SecurityFocus Newsletter #160
John Boletta <[email protected]> Wed, 4 Sep 2002 08:55:04 -0600 (MDT)
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #160
-----------------------------
This Issue Is Sponsored By: SpiDynamics
Aberdeen Alert! FREE Research Report on Web App Attacks Using ports 80 and
443 as expressways through network firewalls, hackers are free to probe
and breach web applications! 75% of today's successful system hacks
involve Web Application vulnerabilities, not network security flaws.
Download this FREE Aberdeen Research Report!
http://www.spidynamics.com/mktg/aberdeen21/
-------------------------------------------------------------------------------
I. FRONT AND CENTER
1. Configuring IPSec and Ike on Solaris, Part Two
2. Justifying the Expense of IDS, Part Two: Calculating ROI for IDS
3. Lobbying for Insecurity
4. When Feds are the Crackers
5. SecurityFocus DPP Program
6. InforwarCon 2002
II. BUGTRAQ SUMMARY
1. Microsoft Internet Explorer Download Dialogue File Source...
2. Microsoft Internet Explorer XML Redirect File Disclosure...
3. PHP Mail Function ASCII Control Character Header Spoofing...
4. Mantis Unauthorized Bug Viewing Vulnerability
5. UTStarcom BAS-1000 Default User Accounts Vulnerability
6. Mantis Unauthorized Project Bug List Viewing Vulnerability
7. Blazix Special Character Handling Server Side Script...
8. Blazix Password Protected Directory Information Disclosure...
9. OmniHTTPD Sample Scripts Cross Site Scripting Vulnerabilities
10. PHPReactor Style Attribute HTML Injection Vulnerability
11. Kerio Personal Firewall Multiple SYN Packet Denial Of Service...
12. Belkin F5D6130 Wireless Network Access Point SNMP Request...
13. OmniHTTPD Sample Application URL Encoded Newline HTML...
14. Gaim Manual Browser Command Arbitrary Command Execution...
15. mIRC Scripting ASCTime Buffer Overflow Vulnerability
17. Caldera X Server Unspecified Buffer Overflow Vulnerability
18. GDAM123 Filename Buffer Overflow Vulnerability
20. Ultimate PHP Board Second 'admin' Account Vulnerability
21. Python os.py Predictable Temporary Filename Command Execution...
III. SECURITYFOCUS NEWS ARTICLES
1. Lamo Bumped from NBC After Hacking Them
2. Ziff pays $125K to settle security breach
3. Spyware Trojan sends Hotmail to your boss
4. MS in fresh digital cert flaw
IV. SECURITYFOCUS TOP 6 TOOLS
1. checkpassword-ldap v0.1
2. Prelude Log Monitoring Lackey v 0.8.1
3. batemail v0.8.6
4. GPGME 0.3.9 v0.3.9
5. iptables-control v1.0.3
6. l0stat v1.1
V. SECURITYJOBS LIST SUMMARY
1. Security Career Opportunities in Chicago Area (Thread)
2. Enterprise Security Software Sales (Thread)
3. Security Training Manager - Austin, TX (Thread)
4. Resume ( to work as Security Analyst trainee in Brazil ) (Thread)
5. Need a Java developer with an internet secuirty background in...
6. INFOSEC Engineer/Digital Forensics Engineer - looking for...
7. Security Analyst (Thread)
8. Management Security Consultants wanted in Germany and Holland (Thread)
9. In need of middleware engineers (Thread)
10. Security Engineer looking for work DFW, Texas or other US...
11. Security Lab Administrator Position in Washington DC (Thread)
12. Nortel Contivity/VPN technologies needed DC metro area (Thread)
13. Actively seeking employment (Thread)
14. Security/Forensic Analyst looking for relocation (Thread)
15. Network Security Support Specialist (Thread)
16. Information Assurance Analyst position in Falls Church, VA...
17. Potential Opportunities in MD (Thread)
18. Firewall Security Engineer position available in sunny Orlando...
VI. INCIDENTS LIST SUMMARY
1. What's going on here? (Thread)
2. [incidents] Bots hitting my web server? (Thread)
3. Bots hitting my web server? (Thread)
4. 2002/udp flood (Thread)
5. Trojan? DDOS Bot? (Thread)
6. Anyone seen this? (Thread)
7. TCP 6129 - Dameware, TCP 17890 IIS.EXE, SVR1984.exe - Team...
8. SMB overflow attacks (Thread)
9. looking for what? portscan 15000/tcp (Thread)
10. BAD TRAFFIC 0 ttl (Thread)
11. Unicode worm? (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
1. SUMMARY: SMB overflow attacks (Thread)
2. Secure Yahoo logins (Thread)
3. Windows SMB DoS - Proof of concept (Thread)
4. MS API Releases (Thread)
5. More on Shatter (Thread)
6. SMB overflow attacks (Thread)
7. killer k00kie [was Re: SILLY BEHAVIOR : Internet Explorer 5.5...
8. Apache-Nosejob (Thread)
9. Lotus Sametime issues? (Thread)
10. [Full-Disclosure] Lotus Sametime issues? (Thread)
11. exploiting printers, home routers & smb routers (Thread)
12. exploiting printers, home routers & smb routers (Thread)
13. FreeBSD System Call Signed Integer Buffer Overflow...
14. ToorCon Computer Security Conference 2002 Announcement (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
1. IIS and Frontpage Extensions Vulnerability. (Thread)
2. SecureIIS (Thread)
3. Internet Explore lock up software! (Thread)
4. MS02-042 Patch on win2k pro kills capability to map to defaul...
5. Password Change Utility (Thread)
6. MS02-042 Patch on win2k pro kills capability to map to default...
7. SecurityFocus Microsoft Newsletter #101 (Thread)
8. MS02-042 Patch on win2k pro kills capability to map to default...
IX. SUN FOCUS LIST SUMMARY
1. which process bind some port (Thread)
X. LINUX FOCUS LIST SUMMARY
1. MD5 checksum's for Redhat 7.3 binaries? (Thread)
2. Who: No users logged (Thread)
3. Who: No users logged [Solved] (Thread)
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. Configuring IPSec and Ike on Solaris, Part Two
By Ido Dubrawsky
This article is the second in a three-part series devoted to configuring
IPsec and IKE for Solaris. The first installment of this series covered
the underlying IPsec protocols as well as how the Internet Key Exchange
(IKE) works. This installment covers configuring IPsec to protect the
traffic between two Solaris hosts.
http://online.securityfocus.com/infocus/1625
2. Justifying the Expense of IDS, Part Two: Calculating ROI for IDS
by David Kinn and Kevin Timm
This article is the second of a two-part series exploring ways to justify
the financial investment in IDS protection. In part one of this series we
discussed general IDS types and expanded on the impact that the logical
location of a company's critical networked assets could have on the risk
equations. To this end we introduced the Cascading Threat Multiplier (CTM)
to expand on the Single Loss Expectancy (SLE) equation. We also reviewed
implementation and management costs based on various support profiles and
reviewed the commonly accepted risk equations. Finally, we left off with
the basic formula for calculating ROI for security, otherwise commonly
known as Return on Security Investment (ROSI).
http://online.securityfocus.com/infocus/1621
3. Lobbying for Insecurity
By Jon Lasser
The NSA's Linux security project was so good it almost made up for that
whole Echelon thing. Then politics entered the picture.
http://online.securityfocus.com/columnists/106
4. When Feds are the Crackers
By Mark Rasch
In medieval times, attackers would use a bell-shaped metal grenade or
"petard" to break enemy defenses. These unreliable devices frequently went
off unexpectedly, destroying not only the enemy, but the attacker. As
Shakespeare noted, "'tis the sport to have the enginer Hoist with his owne
petar."
http://online.securityfocus.com/columnists/105
5. SecurityFocus DPP Program
Attention Non-profit Organizations and Universities!! Sign-up now for
preferred pricing on the only global early-warning system for cyber
attacks - SecurityFocus DeepSight Threat Management System.
Click here for more information:
http://www.securityfocus.com/corporate/products/dpsection.shtml
6. InforwarCon 2002
InforwarCon 2002: Homeland Defense and Cyber-Terrorism, Washington, DC
September 4-5, 2002, optional workshops September 3 & 6. Presented by MIS
Training Institute and Interpact, Inc. Proven strategies for protecting
against threats to critical infrastructures and government systems.
Visit us at:
http://www.misti.com/08/iw02nl26inf.html
II. BUGTRAQ SUMMARY
-------------------
1. Microsoft Internet Explorer Download Dialogue File Source Obfuscation Vulnerability
BugTraq ID: 5559
Remote: Yes
Date Published: Aug 23 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5559
Summary:
A vulnerability has been reported for Microsoft Internet Explorer in how
download dialogues are displayed to users. This issue affects Microsoft
Internet Explorer 5.0.1 to 6.0.
Reportedly, Internet Explorer may misrepresent the origin of a file in the
File Download Dialogue box. An attacker can exploit this flaw to trick
unsuspecting users into downloading a file from a supposedly trusted
source when, in fact, it may originate from an attacker controlled source.
The vulnerability is the result of Internet Explorer failing to process
malformed URL links when displaying information in a File Download
Dialogue box. If the Internet Explorer File Download dialogue encounters
certain special characters, it will not be able to display the proper
download location.
An attacker exploiting this flaw may create a false sense of trust which
results in the victim user downloading and installing files that originate
from an untrustworthy source. The user must still interactively download
and execute the misrepresented file.
This issue was originally described in BID 5557, Multiple Microsoft
Internet Explorer Vulnerabilities, and is now being assigned its own
BugTraq ID.
2. Microsoft Internet Explorer XML Redirect File Disclosure Vulnerability
BugTraq ID: 5560
Remote: Yes
Date Published: Aug 23 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5560
Summary:
A flaw in Microsoft Internet Explorer may reveal the entire contents of
XML files and partial contents of other files to attackers . This issue
affects Microsoft Internet Explorer 5.0.1 to 6.0.
This vulnerability allows an attacker to read the entire contents of XML
files, and fragments of other files, existing in a known location, from a
victim user's system.
This vulnerability is due to Internet Explorer improperly handling an HTML
directive to display XML data. The directive is not correctly checked to
ensure that a referenced XML data source is not redirected to a data
source in a different domain. By using the <script> tag and assigning a
URL to the "src" attribute, to redirect the HTTP request a local or remote
location, will result in the XML engine processing and displaying the
contents of that location.
This vulnerability can be exploited via a malicious webpage or via
malicious HTML e-mail. Other applications that use the Internet Explorer
engine are affected as well (Outlook, MSN Explorer, etc.).
This issue was originally described in BID 5557, Multiple Microsoft
Internet Explorer Vulnerabilities, and is now being assigned its own
BugTraq ID.
3. PHP Mail Function ASCII Control Character Header Spoofing Vulnerability
BugTraq ID: 5562
Remote: Yes
Date Published: Aug 23 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5562
Summary:
PHP is the Personal HomePage development toolkit, distributed by the
PHP.net, and maintained by the PHP Development Team in public domain.
A problem in PHP could lead to users sending email with spoofed headers.
The PHP mail function does not properly sanitize user input. Because of
this, a user may pass ASCII control characters to the mail() function that
could alter the headers of email. This could result in spoofed mail
headers. This is an issue in cases where scripts accept user-supplied
input which is passed through the function.
This problem could be exploited by spammers as a means of sending email
from obscure origins.
4. Mantis Unauthorized Bug Viewing Vulnerability
BugTraq ID: 5563
Remote: Yes
Date Published: Aug 23 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5563
Summary:
Mantis is a web-based bug tracking system. It is written in PHP and
back-ended by a MySQL database.
Mantis suffers from a security issue which may allow malicious users of
the system to view arbitrary bugs. Normally, users are only able to view
bugs for which they have adequate protection.
A number of scripts used to view bug data do not check user permissions.
Users may directly call these scripts, and specify arbitrary bug IDs
through CGI parameters.
This error has been reported in the scripts view_bug_page.php,
view_bug_advanced_page.php, bug_update_page.php and
bug_update_advanced_page.php.
Exploitation of this issue may result in the disclosure of sensitive
information
5. UTStarcom BAS-1000 Default User Accounts Vulnerability
BugTraq ID: 5564
Remote: Yes
Date Published: Aug 23 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5564
Summary:
The BAS-1000 is a unified subscriber management solution designed
distributed by UTStarcom.
A problem with the firmware of this device may allow unauthorized access
to affected systems.
It has been discovered that the firmware for the BAS-1000 includes four
accounts with default passwords. Two of these accounts, the guru and
field account, give users privileges equal to or greater than that of the
manager of the system. The system also includes accounts for an snmp
user, and dbase user.
The following default account and password combinations are used:
User Password
field *field
guru *3noguru
snmp snmp
dbase dbase
These accounts may allow a remote user to gain administrative access to a
vulnerable system.
6. Mantis Unauthorized Project Bug List Viewing Vulnerability
BugTraq ID: 5565
Remote: Yes
Date Published: Aug 23 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5565
Summary:
Mantis is a web-based bug tracking system. It is written in PHP and
back-ended by a MySQL database.
Mantis is prone to an issue which may allow malicious users of the bug
tracking system to gain unauthorized access to restricted projects. This
may be a security concern in organizations that use the software to
restrict viewing rights of bugs to some users.
A user who does not have permissions to view any projects will be able to
view bugs from all public and private projects on the 'View Bugs' page.
A malicious user who happens to have no permissions may be able to exploit
this issue to view summary information on arbitrary bugs in the system. It
will not, however, be possible to view full details on bugs through
exploitation of this issue.
7. Blazix Special Character Handling Server Side Script Information Disclosure Vulnerability
BugTraq ID: 5566
Remote: Yes
Date Published: Aug 24 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5566
Summary:
Blazix is a freely available, open source web server written in Java. It
is available for Linux and Microsoft Windows operating systems.
A problem with Blazix may make it possible for a remote user to gain
access to sensitive information.
Blazix does not properly handle some special characters when appended to
requests. By passing a special character with a request to the web
server, it is possible for a user to gain access to the source of
server-side scripts. This could result in information disclosure, and
could potentially be used to gain intelligence in launching an attack
against a system.
When a user passes a request to the web server that ends in either a plus
(+) or backslash (\), the web server may react unpredictably. This type
of character appended to the name of a .jsp file has been reported to
reveal the contents of the .jsp file.
8. Blazix Password Protected Directory Information Disclosure Vulnerability
BugTraq ID: 5567
Remote: Yes
Date Published: Aug 25 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5567
Summary:
Blazix is a freely available, open source web server written in Java. It
is available for Linux and Microsoft Windows operating systems.
A problem with Blazix may make it possible for a remote user to gain
access to sensitive information.
Blazix does not properly handle some special characters when appended to
requests. By passing a special character with a request to the web
server, it is possible for a user to gain access to a listing of a
password protected directory. This could result in information
disclosure, and could potentially be used to gain intelligence in
launching an attack against a system.
When a user passes a request to the web server that ends in either a plus
(+) or backslash (\), the web server may react unpredictably. This type
of character appended to the name of a password-protected directory has
been reported to reveal the contents of the directory.
9. OmniHTTPD Sample Scripts Cross Site Scripting Vulnerabilities
BugTraq ID: 5568
Remote: Yes
Date Published: Aug 26 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5568
Summary:
OmniHTTPD is a webserver for Microsoft Windows operating systems.
OmniHTTPD supports a number of extensions which provide dynamic content,
including server side includes (SSI) and PHP CGI scripts.
Cross site scripting vulnerabilities have been reported in multiple sample
scripts including with OmniHTTPD. In particular, test.shtml and test.php
contain errors.
An attacker may exploit this vulnerability by causing a victim user to
follow a malicious link to one of the vulnerable scripts.
Attacker-supplied code may execute within the context of the site hosting
the vulnerable software when the malicious link is visited.
This type of vulnerability may be used to steal cookies or perform other
web-based attacks.
10. PHPReactor Style Attribute HTML Injection Vulnerability
BugTraq ID: 5569
Remote: Yes
Date Published: Aug 24 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5569
Summary:
php(Reactor) is an integrated system of web applications designed for
website maintenance. It will run on most Linux and Unix variants, in
addition to Microsoft Windows operating systems.
php(Reactor) does not sufficiently sanitize HTML from various fields (such
as in the body of a message or in profile fields). It is possible to
inject arbitrary HTML and script code into these fields. In particular,
the "STYLE" attribute in an arbitrary HTML tag is not properly sanitized.
Arbitrary HTML and script code injected in this manner will be displayed
to other users who visit the vulnerable website.
An attacker may potentially exploit this situation to cause arbitrary HTML
and script code to execute in the web client of a user of a vulnerable
website. The attacker-supplied code will execute in the context of the
vulnerable website.
11. Kerio Personal Firewall Multiple SYN Packet Denial Of Service Vulnerability
BugTraq ID: 5570
Remote: Yes
Date Published: Aug 26 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5570
Summary:
Kerio Personal Firewall (KPF) is a personal firewall product for the
Microsoft Windows operating system.
A denial of service vulnerability has been reported in some versions of
KPF. When a large number of SYN packets are recieved from a single source,
the firewall process will consume all available CPU time, and eventually
hang the vulnerable system. A reboot may be required in order to regain
normal functionality.
Reportedly, this attack is possible regardless of the configured behavior
of the firewall. It has been reported that between 300 and 500 SYN packets
is sufficient to exploit this condition in laboratory conditions.
12. Belkin F5D6130 Wireless Network Access Point SNMP Request Denial Of Service Vulnerability
BugTraq ID: 5571
Remote: Yes
Date Published: Aug 26 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5571
Summary:
A denial of service vulnerability has been reported in the Belkin F5D6130
Wireless Network Access Point.
Reportedly, this issue may be exploited by making a sequence of SNMP
requests. A valid community name is not required. The device will respond
to each request by broadcasting at least one SNMP trap.
If a number of SNMP requests are made, the device will fail to respond to
further requests. Additionally, all wireless connections will be dropped,
and new connections refused, denying service to legitimate users of the
wireless service.
Under some conditions, the device may also fail to respond on the ethernet
interface, eliminating all means of managing the device. In this case, a
manual restart will be required in order to regain normal functionality.
13. OmniHTTPD Sample Application URL Encoded Newline HTML Injection Vulnerability
BugTraq ID: 5572
Remote: Yes
Date Published: Aug 26 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5572
Summary:
OmniHTTPD is a webserver for Microsoft Windows operating systems.
OmniHTTPD supports a number of CGI extensions which provide dynamic
content.
Cross site scripting vulnerabilities have been reported in the
'/cgi-bin/redir.exe' sample CGI included with OmniHTTPD. Reportedly, it is
possible for an attacker to URL encode the newline character (%0D) and
insert malicious HTML code. A vulnerable server receiving a malformed
request will return a 302 redirect HTTP response containing the malicious
attacker-supplied code.
An attacker may exploit this vulnerability by causing a victim user to
follow a malicious link to the vulnerable CGI. Attacker-supplied code may
execute within the context of the site hosting the vulnerable software
when the malicious link is visited.
This type of vulnerability may be used to steal cookies or perform other
web-based attacks.
14. Gaim Manual Browser Command Arbitrary Command Execution Vulnerability
BugTraq ID: 5574
Remote: Yes
Date Published: Aug 27 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5574
Summary:
Gaim is an instant messaging client that supports numerous protocols. It
is available for Unix and Linux variant operating systems.
Gaim allows the user to define a 'Manual' browser option. When URL links
are recieved in instant messages, the user is able to click on the link in
order to pass the URL to a specified application.
The URL recieved is not properly sanitized. A malicious instant message
may include a URL with shell metacharacters, such as ';' or '|'. When
passed to the shell command intended to invoke the browser, this
characters will allow additional commands appended to the URL to be
executed.
Commands supplied will execute with the privileges of the user running
Gaim. It is likely that exploitation of this vulnerability could result in
the attacker gaining local access to the vulnerable system.
15. mIRC Scripting ASCTime Buffer Overflow Vulnerability
BugTraq ID: 5576
Remote: Yes
Date Published: Aug 27 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5576
Summary:
mIRC is a chat client for the IRC protocol, designed for Microsoft Windows
based operating systems. mIRC includes support for a scripting language.
A buffer overflow vulnerability has been reported in the $asctime
identifier, a function in the mIRC scripting language. If an oversized
format specifier is passed to this function, process memory will be
corrupted. It has been reported possible to exploit this vulnerability to
execute arbitrary code with the privileges of the user running mIRC.
Exploitation will rely on a script passing untrusted output to the
vulnerable function. Reportedly, default scripts included with mIRC do not
use the $asctime function in a manner which allows exploitation. It is
possible, however, that third party scripts may provide possibilities for
attackers.
16. Caldera X Server External Program Privileged Invocation Weakness
BugTraq ID: 5575
Remote: No
Date Published: Aug 27 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5575
Summary:
Caldera's X Server implementation invokes external commands without
dropping existing privilege levels. A local attacker may be able to
exploit this weakness and use the XServer to invoke programs with elevated
privileges.
This weakness was reported to be present in X11R6.3 based X servers that
have the XKEYBOARD extension enabled. The XKEYBOARD (XKB) extension is
used to bind other keyboard mappings.
This weakness is due to the Xserver not dropping privileges when invoking
'xkbcomp' and other related utilities. It is possible to call Xserver with
the '-xkbdir' option and specify a XKB file. When Xserver is called this
way, it will invoke the 'xkbcomp' utility, which is used to compile XKB
keyboard descriptions.
Xserver calls xkbcomp in an insecure manner, using the popen() or system()
calls. Any shell metacharacters included an the '-xkbdir' option will be
interpreted and executed with the privileges of the xkbcomp utility.
While this would not typically be an issue, as execution of the binary
would typically result in the execution of code in the security context of
the invoking user, the xkbcomp utility is executed by the Xserver process
before privileges are dropped.
This weakness can be exploited by local attacker to execute arbitrary
commands with elevated privileges. It should also be noted that this
weakness could allow the execution of code through other utilities
executed by the Xserver if a vulnerability is present in the applications.
17. Caldera X Server Unspecified Buffer Overflow Vulnerability
BugTraq ID: 5577
Remote: Unknown
Date Published: Aug 27 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5577
Summary:
A buffer overflow vulnerability was reported for Caldera's X Server
implementation.
The nature of this vulnerability is currently unspecified and further
details are not available at this time.
As this vulnerability is reportedly due to a buffer overflow condition, it
is highly possible that attackers may be able to cause Xserver to corrupt
memory and execute malicious attacker supplied code. Any code to be
executed will be executed with the privileges of the Xserver process.
18. GDAM123 Filename Buffer Overflow Vulnerability
BugTraq ID: 5578
Remote: No
Date Published: Aug 24 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5578
Summary:
GDAM123 is a command-line MP3 player supplied with GDAM real-time digital
DJ mixing software package. GDAM is available for Unix and Linux
variants.
The GDAM123 player is prone to a buffer overflow condition when handling
overly long filenames. Filenames are supplied via the command line and
used in a strcpy() operation. It is possible to trigger the overflow by
supplying a filename that is over 1024 bytes in length, which will result
in corruption of stack variables. If stack variables (such as the return
address) can be corrupted with attacker-supplied values, it is possible to
execute arbitrary code.
Under some circumstances, the player may be installed setuid root to allow
unprivileged users to run the player if access to certain devices is
required. In a situation such as this, the buffer overflow may be
exploited to gain elevated privileges via the execution of arbitrary code.
19. Yahoo Instant Messenger Signed Content Weakness
BugTraq ID: 5579
Remote: Yes
Date Published: Aug 27 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5579
Summary:
Yahoo Instant Messenger is an instant messenger client distributed by
Yahoo. It is available for Microsoft Windows sytems.
A weakness has been reported in the Yahoo Instant Messenger installer
where an attacker may use the installer to install malicious software on
the vulnerable system. The Yahoo Instant Messenger Installer uses HTTP,
and though it uses signed content for the installer, does not verify the
signature of packages downloaded from Yahoo.
In order to exploit this weakness, the attacker must control the machine
located at a19.g.a.yimg.com, from the perspective of the vulnerable
client. It may be possible to create this condition through some known
techniques, including DNS cache poisoning and DNS spoofing.
20. Ultimate PHP Board Second 'admin' Account Vulnerability
BugTraq ID: 5580
Remote: Yes
Date Published: Aug 27 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5580
Summary:
Ultimate PHP Board is a freely available, open source PHP bulletin board.
It is available for Unix, Linux, and Microsoft Operating Systems.
Ultimate PHP Board does not prevent the registration of names that could
be potentially confusing to users.
Under some circumstances, it may be possible to register an account that
could be confused with the 'Admin' user of the board. Ultimate PHP Board
does not prevent the registration of the 'admin' account. While the
'admin' account is a regular board member account, and the 'Admin' account
is that of the board administrator, it may be possible for a user to use
the account in a social engineering scenario to impersonate the
administrative user.
21. Python os.py Predictable Temporary Filename Command Execution Vulnerability
BugTraq ID: 5581
Remote: No
Date Published: Aug 28 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5581
Summary:
Python is an open source, object oriented programming language.
It has been reported that some versions of Python create temporary files
in an insecure manner. The vulnerability occurs in the os._execvpe
function found in os.py.
It has been reported that exploitation of this vulnerability could lead to
the execution of arbitrary code.
The nature of this vulnerability is currently unspecified and further
details are not available at this time.
Reportedly, Python 2.3 is not vulnerable to this issue.
III. SECURITYFOCUS NEWS AND COMMENTARY
--------------------------------------
1. Lamo Bumped from NBC After Hacking Them
By Kevin Poulsen, SecurityFocus
The helpful hacker demonstrates his techniques on camera for the NBC
Nightly News, but lawyers kill the story when he cracks the broadcast
network's own systems ...
http://online.securityfocus.com/news/595
2. Ziff pays $125K to settle security breach
By John Leyden, The Register
Publisher Ziff-Davis has agreed to pay $125,000 to settle legal actions
brought after a security breach that exposed customer credit card details
on the Web.
http://online.securityfocus.com/news/601
3. Spyware Trojan sends Hotmail to your boss
By Thomas C. Greene, The Register
Here's a piece of software that will make any decent human being vomit.
Proudly marketed by spyware outfit SpectorSoft, it's a lowlife Trojan
called eBlaster which you can e-mail to anyone in the world foolish enough
to use Windows and log their keystrokes, and force their POP mail and
Hotmail and Yahoo Web mail accounts to copy you in everything going on.
http://online.securityfocus.com/news/600
4. MS in fresh digital cert flaw
By John Leyden, The Register
A flaw in the Windows handles digital certificates enables sophisticated
crackers to get up to all sorts of mischief on unprotected boxes.
http://online.securityfocus.com/news/599
IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. checkpassword-ldap v0.1
by Dan Melomedman [email protected]
Relevant URL:
http://foobarco.net/checkpwd.html
Platforms: FreeBSD, Linux, NetBSD, OpenBSD, UNIX
Summary:
checkpassword-ldap searches a specified LDAP directory with a constructed
LDAP filter from a given prefix, username, and suffix, and fetches an
entry. It then compares a given password with the stored password, and
proceeds to run a program as specified if passwords match.
2. Prelude Log Monitoring Lackey v 0.8.1
by yoann
Relevant URL:
http://www.prelude-ids.org/
Platforms: POSIX
Summary:
The Prelude Log Monitoring Lackey (LML) is the host-based sensor program
part of the Prelude Hybrid IDS suite. It can act as a centralized log
collector for local or remote systems, or as a simple log analyzer (such
as swatch). It can run as a network server listening on a syslog port or
analyze log files. It supports logfiles in the BSD syslog format and is
able to analyze any logfile by using the PCRE library. It can apply
logfile-specific analysis through plugins such as PAX. It can send an
alert to the Prelude Manager when a suspicious log entry is detected.
3. batemail v0.8.6
by Ryan VanMiddlesworth
Relevant URL:
http://batemail.sourceforge.net/
Platforms: POSIX
Summary:
batemail is a Perl script that you slip between your MTA (e.g. Sendmail)
and your local mailer (e.g. Procmail) to strip potentially nasty
attachments from email messages. It takes input on STDIN, removes
executable MIME attachments, and gives the result to the local mailer. The
criteria for a taboo attachment are that the filename ends in one of
several "blacklisted" extensions (EXE, VBS, etc.).
4. GPGME 0.3.9 v0.3.9
by wali
Relevant URL:
http://www.gnupg.org/gpgme.html
Platforms: UNIX
Summary:
GnuPG Made Easy (GPGME) is a library designed to make access to GnuPG
easier for applications. It provides a high-level cryptography API for
encryption, decryption, signing, signature verification, and key
management. It currently uses GnuPG as its backend, but the API is not
restricted to this engine. In fact, support for other backends is planned.
5. iptables-control v1.0.3
by Francesco 'StealthP' [email protected]
Relevant URL:
http://devzone.stealthp.org/iptables-control
Platforms: Linux, POSIX
Summary:
Iptables-Control is a fast and easy iptables filter configurator It
features a step-by-step interactive configurator script, a TCP/UDP ports
configurator, LAN settings for routing and masquerading, and ICMP
filtering.
6. l0stat v1.1
by DLC Sistemas
Relevant URL:
http://www.dlcsistemas.com/html/l0stat.html
Platforms: Windows 2000, Windows 95/98, Windows NT
Summary:
L0stat generates an statistical report of strength of NT accounts and
passwords.
This utility gets the L0phtCrack* result files or the LC3 exported text
results file and treats the data to give the NT or security administrator
a global view of security of their SAM database.
As a way to discover NT passwords, L0phtCrack are LC3 great tools.
But if you don't want to know the passwords themselves but the global
security view of passwords quality, you should go one step beyond. For
example, how you can evaluate the security level of an NT entreprise's
database with 1000 accounts ?
There is the place for L0stat. L0stat doesn't replaces L0phtCrack. L0stat
is a reporting tool of data retrieved with L0phtCrack or LC3.
V. SECURITY JOBS SUMMARY
------------------------
1. Security Career Opportunities in Chicago Area (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/289893
2. Enterprise Security Software Sales (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/289896
3. Security Training Manager - Austin, TX (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/289892
4. Resume ( to work as Security Analyst trainee in Brazil ) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/289676
5. Need a Java developer with an internet secuirty background in DC metro area (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/289674
6. INFOSEC Engineer/Digital Forensics Engineer - looking for position (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/289672
7. Security Analyst (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/289426
8. Management Security Consultants wanted in Germany and Holland (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/289406
9. In need of middleware engineers (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/289403
10. Security Engineer looking for work DFW, Texas or other US cities. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/289273
11. Security Lab Administrator Position in Washington DC (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/289216
12. Nortel Contivity/VPN technologies needed DC metro area (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/289204
13. Actively seeking employment (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/289203
14. Security/Forensic Analyst looking for relocation (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/289215
15. Network Security Support Specialist (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/289217
16. Information Assurance Analyst position in Falls Church, VA (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/289202
17. Potential Opportunities in MD (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/289218
18. Firewall Security Engineer position available in sunny Orlando, FL (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/289214
VI. INCIDENTS LIST SUMMARY
-------------------------
1. What's going on here? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/289815
2. [incidents] Bots hitting my web server? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/289817
3. Bots hitting my web server? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/289799
4. 2002/udp flood (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/289620
5. Trojan? DDOS Bot? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/289614
6. Anyone seen this? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/289461
7. TCP 6129 - Dameware, TCP 17890 IIS.EXE, SVR1984.exe - Team Liquid (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/289428
8. SMB overflow attacks (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/289244
9. looking for what? portscan 15000/tcp (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/288899
10. BAD TRAFFIC 0 ttl (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/288877
11. Unicode worm? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/288821
VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. SUMMARY: SMB overflow attacks (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/289865
2. Secure Yahoo logins (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/289850
3. Windows SMB DoS - Proof of concept (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/289756
4. MS API Releases (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/289763
5. More on Shatter (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/289346
6. SMB overflow attacks (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/289281
7. killer k00kie [was Re: SILLY BEHAVIOR : Internet Explorer 5.5 - 6.0] (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/289034
8. Apache-Nosejob (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288891
9. Lotus Sametime issues? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288889
10. [Full-Disclosure] Lotus Sametime issues? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288890
11. exploiting printers, home routers & smb routers (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288797
12. exploiting printers, home routers & smb routers (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288747
13. FreeBSD System Call Signed Integer Buffer Overflow Vulnerability (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/288748
14. ToorCon Computer Security Conference 2002 Announcement (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/289276
VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. IIS and Frontpage Extensions Vulnerability. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/289791
2. SecureIIS (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/289657
3. Internet Explore lock up software! (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/289440
4. MS02-042 Patch on win2k pro kills capability to map to defaul t sh ares (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/289333
5. Password Change Utility (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/289334
6. MS02-042 Patch on win2k pro kills capability to map to default sh ares (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/289242
7. SecurityFocus Microsoft Newsletter #101 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/289246
8. MS02-042 Patch on win2k pro kills capability to map to default sh ares (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/289172
IX. SUN FOCUS LIST SUMMARY
----------------------------
1. which process bind some port (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/289532
X. LINUX FOCUS LIST SUMMARY
---------------------------
1. MD5 checksum's for Redhat 7.3 binaries? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/289802
2. Who: No users logged (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/289682
3. Who: No users logged [Solved] (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/289422
XI. SPONSOR INFORMATION
-----------------------
This Issue Is Sponsored By: SpiDynamics
Aberdeen Alert! FREE Research Report on Web App Attacks Using ports 80 and
443 as expressways through network firewalls, hackers are free to probe
and breach web applications! 75% of todays successful system hacks
involve Web Application vulnerabilities, not network security flaws.
Download this FREE Aberdeen Research Report!
http://www.spidynamics.com/mktg/aberdeen21/
-------------------------------------------------------------------------------