SecurityFocus Newsletter #139
John Boletta <[email protected]>
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #139
-----------------------------
This newsletter is sponsored by SecurityFocus (www.securityfocus.com)
Attention Non-profits and Universities: Sign-up now for preferred pricing
on the only global early-warning system for cyber attacks - SecurityFocus
ARIS Threat Management System.
Click here for more info
http://www.securityfocus.com/corporate/products/pdpsection.shtml
-------------------------------------------------------------------------------
I. FRONT AND CENTER
1. Managing Intrusion Detection Systems in Large Organizations: One
2. Active Directory and Linux
3. Past its Prime: Is Anti-Virus Scanning Obsolete?
4. Death to Old Software
5. A Mickey Mouse Bill
II. BUGTRAQ SUMMARY
1. Microsoft Internet Explorer Known Local File Script Execution...
2. ZeroForum User-Embedded Scripting Vulnerability
3. Microsoft Outlook 2002 HTML Mail Script Execution Vulnerability
4. Microsoft Office XP Spreadsheet Host().SaveAs() File Creation...
5. Caldera OpenLinux StartKDE Script LD_LIBRARY_PATH Vulnerability
6. OpenBSD PF TTL Fingerprinting Vulnerability
7. IPFilter TTL Fingerprinting Vulnerability
8. Sambar Server Authentication Buffer Overflow Vulnerability
9. Sun Solaris XSun Color Database File Heap Overflow Vulnerability
10. Netware Remote Manager Authentication Buffer Overflow...
11. Lotus Domino MS-DOS Device Path Disclosure Vulnerability
12. ZoneLabs ZoneAlarm MailSafe Extension Dot Filtering Bypass...
13. Cyrus SASL LDAP+MySQL Authentication Patch SQL Command...
14. Microsoft Internet Explorer Cascading Style Sheet File...
15. Oracle 8i TNS Listener Local Command Parameter Buffer Overflow...
III. SECURITYFOCUS NEWS ARTICLES
1. Sentencing Study Probes Hacker Motives
2. Privacy Advocates Sue Homeland Security Office
3. E-Insurance for the Digital Age
4. Getting to the Root of All E-Mail
IV.SECURITYFOCUS TOP 6 TOOLS
1. libdvdcss v1.1.0
2. Anubis v2.0.0b-2
3. Ganglia Cluster Toolkit v2.2.2
4. GNUnet v0.3.3
5. LoFiMo v1.0.1
6. BlackHole Spam/Virus Filter v0.9.58 (Stable)
V. SECURITYJOBS LIST SUMMARY
1. No New Content
VI. INCIDENTS LIST SUMMARY
1. VPN connection attempts to resolvers? (Thread)
2. VPN connection attempts to resolvers? (Thread)
3. Botnet/Domains (Thread)
4. DoS, possibly spoofed IP Addresses (Thread)
5. Unknown Hosts file (Thread)
6. Unknown Hosts file (Thread)
7. DoS, possibly spoofed IP Addresses (Thread)
8. I think I've been hacked...please help! (Thread)
9. strange UDP 5400 traffic (Thread)
10. Odd activity (Thread)
11. Email Relay Searches (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
1. (WSS-Advisories-02003) PHPBB BBcode Process Vulnerability (Thread)
2. DoS in Shells: was Re: DoS in debian (potato) proftpd:
3. MS-SQL banners (Thread)
4. Black Hat Briefings (Vegas) Call for Papers (Thread)
5. Multiple Vendor "talkd" user validation fault. (Thread)
6. RFC: suggestions for SSL security enhancements in Microsoft
7. Compaq tru64 setuids /usr/bin/at and /usr/dt/bin/mailcv (Thread)
8. RCA cable modem Deny of Servic (Thread)
9. Progress Setuid patch Installs (Happy Easter or April fools to
10. RCA cable modem Deny of Service (Thread)
11. Happy Easter / April Fools from Snosoft (Oracle 8.1.5 tnslsnr)
12. A Dozen Eggs for Easter! (Thread)
13. Truths and Lies (Thread)
14. DebPloit + ie + passive connecting to attacker? (Thread)
15. Statement on "Re: New Binary Bruteforcing Method Discovered"
16. Re[2]: New Binary Bruteforcing Method Discovered (Thread)
17. Behavior analysis vs. Integrity analysis [was: Binary
18. Behavior analysis vs. Integrity analysis [was: Binary
19. Behavior analysis vs. Integrity analysis [was: Binary
20. PGP 7.x with Outlook will give your passphrase in CLEAR (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
1. Detailed Port Filtering (Thread)
2. Windows NT 4.0 Print Spooler Security (Thread)
3. Detailed Port Filtering (Thread)
4. Internet Services Manager (Thread)
5. ntsds.exe or ntsdc.exe (Thread)
6. A different NTFS ACL question (Thread)
7. A question regarding the way how IIS gets the CRL's (Thread)
8. ntsds.exe or ntsdc.exe (Thread)
9. MS 3/28/02 Security Patch for IE6 - warning! (Thread)
10. Looking for a tool that... (Thread)
11. A question regarding the way how IIS gets the CRL's (Thread)
12. Looking for a tool that... (Thread)
13. How to migrate my VeriSign SSL certificate from IIS 4 to IIS 5
14. fake sender and Exchange 5.5 (Thread)
15. How to migrate my VeriSign SSL certificate from IIS 4 to IIS 5
16. Domain Controller Messup (Thread)
17. SecurityFocus Microsoft Newsletter #80 (Thread)
18. fake sender and Exchange 5.5 (Thread)
19. Null session in Windows XP (Thread)
20. Domain Controller Messup (Thread)
21. Port Ranges in IPSec (Thread)
22. IIS Key pairs (Thread)
23. IIS Key pairs (how to export an IIS 4.0 self-issued Root CA a nd
24. AD account lockout problem (Thread)
25. Exchange 2K, and the M: drive. (Thread)
26. A different NTFS ACL question (Thread)
27. AD account lockout problem (Thread)
28. ntfs perms question (Thread)
29. IIS Key pairs (Thread)
IX. SUN FOCUS LIST SUMMARY
1. ?hack cause? (Thread)
2. Followup - Thanks - "Re: ?hack cause? " (Thread)
3. ?hack cause? (Thread)
X. LINUX FOCUS LIST SUMMARY
1. No New Content
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. Managing Intrusion Detection Systems in Large Organizations: Part One
by Paul Innella
This article is the first of a two-part series that will discuss the need
for intrusion detection systems (IDS) in large organizations, including
challenges of deploying IDSs in such environments, managing agents in a
distributed environment, and using collected data. It will also discuss
some real-world IDS experiences of larger companies.
http://online.securityfocus.com/infocus/1564
2. Active Directory and Linux
by David Del Elson
This article discusses the use of Microsoft's Active Directory as an
authentication service for Linux systems. Although Linux has a perfectly
good directory based authentication system (OpenLDAP), it may be desirable
on some sites to authenticate Linux users against a Microsoft Windows 2000
server.
http://online.securityfocus.com/infocus/1563
3. Past its Prime: Is Anti-Virus Scanning Obsolete?
by Paul Schmehl
The title and topic of this article is clearly controversial. It is
guaranteed to get a strong reaction from the anti-virus industry, which is
firmly convinced it sees clear sailing ahead. So, is anti-virus scanning
obsolete? In a word, yes - but dont throw out your scanner. Its
replacement hasnt been created yet. In this article we will examine the
weaknesses of virus scanning that will cause its eventual downfall.
http://online.securityfocus.com/infocus/1562
4. Death to Old Software
by Jon Lasser
We all know that outdated network software is security hazard. The
solution: hard-wired expiration codes that self-destruct an old program
when it's past its prime.
http://online.securityfocus.com/columnists/72
5. A Mickey Mouse Bill
By David Banisar
In the name of protecting copyrights, a new bill introduced in the U.S.
Senate threatens to grind to a halt all advancements in electronics,
computing and networking, decimating the consumer's ability to choose how
they wish to listen, watch, and read. The motion picture industry is back
on the Hill.
http://online.securityfocus.com/columnists/71
II. BUGTRAQ SUMMARY
-------------------
1. Microsoft Internet Explorer Known Local File Script Execution Vulnerability
BugTraq ID: 4392
Remote: Yes
Date Published: Mar 29 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4392
Summary:
A flaw exists in the way that Microsoft Internet Explorer handles scripts
embedded within cookies. Since cookies are essentially an extension of
the website from which they were received, they should be treated as
though they are in the Internet zone.
Since cookies are stored on the local system, however, Internet Explorer
regards them as being in the Local Computer zone. Because of this, any
scripts embedded within a cookie will be executed by Internet Explorer in
the Local Computer zone and with the privileges of the currently logged in
user.
It has been reported that this issue is based on the ability to force
Internet Explorer to open arbitrary known files as HTML content. As a
result, any local file which contains valid HTML or JavaScript may be
rendered as such by the browser. Normally only files with the registered
extensions .html or .htm will be interpreted as HTML content.
Given this ability, an attacker able to inject content into any known file
may exploit this vulnerability to execute arbitrary script code in the
Local Computer context. While cookie files are a valid target, other
options may exist. It has been suggested that it is possible to include
script commands in the Internet Explorer favorites file and the current
WinAmp playlist file, both of which are stored in a known location.
These additional attack vectors may require additional user interaction.
For example, in order to inject content into the Winamp playlist, the
attacker must convince the user to load a mp3 file with malicious artist
or song data.
2. ZeroForum User-Embedded Scripting Vulnerability
BugTraq ID: 4394
Remote: Yes
Date Published: Mar 29 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4394
Summary:
ZeroForum is a message board application which provides an enterprise
level web discussion forum, and runs on most UNIX and Linux Operating
systems. Versions of ZeroForum suffers from a user-embedded scripting
vulnerability
ZeroForum allows forum users to post images in messages. It is reportedly
possible for attackers to cause script code to be embedded in the image
tags.
When other users view the images, the attacker-embedded script code will
execute within the context of the website. Attackers may design script
code that can obtain cookies or perform actions as the victim user. This
may result in a compromise of the victim's forum account.
3. Microsoft Outlook 2002 HTML Mail Script Execution Vulnerability
BugTraq ID: 4397
Remote: Yes
Date Published: Mar 31 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4397
Summary:
Microsoft Outlook 2002 can be made to execute script embedded in HTML mail
without warning the user. This is done by creating a web browser object
containing script in the "Location" parameter specified by a <PARAM ... >
tag and embedding this in the mail.
When a user chooses to "reply" or "forward" the message, the script is
executed. The consequences of this might be limited by Microsoft Outlook
security settings (as yet undetermined), but even if this is the case this
may be used to force users to view hostile web sites. This also could
pose a serious threat if combined with other vulnerabilities.
Script may also be embedded in .doc or .xls attachments.
It may be possible to exploit this vulnerability to cause arbitrary
commands to be executed on the system running the vulnerable software.
It has been reported that this is an issue only if the WordMail editor is
used. Those who use the default Outlook editor are allegedly not affected
by this vulnerability.
4. Microsoft Office XP Spreadsheet Host().SaveAs() File Creation Vulnerability
BugTraq ID: 4398
Remote: No
Date Published: Mar 31 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4398
Summary:
Microsoft Office XP provides a spreadsheet component that can be embedded
in web pages and office documents. This spreadsheet component contains a
bug in a function called HOST() that can be exploited to write arbitrary
files. This can be done from office documents, and possibly other vectors
such as HTML mail.
This is accomplished by embedding a spreadsheet object containing a
formula similar to the following: =Host().SaveAs("arbitraryfilename")
This saves the spreadsheet data to the file specified.
5. Caldera OpenLinux StartKDE Script LD_LIBRARY_PATH Vulnerability
BugTraq ID: 4400
Remote: No
Date Published: Apr 01 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4400
Summary:
OpenLinux is a freely available, open source implementation of the Linux
operating system. It is maintained and distributed by Caldera.
A problem with the OpenLinux startkde script could lead to arbitrary
library attacks. The problem is in the initialization of an environment
variable.
The startkde script insecurely initializes the LD_LIBRARY_PATH environment
variable. When the script is executed, it by default searches the current
working directory. Any libraries needed by KDE that are found in the
current working directory will be loaded.
This vulnerability requires that a user start KDE with the startkde script
outside of his or her home directory. Additionally, it requires that the
directory the script is executed in be write accessible to other system
users.
6. OpenBSD PF TTL Fingerprinting Vulnerability
BugTraq ID: 4401
Remote: Yes
Date Published: Mar 31 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4401
Summary:
PF is a packet filter implementation, available for OpenBSD. It is
developed and maintained by the OpenBSD Project.
A problem with PF could allow remote users to gain information about open
ports on a system. The problem is in the response to some types of
traffic.
Under some circumstances, PF sends responses that can allow an attacker to
gain information about the firewall ruleset. When an attempt is made to
connect to a system via TCP on a port that is filtered by PF, and PF
returns a RST, it is possible to differentiate between filtered and
unfiltered ports. A port that is filtered will return a RST with a TTL
field set to 128, whereas the operating system returns a value of 64 by
default.
In the event that a system is filtering certain ports, analysis of the TTL
values returned by the system could lead to accurately predicting ports
that are open but have no services running on them, as would be indicated
by a TTL of 64. For ports filtered by PF, the returned TTL of 128 would
give information about a port that can't be accessed due to PF.
This vulnerability can only be exploited in rulesets which return RST
values for unauthorized connection attempts. Rulesets that do not return
RSTs but simply drop the incoming packet are not affected.
7. IPFilter TTL Fingerprinting Vulnerability
BugTraq ID: 4403
Remote: Yes
Date Published: Mar 31 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4403
Summary:
IPFilter is a freely available, open source firewall package written by
Darren Reed. It is available for multiple platforms, including Unix and
Linux operating systems.
A problem with IPFilter could allow remote users to gain information about
open ports on a system. The problem is in the response to some types of
traffic.
Under some circumstances, IPFilter sends responses that can allow an
attacker to gain information about the firewall ruleset. When an attempt
is made to connect to a system via TCP on a port that is filtered by
IPFilter, and IPFilter returns a RST, it is possible to differentiate
between filtered and unfiltered ports. A port that is filtered by
IPFilter will return a RST with a TTL field set to 60, whereas the
operating system will return it's default TTL value for a RST.
In the event that a system is filtering certain ports, analysis of the TTL
values returned by the system could lead to accurately predicting ports
that are open but have no services running on them, as would be indicated
by a TTL characteristic of the default operating system. For ports
filtered by IPFilter, the returned TTL of 60 would give information about
a port that can't be accessed due to filtering by IPFilter.
This vulnerability can only be exploited in rulesets which return RST
values for unauthorized connection attempts. Rulesets that do not return
RSTs but simply drop the incoming packet are not affected. Firewalls that
filter all ports by default will not exhibit this behavior.
8. Sambar Server Authentication Buffer Overflow Vulnerability
BugTraq ID: 4404
Remote: Yes
Date Published: Apr 01 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4404
Summary:
Sambar Server is a multi-threaded web server which will run on Microsoft
Windows 9x/ME/NT/2000 operating systems.
A buffer overflow vulnerability has been reported in some versions of
Sambar Server. If extremely long strings are sent for the username and
password used for authentication, it is possible to overwrite stack
memory. It is possible to overwrite stack frame data, which can lead to
the execution of arbitrary code.
As the Sambar server runs with SYSTEM privileges, exploitation of this
vulnerability can lead to remote access to the system with administrative
privileges.
Less clever exploitation of this vulnerability may cause the Sambar
process to crash, resulting in a denial of service attack.
9. Sun Solaris XSun Color Database File Heap Overflow Vulnerability
BugTraq ID: 4408
Remote: No
Date Published: Apr 02 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4408
Summary:
Solaris is the freely available Unix operating system distributed by Sun
Microsystems.
A problem in the Solaris windowing software package could make it possible
for a local user to gain elevated privileges. The problem is in the
handling of some commandline options by the Xsun program.
Xsun is the X Window System server binary distributed with Solaris. It is
on top of this program that desktop environments distributed with Solaris
such as CDE, Openwin, and Gnome run. Xsun is by default installed as a
setgid root executable.
The Xsun commandline option of -co is used to load a color database file.
It may be possible for a local user to gain elevated privileges. When
Xsun is executed, and an excessively long argument is supplied to the -co
flag, a heap overflow occurs. This problem could allow a local user to
supply a maliciously formatted string with the -co option that could
result in the execution of arbitrary code, and elevated privileges.
The overflow has been reproduced when 6000 or more characters are supplied
as the argument to the -co option. This problem could result in a local
user executing arbitrary code with the group privileges of root, and
gaining local administrative access.
10. Netware Remote Manager Authentication Buffer Overflow Vulnerability
BugTraq ID: 4405
Remote: Yes
Date Published: Apr 02 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4405
Summary:
Novell Netware Remote Manager provides a web based administrative
interface for the Novell product. The Remote Manager accepts SSL
connections on port 8009 by default.
If a HTTP Basic Authentication request is sent with extremely long values
for the username or password field, a buffer overflow will occur.
Depending on the length of the string submitted, either the SERVER.NLM or
the HTTPSTK.NLM processes will halt with an ABEND error.
Depending on the details of exploitation, it is possible to cause the
process to free memory through an overwritten pointer address, or to use a
corrupted register in a CMP instruction. These issues do not immediately
lead to the execution of arbitrary code. However, as memory corruption is
occuring, the possibility remains.
11. Lotus Domino MS-DOS Device Path Disclosure Vulnerability
BugTraq ID: 4406
Remote: Yes
Date Published: Apr 02 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4406
Summary:
Lotus Domino Server is an application framework for web based
collaborative software. It runs on multiple platforms including Microsoft
Windows and Unix.
A problem exists in the CGI parser for Lotus Domino that may enable a
remote attacker to gather sensitive information about a host running the
vulnerable software.
Vulnerable versions of Lotus Domino do not properly handle specially
crafted requests for MS-DOS devices. It is possible to specially craft a
web request for a MS-DOS device which will cause sensitive path
information to be disclosed in error messages generated by the malformed
request.
Sensitive information gathered in this manner may aid the attacker in
further attacks against the host running the vulnerable software.
This issue was reported for Lotus Domino v5.0.9a for Microsoft Windows
platforms. Earlier versions may also be affected.
12. ZoneLabs ZoneAlarm MailSafe Extension Dot Filtering Bypass Vulnerability
BugTraq ID: 4407
Remote: Yes
Date Published: Apr 02 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4407
Summary:
ZoneLabs ZoneAlarm is a firewall for Microsoft Windows based PCs. It
supports a wide range of functions, including a MailSafe feature designed
to block email containing malicious content or attachments.
A vulnerability has been reported in some versions of ZoneAlarm. MailSafe
may be configured to block file attachments with a certain extension, for
example all .exe files. If the same file is sent with an additional '.'
appended to the filename, it will not be blocked.
Unfortunately, many versions of Windows will treat both files identically.
An end user may trust filtered content which is in fact malicious. This
behavior has also been reported in Outlook and Outlook Express.
It has been reported that other methods to bypass filtering are available,
although details have not been released.
13. Cyrus SASL LDAP+MySQL Authentication Patch SQL Command Execution Vulnerability
BugTraq ID: 4409
Remote: Yes
Date Published: Apr 02 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4409
Summary:
The Cyrus SASL LDAP+MySQL patch is a freely available, open source
enhancement patch. It is designed for use on the Unix and Linux operating
systems.
A problem with the patch could make it possible for remote users to gain
access to the mail account of any user. The problem is in the handling of
user input.
The Cyrus SASL LDAP+MySQL patch is designed to integrate LDAP and MySQL
authentication with Cyrus SASL. This makes it possible to centralize
authentication data.
Due to a design problem in the patch, users may gain access to the mail
accounts of others. By passing a specially crafted SQL command to the
password challenge, it is possible to provoke a successful authentication
response from the MySQL server. This would give access to the mail of the
user specified in the login challenge.
Exploitation of this vulnerability may offer intermitted success through
the use of a string such as ') OR 1=1 HAVING FLOOR(RAND()*100)=1 AND
('1'='1. If the attacker has knowledge of database layout via another
vulnerability that allows SQL command stuffing, the probability of
exploitation increases significantly.
This problem may allow a remote user to gain access to the mail spool of
the desired user.
14. Microsoft Internet Explorer Cascading Style Sheet File Disclosure Vulnerability
BugTraq ID: 4411
Remote: Yes
Date Published: Apr 02 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4411
Summary:
One of the features of Cascading Style-Sheets (CSS) is that external files
containing CSS code may be linked to from within another document. A
vulnerability in Microsoft Internet Explorer has been discovered which
demonstrates that this functionality, under some circumstances, may be
abused by an attacker to disclose the contents of files that exist on an
arbitrary web user's system.
It is possible to use the cssText property of the styleSheet to read
portions of files that exist on an arbitrary web user's system. Successful
exploitation will cause the CSS interpreter used by Internet Explorer to
read portions of text if the targetted file contains a "{" character.
An attacker may exploit this via a malicious webpage to disclose sensitive
information contained in (almost) arbitrary files that exist on a web
user's system.
15. Oracle 8i TNS Listener Local Command Parameter Buffer Overflow
Vulnerability
BugTraq ID: 4413
Remote: No
Date Published: Apr 01 2002 12:00A
Relevant URL: http://www.securityfocus.com/bid/4413
Summary:
Oracle 8i is a powerful relational database product. It is available for
Windows, Linux, and a wide range of Unix operating systems.
A vulnerability has been reported with some versions of Oracle 8i for
Linux. A local attacker able to execute the tnslsnr process may pass an
oversized command line parameter. It is possible to overflow stack memory,
including sensitive data used to restore CPU registers. If done correctly,
this can lead to the execution of arbitrary code.
The TNS Listener is central to the Oracle system. Under Linux, it runs
suid as the user 'oracle', and is world executable by default.
Versions of Oracle 8i available for other operating systems have not yet
been confirmed as vulnerable.
III. SECURITYFOCUS NEWS AND COMMENTARY
------------------------------------------
1. Sentencing Study Probes Hacker Motives
By Alex Handy
A computer savvy law professor on the United States Sentencing Commission
launches a rare study that may decide how hackers are sentenced in federal
court.
http://online.securityfocus.com/news/363
2. Privacy Advocates Sue Homeland Security Office
By Ann Harrison
EPIC takes the government to court for details of a secret national I.D.
plan.
http://online.securityfocus.com/news/362
3. E-Insurance for the Digital Age
By Alex Salkever, Business Week
The past six months have been tough on the insurance industry. Claims
resulting from the September 11 terrorist attacks have totaled into the
tens of billions of dollars. At the same time, insurers are struggling to
recover from a decade of price wars that left reserves depleted. But one
tiny part of this sector is going great guns -- the e-business insurance
market.
http://online.securityfocus.com/news/361
4. Getting to the Root of All E-Mail
By David McGuire, Newsbytes
Squatting unobtrusively on the banks of a manmade pond in an unremarkable
corporate subdivision a few miles outside the Beltway, the home of the
Internet's authoritative root server and master registry of dot-com
addresses is virtually indistinguishable from the other red brick office
buildings that surround it.
http://online.securityfocus.com/news/360
IV.SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. libdvdcss v1.1.0
by The VideoLAN Team [email protected]
Relevant URL:
http://www.videolan.org/libdvdcss/
Platforms: BeOS, FreeBSD, Linux, OpenBSD, Windows 2000, Windows 95/98,
Windows NT
Summary:
libdvdcss is a cross-platform library for transparent DVD device access
with on the fly CSS decryption. It currently runs under Linux, FreeBSD,
NetBSD, OpenBSD, BSD/OS, Solaris, BeOS, Win98, Win2k and MacOS X. It is
used for the vlc DVD player because of its portability and because, unlike
similar libraries, it does not require your DVD drive to be region-locked.
2. Anubis v2.0.0b-2
by The Anubis Team [email protected]
Relevant URL:
http://anubis.sourceforge.net/
Platforms: Linux, Windows 2000, Windows 95/98, Windows NT
Summary:
Anubis is an anonymous email sender for Unix, BeOS, Win32, and AmigaOS. It
supports WinGates, encrypted TLS/SSL connections, remailers, anonymous
news posting, and more.
3. Ganglia Cluster Toolkit v2.2.2
by Matt Massie [email protected]
Relevant URL:
http://sourceforge.net/project/showfiles.php?group_id=43021
Platforms: FreeBSD, Linux, Solaris, SunOS
Summary:
Ganglia is a massively scalable cluster monitoring and execution
environment written at the University of California, Berkeley Computer
Science division as part of the Millennium Project. Ganglia monitors over
25 core host metrics (such as CPU, load and memory) and any number of
custom metrics on clusters with hundreds of nodes. Clients can plug into
the Ganglia monitoring core via an XML interface to generate a multitude
of useful visualizations. rrdtool is the tool of choice for Web
visualization of cluster status and historical trends.
4. GNUnet v0.3.3
by Christian Grothoff
Relevant URL:
http://gecko.cs.purdue.edu/GNUnet/
Platforms: FreeBSD, Linux, NetBSD, OpenBSD, POSIX
Summary:
GNUnet is a decentralized, distributed networkwith confidential and
authenticated communication. A first service implemented on top of the
networking layer allows anonymous distribution and retrieval of content.
5. LoFiMo v1.0.1
by anzac
Relevant URL:
http://lofimo.sourceforge.net/
Platforms: Os Independent
Summary:
LoFiMo monitors log files in realtime. Its architecture allows you to add
components that make it possible to monitor virtually any log-producing
facility and render them in many ways. Filters can be used to parse log
entries and, for example, only display important information or set the
font/color used for rendering log entries. Actions can be assigned to
certain log entries to, for example, play a sound when email arrives.
LoFiMo makes it possible to implement auditing and accounting for the
monitored logs. LoFiMo is written in Java and is platform independent.
6. BlackHole Spam/Virus Filter v0.9.58 (Stable)
by Chris Kennedy [email protected]
Relevant URL:
http://the.groovy.org/blackhole.shtml
Platforms: UNIX
Summary:
Blackhole is a C program designed to stop spam and prevent unwanted
senders from sending you email. It is put in the .qmail file and will
divert spam and viruses to separate files which can be checked with an
IMAP client if configured to do so. It not only uses the RBL type servers,
but also checks against your own list of good/bad domains/users. You can
also block email that is sent to an address that is not specified in a
list of addresses to use for emailing you. Blackhole can log and keep the
email it blocks, and you can configure it to either reply with a message
of your choice or make it look like you don't exist on the system.
Finally, you can add relays to the list of relays that will be skipped by
the script. It also has subject line checking with ^ and $ matching lines,
and includes a virus checking server program.
V. SECURITY JOBS SUMMARY
------------------------
No New Content This Week
VI. INCIDENTS LIST SUMMARY
-------------------------
1. VPN connection attempts to resolvers? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
2. VPN connection attempts to resolvers? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
3. Botnet/Domains (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
4. DoS, possibly spoofed IP Addresses (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
5. Unknown Hosts file (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
6. Unknown Hosts file (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/000b01c1d9f3$94fa0c60$0100a8c0@winxp
7. DoS, possibly spoofed IP Addresses (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
8. I think I've been hacked...please help! (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
9. strange UDP 5400 traffic (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/002401c1d958$8126fd10$195019ac@shadowplay
10. Odd activity (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/021d01c1d84b$3d7c07d0$8300a8c0@TikTok
11. Email Relay Searches (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. (WSS-Advisories-02003) PHPBB BBcode Process Vulnerability (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/002501c1dc27$6354c660$0100a8c0@winxp
2. DoS in Shells: was Re: DoS in debian (potato) proftpd: 1.2.0pre10-2.0potato1 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
3. MS-SQL banners (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
4. Black Hat Briefings (Vegas) Call for Papers (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
5. Multiple Vendor "talkd" user validation fault. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
6. RFC: suggestions for SSL security enhancements in Microsoft Internet Explorer (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/OFD477DB7E.54B7611B-ON85256B90.0045CC1F@com
7. Compaq tru64 setuids /usr/bin/at and /usr/dt/bin/mailcv (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
8. RCA cable modem Deny of Servic (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
9. Progress Setuid patch Installs (Happy Easter or April fools to Progress) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
10. RCA cable modem Deny of Service (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
11. Happy Easter / April Fools from Snosoft (Oracle 8.1.5 tnslsnr) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
12. A Dozen Eggs for Easter! (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
13. Truths and Lies (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
14. DebPloit + ie + passive connecting to attacker? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
15. Statement on "Re: New Binary Bruteforcing Method Discovered" (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
16. Re[2]: New Binary Bruteforcing Method Discovered (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
17. Behavior analysis vs. Integrity analysis [was: Binary Bruteforcing] (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/75C025AE395F374B81F6416B1D4BDEFB4BBA0F@MTV-CORPMAIL
18. Behavior analysis vs. Integrity analysis [was: Binary Bruteforcing] (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
19. Behavior analysis vs. Integrity analysis [was: Binary Bruteforcing] (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
20. PGP 7.x with Outlook will give your passphrase in CLEAR (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Detailed Port Filtering (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
2. Windows NT 4.0 Print Spooler Security (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/AD1B7D8D1726D5118A0100508BC5C0AA709B70@EXCHANGE
3. Detailed Port Filtering (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
4. Internet Services Manager (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/1017957403.1229.24.camel@localhost
5. ntsds.exe or ntsdc.exe (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
6. A different NTFS ACL question (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
7. A question regarding the way how IIS gets the CRL's (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
8. ntsds.exe or ntsdc.exe (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
9. MS 3/28/02 Security Patch for IE6 - warning! (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/001401c1db6f$f228af90$0201a8c0@neurotika
10. Looking for a tool that... (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
11. A question regarding the way how IIS gets the CRL's (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/011201c1db32$df5211f0$0600a8c0@home
12. Looking for a tool that... (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/9AACD631D86FD51182C500306E02085801E0134F@asbutl16.asb.countrycompanies.com
13. How to migrate my VeriSign SSL certificate from IIS 4 to IIS 5 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
14. fake sender and Exchange 5.5 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
15. How to migrate my VeriSign SSL certificate from IIS 4 to IIS 5 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
16. Domain Controller Messup (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
17. SecurityFocus Microsoft Newsletter #80 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
18. fake sender and Exchange 5.5 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/00ea01c1da56$07889a00$020310ac@slelaptop
19. Null session in Windows XP (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/000601c1da18$016570a0$3c00000a@Laptom
20. Domain Controller Messup (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
21. Port Ranges in IPSec (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
22. IIS Key pairs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/E846E1497BC9E747A88011167C797D0A09B245@pantera.corp.workscape.net
23. IIS Key pairs (how to export an IIS 4.0 self-issued Root CA a nd import into new IIS 4.0 box) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
24. AD account lockout problem (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
25. Exchange 2K, and the M: drive. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
26. A different NTFS ACL question (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/001001c1d92b$0b4b9b50$fdfea8c0@dellydoo
27. AD account lockout problem (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
28. ntfs perms question (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
29. IIS Key pairs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/E846E1497BC9E747A88011167C797D0A09B219@pantera.corp.workscape.net
IX. SUN FOCUS LIST SUMMARY
----------------------------
1. ?hack cause? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
2. Followup - Thanks - "Re: ?hack cause? " (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
3. ?hack cause? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
X. LINUX FOCUS LIST SUMMARY
---------------------------
No New Content This Week
XI. SPONSOR INFORMATION
-----------------------
This newsletter is sponsored by SecurityFocus (www.securityfocus.com)
Attention Non-profits and Universities: Sign-up now for preferred pricing
on the only global early-warning system for cyber attacks - SecurityFocus
ARIS Threat Management System.
Click here for more info
http://www.securityfocus.com/corporate/products/pdpsection.shtml
-------------------------------------------------------------------------------