SecurityFocus Newsletter #138
John Boletta <[email protected]>
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #138
-----------------------------
This newsletter is sponsored by SecurityFocus (www.securityfocus.com)
Attention Non-profits and Universities: Sign-up now for preferred pricing
on the only global early-warning system for cyber attacks - SecurityFocus
ARIS Threat Management System.
Click here for more info
http://www.securityfocus.com/corporate/products/pdpsection.shtml
-------------------------------------------------------------------------------
I. FRONT AND CENTER
1. No Stone Unturned, Part Two
2. Always On, Always Vulnerable: Security Broadband Connections
3. Beware the Kindness of Strangers: The Case Against Good...
4. Forcing Teamwork on Redmond
II. BUGTRAQ SUMMARY
1. NEWLOG NetSupport Manager Directory Traversal Vulnerability
2. PostNuke Cross Site Scripting Vulnerability
3. Webmin Plaintext Authentication Credentials Disclosure...
4. Linux Directory Penguin NSLookup Perl Script Arbitrary...
5. Alguest Cookie Falsification Vulnerability
6. WebSight Directory System Cross Site Scripting Vulnerability
7. Apache Double-Reverse Lookup Log Entry Spoofing Vulnerability
8. Instant Web Mail POP Command Execution Vulnerability
9. Squid Compressed DNS Buffer Overflow Vulnerability
10. SouthWest Talk Server Denial of Service Vulnerability
11. ht://Dig Configuration File Path Disclosure Vulnerability
12. Etnus TotalView Insecure UID/GID Privilege Escalation...
13. Linux Kernel d_path() Path Truncation Vulnerability
14. CSSearch Remote Command Execution Vulnerability
15. HP Praesidium Webproxy Unauthorized Access Vulnerability
16. Qualcomm Eudora WebBrowser Control Embedded Media Player...
17. WorkforceROI Xpede Weak Password Encryption Vulnerability
18. WorkforceROI Xpede Re-Authentication Plain Text Password...
19. Gravity Storm Service Pack Manager 2000 Directory Permissions...
III. SECURITYFOCUS NEWS ARTICLES
1. Network Associates Discloses SEC Probe
2. Panel Debates Hacker Amnesty
IV.SECURITYFOCUS TOP 6 TOOLS
1. Zebedee 2.3.1
2. SILC (Secure Internet Live Conferencing)(client) v0.8.4
3. CryptNET_Keyserver v0.1.0b
4. File::Scan v0.17
5. slidentd v0.0.15
6. OpenVPN v1.0.2
V. SECURITYJOBS LIST SUMMARY
1. Security Engineer - NY office (Thread)
2. my resume (Thread)
3. Hola, Mundo (Thread)
4. Seeking Opportunities (Thread)
5. Security Analyst (Thread)
6. Security Lead Architect wanted for EAI company (Thread)
7. looking for position in NYC area (Thread)
8. Information Security Professional looking for a suitable position
9. looking for internship (Thread)
10. Internet Security Specialist (Thread)
11. Resume: Philadelphia Metro Area -- Avail: August 02 (Thread)
12. Security Hacker For Lease (Thread)
13. Seeking for an IT Audit Job (Thread)
14. Sales Management Positions (Thread)
15. Senior Security Architects - Sydney, Australia (Thread)
16. Resume: DC/MD/VA or South Florida (Thread)
17. Student Network Admin Assistant (Thread)
18. SAP Security Specialist Available - UK (Thread)
19. NetSec Eng available in Baltimore, MD (Thread)
20. List closure (Thread)
21. Security Engineer (Thread)
22. Penetration Testers for the UK (Thread)
23. CISSP in NYC (Thread)
VI. INCIDENTS LIST SUMMARY
1. Sendmail DOS ? (Thread)
2. Sendmail DOS ? (Thread)
3. Excess SMTP traffic to non-mail host (Thread)
4. Excess SMTP traffic to non-mail host (Thread)
5. network mystery (Thread)
6. DoS yesterday (Thread)
7. watching them -after the fact (Thread)
8. fun with posiden rootkit (Thread)
9. Logon Banners (Thread)
10. Logon Banners (Thread)
11. {MERIT-INP} 7.0.1.0 -> 14.0.2.13 (Thread)
12. Port 1900/5000 connection attempts (Thread)
13. different, nimda like, probes (Thread)
14. increase in scans for RPC (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
1. New Binary Bruteforcing Method Discovered (Thread)
2. Re New Binary Bruteforcing Method Discovered (Thread)
3. Re: New Binary Bruteforcing Method Discovered (Thread)
4. Compaq tru64 setuids /usr/bin/at and /usr/dt/bin/mailcv (Thread)
5. Bigger bug than expected? (Thread)
6. Wireless device vulnerability? (Thread)
7. Compaq tru64 setuids /usr/bin/at and /usr/dt/bin/mailcv (Thread)
8. Wireless Legality- Netstumbler and kin (Thread)
9. Format String Bug in Posadis DNS Server (Thread)
10. RCA cable modem Deny of Service (Thread)
11. Root compromise through LogWatch 2.1.1 (Thread)
12. A note about PHP and path disclosure errors (Thread)
13. w3com Personal Web Site (Thread)
14. A buffer overflow study - generic protections (Thread)
15. Buffer overflow in awk (Thread)
16. Problem with xkill (Thread)
17. Wireless device vulnerability? (Thread)
18. Ph.D Network/Internet/Web/App security (Thread)
19. I HATE antivirus scanners (Thread)
20. Wireless Legality- Netstumbler and kin (Thread)
21. IDS and SSL (Thread)
22. /usr/bin/addresses seg fault (Thread)
23. I HATE antivirus scanners (Thread)
24. Regex or Progress? Whos fault? (Thread)
25. about idq.dll problem!!! (Thread)
26. about idq.dll problem!!! (Thread)
27. IDS and SSL (Thread)
28. Buffer overflow in awk (Thread)
29. Re[2]: I HATE antivirus scanners (Thread)
30. pure IE code injection (Thread)
31. Outlook 2000 and maybe others contain begin 666 filename.exe or
32. pure IE code injection (Thread)
33. ScanMail Message: To Recipient virus found or matched file
34. Issues with ical (Thread)
35. Problem with xkill (Thread)
36. CSS implication (Thread)
37. Progress Software suid overflows again. (Thread)
38. One more way to bypass NAV (Thread)
39. DOCSIS vulnerability (Thread)
40. useless security@ contacts (Thread)
41. Testing zlib vulnerability (Thread)
42. Vulnerability in Apache for Win32 batch file processing -Remote
43. NAV to test (Thread)
44. Vulnerability in Apache for Win32 batch file processing - Remote
VIII. MICROSOFT FOCUS LIST SUMMARY
1. Null session in Windows XP (Thread)
2. Null session in Windows XP (Thread)
3. udp forwarding/filtering.. (Thread)
4. ADSI and delegation (Thread)
5. Frontpage 2000 (Thread)
6. Frontpage 2000 (Thread)
7. SecurityFocus Microsoft Newsletter #79 (Thread)
8. udp forwarding/filtering.. (Thread)
9. Port Ranges in IPSec (Thread)
10. Encrypted partition solution for Windows OSes? (Thread)
11. Encrypted partition solution for Windows OSes? (Thread)
12. ISA-Server Problem (Thread)
13. Group Policies on OUs not Propagated (Thread)
14. Group Policies on OUs not Propagated (Thread)
15. Sub7 (SubSeven), Win2k, and IE 5.5 (Thread)
16. Outlook/Exchange (Thread)
17. account lockout problems (Thread)
18. Between Forest IPSec Implementation? (Thread)
19. HFNetChk Pro vs. other means to push out updates (Thread)
20. Sub7 (SubSeven), Win2k, and IE 5.5 (Thread)
21. ISA-Server Problem (Thread)
IX. SUN FOCUS LIST SUMMARY
1. ?hack cause? (Thread)
2. ?hack cause? (Thread)
3. Followup - Thanks - " ?hack cause? " (Thread)
4. BSM audit viewer with java option (Thread)
X. LINUX FOCUS LIST SUMMARY
1. SecurID and FreeS/WAN GW (Thread)
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. No Stone Unturned, Part Two
by H. Carvey
This is the second installment of a 5-part series describing the
(mis)adventures of a sys admin named Eliot and his haphazard journey in
discovering The Way of Incident Response.
http://online.securityfocus.com/infocus/1561
2. Always On, Always Vulnerable: Securing Broadband Connections
by Matthew Tanase
You finally got it. No more late nights at the office wasted on
downloading sprees. No more screeching modems or constant busy signals.
Streaming media, lightning quick file transfers and online gaming, all
within your reach. Yes - you finally have broadband Internet access!
http://online.securityfocus.com/infocus/1560
3. Beware the Kindness of Strangers: The Case Against Good Samaritan
Hackers
by Richard Forno
The debate around Good Samaritan hackers has merits on both sides.
However, according to the author, the answer to the answer is cut and
dried.
http://online.securityfocus.com/columnists/70
4. Forcing Teamwork on Redmond
By Tim Mullen
Recently while traveling in Ireland I was surprised to see that the
procedures followed by airline security, both while arriving-in and
departing-from the country, were far less restrictive and invasive than
here in the states. Even in London's Heathrow airport, a "tight schedule"
backed by a little social engineering allowed me to bypass much of the
security that was in place.
http://online.securityfocus.com/columnists/69
II. BUGTRAQ SUMMARY
-------------------
1. NEWLOG NetSupport Manager Directory Traversal Vulnerability
BugTraq ID: 4348
Remote: Yes
Date Published: Mar 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4348
Summary:
NEWLOG NetSupport Manager is a remote control desktop management software
to assist in remote system administration.
A vulnerability has been reported in NetSupport Manager which may allow a
remote attacker to view arbitrary files.
Reportedly, NetSupport Manager does not adequately filter '../' sequences
from web requests, making it prone to directory traversal attacks. This
vulnerability could be exploited to effectively disclose any file on a
host running the affected software.
Successful exploitation of this vulnerability could lead to the disclosure
of sensitive information, assisting an attacker in further attacks against
the host.
2. PostNuke Cross Site Scripting Vulnerability
BugTraq ID: 4350
Remote: Yes
Date Published: Mar 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4350
Summary:
PostNuke is a content management system originally forked from the
PHP-Nuke project. It is implemented in PHP, and available for Windows,
Linux and other Unix based systems.
Cross site scripting vulnerabilites have been reported in some versions of
PostNuke. User supplied input may be inserted into the HTML produced by
both the index.php and modules.php scripts. The script will then execute
within the context of the vulnerable site.
Exploitation of this vulnerability may result in the theft of cookie data
and, with it, session authentication data. More subtle attacks such as
information subversion may also be attempted.
The reported consequences of exploitation suggest that this vulnerability
may be a result of a SQL injection problem. This has, however, not been
confirmed. Additionally, exploitation of this vulnerability may be related
to web based error reporting, as controlled by the local PHP
configuration. This is also unconfirmed at this time.
3. Webmin Plaintext Authentication Credentials Disclosure Vulnerability
BugTraq ID: 4351
Remote: No
Date Published: Mar 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4351
Summary:
Webmin is a web-based interface for system administration of Unix and
Linux operating systems.
A vulnerability has been discovered that may potentially cause
authentication credentials for remote Webmin servers to be disclosed to a
local attacker.
It has been reported that authentication credentials for remote servers
are stored in plaintext by Webmin. These credentials are stored in the
'/etc/webmin/servers/' directory. The filename associated with each host
is derived from the system time at the point when the host was first
discovered by the local Webmin server. Though the directory is
unreadable, the execute bit enabled. The consistent naming based on system
time allows for an attacker to search for existing files.
A clever attacker may exploit this to disclose authentication credentials
for remote hosts on the network which are running Webmin.
4. Linux Directory Penguin NSLookup Perl Script Arbitrary File Reading Vulnerability
BugTraq ID: 4353
Remote: Yes
Date Published: Mar 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4353
Summary:
Penguin nslookup.pl is a freely available, open source script for tracing
network hops from a web server. It is distributed by Linux Directory.
A problem with the script could make it possible for a remote user to view
arbitrary files, and execute arbitrary commands. The problem is in the
filtering of special characters.
The Penguin nslookup script does not adequately filter special characters.
This makes it possible for a remote user to access specific files on the
local system. The attacker may read files that are accessible by the web
server. Additionally, the attacker may be able to execute arbitrary
commands with the permissions of the web server by encapsulating commands
in special characters.
This problem makes it possible for a remote user to gain access to
potentially sensitive information, and potentially local access to the
system with the permissions of the web server.
5. Alguest Cookie Falsification Vulnerability
BugTraq ID: 4355
Remote: Yes
Date Published: Mar 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4355
Summary:
Alguest is a guestbook program, written in PHP and back-ended by a MySQL
database. It will run on most Unix and Linux variants, as well as
Microsoft Windows operating systems.
Alguest allows administrators to authenticate via cookie-based
authentication credentials. However, Alguest administrative cookies are
not properly checked for administrative rights (via a shared secret,
credentials such as username/password, etc.). Alguest only checks that an
administrative cookie exists. As a result, it is trivial for a remote
attacker to falsify an administrative cookie.
6. WebSight Directory System Cross Site Scripting Vulnerability
BugTraq ID: 4357
Remote: Yes
Date Published: Mar 25 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4357
Summary:
WebSight Directory System is a directory system program for Electronic
Music World and is maintained by Stefan Koopmanschap.
WebSight does not filter Javascript from URL parameters, making it prone
to cross-site scripting attacks.
As a result, it is possible for a remote attacker to create a malicious
link containing script code which will be executed in the browser of a
legitimate user, in the context of the website running WebSight.
This issue may be exploited to steal cookie-based authentication
credentials from legitimate users of the service. Cookie-based
authentication credentials may be used by the attacker to hijack the
session of the legitimate user.
This has been reported to be exploitable when submitting a new link
suggestion. The URL is approved via an administration interface. Thus, a
user could compromise the administrator account.
7. Apache Double-Reverse Lookup Log Entry Spoofing Vulnerability
BugTraq ID: 4358
Remote: Yes
Date Published: Mar 25 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4358
Summary:
Apache is a freely available webserver for Unix and Linux variants, as
well as Microsoft operating systems.
A vulnerability has been discovered in the way Apache logs double-reverse
DNS lookups. This may cause Apache to log invalid hostname information.
A double-reverse DNS lookup is a security measure where an IP address is
translated to a hostname and then the hostname is translated back to the
IP address.
If a double-reverse DNS lookup is performed but fails, then an invalid
hostname may appear in the logs. For example, this may occur if the
hostname does not properly resolve to the IP address in the double-reverse
DNS lookup. This problem occurs because Apache logs the (potentially
falsified) hostname instead of the numeric IP address.
A remote attacker may deliberately exploit this issue to cause spoofed
information to be logged by the webserver.
8. Instant Web Mail POP Command Execution Vulnerability
BugTraq ID: 4361
Remote: Yes
Date Published: Mar 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4361
Summary:
Instant Web Mail is a free, web based POP email client. It is implemented
in PHP, and can be expected to run under Windows, Linux and most Unix
systems.
A vulnerability has been reported in some versions of Instant Web Mail. An
attacker may create links to vulnerable scripts including arbitrary POP
commands, and send an email including these links to a user of the system.
If the link is followed, the command will be executed. This may result in
lost email or more subtle attacks.
In addition, Instant Web Mail allows the inclusion of additional POP
commands. This is possible when CR/LF characters are included in attacker
supplied data used to build the expected POP commands. This may allow the
above attack to pass undetected, as the results will not be immediately
displayed to the vulnerable user.
9. Squid Compressed DNS Buffer Overflow Vulnerability
BugTraq ID: 4363
Remote: Yes
Date Published: Mar 26 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4363
Summary:
Squid is a high performance web cache and proxy. Squid was initially
developed for the Unix platform, and is available for Linux and most major
Unix like operating systems. Recent versions of Squid may function under
Windows.
A boundary condition error exists in the internal DNS implementation
included with the Squid web proxy. If a malicious DNS server returns a
malformed compressed DNS answer message, Squid may exit with a SIGSEGV
error.
There have been reports that this vulnerability is the result of heap
memory corruption. Successful exploitation of this vulnerability may allow
a remote attacker to execute arbitrary code on the vulnerable system. This
possibility has not yet been confirmed.
Internal DNS queries are enabled by default.
10. SouthWest Talk Server Denial of Service Vulnerability
BugTraq ID: 4362
Remote: Yes
Date Published: Mar 25 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4362
Summary:
A denial of service condition has been reported to exist in SouthWest.
SouthWest is a talker chat server for Windows environments, and is
maintained by Scott Lloyd. SouthWest also includes an embedded web server
which provides information about the service, installed by default on port
5002.
A denial of service condition has been reported which could cause the
service and all user connections to terminate.
It is possible to request information for a specific user through the web
service. If this request is made while that user is connected, the entire
SouthWest process will crash. A restart is required in order to regain
normal functionality.
The web server will also provide a list of currently connected users.
11. ht://Dig Configuration File Path Disclosure Vulnerability
BugTraq ID: 4366
Remote: Yes
Date Published: Mar 26 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4366
Summary:
ht://Dig is a freely available, open source search engine. It is
developed and maintained by the ht://Dig project, and functions on the
Unix and Linux operating systems.
A problem with ht://Dig could make it possible for a local user to gain
access to potentially sensitive information. The problem is in the
generation of error messages.
An error page will be returned when a request is made via the htsearch
component and the value for the 'config' variable is erroneous or
non-sensical. The error page will contain the full path of the
configuration file directory for ht://Dig. Additionally, the 'config'
variable being accessible by any user may allow the ht://Dig program to
load arbitrary files as configuration.
The problem makes it possible for a remote user to gain knowledge of the
directory structure and ht://Dig configuration file directory. It may
additionally result in the loading of arbitrary ht://Dig configuration
files.
12. Etnus TotalView Insecure UID/GID Privilege Escalation Vulnerability
BugTraq ID: 4365
Remote: No
Date Published: Mar 26 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4365
Summary:
TotalView is a debugger for programs written in the C, C++, and Fortran.
It is maintained by Etnus and is available for a number of Linux and Unix
variants.
A flaw in the installation of TotalView may circumstantially enable a
local attacker to elevate privileges on the host running the vulnerable
software.
TotalView, when installed, fails to create a number of files and
directories with the correct UID/GID. These files/directories are created
with write permissions for UID 5039/GID 59. Normally, these files and
directories would be created with a UID/GID of root. A local attacker who
has access to an account with UID 5039 or GID 59 may be able to backdoor
the affected files, which will result in an elevation of privleges when
the affected files are executed through TotalView by the root user.
This vulnerability has been reported for version 5.0.0-4 on the Linux
platform. Other versions/platforms may also be affected.
13. Linux Kernel d_path() Path Truncation Vulnerability
BugTraq ID: 4367
Remote: No
Date Published: Mar 26 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4367
Summary:
The Linux kernel d_path() function converts a dentry structure into an
ASCII path name. The full path to the specified dentry is returned in a
fixed length buffer of size PAGE_SIZE bytes.
Reportedly, if a dentry structure is passed with a path which exceeds this
length, an erroneous value is returned. The path which is returned has
leading entries truncated, and no error is reported.
Multiple higher level functions are dependent on d_path(), including
getcwd(2) and readlink(2). As such, exploitation of this vulnerability may
have security implications in programs that use these functions. Under
some circumstances, a privileged process may perform operations within an
inappropriate directory, possibly on incorrect files. This may result in
security checks specific to an application failing.
14. CSSearch Remote Command Execution Vulnerability
BugTraq ID: 4368
Remote: Yes
Date Published: Mar 26 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4368
Summary:
csSearch is a website search script, written in Perl. It will run on most
Unix and Linux variants, as well as Microsoft operating systems.
csSearch is prone to an issue which may enable an attacker to execute Perl
code with the privileges of the webserver process.
It is possible to craft a web request which is capable of passing
arbitrary data to the configuration script, including attacker-supplied
Perl code. Perl code passed in this manner will be interpreted by the
vulnerable script, effectively allowing a remote attacker to execute
arbitrary Perl code with the privileges of the webserver process.
For exploitation to be successful, the attacker must pass properly URL
encoded Perl code in CGI parameters via a web request. For example:
http://host/cgi-bin/csSearch.cgi?command=savesetup&setup=PERL_CODE_HERE
This issue may enable a remote attacker to gain local, interactive access
to the host running the vulnerable software.
15. HP Praesidium Webproxy Unauthorized Access Vulnerability
BugTraq ID: 4342
Remote: Yes
Date Published: Mar 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4342
Summary:
HP VirtualVault is a secure implementation package distributed by
Hewlett-Packard for use as a web and e-commerece platform. HP Praesidium
Webproxy assists in integration of VirtualVault on a hosts system
architecture.
An issue has been reported in HP Praesidium Webproxy which could enable an
unauthorized remote user to bypass proxy checks.
Upon receiving an absolute URI GET request, Webproxy may forward the
request to the internal administrative interface without applying other
modules' translation phase modifications to the URI.
As a result, unauthorized access to the local network is possible,
potentially compromising the integrity of a vulnerable system.
16. Qualcomm Eudora WebBrowser Control Embedded Media Player File Vulnerability
BugTraq ID: 4343
Remote: Yes
Date Published: Mar 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4343
Summary:
The WebBrowser control is used in some email clients in order to launch
Internet Explorer to render HTML content.
An issue has been reported with email clients using the WebBrowser control
which may result in the automatic execution of JavaScript in HTML
formatted email.
Reportedly, this vulnerability may be exploited through an embedded
<t:video> tag. If the image tag references one of a number of file
extensions associated with Windows Media Player, it will be opened
automatically.
The file may then contain JavaScript which is automatically executed. This
JavaScript may, in turn, open an arbitrary web page or application through
usage of the player.LaunchURL() method. This page may contain additional
JavaScript, or reference code through a JavaScript: or about: URL.
When exploited in conjunction with the issues described in BID 4306, it is
possible to execute arbitrary script code in the My Computer zone.
The discoverer of this vulnerability has speculated that Microsoft Outlook
and Outlook Express may also be vulnerable to this issue. This has not
been tested or proven as of yet.
17. WorkforceROI Xpede Weak Password Encryption Vulnerability
BugTraq ID: 4344
Remote: No
Date Published: Mar 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4344
Summary:
Xpede is a project accounting program which tracks time, expenses and
inventory. It should be noted that Intellisol use to maintain Xpede,
however Workforce ROI has acquired Intellisol.
An issue has been reported in Xpede, which could allow for a user to
reveal authentication information.
Reportedly, Xpede cookies containing username and password data is stored
using a weak encryption method. Therefore if a user obtains access to
cookies reisding on a local system, he/she may be able to reveal
authentication information of Xpede users.
18. WorkforceROI Xpede Re-Authentication Plain Text Password Disclosure Vulnerability
BugTraq ID: 4346
Remote: No
Date Published: Mar 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4346
Summary:
Xpede is a project accounting program which tracks time, expenses and
inventory. It should be noted that Intellisol use to maintain Xpede,
however Workforce ROI has acquired Intellisol.
An issue has been reported in Xpede which could allow a user to reveal the
plain text password of users.
When attempting re-authentication for a timed out session, Xpede uses
Javascript to verify whether a user has enabled the 'Remember my password'
option.
Reportedly, the source code of the offending Javascript will reveal the
user's password in plain text, regardless of whether or not the 'Remember
my passord' option was selected.
An attacker with local access to a work station displaying this screen may
trivially acquire the password of the previously logged in user.
19. Gravity Storm Service Pack Manager 2000 Directory Permissions Vulnerability
BugTraq ID: 4347
Remote: No
Date Published: Mar 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4347
Summary:
Gravity Storm Service Pack Manager 2000 is an application designed to
detect, track, monitor, and install Microsoft Windows NT/2000 Service
Packs and Hotfixes on your network.
Reportedly, when Gravity Storm Service Pack Manager is installed it
creates a hidden share (SPM2000c$) which is mapped to the local c: drive.
An issue has been reported in Service Pack Manager, which allows the
everyone group read and write permissions to the System32 directory.
As a result, local users could gain access to this share (SPM2000c$) and
peruse C:\winnt\system32 with read and write permissions.
It should be noted that the 'C:\winnt\system32\repair' directory, has only
been reported to allow read access.
III. SECURITYFOCUS NEWS AND COMMENTARY
--------------------------------------
1. Network Associates Discloses SEC Probe
By Dick Kelsey, Newsbytes
A series of events that rocked the company on the day after Christmas 2000
is under investigation by the Securities and Exchange Commission (SEC).
http://online.securityfocus.com/news/359
2. Panel Debates Hacker Amnesty
By Kevin Poulsen
Should hack-and-tell intruders who warn companies about security holes do
time with hardened criminals? Security experts probe the ethics of
hacking.
http://online.securityfocus.com/news/358
IV.SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Zebedee 2.3.1
by Neil Winton, [email protected]
Relevant URL:
http://www.winton.org.uk/zebedee/download.html
Platforms: UNIX, Windows 95/98, Windows NT
Summary:
Zebedee is a simple program to establish an encrypted, compressed "tunnel"
for TCP/IP or UDP data transfer between two systems. This allows traffic
such as telnet, FTP, and X to be protected from snooping as well as
potentially gaining performance over low-bandwidth networks from
compression. The main goals for Zebedee are to provide full client and
server functionality under both UNIX and Windows 95/98/NT, to be easy to
install, use, and maintain with little or no configuration required, and
to use only algorithms that are either unpatented or for which the patent
has expired.
2. SILC (Secure Internet Live Conferencing)(client) v0.8.4
by priikone
Relevant URL:
http://silcnet.org/
Platforms: Linux, UNIX
Summary:
SILC Client package is intended for end users who are looking for a good
and full featured SILC client. The SILC Client package currently includes
Irssi-SILC client that supports all SILC features, themes and much more.
It is curses based but has a possibility of adding various other frontends
to it. The Irssi-SILC client's user interface is based on the Irssi client
(see Irssi project).
3. CryptNET_Keyserver v0.1.0b
by VAB
Relevant URL:
http://www.cryptnet.net/fsp/cks/
Platforms: Linux
Summary:
CKS is an openPGP (RFC2440) compliant public key server. It is currently
under development. It is written in C, and runs on Linux. It uses
PostgreSQL for key storage, and supports the hkp protocol (it can
interface with GnuPG and NAI PGP). The keyserver is mostly functional, and
there is a link to a running copy on the homepage.
4. File::Scan v0.17
by Henrique Dias [email protected]
Relevant URL:
http://www.cpan.org/authors/id/H/HD/HDIAS/
Platforms: N/A
Summary:
File::Scan allows users to make multiplataform virus scanners which can
detect Windows/DOS/Mac viruses. It include a virus scanner and signatures
database.
5. slidentd v0.0.15
by Sean Hunter
Relevant URL:
http://www.uncarved.com/slidentd/
Platforms: Linux, POSIX
Summary:
slidentd is a minimal ident (RFC1413) daemon which runs from inetd,
xinetd, or tcpserver. It is similar in purpose to pidentd, which is
installed with most Linux systems. However its design goals are somewhat
different. It was written because the author wanted a very small, simple
daemon that would not give out any sensitive information (such as
usernames). In this regard it is not RFC compliant (RFC 1413 requires the
daemon to be insecure by default with secure settings as an option).
6. OpenVPN v1.0.2
by James Yonan
Relevant URL:
http://openvpn.sourceforge.net/
Platforms: Linux, POSIX
Summary:
OpenVPN is a robust and highly configurable VPN (Virtual Private Network)
daemon which can be used to securely link two or more private networks
using an encrypted tunnel over the Internet. You can tunnel any IP
subnetwork or virtual ethernet adapter over a single UDP port, use all of
the encryption, authentication, and certification features of the OpenSSL
library to protect your private network traffic, use any cipher, key size,
or HMAC digest (for packet authentication) supported by the OpenSSL
library, choose between static-key based conventional encryption or
certificate-based public key encryption, use static or TLS-based dynamic
key exchange, and tunnel networks whose public endpoints are dynamic such
as DHCP clients or dial-in users.
V. SECURITY JOBS SUMMARY
------------------------
1. Security Engineer - NY office (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
2. my resume (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/002101c1d536$ec08bb30$696c010a@dougstyle
3. Hola, Mundo (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
4. Seeking Opportunities (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
5. Security Analyst (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
6. Security Lead Architect wanted for EAI company (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/000601c1d4bb$f3d993a0$6701a8c0@coitvaioF370
7. looking for position in NYC area (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
8. Information Security Professional looking for a suitable position (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
9. looking for internship (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
10. Internet Security Specialist (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
11. Resume: Philadelphia Metro Area -- Avail: August 02 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
12. Security Hacker For Lease (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
13. Seeking for an IT Audit Job (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
14. Sales Management Positions (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
15. Senior Security Architects - Sydney, Australia (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
16. Resume: DC/MD/VA or South Florida (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
17. Student Network Admin Assistant (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
18. SAP Security Specialist Available - UK (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
19. NetSec Eng available in Baltimore, MD (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/003901c1d1ec$1c9023e0$3678a8c0@spinalcord
20. List closure (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
21. Security Engineer (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
22. Penetration Testers for the UK (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
23. CISSP in NYC (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
VI. INCIDENTS LIST SUMMARY
-------------------------
1. Sendmail DOS ? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/Pine.LNX.4.44.0203272240100.32501-100000@ultra1.hugo.vanderkooij.org
2. Sendmail DOS ? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
3. Excess SMTP traffic to non-mail host (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
4. Excess SMTP traffic to non-mail host (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
5. network mystery (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
6. DoS yesterday (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
7. watching them -after the fact (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
8. fun with posiden rootkit (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/Pine.LNX.4.44.0203252321310.16240-100000@shiva0.cac.washington.edu
9. Logon Banners (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
10. Logon Banners (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
11. {MERIT-INP} 7.0.1.0 -> 14.0.2.13 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
12. Port 1900/5000 connection attempts (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
13. different, nimda like, probes (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/1016755644.2264.192.camel@bloodnock
14. increase in scans for RPC (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. New Binary Bruteforcing Method Discovered (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
2. Re New Binary Bruteforcing Method Discovered (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
3. Re: New Binary Bruteforcing Method Discovered (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
4. Compaq tru64 setuids /usr/bin/at and /usr/dt/bin/mailcv (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
5. Bigger bug than expected? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
6. Wireless device vulnerability? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/06e501c1d58c$90c1c400$1f0a0a0a@jwlampe12
7. Compaq tru64 setuids /usr/bin/at and /usr/dt/bin/mailcv (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/003801c1d579$bd3d6100$6700a8c0@ws1014
8. Wireless Legality- Netstumbler and kin (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/000901c1d56a$ccf5e040$0200a8c0@organiza
9. Format String Bug in Posadis DNS Server (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
10. RCA cable modem Deny of Service (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
11. Root compromise through LogWatch 2.1.1 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
12. A note about PHP and path disclosure errors (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/Pine.LNX.4.33.0203261911210.11191-100000@cailleach
13. w3com Personal Web Site (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
14. A buffer overflow study - generic protections (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
15. Buffer overflow in awk (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
16. Problem with xkill (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
17. Wireless device vulnerability? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
18. Ph.D Network/Internet/Web/App security (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
19. I HATE antivirus scanners (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
20. Wireless Legality- Netstumbler and kin (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
21. IDS and SSL (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
22. /usr/bin/addresses seg fault (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
23. I HATE antivirus scanners (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/7FA8FEA22737D41192590002A537E720025BC130@SSLMEXCH1
24. Regex or Progress? Whos fault? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
25. about idq.dll problem!!! (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
26. about idq.dll problem!!! (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
27. IDS and SSL (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/008901c1d382$2aadb180$3678a8c0@spinalcord
28. Buffer overflow in awk (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
29. Re[2]: I HATE antivirus scanners (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
30. pure IE code injection (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
31. Outlook 2000 and maybe others contain begin 666 filename.exe or filename.whatever (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
32. pure IE code injection (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/001601c1d2d6$06950bb0$0a0010ac@Casa
33. ScanMail Message: To Recipient virus found or matched file blocking setting. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
34. Issues with ical (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
35. Problem with xkill (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
36. CSS implication (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
37. Progress Software suid overflows again. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
38. One more way to bypass NAV (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
39. DOCSIS vulnerability (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
40. useless security@ contacts (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
41. Testing zlib vulnerability (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/E16o9KF-00004Q-00@debian-vmware
42. Vulnerability in Apache for Win32 batch file processing -Remote command execution (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
43. NAV to test (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
44. Vulnerability in Apache for Win32 batch file processing - Remote command execution (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/F4158E9E43A9D511BE1100065B043249655E2F@perfectopdc
VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Null session in Windows XP (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/904E9CDD6D849A4BB9E5BA71A0551FC69301B1@bedexch01
2. Null session in Windows XP (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
3. udp forwarding/filtering.. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
4. ADSI and delegation (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
5. Frontpage 2000 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
6. Frontpage 2000 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
7. SecurityFocus Microsoft Newsletter #79 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
8. udp forwarding/filtering.. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/00d101c1d446$99a85670$0100a8c0@bosco
9. Port Ranges in IPSec (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
10. Encrypted partition solution for Windows OSes? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
11. Encrypted partition solution for Windows OSes? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
12. ISA-Server Problem (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/9D884881F5E1F24FB845967851720FC302C9B80D@red-msg-12.redmond.corp.microsoft.com
13. Group Policies on OUs not Propagated (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/000401c1d17d$164c9780$740110ac@kingen
14. Group Policies on OUs not Propagated (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/00fe01c1d13d$ae6a5920$66e9a8c0@sk3tchtogo
15. Sub7 (SubSeven), Win2k, and IE 5.5 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/04c901c1d12a$4b256ca0$93a606d0@micheal
16. Outlook/Exchange (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
17. account lockout problems (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
18. Between Forest IPSec Implementation? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
19. HFNetChk Pro vs. other means to push out updates (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/8628ADFB314FD5119C390008C7E9638EE7C890@MESSENGER
20. Sub7 (SubSeven), Win2k, and IE 5.5 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/2D91E1663BD330459B5D32C08AC4668243541A@huskirk.FATHOMTECHNOLOGY.COM
21. ISA-Server Problem (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
IX. SUN FOCUS LIST SUMMARY
----------------------------
1. ?hack cause? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
2. ?hack cause? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
3. Followup - Thanks - " ?hack cause? " (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
4. BSM audit viewer with java option (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
X. LINUX FOCUS LIST SUMMARY
---------------------------
1. SecurID and FreeS/WAN GW (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/[email protected]
XI. SPONSOR INFORMATION
-----------------------
This newsletter is sponsored by SecurityFocus (www.securityfocus.com)
Attention Non-profits and Universities: Sign-up now for preferred pricing
on the only global early-warning system for cyber attacks - SecurityFocus
ARIS Threat Management System.
Click here for more info
http://www.securityfocus.com/corporate/products/pdpsection.shtml
-------------------------------------------------------------------------------