypto-Analyst or a...
     9. Seeking permanent work in IL (Thread)
     10. Fwd: Seeking full time or contract work in NH/MA (Thread)
     11. Cleared Information Assurance Professional wanted in Annapolis...
     12. Seeking full time or contract work in NH/MA (Thread)
     13. CISSP in Duluth, MN (Thread)
     14. Network Security Manager Position in Florida (Thread)
     15. PKI Position in Washington DC (Thread)
     16. SAP/CSS Security Professional Needed (Thread)
     17. Wanted: Security Job in Switzerland (Thread)
     18. Infrastructure Security Director (Thread)
     19. Security jobs in the UK (Thread)
     20. Security Consultants positions in New Jersey (Thread)
     21. 2 positions in Rosslyn, VA (Thread)
     22. Seeking SalesMgnt/Business Development Position E/SE/S FL...
     23. Senior Sales Executives - East Coast (South Florida) (Thread)
VI. INCIDENTS LIST SUMMARY
     1. Anyone know this rootkit (rootkits?) (Thread)
     2. Rating Attackers (Thread)
     3. Trojan located in latest openssh tar files (Thread)
     4. openssh-3.4p1.tar.gz trojaned (Thread)
     5. scanning for HTTP proxies, ports 80, 81, 1080, 3128, 4480, 6588...
     6. Packet suckers? (Thread)
     7. scanning for HTTP proxies, ports 80, 81, 1080, 3128, 4480...
     8. observations on recent unicode attacks against IIS servers...
     9. Compromized Windows NT machine? (Thread)
     10. Anyone know this rootkit (rootkits?)  (details and files...
     11. Anyone know this rootkit (rootkits?)  (details and...
     12. Bind 9.2.X exploit??? (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. Comment on DMCA, Security, and Vuln Reporting] (Thread)
     2. Weird WinME Login Bug (Thread)
     3. ssh trojaned (Thread)
     4. It takes two to tango (Thread)
     5. [Full-Disclosure] RE: It takes two to tango (Thread)
     6. Actuate Server CSS Vulnerability (Thread)
     7. Comment on DMCA, Security, and Vuln Reporting (Thread)
     8. Formal Response to HP (Thread)
     9. WHERE'S THE CA$H: Internet Explorer 6.00. Outlook Express 6.00...
     10. Possible cable modem denial of service ? (Thread)
     11. Terminal Service - Denial of Service (Thread)
     12. Directory traversal vulnerability in sendform.cgi (Thread)
     13. Administrivia #14344 (Vegas, woo hoo!) (Thread)
     14. Does MSN Messenger Bypass Group Policy? (Thread)
     15. Operation TIPS - the FEMA response (Thread)
     16. MS Terminal Service problem (Thread)
     17. Vulnerability: protected Adobe eBooks can be copied between...
     18. php-4.0.6 vulnerability (Thread)
     19. Re[2]: Possible cable modem denial of service ? (Thread)
     20. removal of /tmp/appXXXXXX (Thread)
     21. Malicious COM Surrogates (Thread)
     22. is any one sniffing comports on win2k or XP? (Thread)
     23. Perl 5.6.0 (on Linux) getpwuid() leave /etc/shadow opened...
     24. nmapwin  Scan 10.10.10.*  after you install it and start the...
     25. nmapwin  Scan 10.10.10.*  after you install it and start the...
     26. Phenoelit Advisory, 0815 ++ * - Cisco_tftp (Thread)
     27. Phenoelit Advisory  #0815 +-+ (Thread)
     28. Phenoelit Advisory 0815 ++ /+ HP ProCurve (Thread)
     29. Phenoelit Advisory #0815 +-- (Thread)
     30. Phenoelit Advisory 0815 ++ -- Brick (Thread)
     31. Phenoelit Advisory 0815 ++ // Xedia (Thread)
     32. Phenoelit ADvisory 0815 ++ ** Ascend (Thread)
     33. Phenoelit Advisory  #0815 ++-+ dp_300 (DLINK) (Thread)
     34. 0815 ++ */ SEH_Web (Thread)
     35. Phenoelit Advisory, 0815 ++ /- Brother_NC (Thread)
     36. Announcement: injectso-0.2 (Thread)
     37. winmessenger help (Thread)
     38. [Full-Disclosure] Re: UPDATE: Re: REFRESH: EUDORA MAIL 5.1.1...
     39. UPDATE: Re: REFRESH: EUDORA MAIL 5.1.1 (Thread)
     40. REFRESH: EUDORA MAIL 5.1.1 (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. Linux firewall/ISA Server (Thread)
     2. windows update reporting info back to MS? (and .NET fw SP1)...
     3. Windows 2000 special folder restrictions (Thread)
     4. W2000 Server lockout issue (Thread)
     5. local admin passwords (Thread)
     6. Flush.exe & Flushserv.exe (Thread)
     7. FW: secure remote management of nt4 and w2k servers (Thread)
     8. Good software against spam (Thread)
     9. IIS SMTP queue reader (Thread)
     10. Update Expert (Thread)
     11. HFNETCHKpro (Thread)
     12. change the nt-password in a other domain (Thread)
     13. HFNETCHKpro? (Thread)
     14. Auditing ACL Changes (Thread)
     15. restricting MMC with GPO for SQL Enterprise Manager (Thread)
     16. Laptop Encryption (Thread)
     17. AW: hfnetchk reporting (Thread)
     18. Securing Laptops (Thread)
     19. Registry key for "QueryIpMatching" (Thread)
     20. Setting Account Lockout Policies with a NT PDC (Thread)
     21. hfnetchk reporting (Thread)
     22. Anyone know this scan/tool? (Thread)
     23. FW: Anyone know this scan/tool? (Thread)
     24. Fw: Setting Account Lockout Policies with a NT PDC (Thread)
     25. Issues/Concerns with Exchange 2000 SP3 (Thread)
IX. SUN FOCUS LIST SUMMARY
     1. Solaris and lack of loopback routes (Thread)
     2. Administrivia: Gone Fishin' (Thread)
     3. Solaris 8 username contingency (Thread)
X. LINUX FOCUS LIST SUMMARY
     1. LDAP Auth? (Thread)
     2. LDAP auth (Thread)
     3. Administrivia: Gone Fishin' (Thread)
     4. Security by hiding processes (Thread)
XI. SPONSOR INFORMATION




I. FRONT AND CENTER
-------------------
1. Advanced Log Processing
By Anton Chuvakin

Reading logs is a crucial part of incident detection and response.
However, it is easy for security personnel to be overwhelmed by the sheer
volume of logs. This article will offer a brief overview of log analysis,
particularly: log transmission, log collection and log analysis. It will
also briefly touch upon log storing and archival.

http://online.securityfocus.com/infocus/1613

2.  Assessing Internet Security Risk, Part Three: an Internet Assessment
Methodology Continued
by Charl van der Walt

This article is the third in a series that is designed to help readers to
assess the risk that their Internet-connected systems are exposed to. In
the first installment, we established the reasons for doing a technical
risk assessment. In the second part, we started to discuss the methodology
that we follow in performing this kind of assessment. In this installment,
we will continue to discuss methodology, particularly visibility and
vulnerability scanning.

http://online.securityfocus.com/infocus/1612

3. Copyright, Security, and the Hollywood Hacking Bill
By Richard Forno

Proposed copyright enforcement legislation may allow the powerful
entertainment lobby to circumvent fundamental constitutional protections,
and may create chaos on the Internet.

http://online.securityfocus.com/columnists/99

4. The Right to Defend
By Tim Mullen Jul 29, 2002

When it comes to matters of security, most policies are hastily enacted as
a reaction to some pressing force or foe. This is evident when you look at
the rash of laws, procedures and policies put in place since September 11.
I guess it is only natural-- our fragile human psyche requires immediate
comfort in the face of danger; our fears only resting when we know
something is being done, even if that "something" equates to nothing at
all.

http://online.securityfocus.com/columnists/98

5. SecurityFocus DPP Program

Attention Non-profit Organizations and Universities!!
Sign-up now for preferred pricing on the only global early-warning system
for cyber attacks - SecurityFocus DeepSight Threat Management System.

Click here for more information:
http://www.securityfocus.com/corporate/products/dpsection.shtml


II. BUGTRAQ SUMMARY
-------------------
1. T. Hauck Jana Server SOCKS5 Proxy Server Authentication Buffer Overflow Vulnerability
BugTraq ID: 5321
Remote: Yes
Date Published: Jul 26 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5321
Summary:

Jana Server is a server for Microsoft Windows based systems. Jana Server
provides a wide range of proxy servers, and a number of other services. A
SOCKS5 proxy server is included.

A buffer overflow vulnerability has been reported in the SOCKS5 proxy
server. Reportedly, when authenticating a client, a username, password or
hostnamed longer than 127 characters may cause an error. This may be due
to the incorrect usage of a signed value as an array index.

Due to the nature of this vulnerability, it may be possible for a remote
attacker to execute arbitrary code as the server process. Reportedly, Jana
Server runs with SYSTEM privileges on Windows NT systems. The ability to
execute arbitrary code has not yet been confirmed.

2. T. Hauck Jana Server POP3 Gateway Server Response Buffer Overflow Vulnerability
BugTraq ID: 5322
Remote: No
Date Published: Jul 26 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5322
Summary:

Jana Server is a server for Microsoft Windows based systems. Jana Server
provides a wide range of proxy servers, and a number of other services. A
POP3 gateway service is provided.

A buffer overflow vulnerability has been reported in the POP3 gateway
service. A malicious server may return an oversized reply to Jana Server.
This may result in the corruption of process memory, and the vulnerable
server crashing.

It has been reported possible to exploit this condition by returning an
oversized argument to the '+OK' response.

Due to the nature of this vulnerability, it may be possible for a remote
attacker to execute arbitrary code as the server process. Reportedly, Jana
Server runs with SYSTEM privileges on Windows NT systems. The ability to
execute arbitrary code has not yet been confirmed.

3. IPSwitch IMail Web Messaging HTTP Get Buffer Overflow Vulnerability
BugTraq ID: 5323
Remote: Yes
Date Published: Jul 26 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5323
Summary:

IMail is a commercial email server software package distributed and
maintained by Ipswitch, Incorporated.  IMail is available for Microsoft
Operating Systems.

A problem with IMail could make it possible for a user to potentially
execute code on a vulnerable server.

IMail includes a web server as part of the features package.  The web
server included with IMail provides users with an interface to perform Web
Messaging.  The web messaging interface by default runs on port 8383/TCP.

The web messaging server is vulnerable to a buffer overflow.  When the
server receives a request for HTTP version 1.0, and the total request is
96 bytes or greater, a buffer overflow occurs.  This could result in the
execution of attacker-supplied instructions, and potentially allow an
attacker to gain local access.

** Ipswitch has reported they are unable to reproduce this issue. In
addition, Ipswitch has stated that the supplied, third party patch may in
fact open additional vulnerabilities in the product. Ipswitch suggests
that users do not apply the supplied patch. If the patch has been applied,
users are advised to disable the service and investigate the system for
signs of compromise.

4. T. Hauck Jana Server SMTP Gateway Server Response Buffer Overflow Vulnerability
BugTraq ID: 5324
Remote: Yes
Date Published: Jul 26 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5324
Summary:

Jana Server is a server for Microsoft Windows based systems. Jana Server
provides a wide range of proxy servers, and a number of other services. A
SMTP gateway service is provided.

A buffer overflow vulnerability has been reported in the SMTP gateway
service. A malicious server may return an oversized reply to Jana Server.
This may result in the corruption of process memory, and the vulnerable
server crashing.

Due to the nature of this vulnerability, it may be possible for a remote
attacker to execute arbitrary code as the server process. Reportedly, Jana
Server runs with SYSTEM privileges on Windows NT systems. The ability to
execute arbitrary code has not yet been confirmed.

5. T. Hauck Jana Server FTP Server PASV Mode Port Exhaustion Denial Of Service Vulnerability
BugTraq ID: 5325
Remote: Yes
Date Published: Jul 26 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5325
Summary:

Jana Server is a server for Microsoft Windows based systems. Jana Server
provides a wide range of proxy servers, and a number of other services,
including a FTP server.

A design error exists in the FTP server included with Jana Server that may
allow an authenticated remote user to create a denial of service
condition. When the FTP PASV command is used, the FTP server will open a
TCP connection on a new port. Reportedly, this connection does not time
out, and will remain open indefinitely. A malicious user may make a number
of PASV requests and exhaust all TCP ports on the vulnerable system,
creating a system wide denial of service condition.

6. T. Hauck Jana Server POP3 Gateway Username Enumeration Vulnerability
BugTraq ID: 5326
Remote: Yes
Date Published: Jul 26 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5326
Summary:

Jana Server is a server for Microsoft Windows based systems. Jana Server
provides a wide range of proxy servers, and a number of other services. A
POP3 gateway service is provided.

An error has been reported in the POP3 gateway server included with Jana
Server. It is a widely accepted security practice that authentication
error messages do not distinguish between the case where an invalid
username is submitted, and that where an invalid password is submitted.
This prevents a malicious party from determining if they have acquired or
guessed a valid system username.

Jana Server does not obey this property in authentication, which takes
place through the POP3 gateway. Exploitation of this vulnerability may aid
an attacker in gathering information about the system or internal network.

Reportedly, the POP3 gateway also allows an unlimited number of password
attempts. This may allow a brute force password attack against a verified
username.

7. T. Hauck Jana Server POP3 Invalid Message Index Denial Of Service Vulnerability
BugTraq ID: 5327
Remote: Yes
Date Published: Jul 26 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5327
Summary:

Jana Server is a server for Microsoft Windows based systems. Jana Server
provides a wide range of proxy servers, and a number of other services. A
POP3 mail server is included.

Reportedly, Jana Server does not properly validate POP3 message index
values received from the client. A malicious user may specify a large,
invalid message index. The server will attempt to access this message and
crash due to a memory error.

POP3 commands of the following form are sufficient to exploit this issue:

RETR 1000000 or DELE 1000000

Exploitation of this vulnerability may result in a denial of service
condition for other users of the server. A restart may be required in
order to regain normal functionality.

8. Cisco IOS TFTP Server Long File Name Buffer Overflow Vulnerability
BugTraq ID: 5328
Remote: Yes
Date Published: Jul 27 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5328
Summary:

A problem has been discovered in Cisco IOS that could result in a denial
of service, and potential code execution.

It has been discovered that the TFTP server file name handling of Cisco
IOS is vulnerable to a buffer overflow.  This overflow is the result of
insufficient bounds checking on file names requested from the TFTP server.
A request for a file name of 700 or more bytes will result a crash of the
router, and reboot of the device.

It is currently unknown whether this vulnerability could result in the
execution of arbitrary code.  In the event that this problem could be
exploited to execute code, it would be possible for an attacker to execute
arbitrary instructions on a vulnerable Cisco router with the privileges of
the TFTP server.

It should be noted that this vulnerability occurs only when a file is
being served via the Cisco TFTP server, the file is stored on a flash
device, and no alias has been assigned to the file.

Cisco IOS versions 12.0 and later are not prone to this issue.  Cisco has
assigned Cisco Bug ID CSCdy03429 to this vulnerability.

9. SEH IC9 Pocket Print Server Web Administrative Interface Password Denial Of Service Vulnerability
BugTraq ID: 5329
Remote: Yes
Date Published: Jul 27 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5329
Summary:

IC9 is the Pocket Print Server distributed by SEH.  It provides network
capability to parallel port printers.

A problem with the administration interface makes it possible to reboot a
pocket print server, and the attached printer.

SEH Pocket Print Servers provide a web administration interface.  This
interface can be reached via the network to which the printer is attached,
and allows users of the printer to change configuration parameters for the
device.

A user accessing the web administration interface of a vulnerable device
may be able to reboot the print server, and attached printer.  By sending
an administrative password of 300 or more bytes, it is possible for a
remote user to cause a crash in the print server.  This results in a
denial of service, as the print server and printer are unavailable during
the reboot process.

This vulnerability is likely due to a memory corruption bug, and may be an
exploitable buffer overflow.  If this is an exploitable buffer overflow,
it would be possible for a user to execute arbitrary instructions on the
server with the privileges of the web administration interface.

10. D-Link Print Server Long Post Request Denial Of Service Vulnerability
BugTraq ID: 5330
Remote: Yes
Date Published: Jul 27 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5330
Summary:

The DP-303 Print Server is a hardware device designed to allow the sharing
of printers over an ethernet connection.

A problem with the print server could make it possible for a remote user
to deny service to the administrative interface.

The DP-303 offers a web administration interface that can be accessed via
the attached network.  This interface allows the changing of print server
parameters.

It is possible to crash the web server that serves the administrative
interface.  Upon connecting to the server and sending an excessively long
HTTP POST request to a known configuration page, the web server becomes
unstable and crashes.  The web server will not function again until the
device is power-cycled.

This vulnerability is likely a memory corruption bug, and is potentially
an exploitable buffer overflow condition, though this possibility is
currently unverified.  In the event that this is an exploitable buffer
overflow, an attacker would be able to execute arbitrary instructions in
the security context of the administrative web server process.

11. HP JetDirect Printers SNMP Get Administrative Password Retrieval Vulnerability
BugTraq ID: 5331
Remote: Yes
Date Published: Jul 27 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5331
Summary:

JetDirect printers are network-enabled printers distributed by
Hewlett-Packard.

A problem with JetDirect printers could make it possible for a remote user
to gain administrative access to the printer.

It has been reported that HP JetDirect printers leak the telnet and HTTP
administrative password under some circumstances.  By sending an SNMP READ
request to a vulnerable printer, the printer will return the hex-encoded
password to the requester.  This could allow a remote user to access and
change configuration of the printer.

Upon sending a request for the string
.iso.3.6.1.4.1.11.2.3.9.4.2.1.3.9.1.1.0 via a public community string, the
printer returns a string of bytes.  It has been reported that the bytes
after the second byte are hex representation of the ASCII characters
comprising the administrative password.

12. HP ChaiVM ChaiServer Arbitrary Service Modification Vulnerability
BugTraq ID: 5332
Remote: No
Date Published: Jul 27 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5332
Summary:

ChaiVM is the Chai Virtual Machine.  The ChaiServer is a component of the
ChaiVM infrastructure.  It is distributed and maintained by
Hewlett-Packard.

A problem has been discovered in the Chai Virtual Machine that could allow
a user to change arbitrary services.

It has been reported that the ChaiVM does not sufficiently enforce access
control at the file system level.  A user with access to the file system
hosting a ChaiVM may be able to modify, add, and delete services hosted by
the ChaiServer running on the vulnerable appliance.  It has also been made
known that this vulnerability is especially present when files are
accessible on the device using Printer Job Language (PJL), a proprietary
communication language used by HP printers.

This problem could allow an unauthorized user to remove services from a
ChaiServer, and replace them with malicious versions of the originally
removed service.  In-depth technical details of this vulnerability are
currently unavailable.

The impact of this vulnerability is escalated when coupled with that
described in Bugtraq ID 5334.

13. HP ChaiVM EZLoader Arbitrary JAR Loading Vulnerability
BugTraq ID: 5334
Remote: No
Date Published: Jul 27 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5334
Summary:

ChaiVM is the Chai Virtual Machine.  The ChaiServer is a component of the
ChaiVM infrastructure.  It is distributed and maintained by
Hewlett-Packard.

A problem has been discovered in the Chai Virtual Machine that could allow
a user to load arbitrary services.

The EZLoader is an advanced loader distributed by HP.  It is designed to
make the loading of services via the ChaiServer more stream-lined and
user-friendly.  It replaces the previous default loader this.loader.

The EZLoader does not sufficiently validate JAR signatures of services
prior to loading them.  Because of this, a user with access to the local
system may be able to load unauthorized services of questionable origin
via the ChaiServer.  This could allow a user to remove a legitimate
service from the ChaiServer, and replace it with a malicious version of
the original service.

This problem, when coupled with that described in Bugtraq ID 5332, makes
it possible for users to circumvent the security model of the ChaiVM.

14. Lucent Brick Spoofed Address Communication Denial Of Service Vulnerability
BugTraq ID: 5337
Remote: Yes
Date Published: Jul 27 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5337
Summary:

Brick is the firewall and VPN management system distributed by Lucent.
It is a hardware/firmware solution.

A problem with Brick systems may make it possible for an attacker to
terminate communication with arbitrary systems.

It has been reported that Brick systems may be forced into terminating
communication with specific systems.  By binding the IP address of a
specific system to a different system and pinging the Brick with the
specified IP address, the Brick will update it's ARP cache.  Upon updating
the cache, the Brick terminates communication with the system legitimately
using the IP address.

This problem could be exploited to deny service to systems such as the
Lucent Security Management Server(LSMS), which provides remote
administration and logging of activity to Brick systems.  In exploiting
this vulnerability, an attacker would be able to launch an attack without
being reported to the LSMS system.  This vulnerability could be exploited
to deny communication to a system that is either outside of the network
filtered by the Brick, or one behind the Brick.

It should be noted that this problem is only present when the "Floating
MAC" option is enabled on the Brick. Lucent has reported that this option
is disabled by default.

15. Lucent Brick ARP Traffic Forwarding Vulnerability
BugTraq ID: 5338
Remote: Yes
Date Published: Jul 27 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5338
Summary:

Brick is the firewall and VPN management system distributed by Lucent.
It is a hardware/firmware solution.

A problem with the handling of some types of network traffic may make it
possible for an attacker to send illicit communications across a Brick
system.

It has been reported that Brick systems forward ARP traffic across
interfaces, regardless of any defined firewall rulesets.  This could allow
a system local to the Brick to send ARP traffic across interfaces, and
potentially deny service to other hosts local to the Brick system.

This vulnerability may also be used to hijack sessions, or perform
man-in-the-middle attacks against other systems by spoofing the ARP
entries of hosts local to the Brick system.  This could allow an attacker
to gain access to potentially sensitive information.

Lucent has reported that this behavior will not occur if the interfaces of
the Brick device are bound to different IP subnets.

16. Lucent Access Point IP Services Router Long HTTP Request Denial Of Service Vulnerability
BugTraq ID: 5333
Remote: Yes
Date Published: Jul 27 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5333
Summary:

The Lucent Access Point series of routers support a web based
administrative interface. An error has been reported in the embedded HTTP
server.

It has been reported that sending a HTTP request consisting of
approximately 4000 characters of data will cause the device to reboot.
This may result in an interruption of service for legitimate users of the
device.  Repeated exploitation may create a long term denial of service
condition.

This problem is likely a memory corruption bug, and may be an exploitable
buffer overflow.  In the event that this is an exploitable buffer
overflow, it would be possible for an attacker to execute arbitrary code
in the security context of the web server process.

17. Multiple Lucent Router UDP Port 9 Information Disclosure Vulnerability
BugTraq ID: 5335
Remote: Yes
Date Published: Jul 27 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5335
Summary:

Several Lucent Router product lines include support for a configuration
tool which communicates over UDP on port 9.

If a specially crafted packet is sent to some of these devices on UDP port
9, a response is issued which contains sensitive information. Reportedly,
the host name, MAC, IP address, serial number, device type and some
information on installed features are returned.

An attacker able to communicate with the vulnerable device may take
advantage of this feature in order to gather intelligence about the
router. This information may be of aid in further attacks against the
network or device.

It may also be possible to use this protocol to configure some elements of
the device, if the SNMP write community is known. Further details are not
currently available.

18. HP ProCurve Switch SNMP Write Denial Of Service Vulnerability
BugTraq ID: 5336
Remote: Yes
Date Published: Jul 27 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5336
Summary:

An issue has been reported with the HP ProCurve 4000M Switch.

An attacker with SNMP write access to the device may write to the SNMP
variable .iso.3.6.1.4.1.11.2.36.1.1.2.1.0. If more than 85 characters are
written to this variable, the device will crash the next time it accepts a
connection to either the configured telnet or HTTP port.

Exploitation of this vulnerability may allow an attacker to deny service
to legitimate users of the device.

This problem may be the result of a memory corruption bug, and may be an
exploitable buffer overflow.  In the event that this is an exploitable
buffer overflow, it would be possible for an attacker to execute arbitrary
code on the vulnerable device.

This vulnerability may be related to issues described in BIDs 4088 and
4089. This has not, however, been confirmed.

19. Brother NC-3100H Denial Of Service Vulnerability
BugTraq ID: 5339
Remote: Yes
Date Published: Jul 29 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5339
Summary:

Brother produces various devices for the office environment including
printers.

A vulnerability has been reported for Brother NC-3100h printers.
Reportedly, it is possible to cause NC-3100h printers to crash when using
the web interface.

The vulnerability is reportedly the result of a buffer overflow condition.
If an attacker submits an overly long administrative password, via the web
interface, it is possible to cause NC-3100h printer to stop responding. A
restart may be required in order to regain normal functionality.

The attacker needs to submit an administrative password consisting of 136
or more characters. This will cause the printer to stop responding to
requests for service.

Earlier versions of the Brother firmware may share this vulnerability,
however this has not been confirmed.

20. Ben Chivers Easy Homepage Creator File Modification Vulnerability
BugTraq ID: 5340
Remote: Yes
Date Published: Jul 29 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5340
Summary:

Ben Chivers Easy Homepage Creator is a collecion of perl scripts meant to
facilitate easy home page creation.

The vulnerability has been reported for Easy Homepage Creator 1.0. It is
possible for an atttacker to modify any user's home page. The
vulnerability is the result of Homepage Creator failing to properly
authenticate users who wish to edit home pages. A remote attacker may post
directly to the 'edit.cgi' script, supplying an arbitrary username and new
page content. No authentication is required.

An attacker may be able to edit any user's home page without prior
consent.

21. Ben Chivers Easy Guestbook Administrative Access Vulnerability
BugTraq ID: 5341
Remote: Yes
Date Published: Jul 29 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5341
Summary:

Ben Chivers Easy Guestbook is a collecion of perl scripts meant to
facilitate easy guestbook creation.

The vulnerability has been reported for Easy Guestbook 1.0. It is possible
for an atttacker to modify any user's guestbook by deleting entries. The
vulnerability is the result of Guestbook failing to properly authenticate
users who wish to edit guestbooks. A remote attacker may post directly to
the 'admin.cgi' script, specifying administrative actions. No further
authentication is required.

An attacker may be able to edit any user's guestbook without prior
consent.

22. phpBB2 Gender Mod Remote SQL Injection Vulnerability
BugTraq ID: 5342
Remote: Yes
Date Published: Jul 29 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5342
Summary:

phpBB2 is an open-source web forum application that is written in PHP and
backended by a number of database products. It will run on most Unix and
Linux variants, as well as Microsoft Windows operating systems.

Gender Mod is a modification for phpBB2 which allows the association of a
gender with a given user profile. A SQL injection vulnerability has been
reported in this mod.

A malicious user may modify the specified value for 'gender' when updating
their profile. It is possible to include additional SQL statements in this
string, and subvert the SQL statement used to update the user profile.

It has been reported possible to gain administrative access to the phpBB2
site through exploitation of this issue. Other attacks may be possible,
including the ability to view sensitive database information or to modify
additional information stored in the database.

23. Util-linux File Locking Race Condition Vulnerability
BugTraq ID: 5344
Remote: No
Date Published: Jul 29 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5344
Summary:

The util-linux package is a set of commonly used system utilities such as
'chfn' and 'chsh'.  It is included with many Linux distributions.

A race condition has been reported in code shared by the util-linux
utilities.  The condition is related to file locking.  Failure to check
for the existence of a lockfile prior to sensitive operations may, under
specific circumstances, open a window of opportunity for attack.  The
util-linux utilities often write to sensitive files such as /etc/passwd/.
Attackers may exploit the condition to inject arbitrary data into these
files to elevate privileges.

The reported attacks are complex, time dependent and require specific
circumstances such as system administrator interaction and a large passwd
file.

Red Hat Linux is known to ship with util-linux as a core component.
Other distributions, those that are derived from Red Hat in particular,
may also be vulnerable.

It should be noted that the utilities included with the shadow-utils
package (shipped with SuSE Linux) are not vulnerable.

24. Multiple Browser Vendor Same Origin Policy Design Error Vulnerability
BugTraq ID: 5346
Remote: Yes
Date Published: Jul 29 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5346
Summary:

In modern browsers, script code executing in the context of one website
should not be able to access the properties of another.  This is a
security feature known as the 'same origin policy'.  It is put in place to
prevent malicious websites from interacting with and possibly stealing
sensitive information from others in different windows.  The current
specification of the same origin policy is flawed such that it creates a
vulnerability under some circumstances.

Only hostnames are used when evaluating whether access to content by
script code should be permitted -- the IP address is not taken into
consideration.  If the IP address associated with a hostname were to
change in DNS records, content served from a second host may be accessed
by script code served from the first.  This could theoretically be
exploited to access content served from behind a firewall (or on an
internal network).

Further simplifying attack, the Same Origin Policy allows for DOM access
privileges to be inherited across subdomains, for example: script from
xxxx.yyy may access content in a child window opened to zzz.xxxx.yyy.
This eliminates the need to quickly change a DNS record.  To exploit this,
the attacker need only create a subdomain with an address behind the
victim firewall.

Exploitation of this vulnerability may result in disclosure of sensitive
information, enumeration of hosts behind a firewall or accessing of
internal web services (XML-RPC/SOAP requests may also be possible).

25. Abyss Web Server HTTP GET Request Directory Contents Disclosure Vulnerability
BugTraq ID: 5345
Remote: Yes
Date Published: Jul 29 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5345
Summary:

Abyss Web Server is a freely available personal web server. It is
maintained by Aprelium Technologies and runs on Microsoft Windows
operating systems, as well as Linux.

A vulnerability has been reported for Abyss Web Server 1.0.3 running on a
Microsoft Windows platform. It is possible for an attacker to make a
request such that the contents of the specified directory are revealed.

The vulnerability occurs due to the manner in which excessive '/'
characters are handled in web requests. An attacker making a GET request
followed by 256 '/' characters will cause Abyss Web Server to return an
error page containing the directory listing of the specified directory.

An attacker may be able to use this information to launch further,
potentially damaging attacks, against a vulnerable system.

26. DotProject User Cookie Authentication Bypass Vulnerability
BugTraq ID: 5347
Remote: Yes
Date Published: Jul 29 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5347
Summary:

dotproject is web-based project management software, written in PHP.  It
is designed to run on Unix and Linux variants.

dotproject is prone to an issue which may allow remote attackers to bypass
authentication and gain administrative access to the software.

This may be accomplished by submitting a maliciously crafted 'user_cookie'
value either manually or via manipulation of URI parameters.  For example,
the attacker may manually craft a cookie with a 'user_cookie' value of 1
and submit it to the project management system.  An attacker may also
submit a malicious web request with the 'user_cookie' URI parameter set to
1.  In both instances, the attacker will gain administrative access to the
project management system.

This problem is due to the software relying on the 'user_cookie' value to
authenticate the user.

27. Hylafax Incoming TSI Format String Denial Of Service Vulnerability
BugTraq ID: 5348
Remote: Yes
Date Published: Jul 29 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5348
Summary:

Hylafax is a software package designed to handle the transmission of
faxes.

Incoming fax messages include a Transmitting Subscriber Identification
(TSI) string, used to identify the fax machine of origin. An error exists
in the handling of these values in some versions of Hylafax.

The vulnerability occurs with the faxgetty program distributed with
Hylafax. faxgetty monitors incoming calls and modem status. The TSI value
is used by faxgetty to notify the Hylafax scheduler. A malicious attacker
may send a fax including format modifiers such as '%x' as part of the TSI
string. This data is not sanitized before being used. An attacker may be
able to cause the Hylafax process to crash by including characters which
will de-reference adjacent stack values, such as '%s', resulting in a
denial of service condition.

It may prove possible to exploit this vulnerability to execute arbitrary
code. However, it has been reported that there is a 20 character limit on
the length of the TSI string within Hylafax, which may complicate or
prevent this mode of exploitation.

28. Hylafax Oversized Scan Line Remote Buffer Overflow Vulnerability
BugTraq ID: 5349
Remote: Yes
Date Published: Jul 29 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5349
Summary:

Hylafax is a software package designed to handle the transmission of
Faxes.

A buffer overflow has been reported in the faxgetty program distributed
with some versions of Hylafax. faxgetty monitors incoming calls and modem
status. A malicious fax transmission may include a long scan line that
will overflow a memory buffer, corrupting adjacent memory.

It is possible to exploit this vulnerability to create a denial of service
condition. More careful exploitation may result in the corruption of stack
frame data, and the execution of arbitrary code as the faxgetty process.
In typical installations, faxgetty will run with root privileges.

29. Microsoft Outlook Express XML File Attachment Script Execution Vulnerability
BugTraq ID: 5350
Remote: Yes
Date Published: Jul 29 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5350
Summary:

An error has been reported in Microsoft Outlook Express which may allow
malicious XML file attachments to execute arbitrary code in the context of
the local system. Code execution could occur when the file attachment is
opened, without further prompting or user interaction. By default, XML
documents may be considered 'safe', and open without a warning prompt.

XSL stylesheets can be associated with XML documents. Additionally, some
XSL information can be embedded within an XML document. As XSL may contain
script code, the usage of XSL is normally restricted with documents
executing within sensitive security zones such as the Internet Zone.

It is, however, possible to include some script code in an XML file. As
XML files are considered safe, an XML attachment may be opened from within
Outlook without further prompting. Some embedded script code may still
execute, despite the generation of an XML parsing error. When script code
included in style information executes, it is able to determine the
location of the document, and in turn the location of the Temporary
Internet File (TIF) directory the document is stored in.

Information about the location of the TIF directory can be used to
reference additional malicious attachements, including executable content,
within the context of the local file system. This can in turn lead to the
execution of arbitrary code within the Local System security zone.

This behavior has been reported in Outlook Express 6. Other versions of
Outlook may share this vulnerability, this has not however been confirmed.

30. Fake Identd Client Query Remote Buffer Overflow Vulnerability
BugTraq ID: 5351
Remote: Yes
Date Published: Jul 29 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5351
Summary:

Fake Identd is an open source Ident server designed to return the same
information to all incoming requests. It is implemented by Tomi Ollila,
and available for Linux and a number of other Unix based operating
systems.

Reportedly, some versions of Fake Identd fail to properly handle long
client requests. A specially formatted request split across multiple TCP
packets may cause an internal buffer to overflow. Reportedly, execution of
arbitrary code as the Fake Identd server process is possible.

Fake Identd is designed to drop privileges. However, it has also been
reported that this behavior is flawed in some versions. As a result,
exploitation may result in the execution of code with root privileges.

31. MM Shared Memory Library Temporary File Privilege Escalation Vulnerability
BugTraq ID: 5352
Remote: No
Date Published: Jul 29 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5352
Summary:

The MM Shared Memory Library is designed to provide simplified usage of
shared memory between forked processes.  It was originally intended to be
used as a library for providing shared memory to Apache modules and may be
present in some Apache implementations.

The MM Shared Memory library is reported to be prone to a race condition
with regards to temporary files which may enable a local attacker to gain
elevated privileges.  The vulnerable library creates a temporary memory
file with a predictable filename and performs actions on the memory file
without sufficiently checking to see if the file already exists.  These
two conditions make the vulnerable library prone to symlink attacks.

According to MandrakeSoft and other vendors, this issue may be exploited
by an attacker with shell access as the Apache webserver user to gain root
privileges on a vulnerable host.

32. Multiple OpenSSL Remote Buffer Overflow Vulnerabilities
BugTraq ID: 5353
Remote: Yes
Date Published: Jul 30 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5353
Summary:

Multiple buffer overflow vulnerabilities have been reported for OpenSSL
0.9.7 and earlier.

1. It is possible for the master key supplied by a client to an SSL
version 2 server to be oversized. This would cause stack memory to become
corrupted. It has been reported that this issue is remotely exploitable.
Systems that do not enable SSLv2 functionality are not vulnerable to this
issue. This issue has been given CVE ID:  CAN-2002-0656.

2. A SSL version 3 session ID supplied to a client from a malicious server
may be oversized. This would cause a buffer to be overrun and corrupt key
memory areas on the client system. This issue has been given CVE ID:
CAN-2002-0656.

3. A master key supplied to a SSL version 3 server could be oversized.
This would cause stack memory on the vulnerable server to become
corrupted. This issue only affects systems that use OpenSSL 0.9.7 before
0.9.7-beta3 with Kerberos enabled. This issue has been given CVE ID:
CAN-2002-0657.

4. An issue with buffers used to hold ASCII representations of integers on
64 bit platforms has been reported. It is possible to overflow these
buffers on a vulnerable system if overly large values are submitted by a
malicious attacker. This issue has been given CVE ID: CAN-2002-0655.

5. Another issue exists with the ASN.1 library used by OpenSSL. Reportedly
there are parsing issues with the library. This issue has been given CVD
ID: CAN-2002-0659.

** This report is deprecated. For current details on these issues, please
reference BIDs 5361, 5362, 5363, 5364 and 5366.

33. Multiple Vendor BSD pppd Arbitrary File Permission Modification Race Condition Vulnerability
BugTraq ID: 5355
Remote: No
Date Published: Jul 29 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5355
Summary:

Multiple BSD based operating systems include a point-to-point protocol
daemon, pppd. pppd acts as the server side of point-to-point connections,
handling the ppp connection from a peer, and negotiating the connection.

A vulnerability has been reported in some versions of pppd. A race
condition error in the code may result in the pppd process changing the
file permissions on an arbitrary system file. pppd will generally run as a
privileged user.

When pppd opens a tty device file, the current file permissions are
recorded. If an error then occurs when initializing the device, pppd
attempts to restore the original file permissions. An attacker may take
advantage of this feature by replacing the specified tty device file with
a symbolic link to an arbitrary system file, which will then have it's
permissions modified.

A local attacker may exploit this vulnerability to gain unauthorized
access to sensitive files. Obtaining write access to, for example,
/etc/passwd or /etc/crontab, may allow immediate elevation of privileges.

This issue has been reported in OpenBSD versions 3.0 and 3.1. Earlier
versions of OpenBSD may share this vulnerability, this has not however
been confirmed.

34. Multiple Vendor Sun RPC xdr_array Buffer Overflow Vulnerability
BugTraq ID: 5356
Remote: Yes
Date Published: Jul 30 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5356
Summary:

The xdr_array procedure is used by client/server applications implementing
Sun RPC to filter between local C representations of variable length
arrays and their machine-independent external data representations (XDR).

A buffer overflow vulnerability has been reported in the xdr_array()
procedure.  Remote attackers may exploit this vulnerability through RPC
services to execute arbitrary code on target hosts.  As RPC services
typically run with root privileges, successful exploitation may mean
complete compromise.

OpenBSD originally reported that this vulnerability may be exploited by
remote attackers to cause a denial of service.  If this is a heap-based
overflow, the nature of the OpenBSD malloc implementation may only allow
for exploitation to cause a crash.  Other platforms that use the same Sun
RPC code but a different malloc implementation may allow for code
execution.

35. ShoutBox Form Field HTML Injection Vulnerability
BugTraq ID: 5354
Remote: Yes
Date Published: Jul 29 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5354
Summary:

shoutBOX is web-based user feedback software.  It is written in PHP and
runs on Unix and Linux variants as well as Microsoft Windows operating
systems.

ShoutBox does not sufficiently sanitize HTML tags from input supplied via
form fields.  In particular, the user website URL field of the feedback
form is not sanitized of HTML tags.

Attackers may exploit this lack of input validation to inject arbitrary
HTML and script code into pages that are generated by the script.  This
may result in execution of attacker-supplied code in the web client of a
user who visits such a page.  HTML and script code will be executed in the
security context of the site hosting the software.

This condition may be exploited to hijack web content or potentially steal
cookie-based authentication credentials.

36. Adobe eBook Reader File Transfer Authorization Voucher Weak Algorithm Vulnerability
BugTraq ID: 5358
Remote: No
Date Published: Jul 30 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5358
Summary:

Adobe eBook Reader is a client side application which is able to view
Adobe eBooks, available for Microsoft Windows and Macintosh OS 9. eBooks
are electronic books which provide some protection for content. Users may
own and view a book, but have limited rights to transfer the content.

Reportedly, an eBook may be transferred to a different computer by backing
up the book content and a number of datafiles. When the eBook is opened,
however, the user will be prompted for a new authorization voucher, and
given a challenge string. Normally, the user must contact Adobe for an
updated voucher response.

It has been reported that the encryption scheme used for this challenge /
response cycle is fundamentally flawed. Allegedly, both the challenge and
response can be computed using commonly available cryptographic
algorithms. Additionally, the secret information required to generate both
strings is stored within the eBook Reader executable file, which is
available to the local user.

Full details on the algorithms used have not been provided. It is not
unreasonable, however, to assume that a skilled attacker could derive the
details of the algorithm through experimentation.

As a result, a malicious user may freely transfer eBook content between
computers.

37. Microsoft Windows Media Player Filename Buffer Overflow Vulnerability
BugTraq ID: 5357
Remote: Yes
Date Published: Jul 30 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5357
Summary:

The Microsoft Windows Media Player executable is prone to a buffer
overflow condition.

This is due to insufficient bounds checking of filenames which are
supplied when the executable is invoked by a user.  It has been reported
that this condition occurs when a filename of 279+ characters is supplied.
A valid file extension (such as .mp3) must be supplied with the oversized
filename.  This will cause the stack of the vulnerable function in process
memory to be corrupted with attacker-supplied data, which may allow for
execution of arbitrary code.

Since the program is executed in the context of the user invoking it, it
is not likely that a local attacker could exploit this issue to gain
elevated privileges.  However, if the program can be invoked remotely or a
user can be somehow enticed into invoking the program with a malformed
filename, then this may be exploited by an attacker.  Realistically,
another exposure or vulnerability would have to exist on the host system
for an attacker to exploit this issue.

It is not currently known exactly which versions of the software are
affected.

38. Microsoft Office XP/Internet Explorer OWC File Creation Vulnerability
BugTraq ID: 5359
Remote: Yes
Date Published: Jul 30 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5359
Summary:

A reliable source has announced a vulnerability affecting users of
Microsoft Internet Explorer and Microsoft Office XP.

The vulnerability is related to Office Web Components (OWC), a set of
plugins for MSIE that have been taken off of Microsoft's website for
security reasons.

As described in Bugtraq ID 4398, it is possible to use the Microsoft
spreadsheet component Host() function to create files on a client system.
While this issue was addressed in a vendor-supplied fix, it is still
possible to abuse this functionality via Internet Explorer.  In this
specific instance, it is possible to abuse OWC in combination with a
malicious .xls or .xla file to cause an almost arbitrary file to be
written to a client system.

This issue affects systems that still have OWC installed and may be
exploited from a malicious webpage.

39. Sympoll File Disclosure Vulnerability
BugTraq ID: 5360
Remote: Yes
Date Published: Jul 30 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5360
Summary:

Sympoll is web-based voting booth software.  It is implemented in PHP and
will run on most Unix and Linux variants as well as Microsoft Windows
operating systems.

Sympoll is prone to an issue which may allow remote attackers to disclose
the contents of arbitrary webserver readable files.  This vulnerability is
only present on hosts which are running the vulnerable version of the
software and have the PHP 'register_globals' directive enabled.  The
source of this vulnerability is reported to be insufficient integrity
checking of variables.

The vendor has stated that this issue is only believed to affect Sympoll
version 1.2.

Exploitation of this issue on Microsoft Windows operating systems may
potentially expose arbitrary system files since webservers typically run
in the SYSTEM context.

40. OpenSSL Kerberos Enabled SSLv3 Master Key Exchange Buffer Overflow Vulnerability
BugTraq ID: 5361
Remote: Yes
Date Published: Jul 30 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5361
Summary:

OpenSSL is an open source implementation of the SSL protocol. It is used
by a number of other projects, including but not restricted to Apache,
Sendmail, Bind, etc.. It is commonly found on Linux and Unix based
systems.

A vulnerability has been reported for OpenSSL 0.9.7 pre-release versions.

This vulnerability is present only when Kerberos is enabled for a system
using SSL version 3.

When initiatiating contact between a SSLv3 server, master keys are
exchanged between the client and the server. When an oversized master key
is supplied to a SSL version 3 server by a malicious client, it may cause
a buffer to overflow on the vulnerable system. As a result, stack memory
on the vulnerable server will become corrupted. This could enable the
attacker to take control of the SSLv3 server process and cause it to
execute malicious, attacker supplied code.

** This vulnerability was originally part of BID 5353, Multiple OpenSSL
Buffer Overflow Vulnerabilities. It has now been reissued as a separate
vulnerability.

41. OpenSSL SSLv3 Session ID Buffer Overflow Vulnerability
BugTraq ID: 5362
Remote: Yes
Date Published: Jul 30 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5362
Summary:

OpenSSL is an open source implementation of the SSL protocol. It is used
by a number of other projects, including but not restricted to Apache,
Sendmail, Bind, etc.. It is commonly found on Linux and Unix based
systems.

A vulnerability has been reported for OpenSSL. The vulnerability affects
SSLv3 session IDs.

When initiating contact with SSLv3 servers, clients and servers alike
exchange information. Session information is stored in a session key with
a unique session ID.

Reportedly when a an oversized SSL version 3 session ID is supplied to a
client from a malicious server, it is possible to overflow a buffer on the
remote system. This could result in key memory areas on the vulnerable,
remote system being overwritten, including stack frame data.

An attacker may be able to take advantage of this vulnerability to execute
malicious code on a vulnerable SSLv3 client machine.

Oracle reports that CorporateTime Outlook Connector is only vulnerable
under Microsoft Windows 98, NT, 2K, and XP.

** This vulnerability was originally part of BID 5353, Multiple OpenSSL
Buffer Overflow Vulnerabilities. It has now been reissued as a separate
vulnerability.

42. OpenSSL SSLv2 Malformed Client Key Remote Buffer Overflow Vulnerability
BugTraq ID: 5363
Remote: Yes
Date Published: Jul 30 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5363
Summary:

OpenSSL is an open source implementation of the SSL protocol. It is used
by a number of other projects, including but not restricted to Apache,
Sendmail, Bind, etc.. It is commonly found on Linux and Unix based
systems.

A buffer overflow vulnerability has been reported in some versions of
OpenSSL.

When initiating an OpenSSL session, some information is shared between the
client and the server, including key data. The reported vulnerability lies
in the handling of the client key value during the negotiation of the
SSLv2 protocol.

A malicious client may exploit this vulnerability by transmitting a
malformed key to the vulnerable server. Careful exploitation may result in
execution of arbitrary code as the server process, and the attacker
gaining local access to the vulnerable system. More primitive attacks may
result in the server process crashing, possibly producing a denial of
service condition.

The consequences of exploitation may vary with the nature of the
application using OpenSSL.

Oracle reports that CorporateTime Outlook Connector is only vulnerable
under Microsoft Windows 98, NT, 2K, and XP.

** This vulnerability was originally part of BID 5353, Multiple OpenSSL
Buffer Overflow Vulnerabilities. It has now been reissued as a separate
vulnerability.

43. OpenSSL ASCII Representation Of Integers Buffer Overflow Vulnerability
BugTraq ID: 5364
Remote: Yes
Date Published: Jul 30 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5364
Summary:

OpenSSL is an open source implementation of the SSL protocol.  It is used
by a number of other projects, including but not restricted to Apache,
Sendmail, Bind, etc..  It is commonly found on Linux and Unix based
systems.

Remotely exploitable buffer overflow conditions have been reported in
OpenSSL.  This issue is due to insufficient checking of bounds with
regards to ASCII representations of integers on 64 bit platforms.  It is
possible to overflow these buffers on a vulnerable system if overly large
values are submitted by a malicious attacker.

Exploitation of this vulnerability may allow execution of arbitrary code
with the privileges of the vulnerable application, service or client.

Oracle reports that CorporateTime Outlook Connector is only vulnerable
under Microsoft Windows 98, NT, 2K, and XP.

** This vulnerability was originally part of BID 5353, Multiple OpenSSL
Buffer Overflow Vulnerabilities. It has now been reissued as a separate
vulnerability.

44. OpenSSL ASN.1 Parsing Error Denial Of Service Vulnerability
BugTraq ID: 5366
Remote: Yes
Date Published: Jul 30 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5366
Summary:

OpenSSL is an open source implementation of the SSL protocol.  It is used
by a number of other projects, including but not restricted to Apache,
Sendmail, Bind, etc..  It is commonly found on Linux and Unix based
systems.

A remotely exploitable denial of service condition has been reported in
the OpenSSL ASN.1 library.

This vulnerability is due to parsing errors and affects SSL, TLS, S/MIME,
PKCS#7 and certificate creation routines.  In particular, malformed
certificate encodings could cause a denial of service to server and client
implementations which depend on OpenSSL.

Oracle reports that CorporateTime Outlook Connector is only vulnerable
under Microsoft Windows 98, NT, 2K, and XP.

** This vulnerability was originally part of BID 5353, Multiple OpenSSL
Buffer Overflow Vulnerabilities. It has now been reissued as a separate
vulnerability.

45. IPSwitch IMail Web Calendaring Incomplete Post Denial Of Service Vulnerability
BugTraq ID: 5365
Remote: Yes
Date Published: Jul 30 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5365
Summary:

IMail is a commercial email server software package distributed and
maintained by Ipswitch, Incorporated. IMail is available for Microsoft
Operating Systems.

A problem has been discovered in the web calendaring service that could
lead to a denial of service.

When a HTTP POST command is made to the web calendaring service on port
8484, and the "content-length:" header field is blank, the service becomes
unstable.  It has been reported that such a transaction with the service
results in a crash of the iwebcal service.  This could allow users to deny
service to other legitimate users of the service.

It should be noted that the service will not resume normal operation
unless restarted manually.

46. William Deich Super SysLog Format String Vulnerability
BugTraq ID: 5367
Remote: No
Date Published: Jul 31 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5367
Summary:

super is an open source set-uid root utility that allows for a similar
functionality to that of the sudo utility. It is written for use on Linux
and Unix variant operating systems.

super is prone to a format string vulnerability. This problem is due to
incorrect use of the syslog() function to log error messages. It is
possible to corrupt memory by passing format strings through the
vulnerable logging function. This may potentially be exploited to
overwrite arbitrary locations in memory with attacker-specified values.

The vulnerability is a result of compiling super with syslog support. Due
to an error in the file, error.c, users that are not in the super
configuration file will still be able to execute code with root
privileges.

Successful exploitation of this issue may allow the attacker to execute
arbitrary instructions with root privileges.

47. HP JetDirect Embedded Web Server Password Handling Vulnerability
BugTraq ID: 5368
Remote: Yes
Date Published: Jul 31 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5368
Summary:

Some HP printers using Jetdirect firmware include an Embedded Web Server
(EWS), which allows remote administration of the device.

A vulnerability has been reported in some versions of the Jetdirect
firmware. Reportedly, the embedded web server may handle passwords in an
insecure manner.

Full details of this vulnerability are not currently available. HP has
reported that exploitation of this vulnerability may result in an attacker
gaining unauthorized access to the device, or being able to create a
denial of service condition.

This vulnerability may be related to issues discussed in BID 3132. This
has not, however, been confirmed.

48. T. Hauck Jana Server HTTP Server Request Logging Buffer Overflow Vulnerability
BugTraq ID: 5319
Remote: Yes
Date Published: Jul 26 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5319
Summary:

Jana Server is a server for Microsoft Windows based systems. In addition
to performing a wide range of proxy server functions, it supports an HTTP
server.

A buffer overflow vulnerability has been reported in the HTTP server. If
an extremely long HTTP request is received, the server will crash when
attempting to log the request. This has been reported to be the result of
a buffer overflow condition.

The malicious request will take the following form:

GET / HTTP/[buffer].0

Due to the nature of this vulnerability, it may be possible for a remote
attacker to execute arbitrary code as the server process. Reportedly, Jana
Server runs with SYSTEM privileges on Windows NT systems. The ability to
execute arbitrary code has not yet been confirmed.

49. T. Hauck Jana Server HTTP Proxy Server Request Logging Buffer Overflow Vulnerability
BugTraq ID: 5320
Remote: Yes
Date Published: Jul 26 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5320
Summary:

Jana Server is a server for Microsoft Windows based systems. Jana Server
provides a wide range of proxy servers, and a number of other services. A
HTTP proxy server is included.

A buffer overflow vulnerability has been reported in the HTTP proxy
server. The HTTP proxy server listens to TCP port 3128. If an extremely
long HTTP request is received, the server will crash when attempting to
log the request. This has been reported to be the result of a buffer
overflow condition.

The malicious request will take the following form:

GET / HTTP/[buffer].0

Due to the nature of this vulnerability, it may be possible for a remote
attacker to execute arbitrary code as the server process. Reportedly, Jana
Server runs with SYSTEM privileges on Windows NT systems. The ability to
execute arbitrary code has not yet been confirmed.


III. SECURITYFOCUS NEWS AND COMMENTARY
--------------------------------------
1. When Dreamcasts Attack
By  Kevin Poulsen

White hat hackers use game consoles, handheld PCs to crack networks from
the inside out.

http://online.securityfocus.com/news/558

2. Wi-Fi Honeypots a New Hacker Trap
By  Kevin Poulsen

War drivers beware, the next wireless network you tap might be part of an
elaborate sting.

http://online.securityfocus.com/news/552

3. OpenSSH trojaned!
By John Leyden, The Register

Copies of OpenSSH packages on popular download sites have been trojaned,
developers have warned.

http://online.securityfocus.com/news/560

4. Multiple virus scanning needed, says multiple scanning firm
By John Leyden, The Register

No single anti-virus product catches a comprehensive range of email
viruses and malware within a variety of compressed and uncompressed file
formats.

http://online.securityfocus.com/news/559


IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Snort Alert Monitor v2002-07-31
by Sam Freiberg
Relevant URL:
http://freesoftware.lookandfeel.com/sam/
Platforms: Os Independent
Summary:

SAM is a real-time Snort alert monitor. It provides many ways to indicate
that you may be experiencing an intrusion attempt on your network,
including audio/visual warnings, email warnings, etc.

2. IMAPScrape v0.1
by by Graham Bennett
Relevant URL:
http://www.lamity.org/~graham/imapscrape/index.html
Platforms: Os Independent
Summary:

IMAPScrape is a utility to scrape messages which match certain criteria
from an IMAP server and place them in a mailbox file.

3. DansGuardian Anti-Virus Scanner v1.0rc1
by James A. Pattie
Relevant URL:
http://www.pcxperience.org/dgvirus/
Platforms: FreeBSD, Linux, OpenBSD, Solaris, SunOS
Summary:

The DansGuardian Anti-Virus Scanner gives you the ability to virus-scan
all content that passes through DansGuardian. It uses the scanning code
from the MailScanner project to do the actual virus scanning, so it
supports all the virus engines that the MailScanner project supports. The
scanning is done as the file is being downloaded, so your current network
apps don't have to be modified, etc. They just have to support using a
proxy.

4. ACiD alpha
by Roberto Larcher
Relevant URL:
http://webteca.port5.com/ACiD.htm
Platforms: FreeBSD, OpenBSD, Windows 2000, Windows NT, Windows XP
Summary:

ACiD (ARP Change intrusion Detection) is a network monitoring tool that
detects anomalies in IP to MAC pairs.

ACiD has been designed to evidence the anomalies that are due to active
attacks on the network. For example is possible to detect arpspoof-like
attacks.

5. tcptraceroute v1.4
by Michael C. Toren
Relevant URL:
http://michael.toren.net/code/tcptraceroute/
Platforms: N/A
Summary:

tcptraceroute is a traceroute implementation using TCP SYN packets,
instead of the more traditional UDP or ICMP ECHO packets. In doing so, it
is able to trace through many common firewall filters.

6. FCheck 2.07.59
by Michael A. Gumienny
Relevant URL:
http://www.geocities.com/fcheck2000/FCheck_2.07.59.tar.gz
Platforms: AIX, BSDI, DG-UX, Digital UNIX/Alpha, FreeBSD, HP-UX, Linux,
NetBSD, OpenBSD, Perl (any system supporting perl), SCO, Solaris, SunOS,
UNIX, Unixware, Windows 2000, Windows 3.x, Windows 95/98, Windows NT
Summary:

FCHECK is a very stable PERL script written to generate and comparatively
monitor a UNIX system against its baseline for any file alterations and
report them through syslog, console, or any log monitoring interface.
Monitoring events can be done in as little as one minute intervals if a
system's drive space is small enough, making it very difficult to
circumvent. This is a freely-available open-source alternative to
'tripwire' that is time tested, and is easier to configure and use.


V. SECURITY JOBS SUMMARY
------------------------
1. Software Engineer - Anti-Virus Research (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/285502

2. Computer and Network Security Officer Job Vacancy (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/285500

3. (2) Information Security Scientist roles for Risk Assessments - One Junior, One Senior - Located in IL - Greythorn (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/285366

4. Looking for a Job. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/285367

5. Information Security Architect (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/285360

6. Info Security Opportunity - Northbrook, IL (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/285194

7. Security System Engineers in the MA/Cambridge Area needed. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/285193

8. Exciting opportunity for a Crypto-Analyst or a Crypto-mathematici    an in the Maryland area (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/285192

9. Seeking permanent work in IL (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/285191

10. Fwd: Seeking full time or contract work in NH/MA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/285190

11. Cleared Information Assurance Professional wanted in Annapolis, MD (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/285189

12. Seeking full time or contract work in NH/MA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/285047

13. CISSP in Duluth, MN (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/285034

14. Network Security Manager Position in Florida (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/285033

15. PKI Position in Washington DC (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/284914

16. SAP/CSS Security Professional Needed (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/284911

17. Wanted: Security Job in Switzerland (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/284858

18. Infrastructure Security Director (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/284775

19. Security jobs in the UK (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/284869

20. Security Consultants positions in New Jersey (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/284622

21. 2 positions in Rosslyn, VA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/284624

22. Seeking SalesMgnt/Business Development Position E/SE/S FL (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/284623

23. Senior Sales Executives - East Coast (South Florida) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/284620


VI. INCIDENTS LIST SUMMARY
-------------------------
1. Anyone know this rootkit (rootkits?) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/285572

2. Rating Attackers (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/285549

3. Trojan located in latest openssh tar files (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/285547

4. openssh-3.4p1.tar.gz trojaned (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/285538

5. scanning for HTTP proxies, ports 80, 81, 1080, 3128, 4480, 6588, 8000, 8080, 8081 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/284933

6. Packet suckers? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/284924

7. scanning for HTTP proxies, ports 80, 81, 1080, 3128, 4480,  6588, 8000, 8080, 8081 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/284922

8. observations on recent unicode attacks against IIS servers (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/284846

9. Compromized Windows NT machine? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/284843

10. Anyone know this rootkit (rootkits?)  (details and files attached) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/284591

11. Anyone know this rootkit (rootkits?)  (details and filesattached) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/284516

12. Bind 9.2.X exploit??? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/284513


VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. Comment on DMCA, Security, and Vuln Reporting] (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/285706

2. Weird WinME Login Bug (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/285709

3. ssh trojaned (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/285705

4. It takes two to tango (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/285703

5. [Full-Disclosure] RE: It takes two to tango (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/285589

6. Actuate Server CSS Vulnerability (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/285704

7. Comment on DMCA, Security, and Vuln Reporting (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/285584

8. Formal Response to HP (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/285434

9. WHERE'S THE CA$H: Internet Explorer 6.00. Outlook Express 6.00 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/285435

10. Possible cable modem denial of service ? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/285432

11. Terminal Service - Denial of Service (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/285312

12. Directory traversal vulnerability in sendform.cgi (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/285311

13. Administrivia #14344 (Vegas, woo hoo!) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/285151

14. Does MSN Messenger Bypass Group Policy? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/285122

15. Operation TIPS - the FEMA response (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/285105

16. MS Terminal Service problem (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/285060

17. Vulnerability: protected Adobe eBooks can be copied between computers (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/285059

18. php-4.0.6 vulnerability (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/285055

19. Re[2]: Possible cable modem denial of service ? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/285054

20. removal of /tmp/appXXXXXX (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284989

21. Malicious COM Surrogates (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284987

22. is any one sniffing comports on win2k or XP? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284976

23. Perl 5.6.0 (on Linux) getpwuid() leave /etc/shadow opened (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284958

24. nmapwin  Scan 10.10.10.*  after you install it and start the    service. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284706

25. nmapwin  Scan 10.10.10.*  after you install it and start the service. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284679

26. Phenoelit Advisory, 0815 ++ * - Cisco_tftp (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284668

27. Phenoelit Advisory  #0815 +-+ (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284667

28. Phenoelit Advisory 0815 ++ /+ HP ProCurve (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284665

29. Phenoelit Advisory #0815 +-- (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284666

30. Phenoelit Advisory 0815 ++ -- Brick (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284664

31. Phenoelit Advisory 0815 ++ // Xedia (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284662

32. Phenoelit ADvisory 0815 ++ ** Ascend (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284661

33. Phenoelit Advisory  #0815 ++-+ dp_300 (DLINK) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284659

34. 0815 ++ */ SEH_Web (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284658

35. Phenoelit Advisory, 0815 ++ /- Brother_NC (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284656

36. Announcement: injectso-0.2 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284497

37. winmessenger help (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284501

38. [Full-Disclosure] Re: UPDATE: Re: REFRESH: EUDORA MAIL 5.1.1 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284496

39. UPDATE: Re: REFRESH: EUDORA MAIL 5.1.1 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284495

40. REFRESH: EUDORA MAIL 5.1.1 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/284400


VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Linux firewall/ISA Server (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285652

2. windows update reporting info back to MS? (and .NET fw SP1) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285651

3. Windows 2000 special folder restrictions (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285645

4. W2000 Server lockout issue (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285650

5. local admin passwords (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285648

6. Flush.exe & Flushserv.exe (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285653

7. FW: secure remote management of nt4 and w2k servers (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285649

8. Good software against spam (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285550

9. IIS SMTP queue reader (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285536

10. Update Expert (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285389

11. HFNETCHKpro (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285372

12. change the nt-password in a other domain (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285362

13. HFNETCHKpro? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285365

14. Auditing ACL Changes (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285294

15. restricting MMC with GPO for SQL Enterprise Manager (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285147

16. Laptop Encryption (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285145

17. AW: hfnetchk reporting (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285129

18. Securing Laptops (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285128

19. Registry key for "QueryIpMatching" (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285136

20. Setting Account Lockout Policies with a NT PDC (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285131

21. hfnetchk reporting (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/285139

22. Anyone know this scan/tool? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/284963

23. FW: Anyone know this scan/tool? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/284947

24. Fw: Setting Account Lockout Policies with a NT PDC (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/284935

25. Issues/Concerns with Exchange 2000 SP3 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/284569


IX. SUN FOCUS LIST SUMMARY
----------------------------
1. Solaris and lack of loopback routes (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/285166

2. Administrivia: Gone Fishin' (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/285161

3. Solaris 8 username contingency (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/284524


X. LINUX FOCUS LIST SUMMARY
---------------------------
1. LDAP Auth? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/285167

2. LDAP auth (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/285168

3. Administrivia: Gone Fishin' (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/285159

4. Security by hiding processes (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/284545


XI. SPONSOR INFORMATION
-----------------------
This Newsletter is Sponsored by: Qualys

Bulletproof Your Network: FREE Guide

Existing security products -- firewalls, anti-virus and IDS -- are simply
no longer enough to ensure your networks are safe against sophisticated
attacks and worms such as Code Red and Nimda. FREE Guide shows you how to
ensure TOTAL security for your network. Get it now.

Visit us at: https://www.qualys.com/forms/guide_220.php

-------------------------------------------------------------------------------