SecurityFocus Newsletter #158

John Boletta <[email protected]> Mon, 19 Aug 2002 12:36:57 -0600 (MDT)
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #158
-----------------------------

This Issue is Sponsored By: Qualys

Bulletproof Your Network: FREE Guide

Existing security products -- firewalls, anti-virus and IDS -- are simply
no longer enough to ensure your networks are safe against sophisticated
attacks and worms such as Code Red and Nimda. FREE Guide shows you how to
ensure TOTAL security for your network. Get it now.

Visit us at:
https://www.qualys.com/forms/guide_220.php
-------------------------------------------------------------------------------


I. FRONT AND CENTER
     1. Configuring IPsec/IKE on Solaris
     2. No Stone Unturned, Part Six
     3. Unlocking the Secrets of Crypto: Cryptography, Encryption...
     4. The Original Anti-Piracy Hack
     5. SecurityFocus DPP Program
     6. InforwarCon 2002
     7. SpiDynamics ALERT
II. BUGTRAQ SUMMARY
     1. Orinoco OEM Residential Gateway SNMP Community String Remote...
     2. BlueFace Falcon Web Server Error Message Cross-Site Scripting...
     3. SGI IRIX ftpd PASV Mode Data Channel Hijacking Vulnerability
     4. ISDN4Linux IPPPD Device String SysLog Format String Vulnerability
     5. Midicart ASP Remote Customer Information Retrieval Vulnerability
     6. Citrix Metaframe Java ICA Environment Denial Of Service...
     7. Cisco VPN Client IKE Packet Excessive Payloads Vulnerability
     8. Cisco VPN Client IKE Security Parameter Index Payload Buffer...
     9. Cisco VPN Client Zero Length IKE Packet Denial Of Service...
     10. OpenBSD select() Buffer Overflow Vulnerability
     11. Multiple Vendor CDE ToolTalk Database Server Heap Corruption...
     12. Macromedia Flash Malformed SWF Denial Of Service Vulnerability
     13. PGP / GnuPG Chosen Ciphertext Message Disclosure Vulnerability
     14. W3C CERN httpd Proxy Cross-Site Scripting Vulnerability
     15. SGI Irix Bulk Data Services Arbitrary File Disclosure...
     16. PGPFreeware Malformed IKE Response Packet Buffer Overflow...
     17. Microsoft Internet Explorer File Attachment Script Execution...
     18. L2TPD Weak Random Number Generator Seeding Vulnerability
     19. Red Hat Interchange Arbitrary File Read Vulnerability
     20. HP-UX VVOS Unspecified Local Passwd Vulnerability
     21. Oracle 9iAS OJSP Demo Scripts Cross-Site Scripting Vulnerability
     22. CafeLog b2 WebLog Tool Cross Site Scripting Vulnerability
     23. CafeLog b2 WebLog Tool SQL Injection Vulnerability
     24. Oracle Listener Malformed Debugging Command Denial Of Service...
     25. Xinetd Open File Descriptor Denial Of Service Vulnerability
     26. HP-UX VVOS TGAD Unspecified Stack Corruption Vulnerability
     27. Oracle Net Listener Format String Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
     1. Audit Shows More PCs At the IRS Are Missing
     2. MS soft-pedals SSL hole
     3. Sleuths Invade Military PCs With Ease
     4. U.S. Aiding Asia-Pacific Anti-Cybercrime Efforts
IV. SECURITYFOCUS TOP 6 TOOLS
     1. Advisor v1.2.6-3
     2. Netfilter2html v0.6b
     3. spasm anti-spam milter v0.22
     4. radiusContext v1.81
     5. fauxident.py v1.0
     6. HTun v0.9.3b
V. SECURITYJOBS LIST SUMMARY
     1. Job openings at eEye Digital Security (Thread)
     2. DITSCAP/ INFOSEC (Thread)
     3. Information Assurance Engineer (Thread)
     4. Resume (Thread)
     5. Cyber Penetration Testing Specialist (Thread)
     6. Managed Security Services Engineer (Thread)
     7. Security Services Manager - Madison, WI (Thread)
     8. Sales Engineer (Thread)
     9. UK based Blue Chip seeks Security Architect (Thread)
     10. Checkpoint Resource needed in Boston (Thread)
     11. Sr Security SW/HW Executive (Thread)
     12. Resume of Terrence Martin (BS, CISSP) (Thread)
     13. The resume for Rafal Wojtczuk (Thread)
     14. Degree Educated Sales Executive UK ; Security Software Legal...
     15. South Florida: Information Security Engineer-Unix (Thread)
     16. Opportunity for a Sr. InfoSec Engineer with C&A Experience at...
     17. Opportunity for a Crypto-Analyst to help support our Computer...
     18. bay area security professional, $6.75/hr... Please read below!...
     19. pki, vpn, infosec engineer available in southeast (Thread)
     20. Looking for positions in Oakland, Sacramento, or the East Bay...
     21. Available Sr. Sales Engineer - Security (Thread)
     22. Looking for a position in UK (Thread)
VI. INCIDENTS LIST SUMMARY
     1. Standardized Reporting (Thread)
     2. Subseven Scans; Standardized Reporting (Thread)
     3. Subseven Scans (Thread)
     4. Increased IIS scans mainly on 66.0.0.0/8 (Thread)
     5. Odd scans and stuff bouncing off firewalls (Thread)
     6. RPC scans (Thread)
     7. FW: Subseven Scans (Thread)
     8. Re[2]: Subseven Scans (Thread)
     9. strange apache log entry (Thread)
     10. Odd activity. (Thread)
     11. Strange pings from akamai? {1-112POX} (Thread)
     12. large scale distributed scan of port tcp 445 (Thread)
     13. [unisog] Re: large scale distributed scan of port tcp 445...
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. Extending IE SSL exploit to exploit WindowsUpdate (Thread)
     2. SILLY BEHAVIOR : Internet Explorer 5.5 - 6.0 (Thread)
     3. ZoneAlarm memory leak ? (Thread)
     4. L-Forum Vulnerability - SQL Injection (Thread)
     5. Multiple Vulnerabilities in CafeLog Weblog Package (Thread)
     6. strange man behavior (Thread)
     7. ie ssl and software (Thread)
     8. ToorCon Call for Papers 5 Day Notice (Thread)
     9. Apache 2.0 vulnerability affects non-Unix platforms (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. Win2k network changes (Thread)
     2. SP3 Problems? (Thread)
     3. Exchange SSL Connection warning message (Thread)
     4. Patch for ms02-40 "HELLO BUG" doesn't working (Thread)
     5. Problems using Windows Update on Windows XP Pro (Thread)
     6. .Net Server and 'taskkill' (Thread)
     7. Win2k Terminal Services (Thread)
     8. Client certificates in M$ outlook (Thread)
     9. Password change utility (Thread)
     10. SCE Templates from a Network Drive (Thread)
     11. SecurityFocus Microsoft Newsletter #99 (Thread)
     12. Another SUS / Autoupdate question (Thread)
     13. AW: SP3 Problems? (Thread)
     14. SP3 Article Updated on Microsoft Technet (Thread)
IX. SUN FOCUS LIST SUMMARY
     1. Hardening NIS+ (Thread)
     2. There's something about hardening NFS? (Thread)
     3. Solaris and lack of loopback routes (Thread)
     4. Solaris 8 username contingency (Thread)
     5. Fwd: Hardening NIS+ (Thread)
X. LINUX FOCUS LIST SUMMARY
     1. NO NEW POSTS THIS WEEK
XI. SPONSOR INFORMATION




I. FRONT AND CENTER
-------------------
1. Configuring IPsec/IKE on Solaris
By Ido Dubrawsky

The IP Security Protocol (IPsec) and the Internet Key Exchange (IKE)
protocol are designed to permit system and network administrators the
capability to protect traffic between two systems. This article is the
first of a three-part series that will examine IPsec and the key
management protocol, IKE, and provide readers with an introduction on how
to configure both protocols on a Solaris host.

http://online.securityfocus.com/infocus/1616

2. No Stone Unturned, Part Six
by H. Carvey

This is an additional installment to the No Stone Unturned series, which
was written to help clarify to NT/2K admins the steps they can take to
determine the nature and purpose of suspicious files found on their
systems. In Part Five of the series, our heroic system administrator found
an unusual file on a compromised system. In this bonus installment, he
attempts to determine the nature and purpose of that file.

http://online.securityfocus.com/infocus/1618

3. Unlocking the Secrets of Crypto: Cryptography, Encryption, and
Cryptology Explained
by Sarah Granger

Encryption, decryption and code breaking came into the public
consciousness in the 1980s with popularity of the movie War Games. It
became newsworthy in the 1990s with the legal battles surrounding PGP and
the political discussion of the Clipper Chip. Now, with information
security becoming more and more of a common concern, the terms encryption,
cryptography and cryptology - commonly grouped together under the term
crypto” - are seeping into our daily language. Still, many people are
unsure of what these terms refer to. The purpose of this article is to
demystify crypto and break it down to simple tools that aid us in
achieving satisfactory privacy and security.

http://online.securityfocus.com/infocus/1617

4. The Original Anti-Piracy Hack
By George Smith

The entertainment industry's plan to use malicious cyber attacks to
enforce its copyrights has precedent in a strange British case from a
decade past

http://online.securityfocus.com/columnists/102

5. SecurityFocus DPP Program

Attention Non-profit Organizations and Universities!! Sign-up now for
preferred pricing on the only global early-warning system for cyber
attacks - SecurityFocus DeepSight Threat Management System.

Click here for more information:
http://www.securityfocus.com/corporate/products/dpsection.shtml

6. InforwarCon 2002

InforwarCon 2002: Homeland Defense and Cyber-Terrorism, Washington, DC
September 4-5, 2002, optional workshops September 3 & 6. Presented by MIS
Training Institute and Interpact, Inc. Proven strategies for protecting
against threats to critical infrastructures and government systems.

Visit us at:
http://www.misti.com/08/iw02nl26inf.html

7. SpiDynamics

ALERT: Top 14 Web Application Attack Techniques and Methods to Combat them
Firewalls, IDS and Access Controls don't stop these attacks because
hackers using the web application layer are NOT seen as intruders. Learn
why 75% of today's successful system hacks involve Web Application
vulnerabilities, not network security flaws. Download this *FREE* white
paper from SPI Dynamics for a complete guide of Web application
vulnerabilities.

http://www.spidynamics.com/mktg/webappsecurity20


II. BUGTRAQ SUMMARY
-------------------
1. Orinoco OEM Residential Gateway SNMP Community String Remote Configuration Vulnerability
BugTraq ID: 5436
Remote: Yes
Date Published: Aug 09 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5436
Summary:

Orinoco is the manufacturer of various wireless network components,
including access points and network cards.

A problem with some systems manufactured by Orinoco may allow remote users
to gain access to sensitive information, and potentially make AP
configuration changes.

The Orinoco series OEM products typically use a unique identification
string to provide access control to the management interface.  This
identification string is unique and static.  This identification string is
used as the authentication string for performing configuration of the
access point.

It is possible to remotely gain access to the identification string used
for configuration of OEM access points manufactured by Orinoco through
SNMP.  By sending a custom-crafted SNMP query to a vulnerable access
point, the access point will return system credentials, including the
identification string.  This identification string can be used as the
administrative community string.

Through the use of this identification string as a SNMP community string,
a remote user may make configuration changes to the access point.  These
changes may include the alteration of domain name servers, and the wired
equivalent privacy key.

2. BlueFace Falcon Web Server Error Message Cross-Site Scripting Vulnerability
BugTraq ID: 5435
Remote: Yes
Date Published: Aug 09 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5435
Summary:

Falcon Web Server is a small web server that runs on several Microsoft
Windows platforms. It is mainly intended for small to medium sized
businesses.

Falcon Webserver does not sufficiently sanitize HTML tags from error
message output.  In particular, attackers may inject HTML into 301 and 404
error pages.  It is possible to cause the server to generate a 301 error
page by making a request for a non-existent file and then not terminating
the request with a slash (/).  404 error messages are displayed by the
server when a request for a non-existent file is made and is terminated
with a slash.  When a 301 error message is generated, the server will add
a slash the request and a 404 error message will be generated in turn,
which may cause the attacker's script code or HTML to be rendered twice.

It is possible to create a malicious link to the server which will
generate an error page with attacker-supplied HTML and script code when
visited.  Arbitrary HTML and script code will be executed by the web
client of the user visiting the server, in the security context of the
server.

3. SGI IRIX ftpd PASV Mode Data Channel Hijacking Vulnerability
BugTraq ID: 5461
Remote: Yes
Date Published: Aug 14 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5461
Summary:

The FTP server included with SGI IRIX is vulnerable to hijacking of data
connections when PASV mode is in use.

When in PASV mode, the server listens on a port when a transfer of data is
to occur. The client then connects and the data is transferred. SGI has
reported that the ftpd selects predictable PASV mode port numbers. As a
result, it is trivial for remote attackers to hijack data connections and
retrieve data before the client can.

It should be noted that this vulnerability has not been eliminated
entirely. Preventing IP addresses other than that of the client from
connecting to data ports would break RFC compliance, and would not prevent
attacks from the client address (perhaps other internal hosts if NAT is in
use). Data ports are now randomly selected by the server, making them more
difficult to guess successfully before the client connects. This should be
kept in mind when applying the fix.

4. ISDN4Linux IPPPD Device String SysLog Format String Vulnerability
BugTraq ID: 5437
Remote: No
Date Published: Aug 10 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5437
Summary:

isdn4linux is a freely available, open source package of isdn
compatibility tools.  It is available for Linux operating systems.

A problem with isdn4linux may make local code execution and privilege
elevation possible.

isdn4linux contains a format string vulnerability in the ipppd utility.
In some installations, this utility is installed with setuid root
privileges.  Exploitation of this vulnerability could lead to a local
attacker executing code with administrative privileges.

The problem is in handling of device strings.  By executing ipppd with an
excessively long device string (256 or greater bytes), and embedding
format string specifiers in the device string, it is possible to execute
arbitrary attacker-supplied instructions.

SecurityFocus staff have determined that this vulnerability has apparently
been fixed in version 3.2p1 of the software.  This has not been confirmed
by the vendor.

5. Midicart ASP Remote Customer Information Retrieval Vulnerability
BugTraq ID: 5438
Remote: Yes
Date Published: Aug 10 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5438
Summary:

Midicart ASP is a commercially available e-commerce solution distributed
by Coxco Support.  It is available for the Microsoft Windows operating
system.

A problem with the default installation of Midicart ASP may make it
possible for remote users to gain access to sensitive information.

Midicart ASP uses Microsoft Access database files to store information
about customers.  These database files are stored in the web path, and
require restrictive permissions to prevent retrieval by users via the web.

The default installation of Midicart ASP does not place sufficient access
control on the midicart.mdb file.  Due to this lack of access control, it
is possible for a remote user to gain access to this file.  This file may
yield sensitive customer information, such as customer names, addresses,
and credit card information.

6. Citrix Metaframe Java ICA Environment Denial Of Service Vulnerability
BugTraq ID: 5439
Remote: Yes
Date Published: Aug 11 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5439
Summary:

Citrix Metaframe is a commercially available remote desktop application.
This issue affects Metaframe on the Microsoft Windows platform.

A problem with Citrix Metaframe could make it possible for a remote user
to crash the system.

It has been discovered that Metaframe can be made to become unstable.  By
connecting to the Metaframe server using custom-crafted Java ICA files, a
remote user may be able to create instability in the Metaframe server.
The server typically reacts to this vulnerability by disconnecting all
users, and either crashing requiring a manual reboot, or crashing and
rebooting.

The problem is in the handling of variables specified in the Java ICA
files.  Though the exact nature of this vulnerability is unknown, an
attacker needs only edit a Java ICA file.  Upon loading the file in a
browser such as Internet Explorer, and setting the browser to full-screen
mode and refreshing, the vulnerable server hosting Citrix crashes.

7. Cisco VPN Client IKE Packet Excessive Payloads Vulnerability
BugTraq ID: 5443
Remote: Yes
Date Published: Aug 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5443
Summary:

The Cisco VPN Client is Virtual Private Network software.  It is available
for a number of platforms including Microsoft Windows and Unix and Linux
variants.

The Cisco VPN Client is prone to a remotely exploitable buffer overflow
condition.  It is possible to trigger this condition by sending malformed
IKE packets to the client.  The overflow is known to occur when the client
attempts to process an IKE packet with more than 57 valid payloads.  When
the malformed packet is handled by the client, memory can be corrupted
with attacker-supplied values, which may enable the attacker to execute
arbitrary instructions.

An attacker would most likely exploit this vulnerability with a malicious
server.  It may also be possible to exploit this issue by injecting a
malicious packet into a legitimate VPN connection. The ability to inject
data will depend on network proximity of the attacker, however VPN
connections are commonly made when traffic must pass through untrusted
network space.

It may be possible to exploit this condition to execute arbitrary code
with the privileges of the client.  It is possible that exploitation of
this vulnerability may affect availability of the client, resulting in a
denial of service condition.

This issue is reported to be exploitable when the client software is
operating in Aggressive Mode during a phase 1 IKE exchange.

This vulnerability affects versions of the client on all platforms.

8. Cisco VPN Client IKE Security Parameter Index Payload Buffer Overflow Vulnerability
BugTraq ID: 5441
Remote: Yes
Date Published: Aug 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5441
Summary:

The Cisco VPN Client is Virtual Private Network software.  It is available
for a number of platforms including Microsoft Windows and Unix and Linux
variants.

The Cisco VPN Client is prone to a remotely exploitable buffer overflow
condition.  It is possible to trigger this condition by sending malformed
IKE packets to the client.  The overflow occurs when the Security
Parameter Index payload of the IKE packet is longer than 16 bytes in
length.  When the malformed packet is handled by the client, memory can be
corrupted with attacker-supplied values, which may enable the attacker to
execute arbitrary instructions.

An attacker would most likely exploit this vulnerability with a malicious
server.  It may also be possible to exploit this issue by injecting a
malicious packet into a legitimate VPN connection.  The ability to inject
data will depend on network proximity of the attacker, however VPN
connections are commonly made when traffic must pass through untrusted
network space.

It may be possible to exploit this condition to execute arbitrary code
with the privileges of the client.  It is possible that exploitation of
this vulnerability may affect availability of the client, resulting in a
denial of service condition.

This issue is reported to be exploitable when the client software is
operating in Aggressive Mode during a phase 1 IKE exchange.

This vulnerability affects versions of the client on all platforms.

9. Cisco VPN Client Zero Length IKE Packet Denial Of Service Vulnerability
BugTraq ID: 5440
Remote: Yes
Date Published: Aug 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5440
Summary:

The Cisco VPN Client is Virtual Private Network software. It is available
for a number of platforms including Microsoft Windows and Unix and Linux
variants.

Some versions of the VPN Client are vulnerable to a denial of service
attack.

When vulnerable clients receive a specific IKE packet with a zero length
payload, the VPN client will consume all available processor time. This
may result in a denial of service condition, and require that the VPN
client process be manually killed and restarted in order to regain normal
functionality.

It may be possible to exploit this vulnerability with a malicious server.
It may also be possible to exploit this issue by injecting a malicious
packet into a legitimate VPN connection. The ability to inject data will
depend on network proximity of the attacker, however VPN connections are
commonly made when traffic must pass through untrusted network space.

10. OpenBSD select() Buffer Overflow Vulnerability
BugTraq ID: 5442
Remote: No
Date Published: Aug 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5442
Summary:

OpenBSD is a freely available, open source operating system designed with
security in mind. It is maintained and distributed by the OpenBSD project.

A buffer overflow vulnerability has been reported for the select(2)
function. The vulnerability occurs when using the select(2) call.
select(2) provides programmers with the facility to examine I/O
descriptors.

The size parameter for the select() function is a signed integer.
Reportedly, select() evaluates the upper boundary checks in a signed
context. As a result, an attacker is able to cause the kernel to overwrite
arbitrary locations in memory when supplying select() with certain
negative values for the size parameter.

An attacker can exploit this vulnerability by causing the kernel to
overwrite memory locations with arbitrary attacker-supplied values. This
may result in the attacker causing the kernel to execute malicious,
attacker-supplied code.

11. Multiple Vendor CDE ToolTalk Database Server Heap Corruption Vulnerability
BugTraq ID: 5444
Remote: Yes
Date Published: Aug 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5444
Summary:

The ToolTalk database server (rpc.ttdbserverd) is an ONC RPC service which
manages objects needed for the operation of the ToolTalk service.
ToolTalk-enabled processes communicate with each other using RPC calls to
this program, which runs on each ToolTalk-enabled host. This program is a
standard component of the ToolTalk system, which ships as a standard
component of many commercial Unix operating systems. The ToolTalk database
server typically runs as root.

A buffer overflow vulnerability has been reported in the ToolTalk RPC
database server. The vulnerability exists when invoking the
_TT_CREATE_FILE procedure.

An attacker may exploit this vulnerability by invoking the _TT_CREATE_FILE
procedure with specially crafted values. This results in the the ToolTalk
RPC database server corrupting certain areas in heap memory. This allows
the attacker to control the ToolTalk RPC server process and cause it to
execute malicious, attacker-supplied code with the privileges of the
compromised server process.

12. Macromedia Flash Malformed SWF Denial Of Service Vulnerability
BugTraq ID: 5445
Remote: Yes
Date Published: Aug 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5445
Summary:

Macromedia Flash is a modular package designed to enhance web browsing and
enables users to view various multimedia web content.

Macromedia Flash Player is prone to a denial of service condition when
attempting to handle Flash Shockwave (.SWF) movie files with a malformed
body.  It has been reported that to reproduce this condition, the header
data in the .SWF file must be intact.

This vulnerability was initially reproduced by ROT13 encoding randomly
selected data in the body of the file.  However, the same effect could be
achieved by using a hex editor to replace body data with random
characters.

The Macromedia Flash plug-in is included in a number of web browsers.
Successful exploitation will cause the browser to crash.  An attacker can
recreate this condition via a malicious webpage, HTML e-mail, newsgroups
or a number of other means.

It is not known whether the memory corruption caused when the malformed
file is loaded by the player can be exploited to execute arbitrary code.

13. PGP / GnuPG Chosen Ciphertext Message Disclosure Vulnerability
BugTraq ID: 5446
Remote: Yes
Date Published: Aug 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5446
Summary:

PGP and GnuPG are two popular implementations of the OpenPGP encryption
specification. Both are available for a range of platforms, including
Microsoft Windows and Linux based systems.

A weakness in the OpenPGP specification, as implemented by both products,
may allow an attacker to learn the plaintext contents of encrypted
communications. While some degree of user interaction is required, the
attack is very plausible against non-technical end users.

In order to exploit this issue, an attacker E must first intercept an
encrypted message of interest between two users, B and A. The attacker may
modify this message and inject additional content into the encrypted
content.  This modified message must then be transmitted to A, the
recipient of the original message.

The attacker must then entice A into decrypting this message, and
revealing the results of the decrypted message. This may occur if A
responds to the malicious message with text that includes the decrypted
contents. As the results of decryption will appear garbled and
meaningless, it is conceivable that A would reply and include the original
"quoted" message in an attempt to determine what has gone wrong.

Given the decrypted version of the malicious message, and the original
encrypted message, the attacker may recover a portion of the original
plaintext. In general the attacker will be able to recover at best half of
the plaintext content per attack, as it is difficult to modify the
encrypted length of the message, and an equal amount of injected content
is required in order to implement the attack. Under many applications this
will be sufficient, however multiple attacks may result in full disclosure
of the plaintext message.

It is not believed to be possible to exploit this weakness against message
content which is compressed during the OpenPGP encryption process.
Attacker supplied content will cause an error in the decompression process
with a high degree of probability, which may alert the end user or prevent
the display of the decrypted content. Compression is reported to be
enabled in both products by default. Files which are already compressed,
however, may not be compressed again, allowing exploitation.

It is important to note that exploitation of this issue will result in the
plaintext contents of a specific, intercepted message being disclosed to a
third party. The integrity of the private keys involved in the original
communication is not compromised, and widespread exploitation of this
weakness is extremely likely to be noticed by the end user.

14. W3C CERN httpd Proxy Cross-Site Scripting Vulnerability
BugTraq ID: 5447
Remote: Yes
Date Published: Aug 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5447
Summary:

CERN httpd is a freely available HTTP server and HTTP proxy server
available from the W3C.

The httpd Proxy does not protect against cross-site scripting attacks.

When it cannot retrieve a web document, Proxomitron outputs an error
webpage.  The URL that it attempted to use is displayed without being
sanitized.  It is possible for attackers to construct urls that will cause
arbitrary HTML or script code to be embedded in the error page.  When the
client interprets the error page, the attacker-supplied code may execute
within the context of the proxy server.

This type of vulnerability may be used to steal cookies or perform other
web-based attacks.

15. SGI Irix Bulk Data Services Arbitrary File Disclosure Vulnerability
BugTraq ID: 5448
Remote: Yes
Date Published: Aug 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5448
Summary:

SGI Bulk Data Service (BDS) is a NFS extension available for the Irix
operating system. It is designed to facilitate the transfer of large files
over a high speed network to enhance the performance of applications using
remote file systems.

A vulnerability has been reported in some versions of the Bulk Data
Service. It may be possible for a client application to gain read access
to arbitrary files on the vulnerable system. Exploitation of this
vulnerability may allow a remote attacker to gain access to sensitive
information, such as system configuration files. This data may aid in
further attacks against the vulnerable system.

16. PGPFreeware Malformed IKE Response Packet Buffer Overflow Vulnerability
BugTraq ID: 5449
Remote: Yes
Date Published: Aug 12 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5449
Summary:

The implementation of Internet Key Exchange (IKE) used by the PGPFreeware
VPN client is reported to be prone to a buffer overflow when handling
malformed IKE response packets.  An attacker may exploit this condition to
cause process memory to be corrupted with attacker-supplied data on the
client system, which may result in execution of arbitrary code.
Exploitation may also result in a denial of service.

It is possible to exploit this issue via a malicious server.  However,
this may also potentially be exploited if the attacker can inject
malformed packets into an existing client-server communication.

Other vendor products are reported to be affected by similar issues.
Bugtraq ID(s) 5440, 5441, 5443 describe similar issues with regards to the
handling of malformed IKE response packets.  There are currently not
enough details available to determine if PGPFreeware is affected by any of
these specific issues.

This issue was reported in PGPFreeware 7.03 running on Windows NT 4.0 SP6.
Other versions and platforms may also be affected.

17. Microsoft Internet Explorer File Attachment Script Execution Vulnerability
BugTraq ID: 5450
Remote: Yes
Date Published: Aug 13 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5450
Summary:

An error has been reported in Microsoft Internet Explorer 6, which may
allow malicious file attachments to execute arbitrary code in the context
of the local system.

Due to a mismatched MIME type on the server, where file of type text/html
are read as text/htm, it is possible for for an attacker to cause Internet
Explorer to force a download of a malicious HTM file. HTM files are
associated with Internet Explorer. The downloaded HTM file may include
malicious attacker-supplied script instructions that will be executed on
the victim user's system.

When script code executes, it is able to determine the location of the
document, and in turn the location of the Temporary Internet File (TIF)
directory the document is stored in.

Information about the location of the TIF directory can be used to
reference additional malicious attachments in the body of the downloaded
HTM file, including executable content, within the context of the local
file system. This can in turn lead to the execution of arbitrary code
within the Local System security zone.

This behavior has been reported in Internet Explorer 6. Other versions of
Internet Explorer may share this vulnerability, this has not however been
confirmed.

18. L2TPD Weak Random Number Generator Seeding Vulnerability
BugTraq ID: 5451
Remote: Yes
Date Published: Aug 13 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5451
Summary:

l2tpd is a Layer 2 Tunneling Protocol daemon, implementing the protocol
defined in RFC 2661.

Some versions of l2tpd fail to seed the random number generator before
calling the function rand(). This may result in predictable random numbers
being generated. Random numbers are used for a number of purposes within
l2tpd, including tunnel and session ids, and within the challenge /
response mechanism.

An attacker may be able to exploit this vulnerability to predict the
numbers which will be generated by l2tpd. This may allow a number of
attacks. The ability to guess session and tunnel ids may allow an attacker
to inject data into a valid conversation. The ability to predict the
behavior of the challenge / response mechanism may allow man in the middle
attacks, or some replay attacks. In both cases, the integrity of
connections made with l2tpd may be compromised.

The consequences of exploitation will be highly dependant on the
environment l2tpd is deployed in.

19. Red Hat Interchange Arbitrary File Read Vulnerability
BugTraq ID: 5453
Remote: Yes
Date Published: Aug 13 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5453
Summary:

Interchange is a Web application development environment with a focus on
ecommerce and dynamic content management. It is available for Linux and
Unix variant operating systems.

A vulnerability has been reported for Interchange 4.8.5 and earlier.
Interchange may disclose contents of files to attackers.

The vulnerability occurs due to the placement of the 'doc' folder.
Reportedly, the folder will be installed as follows:
<INTERCHANGE_ROOT>/doc. This folder, by default, contains Interchange man
pages. This vulnerability is only exploitable when the Interchange service
runs in INET (Internet service) mode.

An attacker may exploit this vulnerability to the contents of restricted
files accessible to the Interchange process. The potentially sensitive
information obtained may be used to mount further attacks against a
vulnerable system.

It has been reported that this issue may be exploited through a '../'
directory traversal sequence in a HTTP request to the vulnerable server.
URLs may escape the document root in this manner, and request arbitrary
files on the system, subject to the permissions of the server process.

20. HP-UX VVOS Unspecified Local Passwd Vulnerability
BugTraq ID: 5454
Remote: No
Date Published: Aug 13 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5454
Summary:

Virtual Vault Operating System (VVOS) is a commercially-available
operating system distributed by HP.  It is designed to offer enhanced
security features.

An unspecified vulnerability has been reported in VVOS.  A vulnerability
in the passwd program has been discovered, and a fix is available by HP.

Information concerning this vulnerability has not been made available.
However, it's likely that this problem allows local privilege elevation on
vulnerable systems, as passwd is a setuid root binary typically accessible
only to users with shell-level access to a system.  This could result in a
local attacker gaining elevated access, and potentially administrative
access.

21. Oracle 9iAS OJSP Demo Scripts Cross-Site Scripting Vulnerability
BugTraq ID: 5452
Remote: Yes
Date Published: Aug 13 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5452
Summary:

Oracle 9iAS is bundled with a number of sample JSP scripts.  These scripts
are included as examples of how to use JSP with Oracle 9iAS.

Some of the sample scripts are prone to cross-site scripting attacks.
This is due to insufficient sanitization of HTML tags from data submitted
via text fields in forms used by the vulnerable scripts.  This data may
also be submitted via parameters in a CGI query string. The data submitted
is output in webpages. 'hellouser.jsp', 'welcomeuser.jsp' and
'usebean.jsp' are all affected by this issue.

This may potentially be exploited to cause arbitrary HTML and script code
to be executed in the browser of a legitimate user of Oracle 9iAS.  An
attacker would typically exploit this issue by including HTML/script code
in a malicious link to one of the vulnerable scripts and then enticing a
legitimate user to visit the link.  HTML and script code will be executed
in the context of the server hosting the vulnerable scripts.
Exploitation of this issue may cause the user's JSESSIONID to be disclosed
to an attacker.

22. CafeLog b2 WebLog Tool Cross Site Scripting Vulnerability
BugTraq ID: 5455
Remote: Yes
Date Published: Aug 13 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5455
Summary:

CafeLog b2 WebLog Tool allows users to generate news pages and weblogs
dynamically.  It uses PHP and a MySQL database to generate dynamic pages.

The b2 WebLog Tool will echo data back to the browser.  Some variables are
assumed by the scripts to have been set by internal data, when they can be
set by remote users.  Since these variables are not sufficiently sanitized
of HTML tags, this makes b2 WebLog Tool prone to cross-site scripting
attacks.

When the client interprets the returned page, the attacker-supplied code
may execute within the context of the site hosting the vulnerable
software.

This type of vulnerability may be used to steal cookies or perform other
web-based attacks.

23. CafeLog b2 WebLog Tool SQL Injection Vulnerability
BugTraq ID: 5456
Remote: Yes
Date Published: Aug 13 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5456
Summary:

CafeLog b2 WebLog Tool allows users to generate news pages and weblogs
dynamically.  It uses PHP and a MySQL database to generate dynamic pages.

The b2 WebLog Tool does not properly sanitize user input that is sent to
the tableposts variable.  The tableposts variable is passed to SQL
queries.  SQL code may be inserted into the requests and executed by the
database server.  These requests could include adding, deleting, and
modifying data.  Additionally, this may allow a remote attacker to exploit
vulnerabilities that exist in the underlying database.

24. Oracle Listener Malformed Debugging Command Denial Of Service Vulnerability
BugTraq ID: 5457
Remote: Yes
Date Published: Aug 13 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5457
Summary:

The Oracle Listener includes support for a number of debugging commands.
These may be used by a remote administrator to retrieve information about
the database.

A denial of service vulnerability exists in some versions of the Listener.
A remote attacker may send a malformed debugging request to the Listener.
The vulnerable process will then crash or otherwise become unavailable
when attempting to process this command. A restart may be required in
order to regain normal functionality.

It has been reported that the debugging features in question are enabled
by default, and may not be disabled through configuration.

25. Xinetd Open File Descriptor Denial Of Service Vulnerability
BugTraq ID: 5458
Remote: No
Date Published: Aug 13 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5458
Summary:

Xinetd is intended as a secure replacement for inetd. It is designed for
use with Linux and Unix variant operating environments.

Reportedly, xinetd is vulnerable to a denial of service condition. The
vulnerability is the result of file descriptors for the signal pipe being
inherited by child processes launched by xinetd. This may result in a
malicious attacker access to pipes associated with xinetd thus having the
ability to communicate with xinetd.

Local attackers may misuse the open file descriptors by sending extraneous
or malformed data to xinetd which may cause the service to crash. This
results xinetd failing to respond to legitimate requests for service.

The signal pipe was introduced in version 2.3.4 of Xinetd.  Earlier
versions are not prone to this issue.

26. HP-UX VVOS TGAD Unspecified Stack Corruption Vulnerability
BugTraq ID: 5459
Remote: Unknown
Date Published: Aug 14 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5459
Summary:

Virtual Vault Operating System (VVOS) is a commercially-available
operating system distributed by HP. It is designed to offer enhanced
security features.

The TGA (Trusted Gateway Agent) Daemon in VVOS is vulnerable to an
unspecified stack corruption vulnerability.  Successful exploitation may
lead to unauthorized access to system files.

Information concerning this vulnerability has not been made available.
However, it's likely that this problem allows local privilege elevation on
vulnerable systems.  This could result in a local attacker gaining
elevated access, and potentially administrative access.

27. Oracle Net Listener Format String Vulnerability
BugTraq ID: 5460
Remote: Yes
Date Published: Aug 14 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5460
Summary:

The Oracle Net Listener is a tool used by Oracle DBAs to deal with client
requests for database services. Oracle also provides a mechanism to allow
DBAs to remotely administer the Listener tool.

A vulnerability has been reported for the Listener Control utility
(LSNRCTL). Reportedly, the Listener Control utility is vulnerable to
format string attacks. This vulnerability is due to the default
configuration of the Oracle Listener. The Listener, by default, allows
users to modify configuration files without authenticating. It is possible
for an attacker to modify certain entries in the file, listener.ora, to
insert a format string exploit.

Modifying the configuration file may cause Listener to crash upon next
restart. It is also possible for an attacker to obtain control over the
Listener Control utility's path of execution when an Oracle DBA attempts
to use the Listener Control utility. The attacker cannot use this attack
to obtain control of the database server but access to the unsuspecting
DBA's system may be obtained.


III. SECURITYFOCUS NEWS AND COMMENTARY
--------------------------------------
1. Audit Shows More PCs At the IRS Are Missing
By Albert B. Crenshaw, Washington Post

The Internal Revenue Service has lost to thieves or has misplaced another
batch of computers, adding to the thousands already missing from that and
other government agencies.

http://online.securityfocus.com/news/583

2. MS soft-pedals SSL hole
By Thomas C. Greene, The Register

A Microsoft security PR bulletin dealing with the recent SSL (Secure
Sockets Layer) certificate hole reported by Mike Benham goes out of its
way to assure Windows users that there's little to be concerned about. The
recent negative talk about it hasn't been properly 'balanced' (i.e.,
approved by the Marketing Department), apparently.

http://online.securityfocus.com/news/582

3. Sleuths Invade Military PCs With Ease
By Robert O'Harrow Jr., Washington Post

Security consultants entered scores of confidential military and
government computers without approval this summer, exposing
vulnerabilities that specialists say open the networks to electronic
attacks and spying.

http://online.securityfocus.com/news/581

4. U.S. Aiding Asia-Pacific Anti-Cybercrime Efforts
By Brian Krebs, Washington Post

U.S. law enforcement officials will meet with representatives from a host
of Asia-Pacific countries this weekend as part of an international
training program to help developing nations combat computer crime and
cyberterrorism.

http://online.securityfocus.com/news/580


IV. SECURITYFOCUS TOP 6 TOOLS
----------------------------
1. Advisor v1.2.6-3
by miron
Relevant URL:
http://www.niftybox.com/download.php
Platforms: Linux
Summary:

Advisor monitors a security advisory database and sends alerts whenever an
advisory affects an installed software package. For example, if there is a
security advisory regarding Apache, and you have Apache installed, a
notification will be sent out. Currently, RedHat and Mandrake are
supported.

2. Netfilter2html v0.6b
by Rodrigo P. Telles [email protected]
Relevant URL:
http://webtools.linuxsecurity.com.br/
Platforms: UNIX
Summary:

Netfilter2html is a script developed in AWK for filtering
netfilter/iptables logs to generate HTML reports.

3. spasm anti-spam milter v0.22
by Aradia
Relevant URL:
http://www.theasylum.org/spasm/
Platforms: Linux
Summary:

The spasm anti-spam milter is a spam filter for sendmail 8.12+ (with
libmilter support). Current features include logging of rejected spam,
fully virtualised settings for domains, individual whitelists, and over
two dozen blacklist filters which can be set individually on a per-domain
or per-email address basis (including local blacklist, rDNS resolution,
HELO/EHLO verification, envelope sender address verification, numerous
DNS-based lists, whitelist-only mode, tagging-only mode, and
auto-blacklisting features).

4. radiusContext v1.81
by Evelyn Mitchell
Relevant URL:
http://www.tummy.com/radiusContext/
Platforms: Os Independent
Summary:

radiusContext is a RADIUS (Remote Authentication Dial In User Services)
accounting log analysis package. Livingston, MERIT and Ascend RADIUS log
formats are supported. It is written in python and is able to parse log
files up to several Gigabytes in size.

5. fauxident.py v1.0
by Eleventh Hour
Relevant URL:
http://www.alcyone.com/pyos/fauxident/
Platforms: POSIX, UNIX
Summary:

fauxident is a small Python script that will act as an extremely naive
ident server, answering all ident requests with a consistent response
(either ERROR or USERID). This can be advantageous on systems where
running a true identd is unavailable, where it would be would be a
security risk, or when masquerading firewalls are in use, where multiple
machines are involved behind the firewall and running a proper ident
system is not an option.

6. HTun v0.9.3b
by Moshe Jacobson
Relevant URL:
http://htun.runslinux.net/
Platforms: Linux
Summary:

HTun is a VPN (Virtual Private Network) interface that allows you to
create a fully bidirectional IP-layer VPN over an HTTP proxy or just over
port 80, allowing you to bypass restrictive firewalls and use any IP-based
service you desire.


V. SECURITY JOBS SUMMARY
------------------------
1. Job openings at eEye Digital Security (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/287655

2. DITSCAP/ INFOSEC (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/287653

3. Information Assurance Engineer (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/287652

4. Resume (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/287651

5. Cyber Penetration Testing Specialist (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/287654

6. Managed Security Services Engineer (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/287650

7. Security Services Manager - Madison, WI (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/287649

8. Sales Engineer (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/287403

9. UK based Blue Chip seeks Security Architect (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/287379

10. Checkpoint Resource needed in Boston (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/287656

11. Sr Security SW/HW Executive (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/287365

12. Resume of Terrence Martin (BS, CISSP) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/287330

13. The resume for Rafal Wojtczuk (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/287175

14. Degree Educated Sales Executive UK ; Security Software Legal & Financial Sector (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/287174

15. South Florida: Information Security Engineer-Unix (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/287172

16. Opportunity for a Sr. InfoSec Engineer with C&A Experience at our    NJ location (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/287078

17. Opportunity for a Crypto-Analyst to help support our Computer    Forensics Team (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/287060

18. bay area security professional, $6.75/hr... Please read below! (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/287077

19. pki, vpn, infosec engineer available in southeast (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/286987

20. Looking for positions in Oakland, Sacramento, or the East Bay area of California (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/286981

21. Available Sr. Sales Engineer - Security (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/286776

22. Looking for a position in UK (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/286781


VI. INCIDENTS LIST SUMMARY
-------------------------
1. Standardized Reporting (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/287595

2. Subseven Scans; Standardized Reporting (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/287530

3. Subseven Scans (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/287504

4. Increased IIS scans mainly on 66.0.0.0/8 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/287384

5. Odd scans and stuff bouncing off firewalls (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/287322

6. RPC scans (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/287248

7. FW: Subseven Scans (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/287137

8. Re[2]: Subseven Scans (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/287075

9. strange apache log entry (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/287029

10. Odd activity. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/286985

11. Strange pings from akamai? {1-112POX} (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/286988

12. large scale distributed scan of port tcp 445 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/286974

13. [unisog] Re: large scale distributed scan of port tcp 445 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/286684


VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. Extending IE SSL exploit to exploit WindowsUpdate (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/287606

2. SILLY BEHAVIOR : Internet Explorer 5.5 - 6.0 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/287605

3. ZoneAlarm memory leak ? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/287568

4. L-Forum Vulnerability - SQL Injection (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/287396

5. Multiple Vulnerabilities in CafeLog Weblog Package (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/287227

6. strange man behavior (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/287125

7. ie ssl and software (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/287131

8. ToorCon Call for Papers 5 Day Notice (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/287128

9. Apache 2.0 vulnerability affects non-Unix platforms (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/286794


VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Win2k network changes (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/287571

2. SP3 Problems? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/287558

3. Exchange SSL Connection warning message (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/287584

4. Patch for ms02-40 "HELLO BUG" doesn't working (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/287352

5. Problems using Windows Update on Windows XP Pro (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/287348

6. .Net Server and 'taskkill' (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/287309

7. Win2k Terminal Services (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/287211

8. Client certificates in M$ outlook (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/287215

9. Password change utility (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/287160

10. SCE Templates from a Network Drive (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/287155

11. SecurityFocus Microsoft Newsletter #99 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/287081

12. Another SUS / Autoupdate question (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/287054

13. AW: SP3 Problems? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/286995

14. SP3 Article Updated on Microsoft Technet (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/286967


IX. SUN FOCUS LIST SUMMARY
----------------------------
1. Hardening NIS+ (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/287566

2. There's something about hardening NFS? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/287563

3. Solaris and lack of loopback routes (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/287224

4. Solaris 8 username contingency (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/287222

5. Fwd: Hardening NIS+ (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/286821


X. LINUX FOCUS LIST SUMMARY
---------------------------
1. NO NEW POSTS FOR THIS WEEK


XI. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored By: Qualys

Bulletproof Your Network: FREE Guide

Existing security products -- firewalls, anti-virus and IDS -- are simply
no longer enough to ensure your networks are safe against sophisticated
attacks and worms such as Code Red and Nimda. FREE Guide shows you how to
ensure TOTAL security for your network. Get it now.

Visit us at:
https://www.qualys.com/forms/guide_220.php
-------------------------------------------------------------------------------