SecurityFocus Newsletter #321
Peter Laborge <[email protected]> Wed, 26 Oct 2005 16:09:23 -0600
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #321
----------------------------------------
Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!
http://www.securityfocus.com/sponsor/Symantec_sf-news_041130
------------------------------------------------------------------
I. FRONT AND CENTER
1. Collaborative endpoint security, part one
2. Evolution of Web-based worms
3. The click-wrap conundrum
II. BUGTRAQ SUMMARY
1. Sun Solaris Proc Filesystem Local Denial Of Service Vulnerability
2. Flexbackup Multiple Insecure Temporary File Creation Vulnerabilities
3. Lynx NNTP Article Header Buffer Overflow Vulnerability
4. Comersus BackOffice Plus Multiple Cross-Site Scripting Vulnerabilities
5. PHP Safedir Restriction Bypass Vulnerabilities
6. Gentoo Linux Multiple Packages Insecure RUNPATH Vulnerability
7. OpenWBEM Multiple Unspecified Remote Buffer Overflow Vulnerabilities
8. Linux Kernel Console Keymap Local Command Injection Vulnerability
9. RARLAB WinRAR Command Line Processing Buffer Overflow Vulnerability
10. Opera Web Browser Multiple Malformed HTML Parsing Denial Of Service Vulnerabilities
11. E107 Resetcore.PHP SQL Injection Vulnerability
12. IBM DB2 Universal Database Multiple Vulnerabilities
13. NetFlow Analyzer 4 Cross-Site Scripting Vulnerability
14. NetPBM PNMToPNG Buffer Overflow Vulnerability
15. Rockliffe MailSite Express Arbitrary File Upload Vulnerability
16. Microsoft Windows Unspecified Remote Code Execution Vulnerability
17. Snort Back Orifice Preprocessor Remote Stack Buffer Overflow Vulnerability
18. MySource Multiple Cross-Site Scripting Vulnerabilities
19. MySource Multiple Remote File Include Vulnerabilities
20. Oracle October Security Update Multiple Vulnerabilities
21. Xerver Multiple Input Validation Vulnerabilities
22. HP-UX LPD Arbitrary Command Execution Vulnerability
23. PHPNuke Modules.PHP Search Module Remote Directory Traversal Vulnerability
24. HP-UX FTP Server Directory Listing Vulnerability
25. Oracle Workflow Multiple Unspecified Cross-Site Scripting Vulnerabilities
26. Yiff-Server File Permission Bypass Weakness
27. Paros HSQLDB Remote Authentication Bypass Vulnerability
28. Symantec LiveUpdate for Macintosh Local Privilege Escalation Vulnerability
29. Symantec Norton Antivirus For Macintosh DiskMountNotify Local Privilege Escalation Vulnerability
30. Cisco 11500 Content Services Switch Malformed SSL Client Certificate Denial of Service Vulnerability
31. Oracle Workflow Wf_monitor Cross-Site Scripting Vulnerability
32. Oracle Application Server 10g emagent.exe Stack Overflow Vulnerability
33. Oracle Workflow Wf_route Cross-Site Scripting Vulnerability
34. Ethereal Multiple Protocol Dissector Vulnerabilities In Versions Prior To 0.10.13
35. Chipmunk Multiple Cross-Site Scripting Vulnerabilities
36. PHP-Nuke Modules.PHP NukeFixes Addon Remote Directory Traversal Vulnerability
37. Debian Module-Assistant Insecure Temporary File Creation Vulnerability
38. Splatt Forums Remote Authentication Bypass Vulnerability
39. BMV PostScript File Handling Integer Overflow Vulnerability
40. Linux Kernel World Writable SYSFS DRM Debug File Vulnerability
41. Linux Kernel IPV6 Unspecified Denial of Service Vulnerability
42. Squid FTP Server Response Denial Of Service Vulnerability
43. Ethereal Service Location Protocol Dissection Stack Buffer Overflow Vulnerability
44. SCO UnixWare PPP Prompt Local Buffer Overflow Vulnerability
45. SCO OpenServer Backupsh Local Buffer Overflow Vulnerability
46. ZipGenius Multiple Archive Formats File Name Buffer Overflow Vulnerabilities
47. AL-Caricatier SS.PHP Authentication Bypass Vulnerability
48. Oracle Application Server HTTP Response Splitting Vulnerability
49. TikiWiki Unspecified Cross-Site Scripting Vulnerability
50. SUSE Linux Squid Proxy SSL Handling Denial of Service Vulnerability
51. Nuked Klan Multiple HTML Injection Vulnerabilities
52. BMC Control M Agent Insecure File Permission Vulnerability
53. Zomplog Detail.PHP HTML Injection Vulnerability
54. phpMyAdmin Theme Variable Local File Inclusion Vulnerability
55. phpBB Avatar Upload HTML Injection Vulnerability
56. eBASEweb Unspecified SQL Injection Vulnerability
57. FlatNuke Index.PHP Multiple Remote File Include Vulnerabilities
III. SECURITYFOCUS NEWS
1. Web defacer sentenced, facing deportation
2. Snort vulnerability "wormable" but not widespread
3. Worm worries don't wait for Windows exploits
4. Arrests unlikely to impact bot net threat, say experts
5. Say hello to the Skype Trojan
6. Shared music abuse bug hits iTunes
7. US cybersecurity all at sea
8. Worm fears over MS October patch batch
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] Quality Assurance, New York
2. [SJ-JOB] Security Researcher, Redwood City, CA; Santa Monica, CA; Waltham, MA; Herndon, VA
3. [SJ-JOB] Security Researcher, Redwood City, CA; Santa Monica, CA; Waltham, MA; Herndon, VA
4. [SJ-JOB] Sr. Security Analyst, Reading, Berkshire
5. [SJ-JOB] Disaster Recovery Coordinator, Silver Spring
6. [SJ-JOB] Developer, Columbia
7. [SJ-JOB] Security Architect, Alexandria
8. [SJ-JOB] Developer, Hyderabad
9. [SJ-JOB] Security Engineer, Hyderabad
10. [SJ-JOB] Sr. Security Engineer, Washington
11. [SJ-JOB] Sales Engineer, Vienna
12. [SJ-JOB] Application Security Engineer, Vienna
13. [SJ-JOB] Sales Engineer, Any US location
14. [SJ-JOB] Sales Engineer, Scottsdale
15. [SJ-JOB] Security Engineer, Reston/Dulles
16. [SJ-JOB] Security Consultant, London
17. [SJ-JOB] Forensics Engineer, London
18. [SJ-JOB] Manager, Information Security, Kent
19. [SJ-JOB] Security Engineer, GTA - Markham
20. [SJ-JOB] Sales Engineer, Sunnyvale
21. [SJ-JOB] Sr. Security Engineer, Mountain View
22. [SJ-JOB] Forensics Engineer, Duesseldorf / Muenchen
23. [SJ-JOB] Security Product Manager, Allentown
24. [SJ-JOB] Technology Risk Consultant, London
25. [SJ-JOB] Director, Information Security, London
26. [SJ-JOB] Compliance Officer, London
27. [SJ-JOB] Regional Channel Manager, New York
28. [SJ-JOB] Quality Assurance, Milpitas
29. [SJ-JOB] Developer, Sunnyvale
30. [SJ-JOB] CHECK Team Leader, Manchester
31. [SJ-JOB] Management, Redwood City
32. [SJ-JOB] Security Engineer, Acton
33. [SJ-JOB] Sales Engineer, Miami
34. [SJ-JOB] Security Engineer, New York
35. [SJ-JOB] Security Engineer, Rockville
36. [SJ-JOB] Security Engineer, Staines, Middlesex
V. INCIDENTS LIST SUMMARY
1. Who is looking for port 2036?
2. SSH bruteforce on its way...
3. Dismantling Botnets?
VI. VULN-DEV RESEARCH LIST SUMMARY
1. problem in rewrite RET address in Buffer OverFlow
2. Vulnerability Assesment tools(Vuln testing tools)
3. MS05-047 remote DOS (exploit code attached; compiles on linux)
4. Oracle 10g - emagent.exe Stack-Based Overflow
5. Vulnerability Buyer Company
VII. MICROSOFT FOCUS LIST SUMMARY
1. CFP: The First International Conference on Availability, Reliability and Security (AReS 2006), 20-22 April, 2006, Vienna, Austria
2. Change Password
3. Account Lockout Policy
4. security policy 'not specified' option
5. FW: Account Lockout Policy
6. Account Lockout Policy
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
1. httpd and port 7200
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Collaborative endpoint security, part one
By Ivan Arce, Eduardo Arias
Part one of this article introduces endpoint security solution technologies and proposes a collaborative approach to solving technical challenges that are commonly faced by the community.
http://www.securityfocus.com/infocus/1849
2. Evolution of Web-based worms
By Daniel Hanson
The Myspace Web worm used a simple vulnerability and XSS to propagate, and it might be a sign of things to come.
http://www.securityfocus.com/columnists/362
3. The click-wrap conundrum
By Mark Rasch
With the rise of spyware, the fact that you didn't understand what you were doing by downloading and installing the software doesn't mean you weren't bound by the End User License Agreement (EULA). However, the FTC argues otherwise.
http://www.securityfocus.com/columnists/365
II. BUGTRAQ SUMMARY
--------------------
1. Sun Solaris Proc Filesystem Local Denial Of Service Vulnerability
BugTraq ID: 15115
Remote: No
Date Published: 2005-10-16
Relevant URL: http://www.securityfocus.com/bid/15115
Summary:
Sun Solaris is prone to a local denial of service vulnerability.
A local unauthorized user can cause a system panic in the '/proc' filesystem and cause a denial of service.
2. Flexbackup Multiple Insecure Temporary File Creation Vulnerabilities
BugTraq ID: 15116
Remote: No
Date Published: 2005-10-17
Relevant URL: http://www.securityfocus.com/bid/15116
Summary:
Flexbackup creates several temporary files in an insecure manner.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
Flexbackup 1.2.1 and earlier versions are affected.
3. Lynx NNTP Article Header Buffer Overflow Vulnerability
BugTraq ID: 15117
Remote: Yes
Date Published: 2005-10-17
Relevant URL: http://www.securityfocus.com/bid/15117
Summary:
Lynx is prone to a buffer overflow when handling NNTP article headers.
This issue may be exploited when the browser handles NNTP content, such as through 'news:' or 'nntp:' URIs. Successful exploitation will result in code execution in the context of the program user.
4. Comersus BackOffice Plus Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 15118
Remote: Yes
Date Published: 2005-10-17
Relevant URL: http://www.securityfocus.com/bid/15118
Summary:
BackOffice Plus is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
5. PHP Safedir Restriction Bypass Vulnerabilities
BugTraq ID: 15119
Remote: Yes
Date Published: 2005-10-17
Relevant URL: http://www.securityfocus.com/bid/15119
Summary:
PHP is prone to multiple vulnerabilities that permit an attacker to bypass the 'safedir' directory restriction.
An attacker can exploit these vulnerabilities to possible execute arbitrary code currently existing on a vulnerable system, or to retrieve the contents of arbitrary files, all in the security context of the Web server process.
Information obtained may aid in further attacks against the affected system; other attacks are also possible.
These issues have been addressed in the latest CVS version.
6. Gentoo Linux Multiple Packages Insecure RUNPATH Vulnerability
BugTraq ID: 15120
Remote: No
Date Published: 2005-10-17
Relevant URL: http://www.securityfocus.com/bid/15120
Summary:
Multiple packages in Gentoo Linux are susceptible to an insecure RUNPATH vulnerability. This issue is due to a flaw in the build system that results in insecure RUNPATHs being included in certain binaries.
This vulnerability may result in arbitrary code being executed in the context of users executing the vulnerable executables. This may facilitate privilege escalation.
This issue is only exploitable by users that are members of the 'portage' group.
7. OpenWBEM Multiple Unspecified Remote Buffer Overflow Vulnerabilities
BugTraq ID: 15121
Remote: Yes
Date Published: 2005-10-17
Relevant URL: http://www.securityfocus.com/bid/15121
Summary:
OpenWBEM is susceptible to multiple unspecified remote buffer overflow vulnerabilities. These issues are due to a failure of the application to properly bounds check user-supplied data prior to copying it to insufficiently sized memory buffers.
These issues are identified as multiple integer overflow and buffer overflow vulnerabilities. No further details are currently available. This BID will be updated as further information is disclosed.
These issues allow remote attackers to execute arbitrary machine code with superuser privileges, facilitating a complete system compromise.
8. Linux Kernel Console Keymap Local Command Injection Vulnerability
BugTraq ID: 15122
Remote: No
Date Published: 2005-10-17
Relevant URL: http://www.securityfocus.com/bid/15122
Summary:
The Linux kernel is susceptible to a local command injection vulnerability via console keymap modifications. This issue is due to the ability of unprivileged users to alter the system-wide console keymap.
Local users may modify the console keymap to include scripted macro commands. This allows attackers to execute arbitrary commands with the privileges of the user that uses the console after them, potentially facilitating privilege escalation.
9. RARLAB WinRAR Command Line Processing Buffer Overflow Vulnerability
BugTraq ID: 15123
Remote: Yes
Date Published: 2005-10-17
Relevant URL: http://www.securityfocus.com/bid/15123
Summary:
A remote, client-side buffer overflow vulnerability has been reported in the command line processing of RARLAB WinRAR. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
10. Opera Web Browser Multiple Malformed HTML Parsing Denial Of Service Vulnerabilities
BugTraq ID: 15124
Remote: Yes
Date Published: 2005-10-17
Relevant URL: http://www.securityfocus.com/bid/15124
Summary:
The Opera Web browser is prone to multiple vulnerabilities that may result in a browser crash. These issues are exposed when the browser attempts to parse certain malformed HTML content. It is conjectured that this will only result in a denial of service and is not further exploitable to execute arbitrary code, though this has not been confirmed.
11. E107 Resetcore.PHP SQL Injection Vulnerability
BugTraq ID: 15125
Remote: Yes
Date Published: 2005-10-18
Relevant URL: http://www.securityfocus.com/bid/15125
Summary:
e107 is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
An attacker can exploit this vulnerability to gain administrative access to the affected application. This may ultimately lead to a system compromise in the security context of the Web server process.
12. IBM DB2 Universal Database Multiple Vulnerabilities
BugTraq ID: 15126
Remote: Yes
Date Published: 2005-10-18
Relevant URL: http://www.securityfocus.com/bid/15126
Summary:
IBM DB2 Universal Database is prone to multiple vulnerabilities.
These issues may allow attackers to carry out denial of service attacks and other unauthorized actions.
These issues affect DB2 versions prior to 8 FixPak 10 also known as version 8.2 FixPak 3.
13. NetFlow Analyzer 4 Cross-Site Scripting Vulnerability
BugTraq ID: 15127
Remote: Yes
Date Published: 2005-10-18
Relevant URL: http://www.securityfocus.com/bid/15127
Summary:
NetFlow Analyzer 4 is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
14. NetPBM PNMToPNG Buffer Overflow Vulnerability
BugTraq ID: 15128
Remote: Yes
Date Published: 2005-10-18
Relevant URL: http://www.securityfocus.com/bid/15128
Summary:
pnmtopng is susceptible to a buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer. This issue reportedly only occurs when the '-trans' command line option is utilized.
This issue allows attackers to create malicious PNM files, that when parsed by the affected utility, allow arbitrary machine code to be executed. This occurs in the context of the user running the affected utility.
This vulnerability was reported in version 10.0 of NetPBM. Other versions may also be affected.
15. Rockliffe MailSite Express Arbitrary File Upload Vulnerability
BugTraq ID: 15129
Remote: Yes
Date Published: 2005-10-18
Relevant URL: http://www.securityfocus.com/bid/15129
Summary:
MailSite Express is prone to an arbitrary file upload vulnerability.
An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the Web server process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
16. Microsoft Windows Unspecified Remote Code Execution Vulnerability
BugTraq ID: 15130
Remote: Yes
Date Published: 2005-10-17
Relevant URL: http://www.securityfocus.com/bid/15130
Summary:
Microsoft Windows is prone to an unspecified remote code execution vulnerability.
Reportedly, this vulnerability affects Windows Media Player and Internet Explorer, allowing a remote attacker to execute arbitrary code and potentially gain unauthorized access in the context of the user running an affected client.
Due to a lack of information, further details cannot be described at the moment. This BID will be updated when more information becomes available.
17. Snort Back Orifice Preprocessor Remote Stack Buffer Overflow Vulnerability
BugTraq ID: 15131
Remote: Yes
Date Published: 2005-10-18
Relevant URL: http://www.securityfocus.com/bid/15131
Summary:
Snort is susceptible to a remote buffer overflow vulnerability. This issue is due to a failure of the application to securely copy network-derived data into sensitive process buffers. The specific issue exists in the Back Orifice preprocessor.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
Due to the nature of this issue, attackers may exploit it by sending a single UDP packet with a potentially spoofed source address to an arbitrary destination address and port. As long as the application can sniff the packet, it may be exploited. These aspects of this issue may aid attackers in bypassing firewalls in order to compromise a wider number of computers.
Reportedly, this issue is difficult to reliably exploit across differing operating systems and compiler versions. Failed exploit attempts likely result in crashing the application, thereby disabling detection of other attacks.
Snort versions 2.4.0 through 2.4.2 are affected by this issue. Other versions may also be affected, but this has not been confirmed.
18. MySource Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 15132
Remote: Yes
Date Published: 2005-10-18
Relevant URL: http://www.securityfocus.com/bid/15132
Summary:
MySource is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may facilitate the theft of cookie-based authentication credentials as well as other attacks.
19. MySource Multiple Remote File Include Vulnerabilities
BugTraq ID: 15133
Remote: Yes
Date Published: 2005-10-18
Relevant URL: http://www.securityfocus.com/bid/15133
Summary:
MySource is prone to multiple remote and local file include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage any of these issues to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
20. Oracle October Security Update Multiple Vulnerabilities
BugTraq ID: 15134
Remote: Yes
Date Published: 2005-10-18
Relevant URL: http://www.securityfocus.com/bid/15134
Summary:
Various Oracle Database Server, Oracle Enterprise Manager, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite and Applications, and Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne are affected by multiple vulnerabilities.
The issues identified by the vendor affect all security properties of the Oracle products and present local and remote threats.
Oracle has released a Critical Patch Update advisory for October 2005 to address these vulnerabilities. This Critical Patch Update addresses the vulnerabilities for supported releases. Earlier, unsupported releases are likely to be affected by the issues as well.
Specific details regarding these vulnerabilities are not currently available.
This record will be updated and split into individual BIDs for each issue as further information is disclosed.
21. Xerver Multiple Input Validation Vulnerabilities
BugTraq ID: 15135
Remote: Yes
Date Published: 2005-10-19
Relevant URL: http://www.securityfocus.com/bid/15135
Summary:
Xerver is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit a vulnerability to disclose the contents of any Web accessible script. Information obtained may aid in further attacks.
An attacker can retrieve a directory listing of any Web accessible folders. Information obtained may aid in further attacks.
An attacker can perform cross-site scripting attacks. This may be leveraged to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
22. HP-UX LPD Arbitrary Command Execution Vulnerability
BugTraq ID: 15136
Remote: Yes
Date Published: 2005-10-19
Relevant URL: http://www.securityfocus.com/bid/15136
Summary:
HP-UX lpd is affected by a remote arbitrary command execution vulnerability.
A successful attack can facilitate a complete compromise.
Reportedly, this issue was silently addressed by HP in HP security bulletin HPSBUX0208-213.
23. PHPNuke Modules.PHP Search Module Remote Directory Traversal Vulnerability
BugTraq ID: 15137
Remote: Yes
Date Published: 2005-10-19
Relevant URL: http://www.securityfocus.com/bid/15137
Summary:
PHPNuke Search Module is prone to a directory traversal vulnerability. This is due to a lack of proper sanitization of user-supplied input.
A remote attacker may view files that are only intended to be accessible to authenticated and authorized users. Information obtained may be used in further attacks.
24. HP-UX FTP Server Directory Listing Vulnerability
BugTraq ID: 15138
Remote: Yes
Date Published: 2005-10-19
Relevant URL: http://www.securityfocus.com/bid/15138
Summary:
The FTP server included with HP-UX is prone to a vulnerability that may be leveraged by unauthenticated attackers to obtain directory listings.
An attacker does not require authentication credentials to carry out this attack. A successful attack can disclose sensitive information, which may aid in the exploitation of other vulnerabilities.
Reportedly, this issue was silently addressed by HP.
25. Oracle Workflow Multiple Unspecified Cross-Site Scripting Vulnerabilities
BugTraq ID: 15139
Remote: Yes
Date Published: 2005-10-19
Relevant URL: http://www.securityfocus.com/bid/15139
Summary:
Oracle Workflow is prone to multiple unspecified cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Reports indicate these issues were addressed in the Oracle October Critical Patch Update (see BID 15134). However, these issues were not listed in the database matrix of that update.
Due to the availability of more information, this BID has been separated into BID 15145 (Oracle Workflow Wf_monitor Cross-Site Scripting Vulnerability) and BID 15147 (Oracle Workflow Wf_route Cross-Site Scripting Vulnerability). This record is being retired.
26. Yiff-Server File Permission Bypass Weakness
BugTraq ID: 15140
Remote: No
Date Published: 2005-10-19
Relevant URL: http://www.securityfocus.com/bid/15140
Summary:
Yiff-Server is prone to a file permissions bypass weakness. This is due to a design error which allows local users to access the files of other users, regardless of the permissions on the given files.
This vulnerability has been confirmed in version 2.14.5; other versions may also be affected.
27. Paros HSQLDB Remote Authentication Bypass Vulnerability
BugTraq ID: 15141
Remote: Yes
Date Published: 2005-10-19
Relevant URL: http://www.securityfocus.com/bid/15141
Summary:
Paros is prone to a remote authentication bypass vulnerability.
This issue may result in the disclosure of sensitive information, and possible execution of commands on the victim machine.
Paros version 3.2.5 is affected; earlier versions may also be vulnerable.
28. Symantec LiveUpdate for Macintosh Local Privilege Escalation Vulnerability
BugTraq ID: 15142
Remote: No
Date Published: 2005-10-19
Relevant URL: http://www.securityfocus.com/bid/15142
Summary:
Symantec LiveUpdate for Macintosh is affected by a local privilege escalation vulnerability.
A successful attack can allow the attacker to gain complete control over the affected computer.
29. Symantec Norton Antivirus For Macintosh DiskMountNotify Local Privilege Escalation Vulnerability
BugTraq ID: 15143
Remote: No
Date Published: 2005-10-19
Relevant URL: http://www.securityfocus.com/bid/15143
Summary:
Symantec Norton Antivirus for Macintosh is susceptible to a local privilege escalation vulnerability. This issue is due to a failure of the application to properly utilize the PATH environment variable in a setuid-superuser binary.
This vulnerability allows local attackers to gain superuser privileges, leading to complete compromise of the affected computer.
30. Cisco 11500 Content Services Switch Malformed SSL Client Certificate Denial of Service Vulnerability
BugTraq ID: 15144
Remote: Yes
Date Published: 2005-10-19
Relevant URL: http://www.securityfocus.com/bid/15144
Summary:
Cisco 11500 Content Services Switch is prone to a denial of service condition when processing malformed SSL client certificates.
Cisco 11500 Content Services Switch running WebNS operating system versions 7.1 through 7.5 are vulnerable to this issue.
31. Oracle Workflow Wf_monitor Cross-Site Scripting Vulnerability
BugTraq ID: 15145
Remote: Yes
Date Published: 2005-10-19
Relevant URL: http://www.securityfocus.com/bid/15145
Summary:
Oracle Workflow is prone to a cross-site scripting vulnerability.
This issue affects the 'wf_monitor' script.
An attacker may leverage this vulnerability to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
This issue was addressed in Oracle Critical Patch Update - October 2005 BID 15134 (Oracle October Security Update Multiple Vulnerabilities). This issue was also reported in BID 15139 (Oracle Workflow Multiple Unspecified Cross-Site Scripting Vulnerabilities). Due to the availability of more information, this vulnerability is being assigned a new BID.
32. Oracle Application Server 10g emagent.exe Stack Overflow Vulnerability
BugTraq ID: 15146
Remote: Yes
Date Published: 2005-10-20
Relevant URL: http://www.securityfocus.com/bid/15146
Summary:
Oracle Application Server 10g is prone to a buffer overflow. Successful exploitation could allow arbitrary code execution with SYSTEM privileges.
This vulnerability was originally described in Oracle October Security Update Multiple Vulnerabilities (BID 15134). Due to the availability of additional information, it has been assigned its own record.
33. Oracle Workflow Wf_route Cross-Site Scripting Vulnerability
BugTraq ID: 15147
Remote: Yes
Date Published: 2005-10-19
Relevant URL: http://www.securityfocus.com/bid/15147
Summary:
Oracle Workflow is prone to a cross-site scripting vulnerability.
This issue affects the 'wf_route' script.
An attacker may leverage this vulnerability to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
This issue was addressed in Oracle Critical Patch Update - October 2005 BID 15134 (Oracle October Security Update Multiple Vulnerabilities). This issue was also reported in BID 15139 (Oracle Workflow Multiple Unspecified Cross-Site Scripting Vulnerabilities). Due to the availability of more information, this vulnerability is being assigned a new BID.
34. Ethereal Multiple Protocol Dissector Vulnerabilities In Versions Prior To 0.10.13
BugTraq ID: 15148
Remote: Yes
Date Published: 2005-10-19
Relevant URL: http://www.securityfocus.com/bid/15148
Summary:
Several vulnerabilities in Ethereal have been disclosed by the vendor. The reported issues are in various protocol dissectors.
These issues include:
- Buffer overflow vulnerabilities
- Null pointer dereference denial of service vulnerabilities
- Infinite loop denial of service vulnerabilities
- Memory exhaustion denial of service vulnerabilities
- Division by zero denial of service vulnerabilities
- Invalid pointer free() attempt denial of service vulnerabilities
- Unspecified denial of service vulnerabilities
These issues could allow remote attackers to execute arbitrary machine code in the context of the vulnerable application. Attackers could also crash the affected application.
Various vulnerabilities affect differing versions of Ethereal, from 0.7.7, through to 0.10.12.
35. Chipmunk Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 15149
Remote: Yes
Date Published: 2005-10-20
Relevant URL: http://www.securityfocus.com/bid/15149
Summary:
Chipmunk products are prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the applications to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may facilitate the theft of cookie-based authentication credentials as well as other attacks.
36. PHP-Nuke Modules.PHP NukeFixes Addon Remote Directory Traversal Vulnerability
BugTraq ID: 15150
Remote: Yes
Date Published: 2005-10-20
Relevant URL: http://www.securityfocus.com/bid/15150
Summary:
PHP-Nuke NukeFixes Addon is prone to a directory traversal vulnerability. This is due to a lack of proper sanitization of user-supplied input.
A remote attacker may view files that are only intended to be accessible to authenticated and authorized users. Information obtained may be used in further attacks.
37. Debian Module-Assistant Insecure Temporary File Creation Vulnerability
BugTraq ID: 15151
Remote: No
Date Published: 2005-10-20
Relevant URL: http://www.securityfocus.com/bid/15151
Summary:
Debian module-assistant creates temporary files in an insecure manner.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
38. Splatt Forums Remote Authentication Bypass Vulnerability
BugTraq ID: 15152
Remote: Yes
Date Published: 2005-10-20
Relevant URL: http://www.securityfocus.com/bid/15152
Summary:
Splatt Forums is prone to a remote authentication bypass vulnerability.
An attacker may bypass the administrative logon process and make changes to posts with the effective rights of the forum administrator.
39. BMV PostScript File Handling Integer Overflow Vulnerability
BugTraq ID: 15153
Remote: Yes
Date Published: 2005-10-20
Relevant URL: http://www.securityfocus.com/bid/15153
Summary:
BMV is prone to an integer overflow vulnerability.
This issue arises when the application handles a malformed PostScript file.
A successful attack may result in arbitrary code execution leading to unauthorized access. Reports indicate that BMV is installed as setuid root on some distributions by default, which may allow an attacker to gain superuser privileges by exploiting this issue.
40. Linux Kernel World Writable SYSFS DRM Debug File Vulnerability
BugTraq ID: 15154
Remote: No
Date Published: 2005-10-20
Relevant URL: http://www.securityfocus.com/bid/15154
Summary:
Linux kernel is prone to an issue where a world writable file is created in SYSFS. Exploitation could allow an attacker to obtain sensitive information.
41. Linux Kernel IPV6 Unspecified Denial of Service Vulnerability
BugTraq ID: 15156
Remote: Unknown
Date Published: 2005-10-20
Relevant URL: http://www.securityfocus.com/bid/15156
Summary:
Linux Kernel is reported prone to an unspecified denial of service vulnerability.
Reports indicate that this issue arises from an infinite loop and affects the routines responsible for handling IPv6.
No further details are available at the moment. This BID will be updated when more information becomes available.
42. Squid FTP Server Response Denial Of Service Vulnerability
BugTraq ID: 15157
Remote: Yes
Date Published: 2005-10-20
Relevant URL: http://www.securityfocus.com/bid/15157
Summary:
Squid is prone to a remote denial of service vulnerability.
This is due to a flaw in the way that Squid communicates with ftp servers.
This issue has been reported in Squid version 2.5 and prior.
43. Ethereal Service Location Protocol Dissection Stack Buffer Overflow Vulnerability
BugTraq ID: 15158
Remote: Yes
Date Published: 2005-10-20
Relevant URL: http://www.securityfocus.com/bid/15158
Summary:
A remote buffer overflow vulnerability affects Ethereal. This issue is due to a failure of the application to securely copy network-derived data into sensitive process buffers. The specific issue exists in the Service Location Protocol dissector.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
This issue may be exploited by a single TCP packet to port 427, as Ethereal does not keep track of connection states. This allows malicious users to spoof the origin of attacks, as well as exploit this vulnerability when no services are actively listening on TCP port 427.
Note that this issue was originally disclosed in BID 15148 "Ethereal Multiple Protocol Dissector Vulnerabilities In Versions Prior To 0.10.13".
44. SCO UnixWare PPP Prompt Local Buffer Overflow Vulnerability
BugTraq ID: 15159
Remote: No
Date Published: 2005-10-20
Relevant URL: http://www.securityfocus.com/bid/15159
Summary:
SCO UnixWare is prone to a local buffer overflow vulnerability.
The vulnerability presents itself when the application processes excessive data supplied through the Unixware point-to-point protocol (PPP) prompt.
UnixWare 7.1.4 and UnixWare 7.1.3 are reported to be affected by this issue.
45. SCO OpenServer Backupsh Local Buffer Overflow Vulnerability
BugTraq ID: 15160
Remote: No
Date Published: 2005-10-20
Relevant URL: http://www.securityfocus.com/bid/15160
Summary:
backupsh is prone to a local buffer overflow vulnerability.
The vulnerability presents itself when the application processes excessive data, which may corrupt process memory. The specific details about this issue are not currently available.
A successful attack allows arbitrary machine code execution with group backup privileges.
OpenServer 5.0.7 is reported to be affected by this issue.
The authsh utility is also vulnerable to this issue and successful exploitation could result in an attacker gaining group auth privileges.
46. ZipGenius Multiple Archive Formats File Name Buffer Overflow Vulnerabilities
BugTraq ID: 15161
Remote: Yes
Date Published: 2005-10-21
Relevant URL: http://www.securityfocus.com/bid/15161
Summary:
ZipGenius is prone to multiple buffer overflow issues when handling various archive formats.
These issues could be exploited to execute arbitrary code. Arbitrary code execution would occur in the context of the user who is running the application.
ZipGenius versions 5.5.1.468 and 6.0.2.1041 are reported to be vulnerable. Other versions may be affected as well.
47. AL-Caricatier SS.PHP Authentication Bypass Vulnerability
BugTraq ID: 15162
Remote: Yes
Date Published: 2005-10-21
Relevant URL: http://www.securityfocus.com/bid/15162
Summary:
AL-Caricatier is prone to an authentication bypass vulnerability. This is due to a lack of proper validation of user-supplied input by the affected scripts.
This issue may result in the disclosure of sensitive information, and the attacker may gain administrative access to the application or site.
AL-Caricatier version 2.5 and earlier versions are vulnerable.
48. Oracle Application Server HTTP Response Splitting Vulnerability
BugTraq ID: 15163
Remote: Yes
Date Published: 2005-10-21
Relevant URL: http://www.securityfocus.com/bid/15163
Summary:
Oracle Application Server is prone to an HTTP response splitting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
A remote attacker may exploit this vulnerability to influence or misrepresent how Web content is served, cached or interpreted. This could aid in various attacks that attempt to entice client users into a false sense of trust.
This issue was addressed in Oracle Critical Patch Update - October 2005 BID 15134 (Oracle October Security Update Multiple Vulnerabilities). Due to the availability of more information, this vulnerability is being assigned a new BID.
49. TikiWiki Unspecified Cross-Site Scripting Vulnerability
BugTraq ID: 15164
Remote: Yes
Date Published: 2005-10-21
Relevant URL: http://www.securityfocus.com/bid/15164
Summary:
TikiWiki is prone to an unspecified cross-site scripting vulnerability. This is due to a lack of proper sanitization of user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
50. SUSE Linux Squid Proxy SSL Handling Denial of Service Vulnerability
BugTraq ID: 15165
Remote: Yes
Date Published: 2005-10-21
Relevant URL: http://www.securityfocus.com/bid/15165
Summary:
Squid Proxy running on SUSE Linux is affected by a denial of service vulnerability.
Reports indicate that this issue arises when the application handles specially crafted HTTPS data. Due to the nature of the application, it is conjectured that this vulnerability poses a remote threat.
Successful exploitation may cause the service to crash.
SUSE Linux 9.0 is reported to be vulnerable to this issue.
This BID will be updated when more information is available.
51. Nuked Klan Multiple HTML Injection Vulnerabilities
BugTraq ID: 15166
Remote: Yes
Date Published: 2005-10-21
Relevant URL: http://www.securityfocus.com/bid/15166
Summary:
Nuked Klan is prone to multiple HTML injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit these issues to control how the site is rendered to the user; other attacks are also possible.
52. BMC Control M Agent Insecure File Permission Vulnerability
BugTraq ID: 15167
Remote: No
Date Published: 2005-10-22
Relevant URL: http://www.securityfocus.com/bid/15167
Summary:
BMC Control M Agent creates temporary files in an insecure manner.
The application creates temporary files in an insecure manner. An attacker with local access could potentially exploit this issue to overwrite files in the context of the application.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
BMC Control M Agent version 6.1.03 is affected; earlier version may also be affected.
53. Zomplog Detail.PHP HTML Injection Vulnerability
BugTraq ID: 15168
Remote: Yes
Date Published: 2005-10-22
Relevant URL: http://www.securityfocus.com/bid/15168
Summary:
Zomplog is prone to an HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
Zomplog version 3.4 and earlier are affected by this vulnerability.
54. phpMyAdmin Theme Variable Local File Inclusion Vulnerability
BugTraq ID: 15169
Remote: Yes
Date Published: 2005-10-22
Relevant URL: http://www.securityfocus.com/bid/15169
Summary:
phpMyAdmin is prone to a local file include vulnerability.
An attacker may leverage this issue to execute arbitrary server-side script code that resides on an affected computer with the privileges of the Web server process. This may potentially facilitate unauthorized access.
phpMyAdmin 2.6.4-pl2 and earlier versions are reported to be vulnerable.
55. phpBB Avatar Upload HTML Injection Vulnerability
BugTraq ID: 15170
Remote: Yes
Date Published: 2005-10-22
Relevant URL: http://www.securityfocus.com/bid/15170
Summary:
phpBB is prone to an HTML injection vulnerability. This is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
This issue is only present when using the Microsoft Internet Explorer Web browser.
56. eBASEweb Unspecified SQL Injection Vulnerability
BugTraq ID: 15171
Remote: Yes
Date Published: 2005-10-22
Relevant URL: http://www.securityfocus.com/bid/15171
Summary:
eBASEweb is prone to an unspecified SQL injecgtion vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
No further details have been provided.
57. FlatNuke Index.PHP Multiple Remote File Include Vulnerabilities
BugTraq ID: 15172
Remote: Yes
Date Published: 2005-10-22
Relevant URL: http://www.securityfocus.com/bid/15172
Summary:
FlatNuke is prone to multiple remote file include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage any of these issues to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
It should be noted that a malicious user must have an account and be logged into the application to exploit these vulnerabilities.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Web defacer sentenced, facing deportation
By: Robert Lemos
After agreeing to plead guilty to defacing an Air Force Web site, Rafael Nuñez-Aponte gets time served, but possible charges regarding leaked NASA documents could be in the wings.
http://www.securityfocus.com/news/11350
2. Snort vulnerability "wormable" but not widespread
By: Robert Lemos
A three-month-old flaw in a preprocessor function for the open-source intrusion detection system may attract worm writers, but the number of vulnerable systems is thought to be low.
http://www.securityfocus.com/news/11349
3. Worm worries don't wait for Windows exploits
By: Robert Lemos
Security researchers disagree over whether a recently announced flaw in Microsoft Windows will likely become food for an Internet worm.
http://www.securityfocus.com/news/11346
4. Arrests unlikely to impact bot net threat, say experts
By: Robert Lemos
The recent arrests of three men in The Netherlands who allegedly controlled a network of more than 100,000 compromised computers will not likely curtail the criminal economy surrounding bot nets.
http://www.securityfocus.com/news/11344
5. Say hello to the Skype Trojan
By: John Leyden
Virus writers are targeting Skype users with a new Trojan that poses as the latest version of the popular VoIP software.
http://www.securityfocus.com/news/11348
6. Shared music abuse bug hits iTunes
By: John Leyden
Security researchers have discovered a vulnerability in Apple's popular iTunes application which might be exploited to interfere with shared music downloads.
http://www.securityfocus.com/news/11347
7. US cybersecurity all at sea
By: John Leyden
US cybersecurity risks are being poorly managed by the Department of Homeland Security, according to a former US presidential information security advisor.
http://www.securityfocus.com/news/11345
8. Worm fears over MS October patch batch
By: John Leyden
Microsoft's patch train rolled into town on Tuesday carrying a cargo of nine updates.
http://www.securityfocus.com/news/11342
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Quality Assurance, New York
http://www.securityfocus.com/archive/77/414651
2. [SJ-JOB] Security Researcher, Redwood City, CA; Santa Monica, CA; Waltham, MA; Herndon, VA
http://www.securityfocus.com/archive/77/414654
3. [SJ-JOB] Security Researcher, Redwood City, CA; Santa Monica, CA; Waltham, MA; Herndon, VA
http://www.securityfocus.com/archive/77/414655
4. [SJ-JOB] Sr. Security Analyst, Reading, Berkshire
http://www.securityfocus.com/archive/77/414650
5. [SJ-JOB] Disaster Recovery Coordinator, Silver Spring
http://www.securityfocus.com/archive/77/414653
6. [SJ-JOB] Developer, Columbia
http://www.securityfocus.com/archive/77/414499
7. [SJ-JOB] Security Architect, Alexandria
http://www.securityfocus.com/archive/77/414500
8. [SJ-JOB] Developer, Hyderabad
http://www.securityfocus.com/archive/77/414566
9. [SJ-JOB] Security Engineer, Hyderabad
http://www.securityfocus.com/archive/77/414570
10. [SJ-JOB] Sr. Security Engineer, Washington
http://www.securityfocus.com/archive/77/414405
11. [SJ-JOB] Sales Engineer, Vienna
http://www.securityfocus.com/archive/77/414407
12. [SJ-JOB] Application Security Engineer, Vienna
http://www.securityfocus.com/archive/77/414408
13. [SJ-JOB] Sales Engineer, Any US location
http://www.securityfocus.com/archive/77/414403
14. [SJ-JOB] Sales Engineer, Scottsdale
http://www.securityfocus.com/archive/77/414404
15. [SJ-JOB] Security Engineer, Reston/Dulles
http://www.securityfocus.com/archive/77/414126
16. [SJ-JOB] Security Consultant, London
http://www.securityfocus.com/archive/77/414123
17. [SJ-JOB] Forensics Engineer, London
http://www.securityfocus.com/archive/77/414124
18. [SJ-JOB] Manager, Information Security, Kent
http://www.securityfocus.com/archive/77/414121
19. [SJ-JOB] Security Engineer, GTA - Markham
http://www.securityfocus.com/archive/77/414122
20. [SJ-JOB] Sales Engineer, Sunnyvale
http://www.securityfocus.com/archive/77/413991
21. [SJ-JOB] Sr. Security Engineer, Mountain View
http://www.securityfocus.com/archive/77/413992
22. [SJ-JOB] Forensics Engineer, Duesseldorf / Muenchen
http://www.securityfocus.com/archive/77/413986
23. [SJ-JOB] Security Product Manager, Allentown
http://www.securityfocus.com/archive/77/413987
24. [SJ-JOB] Technology Risk Consultant, London
http://www.securityfocus.com/archive/77/413989
25. [SJ-JOB] Director, Information Security, London
http://www.securityfocus.com/archive/77/413988
26. [SJ-JOB] Compliance Officer, London
http://www.securityfocus.com/archive/77/413990
27. [SJ-JOB] Regional Channel Manager, New York
http://www.securityfocus.com/archive/77/413975
28. [SJ-JOB] Quality Assurance, Milpitas
http://www.securityfocus.com/archive/77/413976
29. [SJ-JOB] Developer, Sunnyvale
http://www.securityfocus.com/archive/77/413977
30. [SJ-JOB] CHECK Team Leader, Manchester
http://www.securityfocus.com/archive/77/413973
31. [SJ-JOB] Management, Redwood City
http://www.securityfocus.com/archive/77/413974
32. [SJ-JOB] Security Engineer, Acton
http://www.securityfocus.com/archive/77/413888
33. [SJ-JOB] Sales Engineer, Miami
http://www.securityfocus.com/archive/77/413891
34. [SJ-JOB] Security Engineer, New York
http://www.securityfocus.com/archive/77/413892
35. [SJ-JOB] Security Engineer, Rockville
http://www.securityfocus.com/archive/77/413889
36. [SJ-JOB] Security Engineer, Staines, Middlesex
http://www.securityfocus.com/archive/77/413890
V. INCIDENTS LIST SUMMARY
---------------------------
1. Who is looking for port 2036?
http://www.securityfocus.com/archive/75/414542
2. SSH bruteforce on its way...
http://www.securityfocus.com/archive/75/413877
3. Dismantling Botnets?
http://www.securityfocus.com/archive/75/413832
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. problem in rewrite RET address in Buffer OverFlow
http://www.securityfocus.com/archive/82/414557
2. Vulnerability Assesment tools(Vuln testing tools)
http://www.securityfocus.com/archive/82/414512
3. MS05-047 remote DOS (exploit code attached; compiles on linux)
http://www.securityfocus.com/archive/82/414360
4. Oracle 10g - emagent.exe Stack-Based Overflow
http://www.securityfocus.com/archive/82/413982
5. Vulnerability Buyer Company
http://www.securityfocus.com/archive/82/413980
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. CFP: The First International Conference on Availability, Reliability and Security (AReS 2006), 20-22 April, 2006, Vienna, Austria
http://www.securityfocus.com/archive/88/414510
2. Change Password
http://www.securityfocus.com/archive/88/414507
3. Account Lockout Policy
http://www.securityfocus.com/archive/88/414529
4. security policy 'not specified' option
http://www.securityfocus.com/archive/88/413995
5. FW: Account Lockout Policy
http://www.securityfocus.com/archive/88/413993
6. Account Lockout Policy
http://www.securityfocus.com/archive/88/413952
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. httpd and port 7200
http://www.securityfocus.com/archive/91/414099
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XI. SPONSOR INFORMATION
------------------------
Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!
http://www.securityfocus.com/sponsor/Symantec_sf-news_041130