SecurityFocus Newsletter #159
John Boletta <[email protected]> Mon, 26 Aug 2002 11:42:03 -0600 (MDT)
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #159
-----------------------------
This Issue is Sponsored By: AirDefense, Inc.
***HACK-PROOF YOUR WIRELESS LAN - FREE WLAN SECURITY SEMINAR***
AirDefense brings a WLAN security seminar to your city. Learn the latest
techniques & tools to fortify your WLAN. Topics include:
* WLAN Security Challenges & Vulnerabilities
* Live Hack & Attack Demonstrations
* Practical Actions to Secure Your WLAN.
REGISTER NOW! http://www.airdefense.net/securityfocus/secfseminar.shtm
-------------------------------------------------------------------------------
I. FRONT AND CENTER
1. Windows ICF: Can't Live With it, Can't Live Without it
2. Introduction to Autorooters: Crackers Working Smarter, not Harder
3. Know Your Enemy: Building Virtual Honeynets
4. An Open Letter to the CIO
5. Send Congress Back to School
6. The 21 Best Ways to Lose Your Information
7. SecurityFocus DPP Program
8. InforwarCon 2002
II. BUGTRAQ SUMMARY
1. AOL Instant Messenger Link Special Character Remote Heap...
2. FreeBSD System Call Signed Integer Buffer Overflow Vulnerability
3. Tomahawk Technologies SteelArrow Cookie HTTP Header Buffer...
4. Tomahawk Technologies SteelArrow ARO File Request Buffer...
5. Tomahawk Technologies SteelArrow Chunked Transfer Encoding...
6. PostgreSQL cash_words Function Buffer Overflow Vulnerability
7. nCipher PKCS#11 Symmetric Message Signature Verification...
8. Lynx Command Line URL CRLF Injection Vulnerability
9. Ilia Alshanetsky FUDForum SQL Injection Vulnerability
10. W3C Jigsaw Proxy Server Cross-Site Scripting Vulnerability
11. Kerio MailServer Multiple SYN Packet Denial Of Service...
12. Kerio MailServer Web Mail Multiple Cross Site Scripting...
13. Microsoft File Transfer Manager ActiveX Control Buffer...
14. Mantis Account Update SQL Injection Vulnerability
15. Microsoft File Transfer Manager Arbitrary File Upload/Download...
16. Mantis Configuration Remote File Include Command Execution...
17. Ilia Alshanetsky FUDForum File Modification Vulnerability
18. Ilia Alshanetsky FUDForum File Disclosure Vulnerability
19. MySQL Null Root Password Weak Default Configuration Vulnerability
20. Mantis JPGraph Remote File Include Command Execution...
21. MySQL Bind Address Not Enabled Weak Default Configuration...
22. MySQL Logging Not Enabled Weak Default Configuration...
23. Mantis Print Reports Limit Reporters Option Bypass Vulnerability
24. Mantis Unauthorized Project Bug List Viewing Vulnerabilit...
25. Mozilla Bonsai Multiple Cross Site Scripting Vulnerabilities
26. Mozilla Bonsai Path Disclosure Vulnerability
27. WebEasyMail SMTP Service Format String Vulnerability
28. WebEasyMail POP3 Server Valid User Name Information Disclosure...
29. Novell NetWare HTTP Post Arbitrary Perl Code Execution...
30. Novell NetWare Remote Perl Version Disclosure Vulnerability
31. Novell NetWare Encoded Slash Directory Traversal Vulnerability
32. Novell NetBasic Scripting Server Directory Traversal...
33. Tiny Personal Firewall Log File Viewing Denial Of Service...
34. SCPOnly SSH Environment Shell Escaping Vulnerability
35. Novell NetBasic Interpreter Module Name Buffer Overflow...
36. PostgreSQL Repeat Function Buffer Overflow Vulnerability
37. PostgreSQL String Pad Function Buffer Overflow Vulnerability
38. Multiple VNC Products For Windows Win32 Messaging API...
39. Sun Cobalt RaQ Predictable Temporary Filename Symbolic Link...
40. Pingtel Xpressa Phone Weak Session Parameters Vulnerability
41. Pingtel Xpressa Phone Home Information Leakage Vulnerability
42. LG LR Series WAN Router Telnet Daemon Buffer Overflow...
43. LG LR Series WAN Router Data Stream Denial Of Service...
44. Stephen Ball File Manager Source.PHP Directory Traversal...
46. Novell NetWare 6.0 SP2 RConsoleJ Authentication Bypass...
48. Sun PatchPro Insecure Temporary File Vulnerability
49. Apache Tomcat 4.1 JSP Request Cross Site Scripting Vulnerability
50. Microsoft Windows Media Player File Attachment Script...
51. Multiple Vendor IPv4-IPv6 Transition Address Spoofing...
52. Abyss Web Server Encoded Backslash Directory Traversal...
53. Abyss Web Server Administrative Console Unauthorized Access...
54. Abyss Web Server Malicious HTTP Request Information Disclosure...
55. LG LR Series Router IP Packet Flags Denial of Service...
56. D-Link Remote Administration Arbitrary DHCP Address Release...
57. Caldera UnixWare/Open Unix NDCFG Buffer Overflow Vulnerability
58. Achieva Remote File Include Command Execution Vulnerability
59. Microsoft TSAC ActiveX Control Buffer Overflow Vulnerability
60. Microsoft Network Share Provider SMB Request Buffer Overflow...
61. D-Link Remote Administration Information Leakage Vulnerability
62. Multiple Microsoft Internet Explorer Vulnerabilities
63. Light Channel Name Arbitrary Command Execution Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
1. Sprint Security Faulted in Vegas Hacks
2. Microsoft in summer patch frenzy
3. Worm spreads through KaZaA network, again
4. UK's DMCA: there ain't no sanity clause
IV.SECURITYFOCUS TOP 6 TOOLS
1. ClarkConnect Internet Gateway v1.1
2. lcrzoex v4.11
3. Lcrzo v4.12
4. rssh v0.9.1
5. ProSum 0.2b (Development) v0.2b
6. squidview v0.30
V. SECURITYJOBS LIST SUMMARY
1. Anti-Virus Software Sales Manager (Thread)
2. Enterprise Level Network Security Gurus (Thread)
3. Security Consultants Needed in Washington DC (Thread)
4. Resume (Thread)
5. (job offered) Principal Consultant/Security Evangelist in...
6. Information Systems Security Officer for AT&T (Thread)
7. ISSE Opening Available in sunny Orlando Florida (Thread)
8. INFOSEC positions in Reston, VA. (Thread)
9. Sr. Security Consultants (Thread)
10. CTO - Security - Silicon Valley - CA (Thread)
11. Looking for a Job. (Thread)
12. Senior Security Consultant Opening at Sygate Technologies...
13. INFOSEC Jobs Available Now (Thread)
14. Re[2]: Sr. Security Consultants (Thread)
15. Resume - Information Systems Security Professional (Thread)
16. Southern California TRW InfoSec positions (Thread)
VI. INCIDENTS LIST SUMMARY
1. looking for what? portscan 15000/tcp (Thread)
2. BAD TRAFFIC 0 ttl (Thread)
3. Unicode worm? (Thread)
4. Increased IIS scans mainly on 66.0.0.0/8 - Update (Thread)
5. AOL "proxy" behavior? (Thread)
6. (moderator can kill thread) AOL "proxy" behavior? (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
1. More on Shatter (Thread)
2. Apache-Nosejob (Thread)
3. Lotus Sametime issues? (Thread)
4. [Full-Disclosure] Lotus Sametime issues? (Thread)
5. exploiting printers, home routers & smb routers (Thread)
6. exploiting printers, home routers & smb routers (Thread)
7. FreeBSD System Call Signed Integer Buffer Overflow Vulnerabilit...
8. Follow up:Apache Nosejob (Thread)
9. Exploiting cross-domain scripting vulnerabilities? (Thread)
10. Apache Tomcat 4.1 Cross-Site Scripting Vulnerability (Thread)
11. [[email protected]: [[email protected]: Defcon Phenoelit...
12. Normal Web Surfers In Extreme Danger (Thread)
13. killer k00kie [was SILLY BEHAVIOR : Internet Explorer 5.5...
14. Administrivia: Greetings (Thread)
15. ex-Administrivia (Thread)
16. IE without Images (Thread)
17. Operation TIPS (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
1. MS02-042 Patch on win2k pro kills capability to map to default...
2. info MBSA and patch (Thread)
3. Windows File Sharing with IPCop (Thread)
4. Force user login after 15 minutes of idle time w/o using a...
5. Force user login after 15 minutes of idle time w/o using a...
6. Force user login after 15 minutes of idle time w/o using a...
7. Force user login after 15 minutes of idle time w/o using a...
8. Outlook2000-Security-Settings (Thread)
9. Window XP login (Thread)
10. Windows 2000 SP3 (security) problems (Thread)
11. SP3 Problems? (Thread)
12. Windows Update for XP (Thread)
13. SecurityFocus Microsoft Newsletter #100 (Thread)
IX. SUN FOCUS LIST SUMMARY
1. Solaris NIS+ and Password Aging (Thread)
2. which process bind some port (Thread)
3. Hardening NIS+ (Thread)
4. Solstice Security Manager (Thread)
5. New SecurityFocus Lists! (Thread)
6. There's something about hardening NFS? (Thread)
X. LINUX FOCUS LIST SUMMARY
1. New SecurityFocus Lists! (Thread)
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. Windows ICF: Can't Live With it, Can't Live Without it
By David Wong
Windows ICF (Internet Connection Firewall) is the built-in firewall in
Windows XP. For this article, we put ICF into the lab and set our security
penetration testers loose at it to see how good it is. In this article, we
will give an overview of ICF, see how ICF performs under a simulated
attack, and discuss the pros and cons of ICF. ...
http://online.securityfocus.com/infocus/1620
2. Introduction to Autorooters: Crackers Working Smarter, not Harder
by Matt Tanase
Efficiency and automation: one can argue that they are two of the most
valuable by-products of any technology. There is little doubt that the
electronic tools of today allow us to get more done in less time. We use
software to eliminate tedious work, reduce man-hours, and sift through
mounds of data in seconds. Crackers, as we know, are smart... and lazy. It
should come as no surprise then that they too, have employed technology to
reduce their workload. The result? A type of malicious code known as
autorooters, programs designed to automatically scan and attack target
computers at blistering speeds.
http://online.securityfocus.com/infocus/1619
3. Know Your Enemy: Building Virtual Honeynets
by The Honeynet Project
Over the past several years, honeynets have demonstrated their value as a
security mechanism, primarily to learn about the tools, tactics, and
motives of the blackhat community. This information is critical for
organizations to better understand and protect against the threats they
face. Among the problems with honeynets is that they are resource
intensive, difficult to build, and complex to maintain. Honeynets require
a variety of both physical systems and security mechanisms to be
effectively deployed. However, the Honeynet Project has been researching a
new possibility, virtual honeynets. These systems share many of the values
of traditional honeynets, but have the advantages of running all the
systems on a single system. This makes virtual honeynets cheaper to build,
easier to deploy, and simpler to maintain.
http://online.securityfocus.com/infocus/1614
4. An Open Letter to the CIO
By Richard Forno
As the summer winds down and work resumes in earnest, our humble columnist
offers this open letter to CIOs on behalf of security admins everywhere.
http://online.securityfocus.com/
5. Send Congress Back to School
By Tim Mullen
So this aide walks into the office of Jack Valenti, President and CEO of
the Motion Picture Association of America... "Sorry for the interruption,
Mr. Valenti" she says, "but it's about the Berman Bill. What should we do
about it?"
http://online.securityfocus.com/columnists/103
6. The 21 Best Ways to Lose Your Information
by Kevin Beaver, CISSP ([email protected])
Have you ever wondered what the best ways are to get hacked, be adversely
affected by disasters, or otherwise lose information stored on your
computer systems? Here, in no particular order, are the 21 best ways to
not secure your systems:
http://online.securityfocus.com/guest/16221
7. SecurityFocus DPP Program
Attention Non-profit Organizations and Universities!! Sign-up now for
preferred pricing on the only global early-warning system for cyber
attacks - SecurityFocus DeepSight Threat Management System.
Click here for more information:
http://www.securityfocus.com/corporate/products/dpsection.shtml
8. InforwarCon 2002
InforwarCon 2002: Homeland Defense and Cyber-Terrorism, Washington, DC
September 4-5, 2002, optional workshops September 3 & 6. Presented by MIS
Training Institute and Interpact, Inc. Proven strategies for protecting
against threats to critical infrastructures and government systems.
Visit us at:
http://www.misti.com/08/iw02nl26inf.html
II. BUGTRAQ SUMMARY
-------------------
1. AOL Instant Messenger Link Special Character Remote Heap Overflow Vulnerability
BugTraq ID: 5492
Remote: Yes
Date Published: Aug 18 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5492
Summary:
AIM is the AOL Instant Messenger. It is available for various platforms,
including Linux and Microsoft Windows. This vulnerability affects the
Windows client.
It has been reported that it is possible to cause a heap overflow in AIM.
A problem has been reported in the handling of special characters, such as
spaces (%20). When an URL is sent to a user containing special characters
that must be converted to addressable format, an overflow may occur.
This has reportedly been reproduced to create a denial of service.
In the event that this is an exploitable heap overflow, this vulnerability
could potentially be used to execute arbitrary code. If this is the case,
remote code execution in the context of the AIM user would result.
2. FreeBSD System Call Signed Integer Buffer Overflow Vulnerability
BugTraq ID: 5493
Remote: No
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5493
Summary:
A vulnerability has been reported for the FreeBSD system. Reportedly, a
few system calls are vulnerable to signed integer buffer overflow
conditions.
The vulnerability is the result of system calls assuming that some
arguments were given as positive integers while, in actuality, the
arguments were handled as signed integers. If a negative value was
supplied for the argument, the boundary checking code would fail.
This results in the kernel returning a large portion of kernel memory
which may contain sensitive information including passwords. An attacker
may be able to use the information obtained to elevate privileges.
This vulnerability has been reported to affect the accept(2),
getsockname(2), and getpeername(2) system calls, and the vesa(4)
FBIO_GETPALETTE ioctl(2). The associated files in the kernel source are:
src/sys/i386/isa/vesa.c src/sys/kern/uipc_syscalls.c
src/sys/conf/newvers.sh
Welcome to the SecurityFocus.com 'week in review' newsletter issue
FreeBSD has reported that all versions of FreeBSD, up to and including
4.6.1-RELEASE-p10, are vulnerable to this issue.
3. Tomahawk Technologies SteelArrow Cookie HTTP Header Buffer Overflow Vulnerability
BugTraq ID: 5494
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5494
Summary:
SteelArrow Web Application Server is a freely available application server
by Tomahawk Technologies Inc. It is designed for use with Microsoft
Windows operating systems.
Reportedly, SteelArrow suffers from a buffer overflow condition when
cookies are used. SteelArrow keeps records of user sessions using cookies.
It is possible for an attacker to supply an overly long value of the
Cookie HTTP header that will cause the buffer overflow condition. This
will cause the SteelArrow service to crash and overwrite stack memory with
attacker supplied values.
As the SteelArrow service is installed as a system service, any
attacker-supplied code will be executed with SYSTEM privileges. The
attacker may also crash the service by sending excessive amounts of data
that has not specifically been constructed to cause code execution.
This vulnerability was first described in BugTraq ID 4860, Tomahawk
Technologies SteelArrow Web Application Server Multiple Buffer Overflow
Vulnerabilities.
4. Tomahawk Technologies SteelArrow ARO File Request Buffer Overflow Vulnerability
BugTraq ID: 5495
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5495
Summary:
SteelArrow Web Application Server is a freely available application server
by Tomahawk Technologies Inc. It is designed for use with Microsoft
Windows operating systems.
Reportedly, SteelArrow suffers from a buffer overflow condition requests
for files with a .ARO extension are made. It is possible for an attacker
to supply an overly long value to the SteelArrow service, when requesting
files with a .ARO extension, that will cause the buffer overflow
condition. This results in an access violation in DLLHOST.EXE that will
cause the SteelArrow service to crash and overwrite stack memory with
attacker supplied values.
Any attacker-supplied code will be executed with the privileges of the
IWAM account. The attacker may also crash the service by sending excessive
amounts of data that has not specifically been constructed to cause code
execution.
This vulnerability was first described in BugTraq ID 4860, Tomahawk
Technologies SteelArrow Web Application Server Multiple Buffer Overflow
Vulnerabilities.
5. Tomahawk Technologies SteelArrow Chunked Transfer Encoding Heap Overflow Vulnerability
BugTraq ID: 5496
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5496
Summary:
SteelArrow Web Application Server is a freely available application server
by Tomahawk Technologies Inc. It is designed for use with Microsoft
Windows operating systems.
A heap overflow vulnerability has been reported for SteelArrow when
handling chunked encoded transfers. The HTTP protocol specifies a method
of data encoding called 'Chunked Encoding', designed to facilitate
fragmentation of HTTP requests in transit. When processing requests for
.ARO files coded with the 'Chunked Encoding' mechanism, SteelArrow fails
to properly calculate required buffer sizes.
This will cause SteelArrow to cause an exception in DLLHOST.EXE and
overwrite heap memory. It is possible for an attacker manipulate data
structures to inject malicious code into attacker supplied memory
addresses. Any attacker-supplied code will be executed with the privileges
of the IWAM account.
This vulnerability was first described in BugTraq ID 4860, Tomahawk
Technologies SteelArrow Web Application Server Multiple Buffer Overflow
Vulnerabilities.
6. PostgreSQL cash_words Function Buffer Overflow Vulnerability
BugTraq ID: 5497
Remote: No
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5497
Summary:
PostgreSQL is a freely distributed Object-Relational DBMS.
A buffer overflow vulnerability has been reported for PostgreSQL.
Reportedly, PostgreSQL doesn't properly handle overly long queries when
selecting the cash_words() function.
It is possible to cause the database server process to crash when issuing
a cash_words() function as follows:
psql> select cash_words('-700000000000000000000000000000');
It is believed that an attacker could potentially exploit this condition
to overwrite stack variables with attacker-supplied values. It is highly
possible that exploitation could result in execution of malicious
attacker-supplied code as the database server process.
This vulnerability has been reported for PostgreSQL versions 7.2 and
earlier.
7. nCipher PKCS#11 Symmetric Message Signature Verification Vulnerability
BugTraq ID: 5498
Remote: Unknown
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5498
Summary:
nCipher produces a range of hardware and software security products which
support a range of cryptographic operations. A vulnerability has been
reported in the nCipher cryptographic library, related to the checking of
some message signatures.
The RSA PKCS#11 specification allows the signing of messages with a
symmetric key. Verification of these signatures is supported by the
nCipher cryptographic library. However, an error in the library
implementation may result in incorrect results being returned when
signatures are verified.
Under some conditions, the vulnerable function C_Verify may return the
'CKR_OK' message when an invalid signature is verified. The
'CKR_SIGNATURE_INVALID' message would normally be expected under this
condition. As a result, products and processes which rely on this library
function may make erroneous trust decisions regarding messages with
invalid signatures.
The consequences of exploitation will be highly dependent on the nature of
the application using the vulnerable library. It is likely that
exploitation will allow an attacker to inject or modify encrypted
information which is normally protected by a signature. Impersonation of
trusted parties may be possible.
Reportedly, the vulnerable signature mechanism is used by a number of
common protocols, including SSLv2, SSH and IPSEC.
This issue exists in versions 1.2.0 and later of the nCipher cryptographic
library.
8. Lynx Command Line URL CRLF Injection Vulnerability
BugTraq ID: 5499
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5499
Summary:
Lynx is a freely distributable, text-based WWW client. It is available for
use on various operating systems and platforms including Linux and Unix
variant and Microsoft Windows operating environments.
A CRLF injection vulnerability has been reported for Lynx that may allow
an attacker to include extra HTTP headers when viewing web pages. If Lynx
is called from the command line, carriage return and line feed (CRLF)
characters may be included in the specified URL. These characters are not
escaped when the input is used to construct a HTTP request.
As CRLF is used as a delimiter between headers under the HTTP protocol,
exploitation of this vulnerability will result in additional headers being
included in the HTTP request.
Injection of a 'Host' header may cause the request to be serviced as if
made to a different domain, if the server in question supports multiple
hosts. It may also be possible to inject arbitrary cookie data.
It is still possible for attackers to exploit this vulnerability even if
the '-realm' and '-restrictions=useragen' options are used. Reportedly, it
is also possible for an attacker to contact other type of servers,
including POP3 servers and MTAs (Mail Transfer Agents).
This vulnerability has been reported for Lynx versions 2.8.4rel.1,
2.8.5dev.8, 2.8.3rel.1 and 2.8.2rel.1. It is not known whether other
versions are affected.
*** Links 0.9.6 and ELinks have also been reported as being vulnerable.
Some versions of Links and ELinks URL encode space characters so an
attacker needs to use tab characters, instead of spaces, to exploit the
issue on these browsers.
9. Ilia Alshanetsky FUDForum SQL Injection Vulnerability
BugTraq ID: 5500
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5500
Summary:
Ilia Alshanetsky FUDForum is a freely available Web-based forum. It is
implemented in PHP and is available for Linux and Unix variant, as well
as, Microsoft Windows operating systems.
Reportedly, L-Forum is vulnerable to SQL injection attacks. User input is
not properly sanitized before being included in SQL statements. The
vulnerability lies in the files 'report.php', 'selmsg.php' and
'showposts.php'.
SQL code may be inserted into the requests and executed by the database
server. These requests could include adding, deleting, and modifying data.
It may be possible to access sensitive information, such as authentication
credentials for other users of the forum software.
Additionally, this may allow a remote attacker to exploit vulnerabilities
that exist in the underlying database.
10. W3C Jigsaw Proxy Server Cross-Site Scripting Vulnerability
BugTraq ID: 5506
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5506
Summary:
The W3C Jigsaw project includes a HTTP proxy server written in Java.
When the proxy server cannot successfully resolve a fully qualified domain
name, an error page is served to the client. The requested URL is
included in the content of this page without being adequately sanitized.
Consequently, embedded script code may execute within the context of the
requested URL (and it's domain). Exploitation may result in theft of
cookie information or impersonation of websites associated with the
domain.
11. Kerio MailServer Multiple SYN Packet Denial Of Service Vulnerability
BugTraq ID: 5505
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5505
Summary:
Kerio MailServer is a mail server designed for use with Microsoft Windows
and Linux and Unix variant operating systems.
Kerio MailServer is vulnerable to a denial of service condition when it
receives multiple SYN packets.
An attacker may be able to exploit this vulnerability by sending multiple
SYN packets to all the services of Kerio Mailserver (POP3, SMTP, IMAP,
Secure IMAP, POP3S, Web-mail, Secure Web-mail). This prevents all the
affected services from responding to requests for service.
An attacker sending five SYN packets will cause the service to stop
responding for a few minutes. During this duration, Kerio Mailserver will,
reportedly, consume all resources of the system and fail to respond to any
more requests for service. Repeated exploitation of this vulnerability
will prevent Mailserver from responding at all. Other services offered by
the vulnerable system will be affected as well.
12. Kerio MailServer Web Mail Multiple Cross Site Scripting Vulnerabilities
BugTraq ID: 5507
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5507
Summary:
Kerio MailServer is a mail server designed for use with Microsoft Windows
and Linux and Unix variant operating systems.
Reportedly, Kerio Mailserver is vulnerable to cross site scripting
attacks. The vulnerability is present in Kerio Mailserver's web mail
component.
An attacker may exploit this vulnerability by causing a victim user to
follow a malicious link. Attacker-supplied code may execute within the
context of the site hosting the vulnerable software when the malicious
link is visited.
This type of vulnerability may be used to steal cookies or perform other
web-based attacks. It may be possible to take actions as an authenticated
user of the web mail system.
13. Microsoft File Transfer Manager ActiveX Control Buffer Overflow Vulnerability
BugTraq ID: 5508
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5508
Summary:
The Microsoft File Transfer Manager (FTM) ActiveX control is used to allow
beta test customers and others to download files from certain Microsoft
sites.
The File Transfer Manager ActiveX control is signed by Microsoft and
marked as safe for scripting, which could allow it to be installed by a
website with littlw or no warning on a system if the user has chosen to
always trust content from Microsoft.
A buffer overflow exists in the function that parses input strings that
are passed via scripts to a Persist function. A string passed to TS= that
is longer than 12kb will overflow the buffer, resulting in memory
corruption. Execution of arbitrary code may be possible, since memory can
potentially be corrupted with attacker-supplied data.
14. Mantis Account Update SQL Injection Vulnerability
BugTraq ID: 5510
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5510
Summary:
Mantis is a web-based bug tracking system. It is written in PHP and
back-ended by a MySQL database.
It has been reported that Mantis is vulnerable to a SQL injection attack.
The affected component is 'account_update.php', which is associated with
user account modifications.
According to the vendor, the username and email parameters are not
adequately sanitized before they are used to construct a SQL query string.
As a result, malicious clients may embed special characters that modify
logic and structure of the query.
It is confirmed that users may exploit this vulnerability to elevate their
Mantis user privileges.
15. Microsoft File Transfer Manager Arbitrary File Upload/Download Vulnerability
BugTraq ID: 5512
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5512
Summary:
The Microsoft File Transfer Manager (FTM) ActiveX control is used to allow
beta test customers and others to download files from certain Microsoft
sites.
The File Transfer Manager ActiveX control can queue any download or upload
item in the list of scheduled items without notifying the user. This can
reportedly be accomplished by setting the TGT= and TGN= parameters during
a call to the Persist function.
Through a man in the middle attack, an attacker may be able to set the
URL= parameter to their TCP proxy and pointing the proxy to Microsoft
servers. This could potentially allow the attacker to upload or download
any file of their choosing.
16. Mantis Configuration Remote File Include Command Execution Vulnerability
BugTraq ID: 5509
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5509
Summary:
Mantis is a web-based bug tracking system. It is written in PHP and
back-ended by a MySQL database.
Mantis depends on some include files for configuration of the bug tracking
system. The paths to the all the included configuration related files are
specified in the config_inc2.php script, which may be overridden in the
config_inc.php script. However, attackers may influence the variables
which contain the path to the included files. It is possible for
attackers to specify an arbitrary path, either to a local file or a file
on a remote server. This may be accomplished via a request to any of the
Mantis scripts which rely on includes to external files to pull any
configuration related information. It is also possible to exploit this
issue via a maliciously crafted cookie.
Attackers may use this to include PHP files located on remote servers.
Execution of arbitrary commands with the privileges of the webserver is
the result of successful exploitation. Additionally, this vulnerability
may be exploited to disclose the contents of arbitrary webserver readable
files.
17. Ilia Alshanetsky FUDForum File Modification Vulnerability
BugTraq ID: 5502
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5502
Summary:
Ilia Alshanetsky FUDForum is a freely available Web-based forum. It is
implemented in PHP and is available for Linux and Unix variant, as well
as, Microsoft Windows operating systems.
Reportedly, it is possible for an administrator to manipulate (create,
modify and view) files outside of the FUDForum directories. This
vulnerability is present in the 'adm/admbrowse.php' script. The
vulnerability is the result of FUDForum allowing access to files and
directories outside of FUDForum directories.
By simply making malicious requests to 'adm/admbrowse.php' via URI
parameters, an attacker is able to obtain access to potentially sensitive
files. It may also be possible to create and modify arbitrary files on the
vulnerable system. However, this has not been confirmed.
18. Ilia Alshanetsky FUDForum File Disclosure Vulnerability
BugTraq ID: 5501
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5501
Summary:
Ilia Alshanetsky FUDForum is a freely available Web-based forum. It is
implemented in PHP and is available for Linux and Unix variant, as well
as, Microsoft Windows operating systems.
Reportedly, FUDForum may disclose contents of arbitrary files to
attackers. This vulnerability is present in the 'tmp_view.php' script. The
vulnerability is the result of FUDForum failing to check the path of the
file that is being requested.
By simply making malicious requests to 'tmp_view.php' via URI parameters,
an attacker is able to obtain access to potentially sensitive files.
19. MySQL Null Root Password Weak Default Configuration Vulnerability
BugTraq ID: 5503
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5503
Summary:
MySQL is is an open source relational database project, and is available
for a number of operating systems, including Microsoft Windows.
A weak default configuration problem has been reported in some versions of
MySQL. Reportedly, the root user of the database is defined with no
password, and granted login privileges from any host.
Users unaware of this may fail to define a strong password for the root
user. While the MySQL security documentation does suggest verifying that
the root user has a password defined, an inexperienced administrator may
overlook this step.
Exploitation of this issue can allow a remote attacker to connect to the
database with full privileges. Exploitation may result in access to
sensitive information, or allow denial of service attacks through the
destruction of data.
This issue has been reported in the Windows binary release of MySQL. Other
versions may share this default configuration, this has not however been
confirmed.
20. Mantis JPGraph Remote File Include Command Execution Vulnerability
BugTraq ID: 5504
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5504
Summary:
Mantis is a web-based bug tracking system. It is written in PHP and
back-ended by a MySQL database.
Mantis depends on include files to provide some functionality, such as
dynamic generation of graphs. To generate graphs dynamically, Mantis
relies upon the JpGraph library, which is invoked using a PHP include()
statement. However, since Mantis does not properly validate the path to
the include file, it is possible for attackers to specify an arbitrary
path, either to a local file or a file on a remote server.
This may lead to disclosure or execution of local files. More seriously,
attackers may exploit this issue to include PHP files located on remote
servers. Execution of arbitrary commands with the privileges of the
webserver is the result of successful exploitation.
This issue exists in the summary_graph_functions.php script. Malicious
users may specify an arbitrary path as a value for the $g_jpgraph_path
variable.
21. MySQL Bind Address Not Enabled Weak Default Configuration Vulnerability
BugTraq ID: 5511
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5511
Summary:
MySQL is is an open source relational database project, and is available
for a number of operating systems, including Microsoft Windows.
MySQL supports the 'bind-address' configuration directive. This restricts
database access to the defined address. If remote administration is not
required, this variable may be set to the loopback address 127.0.0.1,
preventing access from any remote system.
This option is not enabled by default, possibly allowing remote access to
default installations of the server. The MySQL security documentation
does, however, suggest restricting remote access to the server to only
required hosts.
This issue has been reported in the Windows binary release of MySQL. Other
versions may share this default configuration, this has not however been
confirmed.
22. MySQL Logging Not Enabled Weak Default Configuration Vulnerability
BugTraq ID: 5513
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5513
Summary:
MySQL is is an open source relational database project, and is available
for a number of operating systems, including Microsoft Windows.
Reportedly, most logging is disabled by default in MySQL. If not
explicitely enabled, an administrator may not detect malicious actions or
attacks against the database.
Logging of errors may, however, be enabled by default.
This issue has been reported in the Windows binary release of MySQL. Other
versions may share this default configuration, this has not however been
confirmed.
23. Mantis Print Reports Limit Reporters Option Bypass Vulnerability
BugTraq ID: 5515
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5515
Summary:
Mantis is a web-based bug tracking system. It is written in PHP and
back-ended by a MySQL database.
Mantis is prone to an issue which may allow malicious users of the bug
tracking system to gain unauthorized access to restricted bug summaries.
This may be a security concern in organizations that use the software to
restrict viewing rights of bugs to some users.
Mantis includes the option limit_reporters, which allows users to view
only those bugs which they reported. This automatically sets the
'reporter' filter on the View Bugs page.
However, there is an option on the View Bugs page which formats the
results for printing. The script responsible for this,
print_all_bug_page.php, does not check for the 'limit_reporters' option,
and will display the summaries for all relevant bugs.
24. Mantis Unauthorized Project Bug List Viewing Vulnerability
BugTraq ID: 5514
Remote: Yes
Date Published: Aug 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5514
Summary:
Mantis is a web-based bug tracking system. It is written in PHP and
back-ended by a MySQL database.
Mantis is prone to an issue which may allow malicious users of the bug
tracking system to gain unauthorized access to restricted projects. This
may be a security concern in organizations that use the software to
restrict viewing rights of bugs to some users.
Vulnerable versions of Mantis do not adequately check that a user has
access to projects. Instead of relying on other forms of authentication
to restrict access to other projects, Mantis simply expects that users
will only attempt to access projects that are listed in a drop-down
project menu on the 'View Bugs' page.
It has been reported that a malicious user may manipulate values in
cookie-based authentication credentials to gain unauthorized viewing
rights to bugs in other projects. However, exploitation of this issue is
limited to gaining a listing of 'Public' bugs in other projects. Further
information about 'Public' bugs may not be disclosed, and 'Private' bugs
may not be listed.
This issue was reported in Mantis 0.17.3. Earlier versions are also
believed to be affected.
25. Mozilla Bonsai Multiple Cross Site Scripting Vulnerabilities
BugTraq ID: 5516
Remote: Yes
Date Published: Aug 20 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5516
Summary:
Mozilla Bonsai is a tool that allows a user to perform queries on the
contents of a CVS archive.
Multiple cross site scripting vulnerabilities have been reported for the
Bonsai tool.
An attacker may exploit this vulnerability by causing a victim user to
follow a malicious link. Attacker-supplied code may execute within the
context of the site hosting the vulnerable software when the malicious
link is visited.
This type of vulnerability may be used to steal cookies or perform other
web-based attacks. It may be possible to take actions as an user of the
Bonsai system.
This vulnerability has been reported for Mozilla Bonsai 1.3 (including all
current and CVS versions).
26. Mozilla Bonsai Path Disclosure Vulnerability
BugTraq ID: 5517
Remote: Yes
Date Published: Aug 20 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5517
Summary:
Mozilla Bonsai is a tool that allows a user to perform queries on the
contents of a CVS archive.
A path disclosure vulnerability has been reported in Mozilla Bonsai. This
issue is reported to affect all current and CVS versions of the utility.
An attacker can exploit this vulnerability by making a malformed request
to Bonsai. This causes Bonsai to return an error page to the requesting
user. This error page will contain the absolute path information about the
requested file.
Information disclosed in this manner may be used by remote attackers in
intelligence gathering and may aid in further attacks against the
vulnerable host.
27. WebEasyMail SMTP Service Format String Vulnerability
BugTraq ID: 5518
Remote: Yes
Date Published: Aug 20 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5518
Summary:
WebEasyMail is a MTA (Mail Transfer Agent) designed for use with Microsoft
Windows NT, 2000 and XP operating systems.
WebEasyMail is prone to a format string vulnerability. This problem is due
to incorrect handling of user input by the SMTP service offered by
WebEasyMail. The affected service's name is emsrv.exe.
When the service receives malformed input, it will reportedly crash. It
may be possible to corrupt memory by passing format strings through the
vulnerable service. This may potentially be exploited to overwrite
arbitrary locations in memory with attacker-specified values.
Successful exploitation of this issue may allow the attacker to execute
arbitrary instructions with the privileges of the WebEasyMail service,
however, this has not been confirmed.
This vulnerability has been reported for WebEasyMail 3.4.2.2. It is not
known whether other versions are affected.
28. WebEasyMail POP3 Server Valid User Name Information Disclosure Vulnerability
BugTraq ID: 5519
Remote: Yes
Date Published: Aug 20 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5519
Summary:
WebEasyMail is a MTA (Mail Transfer Agent) designed for use with Microsoft
Windows NT, 2000 and XP operating systems.
An issue has been discovered in WebEasyMail's POP3 server which may make
it easier for remote attackers to verify the existence of user accounts.
In particular, it is trivial for an attacker to determine if a username
exists or not. When a user authenticates against the POP3 server using an
invalid username followed by a password, WebEasyMail gives the following
feedback:
-ERR invalid username
This issue allows the attacker to determine which usernames are valid. The
attacker may then attempt a brute-force attack in an attempt to crack the
passwords of valid usernames.
29. Novell NetWare HTTP Post Arbitrary Perl Code Execution Vulnerability
BugTraq ID: 5520
Remote: Yes
Date Published: Aug 20 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5520
Summary:
A vulnerability has been reported in some versions of Novell NetWare. This
issue lies in the handling of some HTTP requests when Perl is used as a
handler by a web server.
Reportedly, it is possible for an attacker to execute arbitrary Perl code.
While full technical details are not available, it is likely that the
attacker may specify arbitrary code, which is then executed with the
privileges of the web server.
Exploitation of this issue may result in the attacker gaining local access
to the vulnerable system. Once local access is gained, elevated privileges
are often trivial to obtain.
This issue has been reported in versions of NetWare using Perl 5.003.
Reportedly, systems with Perl 5.6 installed are not vulnerable to this
issue.
30. Novell NetWare Remote Perl Version Disclosure Vulnerability
BugTraq ID: 5521
Remote: Yes
Date Published: Aug 20 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5521
Summary:
A vulnerability has been reported in some versions of Novell NetWare. This
issue exists when a web server uses Perl as a handler.
Reportedly, it is possible for an attacker to execute Perl with the '-v'
parameter, resulting in the disclosure of the version of Perl in use. Full
technical details are not currently available.
Exploitation of this issue may aid a malicious party in planning further
attacks against the vulnerable system.
This issue has been reported in versions of NetWare using Perl 5.003.
Reportedly, systems with Perl 5.6 installed are not vulnerable to this
issue.
31. Novell NetWare Encoded Slash Directory Traversal Vulnerability
BugTraq ID: 5522
Remote: Yes
Date Published: Aug 20 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5522
Summary:
A vulnerability has been reported in some versions of Novell NetWare. This
issue lies in the handling of some HTTP requests when a web server uses
Perl as a handler.
Reportedly, a directory traversal attack is possible. This is the result
of an error in the handling of the URL encoded '\' character, which is
encoded as '%5C'. While full technical details have not been released, it
is likely that exploitation will allow a remote attacker to view any file
on the system, restricted only by the permissions of the web server user.
Exploitation of this issue may result in the disclosure of sensitive
information, and aid a malicious party in making further attacks against
the vulnerable system.
This issue has been reported in versions of NetWare using Perl 5.003.
Reportedly, systems with Perl 5.6 installed are not vulnerable to this
issue.
32. Novell NetBasic Scripting Server Directory Traversal Vulnerability
BugTraq ID: 5523
Remote: Yes
Date Published: Aug 20 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5523
Summary:
The Novell NetBasic Scripting Server (NSN) provides functionality for
interpreting and serving scripts written in NetBasic. It is available for
Netware and the Novell Small Business Suite platforms.
NSN is prone to a vulnerability which may enable remote attackers to gain
access to resources outside of the scripting server root directory. This
is possible if an attacker substitutes '%5' in place of a forward or
backward slash in a request for a resource that resides outside of the
scripting server root.
An attacker may potentially exploit this condition to gain unauthorized
access to sensitive information contained in files that reside on the
system hosting NSN.
33. Tiny Personal Firewall Log File Viewing Denial Of Service Vulnerability
BugTraq ID: 5525
Remote: Yes
Date Published: Aug 20 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5525
Summary:
Reportedly, Tiny Personal Firewall is vulnerable to a denial of service
condition. The vulnerability occurs when a user selects to browse the
Personal Firewall Agent Logs and when the system is being portscanned.
An attacker can exploit this vulnerability by portscanning a vulnerable
system and sending numerous TCP, UDP, and ICMP packets. If the victim user
is also viewing the Personal Firewall Agent Logs when the attack takes
place, Tiny Personal Firewall will stop responding. This will cause Tiny
Personal Firewall to consume all CPU resources and cause the system to
stop responding and eventually crash.
This vulnerability is also exacerbated by the fact that Tiny Personal
Firewall does not properly handle spoofed addresses. Specifically, it
doesn't properly handle spoofed packets that supposedly originate from
itself.
This vulnerability was reported for Tiny Personal Firewall 3.0 in a
Windows 2000 Advanced Server and Windows NT environment. It is not known
whether other versions are affected by this vulnerability.
34. SCPOnly SSH Environment Shell Escaping Vulnerability
BugTraq ID: 5526
Remote: No
Date Published: Aug 20 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5526
Summary:
scponly is a freely available, open source restricted secure copy client.
It is available for Unix and Linux operating systems.
A problem with scponly could make it possible for a user to gain
unintended access to a system running a vulnerable version.
The default installation of scponly does not place sufficient access
controls on the .ssh subdirectory. Due to this oversight, it is possible
for a remote user to upload files which may allow command execution.
This could lead to unintended command execution, and regular shell access
to a vulnerable host.
The problem is in the environment file contained within the .ssh
subdirectory. If this file is installed with permissions that allow user
modification to the file (which is the default behavior), a user would be
able to upload a new version of this file. This file could contain
malicious commands, such as changing the user's shell, and would be
executed by the user upon the next log-in.
35. Novell NetBasic Interpreter Module Name Buffer Overflow Vulnerability
BugTraq ID: 5524
Remote: Yes
Date Published: Aug 20 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5524
Summary:
The Novell NetBasic Scripting Server (NSN) provides functionality for
interpreting and serving scripts written in NetBasic. It is available for
Netware and the Novell Small Business Suite platforms.
The Novell NetBasic interpreter included in Novell NetBasic Scripting
Server (NSN) is prone to a remotely exploitable buffer overflow condition.
This is due to insufficient bounds checking of requests for modules. It
is possible to reproduce this condition by supplying an overly long module
name (230+ bytes) in a request to NSN. This will cause NSN to ABEND
(abnormally end).
As a result, memory may potentially be corrupted with attacker-supplied
data. This condition may be exploited to cause a denial of service, and
could potentially be exploited to execute arbitrary code with the
privileges of NSN.
36. PostgreSQL Repeat Function Buffer Overflow Vulnerability
BugTraq ID: 5527
Remote: Yes
Date Published: Aug 20 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5527
Summary:
PostgreSQL is a freely distributed Object-Relational DBMS.
An overflow vulnerability has been reported in some versions of
PostgreSQL. The issue lies in the handling of large integer arguments by
the repeat() function, used to create a text string with a specified
number of copies of the original argument.
Reportedly, if this function is called with an extremely large integer
argument, memory allocated on the heap will be overflowed. An attacker
able to call this function may corrupt adjacent data. It may be possible
to corrupt control structures used by some heap implementations and force
the database process to execute arbitrary, attacker-supplied code.
37. PostgreSQL String Pad Function Buffer Overflow Vulnerability
BugTraq ID: 5528
Remote: No
Date Published: Aug 20 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5528
Summary:
PostgreSQL is a freely distributed Object-Relational DBMS.
A buffer overflow vulnerability has been reported for PostgreSQL.
Reportedly, PostgreSQL doesn't properly handle overly large integer
arguments given to the lpad() and rpad() funtions. The functions are
lpad() and rpad() found in the file,
src/backend/utils/adt/oracle_compat.c, and serve to pad an existing text
string with another up to a given length.
This vulnerability only affects data bases that were created using special
international encodings. For example, databases that were created using a
'UNICODE' encoding are vulnerable to this issue.
It is possible to cause the database server process to crash when issuing the lpad() or rpad() function as follows:
my_db=# select lpad('xxxxx',1431655765,'yyyyyyyyyyyyyyyy'); my_db=# select
rpad('xxxxx',1431655765,'yyyyyyyyyyyyyyyy');
This will cause PostgreSQL to improperly allocate space on the system
stack. Thus, it is believed that an attacker could potentially exploit
this condition to overwrite stack variables with malicious
attacker-supplied values. It is highly possible that exploitation could
result in execution of malicious attacker-supplied code as the database
server process.
Reportedly, databases created with EUC_JP, EUC_CN, EUC_KR, EUC_TW,
UNICODE, or MULE_INTERNAL encodings are vulnerable to this issue.
38. Multiple VNC Products For Windows Win32 Messaging API Vulnerability
BugTraq ID: 5530
Remote: No
Date Published: Aug 21 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5530
Summary:
Virtual Network Computing, or VNC, is a system which provides remote
access to a desktop environment. A vulnerability has been reported in a
number of VNC products when used on Microsoft Windows based systems.
Vulnerable VNC products provide graphical user interface elements which
run with privileges. A local user with lower privileges may send arbitrary
Win32 messages to the privileged process.
It has been reported possible to exploit this ability to force the VNC
process to execute arbitrary code, providing the attacker with elevated
privileges. More subtle attacks based on modifications to the dialogs
presented to the user may also be possible, although this has not been
confirmed.
This general class of vulnerabilities has been documented as BID 5408.
39. Sun Cobalt RaQ Predictable Temporary Filename Symbolic Link Attack Vulnerability
BugTraq ID: 5529
Remote: No
Date Published: Aug 21 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5529
Summary:
Cobalt RaQ is a server appliance for Internet-based services. It is
distributed and maintained by Sun Microsystems.
A vulnerability has been reported in Cobalt RaQ that may allow attackers
to obtain elevated privileges. The vulnerability exists in the
/usr/lib/authenticate utility which is used by Apache for authentication
purposes. Reportedly, the utility creates temporary files with predictable
names with world-writeable permissions.
The /usr/lib/authenticate utility creates a temporary file called
'gmon.out' in the temporary directory.
An attacker can exploit this vulnerabilty to create files on the
filesystem with world-writeable permissions. This vulnerability is further
exacerbated by the fact that /usr/lib/authenticate is a setuid root
binary.
This vulnerability was reported for the Apache web server distributed with
Cobalt RaQ 4.0. It is not known whether other versions of Cobalt RaQ are
vulnerable to this issue.
40. Pingtel Xpressa Phone Weak Session Parameters Vulnerability
BugTraq ID: 5537
Remote: Yes
Date Published: Aug 20 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5537
Summary:
Xpressa is the Java-Based Voice-Over-IP phone developed and distributed by
Pingtel. The Session Identification Protocol (SIP) is used by VoIP devices
to initiate communication sessions.
When a SIP session is created, two integer values are associated with
requests. A Call-ID value is unique for each session, and a CSeq value is
used as a sequence counter for each message. Reportedly, both of these
attributes are given predictable values by vulnerable devices.
The Call-ID value is static and predictable for each device. Reportedly,
the Call-ID value will be '8-reg@IP' or '9-reg@IP', where IP is the IP
address of the device. The CSeq counter is initalized to 1.
The ability to predict both of these values may aid an attacker in
attempting a number of attacks against a communication stream. It may be
possible to inject malicious data, possibly hijacking or subverting a
session.
41. Pingtel Xpressa Phone Home Information Leakage Vulnerability
BugTraq ID: 5534
Remote: Yes
Date Published: Aug 20 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5534
Summary:
Xpressa is the Java-Based Voice-Over-IP phone developed and distributed by
Pingtel.
Pingtel Xpressa IP phones may potentially leak sensitive information
across the network. When the phone is booted, registration information is
sent via the HTTP protocol to Pingtel's MyPingtel Portal. This
information includes the administrative name and hashed credentials.
Credentials are hashed using MD5. The MAC address and IP address for the
phone are also sent, in addition to other sensitive information.
An attacker with the ability to intercept traffic between the phone and
the MyPingtel Portal can gain access to this sensitive information. If
the hashed credentials can be obtained, it is trivial for an attacker to
mount a brute-force attack on the hash value.
The information leaked in this manner is sufficient for an attacker to
fully compromise the phone.
42. LG LR Series WAN Router Telnet Daemon Buffer Overflow Vulnerability
BugTraq ID: 5536
Remote: Yes
Date Published: Aug 21 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5536
Summary:
The LR series WAN routers are hardware and firmware solutions manufactured
and distributed by LG Electronics.
A problem with the router may make it possible for a remote user to deny
service to legitimate users of the router.
It has been discovered that when a stream of data is sent to the telnet
daemon when the prompt for a password is presented, the router becomes
unstable. By sending a stream of data in the password field of the
authentication challenge by the telnet daemon, the router reacts
unpredictably. This type of attack typically results in a crash of the
router.
It has been theorized that this issue is an exploitable buffer overflow.
If this proves to be the case, it could be possible for a remote attacker
to execute arbitrary code on a vulnerable WAN router.
43. LG LR Series WAN Router Data Stream Denial Of Service Vulnerability
BugTraq ID: 5532
Remote: Yes
Date Published: Aug 21 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5532
Summary:
The LR series WAN routers are hardware and firmware solutions manufactured
and distributed by LG Electronics.
A problem with the router may make it possible for a remote user to deny
service to legitimate users of the router.
It has been discovered that when a stream of data is sent to the router on
certain ports, the router becomes unstable. By sending a stream of data
to port 23/TCP (and also port 80/TCP on some models), which is accessible
by default, the router reacts unpredictably. This type of attack
typically results in a crash of the router.
It has been theorized that this issue is a bug in the TCP/IP stack of the
device, and possibly an exploitable buffer overflow. This theory is drawn
upon the fact that the device reports one of the following errors:
Router# [BUFFER] Unknown free 0xffffffff
Router# can't malloc
or
Router# [BUFFER] ERROR free not in use
Router# can't malloc
This is likely a memory exhaustion bug. If this proves to be a boundry
condition error, it could be possible for a remote attacker to execute
arbitrary code on a vulnerable router.
44. Stephen Ball File Manager Source.PHP Directory Traversal Vulnerability
BugTraq ID: 5533
Remote: Yes
Date Published: Aug 21 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5533
Summary:
Stephen Ball File Manager is a utility to manage files on a system. It is
implemented in PHP and is available for Microsoft Windows and Unix and
Linux variant operating systems.
A vulnerability has been reported for File Manager 1.5. Reportedly, it is
possible to launch directory traversal attacks against File Manager. It is
possible for remote attackers to access arbitrary files residing on a
vulnerable host.
An attacker may exploit this issue by submitting a request to the script
'source.php', and passing a CGI parameter specifying an arbitrary system
file. The '../' character sequence may be used to escape the specified
root directory.
Information disclosed through this vulnerability may aid an attacker in
making further attacks against the vulnerable system.
45. Microsoft Terminal Services Inactive Console Screensaver Lock Failure Weakness
BugTraq ID: 5535
Remote: No
Date Published: Aug 21 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5535
Summary:
A weakness has been reported for Microsoft Windows Terminal Services.
Reportedly, the Terminal Services screensaver will not automatically lock
the session if the client window is minimized.
If the automatic invocation of a screen saver is relied upon to provide
security, sessions may not be protected. An attacker able to gain local
access to a client session may access minimized Terminal Services session
as the vulnerable user.
This vulnerability was reported on a Microsoft Windows 2000 Server
operating environment. It is not known whether Terminal Server for Windows
NT is affected.
46. Novell NetWare 6.0 SP2 RConsoleJ Authentication Bypass Vulnerability
BugTraq ID: 5541
Remote: Yes
Date Published: Aug 21 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5541
Summary:
A vulnerability has been reported in some versions of Novell NetWare. The
issue lies in RCONAG6, used to permit remote access to the system through
an IP connection with RConsoleJ.
Under some conditions, a remote user may connect using RConsoleJ without
checking the console server password. In particular, this will happen if
the RConJ 'Secure IP' option (SSL) is used when the connection is
initiated.
Exploitation of this issue may grant a remote attacker local access to the
vulnerable system, without the need to authenticate.
This issue has been reported only in NetWare 6.0 SP2.
47. Linux Kernel 2.4.18 Security Issues
BugTraq ID: 5539
Remote: Unknown
Date Published: Aug 21 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5539
Summary:
Red Hat has issued an advisory reporting the correction of several
vulnerabilities in version 2.4.18 of the Linux kernel. Some of the
security issues are related to the following device drivers:
stradis rio500 se401 usbvideo apm
Furhermore, vulnerabilities reportedly exist in components of the procfs
virtual filesystem that may cause kernel memory to be exposed. It should
be assumed that at the very least, local attackers may exploit these
vulnerabilities to elevate privileges.
SecurityFocus is currently completing analysis of the reported
vulnerabilities and will issue individual alerts for each.
48. Sun PatchPro Insecure Temporary File Vulnerability
BugTraq ID: 5540
Remote: No
Date Published: Aug 21 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5540
Summary:
PatchPro is a freely available program written in Java for the Solaris
operating system. It is distributed and maintained by Sun Microsystems.
A problem with the program could create potential unspecified security
risks.
It has been revealed by Sun Microsystems that PatchPro insecurely creates
temporary files. This problem is likely to result in symbolic link
attacks, and possibly race condition errors. The exact nature of this
vulnerability is unspecified.
49. Apache Tomcat 4.1 JSP Request Cross Site Scripting Vulnerability
BugTraq ID: 5542
Remote: Yes
Date Published: Aug 21 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5542
Summary:
Jakarta Tomcat is a Java Servlet and JSP server produced by the Apache
Software Foundation. Tomcat is available for Microsoft Windows, Linux, and
other Unix based operating systems.
A cross site scripting vulnerability has been reported in some versions of
Tomcat. Reportedly, if a HTTP request is made for a JSP, malicious script
code embedded in the URI may be included in a page generated by Tomcat.
An attacker may generate a link to a vulnerable site, and include
arbitrary malicious script code. If a user is enticed into following this
link, the supplied code will be returned by the server, and execute within
the context of the vulnerable site.
Exploitation may result in the disclosure of sensitive cookie data, or the
ability to take actions as an authenticated user of the vulnerable site.
The consequences of exploitation will be highly dependant on the details
of the vulnerable site.
This may be related to the issues discussed in BID 2982. This has not,
however, been confirmed.
50. Microsoft Windows Media Player File Attachment Script Execution Vulnerability
BugTraq ID: 5543
Remote: Yes
Date Published: Aug 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5543
Summary:
Microsoft Windows Media Player is distributed with multiple versions of
the Microsoft Windows Operating System.
Reportedly, Microsoft Windows Media Player may allow malicious file
attachments to execute arbitrary code in the context of the local system.
Specifically the vulnerability is due to incorrect validation of WMD
(*.wmd) files. WMD (Windows Media Download) packages are used by Media
Player to store files in a user's known Virtual Music directory.
When downloaded, WMD packages will create a folder with the same name as
the downloaded package and store it in the default "Virtual Music" folder.
This folder typically resides in My Documents\My Music\Virtual Albums\.
It is possible for an attacker to compose a malicious WMD file consisting
of a malicious .ASX and .ASF file and have Media Player extract these
files into a known location. The ASX enables a user to play streaming
media residing on an intranet or external site.
Windows Media Player runs in the security context of the user currently
logged on, therefore arbitrary code would be run at the privilege level of
that particular user.
51. Multiple Vendor IPv4-IPv6 Transition Address Spoofing Vulnerability
BugTraq ID: 5545
Remote: Yes
Date Published: Aug 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5545
Summary:
IPv6 is a protocol designed to replace IPv4. IPv6 allows for the
encapsulation of IPv4 addresses, in order to facilitate transition between
the two standards, and allow the usage of IPv4 legacy applications under
IPv6 networking.
Additionally, many systems are expected to support both IPv4 and IPv6
traffic, in order to allow a transition period between the two standards.
Malicious parties may be able to abuse this feature in order to spoof IPv4
addresses. Under some circumstances, IPv4 addresses may be extracted from
IPv6 traffic and passed to applications. These applications will not be
able to distinguish between legitimate IPv4 traffic and that embedded in
IPv6 traffic.
If trust decisions are made based on this information, an attacker may be
able to bypass some security measures. For example, certain applications
may restrict access to a limited range of IPv4 addresses, only allow
access from the loopback address 127.0.0.1, or perform reverse lookup
checks on IPv4 addresses.
The details and consequences of exploitation will be highly dependant on
the specifics of deployed applications. It may be possible to gain
unauthorized access to systems, or to generate malicious network traffic
through the usage of the loopback address or broadcast addresses.
52. Abyss Web Server Encoded Backslash Directory Traversal Vulnerability
BugTraq ID: 5547
Remote: Yes
Date Published: Aug 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5547
Summary:
Abyss Web Server is a freely available personal web server. It is
maintained by Aprelium Technologies and runs on Microsoft Windows
operating systems, as well as Linux.
A directory traversal vulnerability has been reported for Abyss Web
Server. The issue is related to the failure to properly process the
backslash '\', encoded as '%5c', character, which may be used as a
directory delimiter under these platforms. By using the URL encoded
sequence '%2e%2e%5c', the web root may be escaped.
Exploitation can result in arbitrary system files being sent to a remote
attacker. This information may be of value in attempting further attacks
against the vulnerable system.
The directory traversal vulnerability was reported for Abyss Web Server
for both the Microsoft Windows and Linux operating environment. In a Linux
environment, it is only possible to escape immediately out of the web root
directory and into the Abyss folder; it is not possible for an attacker to
view files residing outside of the Abyss installation folder. However, in
a Windows environment the attacker is able to traverse outside of the
webroot and into all areas of the filesystem.
53. Abyss Web Server Administrative Console Unauthorized Access Vulnerability
BugTraq ID: 5548
Remote: Yes
Date Published: Aug 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5548
Summary:
Abyss Web Server is a freely available personal web server. It is
maintained by Aprelium Technologies and runs on Microsoft Windows
operating systems, as well as Linux.
A vulnerability has been reported for Abyss Web Server for both the Linux
and Microsoft Windows operating environments. Reportedly, it is possible
for an attacker to obtain access to Abyss Web Server's administrative
console without any need for authentication.
An attacker can exploit this vulnerability to change any, and all,
configuration parameters of Abyss Web Server, including the administrative
password. It will also enable the remote attacker to stop and restart the
Web server.
54. Abyss Web Server Malicious HTTP Request Information Disclosure Vulnerability
BugTraq ID: 5549
Remote: Yes
Date Published: Aug 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5549
Summary:
Abyss Web Server is a freely available personal web server. It is
maintained by Aprelium Technologies and runs on Microsoft Windows
operating systems, as well as Linux.
Reportedly, it is possible for attackers to obtain the contents of files
by appending a special character to HTTP requests to Abyss Web Server.
An attacker can exploit this vulnerability to obtain access to contents of
potentially sensitive files. Reportedly, by appending the '+' character,
Abyss Web Server will disclose the contents of some files to remote
attackers.
It has been reported possible to exploit this vulnerability to view the
contents of '.chl' files used for remote administration of the server. It
may be possible to view the contents of other executable files intended to
serve CGI requests. This has not, however, been confirmed.
This vulnerability has been reported for Abyss Web Server 1.0.3. It is not
known whether other versions are affected.
55. LG LR Series Router IP Packet Flags Denial of Service Vulnerability
BugTraq ID: 5550
Remote: Yes
Date Published: Aug 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5550
Summary:
The LR series WAN routers are hardware and firmware solutions manufactured
and distributed by LG Electronics.
A problem with the router may make it possible for a remote user to deny
service to legitimate users of the router.
It has been reported that scanning some LG routers using various IP flags
can cause the router to become unstable. When the router is scanned with
a tool such as nmap, and the fingerprinting option is enabled, the router
may crash.
This problem has been reported in the LR3100p, and may be present in other
versions. This issue could be exploited to deny service to legitimate
users of the router.
56. D-Link Remote Administration Arbitrary DHCP Address Release Vulnerability
BugTraq ID: 5544
Remote: Yes
Date Published: Aug 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5544
Summary:
The DI-804 is a hardware gateway and firewall solution distributed and
maintained by D-Link.
A problem with the DI-804 could make it possible for a remote user to deny
service to legitimate users of the device.
It has been reported that a problem with the remote administration
interface could allow for the release of DHCP allocated addresses. When
remote administration is enabled, insufficient access control is allegedly
placed on the /release.html page. This page is used to manipulate DHCP
allocated addresses, and could be used to revoke leases on assigned
addresses.
This problem makes it possible for a remote user to access the DHCP
address release page, and release arbitrary DHCP assigned addresses. It
should be noted that this vulnerability is only capable of being exploited
when the web administration interface is enabled.
57. Caldera UnixWare/Open Unix NDCFG Buffer Overflow Vulnerability
BugTraq ID: 5551
Remote: No
Date Published: Aug 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5551
Summary:
Caldera UnixWare and Open Unix ship with a utility called ndcfg, which is
used for installation, configuration and maintenance of network drivers.
This utility is prone to an exploitable buffer overflow condition. The
condition is due to insufficient bounds checking of input supplied via the
command line when the utility is invoked. It is possible for local
attackers to invoke the utility with malformed command line parameters and
potentially corrupt process memory with attacker-supplied data. If memory
such as stack variables can be overwritten with attacker-supplied data,
this may be exploited to execute arbitrary instructions.
When ndcfg is executed, the utility is reported to raise privileges using
the security subsystem. Therefore it may be exploited by an attacker to
execute code with elevated privileges.
Other components are also known to routinely invoke the vulnerable
utility.
58. Achieva Remote File Include Command Execution Vulnerability
BugTraq ID: 5552
Remote: Yes
Date Published: Aug 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5552
Summary:
Achieva is web-based project management software. It is implemented in
PHP.
Achieva is prone to a remote file include vulnerability which may enable a
remote attacker to execute arbitrary commands on a system hosting the
software.
Achieva includes a PHP script which is used to generate JavaScript
(class.atkdateattribute.js.php). This script employs a number of PHP
include_once() statements to call code contained in function libraries and
grab configuration information. Attackers may subvert the variable
($config_atkroot) which is used to store the location of the external
files and specify an arbitrary location, such as an attacker-supplied PHP
script on a remote host. This may be accomplished via a web request for
the script with maliciously formatted parameters which specify a path to a
remote attacker-supplied script.
Exploitation of this issue will enable the remote attacker to execute
commands with the privileges of the webserver hosting the vulnerable
software.
59. Microsoft TSAC ActiveX Control Buffer Overflow Vulnerability
BugTraq ID: 5554
Remote: Yes
Date Published: Aug 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5554
Summary:
Microsoft offers Terminal Services client functionality over the web
through the Terminal Services Advanced Client (TSAC) ActiveX control. It
is an optional component that can be installed by end-users.
A buffer overflow vulnerability has been reported in the TSAC control.
The condition occurs when the invoking parameters are of excessive length.
This may be exploited by remote attackers to execute arbitrary
instructions on the affected client host.
As ActiveX objects are invoked through HTML, exploitation may occur if
victims visit malicious websites. Attacks through malicious HTML e-mail
may also be possible if the victim is using versions of Outlook and
Outlook Express prior to 2002 and 6.0 respectively, without having added
the Outlook Email Security Update.
The TSAC control is not shipped with Windows or MSIE by default. It is an
optional component that may be added if a client connects to a webserver
with Terminal Services. To determine if the control is present,
users/administrators should open MSIE and perform the following
operations:
- select the "Tools" menu-bar option
- select "Internet Options"
- click on the "General" tab
- click on "Settings"
- click on "View Objects"
Check the list for the following program files:
"Microsoft Terminal Services Client Control"
"Microsoft RDP Client Control"
If they are not present, the control is not installed.
If they are present, right click on them and view their
properties. If the following IDs are listed, a vulnerable version
of the TSAC control is installed:
{1fb464c8-09bb-4017-a2f5-eb742f04392f}
{791fa017-2de3-492e-acc5-53c67a2b94d0}
Servers hosting the TSAC control should install the patch to ensure that
vulnerable versions are not installed by users.
60. Microsoft Network Share Provider SMB Request Buffer Overflow Vulnerability
BugTraq ID: 5556
Remote: Yes
Date Published: Aug 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5556
Summary:
Microsoft Windows operating systems use the Server Message Block (SMB)
protocol to support services such as file and printer sharing. A buffer
overflow vulnerability has been reporting in the handling of some
malformed SMB requests.
A remote attacker able to connect to a vulnerable system may send a
specially constructed SMB request packet in order to exploit this
vulnerability. Maliciously formatted packets requesting the
NetServerEnum2, NetServerEnum3 or NetShareEnum transaction, may corrupt
heap memory, causing the system to crash. A reboot is required in order to
regain normal functionality.
This problem occurs when messages are received with the fields 'Max Param
Count' or 'Max Data Count' set to zero. In both cases, insufficient heap
memory is allocated to store some data from the packet. This error leads
to the eventual corruption of control data used for adjacent blocks of
heap memory. In turn, heap manipulation functions will be led to access
invalid memory locations, causing the system to crash.
Due to the nature of this vulnerability, it is possible that careful
exploitation could lead to the execution of arbitrary code. In this case,
an attacker may gain local access to the vulnerable system, possibly with
privileges. However, the ability to execute arbitrary code through
exploitation of this issue has not yet been confirmed.
This vulnerability may be exploited both as an authenticated user, and
with anonymous access to the service. Reportedly, anonymous access is
enabled by default on some systems.
61. D-Link Remote Administration Information Leakage Vulnerability
BugTraq ID: 5553
Remote: Yes
Date Published: Aug 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5553
Summary:
The DI-804 is a hardware gateway and firewall solution distributed and
maintained by D-Link.
A problem with the DI-804 could make it possible for a remote user to gain
sensitive information about the device.
It has been reported that a problem with the remote administration
interface could allow users to gain sensitive information. It is possible
to access to the Device information and Device status pages. These pages
contain information such as the WAN IP, netmask, name server information,
DHCP log, and MAC address to IP address mappings.
This could allow an attacker to gain sensitive information, and result in
an organized attack on network resources.
62. Multiple Microsoft Internet Explorer Vulnerabilities
BugTraq ID: 5557
Remote: Yes
Date Published: Aug 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5557
Summary:
Microsoft has released a security bulletin describing multiple
vulnerabilities in Internet Explorer 5.01, 5.5 and 6.0.
The first issue is a buffer overflow in the Gopher protocol handler.
This vulnerability was previously alerted on and is described in further
detail in Bugtraq ID 4930 "Multiple Microsoft Product Gopher Client Buffer
Overflow Vulnerability". Exploitation will allow arbitrary code to be
executed with the privileges that the affected product is run with.
The second issue is described to be a buffer overflow in an ActiveX
component used to display specially formatted text. This issue in the
Legacy Text Formatting component may enable a remote attacker to execute
code on a client system with the privileges of the user running the
affected client. The vulnerable component is reportedly not installed by
default in current versions of Internet Explorer and was removed from the
Microsoft website when the vendor first learned of the issue.
The third issue reportedly allows a remote attacker to exploit the browser
to read XML data that is located in a known location. The source of the
issue is apparently due to how Internet Explorer handles HTTP redirects.
An attacker may exploit this issue via a malicious webpage that redirects
the browser to access resources on the local filesystem of the client
machine.
The fourth issue is in how Internet Explorer displays download dialogues
to users. It is possible to exploit this condition to misrepresent the
source of a file being downloaded to appear as though it is coming from a
trusted source, when in fact it originates from an untrusted source. The
user must still interactively execute the file that was misrepresented via
the download dialogue.
The fifth issue appears to be an issue that was previously alerted on.
Further details can be found in the vulnerability record Bugtraq ID 5196
"Microsoft Internet Explorer OBJECT Tag Same Origin Policy Violation
Vulnerability". This may allow remote attackers to gain unauthorized
access to local resources on client systems and perform actions such as
the execution of local binaries. The attacker would not be able to pass
parameters to local executables invoked in this manner. The attacker must
know the name and location of the local resource to exploit this issue.
The sixth issue is a variant of the issue described in Microsoft Security
Bulletin MS02-023 and Bugtraq ID 4754 Microsoft Internet Explorer Cookie
Content Disclosure Vulnerability. It may potentially allow an attacker to
cause malicious script code and HTML to execute with the relaxed
restrictions associated with the Local Computer Zone.
** At the earliest possible convenience, this record will be divided up
into new vulnerability records where it is appropriate. Existing records
will also be updated to reflect the information contained in the Microsoft
Security Bulletin.
63. Light Channel Name Arbitrary Command Execution Vulnerability
BugTraq ID: 5555
Remote: Yes
Date Published: Aug 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5555
Summary:
Light is a freely available, open source IRC script for the EPIC IRC
client. It is available for Unix, Linux, and Windows platforms.
Light contains a vulnerability which may allow the execution of arbitrary
code.
It has been discovered that Light does not properly handle some channel
names. A channel containing embedded code in the channel name would, when
joined by a user of Light, result in the execution of the code in the
channel name. This could allow an attacker to gain access to a system in
the security context of the Light user.
III. SECURITYFOCUS NEWS AND COMMENTARY
------------------------------------------
1. Sprint Security Faulted in Vegas Hacks
By Kevin Poulsen
Citing the "compelling, credible testimony" of ex-hacker Kevin Mitnick,
state officials urged Nevada regulators to force a series of dramatic
security reforms on Las Vegas telephone company Sprint of Nevada last
week, as final arguments were filed in the case of an in-room adult
entertainment operator who believes he's being driven out of business by
phone hackers.
http://online.securityfocus.com/news/587
2. Microsoft in summer patch frenzy
By John Leyden, The Register
Microsoft yesterday issued a cumulative patch for Internet Explorer - the
fixes to no less than six newly discovered vulnerabilities.
http://online.securityfocus.com/news/591
3. Worm spreads through KaZaA network, again
By John Leyden, The Register
Virus watchers have discovered the latest in a line of viruses targeted at
file sharing networks.
http://online.securityfocus.com/news/590
4. UK's DMCA: there ain't no sanity clause
By Andrew Orlowski, The Register
The UK's take on the "European DMCA" - the European Copyright Directive -
will make criminals out of ordinary computer users, according to a new
critique by the UK Campaign for Digital Rights. And it will also fail to
protect researchers, says Julian Midgley who penned the report.
http://online.securityfocus.com/news/589
IV.SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. ClarkConnect Internet Gateway v1.1
by Peter Baldwin
Relevant URL:
http://www.clarkconnect.org/download/
Platforms: Linux
Summary:
ClarkConnect is a software package that transforms an old beat up PC into
a smart, simple, and secure Internet gateway and server for your home or
small office network. In addition to connection sharing, the software
comes with a strong firewall, Apache, dynamic DNS utilities, and Samba
filesharing. The software is based on Red Hat Linux.
2. lcrzoex v4.11
by Laurent Constantin
Relevant URL:
http://www.laurentconstantin.com/en/lcrzoex/
Platforms: FreeBSD, Linux, OpenBSD, Solaris, Windows 2000, Windows 95/98,
Windows NT, Windows XP
Summary:
Lcrzoex is a toolbox for network administrators and network hackers.
Lcrzoex contains over 300 functionnalities using network library lcrzo.
Each one can be compiled alone and modified to match your needs.
Lcrzoex can be used in the following contexts :
- discover the Ethernet address of a computer (number 2, 3, 134, etc.)
- sniff your LAN to detect what's going on (number 7, 8, 9, etc.)
- check the checksums created by a network program which isn't working
(number 16, 17, 18, etc.)
- intercept a session and replay it as many times you want to strictly
test your application (number 10, 11, 12, 22, etc.)
- verify if a router is well configured even if the needed computers are
down (number 48, ..., 53, etc.)
- check if your router/firewall/computer blocks
- IP protocols (number 29, ..., 34, etc.)
- IP options (number 29, ..., 34, 73, ..., 79, etc.), source routing
(number 45, 56, 59, 62, etc.)
- IP fragments (number 44, 55, 58, 61, 72, etc.)
- TCP options (number 48, ..., 53, etc.)
- ICMP types (number 65, ..., 70, etc.)
- ARP poisoning (number 80, 81, 82, 83, etc.)
- create a tcp/udp client with a special local port (number 85, 89, 86,
93, 97, etc.)
- convert between numbers (number 139, ..., 148, etc.) - etc.
3. Lcrzo v4.12
by Laurent Constantin
Relevant URL:
http://www.laurentconstantin.com/en/lcrzo/download/v4/
Platforms: FreeBSD, Linux, OpenBSD, Solaris, Windows 2000, Windows 95/98,
Windows NT, Windows XP
Summary:
Network library lcrzo to sniff, spoof, create decode and display packets,
convert adresses, create clients and servers, etc.
4. rssh v0.9.1
by pizzacoder
Relevant URL:
http://www.pizzashack.org/rssh/
Platforms: POSIX
Summary:
rssh is a small shell that provides the ability for system administrators
to give specific users access to a given system via scp or sftp only.
5. ProSum 0.2b (Development) v0.2b
by fkt
Relevant URL:
http://prosum.sourceforge.net
Platforms: FreeBSD, Linux, NetBSD, OpenBSD, Solaris, SunOS
Summary:
ProSum is a terminal based program that protects your files,
sys_call_table, and IDT in a Tripwire-like way (all in user space, without
kernel modules). In addition, a database with files could be encrypted
with the Blowfish algorythm, and files that are protected could be store
at any secure/bastion host to later replace them. You can disable
sys_call_table and IDT support for non-Linux systems. ProSum can run on
any UNIX system with file protect mode (without IDT and sys_call_table
support).
6. squidview v0.30
by Graeme Sheppard
Relevant URL:
http://www.rillion.net/squidview/
Platforms: Linux, POSIX
Summary:
Squidview is an interactive console program which monitors squid logs and
displays them in a nice fashion. It has searching and reporting functions,
giving information like per user bandwidth and cache hits.
V. SECURITY JOBS SUMMARY
------------------------
1. Anti-Virus Software Sales Manager (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/288492
2. Enterprise Level Network Security Gurus (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/288485
3. Security Consultants Needed in Washington DC (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/288487
4. Resume (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/288494
5. (job offered) Principal Consultant/Security Evangelist in Seattle, Washington (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/288483
6. Information Systems Security Officer for AT&T (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/288498
7. ISSE Opening Available in sunny Orlando Florida (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/288406
8. INFOSEC positions in Reston, VA. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/288404
9. Sr. Security Consultants (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/288407
10. CTO - Security - Silicon Valley - CA (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/288403
11. Looking for a Job. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/288389
12. Senior Security Consultant Opening at Sygate Technologies Inc (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/288326
13. INFOSEC Jobs Available Now (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/288252
14. Re[2]: Sr. Security Consultants (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/288256
15. Resume - Information Systems Security Professional (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/288255
16. Southern California TRW InfoSec positions (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/288113
VI. INCIDENTS LIST SUMMARY
--------------------------
1. looking for what? portscan 15000/tcp (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/288899
2. BAD TRAFFIC 0 ttl (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/288877
3. Unicode worm? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/288821
4. Increased IIS scans mainly on 66.0.0.0/8 - Update (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/288231
5. AOL "proxy" behavior? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/288244
6. (moderator can kill thread) AOL "proxy" behavior? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/288246
VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. More on Shatter (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288975
2. Apache-Nosejob (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288891
3. Lotus Sametime issues? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288889
4. [Full-Disclosure] Lotus Sametime issues? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288890
5. exploiting printers, home routers & smb routers (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288797
6. exploiting printers, home routers & smb routers (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288747
7. FreeBSD System Call Signed Integer Buffer Overflow Vulnerability (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288748
8. Follow up:Apache Nosejob (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288707
9. Exploiting cross-domain scripting vulnerabilities? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288565
10. Apache Tomcat 4.1 Cross-Site Scripting Vulnerability (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288509
11. [[email protected]: [[email protected]: Defcon Phenoelit stuff (Cisco & HP)]] (fwd) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288218
12. Normal Web Surfers In Extreme Danger (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288217
13. killer k00kie [was SILLY BEHAVIOR : Internet Explorer 5.5 - 6.0] (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288239
14. Administrivia: Greetings (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288142
15. ex-Administrivia (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288100
16. IE without Images (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288023
17. Operation TIPS (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288031
VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. MS02-042 Patch on win2k pro kills capability to map to default shares (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/288697
2. info MBSA and patch (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/288703
3. Windows File Sharing with IPCop (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/288698
4. Force user login after 15 minutes of idle time w/o using a screen saver (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/288427
5. Force user login after 15 minutes of idle time w/o using a screen saver (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/288426
6. Force user login after 15 minutes of idle time w/o using a sc reen saver (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/288410
7. Force user login after 15 minutes of idle time w/o using a screen saver (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/288394
8. Outlook2000-Security-Settings (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/288398
9. Window XP login (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/288257
10. Windows 2000 SP3 (security) problems (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/288233
11. SP3 Problems? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/288232
12. Windows Update for XP (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/288134
13. SecurityFocus Microsoft Newsletter #100 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/288117
IX. SUN FOCUS LIST SUMMARY
----------------------------
1. Solaris NIS+ and Password Aging (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/288751
2. which process bind some port (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/288614
3. Hardening NIS+ (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/288610
4. Solstice Security Manager (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/288607
5. New SecurityFocus Lists! (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/288093
6. There's something about hardening NFS? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/288088
X. LINUX FOCUS LIST SUMMARY
---------------------------
1. New SecurityFocus Lists! (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/288099
XI. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored By: AirDefense, Inc.
***HACK-PROOF YOUR WIRELESS LAN - FREE WLAN SECURITY SEMINAR***
AirDefense brings a WLAN security seminar to your city. Learn the latest
techniques & tools to fortify your WLAN. Topics include:
* WLAN Security Challenges & Vulnerabilities
* Live Hack & Attack Demonstrations
* Practical Actions to Secure Your WLAN.
REGISTER NOW! http://www.airdefense.net/securityfocus/secfseminar.shtm
-------------------------------------------------------------------------------