SecurityFocus Newsletter #141

John Boletta <[email protected]>
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #141
-----------------------------

This newsletter is sponsored by SecurityFocus (www.securityfocus.com)

Attention Non-profits and Universities: Sign-up now for preferred pricing
on the only global early-warning system for cyber attacks - SecurityFocus
ARIS Threat Management System.

Click here for more info
http://www.securityfocus.com/corporate/products/pdpsection.shtml
-------------------------------------------------------------------------------

I. FRONT AND CENTER
     1. VBA Emulation: A Viable Method of Macro Virus Detection? Part One
     2. Openwall: Improving Security with the Openwall Patch
     3. Network Intrusion Detection Signatures, Part Five
     4. Closing the Spycam Sniffer Loophole
     5. Peddling Snake Oil as Security
II. BUGTRAQ SUMMARY
     1. Bradford Barrett Webalizer Reverse DNS Buffer Overflow...
     2. Microsoft Internet Explorer History List Script Injection...
     3. Microsoft BackOffice Server Web Administration Authentication...
     4. WebTrends Reporting Center GET Request Buffer Overflow...
     5. Microsoft Internet Explorer Dialog Same Origin Policy Bypass...
     6. Microsoft Windows 2000 Lanman Denial of Service Vulnerability
     7. Sambar Server Script Source Disclosure Vulnerability
     8. AOLServer Developer API Ns_PdLog() Format String Vulnerability
     9. MPE/iX Malformed IP Packet Denial of Service Vulnerability
     10. Pipermail/Mailman Insecure Archives Permissions Vulnerability
     11. PVote Unauthorized Administrative Password Change Vulnerability
     12. PVote Poll Content Manipulation Vulnerability
     13. ColdFusion DOS Device File Request System Information...
     14. FreeBSD Routing Table ICMP Echo Reply Denial Of Service...
     15. Compaq Tru64 C Library Buffer Overflow Vulnerability
     16. Microsoft IIS CodeBrws.ASP File Extension Check Out By One...
     17. MHonArc HTML Script Filter Bypass Vulnerability
     18. Symantec Norton Personal Firewall 2002 Fragmented Packet...
     19. SSH Restricted Shell Escaping Command Execution Vulnerability
     20. Oracle E-Business Suite 11i Unauthorized PL/SQL Procedure...
     21. XPilot Server Remote Buffer Overflow Vulnerability
     22. IcrediBB Script Injection Vulnerability
     23. Foundstone FScan Banner Grabbing Format String Vulnerability
     24. WorkforceROI XPede Unprotected Administrative Facilities...
     25. XPede DataSource.ASP Information Disclosure Vulnerability
     26. WorkforceROI XPede Sprc.ASP SQL Injection Vulnerability
     27. WorkforceROI XPede Weak File Protection Vulnerability
     28. WorkforceROI XPede Arbitrary Time Sheet Disclosure Vulnerabiltiy
     29. Apache Tomcat System Path Information Disclosure Vulnerability
     30. OpenSSH Kerberos 4 TGT/AFS Token Buffer Overflow Vulnerability
     31. Snitz Forums 2000 Members.ASP SQL Injection Vulnerability
     32. PostBoard BBCode IMG Tag Script Injection Vulnerability
     33. PostBoard Topic Title Script Execution Vulnerability
     34. PostBoard BBCode Denial Of Service Vulnerability
     35. Nortel CVX 1800 Multi-Service Access Switch Default SNMP...
     37. Burning Board URL Parameter Manipulation Vulnerability
     38. Mirabilis ICQ .hpf Denial of Service Vulnerability
     39. Demarc PureSecure Authentication Check SQL Injection...
     40. HP Photosmart Mac OS X Print Driver Weak File Permissions...
     41. Microsoft Internet Explorer Unicode Character Handling DoS...
     42. Multiple Microsoft Products for MacOS File URL Buffer Overflow...
     43. Symantec Norton Personal Firewall 2002 Portscan Protection...
     44. Oracle 9i ANSI Outer Join Access Control Bypass Vulnerability
     45. Symantec Raptor / Enterprise Firewall FTP Bounce Vulnerability
     46. FreeBSD 4.5 syncache / syncookies Denial Of Service Vulnerability
     47. Microsoft IIS CodeBrws.ASP Source Code Disclosure Vulnerability
     48. AOL Instant Messenger Arbitrary File Creation Vulnerability
     49. TalentSoft Web+ WML Request Cookie Buffer Overflow Vulnerability
III. SECURITYFOCUS.COM NEWS ARTICLES
     1. GovNet Plans Moving Forward
     2. Ashcroft, Ellison, Win 'Big Brother' Awards
     3. National ID Plans Face Hurdles
     4. FTC Chairman Pushes Net Crime Vigilance, Not New Laws
     5. New Take On Klez Worm Spreading
     6. Privacy Worries, Net Activism Top Privacy Show Agenda
IV.SECURITY FOCUS TOP 6 TOOLS
     1. Logwatch v2.8.5
     2. TinyCA v0.3.0
     3. Castellan Sentry v0.01
     4. Nessus v1.2.0
     5. lcrzoex v4.08
     6. Firewall by Jim v0.28
V. SECURITYJOBS LIST SUMMARY
     1. Positions (Thread)
     2. Senior Security Guy Looking For Interesting Gig (Thread)
     3. Seeking Security Engineer (Thread)
     4. Seeking Security Position (Thread)
     5. Application Security - Chicago - Greythorn (Thread)
     6. Security Test Engineer (Austin, TX) (Thread)
     7. Senior Security Solutions Sales Executive - #693 - NY, NJ, CT...
     8. Seeking a SR Information Security Engineer (Thread)
     9. Looking for Consulting Position (Thread)
     10. Security Consultant (Thread)
     11. Amendment to Andersen Fall Out. (Thread)
     12. QA Hardware Engineer IT Security - UK (Thread)
     13. Head of Information Security reqd for Melbourne, Australia...
     14. IT Security Sales Director (Thread)
     15. Position available at Microsoft in Passport group for recent...
     16. Penetration testing in Dubai (Thread)
     17. Principal Security Consultant for Europe (Thread)
     18. Lab Researcher/Engineer Position in DC Metro Area (Thread)
     19. Security Systems Engineer (Thread)
     20. Systems Security Administrator LFJ (Thread)
     21. Sr. Internetworking & Security Expert , Jersey City (Thread)
     22. Sprint Fall Out! (Thread)
     23. Chief Information Security Officer - #702 - NY (Thread)
VI. INCIDENTS LIST SUMMARY
     1. illogic rootkit (Thread)
     2. Anyone caught a packet of ... ? (Thread)
     3. Wu-ftpd 2.6.2 (Thread)
     4. illogic rootkit (Thread)
     5. known expoit for wu-ftpd 2.6.2(1) ?? (Thread)
     6. distributed ftp scan (Thread)
     7. Fwd: ms02-018 IS dangerous after all (Thread)
     8. HTTP CONNECT attempts (Thread)
     9. Strange UDP Activity (Thread)
     10. Vacation Troller, Please Ignore. (Thread)
     11. Strange UDP Activity (Thread)
     12. Redhat 6.2 Honeypot Hacked (Thread)
     13. <victim>server formmail.pl exploit in the wild (Thread)
     14. Botnet/Domains (Thread)
     15. Strange scans (Thread)
     16. Strange scans (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. Remote MS02-18 Patch Checker (Thread)
     2. Cross site scripting @verisign.com and @cybercash.com (Thread)
     3. Cross site scripting in almost every mayor website (Thread)
     4. OpenSSH 2.2.0 - 3.1.0 server contains a locally exploitable...
     5. OpenSSH 2.2.0 - 3.1.0 server contains a locally exploitable...
     6. weird IE6 crash (Thread)
     7. Keyservers Cross Site Scripting (When CSS Gets Dangerous) (Thread)
     8. Where does the hole lie? (Thread)
     9. buffer overflow with greek characters, NIX (Thread)
     10. buffer overflow with greek characters, NIX (yeah yeah again)...
     11. Cisco VPN client (Thread)
     12. Cisco VPN client (Thread)
     13. Smalls holes on 5 products #1 (Thread)
     14. greek characters buffer overflow, AGAIN! (Thread)
     15. Spanning Tree Switch Exploits? Fact or Fiction? (Thread)
     16. bufferoverflow posadis m5pre - ( POC number 2 ) (Thread)
     17. gawk bufferoverflow (Thread)
     18. bufferoverflow posadis m5pre2 (Thread)
     19. Testing Of Windows 2000 and NT4 IIS .ASP Remote Buffer...
     20. Challenge (Thread)
     21. Challenge (Thread)
     22. [VulnWatch] greek characters buffer overflow, AGAIN! (Thread)
     23. Ddate Proof Of Concept Exploit and Bug details (Thread)
     24. greek characters buffer overflow, AGAIN! (Thread)
     25. Oracle Databases Allow HTML/SQL injection (Thread)
     26. FileSeek cgi script advisory (Thread)
     27. Fw: URLSCAN - Error 50. Ideas? (Thread)
     28. ASP & HTR Overflows (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. windows domain question (Thread)
     2. windows domain question (Thread)
     3. OWA and URLScan (Thread)
     4. URLScan 2.5 SRP (Thread)
     5. Microsoft Security Bulletin MS01-022 (Thread)
     6. Ensuring Disabling/Uninstalation of Windows XP Firewall in LAN...
     7. Microsoft Cluster in DMZ - Need Advice (Thread)
     8. OWA and URLScan (Thread)
     9. Ensuring Disabling/Uninstalation of Windows XP Firewall in...
     10. Win 98 Security (Thread)
     11. Microsoft Security Bulletin MS01-022 (Thread)
     12. Win 98 Security (Thread)
     13. Ensuring Disabling/Uninstalation of Windows XP Firewall in...
     14. Problem with auto unpacking Hotfixes (from 1 machine only)...
     15. ms02-018 IS dangerous after all (Thread)
     16. Any known issue with 10 April 2002 Cumulative Patch for II...
     17. FW: Free HFNetChkPro Invitation (Thread)
     18. Fwd: ms02-018 IS dangerous after all (Thread)
     19. SSL directory structure issue (Thread)
     20. Any known issue with 10 April 2002 Cumulative Patch for  II...
     21. Any known issue with 10 April 2002 Cumulative Patch for IIS...
     22. Administrivia: Users slam Microsoft Security Analyser (Thread)
     23. SSL directory structure issue (Thread)
     24. Posters Slam Microsoft Training (Thread)
     25. Users slam Microsoft Security Analyser (Thread)
     26. Users slam Microsoft Security Analyser (Thread)
     27. SecurityFocus Microsoft Newsletter #82 (Thread)
     28. Posters Slam Microsoft Training (Thread)
     29. URLSCAN error 50 (Thread)
     30. Scanning MS DHCP networks. Reading dhcp.mdb (Thread)
     31. Scanning MS DHCP networks. Reading dhcp.mdb (Thread)
     32. Anyone familiar with bitvise's winsshd? (Thread)
     33. VPN / IPSEC (Thread)
     34. Peculiar login troubles. (Thread)
     35. authentication  NTLM (Thread)
IX. SUN FOCUS LIST SUMMARY
     1. Looking for ftp over SSL (TLS) daemon... (Thread)
     2. Looking for ftp over SSL (TLS) daemon... (Thread)
X. LINUX FOCUS LIST SUMMARY
     1. HiverCon 2002 (Thread)
     2. No Root Shell with SUID /bin/bash (Thread)
XI. SPONSOR INFORMATION


I. FRONT AND CENTER
-------------------
1. VBA Emulation: A Viable Method of Macro Virus Detection? Part One
by Gabor Szappanos

This article is the first in a two-part series that will examine some of
the problems that exist with emulation, with the end in mind of
determining whether or not it is a realistic anti-virus method.

http://online.securityfocus.com/infocus/1571

2. Openwall: Improving Security with the Openwall Patch
by Zeshan Ghory

This article will examine the Openwall Linux kernel Patch, one of the
best-known kernel hardening patches. It will explain how to install the
patch and will examine its main features. Using the patch will require a
basic understanding of how to recompile the kernel. Some of the
explanations will assume a basic knowledge of the C programming language,
but it is not essential to the usage of the patch.

http://online.securityfocus.com/infocus/1570

3. Network Intrusion Detection Signatures, Part 5
by Karen Kent Frederick

This is the fifth and final installment in a series of articles on
understanding and developing signatures for network intrusion detection
systems. In the previous article, we looked at the topic of protocol
analysis, meaning that the intrusion detection system actually understands
how various protocols, such as FTP, are supposed to work. We initially
looked at protocol analysis as it applied to a single request or response.
In this article, we will extend this discussion by looking closely at
stateful protocol analysis, which involves performing protocol analysis
for an entire connection or session, capturing and storing certain pieces
of relevant data seen in the session, and using that data to identify
attacks that involve multiple requests and responses.

http://online.securityfocus.com/infocus/1569

4. Closing the Spycam Sniffer Loophole
by Mark Rasch

Those cheap wireless video cameras hawked by annoying pop-up ads can be
intecepted by anyone with a few hundred dollars and a voyeristic bent.
There's no federal law against it, but there should be.

http://online.securityfocus.com/columnists/76

5. Peddling Snake Oil as Security
Richard Forno

Recently, I received an invitation to speak at a plenary session for an
upcoming conference on wireless security. While the conference venue was
first-rate and they were covering all my expenses, I had to be honest with
the conference coordinators and decline the invitation.

http://online.securityfocus.com/columnists/75


II. BUGTRAQ SUMMARY
-------------------
1. Bradford Barrett Webalizer Reverse DNS Buffer Overflow Vulnerability
BugTraq ID: 4504
Remote: Yes
Date Published: Apr 15 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4504
Summary:

Webalizer is a web server log file program, which generates web site
statistic log files. Log files produced include referrer information,
browser information, web site Hits, Files accessed etc. These log files
are generated in HTML format, so administrators can view them in a web
browser.

A remote buffer overflow vulnerability has been reported in some versions
of Webalizer. A malicious party with control over a DNS server may send
malicious data to Webalizer when a reverse DNS lookup is performed. This
may in turn overflow a memory buffer.

The vendor has reported that this vulnerability is not exploitable for
code execution, due to both memory layout of the process and character
restrictions on the injected data. However some denial of service attacks
may be possible, impacting the ability of an administrator to extract data
from system logs.

It has been reported that the reverse DNS lookup functionality of
Webalizer is disabled by default.

2. Microsoft Internet Explorer History List Script Injection Vulnerability
BugTraq ID: 4505
Remote: Yes
Date Published: Apr 15 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4505
Summary:

A vulnerability has been reported in some versions of Internet Explorer.
It is possible to inject JavaScript code into the browser history list,
and execute it within any page context given appropriate user interaction.

Internet Explorer stores javascript: URLs in the browser history list.
Script executed within the javascript: URL will inherit the security zone
of the last viewed page. This provides protection against javascript: URLs
included within a maliciously constructed web page. However, a user may
navigate to a javascript: URL using the 'Back' button in their browser.
This may result in the injected script code executing within the context
of another page.

It is possible to construct a javascript: URL which will detect the usage
of the 'Back' button, and behave differently under these conditions. This
allows an attacker to construct a javascript: URL which will initially
redirect the user to an arbitrary location, then perform additional
actions when the 'Back' button is used. This can result in arbitrary
script executing within an arbitrary context, so long as the user behaves
as anticipated.

Exploitation of this vulnerability can result in JavaScript code executing
within the context of an arbitrary site, or within the Local Computer
context. This can result in the disclosure of cookie data or local file
contents.

This behavior has been reported in versions 6.0 and 5.5 of IE. Other
versions of Internet Explorer may share this vulnerability. This has not,
however, been confirmed.

3. Microsoft BackOffice Server Web Administration Authentication Bypass Vulnerability
BugTraq ID: 4528
Remote: Yes
Date Published: Apr 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4528
Summary:

Microsoft BackOffice suite of products include a web based administration
ASP based application that runs on IIS. The BackOffice Web Administrator
component of BackOffice Server contains a design flaw, which could allow
for unauthorized users to bypass authentication.

This is achieved when submitting an HTTP request directly to services.asp
(Boadmin/Backoffice/Services.asp). No credentials are required to enter
the administration page, and such a request will bypass the login screen.

It should be noted that this issue only occurs if basic authentication is
being used. In addition by default, the BackOffice Web Administrator is
configured to accept connections only from the Localhost (127.0.0.1).
However, it is likely that administrators have changed this setting in
order to use the administration interface for remote access.

4. WebTrends Reporting Center GET Request Buffer Overflow Vulnerability
BugTraq ID: 4531
Remote: Yes
Date Published: Apr 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4531
Summary:

WebTrends Reporting Center is used to organize and present usage
information for multiple server web environments. Reporting Center is
available for Windows NT and 2000, Linux and Solaris.

A vulnerability has been reported in some versions of WebTrends Reporting
Center. If an oversized GET request is received by the server, a memory
buffer will overflow. Exploitation may result in the execution of
arbitrary code with SYSTEM privileges. Sending arbitrary data may cause
the server to crash, resulting in a denial of service condition.

This attack is only possible for an authenticated user. However, anonymous
authentication is also sufficient, meaning that any public reports
produced by WebTrends may present an avenue of attack.

This vulnerability has only been confirmed to exist on Windows versions of
the Reporting Center.

5. Microsoft Internet Explorer Dialog Same Origin Policy Bypass Vulnerability
BugTraq ID: 4527
Remote: Yes
Date Published: Apr 16 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4527
Summary:

It is possible to bypass the origin policy used by Internet Explorer for
the showModalDialog and showModelessDialog functions. Under some
circumstances, it may be possible to execute script code in sensitive
contexts.

Microsoft Internet Explorer includes support for dialog windows through
script calls to the two functions showModalDialog and showModelessDialog.
These functions accept a URL location for the dialog content, and an
option argument parameter to allow data to be passed to the dialog from
the calling page.

A check is done to ensure that data is only passed to dialogs located in
the same domain, port and protocol as the calling page. This prevents a
malicious party from injecting content into arbitrary dialogs. However, if
the URL provided as the dialog source redirects to a second location, only
the first is subject to this security check.

As a result, a malicious party may open a dialog with a URL which will
pass this check, and then redirect the dialog to an arbitrary file. The
security check will be passed based on the initial provided location, and
attacker supplied data will be passed to the second dialog.

The consequences of exploitation are highly dependant on the functionality
of the targetted dialog. It is likely that this vulnerability could lead
to subversion of information or social engineering attacks.

It has been demonstrated to possibly inject script code into dialogs
included by default with versions of Internet Explorer 5.0, 5.5 and 6.0.
This can be used to execute arbitrary script code in the local computer
context.

6. Microsoft Windows 2000 Lanman Denial of Service Vulnerability
BugTraq ID: 4532
Remote: Yes
Date Published: Apr 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4532
Summary:

An issue has been discovered in Windows 2000, which could cause a denial
of system services.

Submitting malformed data to port 445 could cause the Lanman service to
consume high CPU and Kernel mode memory usage.

A restart of the server may be required in order to regain normal
functionality. Although reports indicate that in extreme cases
administrators have received the error message "You do not have
permissions to shutdown or restart this computer."

7. Sambar Server Script Source Disclosure Vulnerability
BugTraq ID: 4533
Remote: Yes
Date Published: Apr 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4533
Summary:

An issue has been discovered in Sambar Server, which could allow a user to
reveal the source code of script files.

Submitting a request for a known script file along with a space and null
character (%00), will successfully bypass the serverside URL parsing.

For example:

http://target/cgi-bin/file.jsp_%00

If successfully exploited this vulnerability could lead to the disclosure
of sensitive information contained within privileged pages. This
information may assist in more "intelligent" attacks. In addition,
bypassing the serverside URL parsing function could allow for further
attacks against the host.

8. AOLServer Developer API Ns_PdLog() Format String Vulnerability
BugTraq ID: 4535
Remote: Yes
Date Published: Apr 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4535
Summary:

AOLServer is the open source, freely available HTTP server maintained in
cooperation between AOL and the open source developer community. It offers
features such as TCL interpretation, and dynamic content handling.

A format string vulnerability has been reported in the external database
driver proxy daemon API provided with AOLServer. The function Ns_PdLog()
included as part of this package passes external data to the syslog()
function as a format string.

As a result, software developed using this library may contain format
string vulnerabilities if it in turn passes user supplied data to the
Ns_PdLog() function. Exploitation of format string vulnerabilities can
lead to the execution of arbitrary code.

9. MPE/iX Malformed IP Packet Denial of Service Vulnerability
BugTraq ID: 4536
Remote: Yes
Date Published: Apr 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4536
Summary:

HP has announced that a remotely exploitable vulnerability exists in HP
MPE/iX.

It has been reported that a malformed IP packet will cause the system to
fail.  It may not function until it has been manually restarted by an
administrator.  While the nature of the malformed packet is not known, it
is assumed that any remote attacker may construct it and transmit it to
the target system.

Upon receiving the packet, the device reports the error message 'SA1457
out of i_port_timeout.fix_up_message_frame' before failing.

10. Pipermail/Mailman Insecure Archives Permissions Vulnerability
BugTraq ID: 4538
Remote: No
Date Published: Apr 16 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4538
Summary:

Pipermail is a mailing list archiver, which is no longer being maintained.
A newer version of Pipermail has been bundled into the Mailman mailing
list manager.  Both programs will run on most Unix and Linux variants.

The file which contains the mailing list archive is by default
world-executable.  As a result, local attackers may read mailing list
messages archived by Pipermail (and Mailman) due to the insecure
permissions on the files involved.  To exploit this issue the attacker
must be able to antipicate the location of the files on the local
filesystem.

Furthermore, because of the design of the program these permissions must
exist if the archive files are to be read by a legitimate user.

This is only a security concern if the archives are of a private mailing
list.

11. PVote Unauthorized Administrative Password Change Vulnerability
BugTraq ID: 4541
Remote: Yes
Date Published: Apr 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4541
Summary:

PVote is a web voting system written in PHP.  It will run on most Unix and
Linux variants as well as Microsoft Windows operating systems.

It is possible to change the administrative password by submitting a
malicious web request.  The attacker does not require the old
administrative password to change the new one.  The structure of such a
malicious web request is as follows:

http://target/pvote/ch_info.php?newpass=password&confirm=password

The ch_info.php script will accept arbitrary attacker-supplied values for
the newpass and confirm values without requiring any sort of
authentication.

12. PVote Poll Content Manipulation Vulnerability
BugTraq ID: 4540
Remote: Yes
Date Published: Apr 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4540
Summary:

PVote is a web voting system written in PHP.  It will run on most Unix and
Linux variants as well as Microsoft Windows operating systems.

It is possible for a remote attacker to add/delete web polls just by
manipulating the values of URL parameters.  No authentication credentials
are required for the attacker to perform these actions.  This may enable a
remote attacker to manipulate some of the content on a website running the
voting system.

13. ColdFusion DOS Device File Request System Information Disclosure Vulnerability
BugTraq ID: 4542
Remote: Yes
Date Published: Apr 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4542
Summary:

Allaire Macromedia ColdFusion is a web application server. This issue
impacts versions of ColdFusion for the Microsoft Windows family of
operating systems.

Submitting a web request for certain non-existant .cfm or .dbm files will
cause the ColdFusion host to return an error message containing the path
to the web root. This has also been known to occur when submitting a
request for a DOS-device (CON, AUX, PRN, NUL) with either a .cfm or .dbm
extension.

Successful exploitation of this issue will give an attacker sensitive
information about the system configuration, and may allow further,
intelligent attacks.

14. FreeBSD Routing Table ICMP Echo Reply Denial Of Service Vulnerability
BugTraq ID: 4539
Remote: Yes
Date Published: Apr 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4539
Summary:

FreeBSD is a freely available, open source operating system based off the
original Berkeley Software Distribution.  FreeBSD is maintained and
developed by the FreeBSD project.

A problem with FreeBSD could make it possible for a remote user to crash a
vulnerable system.  The problem is in the handling of some types of
network traffic.

When a FreeBSD system initiates a connection to a host for the first time,
an entry for the route to that host is added to the system routing table.
This route is maintained in the table until no further connections to the
host exist, at which point it is removed.

Under some circumstances, it is possible to crash a FreeBSD system.  When
an ICMP echo reply is sent to a vulnerable system, the number referencing
the amount of hosts with current connections via that route is never
decremented after termination of the ICMP traffic.  The memory allocated
for the routing table entry would never be freed.

This problem could make it possible for a remote user to exhaust the
memory resource of a vulnerable system, resulting in a denial of service.

15. Compaq Tru64 C Library Buffer Overflow Vulnerability
BugTraq ID: 4544
Remote: No
Date Published: Apr 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4544
Summary:

Compaq has reported a buffer overflow in the Tru64 C library.  The
condition is related to the handling of the LANG and LOCPATH environment
variables.  The overflow may be triggered by values of LOCPATH and LANG
that are of excessive length.

While the actual cause is not known, it is believed that this is a
stack-based overflow.  Because the overflow exists in the C library, it is
probable that almost all binary programs on the system are vulnerable.
The most likely vector of attack for an attacker would be local,
setuid/setgid applications.  Successful exploitation could yield elevated
privileges for the attacker.

This vulnerability may also be remotely exploitable through the telnet
service.  The telnet protocol facilitates transmission of environment
variables from the client to the server.  Though it appears possible, the
ability to exploit this vulnerability remotely has not yet been confirmed.
It should be assumed that this vulnerability is remotely exploitable
through the telnet service.

16. Microsoft IIS CodeBrws.ASP File Extension Check Out By One Vulnerability
BugTraq ID: 4543
Remote: Yes
Date Published: Apr 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4543
Summary:

Microsoft IIS 5.0 ships with a sample script that may be used to view the
source code of other scripts in the sample scripts (/IISSAMPLES)
directory.

The vulnerable script (CodeBrws.asp) validates user input to ensure that
any file viewed has one of a select set of file extensions, namely .html,
.htm, .asp and .inc. This check is performed by testing a substring taken
from the end of the requested file path.

An out by one error has been reported in this check. The section of the
path tested is larger than required. As a result, provided file extensions
may include an additional character and still pass the test. For example,
.aspx files used by the .NET architecture may also be viewed. This may
allow an attacker to view sensitive information contained in files not
believed to be exposed.

If used in conjunction with the issues discussed in BID 4525, this may
expose files outside of the sample script directory.

17. MHonArc HTML Script Filter Bypass Vulnerability
BugTraq ID: 4546
Remote: Yes
Date Published: Apr 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4546
Summary:

MHonArc is a Perl program designed to automatically parse email into a
HTML based archive format. MHonArc includes filtering support designed to
strip dangerous tags from HTML email during this process, eliminating
JavaScript.

A vulnerability has been discovered in some versions of MHonArc.
Maliciously constructed HTML mail may bypass this filtering process and
inject valid script code into the archive. This can be accomplished in
several ways, including the following:

<SCR<SCRIPT></SCRIPT>IPT>alert(document.domain)</SCR<SCRIPT></SCRIPT>IPT>
<IMG SRC=javascript:alert(document.domain)> <B
foo=&{alert(document.domain)};>

Exploitation may result in attacker supplied script code executing within
the context of the MHonArc archive site.

18. Symantec Norton Personal Firewall 2002 Fragmented Packet Vulnerability
BugTraq ID: 4545
Remote: Yes
Date Published: Apr 16 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4545
Summary:

Symantec Norton Personal Firewall 2002 (NPW)is a firewall for home and
small office machines based on some versions of the Microsoft Windows
operating systems.

It has been reported that NPW may not adequately filter packet fragments.
In particular, denial of service attacks based on fragmented packets have
been reported to work effectively against systems protected by NPW. This
may happen even if the attacking address is entirely blocked from the
system.

Reportedly, this occurs with the block fragmented IP packets feature
enabled.

This may expose protected machines to attacks, in the event that other
software vulnerabilities exist. Further information on the nature of this
issue is not currently available.

These issues have not been confirmed.

19. SSH Restricted Shell Escaping Command Execution Vulnerability
BugTraq ID: 4547
Remote: No
Date Published: Apr 18 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4547
Summary:

SSH (and derivatives) is the protocol Secure Shell protocol
implementation.  It is available for various operating systems, although
this vulnerability affects operating systems such as Unix and Linux.

A problem with the package could make it possible for remote users to
execute unauthorized programs.  The problem is in the handling of command
line execution.

Most versions of SSH permit the execution of commands remotely via the
supplying the command name wrapped in single quotes.  This can allow
remote users to execute commands without logging directly into a shell on
the system.

It has been reported that it is possible for a remote user to upload files
to world-writeable directories, and execute commands from world-writeable
directories.  In doing so, a user may be able to upload a script, and
execute the script to gain access to a regular shell on the system.  This
would allow the user unrestricted, but unprivileged access.

SecurityFocus staff have been unable to reproduce this vulnerability with
OpenSSH version 3.1p1.

20. Oracle E-Business Suite 11i Unauthorized PL/SQL Procedure Access Vulnerability
BugTraq ID: 4551
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4551
Summary:

Oracle has reported the existence of a vulnerability in Oracle E-Business
Suite 11i.  Versions 11i.1 through i11.6 are affected.

The vulnerability allows for users to execute unauthorized procedures
inside the Oracle Applications Database.  The PL/SQL procedures may either
be predefined or user-defined.  The condition appears to be due to an
access validation error, as exploitation requires only modification of the
browser URL.

This may result in a loss of data, elevation of privileges or other
compromise.  Fixes have beem made available by Oracle.

21. XPilot Server Remote Buffer Overflow Vulnerability
BugTraq ID: 4534
Remote: Yes
Date Published: Apr 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4534
Summary:

XPilot is a multi-player 2D space game.  It is available for variants of
the Linux operating system.

A remotely exploitable buffer overflow has been discovered in the XPilot
server.  This is due to improper bounds checking of externally supplied
data.

A remote attacker who exploits this issue may cause locations in memory to
be overwritten with arbitrary data.  This may allow a remote attacker to
execute arbitrary instructions with the privileges of the xpilot server
process.

22. IcrediBB Script Injection Vulnerability
BugTraq ID: 4548
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4548
Summary:

IcrediBB is freely available web forum software.  It is written in PHP and
will run on most Unix and Linux variants, as well as Microsoft Windows
operating systems.

IcrediBB does not adequately filter HTML tags from forum message form
fields. This may enable an attacker to inject malicious script code into
forum messages. In particular, script code is not sufficiently sanitized
from the thread title and body form fields.  When a web user views a
message containing the attacker's script code, the malicious script code
is executed in their browser, in the security context of the website
running the vulnerable software.

An attacker who exploits this may be able to hijack web content or steal
cookie-based authentication credentials.

23. Foundstone FScan Banner Grabbing Format String Vulnerability
BugTraq ID: 4549
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4549
Summary:

FScan is the commercially available network scanning utility distributed
and maintained by Foundstone.  This problem affects the version available
for the Microsoft Windows platform.

A problem with the software package could make it possible to remotely
execute code on a vulnerable host.  The problem is in the banner-grabbing
function of the software.

Under some circumstances, it may be possible to execute arbitrary code on
a scanning host.  This is due to FScan not properly handling banner data
supplied by scanned hosts when the scanner is executed against them.
This problem is the result of a format string vulnerability, and could
lead to the overwriting arbitrary locations in memory, and execution of
attacker supplied code.

This vulnerability may only be exploited when the FScan software has been
configured to grab banners from scanned hosts.  The attacker must place
the exploit string in the banner of a host which will be scanned by FScan.
The result is the execution of code with the privileges of the user
running the FoundScan program.

24. WorkforceROI XPede Unprotected Administrative Facilities Vulnerability
BugTraq ID: 4552
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4552
Summary:

XPede is web-based project accounting software.  It is available for
Microsoft Windows operating systems.

XPede does not prompt non-administrative users for administrative
authentication credentials if they attempt to access an administrative
script. This may enable a malicious XPede user to gain unauthorized access
to the administrative facilities of the software.  For example, the
malicious user may access the '/admin/adminproc.asp' script to
enumerate/add/delete other users of the XPede project accounting system.

Successful exploitation would require the attacker to know the
name/location of administrative scripts.

This issue was reported for XPede 4.1.  Other versions may also be
affected.

25. XPede DataSource.ASP Information Disclosure Vulnerability
BugTraq ID: 4553
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4553
Summary:

XPede is web-based project accounting software.  It is available for
Microsoft Windows operating systems.

XPede uses Microsoft SQL Server to store its data.

When the XPede datasource.asp script is accessed it displayed a HTML form
that contains the database user name.  This script may be accessed by
arbitrary web users without requiring any sort of authentication.

Additionally, the script provides an interface for changing the user's
password.  To change the password, the current password must be provided.
However, since this interface is exposed and the database user name has
also been disclosed, this may provide an attacker with an opportunity to
brute-force the password of the database user.

This issue was reported for XPede 4.1.  Other versions may also be
affected.

26. WorkforceROI XPede Sprc.ASP SQL Injection Vulnerability
BugTraq ID: 4555
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4555
Summary:

XPede is web-based project accounting software.  It is available for
Microsoft Windows operating systems.

XPede is back-ended by Microsoft SQL Server.

A vulnerability in the XPede sprc.asp script makes it possible for a
malicious user to launch SQL injection attacks.  The vulnerable script
contains an option entitled "Qry", which may enable the attacker to inject
a literal SQL query, which will be executed by the underlying database.
This may be possibly be exploited to list database tables or modify/delete
data.  User and administrative authentication credentials are stored in
the database, in addition to other types of project accounting related
information.

Vulnerabilities or misconfigurations in the underlying database might also
be exploited via this issue.

This issue was reported for XPede 4.1.  Other versions may also be
affected.

27. WorkforceROI XPede Weak File Protection Vulnerability
BugTraq ID: 4554
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4554
Summary:

XPede is web-based project accounting software.  It is available for
Microsoft Windows operating systems.

When a user submits an expense claim, the file is saved in the
world-readable '/reports/temp' directory.  By default this directory is
indexable.  Remote clients may be able to access the temporary reports of
other users by accessing this directory.

Furthermore, the files may still be obtained if indexing has been disabled
for the '/reports/temp' directory.  For security reasons, the filenames
assigned are partially random.  Unfortunately the scheme is weak: the
random component of the filename is only 5 bytes in length and limited to
alpha-numeric characters.  This makes the space of possible filenames
relatively small and easily exhausted by an automated guessing utility.

As a result, it may be possible for a user to obtain sensitive information
which could assist in social engineering attacks.

This issue was reported for XPede 4.1.  Other versions may also be
affected.

28. WorkforceROI XPede Arbitrary Time Sheet Disclosure Vulnerabiltiy
BugTraq ID: 4556
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4556
Summary:

XPede is web-based project accounting software.  It is available for
Microsoft Windows operating systems.

An issue has been reported in Xpede which could allow a remote user to
access the time sheets of other users.  The vulnerability is in the
'ets_app_process.asp' script and is due to a lack of adequate
authorization checks.  It is possible for remote attackers to obtain user
timesheets by simply modifying the incrementally assigned TSN id script
parameter.  If a timesheet exists with the attacker-supplied ID number, it
will be output to the client.

As a result, unauthorized users could reveal sensitive user information.
This information may be used to assist in social engineering attacks.

This issue was reported for XPede 4.1.  Other versions may also be
affected.

29. Apache Tomcat System Path Information Disclosure Vulnerability
BugTraq ID: 4557
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4557
Summary:

Apache Tomcat does not properly handle malformed jsp file requests. As a
result, an attacker can obtain potentially sensitive information about the
server.

Submitting malformed requests will reveal an error message containing the
absolute path to the web root.

Requests that allegedly cause the condition:

http://target/+/file.jsp http://target/>/file.jsp http://target/</file.jsp
http://target/%20/file.jsp

Gaining knowledge of path information could assist an attacker in further
attacks against the host.

This issue may be related to the issue discussed in BID 3199.

30. OpenSSH Kerberos 4 TGT/AFS Token Buffer Overflow Vulnerability
BugTraq ID: 4560
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4560
Summary:

A buffer overflow condition allegedly exists in the OpenSSH server.  The
condition is reportedly exploitable by attackers with valid user
credentials.

The vulnerability is related to the handling of Kerberos 4 TGT/AFS tokens
passed by the client.  The overflow may occur when data is written into an
internal credentials structure.  It is believed that the offending code is
an unsafe string copy operation.

Successful exploitation of this vulnerability may allow for attackers with
valid credentials to obtain root privileges.

Note: this vulnerability reportedly does not affect default installations
of OpenSSH.  The vulnerability is present when the server is configured to
use Kerberos 4 or AFS.

This record will be updated once more details are available.

31. Snitz Forums 2000 Members.ASP SQL Injection Vulnerability
BugTraq ID: 4558
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4558
Summary:

Snitz Forums 2000 is ASP-based web forum software. It runs on Microsoft
Windows operating systems.  Snitz is back-ended by a database and supports
Microsoft Access 97/2000, SQL Server 6.5/7.0/2000 and MySQL.

Snitz Forums 2000 includes a feature that allows users to get a listing of
the registered users of the web forum.  To accomplish this, the
members.asp script constructs a query to the underlying database for a
list of registered users.

However, it is possible for a remote attacker to inject SQL into queries
made by the members.asp script.  This may be exploited to manipulate the
logic of a query made by the script.

Depending on the database implementation used, this may possibly result in
sensitive information in the database being disclosed to the attacker or
may enable the attacker to modify data.  There is also the possibility
that this issue may be leveraged to exploit vulnerabilities that may exist
in the underlying database.

The attacker would have to pass properly formatted SQL to the vulnerable
script to exploit this issue.

32. PostBoard BBCode IMG Tag Script Injection Vulnerability
BugTraq ID: 4559
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4559
Summary:

PostBoard is a freely available, open source message board module for the
PostNuke content management system.  It is designed for use on the Unix
and Linux operating systems.

A problem with PostBoard could allow remote users to execute arbitrary
code in the context of the web site.  The problem is in the checking of
some types of input.

PostBoard does not sanitize code submitted to site between IMG tags.  Due
to this, a malicious user may be able to submit a post to the site with
script code between two IMG tags.  This code would be executed by a user's
browser in the context of the site.

33. PostBoard Topic Title Script Execution Vulnerability
BugTraq ID: 4561
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4561
Summary:

PostBoard is a freely available, open source message board module for the
PostNuke content management system.  It is designed for use on the Unix
and Linux operating systems.

A problem with PostBoard may allow the execution of arbitrary script code
in the context of a site.  The problem is in the checking of some input.

PostBoard does not adequately sanitize input by board users.  Because of
this, it is possible for users of the board to insert script code in
message titles.  This would result in a user clicking the message and
executing the script code in the context of the site.

34. PostBoard BBCode Denial Of Service Vulnerability
BugTraq ID: 4562
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4562
Summary:

PostBoard is a freely available, open source message board module for the
PostNuke content management system.  It is designed for use on the Unix
and Linux operating systems.

A vulnerability exists in PostBoard's implementation of BBcode which makes
it possible for an attacker to starve resources on the host running the
affected software. In particular, it is possible to exploit the [code] tag
to create this effect. The [code] tag is used to quote samples of source
code without any of the special characters being interpretted. It is not
known whether other tags may also be exploited in this manner.

The consequence of exploitation is that the webserver will consume an
unusual amount of system resources. This may result in a denial of service
to the webserver and possibly the underlying system if adequate resource
limits are not in place.

If this issue is successfully exploited, the webserver will need to be
restarted for normal functionality to resume.

35. Nortel CVX 1800 Multi-Service Access Switch Default SNMP Community Vulnerability
BugTraq ID: 4507
Remote: Yes
Date Published: Apr 15 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4507
Summary:

Nortel CVX 1800 Multi-Service Access Switch is a hardware modem bank.

The device contains a default SNMP community read string of "public".  A
remote attacker may use a SNMP client to peruse the contents of SNMP
objects using this community string.  This has the potential to disclose
sensitive information such as authentication credentials for local
accounts on the device, details about the infrastructure of the network
that the device has been deployed on, etc.

36. IRIX XFS Filesystem Local Denial of Service Attack BugTraq ID: 4511
Remote: No Date Published: Apr 15 2002 12:00A Relevant URL:
http://www.securityfocus.com/bid/4511 Summary: A vulnerability has been
reported in some versions of the XFS filesystem. XFS is the default
filesystem for all IRIX 6.5 systems.

A local user may be able to create a malicious file. Any process which
then attempts to access this file will hang.

Under some circumstances, this may result in a denial of service
condition. For example, a malicious local user may place a file where it
will be accessed by a web or ftp server, or processed by some automated
system task.

37. Burning Board URL Parameter Manipulation Vulnerability
BugTraq ID: 4512
Remote: Yes
Date Published: Apr 15 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4512
Summary:

Burning Board is web forum software.  It is written in PHP, back-ended by
MySQL, and will run on most Unix and Linux variants as well as Microsoft
Windows.

An attacker may allegedly create a malicious link which is capable of
causing actions to be performed on the behalf of a legitimate Burning
Board user who visits the link.  To exploit this vulnerability, the
attacker must manipulate URL parameters in the malicious link in such a
way as to cause the desired actions to be performed by a user who visits
the link.  The legitimate forum user must also be authenticated via a
cookie-based authentication credential.  The link may include BBCode.

If the attacker launches this attack via a malicious attacker-controlled
webpage, then it is trivial for the attacker to write a script to conceal
that unauthorized actions have been performed on the behalf of the
legitimate user.  The attacker's script would most likely redirect the
user to an expected webpage after the attack has been performed.
Otherwise, it is possible the user may discover that an attempt has been
made to perform actions on their behalf.

This might be exploited by an attacker to cause an arbitrary
attacker-supplied forum message to be posted by a legitimate user who
visits the malicious webpage.

It has been reported, but not confirmed, that other web forum software
(such as phpBB) may also be affected by this vulnerability.

38. Mirabilis ICQ .hpf Denial of Service Vulnerability
BugTraq ID: 4514
Remote: Yes
Date Published: Apr 15 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4514
Summary:

When a new user registers with ICQ, various files are created which are
specific to ICQ, including .pnq (ICQ Plugin), .scm (ICQ Sound Scheme),
.uin (ICQ User) and .hpf (ICQ Home Page Factory). If a file with any of
the mentioned file extensions is accessed, ICQ is the default handler.

An issue has been discovered which could cause ICQ to crash. Reportedly,
if a user attempts to access a maliciously crafted file with a .hpf
extension, ICQ will crash.

This issue may be the result of an unchecked buffer. If this is the case,
there is a possibility that arbitrary code may be executed on the
vulnerable target. However, this has not yet been confirmed.

39. Demarc PureSecure Authentication Check SQL Injection Vulnerability
BugTraq ID: 4520
Remote: Yes
Date Published: Apr 15 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4520
Summary:

Demarc PureSecure is a commercially available graphical front-end for
Snort, in addition to being a generalized network monitoring solution.
Snort is an open-source NIDS (Network Intrusion Detection System). Demarc
PureSecure will run on most Linux and Unix variants, as well as Microsoft
Windows NT/2000/XP operating systems.

A vulnerability has been reported in some versions of PureSecure. User
supplied input is used to construct a SQL statement, allowing SQL
injection attacks. Administrative access may be gained through
exploitation of this flaw.

A session id value is derived from cookie information, which is under the
control of the client. This information is then used to construct a SQL
query, which is used to determine if the user has administrative access. A
malicious attacker may construct a cookie including additional SQL
commands, and modify this query.

It has been reported possible to gain administrative access through this
attack. Further exploitation may be possible, although this has not been
confirmed.

40. HP Photosmart Mac OS X Print Driver Weak File Permissions Vulnerability
BugTraq ID: 4518
Remote: No
Date Published: Apr 15 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4518
Summary:

The HP Photosmart line of printers are designed to allow easy and
efficient printing of digital photographs. An issue has been reported in
some versions of the Mac OS X driver for these printers.

The Mac OS X driver for the Photosmart printer includes the world writable
binary file hp_imaging_connectivity, reportedly located somewhere within
the /Library/Printers/hp/hp_imaging_connectivity.app/ directory. As it is
world writable, any local user may replace it with a trojaned copy or a
symbolic link to another file.

Reportedly, this application is executed as the current user whenever a
user logs onto the system. As a result, a root or administrative login
could automatically execute a trojaned binary, granted elevated privileges
to a local attacker. Execution could also occur when a user attempts to
print a file.

41. Microsoft Internet Explorer Unicode Character Handling DoS Vulnerability
BugTraq ID: 4519
Remote: Yes
Date Published: Apr 16 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4519
Summary:

It has been reported that Microsoft Internet Explorer crashes when
accessing a URL containing an excessive number of unicode characters.
This condition may reportedly be triggered if the web user clicks on a
maliciously constructed link containing an excessive number of unicode
characters.  The attacker would essentially have to entice the user into
submitting the URL with a vulnerable web browser.

It is not known what causes this to occur.  It may not be possible to
reproduce this issue on all environments, including two different systems
running the same version of the Microsoft Windows operating system with
the same version of Internet Explorer.  The exact circumstances of why
this issue occurs in some environments and not in others are not known at
this time.

It has been suggested that this vulnerability is caused by a buffer
overflow condition.

This record will be updated as more information becomes available.

42. Multiple Microsoft Products for MacOS File URL Buffer Overflow Vulnerability
BugTraq ID: 4517
Remote: Yes
Date Published: Apr 16 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4517
Summary:

An issue has been reported in various Microsoft products for MacOS,
including Internet Explorer, Outlook Express, Entourage, PowerPoint, Excel
and Word.

Reportedly, a common component of all of the listed products contain a
buffer overflow condition. The problem exists in the handling of file:///
URLs.

If an attacker creates a file:/// URL containing arbitrary data (approx
1313 bytes) and indexing at least one subdirectory, upon a user accessing
the maliciously crafted link, the arbitrary data will execute and
potentially initiate the overflow. For example:

file:///arbitrary_data or file:///data/data/data/data/

This overflow could overwrite stack variables, including the return
address, and be used to execute arbitrary code with the privilege level of
the user. However, sending random data could cause the application to
crash.

43. Symantec Norton Personal Firewall 2002 Portscan Protection Bypass Vulnerability
BugTraq ID: 4521
Remote: Yes
Date Published: Apr 16 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4521
Summary:

Symantec Norton Personal Firewall 2002 (NPW)is a firewall solution for
home and small office machines based on some versions of the Microsoft
Windows operating systems. It has a variety of features, including the
ability to detect and dynamically block portscans.

An issue has been reported with the manner in which Personal Firewall 2002
handles portscans. Reportedly, only SYN scans are detected. An attacker
may scan with a variety of other methods, including SYN/FIN packets and
evade the protective features of NPW.

Additionally, when a scan is protected it has been reported that only
incoming SYN packets from the attacking address are blocked. The attacker
may continue to probe the target machine with the methods mentioned above,
and currently open connections are not dropped.

It has also been reported that the 30 minute blacklist time for portscan
protection is not configurable. This may allow the attacker to fingerprint
the system as running NPW 2002, possibly allowing for further intelligent
attacks.

44. Oracle 9i ANSI Outer Join Access Control Bypass Vulnerability
BugTraq ID: 4523
Remote: Yes
Date Published: Apr 16 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4523
Summary:

Oracle 9i includes support for the ANSI 'outer join' syntax in SQL
database queries.

It has been reported that a security vulnerability exists in the
implementation of this feature.  According to reports, queries containing
'outer joins' can bypass database access controls.  It may be possible for
users to retrieve data that should not be accessible to them, such as the
password hashes of other database users.

The possible existence of this sort of vulnerability brings to light
questions about the solidity of the underlying security model.  If
confirmed, other vulnerabilities resulting in evasion of access control
may be latent.

45. Symantec Raptor / Enterprise Firewall FTP Bounce Vulnerability
BugTraq ID: 4522
Remote: Yes
Date Published: Apr 16 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4522
Summary:

Raptor Firewall is an enterprise level firewall originally developed by
Axent Technologies and is maintained and distributed by Symantec. Symantec
Enterprise Firewall is formerly known as Raptor firewall. It is available
for Microsoft Windows and Unix operating systems.

Some FTP implementations allow for the FTP PORT command to be used to send
data from the server to a host other than the client.  This well
documented weakness in the protocol is known as the FTP Bounce Attack.
It is fixed in most modern FTP servers.

The Raptor Firewall implementation of the FTP protocol is susceptible to
FTP bounce attacks.

Raptor Firewall rewrites the headers of incoming and outbound packets in
such a way as to make the FTP bounce attacks possible.  When a FTP PORT
command is parsed by the vulnerable firewall, the IP address in the
command is changed to the attacker's and the port is changed to a number
in the ephemeral port range.  To the FTP server behind the firewall, this
is a permissable PORT request.

However, when the firewall handles the resultant outgoing connection made
by the FTP server, the IP address and port of the command are replaced
with the original attacker supplied values.

Consequently, the attacker can cause the data to be sent to an arbitrary
host.

It should be noted that affected firewall implementations disable FTP PORT
connections to ports below 1024.

Symantec has reported that Enterprise Firewall V7.0 for Solaris is also
vulnerable to this issue.

46. FreeBSD 4.5 syncache / syncookies Denial Of Service Vulnerability
BugTraq ID: 4524
Remote: Yes
Date Published: Apr 16 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4524
Summary:

Recent versions of FreeBSD 4.5 include support for a SYN cache (syncache)
and SYN cookies (syncookies) mechanism. This provides some level of
protection from a class of denial of service flooding attacks.

Multiple denial of service issues have been reported in some versions of
these features. A malicious attacker may be able to take advantage of
these issues to cause the vulnerable system to crash. A restart may be
required in order to regain normal functionality.

The first issue results from an uninitialized pointer being referenced
when a SYN packet is accepted with the syncookies mechanism enabled. In
the event that this is a null pointer, the machine will crash.

The second issue occurs when a process is killed and restarted. If a
syncache entry is created before the process is killed, and the process
restarts and listens on the same socket, a matching ACK or duplicated SYN
packet arriving at a later time may result in the original syncache entry
being accessed. Under some circumstances, accessing this old pointer may
also result in a system crash.

47. Microsoft IIS CodeBrws.ASP Source Code Disclosure Vulnerability
BugTraq ID: 4525
Remote: Yes
Date Published: Apr 16 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4525
Summary:

Microsoft IIS 5.0 ships with a sample script that may be used to view the
source code of other scripts in the sample scripts (/IISSAMPLES)
directory.

The vulnerable script (CodeBrws.asp) makes an attempt to filter standard
attempts to break out of the sample scripts directory using dot-dot-slash
directory traversl attacks.  However, this script does not adequately
filter unicode representations of directory traversals.  For example, an
attacker can break out of the sample script directory by substituting
'%c0%ae%c0%ae' for '..' in a dot-dot-slash directory traversal attack.

Disclosure of script source code may reveal sensitive information to an
attacker.  Plaintext database credentials are often contained in script
source code.  Additionally, the attacker may exploit this condition to
search for other more serious vulnerabilities that may exist in scripts on
the host running the vulnerable software.

It has been demonstrated that this issue may be exploited to map out the
directory structure of the filesystem on a host running the vulnerable
script.  This script, when attempting to view the source code for a file,
gives feedback as to the user as to whether the file/directory exists or
not.  For example, a request for a non-existent directory returns a "Path
not found" response.  A request for a non-existent file in a existing
directory returns a "File not found" response.

48. AOL Instant Messenger Arbitrary File Creation Vulnerability
BugTraq ID: 4526
Remote: Yes
Date Published: Apr 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4526
Summary:

An issue has been reported, which could allow an AIM user to save files to
arbitrary locations on another user's system.

Reportedly, this is achievable when a direct connection is made between
two AIM users. Files that are sent to a user include an img tag and a data
tag. Typically, the recipient's client will respond to the img tag by
displaying the icon associated with the received file, the AIM client
automatically executes the file accordingly. When the client automatically
executes the file, a file is created in the Windows temp directory with
the same name it was received with. The file is read directly from the
temp directory.

If the SRC parameter of the img tag is modified to include '..\' sequences
along with the absolute path to a specific directory, the file will be
created in the chosen directory rather than the temp directory. In
addition, the HEIGHT and WIDTH values of the img tag can be modified in
such a way that the icon does not appear in the recipient's client, it may
be possible that the user will not be aware that a file is being sent.

As a result, files may be saved to arbitrary locations on an unknowing
recipient's system. This may assist in leveraging further attacks against
the target user.

49. TalentSoft Web+ WML Request Cookie Buffer Overflow Vulnerability
BugTraq ID: 4530
Remote: Yes
Date Published: Apr 17 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4530
Summary:

TalentSoft Web+ is an environment for developing web-based client/server
applications. It will run on Microsoft Windows 9x/NT/2000 and Unix
operating systems.

An exploitable buffer overflow has been discovered in Web+ when an
oversized cookie is sent with a request for a WML file. This overflow
could overwrite stack variables, including the return address, and be used
to execute arbitrary code as the web server process. However, sending
random data could cause the application to crash.

As the Web+ service runs with SYSTEM privileges under IIS 4, exploitation
of arbitrary code will enable a remote attacker to fully compromise a host
running the vulnerable software. Under IIS 5, IWAM_* privileges may be
obtained with lesser consequences. Regardless, however, exploitation may
allow local access to the vulnerable system.


III. SECURITYFOCUS NEWS AND COMMENTARY
------------------------------------------
1. GovNet Plans Moving Forward
By David McGuire, Newsbytes

White House cybersecurity experts are moving forward with the next phase
of building a secure federal intranet.

http://online.securityfocus.com/news/374

2. Ashcroft, Ellison, Win 'Big Brother' Awards
By Kevin Poulsen

Electronic privacy advocates honor foes at the 12th annual Computers,
Freedom and Privacy conference.

http://online.securityfocus.com/news/373

3. National ID Plans Face Hurdles
By Ann Harrison

Distributing thousands of card readers, guarding against corrupt insiders,
defending against fraudsters and hack attacks... Plans to create a
national ID card are fraught with peril.

http://online.securityfocus.com/news/371

4. FTC Chairman Pushes Net Crime Vigilance, Not New Laws
By Robert MacMillan, Newsbytes

Dealing with online spammers and privacy invasions requires strong
enforcement action from the Federal Trade Commission, but the agency's
chief today upheld his conviction that new legislation will not solve any
problems.

http://online.securityfocus.com/news/370

5. New Take On Klez Worm Spreading
By Steven Bonisteel, Newsbytes

Virus watchers say a variant of an already common Windows worm has begun
making its way around the Internet, and this time it's packing the ability
to replace legitimate executable programs with its own malicious code.

http://online.securityfocus.com/news/369

6. Privacy Worries, Net Activism Top Privacy Show Agenda
By Robert MacMillan, Newsbytes

Concern about the gradual erosion of Internet privacy safeguards and the
desire to figure out the legal boundaries of using the Internet as an
activism tool will rank among the most important topics being discussed
this week as Internet civil liberties groups convene at the Computers,
Freedom and Privacy 2002 conference in San Francisco.

http://online.securityfocus.com/news/368


IV.SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Logwatch v2.8.5
by Kirk Bauer
Relevant URL:
http://www.logwatch.org
Platforms: MPE/iX, N/A
Summary:

Logwatch analyzes and reports on system logs. It is a customizable and
pluggable log-monitoring system and will go through the logs for a given
period of time and make a customizable report. It should work right out of
the package on most systems.

2. TinyCA v0.3.0
by Stephan Martin
Relevant URL:
http://tinyca.sm-zone.net/
Platforms: Linux, OpenNMS, POSIX
Summary:

TinyCA is a simple GUI written in Perl/Tk to manage a small certification
authority. It is based on OpenSSL and Perl modules from the OpenCA
project. TinyCA lets you manage x509 certificates. It is possible to
export data as PEM or DER for use with servers, or as PKCS#12 for use with
clients, or as S/MIME certificates for use with email programs.

3. Castellan Sentry v0.01
by Castellan
Relevant URL:
http://www.castellangroup.com/
Platforms: N/A
Summary:

The Castellan Sentry detects login attempts on SSH, and advises the
desktop via a GUI popup window. This popup allows you to block the remote
machine, ignore the login, or commit an investigation. Investigation
reports back to you the nslookup, reverse DNS, ARIN, and a simple port
scan via NMAP. This will help determine if the source should be blocked or
not and gives you the option of doing either.

4. Nessus v1.2.0
by Renaud Deraison, [email protected]
Relevant URL:
http://www.nessus.org/
Platforms: FreeBSD, IRIX, Linux, NetBSD, OpenBSD, Solaris
Summary:

Nessus is a remote security scanner for Linux, BSD, Solaris, and other
Unices. It is multi-threaded and plug-in-based, has a GTK interface, and
performs over 500 remote security checks. It allows for reports to be
generated in HTML, XML, LaTeX, and ASCII text, and suggests solutions for
security problems.

5. lcrzoex v4.08
by Laurent Constantin
Relevant URL:
http://www.laurentconstantin.com/en/lcrzoex/
Platforms: FreeBSD, Linux, OpenBSD, Solaris, Windows 2000, Windows 95/98,
Windows NT, Windows XP
Summary:

Lcrzoex is a toolbox for network administrators and network hackers.
Lcrzoex contains over 300 functionnalities using network library lcrzo.
Each one can be compiled alone and modified to match your needs.

Lcrzoex can be used in the following contexts : - discover the Ethernet
address of a computer (number 2, 3, 134, etc.)  - sniff your LAN to detect
what's going on (number 7, 8, 9, etc.)  - check the checksums created by a
network program which isn't working (number 16, 17, 18, etc.)  - intercept
a session and replay it as many times you want to strictly test your
application (number 10, 11, 12, 22, etc.)  - verify if a router is well
configured even if the needed computers are down (number 48, ..., 53,
etc.)  - check if your router/firewall/computer blocks - IP protocols
(number 29, ..., 34, etc.)  - IP options (number 29, ..., 34, 73, ..., 79,
etc.), source routing (number 45, 56, 59, 62, etc.)  - IP fragments
(number 44, 55, 58, 61, 72, etc.) - TCP options (number 48, ..., 53, etc.)
- ICMP types (number 65, ..., 70, etc.) - ARP poisoning (number 80, 81,
82, 83, etc.) - create a tcp/udp client with a special local port (number
85, 89, 86, 93, 97, etc.)  - convert between numbers (number 139, ...,
148, etc.) - etc.

6. Firewall by Jim v0.28
by Jim Gifford
Relevant URL:
http://www.jg555.com/firewall
Platforms: N/A
Summary:

This is a firewall that takes advantage of tcp_wrappers information to
block users. It also uses separate files for configuration ease. It is
designed to work out of the box with eth0 for internet and eth1 for the
LAN.


V. SECURITY JOBS SUMMARY
------------------------
1. Positions (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/009001c1e7da$a7564460$0100a8c0@TDIXP

2. Senior Security Guy Looking For Interesting Gig (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

3. Seeking Security Engineer (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

4. Seeking Security Position (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

5. Application Security - Chicago - Greythorn (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/5544986F9407D611A5900008C70964060B98EB@EXCHANGE

6. Security Test Engineer (Austin, TX) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

7. Senior Security Solutions Sales Executive - #693 - NY, NJ, CT (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

8. Seeking a SR Information Security Engineer (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

9. Looking for Consulting Position (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

10. Security Consultant (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

11. Amendment to Andersen Fall Out. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/001401c1e622$779cb600$7caefea9@NONE

12. QA Hardware Engineer IT Security - UK (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

13. Head of Information Security reqd for Melbourne, Australia SJ/RM2522C (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

14. IT Security Sales Director (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

15. Position available at Microsoft in Passport group for recent university graduates (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/4F4182C71C1FDD4BA0937A7EB7B8B4C10490D54D@red-msg-08.redmond.corp.microsoft.com

16. Penetration testing in Dubai (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

17. Principal Security Consultant for Europe (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

18. Lab Researcher/Engineer Position in DC Metro Area (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

19. Security Systems Engineer (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

20. Systems Security Administrator LFJ (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

21. Sr. Internetworking & Security Expert , Jersey City (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

22. Sprint Fall Out! (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/9BAF6985AAD2D4118DD100D0B79E84F103E160DF@exchange4

23. Chief Information Security Officer - #702 - NY (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]


VI. INCIDENTS LIST SUMMARY
-------------------------
1. illogic rootkit (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

2. Anyone caught a packet of ... ? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/8F2D7C893282D3118D9A00508B0909F20401C899@ntexgkrl01

3. Wu-ftpd 2.6.2 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

4. illogic rootkit (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

5. known expoit for wu-ftpd 2.6.2(1) ?? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

6. distributed ftp scan (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

7. Fwd: ms02-018 IS dangerous after all (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

8. HTTP CONNECT attempts (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

9. Strange UDP Activity (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

10. Vacation Troller, Please Ignore. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

11. Strange UDP Activity (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

12. Redhat 6.2 Honeypot Hacked (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

13. <victim>server formmail.pl exploit in the wild (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/p0510154bb8e0f0f73d99@[192.168.1.104]

14. Botnet/Domains (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

15. Strange scans (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

16. Strange scans (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]


VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. Remote MS02-18 Patch Checker (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

2. Cross site scripting @verisign.com and @cybercash.com (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

3. Cross site scripting in almost every mayor website (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

4. OpenSSH 2.2.0 - 3.1.0 server contains a locally exploitable   buffer overflow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/024201c1e8ac$c81bf960$bd2a9aca@SERVER

5. OpenSSH 2.2.0 - 3.1.0 server contains a locally exploitable    buffer overflow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

6. weird IE6 crash (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

7. Keyservers Cross Site Scripting (When CSS Gets Dangerous) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/001301c1e83a$ca66da90$ac00a8c0@noamlp

8. Where does the hole lie? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/1C1E25D810B404489BFE32088773C188223973@CHSVRNT1

9. buffer overflow with greek characters, NIX (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

10. buffer overflow with greek characters, NIX (yeah yeah again) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/02041817420900.15629@a213-22-16-185

11. Cisco VPN client (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

12. Cisco VPN client (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

13. Smalls holes on 5 products #1 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

14. greek characters buffer overflow, AGAIN! (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/001801c1e63d$0d290470$bdb1fea9@mike

15. Spanning Tree Switch Exploits? Fact or Fiction? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

16. bufferoverflow posadis m5pre - ( POC number 2 ) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

17. gawk bufferoverflow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

18. bufferoverflow posadis m5pre2 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

19. Testing Of Windows 2000 and NT4 IIS .ASP Remote Buffer Overflow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/004901c1e636$45b09f30$f701010a@dougstyle

20. Challenge (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

21. Challenge (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

22. [VulnWatch] greek characters buffer overflow, AGAIN! (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/003601c1e5d8$8a8393a0$0b00a8c0@Natasha

23. Ddate Proof Of Concept Exploit and Bug details (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

24. greek characters buffer overflow, AGAIN! (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

25. Oracle Databases Allow HTML/SQL injection (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

26. FileSeek cgi script advisory (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

27. Fw: URLSCAN - Error 50. Ideas? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

28. ASP & HTR Overflows (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]


VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. windows domain question (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

2. windows domain question (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

3. OWA and URLScan (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

4. URLScan 2.5 SRP (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/9AACD631D86FD51182C500306E02085801E014BB@asbutl16.asb.countrycompanies.com

5. Microsoft Security Bulletin MS01-022 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

6. Ensuring Disabling/Uninstalation of Windows XP Firewall in LAN enviro. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

7. Microsoft Cluster in DMZ - Need Advice (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

8. OWA and URLScan (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/859A11E09843BC48A67C176D12E38857337619@BMA-EXCHANGE-2

9. Ensuring Disabling/Uninstalation of Windows XP Firewall in  LAN enviro. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

10. Win 98 Security (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/F50520282C60D511849600306E07D1CA4A6E8D@MGEX1

11. Microsoft Security Bulletin MS01-022 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

12. Win 98 Security (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

13. Ensuring Disabling/Uninstalation of Windows XP Firewall in LAN enviro. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/001301c1e73b$e8f28860$a78386cb@hedni01

14. Problem with auto unpacking Hotfixes (from 1 machine only) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/761DBCC144B6334A81251171C684A6FB73C562@mailserver-2k.fireapple.com

15. ms02-018 IS dangerous after all (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/120097989CFFD1118B8C00805FFEE24608C0BE7B@GBWTM001

16. Any known issue with 10 April 2002 Cumulative Patch for IIS ? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

17. FW: Free HFNetChkPro Invitation (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

18. Fwd: ms02-018 IS dangerous after all (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

19. SSL directory structure issue (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/E846E1497BC9E747A88011167C797D0A09B3AC@pantera.corp.workscape.net

20. Any known issue with 10 April 2002 Cumulative Patch for  IIS ? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

21. Any known issue with 10 April 2002 Cumulative Patch for IIS ? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

22. Administrivia: Users slam Microsoft Security Analyser (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

23. SSL directory structure issue (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

24. Posters Slam Microsoft Training (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

25. Users slam Microsoft Security Analyser (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

26. Users slam Microsoft Security Analyser (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/003b01c1e4db$b6ca5a50$0800a8c0@VAIO

27. SecurityFocus Microsoft Newsletter #82 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

28. Posters Slam Microsoft Training (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

29. URLSCAN error 50 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

30. Scanning MS DHCP networks. Reading dhcp.mdb (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

31. Scanning MS DHCP networks. Reading dhcp.mdb (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/00cc01c1e49b$7e3b64d0$01f9a8c0@localdomain

32. Anyone familiar with bitvise's winsshd? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

33. VPN / IPSEC (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

34. Peculiar login troubles. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/002701c1e455$e35d9a40$0a01a8c0@slelaptop

35. authentication  NTLM (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]


IX. SUN FOCUS LIST SUMMARY
----------------------------
1. Looking for ftp over SSL (TLS) daemon... (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/C3E5D03891AAD411BC6000508B1214FF051930DE@us-cwi-exc-a05.cwi.cablew.com

2. Looking for ftp over SSL (TLS) daemon... (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]


X. LINUX FOCUS LIST SUMMARY
---------------------------
1. HiverCon 2002 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/02041921355504.00223@carmen

2. No Root Shell with SUID /bin/bash (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]


XI. SPONSOR INFORMATION
-----------------------
This newsletter is sponsored by SecurityFocus (www.securityfocus.com)

Attention Non-profits and Universities: Sign-up now for preferred pricing
on the only global early-warning system for cyber attacks - SecurityFocus
ARIS Threat Management System.

Click here for more info
http://www.securityfocus.com/corporate/products/pdpsection.shtml
-------------------------------------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.