SecurityFocus Newsletter #322

Peter Laborge <[email protected]> Tue, 01 Nov 2005 21:28:29 -0700
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #322
----------------------------------------

This Issue is Sponsored By: Watchfire AppScan

Firewalls and SSL may be commonplace today, but websites still remain vulnerable to attack. That's because application security differs from network security, and traditional approaches don't apply. Address Application Security Challenges -- download this white paper today.

https://www.watchfire.com/securearea/whitepapers.aspx?id=701300000002gRE

------------------------------------------------------------------
I.    FRONT AND CENTER
       1. Balancing surveillance
II.   BUGTRAQ SUMMARY
       1. BMC Control M Agent Insecure File Permission Vulnerability
       2. Zomplog Detail.PHP HTML Injection Vulnerability
       3. phpMyAdmin Theme Variable Local File Inclusion Vulnerability
       4. phpBB Avatar Upload HTML Injection Vulnerability
       5. eBASEweb Unspecified SQL Injection Vulnerability
       6. FlatNuke Index.PHP Multiple Remote File Include Vulnerabilities
       7. TriggerTG TClanPortal Index.PHP SQL Injection Vulnerability
       8. Platinum DBoardGear Multiple SQL Injection Vulnerabilities
       9. PunBB Common.PHP Remote File Include Vulnerability
       10. FlatNuke Index.PHP Cross-Site Scripting Vulnerability
       11. PHP Apache 2 Local Denial of Service Vulnerability
       12. PHPNuke Multiple Modules SQL Injection Vulnerabilities
       13. Fetchmail's FetchmailConf Utility Local Information Disclosure Vulnerability
       14. Nuked Klan Multiple SQL Injection Vulnerabilities
       15. SUSE Linux Permissions Package CHKSTAT Insecure Permissions Handling Vulnerability
       16. DCP-Portal Multiple Input Validation Vulnerabilities
       17. SAPHP Lesson Multiple Input Validation Vulnerabilities
       18. SiteTurn Domain Manager Pro Admin Panel Cross-Site Scripting Vulnerability
       19. PHP-Fusion Message Post HTML Injection Vulnerability
       20. Symantec Discovery Web Accounts Default Password Vulnerability
       21. Multiple Vendor Anti-Virus Magic Byte Detection Evasion Vulnerability
       22. Skype Technologies Skype Multiple Buffer Overflow Vulnerabilities
       23. Todd Miller Sudo Local Privilege Escalation Vulnerability
       24. Skype Technologies Skype Networking Routine Heap Overflow Vulnerability
       25. PHP ICalendar Default_View Remote File Include Vulnerability
       26. Platinum DBoardGear Theme Import SQL Injection Vulnerability
       27. XOOPS Multiple HTML Injection Vulnerabilities
       28. Network Appliance iSCSI Authentication Bypass Vulnerability
       29. Basic Analysis And Security Engine Base_qry_main.PHP SQL Injection Vulnerability
       30. LibGDA Multiple Format String Vulnerabilities
       31. AR-Blog Comment HTML Injection Vulnerability 
       32. SparkleBlog Multiple HTML Injection Vulnerabilities
       33. AR-Blog Remote Authentication Bypass Vulnerability
       34. MyBulletinBoard Usercp.PHP SQL Injection Vulnerability
       35. IPBProArcade GameID Parameter Remote SQL Injection Vulnerability
       36. RSA ACE Agent Image Cross-Site Scripting Vulnerability
       37. Belchior Foundry VCard Remote File Include Vulnerability
       38. Microsoft Internet Explorer Java Applet Denial of Service Vulnerability
       39. Flyspray Multiple Cross-Site Scripting Vulnerabilities
       40. Mantis Multiple Unspecified SQL Injection Vulnerabilities 
       41. Jed Wing CHM Lib Stack Buffer Overflow Vulnerability
       42. Mantis Bug_sponsorship_list_view_inc.PHP File Include Vulnerability
       43. Snoopy Arbitrary Command Execution Vulnerability
       44. Woltlab Info-DB Info_db.PHP  Multiple SQL Injection Vulnerabilities
       45. Techno Dreams Multiple Scripts Multiple SQL Injection Vulnerabilities
       46. GCards News.PHP SQL Injection Vulnerability
       47. PAM Unix_Chkpwd Unauthorized Access Vulnerability
       48. Search Enhanced Module for PHP-Nuke HTML Injection Vulnerability
       49. Ethereal IRC Protocol Dissector Denial of Service Vulnerability
       50. Novell ZENworks Patch Management Multiple SQL Injection Vulnerabilities
       51. ATutor Multiple Input Validation Vulnerabilities
       52. Sun Solaris Management Console HTTP TRACE Information Disclosure Vulnerability
       53. PBLang Multiple Cross-Site Scripting Vulnerabilities
       54. Apache Mod_Auth_Shadow Authentication Bypass Vulnerability 
       55. Hasbani Web Server Malformed HTTP GET Request Remote Denial of Service Vulnerability
       56. GNU gnump3d Error Page Cross-Site Scripting Vulnerability
       57. Mantis Multiple Remote Vulnerabilities
       58. GNU gnump3d Directory Traversal Vulnerability
       59. Rockliffe MailSite Express Arbitrary Script File Upload Vulnerability
       60. Rockliffe MailSite Express Information Disclosure Vulnerability
       61. PHPESP Multiple Unspecified Input Validation Vulnerabilities
       62. ASP Fast Forum Error.ASP Cross-Site Scripting Vulnerability
       63. Jed Wing CHM Lib _chm_find_in_PMGL Stack Buffer Overflow Vulnerability
       64. MG2 Authentication Bypass Vulnerability
       65. Hyper Estraier Remote Information Disclosure Vulnerability
       66. PHP Advanced Transfer Manager Remote Unauthorized Access Vulnerability
       67. Subdreamer Multiple Remote SQL Injection Vulnerabilities
III.  SECURITYFOCUS NEWS
       1. U.S. makes securing SCADA systems a priority
       2. Web defacer sentenced, facing deportation 
       3. Snort vulnerability "wormable" but not widespread
       4. Worm worries don't wait for Windows exploits
       5. Say hello to the Skype Trojan
       6. Shared music abuse bug hits iTunes
       7. US cybersecurity all at sea
       8. Worm fears over MS October patch batch
IV.   SECURITY JOBS LIST SUMMARY
       1. [SJ-JOB] Security Engineer, Independence
       2. [SJ-JOB] Auditor, London
       3. [SJ-JOB] Application Security Engineer, Toronto
       4. [SJ-JOB] Jr. Security Analyst, Austin
       5. [SJ-JOB] Security System Administrator, San Diego
       6. [SJ-JOB] Sr. Security Engineer, Crystal Lake
       7. [SJ-JOB] Security Engineer, Seattle
       8. [SJ-JOB] Developer, Redwood City
       9. [SJ-JOB] Director, Information Security, Atlanta
       10. [SJ-JOB] Director, Computer Security, Rockford
       11. [SJ-JOB] Security System Administrator, ALL
       12. [SJ-JOB] Sales Engineer, ALL
       13. [SJ-JOB] Sr. Security Analyst, Cupertino
       14. [SJ-JOB] Sales Engineer, New York (various other locations)
       15. [SJ-JOB] CHECK Team Leader, London
       16. [SJ-JOB] Jr. Security Analyst, Walnut Creek
       17. [SJ-JOB] Application Security Engineer, NYC/DC/LA/Seattle/Bay Area
       18. [SJ-JOB] Security Researcher, Bellevue
       19. [SJ-JOB] Security System Administrator, san francisco
       20. [SJ-JOB] Security Consultant, new york
       21. [SJ-JOB] Sr. Security Engineer, Washington
       22. [SJ-JOB] Sales Engineer, New York
       23. [SJ-JOB] Security Consultant, Anywhere in the states
       24. [SJ-JOB] Security System Administrator, Dallas
       25. [SJ-JOB] Security Consultant, New York City
       26. [SJ-JOB] Technical Support Engineer, Chennai
       27. [SJ-JOB] Information Assurance Analyst, Arlington, VA; Lanham,    MD; Herndon, VA
       28. [SJ-JOB] Security Consultant, Austin
       29. [SJ-JOB] Security Consultant, Charlotte
       30. [SJ-JOB] Regional Channel Manager, San Francisco
       31. [SJ-JOB] Compliance Officer, Warren
       32. [SJ-JOB] Information Assurance Analyst, New York
       33. [SJ-JOB] Sales Representative, Atlanta
       34. [SJ-JOB] Quality Assurance, New York
       35. [SJ-JOB] Security Researcher, Redwood City, CA; Santa Monica, CA;    Waltham, MA; Herndon, VA
       36. [SJ-JOB] Security Researcher, Redwood City, CA; Santa Monica, CA;    Waltham, MA; Herndon, VA
       37. [SJ-JOB] Sr. Security Analyst, Reading, Berkshire
       38. [SJ-JOB] Disaster Recovery Coordinator, Silver Spring
V.    INCIDENTS LIST SUMMARY
       1. ICMP Type:8 Code:137
       2. moderator note: AIM worm...
       3. Fw: troj_cryt.u detected
       4. - AIM virus / worm
       5. AIM virus / worm
       6. Moderator's note: SSH bruteforce on its way..
       7. Who is looking for port 2036?
       8. Dismantling Botnets?
VI.   VULN-DEV RESEARCH LIST SUMMARY
       1. EUSecWest/London Call for Papers and PacSec/Tokyo announcements
       2. New List
       3. Question on new umpnpmgr wsprinfW buffer overflow
       4. Multiple vulnerabilities within RockLiffe MailSite Express WebMail
       5. problem in rewrite RET address in Buffer OverFlow
       6. Vulnerability Assesment tools(Vuln testing tools)
VII.  MICROSOFT FOCUS LIST SUMMARY
       1. Invitation to Join the Collaborative Endpoint Security Project, sponsored by Core Security Technologies
       2. New List - Beta-Announce
       3. SecurityFocus Microsoft Newsletter #262
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Balancing surveillance
By Scott Granneman
With camera and network surveillance now commonplace, and database abuse continuing to appear, how do we balance the positive side of security along with its potential for abuse?
http://www.securityfocus.com/columnists/366


II.  BUGTRAQ SUMMARY
--------------------
1. BMC Control M Agent Insecure File Permission Vulnerability
BugTraq ID: 15167
Remote: No
Date Published: 2005-10-22
Relevant URL: http://www.securityfocus.com/bid/15167
Summary:
BMC Control M Agent creates temporary files in an insecure manner.

The application creates temporary files in an insecure manner.  An attacker with local access could potentially exploit this issue to overwrite files in the context of the application. 

Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.

BMC Control M Agent version 6.1.03 is affected; earlier version may also be affected.


2. Zomplog Detail.PHP HTML Injection Vulnerability
BugTraq ID: 15168
Remote: Yes
Date Published: 2005-10-22
Relevant URL: http://www.securityfocus.com/bid/15168
Summary:
Zomplog is prone to an HTML injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

Zomplog version 3.4 and earlier are affected by this vulnerability.


3. phpMyAdmin Theme Variable Local File Inclusion Vulnerability
BugTraq ID: 15169
Remote: Yes
Date Published: 2005-10-22
Relevant URL: http://www.securityfocus.com/bid/15169
Summary:
phpMyAdmin is prone to a local file include vulnerability.

An attacker may leverage this issue to execute arbitrary server-side script code that resides on an affected computer with the privileges of the Web server process. This may potentially facilitate unauthorized access. 

phpMyAdmin 2.6.4-pl2 and earlier versions are reported to be vulnerable.


4. phpBB Avatar Upload HTML Injection Vulnerability
BugTraq ID: 15170
Remote: Yes
Date Published: 2005-10-22
Relevant URL: http://www.securityfocus.com/bid/15170
Summary:
phpBB is prone to an HTML injection vulnerability. This is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content. 

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

This issue is only present when using the Microsoft Internet Explorer Web browser.


5. eBASEweb Unspecified SQL Injection Vulnerability
BugTraq ID: 15171
Remote: Yes
Date Published: 2005-10-22
Relevant URL: http://www.securityfocus.com/bid/15171
Summary:
eBASEweb is prone to an unspecified SQL injecgtion vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

No further details have been provided.


6. FlatNuke Index.PHP Multiple Remote File Include Vulnerabilities
BugTraq ID: 15172
Remote: Yes
Date Published: 2005-10-22
Relevant URL: http://www.securityfocus.com/bid/15172
Summary:
FlatNuke is prone to multiple remote file include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage any of these issues to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.

It should be noted that a malicious user must have an account and be logged into the application to exploit these vulnerabilities.

7. TriggerTG TClanPortal Index.PHP SQL Injection Vulnerability
BugTraq ID: 15173
Remote: Yes
Date Published: 2005-10-24
Relevant URL: http://www.securityfocus.com/bid/15173
Summary:
TClanPortal is prone to an SQL injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

8. Platinum DBoardGear Multiple SQL Injection Vulnerabilities
BugTraq ID: 15174
Remote: Yes
Date Published: 2005-10-24
Relevant URL: http://www.securityfocus.com/bid/15174
Summary:
DBoardGear is prone to multiple SQL injection vulnerabilities.

These vulnerabilities could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks. 

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

9. PunBB Common.PHP Remote File Include Vulnerability
BugTraq ID: 15175
Remote: Yes
Date Published: 2005-10-24
Relevant URL: http://www.securityfocus.com/bid/15175
Summary:
PunBB is affected by a file include vulnerability.

An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access; other attacks may also be possible.

It has been determined that this issue is identical to the vulnerability described in BID 10760 (Nucleus CMS/Blog:CMS/PunBB Common.PHP Remote File Include Vulnerability).  This record is being retired.

10. FlatNuke Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 15176
Remote: Yes
Date Published: 2005-10-26
Relevant URL: http://www.securityfocus.com/bid/15176
Summary:
FlatNuke is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.


11. PHP Apache 2 Local Denial of Service Vulnerability
BugTraq ID: 15177
Remote: No
Date Published: 2005-10-24
Relevant URL: http://www.securityfocus.com/bid/15177
Summary:
PHP is prone to a local denial of service vulnerability when it is used as an Apache 2 module.

Reports indicate that due to a bug in apache2handler SAPI of 'sapi_apache2.c' file, this issue triggers a segmentation fault and leads to a crash in the server.

This issue affects PHP versions prior to 5.1.0 final and 4.4.1 final.

12. PHPNuke Multiple Modules SQL Injection Vulnerabilities
BugTraq ID: 15178
Remote: Yes
Date Published: 2005-10-24
Relevant URL: http://www.securityfocus.com/bid/15178
Summary:
PHPNuke is prone to multiple SQL injection vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

13. Fetchmail's FetchmailConf Utility Local Information Disclosure Vulnerability
BugTraq ID: 15179
Remote: No
Date Published: 2005-10-24
Relevant URL: http://www.securityfocus.com/bid/15179
Summary:
Fetchmail is susceptible to an information disclosure vulnerability. This issue is due to a race condition in the 'fetchmailconf' configuration utility.

This issue allows local attackers to gain access to potentially sensitive information, including email authentication credentials, aiding them in further attacks.

Versions of Fetchmail prior to 6.2.9-rc6 include a vulnerable version of 'fetchmailconf'. 'fetchmailconf' version prior to 1.43.2 and 1.49 are vulnerable.

14. Nuked Klan Multiple SQL Injection Vulnerabilities
BugTraq ID: 15181
Remote: Yes
Date Published: 2005-10-24
Relevant URL: http://www.securityfocus.com/bid/15181
Summary:
Nuked Klan is prone to multiple SQL injection vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

These vulnerabilities could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks. 

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.


15. SUSE Linux Permissions Package CHKSTAT Insecure Permissions Handling Vulnerability
BugTraq ID: 15182
Remote: No
Date Published: 2005-10-24
Relevant URL: http://www.securityfocus.com/bid/15182
Summary:
The SUSE Linux 'permissions' package is susceptible to a local information disclosure vulnerability. This issue is due to improper handling of file permissions by the 'chkstat' utility.

This issue is due to the inherent insecurity of attempting to modify files contained in world-writable directories.

Local attackers may gain access to the contents of potentially sensitive files, aiding them in further attacks.

16. DCP-Portal Multiple Input Validation Vulnerabilities
BugTraq ID: 15183
Remote: Yes
Date Published: 2005-10-24
Relevant URL: http://www.securityfocus.com/bid/15183
Summary:
DCP-Portal is prone to multiple cross-site scripting and SQL injection vulnerabilities.

Exploitation could allow for theft of cookie-based authentication credentials or unauthorized access to database data. Other attacks are also possible.


17. SAPHP Lesson Multiple Input Validation Vulnerabilities
BugTraq ID: 15185
Remote: Yes
Date Published: 2005-10-26
Relevant URL: http://www.securityfocus.com/bid/15185
Summary:
saphp Lesson is prone to multiple SQL injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

18. SiteTurn Domain Manager Pro Admin Panel Cross-Site Scripting Vulnerability
BugTraq ID: 15186
Remote: Yes
Date Published: 2005-10-24
Relevant URL: http://www.securityfocus.com/bid/15186
Summary:
Domain Manager Pro is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

19. PHP-Fusion Message Post HTML Injection Vulnerability
BugTraq ID: 15187
Remote: Yes
Date Published: 2005-10-24
Relevant URL: http://www.securityfocus.com/bid/15187
Summary:
PHP-Fusion is prone to an HTML injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.


20. Symantec Discovery Web Accounts Default Password Vulnerability
BugTraq ID: 15188
Remote: Yes
Date Published: 2005-10-25
Relevant URL: http://www.securityfocus.com/bid/15188
Summary:
Symantec Discovery is prone to a vulnerability regarding the installation password.

Remote and local attackers can exploit this issue to gain access to the database without requiring a valid password.  This may facilitate further attacks against the database and possibly the underlying system.

21. Multiple Vendor Anti-Virus Magic Byte Detection Evasion Vulnerability
BugTraq ID: 15189
Remote: Yes
Date Published: 2005-10-25
Relevant URL: http://www.securityfocus.com/bid/15189
Summary:
Multiple vendor anti-virus software is prone to a detection evasion vulnerability.

The problem presents itself in the way various anti-virus software determines the type of file it is scanning.

An attacker can exploit this vulnerability to pass malicious files passed the anti-virus software.  This results in a false sense of security, and ultimately could lead to the execution of arbitrary code on the victim user's machine.

22. Skype Technologies Skype Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 15190
Remote: Yes
Date Published: 2005-10-25
Relevant URL: http://www.securityfocus.com/bid/15190
Summary:
Skype is prone to multiple buffer overflow vulnerabilities.  Successful exploitation of these issues could result in a denial of service or arbitrary code execution in the context of the user running the application.

These issues affect Skype for Windows releases 1.1.*.0 through 1.4.*.83.


23. Todd Miller Sudo Local Privilege Escalation Vulnerability
BugTraq ID: 15191
Remote: No
Date Published: 2005-10-25
Relevant URL: http://www.securityfocus.com/bid/15191
Summary:
Sudo is prone to a local privilege escalation vulnerability.

The vulnerability presents itself because the application does not properly sanitize malicious data provided through environment variables.

A successful attack may result in a complete compromise.

24. Skype Technologies Skype Networking Routine Heap Overflow Vulnerability
BugTraq ID: 15192
Remote: Yes
Date Published: 2005-10-25
Relevant URL: http://www.securityfocus.com/bid/15192
Summary:
Skype is prone to a heap overflow vulnerability in its networking routines.  Successful exploitation could result in a denial of service and remote machine code execution in the context of the affected application.

The vendor reports that this vulnerability has not been reproduced to execute arbitrary code, but the reporter of this issue states that they have successfully created proof of concept exploits against the Microsoft Windows and Linux client applications.

This issue affects Skype for Windows 1.4.*.83 and earlier, Skype for Mac OS X 1.3.*.16 and earlier, Skype for Linux 1.2.*.17 and earlier, and Skype for Pocket PC 1.1.*.6 and earlier.


25. PHP ICalendar Default_View Remote File Include Vulnerability
BugTraq ID: 15193
Remote: Yes
Date Published: 2005-10-25
Relevant URL: http://www.securityfocus.com/bid/15193
Summary:
PHP iCalendar is prone to a remote file include vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to execute arbitrary remote PHP code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.

26. Platinum DBoardGear Theme Import SQL Injection Vulnerability
BugTraq ID: 15194
Remote: Yes
Date Published: 2005-10-25
Relevant URL: http://www.securityfocus.com/bid/15194
Summary:
DBoardGear is prone to an SQL injection vulnerability.

This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query when a theme is being imported. 

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

27. XOOPS Multiple HTML Injection Vulnerabilities
BugTraq ID: 15195
Remote: Yes
Date Published: 2005-10-25
Relevant URL: http://www.securityfocus.com/bid/15195
Summary:
XOOPS is prone to multiple HTML injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit these issues to control how the site is rendered to the user; other attacks are also possible.



28. Network Appliance iSCSI Authentication Bypass Vulnerability
BugTraq ID: 15197
Remote: Yes
Date Published: 2005-10-25
Relevant URL: http://www.securityfocus.com/bid/15197
Summary:
Network Appliance's iSCSI implementation is susceptible to an authentication bypass vulnerability.

This issue allows attackers to bypass iSCSI authentication, allowing them to read/write arbitrary data contained in iSCSI volumes. Access to potentially sensitive information will aid them in further attacks. Data destruction and alteration is also possible.

Unmapped LUNs, and LUNs mapped for use by only Fibre Channel initiators are not vulnerable to this issue.

Versions 6.4, 6.5, and 7.0 are reported vulnerable to this issue; other versions may also be affected.

29. Basic Analysis And Security Engine Base_qry_main.PHP SQL Injection Vulnerability
BugTraq ID: 15199
Remote: Yes
Date Published: 2005-10-25
Relevant URL: http://www.securityfocus.com/bid/15199
Summary:
Basic Analysis And Security Engine is prone to an SQL injection vulnerability.
This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.


30. LibGDA Multiple Format String Vulnerabilities
BugTraq ID: 15200
Remote: No
Date Published: 2005-10-25
Relevant URL: http://www.securityfocus.com/bid/15200
Summary:
libgda is prone to multiple format string vulnerabilities.  These issues arise due to insufficient sanitization of user-supplied data.

Very little information is available on these issues.  This BID will be updated as more information becomes available.

31. AR-Blog Comment HTML Injection Vulnerability 
BugTraq ID: 15201
Remote: Yes
Date Published: 2005-10-25
Relevant URL: http://www.securityfocus.com/bid/15201
Summary:
ar-blog is prone to an HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.


32. SparkleBlog Multiple HTML Injection Vulnerabilities
BugTraq ID: 15202
Remote: Yes
Date Published: 2005-10-25
Relevant URL: http://www.securityfocus.com/bid/15202
Summary:
SparkleBlog is prone to multiple HTML injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit these issue to control how the site is rendered to the user; other attacks are also possible.


33. AR-Blog Remote Authentication Bypass Vulnerability
BugTraq ID: 15203
Remote: Yes
Date Published: 2005-10-25
Relevant URL: http://www.securityfocus.com/bid/15203
Summary:
ar-blog is prone to an authentication bypass vulnerability.

An attacker may bypass the authentication process and make changes to posts with the effective rights of the Web log administrator.

Version 5.2 and prior are reported to be vulnerable.


34. MyBulletinBoard Usercp.PHP SQL Injection Vulnerability
BugTraq ID: 15204
Remote: Yes
Date Published: 2005-10-26
Relevant URL: http://www.securityfocus.com/bid/15204
Summary:
MyBulletinBoard is prone to an SQL injection vulnerability.

This vulnerability could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks. 

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.  Reports indicate that an attacker can gain administrative access by exploiting this issue.

35. IPBProArcade GameID Parameter Remote SQL Injection Vulnerability
BugTraq ID: 15205
Remote: Yes
Date Published: 2005-10-26
Relevant URL: http://www.securityfocus.com/bid/15205
Summary:
A remote SQL injection vulnerability reportedly affects ipbProArcade.

The problem affects the 'gameid' parameter. 

An attacker may leverage this issue to manipulate SQL query strings and potentially carry out arbitrary database queries. This may facilitate the disclosure or corruption of sensitive database information.

36. RSA ACE Agent Image Cross-Site Scripting Vulnerability
BugTraq ID: 15206
Remote: Yes
Date Published: 2005-10-26
Relevant URL: http://www.securityfocus.com/bid/15206
Summary:
RSA ACE Agent is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

37. Belchior Foundry VCard Remote File Include Vulnerability
BugTraq ID: 15207
Remote: Yes
Date Published: 2005-10-26
Relevant URL: http://www.securityfocus.com/bid/15207
Summary:
vCard is prone to a remote file include vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to execute arbitrary remote PHP code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.

38. Microsoft Internet Explorer Java Applet Denial of Service Vulnerability
BugTraq ID: 15208
Remote: Yes
Date Published: 2005-10-26
Relevant URL: http://www.securityfocus.com/bid/15208
Summary:
Microsoft Internet Explorer is affected by a denial of service vulnerability. This issue arises because the application fails to handle exceptional conditions in a proper manner. This issue only presents itself when the J2SE Java runtime environment is installed.

An attacker may exploit this issue by enticing a user to visit a malicious site resulting in a denial of service condition in the application. 

Microsoft Internet Explorer 6 SP2 is affected by this issue.

39. Flyspray Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 15209
Remote: Yes
Date Published: 2005-10-26
Relevant URL: http://www.securityfocus.com/bid/15209
Summary:
Flyspray is prone to multiple cross-site scripting vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

40. Mantis Multiple Unspecified SQL Injection Vulnerabilities 
BugTraq ID: 15210
Remote: Yes
Date Published: 2005-10-26
Relevant URL: http://www.securityfocus.com/bid/15210
Summary:
Mantis is prone to multiple unspecified SQL injection vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

Versions 0.19.2 and 1.0.0rc2 are reported to be vulnerable; an upgrade to 0.19.3 is available.


41. Jed Wing CHM Lib Stack Buffer Overflow Vulnerability
BugTraq ID: 15211
Remote: Yes
Date Published: 2005-10-26
Relevant URL: http://www.securityfocus.com/bid/15211
Summary:
CHM lib is susceptible to a buffer overflow vulnerability. This issue is due to a failure of the library to properly bounds check input data prior to copying it into an insufficiently sized memory buffer.

This issue allows attackers to execute arbitrary machine code in the context of the application that utilizes the CHM lib library.

This issue is present in versions 0.36 and prior of the library.

42. Mantis Bug_sponsorship_list_view_inc.PHP File Include Vulnerability
BugTraq ID: 15212
Remote: Yes
Date Published: 2005-10-26
Relevant URL: http://www.securityfocus.com/bid/15212
Summary:
Mantis is prone to a remote and local file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to execute arbitrary remote and local PHP code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.

Versions 0.19.2 and 1.0.0rc2 are affected; an upgrade to version 0.19.3 is available.


43. Snoopy Arbitrary Command Execution Vulnerability
BugTraq ID: 15213
Remote: Yes
Date Published: 2005-10-26
Relevant URL: http://www.securityfocus.com/bid/15213
Summary:
Snoopy is prone to an arbitrary command execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

This issue may facilitate unauthorized remote access in the context of the Web server to the affected computer.

44. Woltlab Info-DB Info_db.PHP  Multiple SQL Injection Vulnerabilities
BugTraq ID: 15214
Remote: Yes
Date Published: 2005-10-26
Relevant URL: http://www.securityfocus.com/bid/15214
Summary:
Info-DB is prone to multiple SQL injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.


45. Techno Dreams Multiple Scripts Multiple SQL Injection Vulnerabilities
BugTraq ID: 15215
Remote: Yes
Date Published: 2005-10-26
Relevant URL: http://www.securityfocus.com/bid/15215
Summary:
Multiple Techno Dreams scripts are prone to multiple SQL injection vulnerabilities.  These issues are due to a failure in the applications to properly sanitize user-supplied input before using it in SQL queries.

Successful exploitation could result in a compromise of the applications, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

46. GCards News.PHP SQL Injection Vulnerability
BugTraq ID: 15216
Remote: Yes
Date Published: 2005-10-26
Relevant URL: http://www.securityfocus.com/bid/15216
Summary:
gCards is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.



47. PAM Unix_Chkpwd Unauthorized Access Vulnerability
BugTraq ID: 15217
Remote: No
Date Published: 2005-10-26
Relevant URL: http://www.securityfocus.com/bid/15217
Summary:
The PAM unix_chkpwd command is prone to an unauthorized access vulnerability.

A local attacker can exploit this vulnerability to perform brute force attacks to obtain the valid passwords of other local users.

48. Search Enhanced Module for PHP-Nuke HTML Injection Vulnerability
BugTraq ID: 15218
Remote: Yes
Date Published: 2005-10-26
Relevant URL: http://www.securityfocus.com/bid/15218
Summary:
Search Enhanced module for is prone to an HTML injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.


49. Ethereal IRC Protocol Dissector Denial of Service Vulnerability
BugTraq ID: 15219
Remote: Yes
Date Published: 2005-10-26
Relevant URL: http://www.securityfocus.com/bid/15219
Summary:
The Ethereal IRC protocol dissector is prone to remotely exploitable denial of service vulnerability.

The issue may be exploited by causing Ethereal to process a malformed packet.  Successful exploitation will cause a denial of service condition in the Ethereal application.

Further details are not currently available. This BID will be updated as more information is disclosed.


50. Novell ZENworks Patch Management Multiple SQL Injection Vulnerabilities
BugTraq ID: 15220
Remote: Yes
Date Published: 2005-10-27
Relevant URL: http://www.securityfocus.com/bid/15220
Summary:
ZENworks Patch Management is prone to multiple SQL injection vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

It should be noted these vulnerabilities can only be exploited if a non-privileged account has been created.  Only an administrator can create such an account.  

51. ATutor Multiple Input Validation Vulnerabilities
BugTraq ID: 15221
Remote: Yes
Date Published: 2005-10-27
Relevant URL: http://www.securityfocus.com/bid/15221
Summary:
ATutor is prone to multiple vulnerabilities.

These issues can allow remote attackers to execute arbitrary PHP commands and carry out local file include and cross-site scripting attacks.

ATutor 1.5.1-pl1 and prior versions are affected.

52. Sun Solaris Management Console HTTP TRACE Information Disclosure Vulnerability
BugTraq ID: 15222
Remote: Yes
Date Published: 2005-10-26
Relevant URL: http://www.securityfocus.com/bid/15222
Summary:
Sun Solaris Management Console is prone to an information disclosure vulnerability.

The vulnerability presents itself because the server responds to the HTTP TRACE request by default.

Enabling HTTP TRACE functionality by default may allow an attacker to compromise user accounts by gaining access to sensitive header information. This issue may be combined with other attacks, such as cross-site scripting, to steal cookie-based authentication credentials. 

53. PBLang Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 15223
Remote: Yes
Date Published: 2005-10-27
Relevant URL: http://www.securityfocus.com/bid/15223
Summary:
PBLang is prone to multiple cross-site scripting vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

These issues are reported to affect PBLang version 4.65; other versions may also be vulnerable.

54. Apache Mod_Auth_Shadow Authentication Bypass Vulnerability 
BugTraq ID: 15224
Remote: Yes
Date Published: 2005-10-27
Relevant URL: http://www.securityfocus.com/bid/15224
Summary:
mod_auth_shadow is prone to a vulnerability that may bypass expected authentication routines.

An attacker can exploit this vulnerability to bypass security restrictions and gain access to possibly sensitive or privileged information.  Information obtained may be used in further attacks against the underlying system; other attacks are also possible.

55. Hasbani Web Server Malformed HTTP GET Request Remote Denial of Service Vulnerability
BugTraq ID: 15225
Remote: Yes
Date Published: 2005-10-27
Relevant URL: http://www.securityfocus.com/bid/15225
Summary:
Hasbani Web Server is affected by a remote denial of service vulnerability.

This issue arises when the server handles malformed HTTP GET requests.

A successful attack can allow an attacker to terminate the server and deny service to legitimate users.

56. GNU gnump3d Error Page Cross-Site Scripting Vulnerability
BugTraq ID: 15226
Remote: Yes
Date Published: 2005-10-28
Relevant URL: http://www.securityfocus.com/bid/15226
Summary:
GNU gnump3d is prone to a cross-site scripting vulnerability.  An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.


57. Mantis Multiple Remote Vulnerabilities
BugTraq ID: 15227
Remote: Yes
Date Published: 2005-10-28
Relevant URL: http://www.securityfocus.com/bid/15227
Summary:
Mantis is prone to multiple remote vulnerabilities.  These issues can allow attackers to disclose sensitive information, execute arbitrary PHP scripts, and carry out cross-site scripting and SQL injection attacks.

These issues arise in Mantis versions prior to 0.19.3.

58. GNU gnump3d Directory Traversal Vulnerability
BugTraq ID: 15228
Remote: Yes
Date Published: 2005-10-28
Relevant URL: http://www.securityfocus.com/bid/15228
Summary:
GNU gnump3d is prone to a directory traversal vulnerability.  Information obtained may be used in further attacks.


59. Rockliffe MailSite Express Arbitrary Script File Upload Vulnerability
BugTraq ID: 15230
Remote: Yes
Date Published: 2005-10-28
Relevant URL: http://www.securityfocus.com/bid/15230
Summary:
MailSite Express is prone to an arbitrary file upload vulnerability.  The problem presents itself in the sanitization process of uploaded files.

An attacker can exploit this vulnerability to upload arbitrary files including malicious scripts and possibly execute the script on the affected server.

This can ultimately facilitate unauthorized access in the context of the Web server. 

60. Rockliffe MailSite Express Information Disclosure Vulnerability
BugTraq ID: 15231
Remote: Yes
Date Published: 2005-10-28
Relevant URL: http://www.securityfocus.com/bid/15231
Summary:
MailSite Express is prone to an information disclosure vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to retrieve arbitrary files in the security context of the Web server process.  Information obtained may aid in further attacks against the underlying system; other attacks are also possible.

61. PHPESP Multiple Unspecified Input Validation Vulnerabilities
BugTraq ID: 15232
Remote: Yes
Date Published: 2005-10-28
Relevant URL: http://www.securityfocus.com/bid/15232
Summary:
phpESP is prone to multiple input validation vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input.

The application is prone to multiple unspecified cross-site scripting and SQL injection vulnerabilities.

Very little information is available on these vulnerabilities.  This BID will be updated as further information becomes available.

62. ASP Fast Forum Error.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 15233
Remote: Yes
Date Published: 2005-10-28
Relevant URL: http://www.securityfocus.com/bid/15233
Summary:
ASP Fast Forum is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

63. Jed Wing CHM Lib _chm_find_in_PMGL Stack Buffer Overflow Vulnerability
BugTraq ID: 15234
Remote: Yes
Date Published: 2005-10-28
Relevant URL: http://www.securityfocus.com/bid/15234
Summary:
CHM lib is susceptible to a buffer overflow vulnerability. This issue is due to a failure of the library to properly bounds check input data prior to copying it into an insufficiently sized memory buffer.

This issue allows attackers to execute arbitrary machine code in the context of the application that utilizes the CHM lib library.

This issue is present in versions 0.35; other versions may also be affected.

64. MG2 Authentication Bypass Vulnerability
BugTraq ID: 15235
Remote: Yes
Date Published: 2005-10-29
Relevant URL: http://www.securityfocus.com/bid/15235
Summary:
MG2 is affected by an authentication bypass vulnerability.  This issue can allow remote attackers to gain access to password protected image galleries.

All versions of MG2 are considered to be vulnerable at the moment.  Minigal B13 is likely affected as well.

65. Hyper Estraier Remote Information Disclosure Vulnerability
BugTraq ID: 15236
Remote: Yes
Date Published: 2005-10-28
Relevant URL: http://www.securityfocus.com/bid/15236
Summary:
Hyper Estraier can allow remote attackers to disclose restricted files.

Information gathered through the exploitation of this vulnerability may aid in other attacks.

Hyper Estraier 1.0.1 and prior versions running in Windows platforms are vulnerable to this issue.

66. PHP Advanced Transfer Manager Remote Unauthorized Access Vulnerability
BugTraq ID: 15237
Remote: Yes
Date Published: 2005-10-29
Relevant URL: http://www.securityfocus.com/bid/15237
Summary:
PHP Advanced Transfer Manager can allow remote attackers to gain unauthorized access.  

Access to sensitive files containing authentication credentials is not restricted, therefore an attacker can simply issue a GET request to obtain a user's password hash.  This information can then allow them to successfully authenticate to the service using a cookie.

PHP Advanced Transfer Manager 1.30 is reported to be vulnerable.  Other versions may be affected as well.

67. Subdreamer Multiple Remote SQL Injection Vulnerabilities
BugTraq ID: 15238
Remote: Yes
Date Published: 2005-10-29
Relevant URL: http://www.securityfocus.com/bid/15238
Summary:
Subdreamer is prone to multiple remote SQL injection vulnerabilities.

These vulnerabilities could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks. Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation. 

Subdreamer 2.2.1 is reported to be vulnerable.  Other versions may be affected as well.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. U.S. makes securing SCADA systems a priority
By: Robert Lemos
Amongst worries that the nation's power systems and utility networks are at risk, the U.S. Department of Homeland Security spins out new initiatives to help companies lock down their control systems.
http://www.securityfocus.com/news/11351

2. Web defacer sentenced, facing deportation 
By: Robert Lemos
After agreeing to plead guilty to defacing an Air Force Web site, Rafael Nu&ntilde;ez-Aponte gets time served, but possible charges regarding leaked NASA documents could be in the wings.
http://www.securityfocus.com/news/11350

3. Snort vulnerability "wormable" but not widespread
By: Robert Lemos
A three-month-old flaw in a preprocessor function for the open-source intrusion detection system may attract worm writers, but the number of vulnerable systems is thought to be low.
http://www.securityfocus.com/news/11349

4. Worm worries don't wait for Windows exploits
By: Robert Lemos
Security researchers disagree over whether a recently announced flaw in Microsoft Windows will likely become food for an Internet worm. 
http://www.securityfocus.com/news/11346

5. Say hello to the Skype Trojan
By: John Leyden
Virus writers are targeting Skype users with a new Trojan that poses as the latest version of the popular VoIP software.
http://www.securityfocus.com/news/11348

6. Shared music abuse bug hits iTunes
By: John Leyden
Security researchers have discovered a vulnerability in Apple's popular iTunes application which might be exploited to interfere with shared music downloads.
http://www.securityfocus.com/news/11347

7. US cybersecurity all at sea
By: John Leyden
US cybersecurity risks are being poorly managed by the Department of Homeland Security, according to a former US presidential information security advisor.
http://www.securityfocus.com/news/11345

8. Worm fears over MS October patch batch
By: John Leyden
Microsoft's patch train rolled into town on Tuesday carrying a cargo of nine updates. 
http://www.securityfocus.com/news/11342

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Security Engineer, Independence
http://www.securityfocus.com/archive/77/415365

2. [SJ-JOB] Auditor, London
http://www.securityfocus.com/archive/77/415366

3. [SJ-JOB] Application Security Engineer, Toronto
http://www.securityfocus.com/archive/77/415364

4. [SJ-JOB] Jr. Security Analyst, Austin
http://www.securityfocus.com/archive/77/415363

5. [SJ-JOB] Security System Administrator, San Diego
http://www.securityfocus.com/archive/77/415311

6. [SJ-JOB] Sr. Security Engineer, Crystal Lake
http://www.securityfocus.com/archive/77/415312

7. [SJ-JOB] Security Engineer, Seattle
http://www.securityfocus.com/archive/77/415309

8. [SJ-JOB] Developer, Redwood City
http://www.securityfocus.com/archive/77/415310

9. [SJ-JOB] Director, Information Security, Atlanta
http://www.securityfocus.com/archive/77/415304

10. [SJ-JOB] Director, Computer Security, Rockford
http://www.securityfocus.com/archive/77/415305

11. [SJ-JOB] Security System Administrator, ALL
http://www.securityfocus.com/archive/77/415306

12. [SJ-JOB] Sales Engineer, ALL
http://www.securityfocus.com/archive/77/415308

13. [SJ-JOB] Sr. Security Analyst, Cupertino
http://www.securityfocus.com/archive/77/415302

14. [SJ-JOB] Sales Engineer, New York (various other locations)
http://www.securityfocus.com/archive/77/415303

15. [SJ-JOB] CHECK Team Leader, London
http://www.securityfocus.com/archive/77/415307

16. [SJ-JOB] Jr. Security Analyst, Walnut Creek
http://www.securityfocus.com/archive/77/415089

17. [SJ-JOB] Application Security Engineer, NYC/DC/LA/Seattle/Bay Area
http://www.securityfocus.com/archive/77/415090

18. [SJ-JOB] Security Researcher, Bellevue
http://www.securityfocus.com/archive/77/415091

19. [SJ-JOB] Security System Administrator, san francisco
http://www.securityfocus.com/archive/77/415087

20. [SJ-JOB] Security Consultant, new york
http://www.securityfocus.com/archive/77/415088

21. [SJ-JOB] Sr. Security Engineer, Washington
http://www.securityfocus.com/archive/77/415074

22. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/415071

23. [SJ-JOB] Security Consultant, Anywhere in the states
http://www.securityfocus.com/archive/77/415072

24. [SJ-JOB] Security System Administrator, Dallas
http://www.securityfocus.com/archive/77/415073

25. [SJ-JOB] Security Consultant, New York City
http://www.securityfocus.com/archive/77/415069

26. [SJ-JOB] Technical Support Engineer, Chennai
http://www.securityfocus.com/archive/77/414751

27. [SJ-JOB] Information Assurance Analyst, Arlington, VA; Lanham,    MD; Herndon, VA
http://www.securityfocus.com/archive/77/414757

28. [SJ-JOB] Security Consultant, Austin
http://www.securityfocus.com/archive/77/414750

29. [SJ-JOB] Security Consultant, Charlotte
http://www.securityfocus.com/archive/77/414753

30. [SJ-JOB] Regional Channel Manager, San Francisco
http://www.securityfocus.com/archive/77/414758

31. [SJ-JOB] Compliance Officer, Warren
http://www.securityfocus.com/archive/77/414755

32. [SJ-JOB] Information Assurance Analyst, New York
http://www.securityfocus.com/archive/77/414756

33. [SJ-JOB] Sales Representative, Atlanta
http://www.securityfocus.com/archive/77/414752

34. [SJ-JOB] Quality Assurance, New York
http://www.securityfocus.com/archive/77/414651

35. [SJ-JOB] Security Researcher, Redwood City, CA; Santa Monica, CA;    Waltham, MA; Herndon, VA
http://www.securityfocus.com/archive/77/414654

36. [SJ-JOB] Security Researcher, Redwood City, CA; Santa Monica, CA;    Waltham, MA; Herndon, VA
http://www.securityfocus.com/archive/77/414655

37. [SJ-JOB] Sr. Security Analyst, Reading, Berkshire
http://www.securityfocus.com/archive/77/414650

38. [SJ-JOB] Disaster Recovery Coordinator, Silver Spring
http://www.securityfocus.com/archive/77/414653

V.   INCIDENTS LIST SUMMARY
---------------------------
1. ICMP Type:8 Code:137
http://www.securityfocus.com/archive/75/414995

2. moderator note: AIM worm...
http://www.securityfocus.com/archive/75/414973

3. Fw: troj_cryt.u detected
http://www.securityfocus.com/archive/75/414971

4. - AIM virus / worm
http://www.securityfocus.com/archive/75/414964

5. AIM virus / worm
http://www.securityfocus.com/archive/75/414941

6. Moderator's note: SSH bruteforce on its way..
http://www.securityfocus.com/archive/75/414748

7. Who is looking for port 2036?
http://www.securityfocus.com/archive/75/414542

8. Dismantling Botnets?
http://www.securityfocus.com/archive/75/413832

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. EUSecWest/London Call for Papers and PacSec/Tokyo announcements
http://www.securityfocus.com/archive/82/415358

2. New List
http://www.securityfocus.com/archive/82/415235

3. Question on new umpnpmgr wsprinfW buffer overflow
http://www.securityfocus.com/archive/82/415219

4. Multiple vulnerabilities within RockLiffe MailSite Express WebMail
http://www.securityfocus.com/archive/82/415218

5. problem in rewrite RET address in Buffer OverFlow
http://www.securityfocus.com/archive/82/414557

6. Vulnerability Assesment tools(Vuln testing tools)
http://www.securityfocus.com/archive/82/414512

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Invitation to Join the Collaborative Endpoint Security Project, sponsored by Core Security Technologies
http://www.securityfocus.com/archive/88/415368

2. New List - Beta-Announce
http://www.securityfocus.com/archive/88/414948

3. SecurityFocus Microsoft Newsletter #262
http://www.securityfocus.com/archive/88/414828

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored By: Watchfire AppScan

Firewalls and SSL may be commonplace today, but websites still remain vulnerable to attack. That's because application security differs from network security, and traditional approaches don't apply. Address Application Security Challenges -- download this white paper today.

https://www.watchfire.com/securearea/whitepapers.aspx?id=701300000002gRE