SecurityFocus Newsletter #143

John Boletta <[email protected]>
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #143
-----------------------------

This Issue is Sponsored by: Tumbleweed Communications

FREE ENTERPRISE SECURITY BREAKFAST SEMINARS

How do you make your email more secure?  How do you extend your network,
while still protecting against viruses, spam, and breaches of
confidentiality?

Find out by attending "Securing The Extended Enterprise", a FREE breakfast
seminar sponsored by Tumbleweed Communications and METAGroup.  Coming to
10 North American cities in May and June. Sign up now!
https://www.tumbleweed.com/dy/security

------------------------------------------------------------------------

I. FRONT AND CENTER
     1. VBA Emulation: A Viable Method of Macro Virus Detection? Part Two
     2. Restricting UNIX Users
     3. No Stone Unturned, Part Three
     4. IDS Evasion Techniques and Tactics
II. BUGTRAQ SUMMARY
     1. Nullsoft Winamp Minibrowser ID3v2 Buffer Overflow Vulnerability
     2. Intel D845 Motherboard BIOS Series Arbitrary Boot Media...
     3. PHP-Survey Global.INC Information Disclosure Vulnerability
     4. Qualcomm QPopper Bulletin Name Buffer Overflow Vulnerability
     5. SAP R/3 with Oracle Unauthorized Data Access Vulnerability
     6. DNSTools Authentication Bypass Vulnerability
     7. Blahz-DNS Direct Script Call Authentication Bypass Vulnerability
     8. ATGuard Personal Firewall Outgoing Connection Restriction...
     9. PhpWebGallery Cookie Manipulation Account Compromise Vulnerability
     10. Livre Dor' Information Disclosure Vulnerability
     11. 0wn f0rum Script Injection Vulnerability
     12. Solaris admintool Local Buffer Overflow Vulnerability
     13. Solaris cachefsd Buffer Overrun Vulnerability
     14. Solaris cachefsd Denial of Service Vulnerability
     15. CIDER Shadow Analyzer Remote Command Execution Vulnerability
     16. Solaris AdminTool Media Installation Path Buffer Overflow...
     17. Solaris LBXProxy Display Name Buffer Overflow Vulnerability
     18. CDE DTPrintInfo Help Volume Search Buffer Overflow Vulnerability
     19. AutoLog IP Spoofing Vulnerability
     20. Messagerie Arbitrary User Removal DoS Vulnerability
     21. 3Com 3CDaemon Buffer Overflow Vulnerability
     22. Mozilla / Netscape 6 XMLHttpRequest File Disclosure Vulnerability
     23. Recherche Cross-Site Scripting Vulnerability
     24. Messagerie Remote File Include Vulnerability
     25. Sun Solaris RWall Daemon Syslog Format String Vulnerability
     26. Kv Guestbook Cross-Site Scripting Vulnerability
     27. Netscape/Mozilla IRC Buffer Overflow Vulnerability
     28. SGI IRIX CPR Buffer Overflow Vulnerability
     29. Netscape/Mozilla/Galeon Local File Detection Vulnerability
     30. BEA Systems WebLogic Server URL Parsing Path Disclosure...
     31. BEA Systems WebLogic Server Null Character DOS Device Denial...
     32. BEA Systems WebLogic Server URL Parsing Source Code...
     33. ISS RealSecure DHCP Signature Remote Denial Of Service...
     34. SGI Irix Insecure IPFilter Device Permissions Vulnerability
     35. Paul L Daniels alterMIME Denial of Service Vulnerability
     36. MyGuestbook Script Injection Vulnerability
     37. HP MPE/iX FTPSRVR Arbitrary Shell Command Execution Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
     1. Melissa virus author jailed for 20 months
     2. Hackers Continue 'Early Warning' Attacks On U.S. Web Sites
     3. WinAmp's 'malicious MP3' vuln
     4. New Stealth Attack Found Against Personal Firewalls
IV.SECURITYFOCUS TOP 6 TOOLS
     1. Astaro Security Linux (ASL) v3.052(beta)
     2. pam_hbci v1.0a
     3. Linux Security Auditing Tool v0.5.0
     4. Secure FTP Wrapper v2.1.1
     5. Gringotts v0.4.4
     6. Port Scan Attack Detector (psad) v0.9.8
V. SECURITYJOBS LIST SUMMARY
     1. New York city based security professional looking for HIPAA work
     2. FW: failure notice (Thread)
     3. (job offered) Forensic Security Consultant, Seattle, Washington
     4. List slow down (Thread)
     5. Junior Level position (Thread)
     6. lots of experience, available immediately (Thread)
     7. Security Consultant position in No. VA (Thread)
     8. Entry Level Position (Thread)
     9. URGENT JOB REQUIREMENT (Thread)
     10. TX Jobs-Sr embedded engineer & Security Test Engineer (Thread)
     11. Sales Engineer-Security SW firm in NYC/NJ area-immediate (Thread)
VI. INCIDENTS LIST SUMMARY
     1. 'rooted' NT/2K boxen? (Thread)
     2. ssh scans using username 'test' or 'oracle'? (Thread)
     3. Windows Systems Defaced (Thread)
     4. A friend's cable modem Linux machine just got compromised (Thread)
     5. Tuxkit (Optic Kit?) -cracked (/dev/tux) (Thread)
     6. Honeynet Project -> The Reverse Challenge (Thread)
     7. New nimda variant? (Thread)
     8. Strange hidden messages in email (Thread)
     9. Strange hidden messages in email (Thread)
     10. FTP Followup (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. Preventing XSS in PHP... (Thread)
     2. Wlan @ bestbuy is cleartext? (Thread)
     3. static char overflow (Thread)
     4. more best buy media coverage (Thread)
     5. Preventing CSS in PHP... (Thread)
     6. Macromedia Flash Activex Buffer overflow (Thread)
     7. Classic Cross Site Scripting: Gibson Research Corporation (Thread)
     8. Best Buy / 802.11 (Thread)
     9. Buffer overflow or overrun? (Thread)
     10. ADT enterNET and Symantec Ghost (Thread)
     11. Wlan @ bestbuy is cleartext? (Thread)
     12. Fwd: Re: Wlan @ bestbuy is cleartext? (Thread)
     13. Fwd:  Wlan @ bestbuy is cleartext? (Thread)
     14. Wireless Point of Sale Solutions (Thread)
     15. latest Progress patch has suid issues AGAIN. (Thread)
     16. AOL passwords (Thread)
     17. AOL passwords / crypt() and online brute forcing (Thread)
     18. SECURITY CAMERA WAR DRIVING (Thread)
     19. AOL passwords / crypt() and online brute forcing (Thread)
     20. SECURITY CAMERA WAR DRIVING (Thread)
     21. FW: Wlan @ bestbuy is cleartext? (Thread)
     22. AOL passwords (Thread)
     23. [Fwd: FW: XP Screen Saver password uses Old password until...
     24. Spanning Tree Switch Exploits? Fact or Fiction? (Thread)
     25. XP Screen Saver password uses Old password until logout or New
     26. [Fwd: FW: XP Screen Saver password uses Old password until
     27. XP Screen Saver password uses Old password until logout or Newone
     28. XP Screen Saver password uses Old password until logout or New
     29. XP Screen Saver password uses Old password until logout or    New
     30. Cross Site Scripting? (Thread)
     31. Call For Papers - Canadian Security & Intelligence Conference
     32. Hacker's Digest Issue Four Spring 2002 (Thread)
     33. AW: Buffer overflow or overrun? (Thread)
     34. cross site scripting ? (Thread)
     35. Security Research Group (Thread)
     36. The Hazard of using 'printer friendly' functions on commercial
     37. The Hazard of using 'printer friendly' functions on commercial
     38. Security Research Group (Thread)
     39. Fw: Security Research Group (Thread)
     40. QPopper 4.0.4 buffer overflow (Thread)
     41. Multiple CSS/XSS vulnerabilities on directNIC.com (Thread)
     42. apache + .htpasswd - bypass pwd check (Thread)
     43. Security holes in 11 products... (Thread)
     44. apache + .htpasswd - bypass pwd chec (Thread)
     45. /lib/ld-2.2.4.so (Thread)
     46. nobody suid shell (kind of relationship with the ld-2.2.4
     47. apache + .htpasswd - bypass pwd check (Thread)
     48. TTP/1.0 Remote BufferOverflow? (Thread)
     49. I'm back (Thread)
     50. Microsoft Baseline Security Analyzer exploit (Exposed
     51. ecartis / listar PoC (Thread)
     52. Microsoft Baseline Security Analyzer exploit (Exposed
     53. TTP/1.0 Remote BufferOverflow? (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. 'rooted' NT/2K boxen? (Thread)
     2. Rolling out patches (Thread)
     3. Strange behavior after removing Klez on Win2000 server (Thread)
     4. Windows Systems Defaced (Thread)
     5. Access is denied: driver signing responsible (Thread)
     6. Access is denied (Thread)
     7. Rolling out patches (Thread)
     8. Microsoft Win2k VPN server placement (Thread)
     9. Microsoft Win2k VPN server placement (Thread)
     10. Windows XP Professional Account Lockouts (Thread)
     11. Remote perf counter access (Thread)
     12. Bypassing Windows 2000 Domain Password settings (Thread)
     13. Admin Preparation for .NET (Thread)
     14. PDC -> Workstation Registry Connect (Thread)
     15. PDC -> Workstation Registry Connect (Thread)
     16. Windows XP Professional Account Lockouts (Thread)
     17. SecurityFocus Microsoft Newsletter #84 (Thread)
     18. Account Permissions (Thread)
     19. Account Permissions (Thread)
     20. Remote perf counter access (Thread)
     21. NTFS Alternate Data Streams (Thread)
IX. SUN FOCUS LIST SUMMARY
     1. Switching audit files under Solaris 8 via cron (Thread)
     2. User Time Restrictions on Solaris 8 (Thread)
     3. How do I set-up secure automated file push and pull? (Thread)
X. LINUX FOCUS LIST SUMMARY
     1. AW: entry in /etc/passwd (Thread)
     2. Trimming replies (Thread)
     3. entry in /etc/passwd (Thread)
XI. SPONSOR INFORMATION


I. FRONT AND CENTER
-------------------
1.  VBA Emulation: A Viable Method of Macro Virus Detection? Part Two
By Gabor Szappanos

This is the second of two articles discussing emulation as a viable method
of virus detection. In this article, we will discuss code execution flow,
underlying operating system problems, and incompatibility issues with
incompatibility in different versions of Office, as well as VBA emulator
environment.

http://online.securityfocus.com/infocus/1576

2. Restricting UNIX Users
by Anton Chuvakin, Ph.D.

Stories of cruel system administrators oppressing poor users have been
around since the rise of UNIX in the 1970s. Users are inherently limited
in what they can do on a UNIX system due to file permissions, passwords
and other standard UNIX controls. However, it is often necessary to
further restrict system users in other ways, both to protect them from
themselves and to protect the system from the malicious or overly
"playful" users. This article will discuss ways in which security
administrators can limit what users are able to do on a UNIX system, with
a particular focus on Linux. Both local and remote users will be
considered. However, restricting root users from doing things on the
system (while possible) is a somewhat different story and will not be
addressed in detail here.

http://online.securityfocus.com/infocus/1575

3. No Stone Unturned, Part Three
by H. Carvey

This is the third installment of a five-part series describing the
(mis)adventures of a sysadmin named Eliot and his haphazard journey in
discovering “The Way” of Incident Response. As we left off last time,
Eliot had just begun compiling a list of tools that would be helpful in
incident investigation when he was interrupted by a call from Dave, a sys
admin with a branch office on the West Coast. Dave had asked for Eliot's
assistance with an apparent incident. Now, having begun an investigation,
Eliot was baffled and had asked Dave for some clarifying information.

http://online.securityfocus.com/infocus/1574

4. IDS Evasion Techniques and Tactics
By Kevin Timm

Blackhats, security researchers and network intrusion detection system
(NIDS) developers have continually played a game of point-counterpoint
when it comes to NIDS technology. The BlackHat community continually
develops methods to evade or bypass NIDS sensors while NIDS vendors
continually counter act these methods with patches and new releases.
Throughout this article we will explain basic evasion techniques as well
as suggest fixes or what to look for in many of these attacks.

http://online.securityfocus.com/infocus/1577


II. BUGTRAQ SUMMARY
-------------------
1. Nullsoft Winamp Minibrowser ID3v2 Buffer Overflow Vulnerability
BugTraq ID: 4609
Remote: Yes
Date Published: Apr 26 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4609
Summary:

Nullsoft Winamp is a media player for Microsoft Windows supporting MP3 and
other filetypes.

ID3v2 is a tagging system that enables users to include relevant
information about audio files within them.

Versions of Winamp are vulnerable to a stack overflow triggered during the
processing of ID3v2 tags.

If a user modifies the title field of the ID3v2 tag with arbitrary
characters, when parsed by Winamp, the overflow occurs.

This has only been reported to occur when the minibrowser is enabled. By
design, the player will prepare to connect to the Winamp site, in order to
gather additional information on the media file. Winamp constructs a URL
containing the data from the file's ID3v2 tag, once the URL is created,
the extraneous data in the title field will overflow the affected buffer.

This overflow could overwrite stack variables, including the return
address, and be used to execute arbitrary code. However, including random
data could cause the application to crash.

It should be noted that this was tested on version 2.79, previous versions
may also be affected by this issue.

2. Intel D845 Motherboard BIOS Series Arbitrary Boot Media Vulnerability
BugTraq ID: 4610
Remote: No
Date Published: Apr 26 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4610
Summary:

The D845 series motherboards are a product of Intel.  These motherboards
are designed to support the Pentium 4 processor.

Under some circumstances, it may be possible for a local user to change
the boot media of a system.  The problem is in the use of special keys.

When a system using a D845 series motherboard is booted, it is possible to
halt the boot to change the boot media, even if a BIOS password is set.
By pressing the F8 key, the D845 BIOS will give a user at the console a
menu.  From this menu, a user may specify a different media than the
default from which the system is to be booted.  Any password set on the
BIOS will be circumvented by this procedure.

The problem makes it possible for a user with local access to the system
to alter the boot configuration.  Additionally, the user may be able to
install new operating systems/software on the system, or other activity.
This problem reportedly affects the D845HV and D845WN model motherboards.

3. PHP-Survey Global.INC Information Disclosure Vulnerability
BugTraq ID: 4612
Remote: Yes
Date Published: Apr 26 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4612
Summary:

PHP-Survey is a web-based survey engine.  It is written in PHP and will
run on most Unix and Linux variants.  It is back-ended by a MySQL
database.

PHP-Survey comes with a script entitled 'global.inc', which contains
configuration information such as the name of the local host, database
credentials, and credentials for the survey administrator.  This file is
not interpreted as a PHP script if requested via HTTP, allowing remote
attackers to trivially gain access to the sensitive information contained
in 'global.inc'.

4. Qualcomm QPopper Bulletin Name Buffer Overflow Vulnerability
BugTraq ID: 4614
Remote: No
Date Published: Apr 28 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4614
Summary:

QPopper is a freely available, open source software package distributed by
Qualcomm.  It is designed for use on various operating systems, although
this problem affects the Unix and Linux platforms.

A problem with the software may allow a local user to execute code.  The
problem is in the handling of bulletins.

QPopper does not sufficiently check bounds on some data.  When a user
supplies a bulletin with a long name (greater than 256 bytes), a buffer
overflow occurs.  This could result in the overwriting of process memory,
including the return address within the stack, and code execution.

This problem makes it possible for a local user to execute arbitrary
commands with the privileges of the QPopper process.  Typically, this
process is started by root, which would therefore allow execution of code
with root privileges.

It should be noted that QPopper servers that do not process a users
.qpopper-options file are not vulnerable to this problem.

5. SAP R/3 with Oracle Unauthorized Data Access Vulnerability
BugTraq ID: 4613
Remote: Yes
Date Published: Apr 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4613
Summary:

A weak default installation issue has been reported, unauthorized users
could compromise SAP R/3 data.

Reportedly, SAP R/3 fails to verify user permissions. As a result,
connecting to the Oracle listener will enable any user to read, write and
modify SAP data. In order to exploit this issue, knowledge of the System
ID (SID) is required.

It should be noted that this issue has only been tested on Oracle, SAP R/3
runs on several databases, therefore other implementations may be affected
by this issue.

6. DNSTools Authentication Bypass Vulnerability
BugTraq ID: 4617
Remote: Yes
Date Published: Apr 28 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4617
Summary:

DNSTools is a web based managment tool for DNS information. It is
implemented in PHP, and available for Linux and Solaris.

A vulnerability has been reported in some versions of DNSTools which
allows any remote attacker to gain administrative access.

Access rights are controlled through the use of the variables
user_logged_in and user_dnstools_administrator. Reportedly, these
variables are not properly initialized, allowing an attacker to
artificially construct a URL setting them to arbitrary values. This allows
the attacker to bypass access control measures, gaining administrative
access to the system.

Administrative access will allow an attacker to freely modify host names,
DNS servers and domain data.

Earlier versions of DNSTools may share this vulnerability. This has not,
however, been confirmed.

7. Blahz-DNS Direct Script Call Authentication Bypass Vulnerability
BugTraq ID: 4618
Remote: Yes
Date Published: Apr 28 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4618
Summary:

Blahz-DNS is a web based management tool for DNS information. It is
implemented in PHP, and available for Linux systems.

A vulnerability has been reported in some versions of Blahz-DNS which
allows any remote attacker to gain administrative access. While
authentication is required to access the scripts through the login page,
no additional checks are performed. An attacker may directly call
additional scripts, bypassing the authentication check altogether.

This may allow an arbitrary attacker to gain full administrative access to
the Blahz-DNS system.

8. ATGuard Personal Firewall Outgoing Connection Restriction Bypass Vulnerability
BugTraq ID: 4620
Remote: No
Date Published: Apr 29 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4620
Summary:

An issue has been reported in ATGuard Personal Firewall. Reportedly, it is
possible for a user to bypass the security restrictions of ATGuard. A
feature exists in ATGuard, which can restrict outbound connections to
authorized applications only. A user can bypass this restriction setting,
and access the internet via arbitrary programs.

This is achieved by renaming the restricted web enabled program with an
authorized program name.

For example, if icq.exe is a restricted application and iexplore.exe is an
authorized application. ATGuard can be tricked to permit the use of
icq.exe, by renaming icq.exe to iexplore.exe.

This issue is the result of weak restricted application checks.

It should be noted that ATGuard Firewall was acquired by Symantec, support
for this product may no longer be available.

9. PhpWebGallery Cookie Manipulation Account Compromise Vulnerability
BugTraq ID: 4622
Remote: Yes
Date Published: Apr 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4622
Summary:

PhpWebGallery is a web application which enables users to create image
galleries, and is maintained by Pierrick Le Gall.

PhpWebGallery use cookies for authentication. When a user is issued a
cookie, the cookie is stored in a non-encrypted format. It is possible for
a malicious user to manipulate values in their cookie and authenticate as
an arbitrary user of the service, including the administrative account.

Successful hijacking of the administrative account will permit the
malicious user to access administrative facilities.

10. Livre Dor' Information Disclosure Vulnerability
BugTraq ID: 4629
Remote: Yes
Date Published: Apr 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4629
Summary:

Livre Dor is subject to an information disclosure issue, which could allow
remote users to obtain sensitive host information.

Reportedly, config.inc and connexion.inc are both world readable and both
contain highly sensitive data. It is possible to gain access to the
information contained in either file by submitting a request for the file.

config.inc contains the data base name, and the administrator
authentication credentials in plain text. The connexion.inc file contains
the data base name and user authentication information, also in plain
text.

Obtaining the information contained in either file will lead to an account
compromise, and assist an attacker in further attacks against the host.

11. 0wn f0rum Script Injection Vulnerability
BugTraq ID: 4626
Remote: Yes
Date Published: Apr 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4626
Summary:

0wn f0rum is a web message board application maintained by ServicesWeb.

A script injection issue has been reported in 0wn f0rum. 0wn f0rum builds
HTML content, including user supplied input, which is not properly
stripped of scripting commands. It has been reported possible to inject
script code into the title and body of a post.

The injected script code will execute within the context of the 0wn f0rum
site. It may be possible to take arbitrary actions as this user, including
posting or deleting content. Account compromise may result from
exploitation of this vulnerability, as it has been reported cookies are
used for authentication.

12. Solaris admintool Local Buffer Overflow Vulnerability
BugTraq ID: 4624
Remote: No
Date Published: Apr 29 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4624
Summary:

The Solaris admintool utility allows a user to perform a number of
administrative tasks through a graphical interface.

A buffer overflow vulnerability exists in the admintool binary which may
allow a local user to gain elevated privileges. admintool is world
executable and suid root in the default installation.

Reportedly, this condition may be exploited through either passing an
oversized command line parameter to the program, or by including an
extremely large value for the PRODVERS variable in the .cdtoc
configuration file used by admintool.

13. Solaris cachefsd Buffer Overrun Vulnerability
BugTraq ID: 4631
Remote: No
Date Published: Apr 29 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4631
Summary:

The Cache File System is a file system caching mechanism developed by Sun
that improves NFS performance and scalability.  It is shipped by default
with the Solaris operating environment.

A buffer overflow exists in cachefsd that may allow for local attackers to
obtain root privileges.  The overflow is due to insufficient bounds
checking on user-supplied mounts.

A successful attack will result in a compromise of the system.

Further technical details are forthcoming.

14. Solaris cachefsd Denial of Service Vulnerability
BugTraq ID: 4634
Remote: Yes
Date Published: Apr 29 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4634
Summary:

The Cache File System is a file system caching mechanism developed by Sun
that improves NFS performance and scalability. It is shipped by default
with the Solaris operating environment.

A vulnerability has been reported in the RPC server component of the Cache
File System.  If a RPC request for an invalid procedure is made, the
daemon will rerportedly crash.  This may result in a disruption of service
or possible loss of data.

Further technical details are forthcoming.

15. CIDER Shadow Analyzer Remote Command Execution Vulnerability
BugTraq ID: 4625
Remote: Yes
Date Published: Apr 29 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4625
Summary:

CIDER (Cooperative Intrusion Detection Evaluation and Response) Shadow
Analyzer is a component of the Shadow Intrusion Detection System.  It will
run on a number of Linux distributions.  The CIDER Shadow Analyzer
component is intended to be only accessible within the internal network.

The CIDER Shadow Analyzer component provides a web-based interface for the
CIDER Shadow Sensor.  It is possible for attackers within the internal
network to mount remote command executions via this web interface.

The CIDER Shadow Analyzer does not adequately filter shell metacharacters.
As a result, remote attackers may execute commands on the underlying host
with the privileges of the webserver process.

This may enable a remote attacker within the internal network to gain
local access to the host running the vulnerable software.

It is not known whether CIDER Shadow 1.7 is also affected by this issue.

16. Solaris AdminTool Media Installation Path Buffer Overflow Vulnerability
BugTraq ID: 4632
Remote: No
Date Published: Apr 29 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4632
Summary:

The Solaris admintool is a graphical user interface for performing
administrative tasks.

admintool is prone to a locally exploitable buffer overflow condition.
This is due to a lack of sufficient bounds checking of the media
installation path.  By supplying an overly long string as a path, it is
possible to overwrite stack variables such as the return address.  The
attacker may exploit this condition to cause attacker-supplied
instructions to be executed.

Since admintool is setuid root, an attacker who can successfully exploit
this vulnerability may gain root privileges.

17. Solaris LBXProxy Display Name Buffer Overflow Vulnerability
BugTraq ID: 4633
Remote: No
Date Published: Apr 29 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4633
Summary:

Low-Bandwidth X Proxy (lbxproxy) is a server that handles low-bandwidth
connections to X Windows.  It runs on Solaris as well as a number of Unix
and Linux variants.

lbxproxy is prone to a locally exploitable buffer overflow condition.
This is due to insufficient bounds checking of the display name.  Display
is used to specify the port of the X Server to connect to.

By supplying an overly long string as a display name, it is possible to
overwrite stack variables such as the return address.  The attacker may
exploit this condition to cause attacker-supplied instructions to be
executed.

Successful exploitation will enable an attacker to execute arbitrary
attacker-supplied instructions and as a consequence gain elevated
privileges.

lbxproxy on Solaris is installed setgid root, so successful exploitation
may enable the attacker to gain the privileges of the root group.

This issue was reported for lbxproxy on the Sun Solaris operating system.
It is not known whether this is an issue on other operating systems.

18. CDE DTPrintInfo Help Volume Search Buffer Overflow Vulnerability
BugTraq ID: 4630
Remote: No
Date Published: Apr 29 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4630
Summary:

CDE is the Common Desktop Environment.  Is it distributed with several
versions of the UNIX Operating System, and maintained by various vendors.

A problem with CDE could make it possible for a local user to gain
elevated privileges.  The problem is due to bounds checking in the
dtprintinfo program.

It is possible to execute arbitrary code through the dtprintinfo program.
When the dtprintinfo program is executed, a help menu is supplied via the
desktop.  By using this help menu, and performing a volume search with a
string of arbitrary length, it is possible to cause a buffer overflow that
could be used to overwrite stack variables, including the return address.

It should be noted that this vulnerability requires access to the desktop.
In order for a user to exploit this vulnerability, the use must either
have local access to the system and a regular user account, or the ability
to export a CDE session from the local desktop to a remote host, via a
mechanism such as CDE remote login.

19. AutoLog IP Spoofing Vulnerability
BugTraq ID: 4627
Remote: Yes
Date Published: Apr 29 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4627
Summary:

AutoLog is website usage tracking software.  It will run on most Unix and
Linux variants, as well as Microsoft Windows operating systems.

AutoLog uses cookies to track which users have visited the website it is
running on.

By sending a specially crafted cookie containing an arbitrary IP address,
a remote attacker may cause a false IP to be logged by the script.

An attacker may exploit this issue to conceal the source of malicious web
activity.

20. Messagerie Arbitrary User Removal DoS Vulnerability
BugTraq ID: 4635
Remote: Yes
Date Published: Apr 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4635
Summary:

Messagerie is a web message board application maintained by La Basse.

A problem with the software package could allow a remote unauthorized user
to delete arbitrary user accounts. The problem is in the permissions set
on the 'supp_membre.php' script.

Reportedly, submitting a specially crafted URL which inlcudes a known
username, by way of this script, could initiate the deletion of the known
user account.

This issue could lead to a denial of services for users of the service,
and potentially the administrator.

21. 3Com 3CDaemon Buffer Overflow Vulnerability
BugTraq ID: 4638
Remote: Yes
Date Published: Apr 30 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4638
Summary:

3CDaemon is an FTP server developed by Dan Gill of 3Com.

Reportedly, it is possible to initiate a buffer overflow on a host running
3CDaemon.

Submitting a large amount of data (at least 400 chars) at the login prompt
could trigger a stack-based overflow condition.

This overflow could overwrite stack variables, including the return
address, and be used to execute arbitrary code. However, sending random
data could cause the application to crash.

22. Mozilla / Netscape 6 XMLHttpRequest File Disclosure Vulnerability
BugTraq ID: 4628
Remote: Yes
Date Published: Apr 30 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4628
Summary:

An issue exists in handling of HTTP redirects in the XMLHttpRequest object
used by Mozilla and Netscape 6.

The XMLHttpRequest object allows a client machine to obtain an XML
document through a HTTP request. Normally, security checks prevent this
object from directly accessing local files when the script is obtained
from an untrusted source, such as a remote web site.

A vulnerability exists when a request is made to a server via the method
XMLHttpRequest.Open()', and the response is a redirect. XMLHttpRequest
will automatically follow the redirect, and read the contents of the file.
The file contents are then accessible by the rest of the script code as
the responseText property, and may be transmitted to another website.

It has been reported that this issue also exists with the load method
applied to XML documents created with the createDocument method of the
DOMImplementation interface. This attack vector is available in Mozilla
1.0RC1.

This could lead to a disclosure of sensitive information to remote
attackers.

23. Recherche Cross-Site Scripting Vulnerability
BugTraq ID: 4636
Remote: Yes
Date Published: Apr 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4636
Summary:

Recherche is a search application which is designed to be implemented in
web sites. Recherche is maintained by PHP Gratuit.

Recherche does not filter script code from URL parameters, making it prone
to cross-site scripting attacks. Attacker-supplied script code may be
included in a malicious link to the 'add.php3' script. The
attacker-supplied script code will be executed in the browser of a web
user who visits this malicious link, in the security context of the host
running Recherche. Such a malicious link might be included in a HTML
e-mail or on a malicious webpage.

This may enable a remote attacker to steal cookie-based authentication
credentials from legitimate users of a website running Recherche.

24. Messagerie Remote File Include Vulnerability
BugTraq ID: 4641
Remote: Yes
Date Published: Apr 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4641
Summary:

Messagerie is a web message board application maintained by La Basse.

A vulnerability has been discovered in Messagerie which may allow a
malicious user to execute arbitrary PHP code.

Messagerie permits remote file including. As a result, a remote attacker
may include an arbitrary file located on a remote host.

If this file is a PHP script, it will be executed on the host running the
vulnerable software.

The attacker may use this as an opportunity to gain local access on the
host running the vulnerable software.

25. Sun Solaris RWall Daemon Syslog Format String Vulnerability
BugTraq ID: 4639
Remote: Yes
Date Published: Apr 30 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4639
Summary:

Solaris is the freely available UNIX derivative operating system developed
and distributed by Sun Microsystems.

A problem with Solaris may allow a remote user to gain local access and
elevated privileges.  The problem is with the rwall daemon.

The rwall daemon is a remote "wall" facility, designed for sending system
broadcast messages.  It works by passing the requests from system to
system via RPC, and handling the starting of the rwall daemon with inetd.

It is possible to execute arbitrary code on vulnerable systems.  When
malicious format strings are sent from one system to another, an insecure
syslog call may make it possible for the remote attacker to exploit the
call to execute arbitrary code.

It should be noted that this vulnerability requires the functioning of
inetd, as well as that of rwalld.  Systems which have disabled rwalld from
the inetd configuration, or have disabled inetd altogether are not
vulnerable to this issue.  Additionally, this vulnerability, if exploited,
will result in the execution of code as root.

26. Kv Guestbook Cross-Site Scripting Vulnerability
BugTraq ID: 4647
Remote: Yes
Date Published: Apr 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4647
Summary:

Kv Guestbook is a web based guest book message board maintained by
KillerVault.

Kv Guestbook does not filter script code from URL parameters, making it
prone to cross-site scripting attacks. Attacker-supplied script code may
be included in a malicious link to the 'guestbook.php' script. The
attacker-supplied script code will be executed in the browser of a web
user who visits this malicious link, in the security context of the host
running Kv Guestbook. Such a malicious link might be included in a HTML
e-mail or on a malicious webpage.

This may enable a remote attacker to steal cookie-based authentication
credentials from legitimate users of Kv Guestbook.

27. Netscape/Mozilla IRC Buffer Overflow Vulnerability
BugTraq ID: 4637
Remote: Yes
Date Published: Apr 30 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4637
Summary:

Mozilla is a freely available, open-source web browser. It runs on most
Linux and Unix variants, as well as MacOS and Microsoft Windows
9x/ME/NT/2000/XP operating systems.  Netscape is another web-browser
product which runs on the same platforms as Mozilla.

Netscape and Mozilla crash when handling an exceptionally long request
(32KB+) for a channel using the IRC protocol.

An attacker may exploit this issue to crash a web user's browser.  This is
most likely to occur via a hyperlink in a malicious webpage, but may also
occur via HTML e-mail.

This issue is most likely due to a buffer overflow condition, but it is
not known whether this condition may be exploited to execute arbitrary
attacker-supplied instructions.

Other browsers based on the Mozilla codebase (such as Galeon) may also be
affected by this issue.

28. SGI IRIX CPR Buffer Overflow Vulnerability
BugTraq ID: 4644
Remote: No
Date Published: Apr 30 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4644
Summary:

IRIX is the UNIX-derived operating system distributed and maintained by
SGI.

A problem with IRIX could make it possible for a local user to gain
elevated privileges.  The problem is in the cpr program.

It has been discovered that the cpr program included with IRIX is
vulnerable to a buffer overflow.  This could allow local exploitation of
the overflow to overwrite stack variables, including the return address.
This could result in the execution of arbitrary code with elevated
privileges.

cpr is by default installed as a setuid root executable.  This problem
makes it possible for a local user exploiting this vulnerability to gain
administrative access to the vulnerable system.

29. Netscape/Mozilla/Galeon Local File Detection Vulnerability
BugTraq ID: 4640
Remote: Yes
Date Published: Apr 30 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4640
Summary:

Mozilla is a freely available, open-source web browser. It runs on most
Linux and Unix variants, as well as MacOS and Microsoft Windows
9x/ME/NT/2000/XP operating systems.  Netscape is another popular
web-browser product which runs on the same platforms as Mozilla.  The
Galeon browser is available for various Linux distributions.

External Cascading Style-Sheets (CSS) may be embedded inside of HTML
files.  This is accomplished using the <LINK> element.  The security model
of the web client is designed to prevent links to other file types and
links to local files on the client's system from remote pages.

It has been demonstrated that it is possible for a webpage to circumvent
this security model by linking to the external file and causing a HTTP
redirect to occur.  This could be exploited to detect the existence of a
file on the local system of the web client viewing the malicious page.

This could lead to a disclosure of sensitive information to remote
attackers.

30. BEA Systems WebLogic Server URL Parsing Path Disclosure Vulnerability
BugTraq ID: 4643
Remote: Yes
Date Published: Apr 30 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4643
Summary:

BEA Systems WebLogic Server is an enterprise level web and wireless
application server for Microsoft Windows and most Unix and Linux
distributions.

It is possible to cause the server to disclose sensitive path information.
This is due to difficulties parsing certain types of malformed requests,
such as those containing null characters (%00).

Various types of malformed web requests will cause the server to display
an error page containing the absolute path to the webroot directory.  For
example, this may be accomplished by appending a '%00.jsp' string to the
end of a request for a HTML file.  This condition may also occur if the
attacker prepends an encoded backslash (%5c) to the beginning of the
filename for a HTML file.  Other types of malformed web requests may also
cause this condition to occur.

Path information may aid the attacker in making further attacks against
the host.

31. BEA Systems WebLogic Server Null Character DOS Device Denial of Service Vulnerability
BugTraq ID: 4646
Remote: Yes
Date Published: Apr 30 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4646
Summary:

BEA Systems WebLogic Server is an enterprise level web and wireless
application server for Microsoft Windows and most Unix and Linux
distributions.

It is possible to create a denial of service condition by appending a null
character to a web request for MS-DOS device name (such as AUX).  Each
such malformed request will cause the connection to hang.  After a number
of these requests, the server will not be able to accept any more
connections, as only so many threads can be processed at once.

This condition is in part due to difficulties parsing requests that
contain NULL characters, but is also caused by poor handling of requests
for MS-DOS devices.  BugTraq ID 3816 "BEA Systems WebLogic Server DOS
Device Denial of Service Vulnerability" describes a similar condition,
which was fixed in WebLogic Server 6.1 SP2.  However, the null character
variation of this attack affects systems running WebLogic Server 6.1 SP2.
Other versions may also be affected.

The server must be restarted to regain normal functionality.

32. BEA Systems WebLogic Server URL Parsing Source Code Disclosure Vulnerability
BugTraq ID: 4645
Remote: Yes
Date Published: Apr 30 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4645
Summary:

BEA Systems WebLogic Server is an enterprise level web and wireless
application server for Microsoft Windows and most Unix and Linux
distributions.

It is possible to cause the server to disclose JSP script source code.
This is due to difficulties parsing certain types of malformed requests,
such as those containing null characters (%00).

Disclosure of script source code may aid allow the attacker to probe for
other vulnerabilities or may disclose sensitive information such as
database credentials.

Various types of malformed web requests will cause the server to disclose
JSP script source code.  For example, this may be accomplished by
appending a '%00x' to a request for an existing JSP script.  An attacker
could also append a '+.' string to the end of a request to disclose script
source code.  Other types of malformed web requests may also cause this
condition to occur.

33. ISS RealSecure DHCP Signature Remote Denial Of Service Vulnerability
BugTraq ID: 4649
Remote: Yes
Date Published: Apr 30 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4649
Summary:

RealSecure is the commercial Intrusion Detection System (IDS) distributed
and maintained by ISS.

A problem with the software could make it possible for a remote user to
crash the IDS.

RealSecure becomes unstable when processing some of the DHCP signatures
packaged with the system.  Due to the construction of the three DHCP
signatures (DHCP_ACK - 7131, DHCP_Discover - 7132, and DHCP_Request -
7133), the RealSecure software may become unstable and crash.  This is due
to the software attempting to dereference a null pointer.

This problem makes it possible for a remote attacker to crash a vulnerable
RealSecure sensor.  By sending malicious DHCP traffic to the server, it is
possible to force the sensor to load one of the malicious signatures,
resulting in this vulnerability.

This vulnerability affects versions 5.x XPU 3.4 and later, 6.0 XPU 3.4 and
later, and 6.5 of the software.

If the sensor is disabled, further attacks may go unnoticed.

34. SGI Irix Insecure IPFilter Device Permissions Vulnerability
BugTraq ID: 4648
Remote: No
Date Published: Apr 30 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4648
Summary:

IPFilter provides NAT (Network Address Translation) and packet filter
firewalling.

The SGI IRIX /dev/MAKEDEV script creates the ipfilter device with insecure
default permissions.  The ipfilter device is created with 644 permissions,
meaning that the device is world-readable, and therefore may allow local
users to gain unauthorized access to the device.

Unprivileged malicious local users may perform operations on the device
which may result in a denial of service.  It has been reported that this
may interfere with network traffic.

35. Paul L Daniels alterMIME Denial of Service Vulnerability
BugTraq ID: 4650
Remote: Yes
Date Published: Apr 26 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4650
Summary:

Paul L Daniels alterMIME is a program to help modify MIME encoded email
packages, including the ability to modify attachments and append text to
outgoing email.

A possible denial of service issue exists in some versions of alterMIME.
Under some circumstances, an unsafe call to snprintf() results in an out
by one error. This causes a null byte to overwrite adjacent stack data, in
this case a form of file structure. This could lead to the corruption of a
file pointer.

It has been reported that this condition can cause the program to crash
when exiting. It is possible that under some conditions, exploitation may
result in a denial of service condition. Additionally, as corruption of
memory is occuring, under some extreme conditions this may allow an
attacker to execute arbitrary code as the alterMIME process. This
possibility has not, however, been confirmed.

36. MyGuestbook Script Injection Vulnerability
BugTraq ID: 4651
Remote: Yes
Date Published: Apr 30 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4651
Summary:

MyGuestbook is freely available guestbook software.  It will run on most
Unix and Linux variants, as well as Microsoft Windows operating systems.

MyGuestbook does not adequately filter HTML tags from various fields.
This may enable an attacker to inject arbitrary script code into pages
that are generated by the guestbook.

The attacker's script code may be executed in the web client of arbitrary
users who view the pages generated by the guestbook, in the security
context of the website running the software.

Attackers may potentially exploit this issue to hijack web content or to
steal cookie-based authentication credentials.

37. HP MPE/iX FTPSRVR Arbitrary Shell Command Execution Vulnerability
BugTraq ID: 4652
Remote: Yes
Date Published: May 01 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4652
Summary:

MPE/iX is an Internet-ready operating system for the HP e3000 class
servers.

It is possible for a user with access to an FTP server to execute commands
on a MPE/iX server.  Due to insufficient checking on input supplied by FTP
users, it is possible to pass arbitrary commands embedded in the argument
to LIST.  This could allow a user without regular shell access to the host
to gain access.

This vulnerability may also allow clients using anonymous FTP access to
gain local access to the system.  It is not currently known if MPE/iX
supports anonymous FTP, and if it is enabled by default.


III. SECURITYFOCUS NEWS AND COMMENTARY
------------------------------------------
1. Melissa virus author jailed for 20 months
By John Leyden, The Register

The author of the infamous Melissa virus was sentenced today to 20 months
in Federal prison for causing millions of dollars of damage through its
release into the wild in March 1999.

http://online.securityfocus.com/news/385

2. Hackers Continue 'Early Warning' Attacks On U.S. Web Sites
By Steven Bonisteel, Newsbytes

A team of hackers, cutting a wide swath of Web-site defacements across the
country in what they say is the interests of national security, added
servers from Sandia National Laboratories, the U.S. Geological Survey and
the National Institute of Standards and Technology (NIST) to a list of
conquests today.

http://online.securityfocus.com/news/384

3. WinAmp's 'malicious MP3' vuln
By Thomas C. Greene, The Register

Users of NullSoft's popular WinAmp player should upgrade to version 2.80
to avoid a vulnerability reported on the Bugtraq mailing list by Swedish
security researcher Andreas Sandblad and confirmed by the company.

http://online.securityfocus.com/news/383

4. New Stealth Attack Found Against Personal Firewalls
By Brian McWilliams, Newsbytes

A new technique for defeating personal firewall software has been
discovered. But at least one firewall vendor said the trick poses little
risk to computer users.

Backstealth, a demonstration program that bypasses the outbound data
filters in firewalls from Symantec, McAfee, and other firms, was posted
last week to Packetstorm, a popular security tools site.

http://online.securityfocus.com/news/382


IV.SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Astaro Security Linux (ASL) v3.052(beta)
by Astaro AG, [email protected]
Relevant URL:
http://www.astaro.com/products/download.html
Platforms: Linux
Summary:

Astaro Security Linux is a new firewall solution. It does stateful
inspection, packet filtering, content filtering, virus scanning, VPN with
IPSec, and much more. With its Web-based management tool and the ability
to pull updates over the Internet, it it is pretty easy to manage. It is
based on a special hardened Linux 2.4 distribution where most daemons are
running in change-roots and are protected by capabilities.

2. pam_hbci v1.0a
by Stefan Palme
Relevant URL:
http://online.securityfocus.com/tools/2634
Platforms: Linux, POSIX
Summary:

pam_hbci is a PAM module for Linux that enables you to use your HBCI
chip-card to identify or authenticate you. HBCI is a German standard for
home banking over TCP/IP. The module contains many options and supports
all chip-card terminals with a working CTAPI interface.

3. Linux Security Auditing Tool v0.5.0
by Triode
Relevant URL:
http://www.dimlight.org/~number9/lsat/
Platforms: Linux, POSIX
Summary:

Linux Security Auditing Tool (LSAT) is a post install security auditing
tool. It is modular in design, so new features can be added quickly. It
checks inetd entries and scans for unneeded RPM packages. It is being
expanded to work with Linux distributions other than Red Hat, and checks
for kernel versions.

4. Secure FTP Wrapper v2.1.1
by Glub Tech, Inc.
Relevant URL:
https://www.glub.com/store/export.jsp?product_id=ftpswrap_2_0
Platforms: Java
Summary:

Secure FTP Wrapper is a server-based package that enables an existing FTP
server to become a Secure FTP server. In this release the wrapper allows
for a Secure Sockets Layer, or SSL, connection to be made to your FTP
server.

5. Gringotts v0.4.4
by Germano Rizzo
Relevant URL:
http://devel.pluto.linux.it/projects/Gringotts/
Platforms: Linux, POSIX
Summary:

Gringotts is a small utility that allows you to jot down sensitive data
(passwords, credit card numbers, PINs, etc.) in an easy-to-read,
easy-to-access, and most of all very secure form. Gringotts makes use of
the MCrypt and MHash libraries for encryption, and uses GTK+ 2 for the
user interface.

6. Port Scan Attack Detector (psad) v0.9.8
by Michael Rash [email protected]
Relevant URL:
http://www.cipherdyne.com/psad/
Platforms: Linux
Summary:

Port Scan Attack Detector (psad) is a program written in Perl that is
designed to work with Linux firewalling code (iptables in the 2.4.x
kernels, and ipchains in the 2.2.x kernels) to detect port scans. It
features a set of highly configurable danger thresholds (with sensible
defaults provided), verbose alert messages that include the source,
destination, scanned port range, begin and end times, TCP flags and
corresponding nmap options (Linux 2.4.x kernels only), email alerting, and
automatic blocking of offending IP addresses via dynamic configuration of
ipchains/iptables firewall rulesets. In addition, for the 2.4.x kernels
psad incorporates many of the TCP signatures included in Snort to detect
highly suspect scans for various backdoor programs (e.g. EvilFTP,
GirlFriend, SubSeven), DDoS tools (mstream, shaft), and advanced port
scans (syn, fin, Xmas) which are easily leveraged against a machine via
nmap.


V. SECURITY JOBS SUMMARY
------------------------
1. New York city based security professional looking for HIPAA work (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

2. FW: failure notice (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

3. (job offered) Forensic Security Consultant, Seattle, Washington (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/MGENLCPOCDFIHEFHOLGOEEFNCLAA.colleen.nelson@certifiedsecuritysolutions.com

4. List slow down (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

5. Junior Level position (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

6. lots of experience, available immediately (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

7. Security Consultant position in No. VA (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

8. Entry Level Position (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/002f01c1ed69$740f6700$9fd9fea9@socrates

9. URGENT JOB REQUIREMENT (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

10. TX Jobs-Sr embedded engineer & Security Test Engineer (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]

11. Sales Engineer-Security SW firm in NYC/NJ area-immediate (Thread)
Relevant URL:

http://online.securityfocus.com/archive/77/[email protected]


VI. INCIDENTS LIST SUMMARY
-------------------------
1. 'rooted' NT/2K boxen? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

2. ssh scans using username 'test' or 'oracle'? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

3. Windows Systems Defaced (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

4. A friend's cable modem Linux machine just got compromised (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

5. Tuxkit (Optic Kit?) -cracked (/dev/tux) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

6. Honeynet Project -> The Reverse Challenge (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

7. New nimda variant? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

8. Strange hidden messages in email (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

9. Strange hidden messages in email (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]

10. FTP Followup (Thread)
Relevant URL:

http://online.securityfocus.com/archive/75/[email protected]


VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. Preventing XSS in PHP... (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

2. Wlan @ bestbuy is cleartext? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

3. static char overflow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

4. more best buy media coverage (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

5. Preventing CSS in PHP... (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

6. Macromedia Flash Activex Buffer overflow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/000901c1f20b$938b5a70$e303120a@none

7. Classic Cross Site Scripting: Gibson Research Corporation (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

8. Best Buy / 802.11 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

9. Buffer overflow or overrun? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

10. ADT enterNET and Symantec Ghost (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

11. Wlan @ bestbuy is cleartext? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

12. Fwd: Re: Wlan @ bestbuy is cleartext? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

13. Fwd:  Wlan @ bestbuy is cleartext? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/7FA8FEA22737D41192590002A537E720025BC46D@SSLMEXCH1

14. Wireless Point of Sale Solutions (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/CZTAMJGDQMVA0NLVTUQJD1YTNOL5Z.3cd0da46@ray

15. latest Progress patch has suid issues AGAIN. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

16. AOL passwords (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/005301c1f17d$90c17c90$1e01320a@drizzt

17. AOL passwords / crypt() and online brute forcing (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

18. SECURITY CAMERA WAR DRIVING (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

19. AOL passwords / crypt() and online brute forcing (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

20. SECURITY CAMERA WAR DRIVING (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/1C1E25D810B404489BFE32088773C18822399B@CHSVRNT1

21. FW: Wlan @ bestbuy is cleartext? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/DF8DAD6ABA96D311B6750050040FBFEC0190AE20@CORPMAIL

22. AOL passwords (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

23. [Fwd: FW: XP Screen Saver password uses Old password until logout  or New one is used.] (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

24. Spanning Tree Switch Exploits? Fact or Fiction? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

25. XP Screen Saver password uses Old password until logout or New one is used. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

26. [Fwd: FW: XP Screen Saver password uses Old password until logoutor    New one is used.] (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

27. XP Screen Saver password uses Old password until logout or Newone   is used. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

28. XP Screen Saver password uses Old password until logout or New one  is used. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

29. XP Screen Saver password uses Old password until logout or    New one is used. (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

30. Cross Site Scripting? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

31. Call For Papers - Canadian Security & Intelligence Conference (CSIC) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

32. Hacker's Digest Issue Four Spring 2002 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/000a01c1f069$9f8af180$2bc1edd1@peach

33. AW: Buffer overflow or overrun? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/000c01c1f063$1d2dbd90$0f08a8c0@hephaistos

34. cross site scripting ? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

35. Security Research Group (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

36. The Hazard of using 'printer friendly' functions on commercial sites (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

37. The Hazard of using 'printer friendly' functions on commercial sites (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

38. Security Research Group (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/DF8DAD6ABA96D311B6750050040FBFEC0190ADEE@CORPMAIL

39. Fw: Security Research Group (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

40. QPopper 4.0.4 buffer overflow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

41. Multiple CSS/XSS vulnerabilities on directNIC.com (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

42. apache + .htpasswd - bypass pwd check (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/Pine.BSF.4.44-Blink.0204271916200.257-100000@deepthought.blinkenlights.nl

43. Security holes in 11 products... (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

44. apache + .htpasswd - bypass pwd chec (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

45. /lib/ld-2.2.4.so (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

46. nobody suid shell (kind of relationship with the ld-2.2.4 thread...) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

47. apache + .htpasswd - bypass pwd check (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

48. TTP/1.0 Remote BufferOverflow? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/B1F2937B437BD3119603000094A18677408AFD@PDC1

49. I'm back (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

50. Microsoft Baseline Security Analyzer exploit (Exposed  vulnerabilities' list) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]

51. ecartis / listar PoC (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/0204260814384G.28233@weez

52. Microsoft Baseline Security Analyzer exploit (Exposed vulnerabilities' list) (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/718D38CAB6E0D011B2C90060970C28A59F9715@exchangeserver.pixelpower.com

53. TTP/1.0 Remote BufferOverflow? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/82/[email protected]


VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. 'rooted' NT/2K boxen? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

2. Rolling out patches (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

3. Strange behavior after removing Klez on Win2000 server (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/002601c1f21a$5c81da90$fe00140a@demodes

4. Windows Systems Defaced (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

5. Access is denied: driver signing responsible (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

6. Access is denied (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

7. Rolling out patches (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

8. Microsoft Win2k VPN server placement (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

9. Microsoft Win2k VPN server placement (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

10. Windows XP Professional Account Lockouts (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

11. Remote perf counter access (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/001001c1f099$eb6e4720$0a0010ac@Casa

12. Bypassing Windows 2000 Domain Password settings (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

13. Admin Preparation for .NET (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

14. PDC -> Workstation Registry Connect (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/88AB06281E1D0F4E86DEF6C486C58C7504CCFA@ip15293.peostamis.belvoir.army.mil

15. PDC -> Workstation Registry Connect (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

16. Windows XP Professional Account Lockouts (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

17. SecurityFocus Microsoft Newsletter #84 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

18. Account Permissions (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

19. Account Permissions (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

20. Remote perf counter access (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

21. NTFS Alternate Data Streams (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/00a101c1ef39$35d26600$1400020a@chaser


IX. SUN FOCUS LIST SUMMARY
----------------------------
1. Switching audit files under Solaris 8 via cron (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]

2. User Time Restrictions on Solaris 8 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]

3. How do I set-up secure automated file push and pull? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/92/[email protected]


X. LINUX FOCUS LIST SUMMARY
---------------------------
1. AW: entry in /etc/passwd (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

2. Trimming replies (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

3. entry in /etc/passwd (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/Pine.GSO.4.44.0205011631280.9349-100000@ismene


XI. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored by: Tumbleweed Communications

FREE ENTERPRISE SECURITY BREAKFAST SEMINARS

How do you make your email more secure?  How do you extend your network,
while still protecting against viruses, spam, and breaches of
confidentiality?

Find out by attending "Securing The Extended Enterprise", a FREE breakfast
seminar sponsored by Tumbleweed Communications and METAGroup.  Coming to
10 North American cities in May and June. Sign up now!
https://www.tumbleweed.com/dy/security

------------------------------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.