SecurityFocus Newsletter #140

John Boletta <[email protected]>
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #140
--------------------------------

This Issue is Sponsored by: NetScreen

PROTECT YOUR NETWORK FROM INTERNAL & EXTERNAL THREATS

NetScreen, a leader in enterprise security, can help, offering the
broadest range of security solutions available. Our new security
appliances are optimized to help guard networks from the effects of
traditional and emerging threats, such as Trojan Horses, worms and
viruses. To find out more about protecting your network from the inside
and out, go to www.netscreen.com/bcr_eweekly

-------------------------------------------------------------------------------

I. FRONT AND CENTER
     1. Securing Privacy, Part One: Hardware Issues
     2. Securing Windows 2000 Communications with IP Filters: Part Two
     3. Managing Intrusion Detection Systems in Large Organizations P2
     4. My Daily Virus
     5. SecurityFocus PDP Program
     6. Event Announcement
II. BUGTRAQ SUMMARY
     1. WatchGuard SOHO Firewall Malformed TCP Packet DoS Vulnerability
     2. Microsoft Office Web Components Local File Read Vulnerability
     3. Microsoft Office Web Components Active Script Execution...
     4. Microsoft OWC Spreadsheet XMLURL Local File Existence Disclosure...
     5. Microsoft Office Web Components Chart Local File Existence...
     6. Microsoft Office Web Components Clipboard Information Disclosure...
     7. Microsoft OWC DataSourceControl ConnectionFile Local File...
     8. CSGuestbook Remote Command Execution Vulnerability
     9. CSLiveSupport Remote Command Execution Vulnerability
     10. CSNews Professional Remote Command Execution Vulnerability
     11. CSChat-R-Box Remote Command Execution Vulnerability
     12. Funk Proxy Weak Default Installation Permissions Vulnerability
     13. Funk Software Proxy Weak Password Storage Vulnerability...
     14. Funk Software Proxy Named Pipe Weak Permissions Arbitrary...
     15. Cisco Aironet Telnet Authentication Denial of Service...
     16. Microsoft Windows Terminal Server Group Policy Bypass...
     17. Powerboards Cookie Manipulation Account Compromise Vulnerability
     18. Microsoft VBScript ActiveX Word Object Denial Of Service...
     19. Abyss Web Server Plaintext Administrative Password...
     20. Abyss Web Server File Disclosure Vulnerability...
     21. Powerboards Administrative Access Vulnerability
     22. Powerboards Unauthorized Post Deletion Vulnerability
     23. Powerboards User Account Arbitrary File Creation Vulnerability
     24. Powerboards error.php Cross Site Scripting Vulnerability
     25. Microsoft IIS HTR ISAPI Extension Buffer Overflow...
     26. ASP-Nuke Image Tag User-Embedded Scripting Vulnerability
     27. ASP-Nuke Cross Site Scripting Vulnerability
     28. Microsoft IIS ISAPI Filter Access Violation Denial of...
     29. Microsoft IIS FTP Connection Status Request Denial of...
     30. ASP-Nuke Cross-Agent Scripting Vulnerability
     31. Microsoft IIS Chunked Encoding Transfer Heap Overflow...
     32. Microsoft IIS Help File Search Cross Site Scripting Vulnerability
     33. Microsoft IIS ASP Server-Side Include Buffer Overflow...
     34. ASP-Nuke Plaintext Cookie Authentication Credentials User...
     35. Microsoft IIS HTTP Error Page Cross Site Scripting Vulnerability
     36. Microsoft IIS HTTP Redirect Cross Site Scripting Vulnerability
     37. Microsoft IIS HTTP Header Field Delimiter Buffer Overflow...
     38. EMUMail HTTP Host Arbitrary Config File Loading Vulnerability
     39. ASP-Nuke Forged Cookie Information Disclosure Vulnerability
     40. Microsoft IIS Chunked Encoding Heap Overflow Variant...
     41. WatchGuard SOHO Firewall Vanishing IP Restrictions Vulnerability
     42. IBM Tivoli Storage Manager Client Acceptor Buffer Overflow...
     43. OpenBSD Default Crontab root Compromise Vulnerability
     44. SGI IRIX Mail Core Dump Vulnerability
     45. IBM Informix Web Datablade SQL Query HTML Decoding Vulnerability
     46. IBM Tivoli Storage Manager Long Username Buffer Overflow
     47. InterNetNews Multiple Local Format String Vulnerabilties
     48. IBM Informix Web Datablade Page Request SQL Injection...
     49. Caldera X11 Library -xrm Buffer Overflow Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
     1. Fears of a Security Brain Drain
     2. Cost, Mistrust Hold Back Security Outsourcing
     3. McAfee OKs Network Associates' New Offer
     4. FBI: Businesses Loath To Report Hacks
IV.SECURITYFOCUS TOP 6 TOOLS
     1. EtherApe v0.8.2
     2. Nikto v1.017
     3. Dante v1.1.12
     4. File System Saint v0.24
     5. ifmonitor v0.25
     6. Syslog-ng v1.5.16
V. SECURITYJOBS LIST SUMMARY
     1. Andersen Fall Out! (Thread)
     2. Seeking: Industrial Security Position (Thread)
     3. Netegrity/iPlanet UUM/Senior Security Engineer - NJ - #248
     4. Security Analyst looking for opportunities (Thread)
     5. Engineering/Sales Lead - Network Security - Rosslyn, VA (Thread)
     6. DIO/DIW Technical Team Lead/Mgr - Columbia, MD (Thread)
     7. Network Security Analyst - Ohio (Thread)
     8. New Business PKI Sales (Thread)
     9. Presales TC / Sales Jnr in Australia/UK/US (Thread)
     10. Sr. Embedded Security Engineer - Austin, TX (Thread)
     11. Software Reverse Engineering Guru (Brisbane, Australia) available
     12. Seeking InfoSec position - Chicago (Thread)
     13. TORONTO- Sales, (Referrals from pre/post Sales Eng.) Security
     14. Security Engineer - Philadelphia, PA (Thread)
     15. System Security Engineer in Washington, DC (Thread)
     16. Looking For InfoSec Position (Thread)
     17. Pre-Sales Specialist - NSW Australia (Thread)
     18. ISO Security Job in AZ (Thread)
     19. Director of Professional Services - San Jose, CA (Thread)
     20. Washington, DC Job Opening (#2) (Thread)
     21. Washington, DC Job Opening (Thread)
     22. Forensics Engineers for a Gov't Agency CORRECTION (Thread)
     23. Director of Professional Services (San Jose, CA) (Thread)
     24. Looking For InfoSec Position (Thread)
     25. Inside Sales - Boston, MA (Thread)
     26. QUEBEC- 5 Bi-lingual Security Architects required (Thread)
     27. Security Analyst Position in Illinois (Thread)
     28. Information Systems Security Engineer opportunity - Chicago, IL
     29. Network Security Internship (Thread)
     30. Forensics Engineers for a Gov't Agency (Thread)
     31. SecurityFocus Vulnerability Analyst (Thread)
     32. Threat Analyst Position - SecurityFocus/ARIS (Thread)
     33. Network Security Analyst  -  Mechanicsburg, PA (Thread)
     34. Security Pro / Nordic (Thread)
     35. Resume - Information Systems Security Professional (Thread)
     36. Seeking Info Security Opportunities in Philadelphia Area (Thread)
VI. INCIDENTS LIST SUMMARY
     1. <victim>server formmail.pl exploit in the wild (Thread)
     2. <victim>server formmail.pl exploit in the wild (Thread)
     3. Possible DOS? (Thread)
     4. FW: Footprints of ASP ISAPI filter buffer overflows (Thread)
     5. IGMP DOS Attack (Thread)
     6. IGMP DOS Attack (Thread)
     7. Redhat 6.2 Honeypot Hacked (Thread)
     8. iPlanet Server vulnerable to HTTP TCP HEAD Attack (Thread)
     9. AIM Backdoor? (Thread)
     10. AIM Backdoor? (Thread)
     11. Probes to previously accessed FTPs and UNCs in XP (Thread)
     12. I think I've been hacked...please help! (Thread)
     13. Probes to previously accessed FTPs and UNCs in XP (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. IIS .asp Remote Buffer Overflow (Thread)
     2. Testing Of Windows 2000 and NT4 IIS .ASP Remote Buffer Overflow
     3. Re[2]: IIS .ASP Remote Buffer Overflow [testing for vulnerable
     4. Re[4]: IIS .ASP Remote Buffer Overflow [testing for vulnerable
     5. Testing Of Windows 2000 and NT4 IIS .ASP Remote Buffer Overflow
     6. Re[2]: Windows 2000 and NT4 IIS .ASP Remote Buffer Overflow
     7. IIS .ASP Remote Buffer Overflow [testing for vulnerable
     8. Windows 2000 and NT4 IIS .ASP Remote Buffer Overflow (Thread)
     9. test script for ASP buffer overflow (Thread)
     10. Buffer overflow or overrun? (Thread)
     11. PHP Nuke All version - ("viewdownload" Path disclosure vulns)
     12. Security holes  : D-Book, CBook, IcrediBB (Thread)
     13. Smashing Windows (Thread)
     14. Windows 2000 and NT4 IIS .ASP Remote Buffer Overflow (Thread)
     15. Security holes in ForamiX (Thread)
     16. Security holes in WoltLab Burning Board (Thread)
     17. Studying buffer overflows [maybe OT] (Thread)
     18. Cross Site Scripting Vulnerability (Thread)
     19. Techniques for Vulneability discovery (Thread)
     20. Hack Proofing Your Network Second Edition (Thread)
     21. Techniques for Vulneability discovery (Thread)
     22. Security holes in ASP-Nuke (Thread)
     23. Security holes in Powerboard forum (Thread)
     24. combinations of 4 (Thread)
     25. Techniques for Vulnerability discovery (Thread)
     26. JAVA more insecure than true compiled code? (Thread)
     27. re: combinations of 4 (Thread)
     28. hello (Thread)
     29. Exploiting the race conditions in logwatch. (Thread)
     30. UBB Vuln (Thread)
     31. security issue at hypovereins bank (Thread)
     32. hello (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. MBSA and MS's attempts at "security" (Thread)
     2. net use and LM / NTLM (Thread)
     3. Peculiar login troubles. (Thread)
     4. Users slam Microsoft Security Analyser (Thread)
     5. MBSA and MS's attempts at "security" (Thread)
     6. URLScan Documentation Contradiction (I think) (Thread)
     7. Info about missing HTML files in MBSA (Thread)
     8. Security policy in the Group policy objects are applied
     9. Microsoft Baseline Security Analyzer v1.0 Released 8th April
     10. VPN / IPSEC (Thread)
     11. Peculiar login troubles. (Thread)
     12. January Security Rollup package listed in Windows update...
     13. Securing Microsoft Windows 2000 Terminal Services with Terminal S
     14. Editing MS-2000 Firewall Rules (Thread)
     15. Problem with auto unpacking Hotfixes (from 1 machine only)
     16. L2tp over Ipsec w2k against Nortel Switch (Thread)
     17. More about MBSA and MS's attempts at "security" (Thread)
     18. Microsoft Baseline Security Analyzer v1.0 Released 8th April
     19. Fwd: L2tp over Ipsec w2k against Nortel Switch (Thread)
     20. Free/Shareware IPSec code or apps for Windows (Thread)
     21. VPN / IPSEC (Thread)
     22. Free/Shareware IPSec code or apps for Windows (Thread)
     23. Microsoft PPTP (Was: Internet Services Manager) (Thread)
     24. msxml3.dll file version to high after applying set of (Thread)
     25. Microsoft PPTP (Was: Internet Services Manager) (Thread)
     26. Internet Services Manager (Thread)
     27. Detailed Port Filtering (Thread)
     28. Group Policy denies access to some programs (Thread)
     29. Using syslog clients (Thread)
     30. SecurityFocus Microsoft Newsletter #81 (Thread)
     31. Group Policy denies access to some programs (Thread)
     32. Editing MS-2000 Firewall Rules (Thread)
     33. SOAP toolkit V2 security and vulnerabilities (Thread)
     34. IE6 Problems Update (Thread)
     35. msxml3.dll file version to high after applying set of  hotfixes
     36. Windows NT 4.0 Print Spooler Security (Thread)
     37. Windows NT 4.0 Print Spooler Security (Thread)
     38. msxml3.dll file version to high after applying set of hotfixes
     39. Cryptographic Authentication Techniques - NTLM ? (Thread)
     40. Problem with auto unpacking Hotfixes (from 1 machine only)
     41. Internet Services Manager (Thread)
IX. SUN FOCUS LIST SUMMARY
     1. RSA SecureID on Solaris (Thread)
     2. RSA SecureID on Solaris (Thread)
     3. Good news: /dev/random from Sun for Solaris 8 (Thread)
     4. Disabling Unnecessary Services from inetd.conf File (Thread)
     5. Disabling Unnecessary Services from inetd.conf File (Thread)
X. LINUX FOCUS LIST SUMMARY
     1. arp flood (Thread)
XI. SPONSOR INFORMATION


I. FRONT AND CENTER
-------------------
1. Securing Privacy, Part One: Hardware Issues
by Scott Granneman

This article is the first of a series of three articles that will examine
privacy concerns as they relate to security. This article will examine
hardware-based privacy issues, specifically: hardware solutions for small
networks and wireless devices, hardware-based spyware, and some attempts
by hardware vendors to infringe upon users' privacy.

http://online.securityfocus.com/infocus/1568

2. Securing Windows 2000 Communications with IP Filters: Part Two
by Joe Klemencic

This is the second part of a two-part series on implementing Windows 2000
IP Security filters. In the first article, we offered an overview of IP
security policies, including defining, testing, and expanding IP security
policies. In this installment, we will be discussing encryption of Windows
systems and implementing IP security filters.

http://online.securityfocus.com/infocus/1566

3. Managing Intrusion Detection Systems in Large Organizations, Part Two
by Paul Innella, Oba McMillan, and David Trout, with assistance from
Rebecca Bace

This is the second part of a two-part series devoted to discussing the
implementation of intrusion detection systems in large organizations. In
the first installment, we looked at some of the challenges of planning,
integrating, and deploying IDSs in a large organization. In this
installment, we will look at managing agents in a distributed environment,
managing data from multiple IDS packages, and correlating data from
distributed agents.

http://online.securityfocus.com/infocus/1567

4. My Daily Virus
by George Smith

Why continue to run a "WildList" cataloging every virus in the world when
they all show up in our inboxes anyway?

http://online.securityfocus.com/columnists/73

5. SecurityFocus PDP Program

Attention Non-profits and Universities: Sign-up now for preferred pricing
on the only global early-warning system for cyber attacks - SecurityFocus
ARIS Threat Management System.Click here for more info

http://www.securityfocus.com/corporate/products/pdpsection.shtml

6. Event Announcement

Infotec 2002 Information Technology Expo & Conference, "Business
Technology in a Changing World---Are You in a Security State of Mind?"
(Omaha, Nebraska April 22-24, 2002).  Held in conjunction with Information
Security Awareness Week on April 20-26. Over 120 different sessions for
everyone; from novice to expert. Sessions range from 75 minutes to full
day depending on content; including HIPAA, Technical Security, Security
Management, and more. Keynotes include: Ryan Russell, SecurityFocus;
Marcus Ranum, NFR; Dr. Peter Neumann, SRI International; Dr. Douglas
Maughan, DARPA; and many more. For full details go to

http://www.infotec.org or contact [email protected]


II. BUGTRAQ SUMMARY
-------------------
1. WatchGuard SOHO Firewall Malformed TCP Packet DoS Vulnerability
BugTraq ID: 4447
Remote: Yes
Date Published: Apr 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4447
Summary:

WatchGuard SOHO Firewall is a firewall appliance intended for use by Home
Office/Small Office users. It offers built-in VPN capabilities.

A vulnerability has been discovered in Watchguard Soho Firewall which has
the potential to deny service to legitimate users.

WatchGuard SOHO Firewall crashes when handling certain types of malformed
TCP packets. Upon attempting to forward a packet with bad IP options, the
firewall will crash and reboot. All current connections will drop when
this occurs, including any VPN sessions.

It should be noted that this is only an issue for packets that are
forwarded by the firewall appliance. This is because the firewall will
only attempt to parse IP options when it is forwarding packets.

2. Microsoft Office Web Components Local File Read Vulnerability
BugTraq ID: 4453
Remote: Yes
Date Published: Apr 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4453
Summary:

Microsoft Office Web Components (OWC) are a collection of ActiveX objects
which provide limited Office functionality to web pages. OWC is installed
by default with both Office 2000 and Office XP.

A vulnerability has been reported within some versions of the OWC
Spreadsheet component. It is possible for a web page using this component
to read the content of any known local file.

This is possible through the LoadText method of the Range object. By
design, this object will throw an error if the requested file is not in
the same domain as the current document. However, it is possible to pass a
URL to this method which causes a redirect to a local file. Under these
circumstances, the trust decision is made based on the URL, and the file
is loaded.

Given access to the file contents, it is possible to transfer it to a
hostile server with additional script code. Under some circumstances, a
malicious script may be able to use this information to perform further,
intelligent attacks.

3. Microsoft Office Web Components Active Script Execution Vulnerability
BugTraq ID: 4449
Remote: Yes
Date Published: Apr 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4449
Summary:

Microsoft Office Web Components (OWC) are a collection of ActiveX objects
which provide limited Office functionality to web pages.

A vulnerability has been reported within some versions of the OWC
Spreadsheet component. It is possible for a web page using this component
to execute arbitrary Active Script code, even when Active Scripting has
been disabled by the client.

This is possible through usage of the HOST() formula within the
Spreadsheet component. It is possible to associate script code with events
of the OWC object. This has been demonstrated through usage of the
setTimeout method, although other vectors may be possible.

Reportedly this formula may also be used to manipulate the browser
Document Object Model (DOM), with less severe consequences.

4. Microsoft OWC Spreadsheet XMLURL Local File Existence Disclosure Vulnerability
BugTraq ID: 4455
Remote: Yes
Date Published: Apr 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4455
Summary:

Microsoft Office Web Components (OWC) are a collection of ActiveX objects
which provide limited Office functionality to web pages. OWC is installed
by default with both Office 2000 and Office XP.

A vulnerability has been reported within some versions of the OWC
Spreadsheet component. It is possible for a web page using this component
to verify the existence of any specified local file.

The XMLURL property of the Spreadsheet object will follow redirections
after making a security decision. As a result, a provided URL in the same
domain as the malicious document which redirects to a specific local file
will be allowed.

If it is passed a file name which does not exist on the local system, an
error message is returned. It is possible for the calling page to detect
this error condition, and determine that the file did not exist.

Additionally, it is possible to view the file contents if the file is a
valid WorkSheet XML document. The attacker may also be able to use this
information to perform further, intelligent attacks against the vulnerable
system.

5. Microsoft Office Web Components Chart Local File Existence Disclosure Vulnerability
BugTraq ID: 4454
Remote: Yes
Date Published: Apr 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4454
Summary:

Microsoft Office Web Components (OWC) are a collection of ActiveX objects
which provide limited Office functionality to web pages. OWC is installed
by default with both Office 2000 and Office XP.

A vulnerability has been reported within some versions of the OWC Chart
component. It is possible for a web page using this component to verify
the existence of any specified local file.

The Load method of the Chart object does not provide any security checks
on the file location. If it is passed a file name which does not exist on
the local system, an error message is returned. It is possible for the
calling page to detect this error condition, and determine that the file
did not exist.

It is not currently believed to be possible to access the file contents in
the case that the specified file does exist on the local system. The
attacker may, however, be able to use this information to perform further,
intelligent attacks against the vulnerable system.

6. Microsoft Office Web Components Clipboard Information Disclosure Vulnerability
BugTraq ID: 4457
Remote: Yes
Date Published: Apr 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4457
Summary:

Microsoft Office Web Components (OWC) are a collection of ActiveX objects
which provide limited Office functionality to web pages. OWC is installed
by default with both Office 2000 and Office XP.

A vulnerability has been reported within some versions of the OWC
Spreadsheet component. It is possible for a web page using this component
to gain control over the clipboard operations.

This is possible via the 'Paste' method of the Range object, and the
'Copy' method of the Cell object. These methods allow a web page to gain
full control of the clipboard. This includes reading the contents and
under some circumstances, manipulating the clipboard contents.

Reportedly, it is possible to exploit this issue even if the 'Allow paste
operations via script' security feature in IE is disabled.

Exploitation of this issue could reveal sensitive information which may
assist in further attacks against the host.

7. Microsoft OWC DataSourceControl ConnectionFile Local File Existence Disclosure Vulnerability
BugTraq ID: 4456
Remote: Yes
Date Published: Apr 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4456
Summary:

Microsoft Office Web Components (OWC) are a collection of ActiveX objects
which provide limited Office functionality to web pages. OWC is installed
by default with both Office 2000 and Office XP.

A vulnerability has been reported within some versions of the OWC
DataSourceControl component. It is possible for a web page using this
component to verify the existence of any specified local file.

The ConnectionFile property of the Spreadsheet object does not provide any
security checks on the file location. If it is passed a file name which
does not exist on the local system, an error message is returned. It is
possible for the calling page to detect this error condition, and
determine that the file did not exist.

It is not currently believed to be possible to access the file contents in
the case that the specified file does exist on the local system. The
attacker may, however, be able to use this information to perform further,
intelligent attacks against the vulnerable system.

8. CSGuestbook Remote Command Execution Vulnerability
BugTraq ID: 4448
Remote: Yes
Date Published: Apr 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4448
Summary:

csGuestbook is web guestbook software. It will run on most Unix and Linux
variants.

csGuestbook is prone to an issue which may enable an attacker to execute
Perl code with the privileges of the webserver process.

It is possible to craft a web request which is capable of passing
arbitrary data to the configuration script, including attacker-supplied
Perl code. Perl code passed in this manner will be interpreted by the
vulnerable script, effectively allowing a remote attacker to execute
arbitrary Perl code with the privileges of the webserver process.

For exploitation to be successful, the attacker must pass properly URL
encoded Perl code in CGI parameters via a web request. For example:

http://host/cgi-bin/csGuestbook.cgi?command=savesetup&setup=PERL_CODE_HERE

This issue may enable a remote attacker to gain local, interactive access
to the host running the vulnerable software.

9. CSLiveSupport Remote Command Execution Vulnerability
BugTraq ID: 4450
Remote: Yes
Date Published: Apr 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4450
Summary:

csLiveSupport is a script for providing live web support. It will run on
most Unix and Linux variants, as well as Microsoft operating systems.

csLiveSupport is prone to an issue which may enable an attacker to execute
Perl code with the privileges of the webserver process.

It is possible to craft a web request which is capable of passing
arbitrary data to the configuration script, including attacker-supplied
Perl code. Perl code passed in this manner will be interpreted by the
vulnerable script, effectively allowing a remote attacker to execute
arbitrary Perl code with the privileges of the webserver process.

For exploitation to be successful, the attacker must pass properly URL
encoded Perl code in CGI parameters via a web request. For example:

http://host/cgi-bin/csLiveSupport.cgi?command=savesetup&setup=PERL_CODE_HERE

This issue may enable a remote attacker to gain local, interactive access
to the host running the vulnerable software.

10. CSNews Professional Remote Command Execution Vulnerability
BugTraq ID: 4451
Remote: Yes
Date Published: Apr 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4451
Summary:

csNews Professional is a script for managing news items on a website. It
will run on most Unix and Linux variants, as well as Microsoft Windows
operating systems.

csNews Professional is prone to an issue which may enable an attacker to
execute Perl code with the privileges of the webserver process.

It is possible to craft a web request which is capable of passing
arbitrary data to the configuration script, including attacker-supplied
Perl code. Perl code passed in this manner will be interpreted by the
vulnerable script, effectively allowing a remote attacker to execute
arbitrary Perl code with the privileges of the webserver process.

For exploitation to be successful, the attacker must pass properly URL
encoded Perl code in CGI parameters via a web request. For example:

http://host/cgi-bin/csNews.cgi?command=savesetup&setup=PERL_CODE_HERE

This issue may enable a remote attacker to gain local, interactive access
to the host running the vulnerable software.

11. CSChat-R-Box Remote Command Execution Vulnerability
BugTraq ID: 4452
Remote: Yes
Date Published: Apr 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4452
Summary:

csChat-R-Box is a web chat script. It will run on most Unix and Linux
variants, as well as Microsoft Windows operating systems.

csChat-R-Box is prone to an issue which may enable an attacker to execute
Perl code with the privileges of the webserver process.

It is possible to craft a web request which is capable of passing
arbitrary data to the configuration script, including attacker-supplied
Perl code. Perl code passed in this manner will be interpreted by the
vulnerable script, effectively allowing a remote attacker to execute
arbitrary Perl code with the privileges of the webserver process.

For exploitation to be successful, the attacker must pass properly URL
encoded Perl code in CGI parameters via a web request. For example:

http://host/cgi-bin/csChatRBox.cgi?command=savesetup&setup=PERL_CODE_HERE

This issue may enable a remote attacker to gain local, interactive access
to the host running the vulnerable software.

12. Funk Proxy Weak Default Installation Permissions Vulnerability
BugTraq ID: 4458
Remote: No
Date Published: Apr 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4458
Summary:

Proxy is a software package distributed and maintained by Funk Software.
It is available for use on the Microsoft Windows platform.

A problem with the software could allow users to alter Proxy software
configurations.  The problem is in the default directory permissions.

A default Proxy installation uses insecure default directory and registry
entries.  In Windows 2000 and NT 4.0 systems, members of the group
'Everyone' are permitted full access to the Proxy software installation
directory.  Additionally, the registry entries in NT 4.0 may be altered by
any member of the group 'Everyone' with 'Special Access'.

This could allow a local user on the system to modify directory contents
in the Proxy directory, or on affected NT 4.0 hosts, registry settings.

13. Funk Software Proxy Weak Password Storage Vulnerability
BugTraq ID: 4459
Remote: No
Date Published: Apr 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4459
Summary:

Proxy is a remote host administration tool distributed and maintained by
Funk Software.  It is available for the Microsoft Windows platforms.

A problem with Proxy could make it possible for users to gain elevated
privileges on a system.  The problem is in the storage of password values.

Proxy uses weak encryption to store the password values of Proxy.  In
doing so, passwords allowing the remote login of administrators may be
recovered.  This could lead to a user gaining elevated privileges on a
host.

On Windows 2000 and NT 4.0 hosts, the password is stored in the registry.
On Windows 9X systems, this value is stored in the PHOST.INI file,
contained in the Proxy install directory.  This problem is compounded by
the vulnerability Bugtraq ID 4458 titled "Funk Proxy Weak Default
Installation Permissions Vulnerability."

14. Funk Software Proxy Named Pipe Weak Permissions Arbitrary Access Vulnerability
BugTraq ID: 4460
Remote: Yes
Date Published: Apr 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4460
Summary:

Proxy is a remote administration software package distributed and
maintained by Funk Software.  It is designed for use on Microsoft Windows
Operating Systems.

A problem with the software package could allow a local user to change
arbitrary configuration variables.  The problem is in the permissions set
on named pipes by Proxy.

The Proxy program does not adequately set permissions on named pipes.
When the program executes, a Windows Named Pipe is created for the
program.  However, 'Full Control' privileges of this named pipe are
granted to group 'Everyone.'

This problem could lead to an attacker changing configuration parameters
through the Proxy host software locally.  Additionally, it could allow a
local user to gain access to the Proxy password.  This problem affects
Windows 2000 and NT 4.0 hosts.

15. Cisco Aironet Telnet Authentication Denial of Service Vulnerability
BugTraq ID: 4461
Remote: Yes
Date Published: Apr 09 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4461
Summary:

The Cisco Aironet product family provides wireless LAN (WLAN) support for
a wide range of applications.

A vulnerability has been reported in some Aironet products. If telnet
access to the device is enabled, an attacker is able to cause the device
to reboot. This may result in a loss of connectivity for clients of the
device. Repeated exploitation can result in a denial of service condition.

Reportedly this vulnerability lies within the authentication process.
While authentication must be required by the server, valid credentials are
not needed.

Direct telnet access to the affected systems is required. Reportedly, it
is not possible to exploit this vulnerability through the web
administration interface.

16. Microsoft Windows Terminal Server Group Policy Bypass Vulnerability
BugTraq ID: 4464
Remote: No
Date Published: Apr 09 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4464
Summary:

An issue has been reported in Microsoft Windows Terminal Server, which
could allow a user of the service to bypass the group policy setting and
access restricted resources.

When group policies are created they are stored in the SYSVOL share. Upon
a user authenticating, the appropriate policies are applied.

Allegedly, exceeding the number of permitted users specified in the per
server license agreement, could allow for any additional users to bypass
group policy settings, and access additional resources residing on the
host. Users are reported to retain their original user permissions, and
may have access to additional applications, files, directories etc. This
issue results because any additional users connected to the host, fail to
connect to the SYSVOL share and inherit appropriate group policy settings.

For example, if group policies are set to only allow two users, and both
are given access to only one application, yet three connections are made
to the host, the third user may be able to access various applications
residing on the host. Group policy settings are not inherited by
additional users that have exceeded the per server agreement, and
therefore users may peruse resources on the host with his/her user
permissions.

This issue may only exist on Microsoft's Terminal Server 90-day trial
edition, however, this is not yet confirmed.

As testing is underway, additional details are forthcoming.

17. Powerboards Cookie Manipulation Account Compromise Vulnerability
BugTraq ID: 4468
Remote: Yes
Date Published: Apr 09 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4468
Summary:

Powerboards is a bulletin board application developed in PHP.

Powerboards use cookies for authentication. When a user is issued a
cookie, the cookie is stored in a non-encrypted format. It is possible for
a malicious user to manipulate values in their cookie and authenticate as
an arbitrary user of the service, including the administrative account.

Successful hijacking of the administrative account will permit the
malicious user to access administrative facilities.

18. Microsoft VBScript ActiveX Word Object Denial Of Service Vulnerability
BugTraq ID: 4463
Remote: Yes
Date Published: Apr 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4463
Summary:

A vulnerability has been discovered which is reported to affect Microsoft
Internet Explorer, Outlook and Word. Other Office components may also be
affected by this issue.

It is possible to misuse VBScript ActiveX Word objects to cause a denial
of service to affected software. This is accomplished by creating an
excessive number of Word objects. A WINWORD.EXE process is created to
facilitate the creation of each individual ActiveX Word object. For
example, an attacker may create a loop which loads the malicious ActiveX
Word object 100 times or more, causing a denial of service condition to
occur.

It should be noted that this misuse of ActiveX Word objects will cause a
security warning to be displayed about the creation of an unsafe ActiveX
object (depending on the security settings of the affected program).
However, even if the user chooses not to proceed, the ActiveX Word object
is still loaded into memory an excessive number of times. The resulting
exhaustion of resources may cause the entire system to become unstable,
resulting in a denial of service.

19. Abyss Web Server Plaintext Administrative Password Vulnerability
BugTraq ID: 4467
Remote: No
Date Published: Apr 07 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4467
Summary:

Abyss Web Server is a freely available personal web server. It is
maintained by Aprelium Technologies and runs on Microsoft Windows
operating systems, as well as Linux.

The administrative password for Abyss Web Server is stored in plaintext in
the configuration file (abyss.conf). If a local attacker can read the
configuration file, they can trivially gain administrative access to the
web server.

Additionally, BugTraq ID 4466 "Abyss Web Server File Disclosure
Vulnerability" describes an issue which may also enable remote attackers
to trivially disclose the contents of the Abyss Web Server configuration
file.

Sensitive information about the web server's configuration may also be
disclosed as a result of this vulnerability.

This issue was reported for Abyss Web Server for Microsoft Windows
operating systems. It is not known whether the Linux version is also
affected by this vulnerability.

20. Abyss Web Server File Disclosure Vulnerability
BugTraq ID: 4466
Remote: Yes
Date Published: Apr 07 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4466
Summary:

Abyss Web Server is a freely available personal web server. It is
maintained by Aprelium Technologies and runs on Microsoft Windows
operating systems, as well as Linux.

Abyss Web Server does not filter certain types of potentially malicious
input from web requests.

It is possible for a remote attacker to disclose the contents of arbitrary
web-readable files by making a specially crafted web request containing
encoded dot-dot-slash (../) sequences. Such a request will enable the
attacker to browse files outside of the wwwroot directory.

This issue may be exploited by a remote attacker to gain access to the
administrative configuration file for the web server. Another known issue
regarding plaintext storage of the administrative password is described in
BugTraq ID 4467 "Abyss Web Server Plaintext Administrative Password
Vulnerability" .

This issue was reported for Abyss Web Server for Microsoft Windows
operating systems. It is not known whether the Linux version is also
affected by this vulnerability. Furthermore, it should be noted that web
servers on multi-user Windows operating systems generally run with SYSTEM
privileges.

21. Powerboards Administrative Access Vulnerability
BugTraq ID: 4471
Remote: Yes
Date Published: Apr 09 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4471
Summary:

Powerboards is a bulletin board message application developed in PHP.

An issue has been reported in Powerboards which could allow a user to gain
administrative access. This is possible by directly calling an
administration script with the parameter 'admin=1'.

This is most likely due to a feature of PHP whereby CGI parameters are
automatically imported into the script process as global variables.

22. Powerboards Unauthorized Post Deletion Vulnerability
BugTraq ID: 4469
Remote: Yes
Date Published: Apr 09 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4469
Summary:

Powerboards is a bulletin board application developed in PHP.

By design, a post may be deleted by either the author of that post, or an
administrator of the Powerboards system. Reportedly, there are no real
access restrictions on this ability. Rather, unauthorized parties are not
provided with a link to the delete function.

As a result, a knowledgeable attacker may artifically construct a URL
which will delete an arbitrary post within the system. It is not known if
a valid user account on the Powerboards system is required. However, the
issues discussed in BID 4468 may reduce the effectiveness of any such
restriction.

Reportedly, a URL of the following form will result in post deletion:

/delpost.php?cat=3&fid=4&pid=5

23. Powerboards User Account Arbitrary File Creation Vulnerability
BugTraq ID: 4473
Remote: Yes
Date Published: Apr 09 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4473
Summary:

Powerboards is a bulletin board application developed in PHP.

An issue has been reported in Powerboards, which allows users to create
and retrieve arbitrary files.

Reportedly, when a user signs up to the service a file is created with the
chosen username as the filename. A flaw exists whereby the file can be
retrieved via a web request. Since the file contains user information,
sensitive data is disclosed to remote users. It should be noted that it is
possible to disclose sensitive user information of any known user of the
service. Reportedly password data is contained in plaintext within this
file.

This issue can potentially be used to execute arbitrary code on the host.
If a user with malicious intent creates an account containing script code,
upon the user submitting a web request to retrieve the known file, the
code could execute on the host. This may happen when the attacker supplied
username is a file type which will be interpreted as a script by the web
server, such as 'exploit.php'.

24. Powerboards error.php Cross Site Scripting Vulnerability
BugTraq ID: 4472
Remote: Yes
Date Published: Apr 09 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4472
Summary:

Powerboards is a bulletin board application developed in PHP.

A Cross Site Scripting issue has been reported in some versions of
Powerboards. The error page error.php builds HTML content, including user
supplied input, which is not properly stripped of scripting commands.

An attacker may construct a link to this page which includes malicious
script. When an innocent user follows this link, the script code will
execute within the context of the Powerboards site. It may be possible to
take arbitrary actions as this user, including posting or deleting
content. Account compromise may result from exploitation of this
vulnerability.

25. Microsoft IIS HTR ISAPI Extension Buffer Overflow Vulnerability
BugTraq ID: 4474
Remote: Yes
Date Published: Apr 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4474
Summary:

A buffer overflow in the HTR ISAPI extension has been reported for
Microsoft IIS (Internet Information Services).

HTR is a scripting technology for IIS that has been largely superseded by
ASP (Active Server Pages).  A condition exists in the HTR ISAPI extension
that may enable a remote attacker to send a number of malformed requests
which are capable of overwriting locations in memory with
attacker-supplied data.

This condition affects IIS 4.0, IIS 5.0 and may be effectively mitigated
by disabling the extension.

Exploitation of this vulnerability may result in a denial of service or
allow for a remote attacker to execute arbitrary instructions on the
victim host.

It is important to note that this BugTraq ID is an individual
vulnerability entry to followup the aggregated Multiple Remote IIS
Vulnerabilities alert released by SecurityFocus.

26. ASP-Nuke Image Tag User-Embedded Scripting Vulnerability
BugTraq ID: 4475
Remote: Yes
Date Published: Apr 09 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4475
Summary:

ASP-Nuke is a web based Portal system. It allows users to create accounts
and contribute content to the site.

ASP-Nuke does not adequately filter script code from image tags. It is
possible for an attacker to post a maliciously constructed forum message
which contains arbitrary script code. When the message is viewed by
legitimate users of the website, the script code will be executed in their
web browser, in the context of the website running the vulnerable
software.

This issue may be exploited by an attacker to steal cookie-based
authentication credentials from legitimate users of the service.

27. ASP-Nuke Cross Site Scripting Vulnerability
BugTraq ID: 4477
Remote: Yes
Date Published: Apr 09 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4477
Summary:

ASP-Nuke is a web based Portal system. It allows users to create accounts
and contribute content to the site.

A Cross Site Scripting issue has been reported in ASP-Nuke. The pages
downloads.asp and post.asp build HTML content, including user supplied
input, which is not properly stripped of scripting commands.

An attacker may construct a link to either page which includes malicious
script. When an innocent user follows this link, the script code will
execute within the context of the ASP-Nuke site. It may be possible to
take arbitrary actions as this user, including posting or deleting
content. Account compromise may result from exploitation of this
vulnerability.

28. Microsoft IIS ISAPI Filter Access Violation Denial of Service Vulnerability
BugTraq ID: 4479
Remote: Yes
Date Published: Apr 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4479
Summary:

A vulnerability has been identified in the way Microsoft Internet
Information Server handles URL errors.  This vulnerability exists on IIS
servers that also have Front Page Server Extensions or ASP.NET installed.

If a certain ISAPI filter that is installed with Front Page Server
Extensions and ASP.NET receives a URL that exceeds the maximum allowable
length, the IIS service will fail.  This is because the ISAPI filter fails
the request and sets the URL to a null value.  When IIS receives the null
value, it still tries to process the request before sending the error
message back to the requester.  This results in an access violation error
which causes the IIS service to fail.

On IIS 4.0 servers, the IIS service would have to be manually restarted to
resume normal operation.  On IIS 5.0 and 5.1 servers, the service will
automatically restart itself.

So far, Microsoft has only identified this issue in one ISAPI filter that
is installed with Front Page Server Extensions and ASP.NET, however, there
is a possibility that other ISAPI filters could contain the same
behaviour.  The vulnerability is not within the ISAPI filter itself, but
with the way that IIS handles the null value returned by the filter.

Custom ISAPI filters may also be affected by this condition.

It is important to note that this BugTraq ID is an individual
vulnerability entry to followup the aggregated Multiple Remote IIS
Vulnerabilities alert released by SecurityFocus.

29. Microsoft IIS FTP Connection Status Request Denial of Service Vulnerability
BugTraq ID: 4482
Remote: Yes
Date Published: Apr 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4482
Summary:

A vulnerability has been identified in Microsoft Internet Information
Server's FTP service.  The FTP service is installed by default with IIS
4.0 but must be specified on installations of IIS 5.0 and 5.1.

The condition is present when a request is made for the FTP transfer
status is made via the STAT command.  A client issuing this command with a
large number of file globbing characters as the argument may cause the
service to crash.

When the malformed request is processed, an error condition is created but
not properly reported back to the software module that relayed the user's
request.  The calling module then uses the uninitialized data, causing an
access violation error.  This causes the IIS service to fail, resulting in
termination of all current FTP sessions as well as failure of web
services.

On IIS 4.0 servers, the IIS service would have to be manually restarted to
resume normal operation.  On IIS 5.0 and 5.1 servers, the service will
automatically restart itself.

It is important to note that this BugTraq ID is an individual
vulnerability entry to followup the aggregated Multiple Remote IIS
Vulnerabilities alert released by SecurityFocus.

30. ASP-Nuke Cross-Agent Scripting Vulnerability
BugTraq ID: 4481
Remote: Yes
Date Published: Apr 09 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4481
Summary:

ASP-Nuke is a web based Portal system. It allows users to create accounts
and contribute content to the site.

ASP-Nuke does not sufficiently sanitize potentially malicious characters
from user profile pages. Potentially malicious characters that may be
passed by an attacker include HTML tags. As a result, it may be possible
to inject arbitrary script code into pages that are generated by
profiles.asp.

The script will execute when the malicious profiles are viewed.

31. Microsoft IIS Chunked Encoding Transfer Heap Overflow Vulnerability
BugTraq ID: 4485
Remote: Yes
Date Published: Apr 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4485
Summary:

A heap overflow condition in the 'chunked encoding transfer mechanism'
related to Active Server Pages has been reported for Microsoft IIS
(Internet Information Services).

Web clients may send data to ASP (Active Server Pages) scripts in variable
sized chunks.  This is part of the HTTP protocol specification and is
known as a chunked encoding tansfer.  The chunked encoding transfer
mechanism must allocate a buffer in order to handle the transfer.

There is a lack of sufficient bounds checking on this buffer, which is
dynamically allocated by the ISAPI extension that handles ASP scripting.
This result is a remotely exploitable heap overflow.

This condition affects IIS 4.0 and IIS 5.0.  Exploitation of this
vulnerability may result in a denial of service or allow for a remote
attacker to execute arbitrary instructions on the victim host.

Microsoft IIS 5.0 is reported to ship with a default script (iisstart.asp)
which may be sufficient for a remote attacker to exploit.  Other sample
scripts may also be exploitable.

It is important to note that this BugTraq ID is an individual
vulnerability entry to followup the aggregated Multiple Remote IIS
Vulnerabilities alert released by SecurityFocus.

32. Microsoft IIS Help File Search Cross Site Scripting Vulnerability
BugTraq ID: 4483
Remote: Yes
Date Published: Apr 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4483
Summary:

A Cross Site Scripting issue exists in some versions of IIS. The Help File
search functionality included with IIS may, under some circumstances,
construct HTML content including unsanitized user supplied input.

An attacker may construct a link to a vulnerable server such that it
exploits this vulnerability. When an innocent user follows this link, the
script code will be reproduced by the server, and execute within the
context of the vulnerable site. This may result in the exposure of
sensitive data and cookie information, or allow the attacker to subvert
the content and functionality of the site.

It is important to note that this BugTraq ID is an individual
vulnerability entry to followup the aggregated Multiple Remote IIS
Vulnerabilities alert released by SecurityFocus.

33. Microsoft IIS ASP Server-Side Include Buffer Overflow Vulnerability
BugTraq ID: 4478
Remote: Yes
Date Published: Apr 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4478
Summary:

A buffer overflow related to the processing requested filenames that are
to be included as file includes in ASP scripts has been reported for
Microsoft IIS (Internet Information Services).

IIS attempts to ensure that the length of the filename is not excessive in
length.  A condition exists that may allow for this check to be bypassed,
resulting in a potential buffer overflow.  This condition affects IIS 4.0,
IIS 5.0 and IIS 5.1.

It may be possible, under some circumstances, for a remote attacker to
supply a malicious value for the filename, which will be processed by the
server.  Exploitation requires that the attacker can influence when and
how the file is included.

Exploitation of this vulnerability may result in a denial of service or
allow for a remote attacker to execute arbitrary instructions on the
victim host.

It is important to note that this BugTraq ID is an individual
vulnerability entry to followup the aggregated Multiple Remote IIS
Vulnerabilities alert released by SecurityFocus.

34. ASP-Nuke Plaintext Cookie Authentication Credentials User Account Compromise Vulnerability
BugTraq ID: 4484
Remote: Yes
Date Published: Apr 09 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4484
Summary:

ASP-Nuke is a web based Portal system. It allows users to create accounts
and contribute content to the site.

ASP-Nuke use cookies for authentication. When a user is issued a cookie,
the cookie is stored in a non-encrypted format. It is possible for a
malicious user to manipulate values in their cookie and authenticate as an
arbitrary user of the service, including the administrative account.

Successful hijacking of the administrative account will permit the
malicious user to access administrative facilities.

35. Microsoft IIS HTTP Error Page Cross Site Scripting Vulnerability
BugTraq ID: 4486
Remote: Yes
Date Published: Apr 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4486
Summary:

A Cross Site Scripting issue exists in some versions of IIS. The HTTP
Error Page created by IIS may, under some circumstances, contain HTML
content which includes unsanitized user supplied input.

When a 404 HTTP error page is constructed by IIS, a portion of the content
includes a link to the top level domain of the missing page. This string
consists of the data between the strings '://' and '/' in the supplied
URL.

An attacker may construct a URL which includes malicious script content
within this string. This may be done by including script code within the
HTTP Basic Authentication section of the URL. Properly escaped, such code
will not interfer with the DNS lookup for the targetted site, and will
display properly on the page returned by IIS.

An attacker may construct a link to a vulnerable server such that it
exploits this vulnerability. When an innocent user follows this link, the
script code will be reproduced by the server, and execute within the
context of the vulnerable site. This may result in the exposure of
sensitive data and cookie information, or allow the attacker to subvert
the content and functionality of the site.

It has been reported that this issue may be exploited to steal
cookie-based authentication credentials from users of a number of
Microsoft domains/services (such as hotmail, passport, etc.).

It is important to note that this BugTraq ID is an individual
vulnerability entry to followup the aggregated Multiple Remote IIS
Vulnerabilities alert released by SecurityFocus.

36. Microsoft IIS HTTP Redirect Cross Site Scripting Vulnerability
BugTraq ID: 4487
Remote: Yes
Date Published: Apr 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4487
Summary:

A Cross Site Scripting issue exists in some versions of IIS. The HTTP
Redirect page created by IIS may, under some circumstances, contain HTML
content which includes unsanitized user supplied input.

An attacker may construct a link to a vulnerable server such that it
exploits this vulnerability. When an innocent user follows this link, the
script code will be reproduced by the server, and execute within the
context of the vulnerable site. This may result in the exposure of
sensitive data and cookie information, or allow the attacker to subvert
the content and functionality of the site.

It is important to note that this BugTraq ID is an individual
vulnerability entry to followup the aggregated Multiple Remote IIS
Vulnerabilities alert released by SecurityFocus.

37. Microsoft IIS HTTP Header Field Delimiter Buffer Overflow Vulnerability
BugTraq ID: 4476
Remote: Yes
Date Published: Apr 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4476
Summary:

A buffer overflow related to the processing of request header fields has
been reported for Microsoft IIS (Internet Information Services).

This problem is related to the interpretation of HTTP header field
delimiters.  It is possible to create a request that may appear to have
field delimiters when the check for them occurs, but does not.  The
evasion of this check creates a potentially exploitable buffer overflow
condition.  This vulnerability affects IIS 4.0, IIS 5.0 and IIS 5.1.

Exploitation of this vulnerability may result in a denial of service or
allow for a remote attacker to execute arbitrary instructions on the
victim host.

It is important to note that this BugTraq ID is an individual
vulnerability entry to followup the aggregated Multiple Remote IIS
Vulnerabilities alert released by SecurityFocus.

38. EMUMail HTTP Host Arbitrary Config File Loading Vulnerability
BugTraq ID: 4488
Remote: No
Date Published: Apr 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4488
Summary:

Emumail is a web mail package available from Emumail, Inc.  It is designed
for use on Linux, Unix, and Windows systems.

A problem with the software could allow a user with local access to gain
elevated privileges.  The problem is in the handling of some types of
input.

When a user accesses emumail, emumail checks the HTTP Host variable.
Once this variable is received from the client, the server opens a file
using the variable.

Under some circumstances, it is possible for a local user to gain
privileges equal to the HTTP server process.  Upon connecting to the
server and supplying a malicious HTTP Host value to emumail, it could be
possible to force the program to open an arbitrary file.  This could
addition result in the execution of an arbitrary program, supplied by an
attacker with local access to the host.

This makes it possible for a local user to execute code with the
privileges of the HTTP process.

39. ASP-Nuke Forged Cookie Information Disclosure Vulnerability
BugTraq ID: 4489
Remote: Yes
Date Published: Apr 09 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4489
Summary:

ASP-Nuke is a web based Portal system. It allows users to create accounts
and contribute content to the site.

An issue has been reported in ASP-Nuke, which could cause the host to
return sensitive system information.

ASP-Nuke use cookies for authentication. When a user is issued a cookie,
the cookie is stored in a non-encrypted format. A user may modify their
authentication cookie in such a way that upon submitting the cookie, the
host will return a list of all currently logged in users or the path to
the web root. This may be done by creating a cookie for a non-existant
user.

Gaining knowledge of this information could assist an attacker in further
attacks against the host. This issue could also be used to exploit a
previously discussed vulnerability in BID 4484.

40. Microsoft IIS Chunked Encoding Heap Overflow Variant Vulnerability
BugTraq ID: 4490
Remote: Yes
Date Published: Apr 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4490
Summary:

A heap overflow condition in the 'chunked encoding transfer mechanism'
related to Active Server Pages has been reported for Microsoft IIS
(Internet Information Services).

Web clients may send data to ASP (Active Server Pages) scripts in variable
sized chunks.  This is part of the HTTP protocol specification and is
known as a chunked encoding tansfer.  The chunked encoding transfer
mechanism must allocate a buffer in order to handle the transfer.

There is a lack of sufficient bounds checking on this buffer, which is
dynamically allocated by the ISAPI extension that handles ASP scripting.
This result is a remotely exploitable heap overflow.

Exploitation of this vulnerability may result in a denial of service or
allow for a remote attacker to execute arbitrary instructions on the
victim host.

This vulnerability is a variant of that discussed in BID 4485 "Microsoft
IIS Chunked Encoding Transfer Heap Overflow Vulnerability".

It is important to note that this BugTraq ID is an individual
vulnerability entry to followup the aggregated Multiple Remote IIS
Vulnerabilities alert released by SecurityFocus.

41. WatchGuard SOHO Firewall Vanishing IP Restrictions Vulnerability
BugTraq ID: 4491
Remote: Yes
Date Published: Apr 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4491
Summary:

SoHo firewall is a hardware firewall solution distributed and maintained
by WatchGuard.

A problem with the firewall package may allow remote users to gain
unauthorized to system resources.  The problem is in the design of the
firmware.

A problem introduced into the 5.0.35 firmware causes the dropping of
arbitrary firewall rules.  When a user configures IP restrictions on
certain IP addresses, the firewall may drop restriction entries
arbitrarily.  This could allow a remote user unintended access to a
supposedly secure network.

This problem has also been reported to occur when configuration changes
are made, such as enabling logging from the firewall admin console.

42. IBM Tivoli Storage Manager Client Acceptor Buffer Overflow Vulnerability
BugTraq ID: 4492
Remote: Yes
Date Published: Apr 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4492
Summary:

IBM Tivoli Storage Manager is a centralized management system providing
data protection for small and large organizations.

A feature called TSM client acceptor, manages the Web backup-archive and
scheduler client. A buffer overflow condition has been discovered in this
feature.

The TSM Client Acceptor does not perform adequate bounds checking. As a
result, submitting specially crafted data to the Client Acceptor (port
1581) could initiate an overflow.

This overflow could overwrite stack variables, including the return
address, and be used to execute arbitrary code as the web server process.
However, sending random data could cause the application to crash.

43. OpenBSD Default Crontab root Compromise Vulnerability
BugTraq ID: 4495
Remote: Unknown
Date Published: Apr 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4495
Summary:

OpenBSD ships with a number of cron jobs configured by default.  The tasks
are for the purpose of summarizing system information.

The mail(1) utility is used to send the summaries to the root user.  This
utility supports escaped characters in message text that allow for
commands to be executed during processing.  In recent versions of mail(1),
this feature is disabled in non-interactive mode to prevent the unintended
execution of malicious embedded command escape sequences.  For some
reason, the feature was reintroduced for non-interactive mode in the
version of mail(1) shipped with OpenBSD 2.9.

If attacker-supplied data can be included in the message text passed to
mail(1) when the cron job runs, commands specified by the attacker may be
executed as root.

The reports mailed to root include certain files on the filesystem.  The
filenames of the files are at least one place where attackers may embed
the escape sequence and command.  It may also be possible to embed the
malicious data in syslog entries.  If this can be accomplished, this
vulnerability may be remotely exploitable.

44. SGI IRIX Mail Core Dump Vulnerability
BugTraq ID: 4499
Remote: No
Date Published: Apr 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4499
Summary:

IRIX is the Unix derivative operating system distributed and maintained by
SGI.

A problem has been discovered in IRIX that may potentially lead to
elevated privileges.  The problem is in the mail program.

Under some circumstances, it may be possible for a local user to force the
mail program to core dump.  This problem is likely due to a buffer
overflow.  As the mail program is typically a setgid mail executable, this
could lead to a local privilege elevation.

This problem may make it possible for a local user to gain read access to
member's email, including that of root.

45. IBM Informix Web Datablade SQL Query HTML Decoding Vulnerability
BugTraq ID: 4498
Remote: Yes
Date Published: Apr 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4498
Summary:

Informix is an enterprise database distributed and maintained by IBM. The
Web Datablade Module for Informix SQL dynamically generates HTML content
based on Database data. Web Datablade is available for Apache, IIS, and
Netscape web servers, and a generic CGI version is provided for
alternative servers. It will execute under Windows NT, Linux and many
Unix-like systems.

Web Datablade supports the function $(WEBUNHTML), which is used to HTML
encode characters such as '"' which may be dangerous if blindly included
in an SQL query. Reportedly, SQL queries executed by Web Datablade perform
a HTML decode operation before execution, undoing the work of the
$(WEBUNHTML) function.

If a developer was to rely upon this function to sanitize user supplied
input, insecure code may be created. This could increase the possibility
of SQL injection vulnerabilities in projects developed within the Web
Datablade system.

Exploitation of this vulnerability will depend upon the details of
projects developed within the Web Database architecture.

46. IBM Tivoli Storage Manager Long Username Buffer Overflow Vulnerability
BugTraq ID: 4500
Remote: Yes
Date Published: Apr 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4500
Summary:

IBM Tivoli Storage Manager is a centralized management system providing
data protection for small and large organizations.

Due to inadequate bounds checking it is possible for a user to initiate a
buffer overflow. Supplying an unusually long username (approx 1976 chars)
to the HTTP port of the server (port 1580), could cause the overflow to
occur.

This overflow could overwrite stack variables, including the return
address, and be used to execute arbitrary code as the web server process.
However, sending random data could cause the application to crash.

47. InterNetNews Multiple Local Format String Vulnerabilties
BugTraq ID: 4501
Remote: No
Date Published: Apr 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4501
Summary:

The Internet Software Consortium (ISC) InterNetNews (INN) project is a
powerful, mature implementation of a usenet system, including a NNTP
server and a newsreading server. It is available for a wide range of Unix
based systems, including Linux.

Multiple vulnerabilities have been reported in two components of INN,
inews and rnews. Reportedly, both are vulnerable to locally exploitable
format string problems. Under some systems these binaries may be installed
suid root or sgid news, allowing a local attacker to gain elevated
privileges.

It has also been reported that insecure open() calls may exist in some
binaries included with INN. Further details are not currently available.

More recent versions of INN may share these problems, this has not however
been confirmed. More recent versions of INN are reported to run with fewer
permissions, reducing the privileges which may be gained through
exploitation.

48. IBM Informix Web Datablade Page Request SQL Injection Vulnerability
BugTraq ID: 4496
Remote: Yes
Date Published: Apr 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4496
Summary:

Informix is an enterprise database distributed and maintained by IBM. The
Web Datablade Module for Informix SQL dynamically generates HTML content
based on Database data. Web Datablade is available for Apache, IIS, and
Netscape web servers, and a generic CGI version is provided for
alternative servers. It will execute under Windows NT, Linux and many
Unix-like systems.

A vulnerability has been reported in some versions of Web Datablade.
Reportedly, it is possible to inject SQL commands into any page request
processed by Web Datablade. This may result in the disclosure of sensitive
information or increased access to the database.

When a page request is recieved by Web Datablade, a database query is made
to retrieve the page contents. This query includes user supplied data
taken from the URL requested, and is not properly sanitized. An attacker
may include the double quotation character '"' and additional SQL
statements, subverting the intended query.

Exploitation may expose or modify sensitive information within the
database, including database user and password information. Usage of
procedures within the database may impact the underlying operating system.
It has been reported that the FileToClob() function may be used to expose
the contents of system files, including /etc/passwd. Usage of the
webexplode() function may allow the execution of arbitrary additional SQL
statements.

There have been reports that a similar issue exists within the HTTP Basic
Authentication process used by Web Datablade, which also submits queries
to the database. However, detailed exploitation information is not
available for this case.

49. Caldera X11 Library -xrm Buffer Overflow Vulnerability
BugTraq ID: 4502
Remote: No
Date Published: Apr 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4502
Summary:

OpenUnix is a derivative of UnixWare, both Unix Operating System
derivatives distributed and maintained by Caldera.

A problem with a X11 library could allow an attacker elevated privileges.
The problem is in bounds checking.

Under some circumstances, it is possible to take advantage of a buffer
overflow that may yield elevated privileges.  Programs that have been
linked against the vulnerable X11 library do not perform proper bounds
checking when the -xrm flag is used.  This could allow the overwriting of
stack variables, including the return address, and code execution.

This vulnerability is likely to be exploited in executables that have been
linked against the library, and have setuid privileges.  Under these
circumstances, the program will execute code with the privileges of the
setuid user.  Other potential problems may arise from setuid programs that
use non-setuid programs linked against the vulnerable library.


III. SECURITYFOCUS NEWS AND COMMENTARY
------------------------------------------
1. Fears of a Security Brain Drain
By Annalee Newitz

Some computer security professionals are already feeling the pinch from a
new Defense Department policy discouraging contractors from hiring
non-citizens. The Pentagon says it's about loyalty; visa holders call it
classic xenophobia.

http://online.securityfocus.com/news/367

2. Cost, Mistrust Hold Back Security Outsourcing
By John Leyden, The Register

Fears about costs and reluctance to trust a third party are holding back
firms from outsourcing security.

http://online.securityfocus.com/news/366

3. McAfee OKs Network Associates' New Offer
By Dick Kelsey, Newsbytes

Web security firm Network Associates [NYSE:NET] said today that McAfee.com
[NASDAQ:MCAF] has approved a new buyout bid that is 15 percent greater
than its previous offer.

http://online.securityfocus.com/news/365

4. FBI: Businesses Loath To Report Hacks
By Brian Krebs, Newsbytes

Ninety percent of businesses and government agencies suffered hacker
attacks within the past year, yet only a third of those businesses
reported the intrusions to law enforcement, an FBI survey found.

http://online.securityfocus.com/news/364


IV.SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. EtherApe v0.8.2
by Juan Toledo, [email protected]
Relevant URL:
http://etherape.sourceforge.net/
Platforms: Linux, NetBSD, Solaris Size: 0 Kb
Summary:

EtherApe is a graphical network monitor for Unix modeled after etherman.
Featuring ether, ip and tcp modes, it displays network activity
graphically. Hosts and links change in size with traffic. Color coded
protocols display. It supports ethernet, fddi, ppp and slip devices. It
can filter traffic to be shown, and can read traffic from a file as well
as live from the network. Uses GNOME libraries and libpcap. Source. Linux
i386 binaries also available.

2. Nikto v1.017
by CIRT.net
Relevant URL:
http://www.cirt.net/code/nikto.shtml
Platforms: Perl (any system supporting perl), UNIX, Windows 2000, Windows
95/98, Windows NT, Windows XP
Summary:

Nikto is a PERL, open source web server scanner which supports SSL. Based
on LibWhisker, it has features which Whisker 1.4 lacks, including proxy
support, host authentication, and SSL. Nikto checks for (and if possible
attempts to exploit) remote web server vulnerabilities and
misconfigurations. It also looks for outdated software and modules, warns
of any version specific problems, supports scans through proxies (with
authentication), host Basic authentication and more. Data is kept in CSV
format databases for easy maintenance, and supports the ability to
automatically update local databases with current versions on the Nikto
web site.Nikto is a PERL, open source web server scanner which supports
SSL. Based on LibWhisker, it has features which Whisker 1.4 lacks,
including proxy support, host authentication, and SSL. Nikto checks for
(and if possible attempts to exploit) remote web server vulnerabilities
and misconfigurations. It also looks for outdated software and modules,
warns of any version specific problems, supports scans through proxies
(with authentication), host Basic authentication and more. Data is kept in
CSV format databases for easy maintenance, and supports the ability to
automatically update local databases with current versions on the Nikto
web site.

3. Dante v1.1.12
by Inferno Nettverk A/S, [email protected]
Relevant URL:
http://www.inet.no/dante/
Platforms: Digital UNIX/Alpha, IRIX, Linux, OpenBSD, Solaris, SunOS
Summary:

Dante is a free implementation of the proxy protocols socks version 4,
socks version 5 (rfc1928), and msproxy. It can be used as a firewall
between networks. The package consists of two parts, a socks server and a
proxy client which supports socks, msproxy, and HTTP proxies. Commercial
support is available.

4. File System Saint v0.24
by haver
Relevant URL:
http://insecure.dk/
Platforms: OpenBSD, Perl (any system supporting perl)
Summary:

File System Saint is a Tripwire-like file system integrity utility, with
primary focus on speed and ease of use. It is developed in Perl, and uses
Digest::MD5 for integrity checking. File System Saint will run on
virtually every platform that has Perl installed, even on Win32 with the
correct modules in place. It uses a flat-file database to store file
information.

5. ifmonitor v0.25
by Edson Medina
Relevant URL:
http://ifmonitor.preteritoimperfeito.com/
Platforms: Linux
Summary:

ifmonitor is a network interface traffic logger and grapher for Linux. It
does not depend on SNMP, and it is written in Perl/PHP. It uses MySQL to
store its logs.

6. Syslog-ng v1.5.16
by Balazs Scheidler, [email protected]
Relevant URL:
http://www.balabit.hu/products/syslog-ng/
Platforms: BSDI, Linux, Solaris
Summary:

syslog-ng, as the name shows, is a syslogd replacement, but with new
functionality for the new generation. The original syslogd allows messages
only to be sorted based on priority/facility pairs; syslog-ng adds the
possibility to filter based on message contents using regular expressions.
The new configuration scheme is intuitive and powerful. Forwarding logs
over TCP and remembering all forwarding hops makes it ideal for firewalled
environments.


V. SECURITY JOBS SUMMARY
------------------------
1. Andersen Fall Out! (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/00e801c1e268$425d9530$7caefea9@NONE

2. Seeking: Industrial Security Position (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

3. Netegrity/iPlanet UUM/Senior Security Engineer - NJ - #248 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

4. Security Analyst looking for opportunities (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

5. Engineering/Sales Lead - Network Security - Rosslyn, VA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

6. DIO/DIW Technical Team Lead/Mgr - Columbia, MD (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

7. Network Security Analyst - Ohio (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

8. New Business PKI Sales (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

9. Presales TC / Sales Jnr in Australia/UK/US (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

10. Sr. Embedded Security Engineer - Austin, TX (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

11. Software Reverse Engineering Guru (Brisbane, Australia) available for remote work (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/001c01c1e1c6$98b6b710$ed21dccb@greensun

12. Seeking InfoSec position - Chicago (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/20020411225855.INHF8815.mtiwmhc23.worldnet.att.net@mailhost.worldnet.att.net

13. TORONTO- Sales, (Referrals from pre/post Sales Eng.) Security (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

14. Security Engineer - Philadelphia, PA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

15. System Security Engineer in Washington, DC (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

16. Looking For InfoSec Position (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/58A264C6193AD51180350002A50920BD01997DB6@SYDEXC01

17. Pre-Sales Specialist - NSW Australia (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/D1A0678F4126D411B71E00062939B52D41B058@ALTUSYD01

18. ISO Security Job in AZ (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

19. Director of Professional Services - San Jose, CA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

20. Washington, DC Job Opening (#2) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

21. Washington, DC Job Opening (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

22. Forensics Engineers for a Gov't Agency CORRECTION (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

23. Director of Professional Services (San Jose, CA) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

24. Looking For InfoSec Position (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

25. Inside Sales - Boston, MA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

26. QUEBEC- 5 Bi-lingual Security Architects required (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

27. Security Analyst Position in Illinois (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

28. Information Systems Security Engineer opportunity - Chicago, IL area - FT (LOCAL CANDIDATES ONLY) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

29. Network Security Internship (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

30. Forensics Engineers for a Gov't Agency (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

31. SecurityFocus Vulnerability Analyst (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

32. Threat Analyst Position - SecurityFocus/ARIS (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

33. Network Security Analyst  -  Mechanicsburg, PA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

34. Security Pro / Nordic (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

35. Resume - Information Systems Security Professional (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

36. Seeking Info Security Opportunities in Philadelphia Area (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]


VI. INCIDENTS LIST SUMMARY
-------------------------
1. <victim>server formmail.pl exploit in the wild (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/Pine.GSO.4.44.0204121623460.19571-100000@westnet

2. <victim>server formmail.pl exploit in the wild (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

3. Possible DOS? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/20C62FD75D71F74786A0036B35A6CFF91853CA@newsub506.Int.Synapsegroupinc.com

4. FW: Footprints of ASP ISAPI filter buffer overflows (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

5. IGMP DOS Attack (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/Pine.LNX.4.44.0204112354510.18792-100000@shiva0.cac.washington.edu

6. IGMP DOS Attack (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

7. Redhat 6.2 Honeypot Hacked (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

8. iPlanet Server vulnerable to HTTP TCP HEAD Attack (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

9. AIM Backdoor? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

10. AIM Backdoor? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/002e01c1e00c$338024f0$76f56bd5@xbox

11. Probes to previously accessed FTPs and UNCs in XP (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/D5E5F4682E75D41185CD00D0B79DC56F04BB1AC4@exchfed01.federatedinv.com

12. I think I've been hacked...please help! (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

13. Probes to previously accessed FTPs and UNCs in XP (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]


VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. IIS .asp Remote Buffer Overflow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/007001c1e32a$be0ae080$4671e2c8@NE0TZ

2. Testing Of Windows 2000 and NT4 IIS .ASP Remote Buffer Overflow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

3. Re[2]: IIS .ASP Remote Buffer Overflow [testing for vulnerable installations] (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/005a01c1e2ff$aa4ac810$cd470544@CX2049796B

4. Re[4]: IIS .ASP Remote Buffer Overflow [testing for vulnerable installations] (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/000601c1e2f9$53f56610$cd470544@CX2049796B

5. Testing Of Windows 2000 and NT4 IIS .ASP Remote Buffer Overflow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

6. Re[2]: Windows 2000 and NT4 IIS .ASP Remote Buffer Overflow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/000701c1e274$b2fb1e50$f9280b0a@kounnes

7. IIS .ASP Remote Buffer Overflow [testing for vulnerable installations] (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/00cf01c1e26f$98f14340$cd470544@CX2049796B

8. Windows 2000 and NT4 IIS .ASP Remote Buffer Overflow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

9. test script for ASP buffer overflow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

10. Buffer overflow or overrun? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/OF173A46C2.C4219D8B-ON03256B99.0058B7F1-03256B99.005A0803@fti.com.br

11. PHP Nuke All version - ("viewdownload" Path disclosure vulns) +(some XSS) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

12. Security holes  : D-Book, CBook, IcrediBB (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

13. Smashing Windows (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

14. Windows 2000 and NT4 IIS .ASP Remote Buffer Overflow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

15. Security holes in ForamiX (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

16. Security holes in WoltLab Burning Board (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

17. Studying buffer overflows [maybe OT] (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

18. Cross Site Scripting Vulnerability (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

19. Techniques for Vulneability discovery (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

20. Hack Proofing Your Network Second Edition (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

21. Techniques for Vulneability discovery (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

22. Security holes in ASP-Nuke (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

23. Security holes in Powerboard forum (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

24. combinations of 4 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

25. Techniques for Vulnerability discovery (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAA+8DoZCJ8SEaYk5pn4rrIf8KAAAAQAAAALrjIIaIxHE+qKs/tTM/[email protected]

26. JAVA more insecure than true compiled code? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

27. re: combinations of 4 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

28. hello (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

29. Exploiting the race conditions in logwatch. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

30. UBB Vuln (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

31. security issue at hypovereins bank (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

32. hello (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]


VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. MBSA and MS's attempts at "security" (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

2. net use and LM / NTLM (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

3. Peculiar login troubles. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

4. Users slam Microsoft Security Analyser (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

5. MBSA and MS's attempts at "security" (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

6. URLScan Documentation Contradiction (I think) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/BB7FD4FF9E440648A731452E5D341FB0C66615@hitsexchange01.advance-med.com

7. Info about missing HTML files in MBSA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

8. Security policy in the Group policy objects are applied successfully but then .asp pages fails (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/004e01c1e201$30b8b2e0$c901070a@admin2002

9. Microsoft Baseline Security Analyzer v1.0 Released 8th April (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/0036E50ED28FDC40B5123322012AF3DD0BCA4B@topdom1.topas-consulting.com

10. VPN / IPSEC (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/0036E50ED28FDC40B5123322012AF3DD0BCA4A@topdom1.topas-consulting.com

11. Peculiar login troubles. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

12. January Security Rollup package listed in Windows update... (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

13. Securing Microsoft Windows 2000 Terminal Services with Terminal S ervices Advanced Client (TSAC) enabled (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

14. Editing MS-2000 Firewall Rules (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

15. Problem with auto unpacking Hotfixes (from 1 machine only) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/E7EAF01D6CD3D411938F00508BAF919B0504682A@simail17.server.bosch.com

16. L2tp over Ipsec w2k against Nortel Switch (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/CDEBAB5BBFE0024AABEAF438FB2A4D07013802DF@exgau100qsm00.oceania.corp.anz.com

17. More about MBSA and MS's attempts at "security" (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

18. Microsoft Baseline Security Analyzer v1.0 Released 8th April (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

19. Fwd: L2tp over Ipsec w2k against Nortel Switch (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

20. Free/Shareware IPSec code or apps for Windows (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

21. VPN / IPSEC (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

22. Free/Shareware IPSec code or apps for Windows (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

23. Microsoft PPTP (Was: Internet Services Manager) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/4652644B98DFF34696801F8F3070D3FE01DB915B@D2CSPEXM001.smartpipes.com

24. msxml3.dll file version to high after applying set of (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

25. Microsoft PPTP (Was: Internet Services Manager) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

26. Internet Services Manager (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

27. Detailed Port Filtering (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

28. Group Policy denies access to some programs (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

29. Using syslog clients (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

30. SecurityFocus Microsoft Newsletter #81 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

31. Group Policy denies access to some programs (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/C14780631B92D311B50400005A42A402062A8364@S-EMAIL2

32. Editing MS-2000 Firewall Rules (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

33. SOAP toolkit V2 security and vulnerabilities (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/E48EF4B51A3A47468CEA37E874AA16D86051E3@eidyia.spherebusinessgroup.com

34. IE6 Problems Update (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/000401c1df3a$ee727420$0201a8c0@neurotika

35. msxml3.dll file version to high after applying set of  hotfixes (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

36. Windows NT 4.0 Print Spooler Security (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

37. Windows NT 4.0 Print Spooler Security (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

38. msxml3.dll file version to high after applying set of hotfixes (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

39. Cryptographic Authentication Techniques - NTLM ? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

40. Problem with auto unpacking Hotfixes (from 1 machine only) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/761DBCC144B6334A81251171C684A6FB73C517@mailserver-2k.fireapple.com

41. Internet Services Manager (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]


IX. SUN FOCUS LIST SUMMARY
----------------------------
1. RSA SecureID on Solaris (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/Pine.SOL.4.10.10204092104290.26282-100000@roadrunner.eng.auburn.edu

2. RSA SecureID on Solaris (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/002101c1e013$c8a7dfd0$0200000a@shamah

3. Good news: /dev/random from Sun for Solaris 8 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/6062E6342806D311836F00AA0020315702EBC0C8@exchuser.demorgan.com.au

4. Disabling Unnecessary Services from inetd.conf File (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]

5. Disabling Unnecessary Services from inetd.conf File (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/F34B3C833DDBD311B77800508B0CB0BF07613D39@nwdc02ex


X. LINUX FOCUS LIST SUMMARY
---------------------------
1. arp flood (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]


XI. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored by: NetScreen

PROTECT YOUR NETWORK FROM INTERNAL & EXTERNAL THREATS

NetScreen, a leader in enterprise security, can help, offering the
broadest range of security solutions available. Our new security
appliances are optimized to help guard networks from the effects of
traditional and emerging threats, such as Trojan Horses, worms and
viruses. To find out more about protecting your network from the inside
and out, go to www.netscreen.com/bcr_eweekly

-------------------------------------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.