SecurityFocus Newsletter #157
John Boletta <[email protected]> Mon, 12 Aug 2002 12:42:08 -0600 (MDT)
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #157
-----------------------------
This Issue is Sponsored by: John Wiley and Sons, Inc.
NEW BOOK FROM KEVIN MITNICK TO BE RELEASED OCTOBER 4
See what Publishers Weekly called a "tour de force - a series of tales of
how some old-fashioned blarney and high-tech skills can pry any
information from anyone..."
For more information and how to order "The Art of Deception:Controlling
the Human Element of Security", visit http://www.amazon.com/mitnick
-------------------------------------------------------------------------------
I. FRONT AND CENTER
1. Malware Infection Vectors: Past, Present, and Future
2. Time for Open-Source to Grow Up
3. Post to Bugtraq -- Go to Jail
4. InforwarCon 2002
5. SecurityFocus DPP Program
II. BUGTRAQ SUMMARY
1. ArGoSoft Mail Server Pro Mail Loop Denial of Service Vulnerability
2. Avaya Cajun Firmware Default Community String Vulnerability
3. Qualcomm Eudora MIME Multipart Boundary Buffer Overflow...
4. Multiple Vendor calloc() Implementation Integer Overflow...
5. FreeBSD Arbitrary FFS Filesystem Data Block Access Vulnerability
6. Opera FTP View Cross-Site Scripting Vulnerability
7. Mozilla FTP View Cross-Site Scripting Vulnerability
8. FreeBSD NFS Zero-Length RPC Message Denial Of Service...
9. qmailadmin Local Buffer Overflow Vulnerability
10. Nullsoft WinAmp HTML Playlist Script Injection Vulnerability
11. FreeBSD kqueue Kernel Panic Denial Of Service Vulnerability
12. Gaim Jabber Plug-In Buffer Overflow Vulnerability
13. Microsoft Windows Window Message Subsystem Design Error...
14. Microsoft Internet Explorer Invalid SSL Certificate Chain...
15. Microsoft Exchange 2000 Post Authorization License Exhaustion...
16. Microsoft SQL Server Remote Buffer Overflow Vulnerability
17. Microsoft Exchange 2000 Multiple MSRPC Denial Of Service...
18. LibPNG Wide Image Processing Memory Corruption Vulnerability
19. Nullsoft SHOUTCast Insecure Permissions Information Disclosure...
20. Microsoft Windows 2000 Insecure Default File Permissions...
22. Ensim Webppliance Unauthorized Email Access Vulnerability
23. Multiple Microsoft Content Management Server 2001 Vulnerabilities
24. Microsoft Content Management Server 2001 User Authentication...
25. Microsoft Content Management Server 2001 SQL Injection...
26. Microsoft Content Management Server 2001 Arbitrary Upload...
27. iSCSI Insecure Configuration File Permissions Information...
28. Google Toolbar Unauthorized JavaScript Configuration...
29. Ipswitch WS_FTP Server CPWD Remote Buffer Overflow Vulnerability
30. Google Toolbar Keypress Monitoring Information Disclosure...
31. HP EMANATE 14.2 Predictable SNMP Community String Vulnerability
32. HP-UX PTrace Page Data Fault Denial Of Service Vulnerability
33. Macromedia Flash Player Arbitrary Local File Access Vulnerability
34. Macromedia Flash Malformed Header Buffer Overflow Vulnerability
35. Qualcomm Eudora File Attachment Spoofing Vulnerability
36. Sun ONE/iPlanet Web Server Chunked Encoding Vulnerability
37. Apache 2.0 Information Disclosure Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
1. 'Creative Attacks' Beat Crypto -- Expert
2. Researcher: Biometrics Unproven, Hard To Test
3. 'Safe' web still wide open - Windows sleuth
4. Dangers of the Google tool bar exposed
IV.SECURITYFOCUS TOP 6 TOOLS
1. ZorbIPtraffic v0.01
2. single-honeypot v0.1
3. myNetMon v1.0.3
4. Gspoof v1.0b
5. nefu v0.7.0
6. Secure Cryptographic Instant Messaging v1.04
V. SECURITYJOBS LIST SUMMARY
1. Available Sr. Sales Engineer - Security (Thread)
2. Looking for a position in UK (Thread)
3. Resume - Information Systems Security Professional (Thread)
4. Security Engineer- Bay Area (Thread)
5. Manager, Information Security -- Dallas, TX (Thread)
6. Senior Sales Manager - East Coast position available (Thread)
7. Network Security Contract: NJ. CISSP, PIX FIREWALLS, INTRUSION...
8. InfoSec Consulting Position (Thread)
9. LDAP & Siteminder Architect/Engineer position in NYC (Thread)
VI. INCIDENTS LIST SUMMARY
1. large scale distributed scan of port tcp 445 (Thread)
2. [unisog] Re: large scale distributed scan of port tcp 445 (Thread)
3. Strange pings from akamai? {1-112POX} (Thread)
4. Strange pings from akamai? (Thread)
5. Scanning Port UDP 4668 (Thread)
6. (AUSCERT#c42e2) Re: odd traffic on port 80 from win 98 system...
7. Honeynet Scan of the Month for August released (Thread)
8. openssh-3.4p1.tar.gz trojaned (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
1. Apache 2.0 vulnerability affects non-Unix platforms (Thread)
2. Cross-Site Scripting Issues in Falcon Web Server (Thread)
3. iDEFENSE Security Advisory: iSCSI Default Configuration File...
4. OpenSSL Exploit (Thread)
5. SQL Command Insertion & Execution in Visual FoxPro (Thread)
6. IDEFENSE PAYING $$$ FOR VULNS (Thread)
7. MS SQL Server Hello Overflow NASL Script (Thread)
8. In regards to the insecurity of AOL Instant Messenger (Thread)
9. ssh trojaned (Thread)
10. qmailadmin SUID buffer overflow (Thread)
11. Cross-Site Scripting Attacks Possible At Multiple Webspace...
12. JanaWeb (Thread)
13. Re: ssh trojaned (Thread)
14. SPIKE 2.5 and associated vulns (Thread)
15. Unchecked Buffer in Jana Web Server (Thread)
16. [Fwd: In regards to ...
17. [Full-Disclosure] Re: Clarification on Xitami DoS (Thread)
18. REFRESH: EUDORA MAIL 5.1.1 (Thread)
19. AOL Instant Messenger - Away Setting and Snoopers (Thread)
20. [Full-Disclosure] AOL Instant Messenger - Away Setting and...
21. Clarification on Xitami DoS (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
1. Password change utility (Thread)
2. SP3 Problems? (Thread)
3. Another SUS / Autoupdate question (Thread)
4. Risks posed by Windows XP Scheduled Tasks? (Thread)
5. Looking for a recent IE SSL bug.. (Thread)
6. Closed thread --> windows update reporting info back to MS?...
7. windows update reporting info back to MS? (and .NET fw SP1)...
8. Re[2]: windows update reporting info back to MS? (and .NET fw...
9. local admin passwords (Thread)
10. Using LDAP Authentication (Thread)
11. FW: White paper: Exploiting the Win32 API. (Thread)
12. windows update reporting info back to MS? (and .NET fwSP1)...
13. SecurityFocus Microsoft Newsletter #98 (Thread)
14. QChain obsolete? (Thread)
15. Synchronising NT User Accounts with a database. (Thread)
16. Windows 2000 special folder restrictions (Thread)
17. AW: Synchronising NT User Accounts with a database. (Thread)
IX. SUN FOCUS LIST SUMMARY
1. Solaris and lack of loopback routes (Thread)
2. Fwd: Hardening NIS+ (Thread)
3. Hardening NIS+ (Thread)
X. LINUX FOCUS LIST SUMMARY
1. LDAP Auth? (Thread)
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. Malware Infection Vectors: Past, Present, and Future
By Paul Schmehl
The vectors that malicious software use to invade systems are constantly
evolving: adapting to new technologies, changing to avoid defense
mechanisms and adding on to attack new weaknesses. This article will look
at what infection vectors have been historically effective, how they've
changed over time and what they probably will do in the future.
http://online.securityfocus.com/infocus/1615
2. Time for Open-Source to Grow Up
By Jon Lasser
The OpenSSH backdoor demonstrates that the community must get pragmatic
about package verification, and fast.
http://online.securityfocus.com/columnists/101
3. Post to Bugtraq -- Go to Jail
By Mark Rasch
Imagine discovering a flaw in an operating system that would permit you to
obtain root privileges. Imagine then posting information about this
vulnerability to a message board dedicated to information security, along
with a link to an exploit that could be assembled to take advantage of the
vulnerability. Does the vendor of the OS congratulate you?
http://online.securityfocus.com/columnists/100
4. InforwarCon 2002
InforwarCon 2002: Homeland Defense and Cyber-Terrorism, Washington, DC
September 4-5, 2002, optional workshops September 3 & 6. Presented by MIS
Training Institute and Interpact, Inc. Proven strategies for protecting
against threats to critical infrastructures and government systems.
Go to: http://www.misti.com/08/iw02nl26inf.html
5. SecurityFocus DPP Program
Attention Non-profit Organizations and Universities!! Sign-up now for
preferred pricing on the only global early-warning system for cyber
attacks - SecurityFocus DeepSight Threat Management System.
Click here for more information:
http://www.securityfocus.com/corporate/products/dpsection.shtml
II. BUGTRAQ SUMMARY
-------------------
1. ArGoSoft Mail Server Pro Mail Loop Denial of Service Vulnerability
BugTraq ID: 5395
Remote: Yes
Date Published: Aug 05 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5395
Summary:
ArGoSoft Mail Server is an STMP, POP3 and Finger server for Microsoft
Windows environments. ArGoSoft has a built in web server to enable remote
access to mail.
A remotely exploitable denial of service vulnerability in ArGoSoft Mail
Server Pro has been reported. It is possible for remote attackers with
regular user privileges to create a mail-loop condition that will consume
all available system resources.
ArGoSoft Mail Server Pro implements mail-loop protection that will prevent
loops when a user account is forwarding mail to itself. When autoreplies
are enabled, however, this protection is not put into place. It is
possible for a user to create a loop condition that is not detected or
stopped by forwarding mail to themselves with autoreplies enabled.
An attacker may consume resources by creating loop conditions with
multiple accounts.
In addition to a denial of mail service, degradation of overall system
performance may result. Furthermore, disk space may be consumed when the
messages are stored.
2. Avaya Cajun Firmware Default Community String Vulnerability
BugTraq ID: 5396
Remote: Yes
Date Published: Aug 05 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5396
Summary:
Vulnerable versions of firmware for the Avaya Cajun line of network
switches include a default read/write community string. Remote attackers
may use the community string to view/set potentially sensitive properties
within the device. Denial of service, network compromise may be possible.
The community string, 'NoGaH$@!', is built into the firmware and has
read/write access to the MIB. Unauthorized remote hosts may utilize it to
gain access to the device.
Using standard SNMP tools, attackers may traverse the MIB and view
potentially sensitive information (interfaces, network configuration,
etc). Attackers may also set configuration parameters and other
properties within the MIB. It has been demonstrated that the device can
be reset by setting a certain property. In addition to the confirmed
denial of service attack, attackers may be able to carry out traffic
redirection attacks. This is not confirmed.
Avaya has removed the default community string in new versions of
firmware.
3. Qualcomm Eudora MIME Multipart Boundary Buffer Overflow Vulnerability
BugTraq ID: 5397
Remote: Yes
Date Published: Aug 05 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5397
Summary:
Eudora is a popular graphical e-mail client for Windows computers offered
for free by Qualcomm. A buffer overflow vulnerability has been reported
in Qualcomm's Eudora mail client for Windows systems.
The condition occurs if a MIME multipart boundary is of excessive length.
It is believed that this is a stack-based overflow. The discoverer of the
vulnerability has confirmed that it can be exploited to execute
instructions on victim hosts.
The vulnerability may be exploited by constructing a malicious message and
then sending it to the victim. The message needs to contain a MIME
encoded message with a boundary delimited by a string of 139 or more
bytes. It is likely that the recipient must open the message before the
overflow is triggered, however this is not confirmed.
Successful exploitation of this vulnerability may provide remote access to
the attacker. This vulnerability has additionally been found to affect
Windows 2000 Professional, Japanese Edition, with Service Pack 2 applied.
4. Multiple Vendor calloc() Implementation Integer Overflow Vulnerability
BugTraq ID: 5398
Remote: Unknown
Date Published: Aug 05 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5398
Summary:
The calloc() C library call is used to dynamically allocate memory. It
differs from malloc() in that it facilitates allocation of a number of
elements of a specified size in one call. In various different
programming languages there exists similiar language-specific operations.
For example, instantiating an array of objects in C++:
pointer = new SomeClass[n];
When calculating the total amount of memory to allocate, several of these
implementations do not check for integer overflow conditions. If the
amount of memory requested exceeds the greatest value that can be
represented by a machine word, a buffer that is too small may be
allocated. As this is not caught, the procedure will return successfully
and the invoking application will operate as though the requested buffer
has been allocated.
This condition may have security implications. A heap overrun condition
may result if the invoking application attempts to write into the buffer
at a location beyond the boundary of what was actually allocated. This
vulnerability is of particular importance if the attacker has full or
limited control over the arguments to the vulnerable operation.
5. FreeBSD Arbitrary FFS Filesystem Data Block Access Vulnerability
BugTraq ID: 5399
Remote: No
Date Published: Aug 06 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5399
Summary:
The default filesystem on FreeBSD systems is the Berkeley Fast File System
(FFS). A vulnerability has been reported when allocating file sizes on a
FFS system.
The vulnerability is a result of improperly calculating file sizes on a
FFS filesystem. The vulnerability may allow users to create files that are
larger than what FreeBSD's virtual memory system may handle. This may
result in a user having access to arbitrary filesystem blocks.
The vulnerability only occurs on FFS filesystems with a block size of
greater than 16k, on the i386 architecture, or greater than 32k, on the
alpha architecture. The filesystem must also have at least six blocks of
free space and an attacker must have write access to at least one file on
the filesystem.
6. Opera FTP View Cross-Site Scripting Vulnerability
BugTraq ID: 5401
Remote: Yes
Date Published: Aug 06 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5401
Summary:
A cross-site scripting vulnerability in Opera has been reported.
When viewing the contents of a FTP site as web content from a ftp:// URL,
the username value is included in the HTML representation. It is not
adequately sanitized before this occurs. An attacker may embed javascript
as this value between opening and closing "<title>" tags in a FTP URL.
When the URL is clicked on and the FTP view is rendered, the embedded
script code will be executed by the victim client in the context of the
server.
Under some circumstances, the script code may be able to access sensitive
data (for eample, cookies associated with the FTP server domain).
This vulnerability has been confirmed on Opera 6.03 and 6.04 for Windows
2000.
7. Mozilla FTP View Cross-Site Scripting Vulnerability
BugTraq ID: 5403
Remote: Yes
Date Published: Aug 06 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5403
Summary:
A cross-site scripting vulnerability in Mozilla has been reported.
When viewing the contents of a FTP site as web content from a ftp:// URL,
the directory name is included in the HTML representation. It is not
adequately sanitized before this occurs. An attacker may embed javascript
as this value between opening and closing "<title>" tags in a FTP URL.
When the URL is clicked on and the FTP view is rendered, the embedded
script code will be executed by the victim client in the context of the
server's domain.
Under some circumstances, the script code may be able to access sensitive
data (for eample, cookies associated with the FTP server domain).
Mozilla 1.0 running on Windows 2000 SP2 is confirmed vulnerable.
8. FreeBSD NFS Zero-Length RPC Message Denial Of Service Vulnerability
BugTraq ID: 5402
Remote: Yes
Date Published: Aug 06 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5402
Summary:
A vulnerability has been reported in FreeBSD's implementation of NFS
(network file system).
The vulnerability occurs due the improper handling of certain incoming RPC
(Remote Procedure Call) messages. When the NFS server receives a message
with a zero length payload, the server would reference the payload from
the previous message. This creates a loop in the message chain and will
later develop into an infinite loop in a different area of the NFS server.
An attacker can exploit this vulnerability by constructing a sequence of
malicious requests to a vulnerable NFS server. This would result in the
NFS server locking up and producing a denial of service condition.
9. qmailadmin Local Buffer Overflow Vulnerability
BugTraq ID: 5404
Remote: No
Date Published: Aug 06 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5404
Summary:
The qmailadmin utility, developed by Inter7, is a web-based qmail
administration tool. The 'qmailadmin' executable is vulnerable to a
buffer overflow condition. The condition may be exploited if attackers
with local access can run it.
The 'qmailadmin' executable is typically installed setuid (owned by root
on some systems, regular users on others). qmailadmin fails to implement
adequate bounds checking when processing the 'QMAILADMIN_TEMPLATEDIR'
environment variable. If a local attacker executes 'qmailadmin' with the
value of this variable set to a string of excessive length, a buffer
overrun will occur.
It is likely that this can be exploited by malicious local users to
elevate privileges.
10. Nullsoft WinAmp HTML Playlist Script Injection Vulnerability
BugTraq ID: 5407
Remote: Yes
Date Published: Aug 06 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5407
Summary:
Nullsoft Winamp is a skinable media player for Microsoft Windows
supporting MP3 and other filetypes.
A script injection vulnerability has been reported for WinAmp. Reportedly,
WinAmp does not properly sanitize user supplied input before being
included when generating HTML playlists. It is possible for an attacker to
include malicious HTML code using certain fields of the ID3v2 file tags.
The vulnerability occurs when malicious HTML code is included as part of
the 'Title' and 'Artist' fields.
An attacker may construct a malicious ID3v2 tag containing dangerous HTML
code and entice a vulnerable user to download the media file. If the
victim user downloads the media file and chooses to create a HTML
playlist, the script code will be rendered, and execute within the context
of the vulnerable system.
It is likely that the script code will execute within the context of the
local system. In this case, it may be possible for the malicious script to
take arbitrary local actions, with the permissions granted by the web
browser software.
This vulnerability was reported for Nullsoft WinAmp 2.76 and 2.79 on
Microsoft Windows 98.
It has been reported that WinAmp 2.80 is not vulnerable to this issue.
This information has not been confirmed by the vendor.
11. FreeBSD kqueue Kernel Panic Denial Of Service Vulnerability
BugTraq ID: 5405
Remote: No
Date Published: Aug 06 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5405
Summary:
A vulnerability has been reported in FreeBSD's implementation of the
kqueue mechanism. kqueue provides a means for user applications to tie
into some events associated with a given file descriptor, and receive
asynchronous notifications when these events occur.
One such event is EVFILT_WRITE, which returns whenever it is possible to
write to the associated file descriptor. If a pipe is created through the
pipe(2) system call, and one end subsequently closed, associating the
EVFILT_WRITE event with the open end can cause a kernel panic.
A local user may easily create this condition with a malicious program.
Exploitation of this vulnerability may allow a local user to create a
denial of service condition, and require that the vulnerable system be
restarted in order to regain normal functionality.
12. Gaim Jabber Plug-In Buffer Overflow Vulnerability
BugTraq ID: 5406
Remote: Yes
Date Published: Aug 06 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5406
Summary:
Gaim is an instant messaging client that supports numerous protocols. It
is available for Unix and Linux variants.
The Gaim client Jabber messaging plug-in is prone to a buffer overflow
condition. The exact details of this issue are not currently known.
However, it is possible that an attacker may leverage this condition to
cause memory to be corrupted with attacker-supplied values, resulting in
execution of arbitrary code as the user running the vulnerable client.
13. Microsoft Windows Window Message Subsystem Design Error Vulnerability
BugTraq ID: 5408
Remote: No
Date Published: Aug 06 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5408
Summary:
A serious design error in the Win32 API has been reported. The issue is
related to the inter-window message passing system.
In the Win32 model, all windows on the desktop are considered peers. As
such, windows may pass messages to each other without respect to the
access level of the controlling processes.
This is a fundamental design flaw, as certain messages may adversely
affect the operation of the receiving process. Win32 messages are fairly
powerful. For example, messages may manipulate the properties of window
components (such as the length limit of a text input field). Altering
these properties may create exploitable conditions. The obvious example is
exposing a buffer overflow condition by changing the length limit of an
input field.
Furthermore, the message 'WM_TIMER' can be used to execute arbitrary code
if instructions can be placed in executable memory of the victim process.
The 'WM_TIMER' message can include the address of a callback function in
process memory. If the address parameter is set to the location of
instructions placed in memory of the target process (through an input
field or some other method), the code will be executed by the target
process. The message 'EM_GETLINE' may also be used to write the
instructions to any location in process memory.
This flaw is wide-ranging, likely affecting almost every Win32
window-based application. Attackers with local access may exploit this
vulnerability to elevate privileges if a window belonging to another
process with higher privileges is present. One example of such a process
is antivirus software, which often must run with LocalSystem privileges.
14. Microsoft Internet Explorer Invalid SSL Certificate Chain Vulnerability
BugTraq ID: 5410
Remote: Yes
Date Published: Aug 06 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5410
Summary:
A flaw has been reported in the handling of SSL certificates by
Microsoft's Internet Explorer web browser. It may be possible for a
malicious party to create SSL certificates for arbitrary domains, which
will be treated as trusted by the vulnerable browser.
SSL certificates are normally granted and signed by a trusted root
authority, several of which are defined by default in most major web
browsers. It is possible, however, to create a chain of certificates. In
this case, the root certificate must be trusted, and intermediate
certificates should possess a Basic Constraints field which states the
certificate may be used as a signing authority.
Reportedly, Microsoft Internet Explorer does not require the Basic
Constraints field be properly defined. As a result, arbitrary certificates
may be used as intermediate authorities in a certificate chain. A
malicious party with one valid certificate may sign a new certificate for
an arbitrary domain.
The attacker may use the new certificate in order to impersonate a domain.
If the attacker is in a position to spoof the domain, or to implement a
man-in-the-middle attack, the malicious certificate may allow the attack
to go undetected.
Reportedly, Internet Explorer 6.0 will honor a Basic Constraints field
which is explicitely set to False. However, certificates without an
explicitely defined value for this field are still accepted as valid
intermediate authorities.
15. Microsoft Exchange 2000 Post Authorization License Exhaustion Denial Of Service Vulnerability
BugTraq ID: 5413
Remote: Yes
Date Published: Aug 06 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5413
Summary:
A vulnerability has been reported for Microsoft Exchange 2000.
Allegedly, Exchange 2000 will experience a denial of service condition
when an authenticated user makes many requests. The vulnerability is due
to IIS incorrectly allocating licenses to Exchange. Making numerous, rapid
requests will exhaust available licenses granted to Exchange by IIS.
Successful exploitation of this vulnerability will result in Exchange not
responding to further, legitimate requests for service.
This vulnerability has been reported for Microsoft Exhange 2000. It is not
known whether other versions are affected. This BID will be updated as
further information becomes available.
16. Microsoft SQL Server Remote Buffer Overflow Vulnerability
BugTraq ID: 5411
Remote: Yes
Date Published: Aug 06 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5411
Summary:
A vulnerability has been discovered in Microsoft SQL Server that could
make it possible for remote attackers to gain access to target hosts.
It is possible for an attacker to cause a buffer overflow condition on the
vulnerable SQL server.
This vulnerability reportedly occurs even before authentication can
proceed. Reportedly, this is due to a default system configuration.
Microsoft SQL Server listens for connections on TCP port 1433.
An attacker can exploit this vulnerability by sending specially crafted
packets to TCP port 1433 which causes SQL Server to crash and possibly
execute attacker supplied code.
It is not known which versions of SQL Server are vulnerable. This BID will
be updated as further information becomes available.
It is possible that this issue may be remotely exploitable to execute
arbitrary code as a system process, possibly leading to local access to
the vulnerable system.
17. Microsoft Exchange 2000 Multiple MSRPC Denial Of Service Vulnerabilities
BugTraq ID: 5412
Remote: Yes
Date Published: Aug 06 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5412
Summary:
Microsoft Exchange makes usage of the MSRPC, the Microsoft Remote
Procedure Call framework. Several potential issues have been reported in
MSRPC, as used in conjunction with Microsoft Exchange.
Reportedly, it is possible to cause the Exchange process to crash with an
Access Violation error. This may occur if malicious MSRPC messages are
recieved. It has been reported that authentication is not required. If
this condition is exploited, the Exchange service may have to be restarted
in order to regain normal functionality.
Additionally, it may be possible to consume all available system memory
through a malformed MSRPC call. This can lead to the system halting with a
blue screen error. In either case, a system restart will be required in
order to regain normal functionality.
The nature of these issues suggests that memory corruption may be
occuring. If that is the case, it is possible that these issues may be
remotely exploitable to execute arbitrary code as a system process,
possibly leading to local access to the vulnerable system. This
possibility has not, however, been confirmed.
18. LibPNG Wide Image Processing Memory Corruption Vulnerability
BugTraq ID: 5409
Remote: Yes
Date Published: Aug 06 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5409
Summary:
The libpng graphics library is reported to be prone to a security-related
issue with regards to handling of overly wide images. It may be possible
to corrupt memory with an overly wide PNG image. An attacker may be able
to exploit this condition to execute arbitrary code with the privileges of
an application or client which handles the overly wide image, though this
possibility has not been confirmed.
It may be possible to exploit this issue via a web client that is
configured to load PNG images automatically.
Patches have been released which address this condition by preventing
libpng from processing overly wide images.
19. Nullsoft SHOUTCast Insecure Permissions Information Disclosure Vulnerability
BugTraq ID: 5414
Remote: No
Date Published: Aug 06 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5414
Summary:
Nullsoft SHOUTCast Server is used to broadcast Shoutcast music. It is
available for Unix and Linux operating systems, as well as Microsoft
Windows.
Nullsoft SHOUTCast may, under some circumstances, leave administrative
credentials stored in a world-readable logfile.
When failed authentication requests (specifically a GET / request) are
made to the SHOUTCast server via TCP port 8001, the real authentication
credentials will be logged to a SHOUTCast server logfile (sc_serv.log),
which is located in the SHOUTCast directory. Local attackers may
trivially gain access to these credentials since the logfile by default
has world-readable permissions.
This issue was reported for versions of the software running and Unix and
Linux platforms. Other versions may also be affected.
20. Microsoft Windows 2000 Insecure Default File Permissions Vulnerability
BugTraq ID: 5415
Remote: No
Date Published: Aug 06 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5415
Summary:
Microsoft Windows 2000 sets the default file permissions on a number of
sensitive system files to prevent modification by unprivileged users.
Files such as boot.ini, autoexec.bat and ntldr are only readable by
non-privileged users. Administrative or 'Power User' access is required to
modify such files.
By default, however, the main system directory which contains these files
is world read and writable. As a result, a non-privileged user may delete
these sensitive files. Once deleted, the files may be replaced with
malicious versions owned by the non-privileged user. If accessed by
automatic system processes, such as during bootup, privileged access may
be trivial to obtain.
21. Cisco VPN 5000 Concentrator Plaintext Password
BugTraq ID: 5417
Remote: Yes
Date Published: Aug 07 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5417
Summary:
The VPN 5000 Concentrator line supports the use of a RADIUS server to
authenticate client connections. An error has been reported in this
authentication process when either PAP or Challenge authentication is
used.
For Access-Request RADIUS messages, the VPN 5000 device will encrypt the
user password. However, if a response to the initial RADIUS request is not
recieved, the device will retransmit a second request. In this case, the
client password is no longer encrypted. An attacker able to sniff network
traffic will be able to view the password.
This condition may also occur if a request is sent to a defined backup
RADIUS server.
Cisco has reported that this issue does not exist if CHAP authentication
is used.
22. Ensim Webppliance Unauthorized Email Access Vulnerability
BugTraq ID: 5418
Remote: Yes
Date Published: Aug 07 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5418
Summary:
Webppliance is a webhosting solution provided by Ensim. It is developed
for use with Linux and Unix variant as well as Microsoft Windows operating
environments.
A vulnerability has been reported for Ensim Webppliance. Reportedly, it is
possible for malicious users of Webppliance to receive other users'
emails.
The vulnerability is the result of Webppliance incorrectly processing an
existing user's email alias. Reportedly, users that are allocated email
and user accounts can intercept another user's email.
An attacker can exploit this vulnerability by selecting to add a valid
email account as an alias. Once this alias has been established, any
emails that arrive for the victim user will be intercepted by the attacker
and arrive in the attacker's inbox.
This vulnerability was reported for Ensim Webppliance 3.0 and 3.1. It is
not known whether other versions are affected.
23. Multiple Microsoft Content Management Server 2001 Vulnerabilities
BugTraq ID: 5419
Remote: Yes
Date Published: Aug 07 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5419
Summary:
Microsoft has reported three vulnerabilities in Microsoft Content
Management Server (MCMS) 2001. Microsoft Content Management Server 2001
is a .NET Enterprise Server product for development and management of
e-business websites.
The first issue is reported to be a buffer overflow condition in a
low-level function that facilitates user-authentication. At least one
webpage that ships with the product contains an exposure to the vulnerable
function, and may allow attackers to exploit the condition. This may be
exploited by a remote attacker to execute arbitrary instructions in the
Local System context or potentially create a denial of service condition.
Malformed authentication information may trigger this condition in a
webpage which provides authentication and calls the vulnerable function.
The second issue is reported to be the result of two flaws in a particular
function (MCMS Authoring) and may potentially allow remote attackers to
upload files to arbitrary locations on a vulnerable system. The first
flaw is in the user authentication aspect of the vulnerable function, and
may allow arbitrary users to submit upload requests to the server.
Additionally, a flaw exists which may allow files to be uploaded to an
arbitrary location. Normally, uploaded files are stored in a directory
without execute permissions. However, the existence of this second flaw
in the affected function may allow for files to be uploaded to an
attacker-specified location, where they will reside for a short period of
time. This may allow for execution of arbitrary attacker-supplied files.
Successful exploitation would cause the file to be executed in the context
of the Web Application Manager.
The third issue is reported to be an SQL injection vulnerability in the
MCMS Resource Request function. This function is used to handle requests
for image files and other types of resources on the server. This issue
could effectively be exploited to execute commands in the context of the
SQL Server 2000 service, which amounts to the privileges of the Domain
user.
** This vulnerability record will be divided into seperate entries for
each individual vulnerability.
24. Microsoft Content Management Server 2001 User Authentication Buffer Overflow Vulnerability
BugTraq ID: 5420
Remote: Yes
Date Published: Aug 07 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5420
Summary:
Microsoft Content Management Server (MCMS) 2001 is a .NET Enterprise
Server product for development and management of e-business websites. A
remotely exploitable buffer overflow condition was reported in the
low-level MCMS Authentication Operation function.
At least one webpage that ships with the product contains an exposure to
the vulnerable user authentication function, and may allow attackers to
exploit the condition. Any created webpages which include authentication
and a call to the vulnerable function may also be prone to this
vulnerability.
An attacker must supply malformed authentication information to trigger
this condition in a webpage which calls the vulnerable function. By
providing appropriately malformed authentication information, it is
possible to corrupt memory with attacker-supplied values. This may be
exploited by a remote attacker to execute arbitrary instructions in the
Local System context or potentially create a denial of service condition.
** This issue was originally described in Bugtraq ID 4519 "Multiple
Microsoft Content Management Server 2001 Vulnerabilities" and has been
divided into this individual record.
25. Microsoft Content Management Server 2001 SQL Injection Vulnerability
BugTraq ID: 5422
Remote: Yes
Date Published: Aug 07 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5422
Summary:
Microsoft Content Management Server (MCMS) 2001 is a .NET Enterprise
Server product for development and management of e-business websites.
MCMS allows users and web pages to request files such as images, from a
database residing on a Microsoft SQL 2000 Server.
The function that accepts these requests does not properly sanitize data
that is accepted from the interface. SQL code may be inserted into the
requests and executed by the server. These requests could include adding,
deleting, and modifying data.
It is also possible for the user to execute operating system commands
through this vulnerability. The commands would be executed with the
privileges of the SQL Server service.
By default, SQL Server has full access to the databases, but only domain
user privileges on the operating system.
** This issue was originally described in Bugtraq ID 4519 "Multiple
Microsoft Content Management Server 2001 Vulnerabilities" and has been
divided into this individual record.
26. Microsoft Content Management Server 2001 Arbitrary Upload Location Vulnerability
BugTraq ID: 5421
Remote: Yes
Date Published: Aug 07 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5421
Summary:
Microsoft Content Management Server (MCMS) 2001 is a .NET Enterprise
Server product for development and management of e-business websites. A
vulnerability has been reported in some versions of MCMS which may allow
the remote execution of arbitrary code.
MCMS provides functionality for authenticated users to upload additional
content to the server. Normally, this content is forced into a safe
location, where it can not be remotely executed. However, the flaw allows
the remote user to specify an arbitrary location on the server.
A malicious user may place executable content such as ASP files in a
public directory. If then requested, the supplied code will execute on the
local machine. By default, code will run as the non-privileged
IWAM_machinename account. Exploitation may, however, provide local access
to the vulnerable system.
Reportedly uploaded files will reside in the specified location for a
short time before being deleted. Some degree of timing may be required in
order to implement a successful attack.
An additional flaw in some versions of MCMS may allow an arbitrary remote
user to upload content without authentication. In conjunction, this may
allow any attacker able to connect to the vulnerable service to exploit
this vulnerability.
** This issue was originally described in Bugtraq ID 4519 "Multiple
Microsoft Content Management Server 2001 Vulnerabilities" and has been
divided into this individual record.
27. iSCSI Insecure Configuration File Permissions Information Disclosure Vulnerability
BugTraq ID: 5423
Remote: No
Date Published: Aug 08 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5423
Summary:
The iSCSI (Internet Small Computer System Interface) protocol is an
Internet Protocol (IP) based storage networking standard for linking data
storage facilities.
iSCSI leaves administrative credentials stored in a world-readable
configuration file.
The configuration file that iSCSI uses is stored in /etc/iscsi.conf.
Reportedly, this file is installed, by default, with world readable and
possibly world writeable permissions enabled. This may have some
potentially serious consequences as the configuration file also stores
password information in plain text.
Reportedly, RedHat Linux Limbo Beta and SuSE ship with iSCSI. SuSE has
reported that proper permissions are enabled for iSCSI. RedHat has
confirmed that Limbo Beta ships with improper file permissions enabled and
will reportedly fix it in the next release of Limbo.
28. Google Toolbar Unauthorized JavaScript Configuration Modification Vulnerability
BugTraq ID: 5424
Remote: Yes
Date Published: Aug 08 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5424
Summary:
The Google Toolbar is an ActiveX control for Microsoft Internet Explorer,
which provides functionality related to the Google search engine. An error
has been reported in the method in which the Google Toolbar updates
configuration options.
It is possible to modify configuration settings by visiting a specific URL
that accepts commands as CGI parameters. While any page may reference this
URL, requests are only honored if they are received from within the
google.com domain, or URLs using the local res:// protocol.
It is possible, however, for malicious scripts to open a new page in
either of the allowed domains, and then reset the location to a URL that
will modify toolbar settings. It is possible to change most options of the
toolbar configuration.
It is also possible to pass arbitrary JavaScript to the configuration URL.
This script code will execute within the context of the referencing site.
If local files referenced with the res:// protocol are used, attacker
supplied script code may execute within the Local Computer security zone.
29. Ipswitch WS_FTP Server CPWD Remote Buffer Overflow Vulnerability
BugTraq ID: 5427
Remote: Yes
Date Published: Aug 08 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5427
Summary:
Ipswitch WS_FTP Server is a FTP server for Microsoft Windows platforms.
WS_FTP Server is vulnerable to a buffer overflow condition when a user
submits a specially crafted FTP command.
The buffer overflow is related to the handling of the CPWD command, used
to modify an authenticated user's password. Reportedly, oversized
parameters to this command allow an attacker to corrupt sensitive process
memory, including stack frame information.
Exploitation may lead to the remote execution of arbitrary code, possibly
with SYSTEM privileges. It may also be possible to crash the server
process by sending arbitrary oversized data, leading to a denial of
service condition.
This issue has been reported in WS_FTP Server 3.1.1. Earlier versions may
share this vulnerability, this has not however been confirmed.
30. Google Toolbar Keypress Monitoring Information Disclosure Vulnerability
BugTraq ID: 5426
Remote: Yes
Date Published: Aug 08 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5426
Summary:
The Google Toolbar is an ActiveX control for Microsoft Internet Explorer,
which provides functionality related to the Google search engine.
It has been reported that keypress events in some versions of the Google
Toolbar are also sent to the underlying browser window. A malicious script
executing in the current browser window may monitor keypress events, and
access whatever is typed into the toolbar.
Under some circumstances, this may lead to the disclosure of potentially
sensitive information.
31. HP EMANATE 14.2 Predictable SNMP Community String Vulnerability
BugTraq ID: 5428
Remote: Yes
Date Published: Aug 08 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5428
Summary:
EMANATE (Enhanced MANagement Agent Through Extensions) allows SNMP
management via modularly extensible management agents.
HP EMANATE 14.2 systems use a predictable default community string.
Attackers who can guess the SNMP community string may gain unauthorized
SNMP access, which may result in disclosure of sensitive information.
"Community strings" are labels used by SNMP to delimit groups of "objects"
(variables) that can be viewed or modified on a device. An attacker with
access to community strings may be able to obtain unauthorized access to
devices. This may lead to disclosure of sensitive information, such as
network infrastructure or exploited to potentially cause a denial of
service.
32. HP-UX PTrace Page Data Fault Denial Of Service Vulnerability
BugTraq ID: 5425
Remote: No
Date Published: Aug 06 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5425
Summary:
HP-UX includes an implementation of the process trace (ptrace) system call
for allowing one process to control the execution of another. ptrace is
used for debugging purposes.
The HP-UX implementation of ptrace is prone to an issue which may allow
local attackers to cause a system to panic, resulting in a denial of
service. This condition is reportedly produced when an incorrect
reference is made to a thread register state, resulting in a data page
fault panic.
33. Macromedia Flash Player Arbitrary Local File Access Vulnerability
BugTraq ID: 5429
Remote: Yes
Date Published: Aug 08 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5429
Summary:
Macromedia Flash is a modular package designed to enhance web browsing and
enables users to view various multimedia web content. An error has been
reported in some versions of the Flash player. Malicious Flash animations
may be able to read arbitrary local files.
Flash animations are allowed to load additional files through HTTP.
Normally, this functionality is used to load data needed for the
animation. The Flash Player prevents the loading of any files outside of
the domain of origin of the animation.
However, if a HTTP redirect is given as the response to a legal request,
additional security checks are not made. A malicious server may issue a
HTTP redirect for a known local file, which will then be loaded by the
animation. The animation may then take actions based on sensitive data, or
transmit the data back to the malicious server.
It has been reported that it is also possible to exploit this issue by
setting a base href URL pointing towards the local system, such as
"file:///c:/", and then using a relative URL within the flash animation.
Relative URLs may also be used in conjunction with content embedded in MHT
files to exploit this issue.
Exploitation of this issue may result in the disclosure of sensitive
information, including authentication credentials. The consequences of
exploitation may be dependant on the details of the vulnerable client
system.
34. Macromedia Flash Malformed Header Buffer Overflow Vulnerability
BugTraq ID: 5430
Remote: Yes
Date Published: Aug 08 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5430
Summary:
Macromedia Flash is a modular package designed to enhance web browsing and
enables users to view various multimedia web content.
Macromedia Flash is prone to a buffer overflow condition. This is due to
insufficient bounds checking of headers in Flash Shockwave movie files
(.SWF). It is reportedly possible to exploit this issue by hand-editing
header information in a movie file with a hex editor. When the movie with
the malformed header is processed by Flash, the condition will occur,
resulting in corruption of memory. In particular, it is frame data in the
header which must be malformed for memory corruption to occur. An
attacker may exploit this to overwrite function pointers with
attacker-supplied values.
Successful exploitation will allow an attacker to execute arbitrary code
on a client system running Macromedia Flash. An attacker would have to
entice a user of the vulnerable software to load the malformed movie file.
This might be accomplished via a malicious webpage, e-mail, newsgroups or
any other means by which the malicious movie file may be transmitted to a
user. Code execution will occur with the privileges of the user running
the player.
The Macromedia Flash plug-in is included in a number of web browsers.
This issue is known to affect Macromedia Flash on all platforms.
35. Qualcomm Eudora File Attachment Spoofing Vulnerability
BugTraq ID: 5432
Remote: Yes
Date Published: Aug 08 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5432
Summary:
Eudora is a graphical e-mail client for Windows computers offered for free
by Qualcomm.
Eudora is reported to be prone to an issue which may allow attackers to
spoof the file extension in an attachment. This may aid an attacker in
enticing a user of the e-mail client into executing malicious content, and
in avoiding generating warning messages.
It is possible to refer to other files or attachments in a message through
specially formatted inline text. It has been demonstrated possible to
misrepresent some aspects of files referenced in this manner. This may
cause end users to make erroneous judgements about the nature of file
attachments, and allow malicious attachments to bypass normal warning
dialogs displayed when executable content is launched.
These errors appear to be related to interactions between the underlying
operating system, the provided attachment path and filename, and an
additional filename which is displayed to the end user.
If an attachment path to an executable file has a single '.' character
appended, warning messages will not be displayed. Attachments such as
'calc.exe.' may execute when launched without the requirement for further
interaction. Additionally, an arbitrary file name may be specified by the
attacker which will be displayed to the end user. If a filename such as
'readme.txt' is associated with a malicious, executable attachment, the
user may make innacurate decisions about the risk associated with opening
the attachment. If the specified file does not exist on the local system,
the full path provided will be used to locate and launch a file, with no
further warnings given.
Successful exploitation may require the attacker to know the full path to
the attachment directory.
36. Sun ONE/iPlanet Web Server Chunked Encoding Vulnerability
BugTraq ID: 5433
Remote: Yes
Date Published: Aug 08 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5433
Summary:
A vulnerability has been discovered in the Sun ONE web server (formerly
known as iPlanet) implementation of 'Chunked Encoding'. The HTTP protocol
specifies a method of data encoding called 'Chunked Encoding', designed to
facilitate fragmentation of HTTP requests in transit. When processing
requests coded with the 'Chunked Encoding' mechanism, Sun ONE fails to
properly calculate required buffer sizes.
Successful exploitation of this vulnerability may be accomplished by
crafting a malformed chunked encoded session which would overwrite the
heap. Thus data structures may be manipulated to inject malicious code
into attacker supplied memory addresses. Execution of arbitrary code or a
denial of service condition may result.
37. Apache 2.0 Information Disclosure Vulnerability
BugTraq ID: 5434
Remote: Yes
Date Published: Aug 09 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5434
Summary:
A vulnerability has been reported in Apache versions 2.0.39 and earlier on
non-Unix platforms (potentially including Apache compiled with CYGWIN).
Platforms that may be affected by this include Windows, OS2, and Netware.
This issue is reported to allow remote attackers to gain access to
sensitive information but may also allegedly be exploited to damage a
server in other ways.
Full details have not been disclosed at this time. However, it has been
reported that it is possible to mitigate this issue via changes to server
configuration. Any additional details that are released will be added to
this record as they become available.
Based on the provided workaround, this issue appears to be related to how
Apache handles requests for restricted resources.
This issue will reportedly be addressed in 2.0.40.
III. SECURITYFOCUS NEWS AND COMMENTARY
--------------------------------------
1. 'Creative Attacks' Beat Crypto -- Expert
By Ann Harrison
Professional encryption breaker says Moore's Law increases security risks
as fast as it boosts chip storage.
http://online.securityfocus.com/news/572
2. Researcher: Biometrics Unproven, Hard To Test
By Ann Harrison
Just how accurate are the face identification systems being rolled out
around the country? It turns out, testing them is harder than it looks.
http://online.securityfocus.com/news/566
3. 'Safe' web still wide open - Windows sleuth
By Andrew Orlowski, The Register
Professor David Martin and Andrew Schulman - the latter best known for his
Windows forensics - have updated their analysis of SafeWeb's privacy
browsing system, and say it still leaves users "sitting ducks".
http://online.securityfocus.com/news/571
4. Dangers of the Google tool bar exposed
By Thomas C. Greene, The Register
A series of attacks based on a flaw in the way the Google tool bar uses
URLs to alter browser settings has been described by Israeli security
outfit GreyMagic Software.
http://online.securityfocus.com/news/570
IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. ZorbIPtraffic v0.01
by Zorbat
Relevant URL:
http://www.atout.be/
Platforms: Linux
Summary:
ZorbIPtraffic shows the IP traffic on a network interface in real time. It
can display traffic statistics for each IP on your internal network, and
it summarizes the total traffic for each IP per year, per month, and per
day. All information is stored in a MySQL database, which makes it easy to
search the traffic measurements for a specific day. ZorbIPtraffic only
works if you use iptables.
2. single-honeypot v0.1
by Luis Wong [email protected]
Relevant URL:
http://sourceforge.net/projects/single-honeypot/
Platforms: POSIX
Summary:
single-honeypot simulates many services like SMTP, HTTP, shell, and FTP.
It can show many different faces, including those of Windows FTP systems,
Windows SMTP systems, different Linux distributions, and some Posix
distributions.
3. myNetMon v1.0.3
by Ekrem ORAL
Relevant URL:
http://www.trsecurity.net/mynetmon/
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
myNetMon is windows based network monitor and packet analyzing (sniffer)
tool. myNetMon uses WinPcap, a windows port of Libpcap which is a packet
capturing library.
4. Gspoof v1.0b
by embyte
Relevant URL:
http://sourceforge.net/projects/gspoof/
Platforms: FreeBSD, Linux, NetBSD, OpenBSD
Summary:
Gspoof is a GTK+ program written in C language which makes easier and
accurate the building and the sending of TCP packets with a data-payload
or not. It's possible to modify TCP/IP fields and also ethernet header
working to Link Level. You can send one or more packets together.
5. nefu v0.7.0
by Ed Colone
Relevant URL:
http://rsug.itd.umich.edu/software/nefu/
Platforms: FreeBSD, Linux, MacOS, OpenBSD, Solaris, SunOS, UNIX
Summary:
nefu (network fidelity utility) is a Unix daemon that monitors services
over the network. It uses a "no false alarms" fault verification
algorithm, and understands network dependancies. Natively-monitored
protocols include ICMP echo (ping), DNS, HTTP, POP, NTP, IMAP, SMTP, and
LDAP, as well as having facilities to execute external programs. Status
pages are available via finger or the Web.
6. Secure Cryptographic Instant Messaging v1.04
by The Project SCIM team
Relevant URL:
http://www.projectscim.com/
Platforms: AIX, AS/400, BeOS, BSDI, DG-UX, Digital UNIX/Alpha, FreeBSD,
HP-UX, IRIX, Java, Linux, MacOS, NetBSD, OpenBSD, OpenVMS, Os Independent,
SCO, SecureBSD, Solaris, SunOS, True64 UNIX, UNIX, Unixware, VMS, Windows
2000, Windows 3.x, Windows 95/98, Windows CE, Windows NT, Windows XP
Summary:
The Project SCIM application allows you to send Encrypted Instant Messages
to your friends and other contacts. The software is free for
non-commercial users and contains a load of cool features.
V. SECURITY JOBS SUMMARY
------------------------
1. Available Sr. Sales Engineer - Security (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/286776
2. Looking for a position in UK (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/286781
3. Resume - Information Systems Security Professional (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/286774
4. Security Engineer- Bay Area (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/286780
5. Manager, Information Security -- Dallas, TX (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/286773
6. Senior Sales Manager - East Coast position available (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/286355
7. Network Security Contract: NJ. CISSP, PIX FIREWALLS, INTRUSION DETECTION (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/286369
8. InfoSec Consulting Position (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/286365
9. LDAP & Siteminder Architect/Engineer position in NYC (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/286353
VI. INCIDENTS LIST SUMMARY
-------------------------
1. large scale distributed scan of port tcp 445 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/286789
2. [unisog] Re: large scale distributed scan of port tcp 445 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/286684
3. Strange pings from akamai? {1-112POX} (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/286619
4. Strange pings from akamai? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/286533
5. Scanning Port UDP 4668 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/286280
6. (AUSCERT#c42e2) Re: odd traffic on port 80 from win 98 system -Frethem.K (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/286176
7. Honeynet Scan of the Month for August released (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/286068
8. openssh-3.4p1.tar.gz trojaned (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/286070
VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. Apache 2.0 vulnerability affects non-Unix platforms (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/286794
2. Cross-Site Scripting Issues in Falcon Web Server (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/286764
3. iDEFENSE Security Advisory: iSCSI Default Configuration File Settings (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/286515
4. OpenSSL Exploit (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/286435
5. SQL Command Insertion & Execution in Visual FoxPro (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/286460
6. IDEFENSE PAYING $$$ FOR VULNS (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/286440
7. MS SQL Server Hello Overflow NASL Script (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/286458
8. In regards to the insecurity of AOL Instant Messenger (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/286459
9. ssh trojaned (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/286436
10. qmailadmin SUID buffer overflow (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/286158
11. Cross-Site Scripting Attacks Possible At Multiple Webspace Providers (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/286117
12. JanaWeb (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/286110
13. Re: ssh trojaned (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/286105
14. SPIKE 2.5 and associated vulns (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/286099
15. Unchecked Buffer in Jana Web Server (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/286082
16. [Fwd: In regards to ... http://online.securityfocus.com/bid/5382] (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/286009
17. [Full-Disclosure] Re: Clarification on Xitami DoS (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/286006
18. REFRESH: EUDORA MAIL 5.1.1 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/285997
19. AOL Instant Messenger - Away Setting and Snoopers (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/285995
20. [Full-Disclosure] AOL Instant Messenger - Away Setting and Snoopers (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/285974
21. Clarification on Xitami DoS (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/285976
VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Password change utility (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/286700
2. SP3 Problems? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/286702
3. Another SUS / Autoupdate question (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/286617
4. Risks posed by Windows XP Scheduled Tasks? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/286505
5. Looking for a recent IE SSL bug.. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/286504
6. Closed thread --> windows update reporting info back to MS? (and .NET fw SP1) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/286434
7. windows update reporting info back to MS? (and .NET fw SP1) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/286390
8. Re[2]: windows update reporting info back to MS? (and .NET fw SP1) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/286331
9. local admin passwords (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/286317
10. Using LDAP Authentication (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/286333
11. FW: White paper: Exploiting the Win32 API. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/286214
12. windows update reporting info back to MS? (and .NET fwSP1) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/286211
13. SecurityFocus Microsoft Newsletter #98 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/286198
14. QChain obsolete? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/286173
15. Synchronising NT User Accounts with a database. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/286184
16. Windows 2000 special folder restrictions (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/286188
17. AW: Synchronising NT User Accounts with a database. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/286174
IX. SUN FOCUS LIST SUMMARY
----------------------------
1. Solaris and lack of loopback routes (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/286822
2. Fwd: Hardening NIS+ (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/286821
3. Hardening NIS+ (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/286799
X. LINUX FOCUS LIST SUMMARY
---------------------------
1. LDAP Auth? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/286526
XI. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored by: John Wiley and Sons, Inc.
NEW BOOK FROM KEVIN MITNICK TO BE RELEASED OCTOBER 4
See what Publishers Weekly called a "tour de force - a series of tales of
how some old-fashioned blarney and high-tech skills can pry any
information from anyone..."
For more information and how to order "The Art of Deception:Controlling
the Human Element of Security", visit http://www.amazon.com/mitnick
-------------------------------------------------------------------------------