Updated SecurityFocus Newsletter #142

John Boletta <[email protected]>
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
* Apologies to SF-News subscribers who may have already received this
week's newsletter. We inadvertently omitted some content, which has been
included in this version.  Please accept SecurityFocus's apologies for any
inconvenience.


SecurityFocus Newsletter #142
-----------------------------

This Issue is Sponsored by: Borderware

Email: whether you are running MS Exchange, Lotus Notes or a Unix mail
system, you have your hands full managing email delivery, spam, viruses
and in implementing workable content controls.

The BorderWare Mail Gateway gives the control you need in a hardened
secure package that can be deployed right on the internet. Not only that,
it provides a unique, easy-to-deploy remote access system that allows your
users to get their email without forwarding or duplication.

Find out more at http://www.borderware.com/mg/

-------------------------------------------------------------------------------

I. FRONT AND CENTER
     1. Securing Privacy, Part Two: Software Issues
     2. Securing Exchange 2000
     3. Teaching the Rules of the Road
     4. Dollar Diddling and the Billion-Dollar Viruses
II. BUGTRAQ SUMMARY
     1. Apache Tomcat System Path Information Disclosure Vulnerability
     2. OpenSSH Kerberos 4 TGT/AFS Token Buffer Overflow Vulnerability
     3. Snitz Forums 2000 Members.ASP SQL Injection Vulnerability
     4. PostBoard BBCode IMG Tag Script Injection Vulnerability
     5. PostBoard Topic Title Script Execution Vulnerability
     6. PostBoard BBCode Denial Of Service Vulnerability
     7. PostCalendar 3.0 Cross Site Scripting Vulnerability
     8. Microsoft Internet Explorer Self-Referential Object Denial of
     Service Vulnerability
     9. Faq-O-Matic Cross Site Scripting Vulnerability
     10. Macromedia Flash ActiveX Control Bandwidth Consumption...
     11. Philip Chinery's Guestbook Script Injection Vulnerability
     12. BSD exec C Library Standard I/O File Descriptor Closure...
     13. SLRNPull Spool Directory Command Line Parameter Buffer...
     14. PsyBNC Oversized Passwords Denial Of Service Vulnerability
     15. Matu FTP Client Buffer Overflow Vulnerability
     16. vqServer CGI Demo Program Script Injection Vulnerability
     17. AOL Instant Messenger Data Interception Vulnerability
     18. Apache Tomcat Servlet Path Disclosure Vulnerability
     19. Summit Computer Networks Lil' HTTP Server Directory Traversal...
     20. National Instruments LabVIEW HTTP Request Denial of Service...
     21. CGIScript.NET csMailto Hidden Form Field Remote Command...
     22. GNU Screen Braille Module Buffer Overflow Vulnerability
     23. Mosix Malformed Packet Handling Denial Of Service Vulnerability
     24. Mosix ClumpOS Blank Default VNC Password Vulnerability
     25. HP-UX Password File Corruption Vulnerability
     26. Internet Explorer Recursive JavaScript Event Denial of Service...
     27. Microsoft Outlook Express DOS Device Denial of Service...
     28. Oracle E-Business Suite 11i Unauthorized PL/SQL Procedure...
     29. IcrediBB Script Injection Vulnerability
     30. Foundstone FScan Banner Grabbing Format String Vulnerability
     31. WorkforceROI XPede Unprotected Administrative Facilities...
     32. XPede DataSource.ASP Information Disclosure Vulnerability
     33. WorkforceROI XPede Sprc.ASP SQL Injection Vulnerability
     34. WorkforceROI XPede Weak File Protection Vulnerability
     35. WorkforceROI XPede Arbitrary Time Sheet Disclosure Vulnerabiltiy
III. SECURITYFOCUS NEWS ARTICLES
     1. FAA Confirms Hack Attack
     2. Microsoft Yanks Office Tools After Security Report
     3. Network Associates Finds Errors, Drops McAfee Bid
     4. Europeans Roll Out PKI For Niche Applications
IV.SECURITYFOCUS TOP 6 TOOLS
     1. Ghost Port Scan v0.9.3-FRC
     2. GreedyDog v2.3
     3. Demarc PureSecure v1.6
     4. WebProxy v1.0
     5. EGADS v0.9
     6. RATS (Rough Auditing Tool for Security) v1.4
V. SECURITYJOBS LIST SUMMARY
     1. Application Security - Chicago - Greythorn (Thread)
     2. Expert IDS Person Available (Thread)
     3. INFOSEC Guy - Seeking a Change (Thread)
     4. Application Security Architect/Engineer #510 - Chicago, IL - $100k
     5. Federal Sales Manager - #698 - VA (Thread)
     6. Seeking Entrepreneurial Security Engineer (Thread)
     7. Inside Sales-Network/Information Security -Boston,MA (Thread)
     8. Technical Marketing Engineer  position in MA (Thread)
     9. Security opportunities @ Ciber (Thread)
     10. Looking job outside my country. (Thread)
     11. Senior/Management Security Position Wanted (Thread)
     12. Network Security Sales Rep. needed in NJ (Thread)
     13. Encryption Security Manager-Baltimore,Md. (Thread)
     14. Several Security system positions in MD,DC,VA (Thread)
     15. Network Security Analyst (Thread)
     16. Security Application Developer (Austin, TX) (Thread)
     17. Security Test Engineer (Austin, TX) (Thread)
     18. 2 Senior Systems Engineer positions (east coast) (Thread)
     19. Seeking Management Position (Thread)
     20. ids/security person looking for a team environment (Thread)
     21. Positions (Thread)
     22. Senior Security Guy Looking For Interesting Gig (Thread)
     23. Seeking Security Engineer (Thread)
     24. Seeking Security Position (Thread)
VI. INCIDENTS LIST SUMMARY
     1. Winfreez DoS question (Thread)
     2. compromised cisco (Thread)
     3. ftp (Thread)
     4. ftp (Thread)
     5. Big traffic on 412/tcp (Thread)
     6. Rootkit or trojan (Thread)
     7. Port 6588 Probes from SA (Thread)
     8. illogic rootkit (Thread)
     9. Anyone caught a packet of ... ? (Thread)
     10. Wu-ftpd 2.6.2 (Thread)
     11. illogic rootkit (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. Sudo version 1.6.6 now available (fwd) (Thread)
     2. /lib/ld-2.2.4.so (Thread)
     3. apache + .htpasswd - bypass pwd check (Thread)
     4. apache + .htpasswd - bypass pwd check (Thread)
     5. nobody suid shell (kind of relationship with the ld-2.2.4
     6. Privacy leak while surfing (Thread)
     7. TTP/1.0 Remote BufferOverflow? (Thread)
     8. draytek-Router: undocumented open configuration ports (Thread)
     9. Eudora Logging (Thread)
     10. Privacy leak while surfing (Thread)
     11. Microsoft Baseline Security Analyzer exploit (Exposed
     12. cheers (Thread)
     13. Cisco response to Cisco VPN Client under XP (Thread)
     14. cheers (Thread)
     15. /lib/ld-2.2.4.so (Thread)
     16. ecartis / listar PoC (Thread)
     17. slrnpull -d PoC (Thread)
     18. Fw: (Case #4944266) (Thread)
     19. php & passthru & system (Thread)
     20. php & passthru & system (Thread)
     21. more info on the iosmash.c exploit (Thread)
     22. Cross site scripting in almost every mayor website (Thread)
     23. Rodopi Security/Functionality (Thread)
     24. 'Leave' behavior after stack overflow. (Thread)
     25. Keyservers Cross Site Scripting (When CSS Gets Dangerous)
     26. full info on iosmash.c as non wheel user (Thread)
     27. ld.so (Thread)
     28. [Fwd:  weird IE6 crash] (Thread)
     29. Remote MS02-18 Patch Checker (Thread)
     30. PHP problem (Thread)
     31. Cross site scripting @verisign.com and @cybercash.com (Thread)
     32. Mildly useful tool. (Thread)
     33. Security holes : Ultimate PHP Board (Thread)
     34. Spanning Tree Switch Exploits? Fact or Fiction? (Thread)
     35. Remote MS02-18 Patch Checker (Thread)
     36. OpenSSH 2.2.0 - 3.1.0 server contains a locally exploitable
     37. OpenSSH 2.2.0 - 3.1.0 server contains a locally exploitable
     38. weird IE6 crash (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. Remote perf counter access (Thread)
     2. problems with hotfix rollup, windows update, mbsa, hfnetchk, and
     3. Network Settings and Power Users (Thread)
     4. Update on status of IE security (Thread)
     5. Question:  How To Secure a Public Access Workstation (Thread)
     6. Microsoft Cluster in DMZ - Need Advice (Thread)
     7. MS defends MBSA (Thread)
     8. Network Settings and Power Users (Thread)
     9. problems with hotfix rollup, windows update, mbsa, hfnetchk, and
     10. Remote perf counter access (Thread)
     11. Role based access in Win2k w/o AD (Thread)
     12. Follow-up on Registry key containing events to be audited
     13. MS defends MBSA (Thread)
     14. IE 5.5 security (Thread)
     15. Securing IIS (Thread)
     16. SecurityFocus Microsoft Newsletter #83 (Thread)
     17. Securing IIS (Thread)
     18. Registry keys for EventLog audit events (Thread)
     19. Question:  How To Secure a Public Access Workstation (Thread)
     20. HFNetCheck Pro in an NT-only environment? (Thread)
     21. Microsoft Cluster in DMZ - Need Advice (Thread)
     22. windows domain question (Thread)
     23. windows domain question (Thread)
     24. OWA and URLScan (Thread)
     25. URLScan 2.5 SRP (Thread)
     26. Microsoft Security Bulletin MS01-022 (Thread)
     27. Ensuring Disabling/Uninstalation of Windows XP Firewall in LAN
     28. OWA and URLScan (Thread)
     29. Ensuring Disabling/Uninstalation of Windows XP Firewall in  LAN
     30. Win 98 Security (Thread)
     31. Microsoft Security Bulletin MS01-022 (Thread)
     32. Win 98 Security (Thread)
     33. Ensuring Disabling/Uninstalation of Windows XP Firewall in LAN
IX. SUN FOCUS LIST SUMMARY
     1. How do I set-up secure automated file push and pull? (Thread)
     2. new zlib patch (Thread)
     3. Looking for ftp over SSL (TLS) daemon... (Thread)
X. LINUX FOCUS LIST SUMMARY
     1. No Root Shell with SUID /bin/bash (Thread)
     2. Adore over adore? (Thread)
     3. Adore over adore? (Thread)
     4. HiverCon 2002 (Thread)
XI. SPONSOR INFORMATION



I. FRONT AND CENTER
-------------------
1. Securing Privacy, Part Two: Software Issues
By Scott Granneman

This is the second article in a three-part series that will examine
privacy concerns as they relate to security. This installment will discuss
software-based issues and solutions. As we shall see, some software is
designed to safeguard privacy, while other software seems designed to
compromise it.

http://online.securityfocus.com/infocus/1573

2.  Securing Exchange 2000
by Chris Weber

This article is the first of a two-part series that will to provide a
technical look at some of the fundamental requirements for securing
Microsoft Exchange Server 2000 and Outlook Web Access (OWA) running in a
Windows 2000 Active Directory environment. I will start by looking at some
exploits for Exchange server to give readers an idea of areas that need
protection. Then I'll get right into the Exchange application and discuss
some of its inherent security features, as well as some secure network
designs for Exchange/OWA deployments.

http://online.securityfocus.com/infocus/1572

3. Teaching the Rules of the Road
By Jon Lasser

Bad system administrators affect more than their own computers -- they
make the entire Internet a little less safe.

http://online.securityfocus.com/columnists/77

4. Dollar Diddling and the Billion-Dollar Viruses
By George Smith

How journalists tap "experts" to reach absurd conclusions about the cost
of computer viruses.

http://online.securityfocus.com/columnists/78


II. BUGTRAQ SUMMARY
-------------------
1. Apache Tomcat System Path Information Disclosure Vulnerability
BugTraq ID: 4557
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4557
Summary:

Apache Tomcat does not properly handle malformed jsp file requests. As a
result, an attacker can obtain potentially sensitive information about the
server.

Submitting malformed requests will reveal an error message containing the
absolute path to the web root.

Requests that allegedly cause the condition:

http://target/+/file.jsp
http://target/>/file.jsp
http://target/</file.jsp
http://target/%20/file.jsp

Gaining knowledge of path information could assist an attacker in further
attacks against the host.

This issue may be related to the issue discussed in BID 3199.

2. OpenSSH Kerberos 4 TGT/AFS Token Buffer Overflow Vulnerability
BugTraq ID: 4560
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4560
Summary:

A buffer overflow condition exists in the OpenSSH server.  The condition
is exploitable by attackers with valid user credentials in versions 2.9.9
and higher.  Exploitation does not require valid user credentials in
versions prior to 2.9.9.

The vulnerability is related to the handling of Kerberos 4 TGT/AFS tokens
passed by the client.  The overflow may occur when data is written into an
internal credentials structure.  The offending code is an unsafe string
copy operation and the overflow occurs on the stack.

Successful exploitation of this vulnerability may allow for attackers to
obtain root privileges on the affected server.

Note: this vulnerability does not affect default installations of OpenSSH.
The vulnerability is present when the server is configured to use Kerberos
4 or AFS.

3. Snitz Forums 2000 Members.ASP SQL Injection Vulnerability
BugTraq ID: 4558
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4558
Summary:

Snitz Forums 2000 is ASP-based web forum software. It runs on Microsoft
Windows operating systems.  Snitz is back-ended by a database and supports
Microsoft Access 97/2000, SQL Server 6.5/7.0/2000 and MySQL.

Snitz Forums 2000 includes a feature that allows users to get a listing of
the registered users of the web forum.  To accomplish this, the
members.asp script constructs a query to the underlying database for a
list of registered users.

However, it is possible for a remote attacker to inject SQL into queries
made by the members.asp script.  This may be exploited to manipulate the
logic of a query made by the script.

Depending on the database implementation used, this may possibly result in
sensitive information in the database being disclosed to the attacker or
may enable the attacker to modify data.  There is also the possibility
that this issue may be leveraged to exploit vulnerabilities that may exist
in the underlying database.

The attacker would have to pass properly formatted SQL to the vulnerable
script to exploit this issue.

4. PostBoard BBCode IMG Tag Script Injection Vulnerability
BugTraq ID: 4559
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4559
Summary:

PostBoard is a freely available, open source message board module for the
PostNuke content management system.  It is designed for use on the Unix
and Linux operating systems.

A problem with PostBoard could allow remote users to execute arbitrary
code in the context of the web site.  The problem is in the checking of
some types of input.

PostBoard does not sanitize code submitted to site between IMG tags.  Due
to this, a malicious user may be able to submit a post to the site with
script code between two IMG tags.  This code would be executed by a user's
browser in the context of the site.

5. PostBoard Topic Title Script Execution Vulnerability
BugTraq ID: 4561
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4561
Summary:

PostBoard is a freely available, open source message board module for the
PostNuke content management system.  It is designed for use on the Unix
and Linux operating systems.

A problem with PostBoard may allow the execution of arbitrary script code
in the context of a site.  The problem is in the checking of some input.

PostBoard does not adequately sanitize input by board users.  Because of
this, it is possible for users of the board to insert script code in
message titles.  This would result in a user clicking the message and
executing the script code in the context of the site.

6. PostBoard BBCode Denial Of Service Vulnerability
BugTraq ID: 4562
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4562
Summary:

PostBoard is a freely available, open source message board module for the
PostNuke content management system.  It is designed for use on the Unix
and Linux operating systems.

A vulnerability exists in PostBoard's implementation of BBcode which makes
it possible for an attacker to starve resources on the host running the
affected software. In particular, it is possible to exploit the [code] tag
to create this effect. The [code] tag is used to quote samples of source
code without any of the special characters being interpretted. It is not
known whether other tags may also be exploited in this manner.

The consequence of exploitation is that the webserver will consume an
unusual amount of system resources. This may result in a denial of service
to the webserver and possibly the underlying system if adequate resource
limits are not in place.

If this issue is successfully exploited, the webserver will need to be
restarted for normal functionality to resume.

7. PostCalendar 3.0 Cross Site Scripting Vulnerability
BugTraq ID: 4563
Remote: Yes
Date Published: Apr 20 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4563
Summary:

PostCalendar 3.0 is a module for PostNuke that provides an interactive
events calendar that users can add entries to.  Under certain conditions
it fails to strip HTML or script from user supplied data, allowing
malicious code to be injected into event listings by users.

This is accomplished by submitted a normal plain-text event (as a logged
in user), proceeding to the preview screen and added the HTML or script
from there.

8. Microsoft Internet Explorer Self-Referential Object Denial of Service Vulnerability
BugTraq ID: 4564
Remote: Yes
Date Published: Apr 20 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4564
Summary:

Microsoft Internet Explorer 6 (perhaps other versions as well) is
vulnerable to a denial of service due to an error in handling certain
self-referential <OBJECT> definitions in HTML documents.  This occurs when
an object of type "text/html" is specified, with the DATA field
referencing the name of the HTML document in which it is defined.  There
may be other circumstances in which this sort of self-reference may lead
to a browser crash.

9. Faq-O-Matic Cross Site Scripting Vulnerability
BugTraq ID: 4565
Remote: Yes
Date Published: Apr 20 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4565
Summary:

Faq-O-Matic 2.711 and 2.712 is a web-based Frequently Asked Question (FAQ)
management system.  It is vulnerable to a cross site scripting issue
arising from a failure to filter HTML or script from a malformed query,
returning the submitted script as an error message which is then processed
by the browser.  This is done by submitting the script as an argument to
the Faq-O-Matic component "fom.cgi" - specifically, to the "file"
parameter.  Since this is an invalid argument, fom.cgi returns an error
message containing the script or HTML and the browser processes it as
though it originated from the website hosting Faq-O-Matic.

10. Macromedia Flash ActiveX Control Bandwidth Consumption Vulnerability
BugTraq ID: 4567
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4567
Summary:

The Macromedia Flash Player is available as an ActiveX plugin for
Microsoft Internet Explorer. An issue in version 6 of this component may
result in excessive bandwidth consumption.

Under normal usage, the Flash Player must download a variety of multimedia
resources, including video, sound and image files. Under some
circumstances, the user may navigate to a different page before this
process is complete. In this case, it is possible that the player will
continue to download outdated information, consuming uneccessary
bandwidth. As these files can be large, this may result in a denial of
service condition.

Macromedia has reported that only the ActiveX version of the Flash Player
suffers from this vulnerability.

11. Philip Chinery's Guestbook Script Injection Vulnerability
BugTraq ID: 4566
Remote: Yes
Date Published: Apr 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4566
Summary:

Philip Chinery's Guestbook is freely available guestbook software.  It
will run on most Unix and Linux variants, as well as Microsoft Windows
operating systems.

Philip Chinery's Guestbook does not filter HTML tags from form fields.
As a result, it is possible for an attacker to inject script code into
pages that are generated by the guestbook.  Additionally, script code is
not filitered from URL parameters, making the guestbook prone to
cross-site scripting attacks.

In both instances, it is possible for an attacker to cause arbitrary
script code to be executed in the browser of a web user, in the security
context of the website running the vulnerable guestbook.

This may allow the attacker to hijack web content or potentially steal
cookie-based authentication credentials.

This issue has been reported for Philip Chinery's Guestbook version 1.1.
Other versions may also be affected.

12. BSD exec C Library Standard I/O File Descriptor Closure Vulnerability
BugTraq ID: 4568
Remote: No
Date Published: Apr 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4568
Summary:

It has been reported that BSD-based kernels do not check to ensure that
the C library standard I/O file descriptors 0-2 are valid open files
before exec()ing setuid images.  Consequently, I/O channels that are
opened by a setuid process may be assigned file descriptors equivelent to
those defined in the C library as 'standard input','standard output', and
'standard error'.

When file descriptors are assigned, the lowest numerical value that is not
already open is used.  If a process has closed 0-2 prior to executing a
setuid image, these file descriptors will be assigned to the first I/O
resources opened or created by the process.

If a sensitive I/O channel has been opened by a setuid/setgid process and
assigned a standard I/O file descriptor, untrusted data may be written to
the sensitive channel by C library functions, due to the preprocessor
definitions of 'STDOUT' and 'STDIN'.  Data may also be read (and then
output, depending on the application) from the I/O resource corresponding
to the STDIN file descriptor.

Exploitation and consequence are dependent on the particular setuid/setgid
application.  It has been confirmed that local attackers can gain root
privileges through some utilities.

13. SLRNPull Spool Directory Command Line Parameter Buffer Overflow Vulnerability
BugTraq ID: 4569
Remote: No
Date Published: Apr 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4569
Summary:

SLRN is a freely available, open source news reading utility.  It is
developed and maintained by the SLRN project, and designed for use on
various operating systems.  This problem affects the UNIX and Linux
implementation.

It may be possible for a local user to gain elevated privileges.  The
problem is in the handling of long directory spool names.

Due to a boundary condition error, a buffer overflow condition exists in
spool directory names.  This problem affects the slrnpull program,
included as part of the slrn package.  When slrnpull is executed with the
-d flag, and a file name of greater than 4091 bytes, the overflow makes it
possible to overwrite process memory, including the return address.

While the default installation of slrnpull is as a non-privileged user
from source, some operating systems include slrnpull as a setuid or setgid
executable.  In including the program with these privileges, a local user
could exploit this overflow to execute user-supplied instructions, and
gain elevated privileges.

14. PsyBNC Oversized Passwords Denial Of Service Vulnerability
BugTraq ID: 4570
Remote: Yes
Date Published: Apr 22 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4570
Summary:

PsyBNC is a freely available, open source IRC bouncing server.  It is
available for the UNIX and Linux operating systems.

A problem with PsyBNC could lead to a denial of service.  The problem is
in the handling of long PsyBNC passwords.

Under some circumstances, it is possible for a remote user to crash a
vulnerable server.  Upon connection to a vulnerable system, if a user
sends a password of 9000 or more characters, and disconnects from the
system, the server process does not die.  Instead, the process continues
to live and consume a large amount of resources.

This vulnerability could result in a user launching several connection
attempts, sending long passwords to the PsyBNC server, and tying up large
amounts of system resources.  This could result in crash of the PsyBNC
server process, and potentially the server hosting the PsyBNC.

15. Matu FTP Client Buffer Overflow Vulnerability
BugTraq ID: 4572
Remote: Yes
Date Published: Apr 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4572
Summary:

Matu FTP is an ftp client that runs on various Microsoft Windows operating
systems.

An issue has been reported which could allow for a malicious ftp host to
execute arbitrary code on a Matu FTP client.

This is acheivable when a Matu FTP user connects to an ftp host, if the
FTP server '220' response is of excessive length. A stack-based overflow
condition can occur, potentially allowing for malicious administrators to
execute arbitrary code on (and gain control of) client hosts. However,
sending random data could cause the application to crash.

16. vqServer CGI Demo Program Script Injection Vulnerability
BugTraq ID: 4573
Remote: Yes
Date Published: Apr 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4573
Summary:

vqServer is a HTTP server implemented in Java. vqServer is available on
any architecture supporting Java, including Linux and Microsoft Windows.

vqServer supports a variety of CGI mechanisms, including Perl scripts,
executables and servlets. vqServer includes a number of demonstration
programs for these methods.

Issues have been reported with multiple scripts included with vqServer.
Reportedly, it is possible to inject JavaScript code through these
programs. In addition to cross site scripting issues, it has been reported
possible to inject script code into cookie content.

Exploitation of these sample programs may allow an attacker to execute
script code in the context of the page hosted with vqServer.

17. AOL Instant Messenger Data Interception Vulnerability
BugTraq ID: 4574
Remote: Yes
Date Published: Apr 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4574
Summary:

It is reportedly possible for a remote attacker to force a direct
connection or file transfer with an AOL Instant Messenger (AIM) client.

AIM accepts connections on port 4443 for direct connections and port 5190
for file transfers.  It is reportedly possible for an arbitrary host to
connect to these ports and receive data that the client happens to be
sending.  It has been reported that this situation is exploited by making
rapid connections to ports 4443 and 5190 in an attempt to connect to the
client at the moment it is sending the data.

A remote attacker may exploit this issue to intercept sensitive data that
the client is sending to another AIM user.

18. Apache Tomcat Servlet Path Disclosure Vulnerability
BugTraq ID: 4575
Remote: Yes
Date Published: Apr 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4575
Summary:

Apache Tomcat is a servlet container for use with the Java Servlet and
JavaServer Pages technologies.  Tomcat may be run on most Unix and Linux
variants as well as Microsoft Windows operating systems.

A problem in the default installation of Apache Tomcat may cause sensitive
information to be disclosed to remote attackers.

Apache Tomcat ships with a number of example classes (SnoopServlet and
TroubleShooter) which may reveal the absolute path of the Tomcat
installation when requested via HTTP.  These classes are included to serve
as an example for developers and are not intended to be used in production
environments.

This information will give the attacker an idea of the layout of the
filesystem on the host running Apache Tomcat.  Disclosure of this type of
sensitive information may aid in further attacks against the host running
the vulnerable software.

19. Summit Computer Networks Lil' HTTP Server Directory Traversal Vulnerability
BugTraq ID: 4576
Remote: Yes
Date Published: Apr 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4576
Summary:

Lil' HTTP server is a web server application for Windows environments and
is maintained by Summit Computer Networks.

An issue has been discovered in Lil' HTTP server, which could allow for a
remote user to disclose sensitive information to remote users.

Reportedly, including '../' character sequences when submitting a request
for a known file, will reveal the contents of the resource.

This information will assist attackers in further attacks against the
host.

It should be noted that SecurityFocus has not been able to successfully
reproduce this issue. Therefore, it is possible that the issue discussed
in BID 4153 may be related to the issue discussed here.

20. National Instruments LabVIEW HTTP Request Denial of Service Vulnerability
BugTraq ID: 4577
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4577
Summary:

A vulnerability has been reported in some versions of National Instruments
LabVIEW for Linux and Microsoft Windows.

LabVIEW includes an integrated HTTP server. If a malformed HTTP request is
received, it is possible to crash the LabVIEW Web Server and LabVIEW
itself. This condition occurs when an HTTP GET request is received and
terminated with two new line characters, as opposed to the compliant
carriage return / new line combination.

Exploitation of this vulnerability may result in a denial of service
condition. It is not currently known if exploitation will allow the
execution of arbitrary code as the server process.

It has been reported that this vulnerability may only be exploited if
logging is enabled on the web server.

21. CGIScript.NET csMailto Hidden Form Field Remote Command Execution Vulnerability
BugTraq ID: 4579
Remote: Yes
Date Published: Apr 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4579
Summary:

CGIScript.NET csMailto is a Perl script designed to support multiple
mailto: forms. A vulnerability has been reported in some versions of this
script.

Reportedly, configuration values used by the script are contained in
hidden form values. As a result, a remote attacker may trivially modify
these values between script invocations.

This is reported to have a number of consequences, including the ability
to execute arbitrary code on the vulnerable server, downloading arbitrary
files, gain administrative access to the script, and using the vulnerable
script as an open mail relay.

Reportedly csMailto attempts to use the HTTP Referrer value as a security
measure. Unfortunately, this information is also under the complete
control of the client, and it is trivial to provide an arbitrary value.

22. GNU Screen Braille Module Buffer Overflow Vulnerability
BugTraq ID: 4578
Remote: No
Date Published: Apr 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4578
Summary:

Screen is a freely available, open source terminal management software
package.  It is distributed and maintained by the Free Software
Foundation.  It is available for the Unix and Linux platforms.

A problem with screen may allow a local user to gain elevated privileges.
The problem is in the handling of long strings of input.

Under some circumstances, it may be possible for a local user to take
advantage of a buffer overflow in screen.  Due to insufficient bounds
checking performed by the braille module of screen, it is possible for a
local user to pass long strings of data to the screen program, which could
result in an overflow, and the overwriting of process memory.  This could
result in the execution of arbitrary code.

As the screen program is typically installed setuid root, any
user-supplied code would be executed as root.  This problem may be
exploited by the attacker placing the exploit code in a screenrc file, and
loading the file with the -c flag of screen.  This problem may also affect
earlier versions of the software.

23. Mosix Malformed Packet Handling Denial Of Service Vulnerability
BugTraq ID: 4580
Remote: Yes
Date Published: Apr 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4580
Summary:

Mosix is a parallel processing software package.  It is designed for use
on the Linux operating system.

A problem with Mosix could lead to a user denying service to cluster
processes.  The problem is in the handling of malformed packets.

It has been reported that Mosix does not properly handle certain
maliciously constructed packets.  When these malformed packets are
received by Mosix, it may react unpredictably, or become unstable.  The
precise nature of the crash-inducing packets is not known.

This vulnerability also reportedly affects Open-Mosix.

Successful exploitation may cause a failure of the process, resulting in a
denial of service.

24. Mosix ClumpOS Blank Default VNC Password Vulnerability
BugTraq ID: 4581
Remote: Yes
Date Published: Apr 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4581
Summary:

ClumpOS is a cd-based Linux and Mosix distribution.  It is maintained and
distributed by the Mosix project.

A problem with ClumpOS could allow unauthorized administrative access to a
vulnerable system.  The problem is the setting of passwords.

ClumpOS does not prompt a user to set a password for VNC when installed.
Instead, ClumpOS leaves the default password for VNC blank.  This could
allow remote root access to the system.

25. HP-UX Password File Corruption Vulnerability
BugTraq ID: 4582
Remote: No
Date Published: Apr 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4582
Summary:

A vulnerability has been reported in some versions of HP-UX.

A user may be able to corrupt password files using the passwd(1) command.
Any user which then attempts to authenticate could be denied access to the
host.

Under some circumstances, this may result in a denial of service
condition.

No further technical details are currently available. As additional
details are made available, this alert will be updated accordingly.

26. Internet Explorer Recursive JavaScript Event Denial of Service Vulnerability
BugTraq ID: 4583
Remote: Yes
Date Published: Apr 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4583
Summary:

An issue has been reported in some versions of Microsoft Internet
Explorer. It is possible for a malicious web page using JavaScript to
crash the browser process. Under some environments, this may impact the
underlying operating system as well.

This behavior has been reported under the following circumstances. An IMG
tag is created with an invalid SRC attribute, and a malicious script is
defined using the onError parameter for the tag. This script, in turn,
resets the SRC attribute to the same value. The result is an indirect
recursive call of the script, which is able to consume all available stack
memory.

It is possible that other conditions will exploit this vulnerability. This
has not, however, been confirmed.

Under these conditions, Internet Explorer has been reported to crash.
Under Windows 95 and 98 this has been reported to cause instability in the
operating system. More recent versions of Windows have been reported to be
unaffected.

27. Microsoft Outlook Express DOS Device Denial of Service Vulnerability
BugTraq ID: 4584
Remote: Yes
Date Published: Apr 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4584
Summary:

A denial of service issue has been reported in Microsoft Outlook Express.

Reportedly, this issue occurs if an HTML email message with a URL pointing
to a non-existent DOS-device (CON, AUX, PRN, NUL), is embedded in the
BGSOUND or IFRAME tag. Upon the user opening the mail message, Outlook
Express will consume 100% CPU usage.

Either the process is ended via the Task Manager or a system restart is
required in order to regain normal functionality.

It has also been reported that the offending message cannot be deleted
from the user's mailbox. If this is the case, re-installation of Outlook
Express may be required.

This issue may be the result of an unchecked buffer. If this is the case,
there is a possibility that arbitrary code may be executed on the
vulnerable target. However, this has not yet been confirmed.

28. Oracle E-Business Suite 11i Unauthorized PL/SQL Procedure Access Vulnerability
BugTraq ID: 4551
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4551
Summary:

Oracle has reported the existence of a vulnerability in Oracle E-Business
Suite 11i.  Versions 11i.1 through i11.6 are affected.

The vulnerability allows for users to execute unauthorized procedures
inside the Oracle Applications Database.  The PL/SQL procedures may either
be predefined or user-defined.  The condition appears to be due to an
access validation error, as exploitation requires only modification of the
browser URL.

This may result in a loss of data, elevation of privileges or other
compromise.  Fixes have beem made available by Oracle.

29. IcrediBB Script Injection Vulnerability
BugTraq ID: 4548
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4548
Summary:

IcrediBB is freely available web forum software.  It is written in PHP and
will run on most Unix and Linux variants, as well as Microsoft Windows
operating systems.

IcrediBB does not adequately filter HTML tags from forum message form
fields. This may enable an attacker to inject malicious script code into
forum messages. In particular, script code is not sufficiently sanitized
from the thread title and body form fields.  When a web user views a
message containing the attacker's script code, the malicious script code
is executed in their browser, in the security context of the website
running the vulnerable software.

An attacker who exploits this may be able to hijack web content or steal
cookie-based authentication credentials.

30. Foundstone FScan Banner Grabbing Format String Vulnerability
BugTraq ID: 4549
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4549
Summary:

FScan is a free network scanning utility distributed and maintained by
Foundstone.  This problem affects the version available for the Microsoft
Windows platform.

A problem with the software package could make it possible to remotely
execute code on a vulnerable host.  The problem is in the banner-grabbing
function of the software.

Under some circumstances, it may be possible to execute arbitrary code on
a scanning host.  This is due to FScan not properly handling banner data
supplied by scanned hosts when the scanner is executed against them.
This problem is the result of a format string vulnerability, and could
lead to the overwriting arbitrary locations in memory, and execution of
attacker supplied code.

This vulnerability may only be exploited when the FScan software has been
configured to grab banners from scanned hosts.  The attacker must place
the exploit string in the banner of a host which will be scanned by FScan.
The result is the execution of code with the privileges of the user
running the FoundScan program.

31. WorkforceROI XPede Unprotected Administrative Facilities Vulnerability
BugTraq ID: 4552
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4552
Summary:

XPede is web-based project accounting software.  It is available for
Microsoft Windows operating systems.

XPede does not prompt non-administrative users for administrative
authentication credentials if they attempt to access an administrative
script. This may enable a malicious XPede user to gain unauthorized access
to the administrative facilities of the software.  For example, the
malicious user may access the '/admin/adminproc.asp' script to
enumerate/add/delete other users of the XPede project accounting system.

Successful exploitation would require the attacker to know the
name/location of administrative scripts.

This issue was reported for XPede 4.1.  Other versions may also be
affected.

32. XPede DataSource.ASP Information Disclosure Vulnerability
BugTraq ID: 4553
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4553
Summary:

XPede is web-based project accounting software.  It is available for
Microsoft Windows operating systems.

XPede uses Microsoft SQL Server to store its data.

When the XPede datasource.asp script is accessed it displayed a HTML form
that contains the database user name.  This script may be accessed by
arbitrary web users without requiring any sort of authentication.

Additionally, the script provides an interface for changing the user's
password.  To change the password, the current password must be provided.
However, since this interface is exposed and the database user name has
also been disclosed, this may provide an attacker with an opportunity to
brute-force the password of the database user.

This issue was reported for XPede 4.1.  Other versions may also be
affected.

33. WorkforceROI XPede Sprc.ASP SQL Injection Vulnerability
BugTraq ID: 4555
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4555
Summary:

XPede is web-based project accounting software.  It is available for
Microsoft Windows operating systems.

XPede is back-ended by Microsoft SQL Server.

A vulnerability in the XPede sprc.asp script makes it possible for a
malicious user to launch SQL injection attacks.  The vulnerable script
contains an option entitled "Qry", which may enable the attacker to inject
a literal SQL query, which will be executed by the underlying database.
This may be possibly be exploited to list database tables or modify/delete
data.  User and administrative authentication credentials are stored in
the database, in addition to other types of project accounting related
information.

Vulnerabilities or misconfigurations in the underlying database might also
be exploited via this issue.

This issue was reported for XPede 4.1.  Other versions may also be
affected.

34. WorkforceROI XPede Weak File Protection Vulnerability
BugTraq ID: 4554
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4554
Summary:

XPede is web-based project accounting software.  It is available for
Microsoft Windows operating systems.

When a user submits an expense claim, the file is saved in the
world-readable '/reports/temp' directory.  By default this directory is
indexable.  Remote clients may be able to access the temporary reports of
other users by accessing this directory.

Furthermore, the files may still be obtained if indexing has been disabled
for the '/reports/temp' directory.  For security reasons, the filenames
assigned are partially random.  Unfortunately the scheme is weak: the
random component of the filename is only 5 bytes in length and limited to
alpha-numeric characters.  This makes the space of possible filenames
relatively small and easily exhausted by an automated guessing utility.

As a result, it may be possible for a user to obtain sensitive information
which could assist in social engineering attacks.

This issue was reported for XPede 4.1.  Other versions may also be
affected.

35. WorkforceROI XPede Arbitrary Time Sheet Disclosure Vulnerabiltiy
BugTraq ID: 4556
Remote: Yes
Date Published: Apr 19 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4556
Summary:

XPede is web-based project accounting software.  It is available for
Microsoft Windows operating systems.

An issue has been reported in Xpede which could allow a remote user to
access the time sheets of other users.  The vulnerability is in the
'ets_app_process.asp' script and is due to a lack of adequate
authorization checks.  It is possible for remote attackers to obtain user
timesheets by simply modifying the incrementally assigned TSN id script
parameter.  If a timesheet exists with the attacker-supplied ID number, it
will be output to the client.

As a result, unauthorized users could reveal sensitive user information.
This information may be used to assist in social engineering attacks.

This issue was reported for XPede 4.1.  Other versions may also be
affected.


III. SECURITYFOCUS NEWS AND COMMENTARY
--------------------------------------
1. FAA Confirms Hack Attack
By Kevin Poulsen

Self-styled patriotic intruders deface a government airline security site
and download a detailed screener database. Their proclaimed mission:
saving the U.S. from foreign cyber terrorists.

http://online.securityfocus.com/news/378

2. Microsoft Yanks Office Tools After Security Report
By Brian McWilliams , Newsbytes

Microsoft [NASDAQ:MSFT] has removed a collection of tools for its Office
suite following an independent report that the tools may open security
vulnerabilities.

http://online.securityfocus.com/news/377

3. Network Associates Finds Errors, Drops McAfee Bid
By Dick Kelsey , Newsbytes

Web security firm Network Associates [NYSE:NET] today said it will restate
its 1999 and 2000 financial reports after finding accounting problems in
both statements.

http://online.securityfocus.com/news/376

4. Europeans Roll Out PKI For Niche Applications
By Robin Arnfield , Newsbytes

Europe is seeing a slow but genuine uptake of digital certificates. But
instead of being used as an all-purpose tool, digital certificates are
being deployed for niche applications, especially secure document
delivery.

http://online.securityfocus.com/news/375


IV.SECURITYFOCUS TOP 6 TOOLS
----------------------------
1. Ghost Port Scan v0.9.3-FRC
by [email protected]
Relevant URL:
http://gps.sourceforge.net/
Platforms: Linux
Summary:

GPS is an advanced port scanner and a firewall rules disclosure software,
which uses IP and ARP spoofing, sniffing and other technics in order to
perform stealth information collections. GPS is especially efficient in
LAN pen-testing, due to its ability to disclose the firewall settings of a
host.

2. GreedyDog v2.3
by UNYUN, [email protected]
Relevant URL:
http://www.shadowpenguin.org/sc_toolbox/unix/gdd
Platforms: FreeBSD, IRIX, Linux, Solaris, SunOS
Summary:

This program is one of the ethernet packet sniffers for LINUX, FreeBSD,
SunOS4.1, Solaris2, and IRIX that can log the all packets in each session
of telnet, rlogin, pop3, and ftp. If you install this program in the
cracked server, you can also know the cracking process and the location of
rootshell by the crackers. The logs of this tool is the evidence of the
cracking, this tool is also useful for administrators.

3. Demarc PureSecure v1.6
by DEMARC Security
Relevant URL:
http://www.demarc.com/
Platforms: BSDI, FreeBSD, HP-UX, Linux, NetBSD, OpenBSD, Perl (any system
supporting perl), UNIX, Windows 2000, Windows NT, Windows XP
Summary:

Instead of having one program perform file integrity checks, another
program monitoring the connectivity and health of your network, and yet
another monitoring your network for intrusion detection attempts, Demarc
PureSecure combines all these services into one powerful client/server
program. Not only can you monitor the status of the different machines in
your network, but you can also respond to changes in your network all from
one centralized location.

Security is already a full time job in any network, and the burden of
monitoring the reports from multiple programs across dozens of servers can
result in information overload. The human mind can only process so much
data at any given time before it simply becomes too much to analyze.
Demarc PureSecure centralizes the reporting and analysis for the entire
network which allows you to more easily weed out the important data from
the superfluous background noise, thereby targeting your efforts where
they really belong.

4. WebProxy v1.0
by Frank Swiderski [email protected]
Relevant URL:
http://www.atstake.com/research/tools/index.html#WebProxy
Platforms: Linux, Solaris, SunOS, Windows 2000, Windows 95/98, Windows NT
Summary:

WebProxy 1.0 is a cross-platform/browser security tool for use in auditing
web sites. Installed as a proxy for your browser, WebProxy allows you to
intercept, modify, log, and re-submit requests, both HTTP and HTTPS.
Editing capabilities include parsing of query parameters, request headers,
and POST parameters, as well as cookie editing. The convenient "browse
from here" capability allows you to edit and resubmit previous requests
and continue browsing on from the returned page. Request interception
allows on-the-fly editing of requests based on a matching regular
expression. There is also dynamic certificate generation. Use WebProxy for
SQL injection, cookie manipulation, parameter testing, or simply
monitoring of requests.

5. EGADS v0.9
by Secure Software Solutions
Relevant URL:
http://www.securesw.com/egads/
Platforms: UNIX, Windows 2000
Summary:

EGADS is a system service and library for providing secure random numbers.
It contains an implementation of the Tiny pseudo-random number generator
and the Tiny entropy gateway. Tiny is an evolution of Yarrow, and was
designed by John Kelsey (an original designer of Yarrow) and John Viega.
We are currently preparing a white paper on the Tiny algorithm.

EGADS provides the same kind of functionality as /dev/random and
/dev/urandom on Linux systems, but works on Windows, and as a portable
Unix program.

EGADS is available as a portable user-level daemon for Unix systems, and
as a service for Windows 2000 machines. An XP-compatible version will be
available shortly.

6. RATS (Rough Auditing Tool for Security) v1.4
by Secure Software Solutions
Relevant URL:
http://www.securesw.com/rats/
Platforms: Windows 2000, Windows 95/98, Windows NT
Summary:

RATS, the Rough Auditing Tool for Security, is a security auditing utility
for C and C++ code. RATS scans source code, finding potentially dangerous
function calls. The goal of this project is not to definitively find bugs
(yet). The current goal is to provide a reasonable starting point for
performing manual security audits.


V. SECURITY JOBS SUMMARY
------------------------
1. Application Security - Chicago - Greythorn (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/5544986F9407D611A5900008C70964060B99A5@EXCHANGE

2. Expert IDS Person Available (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

3. INFOSEC Guy - Seeking a Change (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

4. Application Security Architect/Engineer #510 - Chicago, IL - $100k (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

5. Federal Sales Manager - #698 - VA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

6. Seeking Entrepreneurial Security Engineer (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

7. Inside Sales-Network/Information Security -Boston,MA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

8. Technical Marketing Engineer  position in MA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

9. Security opportunities @ Ciber (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/FE1AFEE45C08D411A7D70008C759418108CAB9ED@exch-corp-den2.ciber.com

10. Looking job outside my country. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

11. Senior/Management Security Position Wanted (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

12. Network Security Sales Rep. needed in NJ (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

13. Encryption Security Manager-Baltimore,Md. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

14. Several Security system positions in MD,DC,VA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

15. Network Security Analyst (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

16. Security Application Developer (Austin, TX) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

17. Security Test Engineer (Austin, TX) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

18. 2 Senior Systems Engineer positions (east coast) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

19. Seeking Management Position (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

20. ids/security person looking for a team environment (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

21. Positions (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/009001c1e7da$a7564460$0100a8c0@TDIXP

22. Senior Security Guy Looking For Interesting Gig (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

23. Seeking Security Engineer (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

24. Seeking Security Position (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]


VI. INCIDENTS LIST SUMMARY
-------------------------
1. Winfreez DoS question (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

2. compromised cisco (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

3. ftp (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/000601c1ebd2$dd9dcb50$0103a8c0@HUNDLEY0012K

4. ftp (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

5. Big traffic on 412/tcp (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

6. Rootkit or trojan (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/3CC49EC9.31454.10C033C@localhost

7. Port 6588 Probes from SA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

8. illogic rootkit (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

9. Anyone caught a packet of ... ? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/8F2D7C893282D3118D9A00508B0909F20401C899@ntexgkrl01

10. Wu-ftpd 2.6.2 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

11. illogic rootkit (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]


VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. Sudo version 1.6.6 now available (fwd) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

2. /lib/ld-2.2.4.so (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

3. apache + .htpasswd - bypass pwd check (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

4. apache + .htpasswd - bypass pwd check (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

5. nobody suid shell (kind of relationship with the ld-2.2.4 thread...) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/002501c1ec72$a7b1f890$110010ac@matrix2k

6. Privacy leak while surfing (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

7. TTP/1.0 Remote BufferOverflow? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

8. draytek-Router: undocumented open configuration ports (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

9. Eudora Logging (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

10. Privacy leak while surfing (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

11. Microsoft Baseline Security Analyzer exploit (Exposed vulnerabilities' list) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

12. cheers (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

13. Cisco response to Cisco VPN Client under XP (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

14. cheers (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

15. /lib/ld-2.2.4.so (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

16. ecartis / listar PoC (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

17. slrnpull -d PoC (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

18. Fw: (Case #4944266) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/014501c1ebf3$78d30480$0a01010a@SONIC

19. php & passthru & system (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

20. php & passthru & system (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

21. more info on the iosmash.c exploit (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

22. Cross site scripting in almost every mayor website (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

23. Rodopi Security/Functionality (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/000d01c1ebb3$26fa3650$030010ac@purity

24. 'Leave' behavior after stack overflow. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

25. Keyservers Cross Site Scripting (When CSS Gets Dangerous) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

26. full info on iosmash.c as non wheel user (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

27. ld.so (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

28. [Fwd:  weird IE6 crash] (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

29. Remote MS02-18 Patch Checker (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/9D884881F5E1F24FB845967851720FC302C9BA2B@red-msg-12.redmond.corp.microsoft.com

30. PHP problem (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/024901c1ea21$14b48600$0403a8c0@guinness

31. Cross site scripting @verisign.com and @cybercash.com (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

32. Mildly useful tool. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

33. Security holes : Ultimate PHP Board (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

34. Spanning Tree Switch Exploits? Fact or Fiction? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

35. Remote MS02-18 Patch Checker (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

36. OpenSSH 2.2.0 - 3.1.0 server contains a locally exploitable   buffer overflow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/024201c1e8ac$c81bf960$bd2a9aca@SERVER

37. OpenSSH 2.2.0 - 3.1.0 server contains a locally exploitable    buffer overflow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

38. weird IE6 crash (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]


VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Remote perf counter access (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/D9CC6F05BDF4D211B6EF00508BAD0786021D1926@SRVNT-TVW09

2. problems with hotfix rollup, windows update, mbsa, hfnetchk, and (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

3. Network Settings and Power Users (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

4. Update on status of IE security (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/B8ED98E8.92B%[email protected]

5. Question:  How To Secure a Public Access Workstation (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

6. Microsoft Cluster in DMZ - Need Advice (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/000e01c1ec6f$fee2b580$caf4450a@deth

7. MS defends MBSA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/6D9F17809993D31198B100508B62016106F46B09@nt-exchange.ifas.ufl.edu

8. Network Settings and Power Users (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

9. problems with hotfix rollup, windows update, mbsa, hfnetchk, and    other tools (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

10. Remote perf counter access (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/1019698417.1441.9.camel@spectre

11. Role based access in Win2k w/o AD (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

12. Follow-up on Registry key containing events to be audited (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

13. MS defends MBSA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

14. IE 5.5 security (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

15. Securing IIS (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

16. SecurityFocus Microsoft Newsletter #83 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

17. Securing IIS (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/8EC06C4282C97848B85CA4C23906991101156047@ntx1.forest.netvision.net.il

18. Registry keys for EventLog audit events (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/3CC457ED.14103.362F46@localhost

19. Question:  How To Secure a Public Access Workstation (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/D5E5F4682E75D41185CD00D0B79DC56F04BB1AC5@exchfed01.federatedinv.com

20. HFNetCheck Pro in an NT-only environment? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/3CC40406.8885.10E21A8@localhost

21. Microsoft Cluster in DMZ - Need Advice (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

22. windows domain question (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/1019278924.1590.37.camel@FranksLaptop

23. windows domain question (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

24. OWA and URLScan (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

25. URLScan 2.5 SRP (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/9AACD631D86FD51182C500306E02085801E014BB@asbutl16.asb.countrycompanies.com

26. Microsoft Security Bulletin MS01-022 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

27. Ensuring Disabling/Uninstalation of Windows XP Firewall in LAN enviro. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

28. OWA and URLScan (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/859A11E09843BC48A67C176D12E38857337619@BMA-EXCHANGE-2

29. Ensuring Disabling/Uninstalation of Windows XP Firewall in  LAN enviro. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

30. Win 98 Security (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/F50520282C60D511849600306E07D1CA4A6E8D@MGEX1

31. Microsoft Security Bulletin MS01-022 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

32. Win 98 Security (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

33. Ensuring Disabling/Uninstalation of Windows XP Firewall in LAN enviro. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/001301c1e73b$e8f28860$a78386cb@hedni01


IX. SUN FOCUS LIST SUMMARY
----------------------------
1. How do I set-up secure automated file push and pull? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]

2. new zlib patch (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]

3. Looking for ftp over SSL (TLS) daemon... (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]


X. LINUX FOCUS LIST SUMMARY
---------------------------
1. No Root Shell with SUID /bin/bash (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

2. Adore over adore? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/8A87A19E6153D4119FA800508BDF093207F9E366@USHEM202

3. Adore over adore? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

4. HiverCon 2002 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/02041921355504.00223@carmen


XI. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored by: Borderware

Email: whether you are running MS Exchange, Lotus Notes or a Unix mail
system, you have your hands full managing email delivery, spam, viruses
and in implementing workable content controls.

The BorderWare Mail Gateway gives the control you need in a hardened
secure package that can be deployed right on the internet. Not only that,
it provides a unique, easy-to-deploy remote access system that allows your
users to get their email without forwarding or duplication.

Find out more at http://www.borderware.com/mg/

-------------------------------------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.