SecurityFocus Newsletter #144
John Boletta <[email protected]>
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #144
-----------------------------
This Issue is Sponsored By: Recourse Technologies, Inc.
FREE white paper, "The Evolution of Honeypots" sheds new light on the
latest innovations in deception technologies, including Recourse ManTrap®
3.0 - the latest advance in the industry's leading deception-based
intrusion detection solution.
Visit us at: http://www.recourse.com/sf
-------------------------------------------------------------------------------
I. FRONT AND CENTER
1. Securing Exchange 2000, Part Two
2. Information Resilience and Homeland Security
3. Patch Management Done Right
II. BUGTRAQ SUMMARY
1. HP-UX ndd Denial of Service Vulnerability
2. Pointsec for PalmOS PIN Disclosure Vulnerability
3. IRIX netstat File Existence Disclosure Vulnerability
4. AstroCam Buffer Overflow Vulnerability
5. WorldClient Arbitrary File Deletion Vulnerability
6. MDaemon Weak Password Encoding Vulnerability
7. MDaemon WorldClient Folder Creation Buffer Overflow Vulnerability
8. MDaemon Default Mail System Account Vulnerability
9. HP Virtualvault Unauthorized Administrative Access Vulnerability
10. Webmin / Usermin Login Cross Site Scripting Vulnerability
12. SquirrelMail Message Header Field Script Injection Vulnerability
13. PHPImageView Cross Site Scripting Vulnerability
14. PhotoDB 1.4 Administrator Access Vulnerability
15. askSam Web Publisher Cross Site Scripting Vulnerability
16. ASPJar Guestbook Cross Site Scripting Vulnerability
17. NewsPro 1.01 Unauthenticated Administrator Vulnerability
18. Solaris cachefsd Heap Overflow Vulnerability
19. B2 B2Config.PHP Remote Command Execution Vulnerability
20. Pascal Michaud ASP Client Check SQL Injection Vulnerability
21. C-Note Squid_Auth_LDAP Pam Logging Format String Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
1. Cable Modem Hacking Goes Mainstream
2. Net Threats Monitored In Malaysia
3. NeuLevel Says Site's Strange Message Not From Attackers
4. Xbox 'Emulator' Front For Online Money-Making Scam
IV.SECURITYFOCUS TOP 6 TOOLS
1. Clam Antivirus v0.11
2. NetUP UTM billing system v3.0
3. fireflier v0.8
4. OpenAI v0.2
5. phpSecurityAdmin v2.1
6. Python milter v0.4.4
V. SECURITYJOBS LIST SUMMARY
1. VP, Information Security, CNET Networks (San Francisco) (Thread)
2. Information Security Instructor Needed - Seattle, WA...
3. SMTP Architect contract position in NJ (Thread)
4. Seeking a Network Security Professional Position (Thread)
5. CISSP and J2EE Analyst wanted for Dallas, Texas (Thread)
6. Seeking Network Security Engineer (Thread)
7. Penetration Tester / Security Analyst seeks job (Thread)
8. Resume for (Systems|Network|Security) (Administrator|Engineer...
9. Seeking Entrepreneurial Security Engineer (Thread)
10. Principal/s wanted: co-launch Security Consultancy (Los...
11. Looking for Pentest professional in Unix/Windows (Thread)
12. Seeking infosec position in NY/NJ (Thread)
13. Seeking an Information Security Position (Thread)
14. Senior security systems Engineer job-Hartford,CT area (Thread)
15. Montreal - Penentration testing position open (Thread)
16. Resume - Information Systems Security Professional (Thread)
17. Information Security Administrator - #709 - Denver, CO (Thread)
19. Request for Referral: NetSec Services Co in DC area seeks...
20. Network Security Intrusion Software Developer, Austin TX...
21. Application Security Analyst - #711 - Chicago, IL (Thread)
VI. INCIDENTS LIST SUMMARY
1. Strange "shotgun" scan (Thread)
2. Strange "shotgun" scan (Thread)
3. Dead Thread - Publishing Nimda Logs (Thread)
4. Publishing Nimda Logs (Thread)
5. netbuie.exe, scorpionsearch.com and fastcounter.bcentral.com...
6. netbuie.exe, scorpionsearch.com and fastcounter.bcentral.com...
7. Publishing Nimda Logs == BAD IDEA (Thread)
8. Nimda Infections and code red resurgence (Thread)
9. Publishing Nimda Logs (Thread)
10. Publishing Nimda Logs - Summary (Thread)
11. Publishing Nimda Logs - Summary (Thread)
12. Unusual Message log contents (Thread)
13. netbuie.exe, scorpionsearch.com and fastcounter.bcentra...
14. AW: Publishing Nimda Logs (Thread)
15. netbuie.exe, scorpionsearch.com and fastcounter.bcentra...
16. info (Thread)
17. info (Thread)
18. Reverse Challenge - Binary released (Thread)
19. 'rooted' NT/2K boxen? (Thread)
20. Windows Systems Defaced (Thread)
21. World-wide distributed DoS and "warez" bot networks (fwd)...
22. Windows Systems Defaced (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
1. Thinking about Security rules... (Thread)
2. whois tricks was : whois is what? (Thread)
3. Publishing Nimda Logs (Thread)
4. Publishing Nimda Logs == BAD IDEA (Thread)
5. Possible ZoneAlarm 3 Problem??? (Thread)
6. Lessons learned writing exploits (Thread)
7. CRLF Injection (Thread)
8. Possible ZoneAlarm 3 Problem??? (Thread)
9. SST (Thread)
10. Thinking about Security rules... (Thread)
11. Sar -o exploitation process info. (Thread)
12. Publishing Nimda Logs (Thread)
13. Publishing Nimda Logs - Summary (Thread)
14. XiRCON && Internet Explorer exposing Cookies (Thread)
15. whois tricks was : whois is what? (Thread)
16. about disclosure of nimda logs (Thread)
17. Buffer Overflow Discovery (Thread)
18. Publishing Nimda Logs == BAD IDEA (Thread)
19. Lessons learned writing exploits (Thread)
20. is: greyhat virus was Publishing Nimda Logs (Thread)
21. OT: Stop Auto Mail Backs (Thread)
22. whois tricks was : Publishing Nimda Logs (Thread)
23. about disclosure of nimda logs (Thread)
24. Fw: Publishing Nimda Logs (Thread)
25. is: whois tricks was : Publishing Nimda Logs (Thread)
26. Multiple Local Vulnerabilities in some FTP Client.Who...
27. Actuate e.Reporting possible vulnerabilities (Thread)
28. Windows XP Raw Sockets tool? (Thread)
29. vxWorks WND checker? (Thread)
30. Windows XP Raw Sockets tool? (Thread)
31. Wlan @ bestbuy is cleartext? (Thread)
32. ADT enterNET and Symantec Ghost (Thread)
33. cURL remote PoC for FBSD (Thread)
34. FrontPage Server Extension : fp30reg.dll Cross Site...
35. [Fwd: FW: XP Screen Saver password uses Old password...
36. LEA Conference Call for Papers (Thread)
37. Multiple Local Vulnerabilities in some FTP Client.Who can...
38. Possible privary leak converting to website stealing (Thread)
39. Slackware 8.0 / ucd-snmpd 4.2.1 exploit works? (Thread)
40. cURL remote PoC for Linux (Thread)
41. [LSD] Solaris cachefsd remote buffer overflow vulnerability...
42. Multiple Local Vulnerabilities in some FTP Client.Who can...
43. Packetstorm archive warning: 73501867, PHP exploit binary...
44. Finding and exploiting buffer overflows in Windows. (Thread)
45. Multiple Local Vulnerabilities in some FTP Client.Who can...
46. Finding and exploiting buffer overflows in Windows. (Thread)
47. trusting user-supplied data (was Re: FreeBSD Security...
48. Security holes : PHP Image View, NewsPro, Photo DB, As_web,...
49. static char overflow (Thread)
50. BACKSTEALTH reverse engineered (Thread)
51. Preventing XSS in PHP... (Thread)
52. Fw: Security Research Group (Thread)
53. backstealth reverse-engineered (Thread)
54. Wlan @ bestbuy is cleartext? (Thread)
55. Macromedia Flash Activex Buffer overflow (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
1. 2K Server locking 98 users out (Thread)
2. FTP tagging (Thread)
3. 2K Server locking 98 users out (Thread)
4. FTP tagging (Thread)
5. Publishing Nimda Logs - Summary (Thread)
6. Publishing Nimda Logs (Thread)
7. SecurityFocus Microsoft Newsletter #85 (Thread)
8. Publishing Nimda Logs (Thread)
9. Macromedia Flash Activex Buffer overflow (Thread)
10. HfNetChk Message: File versions greater than expected: (Thread)
11. 'rooted' NT/2K boxen? (Thread)
12. 'rooted' NT/2K boxen? (Thread)
13. Rolling out patches (Thread)
14. Strange behavior after removing Klez on Win2000 server (Thread)
15. Access is denied (Thread)
16. Windows Systems Defaced (Thread)
IX. SUN FOCUS LIST SUMMARY
1. gpg /netstat problems (Thread)
X. LINUX FOCUS LIST SUMMARY
1. plain text vs. html (Thread)
2. AW: AW: entry in /etc/passwd (Thread)
3. AW: plain text vs. html (Thread)
4. AW: entry in /etc/passwd (Thread)
5. entry in /etc/passwd (Thread)
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. Securing Exchange 2000, Part Two
By Chris Weber
This is the second installment in the two-part series on securing Exchange
2000. This article will focus on secure configuration and administration
of Exchange 2000, including locking down Exchange, and an analysis of some
publicized vulnerabilities.
http://online.securityfocus.com/infocus/1578
2. Information Resilience and Homeland Security
By Richard Forno
Like the full disclosure debate in information security, the debate over
freedom of information is really about who is hindered by restricting
information - criminals and terrorists, or law abiding citizens.
http://online.securityfocus.com/columnists/80
3. Patch Management Done Right
By Tim Mullen
There is no getting around the fact that the even the nominal use of
Microsoft products requires regular component upgrades and patches. When
you are a card-carrying Microsoft supporter like I am, and your
infrastructure runs the gamut of their product offerings, updating servers
and workstations can get downright ugly. Just maintaining the critical
updates containing security rollups and patches can be taxing.
http://online.securityfocus.com/columnists/79
II. BUGTRAQ SUMMARY
-------------------
1. HP-UX ndd Denial of Service Vulnerability
BugTraq ID: 4680
Remote: No
Date Published: May 06 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4680
Summary:
HP-UX 11 includes the ndd command, which may be used to control a number
of network parameters. A vulnerability has been reported in the ndd
binary included with some versions of HP-UX.
It may be possible for a local attacker to exploit this vulnerability to
cause a denial of service condition. While full details are not
available, it is possible that network devices may be impacted.
Reportedly, HP-UX 11.11 is vulnerable only when TRANSPORT patches
PHNE_24211, PHNE_24506, PHNE_25134, or PHNE_25642 have been installed.
2. Pointsec for PalmOS PIN Disclosure Vulnerability
BugTraq ID: 4681
Remote: No
Date Published: May 07 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4681
Summary:
Pointsec Mobile Technologies develops security software for protecting
the privacy of data and credentials on desktops and mobile computing
devices.
A weakness exists in versions of Pointsec developed for PalmOS that may
result in disclosure of authentication credentials to attackers with
physical access. Pointsec uses a PIN (personal identification number) to
unlock a mobile device. Pointsec versions 1.0 and 1.1 do not clear the
authentication code from memory after a successful authentication.
If an attacker obtains physical access to the device after the owner has
authenticated, they may be able to retrieve the PIN by dumping the memory
of the mobile device. It is considered good practice to clear credentials
from memory after the authentication process has completed. As the
software does not do this, the security of the system is weakened.
3. IRIX netstat File Existence Disclosure Vulnerability
BugTraq ID: 4682
Remote: No
Date Published: May 07 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4682
Summary:
The netstat utility is used to display network status of a system. This
utility is part of the default IRIX installation and is found in
/usr/etc/netstat.
A vulnerability exists in the netstat utility to allow non-privileged
users to detect whether a file exists. File information will be disclosed
regardless of whether file permissions or ownership allow it. Versions
prior to 6.5.12 are suceptible to this vulnerability.
Precise technical details are not currently available.
4. AstroCam Buffer Overflow Vulnerability
BugTraq ID: 4684
Remote: Yes
Date Published: May 07 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4684
Summary:
AstroCam is used to control web cams on BSD and Linux systems. AstroCam
has a web interface/server for remote administration and is maintained by
Steffen Wendzel.
Versions of AstroCam prior to 1.4.1 Gtk Beta are susceptible to an
exploitable buffer overflow. A remote attacker able to exploit this
condition may be able to crash the server and create a denial of service
condition. Additionally, due to the nature of this vulnerability it is
likely that it is possible to execute arbitrary code as the server. This
possibility has not, however, been confirmed.
No additional technical details are currently available.
5. WorldClient Arbitrary File Deletion Vulnerability
BugTraq ID: 4687
Remote: Yes
Date Published: May 07 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4687
Summary:
WorldClient is a web interface packaged with MDaemon, an email server for
Microsoft Windows.
A vulnerability exists in WorldClient (version 5.0.5 and older) that
allows for an attacker to delete an arbitrary file on the webserver it
resides on.
The vulnerability occurs when a user chooses to delete an attachment from
their folder. Checks aren't made on the filename to prevent directory
traversal. Thus a user is able to carefully craft a request that will
cause any file writeable by the webserver process to be deleted.
If critical files are deleted, a denial of service may occur.
6. MDaemon Weak Password Encoding Vulnerability
BugTraq ID: 4686
Remote: No
Date Published: May 07 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4686
Summary:
MDaemon is a Microsoft Windows based mail server product.
Encoding for the MDaemon password file (userlist.dat) may be easily
broken. Each character in the password file is shifted using a static
offset and then base64 encoded.
Local attackers with read access to the password file may trivially
decode the passwords for MDaemon mail users.
7. MDaemon WorldClient Folder Creation Buffer Overflow Vulnerability
BugTraq ID: 4689
Remote: Yes
Date Published: May 07 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4689
Summary:
MDaemon is an integrated mail transport agent, webmail, and mail
anti-virus package. It is available for Microsoft Windows operating
systems.
A problem with the package could make it possible for a remote user to
execute arbitrary code. The problem is in the handling of long data
strings.
It may be possible for a remote user to take advantage of a buffer
overflow in the MDaemon software package. The WorldClient.cgi program
packaged with MDaemon does not properly check bounds on user-supplied
data. During the process of creating a folder with a long name, it is
possible to exploit a buffer overflow in the CGI that could result in the
overwriting of process memory, and execution of attacker-supplied
instructions.
It should be noted that exploitation of this vulnerability will result in
the execution of code with SYSTEM privileges on a Windows system.
Additionally, an attacker exploiting this vulnerability must be
authenticated through a regular account on MDaemon system. Exploitation
of this vulnerability will result in a remote attacker gaining local
administrative privileges on a vulnerable system.
It has been confirmed by SecurityFocus staff that this vulnerability may
be exploited both via a web browser, or a connection through a client
program such as netcat or telnet.
8. MDaemon Default Mail System Account Vulnerability
BugTraq ID: 4685
Remote: Yes
Date Published: May 07 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4685
Summary:
MDaemon is a Microsoft Windows based mail server product.
MDaemon ships with a default mail system account. The username and
password of this account are hard-coded into the program, and set by the
system during installation. The username is 'MDaemon' and the password
is 'MServer'. This default account is used internally by the software
and is not intended to be used as a normal mail user.
The system does not prompt administrators to change the default MDaemon
password after installation. Therefore, this account may be abused by
remote attackers.
9. HP Virtualvault Unauthorized Administrative Access Vulnerability
BugTraq ID: 4690
Remote: Yes
Date Published: May 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4690
Summary:
HP Virtualvault is a secure implementation package distributed by
Hewlett-Packard for use as a web and e-commerece platform.
Virtualvault provides administrative access through a web interface. A
vulnerability has been reported in the administration server under some
versions of Virtualvault.
A remote system executing a web server or other privileged process may be
able to access this administion server. Access to this functionality may
allow a malicious party to cause a denial of service condition. It is
possible that sensitive transaction information may be compromised.
It has been reported that only HP9000 series 700/800 machines running
HP-UX 11.04 suffer from this vulnerability.
10. Webmin / Usermin Login Cross Site Scripting Vulnerability
BugTraq ID: 4694
Remote: Yes
Date Published: May 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4694
Summary:
Webmin is a web-based interface for system administration of Unix and
Linux operating systems. Usermin is a related product designed for user
level tasks.
A cross site scripting issue has been reported with the login process for
both systems. User supplied input, under some circumstances, is included
in HTML content used to display an error message.
If a malicious link to this page is constructed, JavaScript code may be
injected into the page. The script will then execute within the context
of the Webmin domain.
Reportedly, this vulnerability can only be exploited if a user has not
authenticated to the system. As a result, authentication data can not
easily be acquired. However, information associated with other pages on
the same domain may be freely accessed.
11. 4D WebServer Authentication Buffer Overflow
BugTraq ID: 4665
Remote: Yes
Date Published: May 03 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4665
Summary:
4D WebServer is a client/server database management system with integrated
web development and serving. It runs on Microsoft Windows and MacOS
operating systems.
Due to insufficient bounds checking of the username/password fields, 4D
WebServer is prone to a buffer overflow condition. It is possible to
overwrite stack variables such as the return address by overflowing either
of these fields. This may enable a remote attacker to cause a denial of
service or execute attacker-supplied instructions.
There is some amount of input validation performed on the authentication
fields, which causes requests to be terminated if invalid characters are
found. As a result, this may restrict exploitability of this issue for
the purpose of executing arbitrary code.
It should be noted that the software will run in the SYSTEM context on
multi-user Windows operating systems, so successful exploitation may
result in a full compromise of the host.
This issue was reported for 4D WebServer version 6.7.3, earlier versions
may also be affected.
12. SquirrelMail Message Header Field Script Injection Vulnerability
BugTraq ID: 4667
Remote: Yes
Date Published: May 03 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4667
Summary:
SquirrelMail is a webmail program implemented in PHP. It is available for
Linux and Unix based operating systems.
SquirrelMail does not adequately filter HTML tags from the message header
fields. An attacker may be able to inject script code into the 'to',
'cc', or 'bcc' fields. This may enable a remote attacker to cause script
code to be executed in the browser of a webmail user.
This issue may be exploited to steal cookie-based authentication
credentials from legitimate users of the webmail system.
13. PHPImageView Cross Site Scripting Vulnerability
BugTraq ID: 4668
Remote: Yes
Date Published: May 04 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4668
Summary:
PHPImageView 1.0 is a simple image display system. It is vulnerable to
cross site scripting whereby a user supplied variable is returned as the
content of an error message, allowing script submitted as a URL to be
interpreted by the browser. This is done by submitting the script
(properly encoded) to the parameter "pic", ie:
/phpimageview.php?pic=javascript:alert(something).
In addition to this, phpinfo() can be invoked - revealing a detailed
summary of operating system setup including file system structure and
version information. This is done by submitting "pw=show" to the script,
ie: /phpimageview.php?pw=show
14. PhotoDB 1.4 Administrator Access Vulnerability
BugTraq ID: 4669
Remote: Yes
Date Published: May 04 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4669
Summary:
PhotoDB 1.4 is a PHP based photo management and display system. It makes
use of a simple authentication script that can easily be bypassed to gain
administrator access. This is done by submitting a request with the
following parameters to the administrator's page:
/[THEADMINSPAGE]?PHPSESSID=abc123&Time=9999999999999&rmtusername=hop&rmtpassword=hop&accessevel=-5
The values for the parameters given above circumvent the simple checks the
script employs, as described in the analysis by "frog frog". The
authentication mechanism ensures the variable "PHPSESSID" is not blank,
the varaible "time" is not stale (bypassed by setting time to an arbitrary
huge value), the two "rmtusername" and "rmtpassword" variables are not
blank, and the "accesslevel" is high enough (circumvented with a negative
number).
15. askSam Web Publisher Cross Site Scripting Vulnerability
BugTraq ID: 4670
Remote: Yes
Date Published: May 05 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4670
Summary:
askSam is a database system. An optional component, askSam Web Publisher
(versions 1 and 4), is reportedly vulnerable to cross site scripting
vulnerability in the as_web.exe (or as_web4.exe) component. This is due
to a failure to strip script and HTML when returning error messages that
include user input.
The same component can also disclose paths on the server when non-existant
files are requested.
16. ASPJar Guestbook Cross Site Scripting Vulnerability
BugTraq ID: 4671
Remote: Yes
Date Published: May 04 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4671
Summary:
ASPJar Guestbook 1.00 allows simple message writing capabilites for web
sites. Script code is not filtered, thus entries can contain HTML and/or
script that executes in the context of the guestbook.
In addition to this, an unauthenticated "delete" script allows removal of
other guestbook entries.
17. NewsPro 1.01 Unauthenticated Administrator Vulnerability
BugTraq ID: 4672
Remote: Yes
Date Published: May 05 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4672
Summary:
NewsPro 1.01 contains a weak authentication mechanism that allows
administrative access to be gained. This is done by constructing a cookie
containing "logged,true". When this cookie information is retrieved by
the authentication mechanism, checks determine that the user is already
logged in as administrator and can behave as an authenticated
administrator.
18. Solaris cachefsd Heap Overflow Vulnerability
BugTraq ID: 4674
Remote: Yes
Date Published: May 06 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4674
Summary:
The Cache File System is a file system caching mechanism developed by Sun
that improves NFS performance and scalability. It is shipped by default
with the Solaris operating environment.
A remotely exploitable heap overflow condition has been reported in
cachefsd. It is possible to cause the condition if the RPC procedure
'cachefsd_fs_mounted_1_svc()' is invoked with a cache name argument that
is excessive in length.
When the cache name argument is processed, it is copied into another
buffer using strcpy(). As strcpy() does not implement any bounds
checking, a potential overrun condition exists. The overflow occurs in
the heap and is reportedly exploitable as valid malloc() chunk structures
are overwritten.
Successful attacks may result in remote attackers gaining root access on
the affected system.
It has been reported that this vulnerability is being actively scanned for
and exploited in the wild.
19. B2 B2Config.PHP Remote Command Execution Vulnerability
BugTraq ID: 4673
Remote: Yes
Date Published: May 06 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4673
Summary:
B2 is a news/weblog tool written in php. b2 allows webmasters to quickly
post news on the frontpage, and let viewers interact with each other. It
is available primarily for Unix and Linux.
A problem in the program may allow an attacker to remotely execute
commands.
A variable that is referenced in the PHP scripts does not actually exist.
Thus, an attacker may be able to define the value of the variable. By
creating a PHP script on the remote side and embedding commands in it, the
attacker is able to reference the remote file. This could potentially
allow the attacker to execute commands on the vulnerable system.
This may lead to the execution of arbitrary commands on the vulnerable
system, with the privileges of the web server process. This may also
potentially result in the disclosure of sensitive information.
20. Pascal Michaud ASP Client Check SQL Injection Vulnerability
BugTraq ID: 4676
Remote: Yes
Date Published: May 06 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4676
Summary:
Pascal Michaud's ASP Client Check is a ASP script designed to provide user
authentication for arbitrary web services. A SQL injection vulnerability
has been reported in some versions of ASP Client Check.
The username supplied by the remote user is used directly to construct SQL
statements. As input sanitization is not properly performed, an attacker
may include special characters such as "'" and additional SQL statements
in the provided username. When the database is queried as part of the
authentication process, the query is subverted.
It has been reported that this may be used to bypass the authentication
process for any known username. However, due to the nature of this
vulnerability, it is possible that database content may be disclosed or
modified. This additional possibility has not yet been confirmed.
21. C-Note Squid_Auth_LDAP Pam Logging Format String Vulnerability
BugTraq ID: 4679
Remote: Yes
Date Published: May 06 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4679
Summary:
mysql_auth_ldap is a freely available, open source authentication package
distributed by C-Note. It is available for the Linux operating system.
A problem with mysql_auth_ldap could make it possible for a remote user to
execute arbitrary code. The problem is in logging of authentication.
Due to a problem in the design of the program, it may be possible to
exploit a format string vulnerability. The logging() function in the
program calls syslog insecurely. As a result, it may be possible for a
remote user attempting to connect to the host to supply format specifiers
that will cause memory to be overwritten.
This problem could result in the execution of attacker supplied code, and
result in elevated privileges.
22. AOL Instant Messenger AddExternalApp Remote Buffer Overflow
BugTraq ID: 4677
Remote: Yes
Date Published: May 06 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4677
Summary:
AOL Instant Messenger (AIM) is a real time messaging service.
The vulnerability exists in the way that AIM parses an AddExternalApp
request with a TLV (type, length, value) type of greater than 0x2711.
This type of request is prone to a buffer overflow which could allow a
remote user to obtain the same privileges of the user who is currently
logged on.
It is important to note that there is currently no way for an AIM user to
block this type of request.
This is a variant of the issue discussed in BID 3769.
**AOL has made modifications to their AIM servers to prevent this
vulnerability from being exploited through their servers. However, the
underlying problem still exists in the client software which could still
be exploited using something similar to a man in the middle attack. This
could also be exploited if the attacker can contrive a way to bypass the
filters on the AIM servers.
III. SECURITYFOCUS NEWS AND COMMENTARY
------------------------------------------
1. Cable Modem Hacking Goes Mainstream
By Kevin Poulsen
An ambitious hackware project promises to bring illicit broadband
"uncapping" to the masses, and with it the risks that come with high-speed
hijinks.
http://online.securityfocus.com/news/394
2. Net Threats Monitored In Malaysia
By Adam Creed, Newsbytes
Alert and attentive, the Malaysian Computer Emergency Response Team
(MyCERT) records, reports and analyzes Internet-based PC security
incidents as they impact on the Malaysian Net population.
http://online.securityfocus.com/news/403
3. NeuLevel Says Site's Strange Message Not From Attackers
By Brian McWilliams, Newsbytes
A bizarre message that appeared Wednesday on several Web sites operated by
domain registry NeuLevel was not the work of hackers but instead resulted
from an internal error, company officials said. The short message, which
was displayed for several hours Wednesday in place of the site's usual
home pages, read "Prowl requests your assistance against the Decepticons!"
http://online.securityfocus.com/news/402
4. Xbox 'Emulator' Front For Online Money-Making Scam
By Brian McWilliams, Newsbytes
A new fraud by Internet scam artists attempts to tap into video game
aficionados' burning desire to play Microsoft Xbox games on their personal
computers.
An "Xbox emulator" currently being offered for free on the Web is actually
a Trojan horse designed to covertly rack up money for its authors using
pay-for-click and other schemes, malicious code experts said.
http://online.securityfocus.com/news/401
IV.SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Clam Antivirus v0.11
by Tomasz Kojm
Relevant URL:
http://www.konarski.edu.pl/~zolw
Platforms: UNIX
Summary:
Clam Antivirus is a powerful anti-virus scanner for Unix. It supports
AMaViS, compressed files, uses the virus database from OpenAntivirus.org,
and includes a program for auto-updating. The scanner is multithreaded,
written in C, and POSIX compliant.
2. NetUP UTM billing system v3.0
by Evgeniy
Relevant URL:
http://www.netup.ru
Platforms: FreeBSD, Linux, NetBSD, OpenBSD, Solaris, SunOS, UNIX
Summary:
NetUP UTM is a billing system for Internet Service Providers and home
networks. It provides a complex and flexible management tool for
administrators. The system works on any UNIX- based system, and is tested
on FreeBSD, Linux, and Solaris. It features a friendly administrator and
user Web interface. Traffic data can be obtained from the interface of a
PC router or from a Cisco router.
3. fireflier v0.8
by Martin Maurer
Relevant URL:
http://sourceforge.net/projects/fireflier
Platforms: Linux, POSIX
Summary:
Fireflier is a firewall tool which is built on top of the iptables
framework. It allows you to create rules based on single incoming network
packets or to simply allow/deny single packets to pass. It features a
client-server approach for administering from another PC, SSL connection
between client and server, rules with timeouts (rules are deleted after
some time or when fireflier-server shuts down), and filtering based on
applications.
4. OpenAI v0.2
by thornhalo [email protected]
Relevant URL:
http://openai.sourceforge.net/downloads.html
Platforms: Linux, POSIX, Solaris, SunOS, Windows 2000, Windows 95/98,
Windows NT, Windows XP
Summary:
The OpenAI site is centered around an Open Source project and community
involving artificial intelligence. The project itself is the creation of a
set of tools that are considered to be models of human intelligence or
biomimicry. These tools are intended to be integrated into applications or
used stand alone for research.
5. phpSecurityAdmin v2.1
by Justin Koivisto
Relevant URL:
http://www.phpclasses.org/browse.html/package/391.html
Platforms: Os Independent
Summary:
phpSecurityAdmin is a PHP application that was designed to be implemented
in custom Content Management Systems (CMS). It is designed to be easy to
use, so that CMS programmers do not have to spend a lot of time managing
user access. It can be used for controlling access to Web pages based on
user names and passwords. The system allows the client to manage user
accounts and access rights, and to add, edit, or delete users. It also
features "user profiles" which provide an efficient method for creating
multiple users with similar access rights.
6. Python milter v0.4.4
by Stuart D. Gathman
Relevant URL:
http://www.bmsi.com/python/milter.html
Platforms: POSIX
Summary:
The milter module for Python provides a python interface to Sendmail's
libmilter that exploits all its features. Milters can run on the same
machine as sendmail, or another machine. The milter can even run with a
different operating system or processor than sendmail. Sendmail talks to
the milter via a local or internet socket, and keeps the milter informed
of events as it processes a mail connection. At any point, the milter can
cut the conversation short by telling sendmail to ACCEPT, REJECT, or
DISCARD the message. After receiving a complete message from sendmail, the
milter can again REJECT or DISCARD it, but it can also ACCEPT it with
changes to the headers or body.
V. SECURITY JOBS SUMMARY
------------------------
1. VP, Information Security, CNET Networks (San Francisco) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
2. Information Security Instructor Needed - Seattle, WA - Greythorn (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/5544986F9407D611A5900008C70964061A5F9E@EXCHANGE
3. SMTP Architect contract position in NJ (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
4. Seeking a Network Security Professional Position (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
5. CISSP and J2EE Analyst wanted for Dallas, Texas (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
6. Seeking Network Security Engineer (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
7. Penetration Tester / Security Analyst seeks job (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
8. Resume for (Systems|Network|Security) (Administrator|Engineer|Man ager|Specialist) position (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
9. Seeking Entrepreneurial Security Engineer (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
10. Principal/s wanted: co-launch Security Consultancy (Los Angeles,CA) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
11. Looking for Pentest professional in Unix/Windows (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
12. Seeking infosec position in NY/NJ (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
13. Seeking an Information Security Position (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
14. Senior security systems Engineer job-Hartford,CT area (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
15. Montreal - Penentration testing position open (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/000401c1f457$807f4100$87298242@MARTINDION
16. Resume - Information Systems Security Professional (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
17. Information Security Administrator - #709 - Denver, CO (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
18. UK based organisation seeking Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
19. Request for Referral: NetSec Services Co in DC area seeks Federal Sales Reps (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
20. Network Security Intrusion Software Developer, Austin TX (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
21. Application Security Analyst - #711 - Chicago, IL (Thread)
Relevant URL:
http://online.securityfocus.com/archive/77/[email protected]
VI. INCIDENTS LIST SUMMARY
-------------------------
1. Strange "shotgun" scan (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
2. Strange "shotgun" scan (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
3. Dead Thread - Publishing Nimda Logs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
4. Publishing Nimda Logs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/Pine.GSO.3.96.1020508231830.20702A-100000@crypto
5. netbuie.exe, scorpionsearch.com and fastcounter.bcentral.com - Wrap up (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/DF88C06B4220D61183B40008C7FA20CE181E2E@SAGEMSJ0002
6. netbuie.exe, scorpionsearch.com and fastcounter.bcentral.com (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
7. Publishing Nimda Logs == BAD IDEA (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
8. Nimda Infections and code red resurgence (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
9. Publishing Nimda Logs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
10. Publishing Nimda Logs - Summary (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/9D884881F5E1F24FB845967851720FC302C9BB44@red-msg-12.redmond.corp.microsoft.com
11. Publishing Nimda Logs - Summary (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
12. Unusual Message log contents (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
13. netbuie.exe, scorpionsearch.com and fastcounter.bcentral.com (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
14. AW: Publishing Nimda Logs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
15. netbuie.exe, scorpionsearch.com and fastcounter.bcentral.com (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/DF88C06B4220D61183B40008C7FA20CE181E29@SAGEMSJ0002
16. info (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/1020780316.28140.29.camel@tardis
17. info (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
18. Reverse Challenge - Binary released (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
19. 'rooted' NT/2K boxen? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
20. Windows Systems Defaced (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
21. World-wide distributed DoS and "warez" bot networks (fwd) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/Pine.LNX.4.44.0205031025360.1167-100000@shiva0.cac.washington.edu
22. Windows Systems Defaced (Thread)
Relevant URL:
http://online.securityfocus.com/archive/75/[email protected]
VII. VULN-DEV RESEARCH LIST SUMMARY
----------------------------------
1. Thinking about Security rules... (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
2. whois tricks was : whois is what? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
3. Publishing Nimda Logs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/0980A271D6DBD211BC2F0008C7911BC00908778C@COLMDEX1
4. Publishing Nimda Logs == BAD IDEA (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
5. Possible ZoneAlarm 3 Problem??? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/0763FFA14A83B842BA7D84B02FC822D6017CA712@exchange2k
6. Lessons learned writing exploits (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
7. CRLF Injection (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
8. Possible ZoneAlarm 3 Problem??? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/3CDA2382.3769.50D1406C@localhost
9. SST (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/6FB083FB72EFD21181D30004AC4CA18A018FB6AE@srv002
10. Thinking about Security rules... (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
11. Sar -o exploitation process info. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
12. Publishing Nimda Logs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
13. Publishing Nimda Logs - Summary (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
14. XiRCON && Internet Explorer exposing Cookies (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/000f01c1f70f$3fdddfc0$9347cc0a@maq0r
15. whois tricks was : whois is what? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/001001c1f70c$1aaf0330$af00a8c0@orange
16. about disclosure of nimda logs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAAowWt3xgdO0Sm94Qn6vzZksKAAAAQAAAA509uXbP5UEq/[email protected]
17. Buffer Overflow Discovery (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/001501c1f6f2$c46bc440$6301a8c0@visp
18. Publishing Nimda Logs == BAD IDEA (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
19. Lessons learned writing exploits (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/06f301c1f6cc$9ddcf770$2e58a8c0@ffornicario
20. is: greyhat virus was Publishing Nimda Logs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/001701c1f6c9$35140b50$af00a8c0@orange
21. OT: Stop Auto Mail Backs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
22. whois tricks was : Publishing Nimda Logs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
23. about disclosure of nimda logs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/1020880876.1063.7.camel@nemo
24. Fw: Publishing Nimda Logs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/004001c1f6b8$84e8f700$24029dd9@kain
25. is: whois tricks was : Publishing Nimda Logs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/002501c1f6b8$10f21340$af00a8c0@orange
26. Multiple Local Vulnerabilities in some FTP Client.Who canexploit it by remote? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/1020873914.1465.80.camel@FranksLaptop
27. Actuate e.Reporting possible vulnerabilities (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/D5E5F4682E75D41185CD00D0B79DC56F04BB1AD1@exchfed01.federatedinv.com
28. Windows XP Raw Sockets tool? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
29. vxWorks WND checker? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/020c01c1f632$d6854360$2e58a8c0@ffornicario
30. Windows XP Raw Sockets tool? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
31. Wlan @ bestbuy is cleartext? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
32. ADT enterNET and Symantec Ghost (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
33. cURL remote PoC for FBSD (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
34. FrontPage Server Extension : fp30reg.dll Cross Site Scripting (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/000701c1f598$3e0f2aa0$6301a8c0@visp
35. [Fwd: FW: XP Screen Saver password uses Old password until logoutor New one is used.] (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/000c01c1f578$2290f350$fdfea8c0@dellydoo
36. LEA Conference Call for Papers (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
37. Multiple Local Vulnerabilities in some FTP Client.Who can exploitit by remote? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
38. Possible privary leak converting to website stealing (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
39. Slackware 8.0 / ucd-snmpd 4.2.1 exploit works? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
40. cURL remote PoC for Linux (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
41. [LSD] Solaris cachefsd remote buffer overflow vulnerability (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
42. Multiple Local Vulnerabilities in some FTP Client.Who can exploitit by remote? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/002b01c1f497$a15f4920$6301a8c0@visp
43. Packetstorm archive warning: 73501867, PHP exploit binary code found to be virus distribution vector for Linux.Jac.8759. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
44. Finding and exploiting buffer overflows in Windows. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
45. Multiple Local Vulnerabilities in some FTP Client.Who can exploit it by remote? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
46. Finding and exploiting buffer overflows in Windows. (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/000001c1f464$4ed407f0$0100000a@vision
47. trusting user-supplied data (was Re: FreeBSD Security AdvisoryFreeBSD-SA-02:23.stdio) (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
48. Security holes : PHP Image View, NewsPro, Photo DB, As_web, GuestBook (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
49. static char overflow (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
50. BACKSTEALTH reverse engineered (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
51. Preventing XSS in PHP... (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
52. Fw: Security Research Group (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/20020503123155.A271@hannibal
53. backstealth reverse-engineered (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
54. Wlan @ bestbuy is cleartext? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
55. Macromedia Flash Activex Buffer overflow (Thread)
Relevant URL:
http://online.securityfocus.com/archive/82/[email protected]
VIII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. 2K Server locking 98 users out (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
2. FTP tagging (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
3. 2K Server locking 98 users out (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/Pine.WNT.4.44.0205081055310.-46145483-100000@dave
4. FTP tagging (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
5. Publishing Nimda Logs - Summary (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
6. Publishing Nimda Logs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
7. SecurityFocus Microsoft Newsletter #85 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
8. Publishing Nimda Logs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/9D884881F5E1F24FB845967851720FC302C9BB38@red-msg-12.redmond.corp.microsoft.com
9. Macromedia Flash Activex Buffer overflow (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
10. HfNetChk Message: File versions greater than expected: (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
11. 'rooted' NT/2K boxen? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
12. 'rooted' NT/2K boxen? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
13. Rolling out patches (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/5DDDFEB53CECD211A8410001FA7E99600C0A4000@xcem-casfo-10.wellsfargo.com
14. Strange behavior after removing Klez on Win2000 server (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
15. Access is denied (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
16. Windows Systems Defaced (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
IX. SUN FOCUS LIST SUMMARY
----------------------------
1. gpg /netstat problems (Thread)
Relevant URL:
http://online.securityfocus.com/archive/92/[email protected]
X. LINUX FOCUS LIST SUMMARY
---------------------------
1. plain text vs. html (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/20020508220710.GA1383@localhost
2. AW: AW: entry in /etc/passwd (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/[email protected]
3. AW: plain text vs. html (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/[email protected]
4. AW: entry in /etc/passwd (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/F9B05628BAE2414A99980964199E954A08FB52@VOYAGER.brisbane.hatfields.com.au
5. entry in /etc/passwd (Thread)
Relevant URL:
http://online.securityfocus.com/archive/91/[email protected]
XI. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored By: Recourse Technologies, Inc.
FREE white paper, "The Evolution of Honeypots" sheds new light on the
latest innovations in deception technologies, including Recourse ManTrap®
3.0 - the latest advance in the industry's leading deception-based
intrusion detection solution.
Visit us at: http://www.recourse.com/sf
-------------------------------------------------------------------------------