SecurityFocus Linux Newsletter #85

John Boletta <[email protected]> Tue, 18 Jun 2002 10:59:07 -0600 (MDT)
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #85
----------------------------------

This newsletter is sponsored by SecurityFocus (www.securityfocus.com)

Attention Non-profits and Universities: Sign-up now for preferred pricing
on the only global early-warning system for cyber attacks - SecurityFocus
Deepsight Analyzer.

Click here for more info
http://www.securityfocus.com/corporate/products/pdpsection.shtml

-------------------------------------------------------------------------------


I. FRONT AND CENTER
     1. Developing an Effective Incident Cost Analysis Mechanism
     2. Assessing Security Risk, Part One: What is Risk Assessment?
     3. The Commoner's Virus
     4. Black Hat Briefings & Training
II. LINUX VULNERABILITY SUMMARY
     1. Ehud Gavron TrACESroute Terminator Function Format String...
     2. WebCalendar Include Files Information Disclosure Vulnerability
     3. Pine Unix Username Account Information Leakage Vulnerability
     4. Multiple Bugzilla Security Vulnerabilities
     5. Geeklog pid CGI Variable SQL Injection Vulnerability
     6. Geeklog Multiple Cross Site Scripting Vulnerabilities
     7. Datalex Bookit! Consumer Plaintext Authentication Credentials...
     8. ZenTrack Ticket.PHP Information Disclosure Vulnerability
     9. Geeklog Calendar Event Form Script Injection Vulnerability
     10. RHMask Local File Overwrite Vulnerability
     11. Apache Tomcat JSP Engine Denial of Service Vulnerability
     12. Ayman Akt IRCIT Invite Message Remote Buffer Overflow...
     13. MMFTPD SysLog Format String Vulnerability
     14. CGIScript.net csNews Double URL Encoding Unauthorized...
     15. CGIScript.net csNews Header File Type Restriction Bypass...
     16. Voxel Dot Net CBMS Multiple Code Injection Vulnerabilities
     17. EDonkey 2000 URI Handler Buffer Overflow Vulnerability
     18. Splatt Forum Image Tag HTML Injection Vulneraility
     19. PHPReactor Global.INC.PHP Cross Site Scripting Vulnerability
     20. MyHelpDesk HTML Injection Vulnerability
     21. MyHelpDesk Cross-Site Scripting Vulnerability
     22. MyHelpDesk SQL Injection Vulnerability
     23. W-Agora Remote File Include Vulnerability
     24. CGIScript.net CSNews Sensitive File Disclosure Vulnerability
III. LINUX FOCUS LIST SUMMARY
     1. Web filtering? (Thread)
     2. RE: Web filtering? (Thread)
     3. Have I been kitted? (Thread)
     4. Time Stamp Server under Linux (Thread)
     5. Thanks for the feedback (Thread)
     6. Snort vs. other (Thread)
IV. NEW PRODUCTS FOR LINUX PLATFORMS
     1. KillDisk
     2. Aventail ExtraNet Center
     3. Tripwire Manager
V. NEW TOOLS FOR LINUX PLATFORMS
     1. TPassguard v0.01a
     2. httpdstats v0.2.2
     3. linksysmon v1.0.1
     4. POP3 Virus Scanner Proxy v0.4
VI. SPONSORSHIP INFORMATION





I. FRONT AND CENTER
-------------------
1. Developing an Effective Incident Cost Analysis Mechanism
By David A. Dittrich

One of the challenges facing security and accounting personnel is to
calculate the real costs of security incidents. In this article,
SecurityFocus contributor Dave Dittrich discusses the Incident Cost
Analysis Modeling Project (I-CAMP), an attempt to develop a workable model
for estimating the costs of computer security incidents.

http://online.securityfocus.com/infocus/1592

2. Assessing Internet Security Risk, Part One: What is Risk Assessment?
by Charl Van der Walt

The Internet, like the Wild West of old, is an uncharted new world, full
of fresh and exciting opportunities. However, like the Wild West, the
Internet is also fraught with new threats and obstacles; dangers the
average businessman and home user hasn't even begun to understand. But I
don’t have to tell you this. You’ve heard that exact speech at just about
every single security conference or seminar you’ve ever attended, usually
accompanied by a veritable array of slides and graphs demonstrating
exactly how serious the threat is and how many millions of dollars your
company stands to loose. The “death toll” statistic are then almost always
followed by a sales pitch for some or other product that’s supposed to
make it all go away. Yeah right.

http://online.securityfocus.com/infocus/1591

3. The Commoner's Virus
By George Smith

Despite its virulence, the Klez worm is ignored by the newspapers and
dismissed by the digerati. Could the demographics of its victims be a
factor?

http://online.securityfocus.com/columnists/87

4. Black Hat Briefings & Training

Attend Black Hat Briefings & Training, July 29 - August 1, Las Vegas, the
world's premier technical security event! 8 tracks, 12 training sessions,
Richard Clarke keynote, 500 delegates from 30 nations, with a near cult
following of both CSOs and "underground" security experts. See for
yourself what the buzz is all about.

Please visit www.blackhat.com for more information.


II. BUGTRAQ SUMMARY
-------------------
1. Ehud Gavron TrACESroute Terminator Function Format String Vulnerability
BugTraq ID: 4956
Remote: No
Date Published: Jun 06 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4956
Summary:

TrACESroute is a freely available, open source traceroute program.  It is
available for Unix and Linux operating systems.

A format string vulnerability exists in TrACESroute.  The problem exists
in the terminator (-T) function of the program.  Due to improper use of
the fprintf function, an attacker may be able to supply a malicious format
string to the program that reults in writing of attacker-supplied values
to arbitrary locations in memory.

As this program requires raw sockets, this program is typically installed
setuid root.  Because of this, it may be possible for a local attacker to
exploit this vulnerability to gain local administrative access.

2. WebCalendar Include Files Information Disclosure Vulnerability
BugTraq ID: 4961
Remote: Yes
Date Published: Jun 07 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4961
Summary:

WebCalendar is a web application used to maintain a calendar for a single
or multiple users. It is implemented in PHP, and should function under any
system supporting the language, including Windows and Linux.

A vulnerability has been reported in WebCalendar that may allow attackers
to view potentially sensitive information.

The vulnerability exists in the naming convention of include files.
Typically include files end with an extension of '.inc' so that they are
easily distinguishable from other files. However, these files aren't
parsed as PHP code by the PHP interpreter and an attacker can easily get
access to the source code. This is a real problem when sensitive
configuration data (e.g database credentials) is placed in these PHP
files.

This information can then be used to mount further attacks against a
vulnerable system.

3. Pine Unix Username Account Information Leakage Vulnerability
BugTraq ID: 4963
Remote: Yes
Date Published: Jun 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4963
Summary:

Pine is a freely available, open source mail user agent (MUA).  It is
available for most Unix and Linux operating systems.

A problem with pine may make it possible for remote users to gain
information about accounts on a system.

Pine allows users to specify their own From: field.  This feature can be
used to mask individual user accounts in such a scenario as a role email
account.  This feature can also be used to obscure user accounts to
prevent third parties from gaining information about local system
accounts.

Pine will leak the Unix username of the original sender.  When a mail is
sent, pine adds headers to the email in the form of either the "Sender:"
field or the "X-X-Sender:" field.  This could allow a remote attacker to
discover the username of the user sending an email, and could be used in
an information gathering attack.

4. Multiple Bugzilla Security Vulnerabilities
BugTraq ID: 4964
Remote: Yes
Date Published: Jun 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4964
Summary:

Bugzilla is a freely available, open source bug tracking software package.
It is available for Linux, Unix, and Microsoft Operating Systems.

Several problems have been discovered in Bugzilla that may allow remote
users to gain information through information leakage, or unauthorized
access to Bugzilla.

The queryhelp.cgi script distributed with Bugzilla could allow remote
users to gain access to information products that set as confidential in
the Bugzilla database.

An attacker may be able to hijack user sessions provided the attacker has
reverse resolution authority for an IP address, and is able to steal a
user's authentication cookie.

When a directory does not exist, Mozilla will attempt to create it.
However, by default, the directory is usually created with world-writeable
permissions.

It is possible for any user with permissions to edit any other user's
details to delete any other user of the board through the edituser.cgi
script.

The Real Names field does not filter HTML.  An attacker may be able to
input malicious HTML in the field, resulting in a cross-site scripting
attack.

When performing a mass change, the groupset of all bugs are set to the
groupset of the first bug in the mass change sequence.

Bugzilla did not handle encoding from some browsers, which could lead to
unintended consequences, such as setting private or confidential
information to a publicly displayed mode.

The syncing of the shadow database was done insecurely.  Under some
circumstances, this could output sensitive data to a user of Bugzilla at
random.

5. Geeklog pid CGI Variable SQL Injection Vulnerability
BugTraq ID: 4968
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4968
Summary:

Geeklog is freely available, open-source weblog software. It is written in
PHP and will run on most Unix and Linux variants, as well as Microsoft
Windows NT/2000. Geeklog is backended by MySQL. Geeklog version 1.3.5 and
prior are subject to SQL injection attacks.

Geeklog does not properly validate externally-supplied input when
including arbitrary characters and additional SQL statements in the 'pid'
variable of some CGI requests. As a result, attackers may be able to
modify SQL queries performed by the application.

This issue has been reported in the comment.php script, and the following
URL has been supplied as an example:


/comment.php?mode=display&sid=foo&pid=PROBLEM_HERE&title=ALPER_Research_Labs

It should be noted that if the 'Magic Quotes' PHP feature is enabled, it
may be difficult for attackers to obtain user information from SQL tables.
This feature may, however, not be sufficient to remove all possibilities
of exploitation.

Exploitation of this vulnerability may result in data corruption,
disclosure of sensitive information and intrusion into the database
server.

6. Geeklog Multiple Cross Site Scripting Vulnerabilities
BugTraq ID: 4969
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4969
Summary:

Geeklog is freely available, open-source weblog software. It is written in
PHP and will run on most Unix and Linux variants, as well as Microsoft
Windows NT/2000. Geeklog is backended by MySQL.

Geeklog does not filter script code from URL parameters, making it prone
to cross-site scripting attacks. Attacker-supplied script code may be
included in a malicious link to the 'index.php' or 'comment.php' script.
The attacker-supplied script code will be executed in the browser of a web
user who visits this link, in the security context of the host running
Geeklog. Such a link might be included in a HTML e-mail or on a malicious
webpage.

This may enable a remote attacker to steal cookie-based authentication
credentials from legitimate users of a host running Geeklog.

This issue has been reported to exist in Geeklog 1.3.5, earlier versions
may also be susceptible to this issue.

7. Datalex Bookit! Consumer Plaintext Authentication Credentials Vulnerability
BugTraq ID: 4972
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4972
Summary:

Datalex Bookit! Consumer is web-based software for provided travel booking
services.  It will run on most Unix and Linux variants in addition to
Microsoft Windows operating systems.

Datalex Bookit! Consumer may be configured to remember authentication
credentials.  If a user chooses to have their authentication credentials
'remembered', then the credentials will be stored in a cookie.  However,
these credentials are stored in plaintext.  This becomes an issue if the
authentication credentials ever become exposed to an attacker.

It should be also noted that in some cases form data is posted using the
GET method.  As a result, sensitive information (including plaintext
authentication credentials) is sent in CGI parameters.

A number of situations exist where an attacker may be able to gain access
to the plaintext credentials.  For example, the authentication credentials
may be cached on a proxy server.  Also, this may be exploited by an
attacker in an appropriate position to sniff network traffic between a
user's web client and the server running the software.  Lastly,
cookie-based authentication credentials may potentially be exposed via
cross-site scripting or HTML injection attacks.

8. ZenTrack Ticket.PHP Information Disclosure Vulnerability
BugTraq ID: 4973
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4973
Summary:

ZenTrack is designed to be a complete project management, bug tracking,
and ticketing system. It is implemented in PHP and is able to run on Unix
and Linux variants as well as Windows operating systems.

A path disclosure vulnerability has been reported in ZenTrack version
2.0.3 and earlier.

By requesting a ticket that doesn't exist, an attacker is able to cause
ZenTrack to reveal the absolute path to the web root in the error output.
It may also cause ZenTrack to reveal other sensitive information to the
attacker.

This information may be used by attackers to mount further attacks against
a vulnerable system.

9. Geeklog Calendar Event Form Script Injection Vulnerability
BugTraq ID: 4974
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4974
Summary:

Geeklog is freely available, open-source weblog software. It is written in
PHP and will run on most Unix and Linux variants, as well as Microsoft
Windows NT/2000. Geeklog is backended by MySQL.

Geeklog does not sufficiently sanitize script code from form fields,
making it prone to script injection attacks.

Attacker-supplied script code included in the Link field of a new Calendar
Event submission form, may potentially end up in webpages generated by
Geeklog and will execute in the browser of a user who views such pages, in
the security context of the website.

It should be noted that new Calendar Event submissions are sent to the web
site administrator for approval.

This issue may potentially be exploited to hijack web content or steal
cookie-based authentication credentials from legitimate users.

10. RHMask Local File Overwrite Vulnerability
BugTraq ID: 4984
Remote: No
Date Published: Jun 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4984
Summary:

rhmask is a is a Red Hat Linux utility for distributing files as masks
against other files.

rhmask does not sufficiently validate the output filename supplied in mask
files.  Attackers may potentially exploit this issue to create a mask file
which may cause other system files to be overwritten via symlinks when the
mask is applied.  Under normal circumstances, the user is prompted with
the name of the target file.  However, rhmask does not check if the target
filename is a symbolic link.

rhmask is not installed by default in recent versions of Red Hat Linux.

11. Apache Tomcat JSP Engine Denial of Service Vulnerability
BugTraq ID: 4995
Remote: Yes
Date Published: Jun 12 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4995
Summary:

Apache Tomcat is a freely available, open source servlet container that is
used to display and interpret Java Servlet and JavaServer Pages (JSP)
technologies.  Apache Tomcat is available for Unix and Linux variants as
well as the Microsoft Windows operating environments.

A vulnerability has been reported in Apache Tomcat for Windows that
results in a denial of service condition. The vulnerability occurs when
Tomcat encounters a malicious JSP page.

The following snippet of code is reported to crash the Tomcat JSP engine:
new WPrinterJob().pageSetup(null,null);

An attacker may exploit this vulnerability by creating a malicious page on
vulnerable systems and by requesting the page from the server. This would
result in the Tomcat JSP engine to attempt to interpret the page and
subsequently crash leading to the denial of service condition.

12. Ayman Akt IRCIT Invite Message Remote Buffer Overflow Vulnerability
BugTraq ID: 4998
Remote: Yes
Date Published: Jun 12 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4998
Summary:

IRCIT is a terminal based IRC client for Linux and Unix systems.

A remote buffer overflow vulnerability has been reported in some versions
of IRCIT. It may be possible for a remote IRC user to exploit this
condition to execute arbitrary code as the vulnerable IRCIT process,
generally with user level permissions.

Reportedly, the issue exists within the handling of the IRC INVITE
command. When a INVITE message is received, the supplied from user data is
copied into a fixed buffer of length MAXHOSTLEN. A maliciously formatted
message may overflow this buffer and overwrite adjacent memory, including
stack frame data such as return addresses.

This issue has been reported in version 0.3.1 of IRCIT. Other versions may
share this vulnerability, this has not however been confirmed.

13. MMFTPD SysLog Format String Vulnerability
BugTraq ID: 4990
Remote: Yes
Date Published: Jun 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4990
Summary:

mmftpd is a freely available, open source FTP server for Linux operating
systems.

A problem with the daemon could make it possible for a remote attacker to
execute arbitrary code.

Due to improper use of the syslog call, a problem exists which could make
the execution of arbitrary code possible.  A syslog call in the program
which logs user-supplied information could be exploited to print to
specified places in memory, including potentially overwriting the return
address of a function and executing arbitrary code.

This problem could allow an attacker to send a malicious format string to
the syslog function of the program.  The malicious format string, and any
code supplied with it, would be executed with the privileges of the mmftpd
user.

14. CGIScript.net csNews Double URL Encoding Unauthorized Administrative Access Vulnerability
BugTraq ID: 4993
Remote: Yes
Date Published: Jun 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4993
Summary:

csNews is a script for managing news items on a website. It will run on
most Unix and Linux variants, as well as Microsoft Windows operating
systems.

csNews may be configured through a web interface. Different users may be
defined with varying levels of access. Users with "public" access may
modify page content, while admin users are able to configure the script.

Reportedly, users with public access may view and modify some
configuration pages normally restricted to admin level users. This may be
accomplished by double url encoding metacharacters in the database name
provided as a CGI parameter.

Users will be able to view and modify options on the 'Advanced Settings'
page, as well as view 'Admin Options'.

This may be exploited by submitting URLs with database names such as
default%2edb.

15. CGIScript.net csNews Header File Type Restriction Bypass Vulnerability
BugTraq ID: 4994
Remote: Yes
Date Published: Jun 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4994
Summary:

csNews is a script for managing news items on a website. It will run on
most Unix and Linux variants, as well as Microsoft Windows operating
systems.

It is possible for an administrator to define a header and footer
displayed by csNews. Normally this is restricted to txt, html and htm
files. However, it is possible for a malicious adminstrator to bypass this
restriction and specify an arbitrary file type.

Reportedly, this may be done simply by submitting a manually constructed
HTTP request with the new configuration information.

Exploitation of this vulnerability allows an attacker to display any
system file as a header or footer. An attacker may, for example, specify a
CGI script file which include authentication information.

The ability to exploit this vulnerability may only require "public" access
to csNews if used in conjunction with issues discussed in BID 4993.

16. Voxel Dot Net CBMS Multiple Code Injection Vulnerabilities
BugTraq ID: 4957
Remote: Yes
Date Published: Jun 06 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4957
Summary:

Voxel Dot Net's CBMS is a client and billing management system designed
for an ISP. It is implemented in PHP, and should function under any system
supporting the language, including Windows and Linux. In addition to
management functionality, customers are able to view and modify their
personal information.

Multiple input validation vulnerabilities have been reported in CBMS.
Reportedly, it is possible to inject HTML, JavaScript and SQL code into
the system.

The ability to inject JavaScript into the system may exist as either a
cross site scripting issue or a script injection problem. It has been
reported possible to exploit this vulnerability through the first name
field on the Add a new client screen. An attacker may be able to exploit
this vulnerability in order to execute script code within the context of
the billing system as an authenticated administrator, possibly granting
full access to the system.

SQL injection has been reported as possible within the dltclnt.php script.
The CGI parameter idnum is used directly within an SQL statement. It is
trivially possible to modify this query in order to mark all clients of
the system as deleted. More subtle SQL injection attacks may allow a
malicious party to view or modify sensitive information. Due to the nature
of this system, it is plausible that billing information may be
compromised.

These issues have been reported in version 0.7 of CBMS. Other versions may
share these vulnerabilities, this has not however been confirmed.

17. EDonkey 2000 URI Handler Buffer Overflow Vulnerability
BugTraq ID: 4951
Remote: Yes
Date Published: Jun 06 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4951
Summary:

eDonkey 2000 is a peer to peer file sharing network. It is similar to
KaZaa and Morpheus. Clients of eDonkey 2000 are built for Windows, Mac and
Linux operating systems.

The eDonkey 2000 Windows client includes a handler for a custom URI,
ed2k://.  This URI handler allows for files to be retrieved from the
network using MSIE or other tools which support it.

It has been reported that the handler for eDonkey 2000 is vulnerable to a
buffer overflow condition when parsing maliciously constructed URIs.  If
an overly long filename is given as part of the ed2k:// URI, the overflow
will cause the stack frame of the affected function to be overwritten.
This may be exploited to crash the user's browser or execute arbitrary
code on the victim client.

It is suspected that earlier versions of the Windows client are
susceptible to this vulnerability as well. Versions for other operating
systems do not appear to be affected.

18. Splatt Forum Image Tag HTML Injection Vulneraility
BugTraq ID: 4953
Remote: Yes
Date Published: Jun 06 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4953
Summary:

Splatt forum is web forum software. It will run on most Unix and Linux
variants, as well as Microsoft Windows operating systems.

Splatt Forum does not filter HTML from image tags. This may allow an
attacker to inject arbitrary script code in forum messages. Injected
script code will be executed in the browser of an arbitrary web user who
views the malicious forum message, in the context of the website running
Splatt Forum.

This can be achieved by entering script or HTML between [img] and [/img]
tags in a forum message.

This may potentially be exploited to hijack web content or steal
cookie-based authentication credentials from legitimate users.

It may be possible to inject JavaScript and HTML in other parts of forum
messages, however this has not been confirmed.

19. PHPReactor Global.INC.PHP Cross Site Scripting Vulnerability
BugTraq ID: 4952
Remote: Yes
Date Published: Jun 06 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4952
Summary:

php(Reactor) is an integrated system of web applications designed for easy
website maintenance. It will run on most Linux and Unix variants, in
addition to Microsoft Windows operating systems.

It is reported that php(Reactor) is vulnerable to cross site scripting
attacks.

The vulnerability is present in the 'global.inc.php' script. php(Reactor)
does not properly santize client-supplied value of the 'go' parameter
prior to output.

Attackers may exploit this vulnerability by constructing a link to one of
these scripts containing malicious HTML code. If the link is sent to a
php(Reactor) user and clicked on, the attacker-supplied HTML code will run
in the context of the user's php(Reactor) session. The HTML code may
obtain cookie values or perform unauthorized actions as the victim user.

20. MyHelpDesk HTML Injection Vulnerability
BugTraq ID: 4967
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4967
Summary:

MyHelpDesk is a web-based helpdesk system written in PHP. It is freely
available and will run on most Unix and Linux variants as well as
Microsoft Windows operating systems.

A vulnerability has been reported for MyHelpDesk (version 20020509 and
earlier) that will allow attackers to inject malicious HTML code.

MyHelpDesk does not properly sanitize HTML tags from form fields.
Attackers may pass arbitrary HTML code through the unsanitized form
fields. The attacker-supplied HTML code will end up being displayed in
MyHelpDesk webpages and will be executed by the web client of users who
visit such pages, in the security context of the site running the
vulnerable software.

The 'Title', 'Description' and 'Update' fields are not properly santized
for malicious HTML input. Additionally, an opportunity for HTML injection
exists when a new ticket is created or edited.

This may potentially be exploited to hijack web content or steal
cookie-based authentication credentials from legitimate users.

21. MyHelpDesk Cross-Site Scripting Vulnerability
BugTraq ID: 4970
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4970
Summary:

MyHelpDesk is a web-based helpdesk system written in PHP. It is freely
available and will run on most Unix and Linux variants as well as
Microsoft Windows operating systems.

It is reported that MyHelpDesk (version 20020509 and earlier) are
vulnerable to cross site scripting attacks.

The vulnerability is present in the 'index.php' script. MyHelpDesk does
not properly sanitize HTML from the 'id' CGI parameter prior to output.

Attackers may exploit this vulnerability by constructing a link to a
vulnerable scripts, passing malicious HTML code as a value for unsanitized
CGI parameters. If the link is sent to a MyHelpDesk user and clicked on,
the attacker-supplied HTML code will run in the context of the site
running the vulnerable software.

This issue may be exploited to steal cookie-based authentication
credentials from legitimate users of MyHelpDesk.

22. MyHelpDesk SQL Injection Vulnerability
BugTraq ID: 4971
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4971
Summary:

MyHelpDesk is a web-based helpdesk system written in PHP. It is freely
available and will run on most Unix and Linux variants as well as
Microsoft Windows operating systems.  MyHelpDesk is back-ended by a MySQL
database.

It is reported that MyHelpDesk (version 20020509 and earlier) are
vulnerable to an SQL injection attack.

A SQL injection vulnerability has been reported within the index.php
script. Data supplied by the remote user, via CGI parameters, is used
directly as part of SQL statements. As input sanitization is not properly
performed, it is possible to modify the logic of a SQL query.

Cleverly executed SQL injection attacks may potentially allow a malicious
party to view or modify sensitive information.  Additionally, an attacker
might potentially use this issue to exploit any existing vulnerabilities
in the underlying database.

23. W-Agora Remote File Include Vulnerability
BugTraq ID: 4977
Remote: Yes
Date Published: Jun 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4977
Summary:

W-Agora is a web publishing and forum software. It is implemented in PHP
and will run on most Linux and Unix variants, in addition to Microsoft
Windows operating systems.

W-Agora is prone to an issue which may allow an attacker to include
arbitrary files located on a remote server. In particular, the 'inc_dir'
variable found in a number of W-Agora scripts defines the path to the
configuration file. It is possible, under some configurations, for an
attacker to specify an arbitrary value for the location of the
configuration file which points to a file on a remote server.

If the included file is a PHP script, this may allow for execution of
arbitrary attacker-supplied code.

Successful exploitation depends partly on the configuration of PHP on the
host running the vulnerable software. If 'all_url_fopen' is set to 'off'
then exploitation of this issue may be limited.

24. CGIScript.net CSNews Sensitive File Disclosure Vulnerability
BugTraq ID: 4991
Remote: Yes
Date Published: Jun 11 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4991
Summary:

csNews is a script for managing news items on a website. It will run on
most Unix and Linux variants, as well as Microsoft Windows operating
systems.

A number of sensitive csNews files may be accessed by unauthorized users.
Database files may be accessed in this manner, potentially exposing
database authentication credentials and other sensitive information.

Metacharacters in requests for database files must be double URL encoded.
For example:

default%2edb


IV. LINUX FOCUS LIST SUMMARY
----------------------------
1. Web filtering? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

2. RE: Web filtering? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

3. Have I been kitted? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

4. Time Stamp Server under Linux (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

5. Thanks for the feedback (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

6. Snort vs. other (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]


IV.NEW PRODUCTS FOR LINUX PLATFORMS
-----------------------------------
1. KillDisk
by LSoft Technologies Inc.
Platforms: DOS, Linux, UNIX, Windows 2000, Windows 95/98, Windows NT,
Windows XP
Relevant URL:
http://www.killdisk.com/eraser.htm
Summary:

Active@ Kill Disk is disk eraser software for secure formatting of hard
drives without any possibility of following data recovery. DOS appication
can be run from floppy boot disk. Eraser uses access to drive's data on
physical level via BIOS bypassing logical drive structure organization,
thus it formats disk bypassing operating systems and file systems located
on IBM PC. DoD 5220.22-M compatible.

2. Aventail ExtraNet Center
by Aventail
Platforms: AIX, DG-UX, HP-UX, Linux, Solaris, Windows NT
Relevant URL:
http://www.aventail.com/managed/extranet.asp
Summary:

Aventail ExtraNet Center is simple to deploy and requires no changes to
your partner's network, applications, or firewall configuration. This
simplifies the political challenges of the extranet, speeds deployment
times to days not months, thus increasing your competitive advantage.
Customer Service: By their very nature, extranets bring key partners and
customers to valuable resources. Aventail ExtraNet Center's client runs
transparently in the background and requires no contact with the user
beyond authentication. This increases the value of the partner extranet
while lowering corporations' support costs. And, it's not just HTTP,
Aventail ExtraNet Center provides security and management for any IP
application.

3. Tripwire Manager
by Tripwire, Inc.
Platforms: Linux, Solaris, Windows 2000, Windows NT
Relevant URL:
http://www.tripwire.com/products/manager/
Summary:

Tripwire Manager is a fully functional, cross-platform management console
that allows you to easily manage all installations of Tripwire for Servers
across an enterprise network. Tripwire Manager eliminates the need to
manually monitor multiple discrete network platforms and point solutions.
Instead, you have a comprehensive view of data and network integrity
status from a single, centralized console. Tripwire Manager saves time by
pinpointing integrity violations and reduces management costs by providing
rapid access to detailed reports and actionable data.


V. NEW TOOLS FOR LINUX PLATFORMS
--------------------------------
1. TPassguard v0.01a
by RUAUDEL Frédéric
Relevant URL:
http://passguard.sourceforge.net
Platforms: Linux, POSIX, UNIX
Summary:

TPassguard is designed for working with Unix systems or the Web, where you
need to remember a number of passwords. This program manages passwords in
an encrypted file, so that you only have to remember one. It uses the
PassGuard Framework and can be interfaced with any kind of encryption via
a plugin system.

2. httpdstats v0.2.2
by charvi
Relevant URL:
http://www.charvolant.org/~doug/httpdstats/
Platforms: Linux, POSIX
Summary:

httpdstats is a Perl script that generates a statistical summary of an
Apache access log, intended for use as a cron job on small, low-traffic
Web servers.

3. linksysmon v1.0.1
by Mike Wohlgemuth
Relevant URL:
http://woogie.net/linksysmon/
Platforms: Linux, POSIX
Summary:

linksysmon is a tool for monitoring Linksys BEFSR41/BEFSR11 firewalls
under Linux and other Unix-like operating systems. It accepts log messages
from the Linksys, and logs the messages to /var/log/linksys.log. It
handles the standard activity logs, as well as the "secret" extended
logging, and can handle logs from multiple firewalls. When using extended
logging, it can detect external IP address changes (if you are using
either DHCP or PPPOE) and can call an external program to process the
change.

4. POP3 Virus Scanner Proxy v0.4
by Folke Ashberg
Relevant URL:
http://pop3vscan.sourceforge.net/
Platforms: Linux, POSIX
Summary:

POP3 Virus Scanner Proxy is a full-transparent proxy daemon which scans
all mails for viruses using third party scanners (built-in support for
AVPD and Trophie) on Linux 2.4.X using iptables/netfilter redirect.


VI. SPONSORSHIP INFORMATION
---------------------------
This newsletter is sponsored by SecurityFocus (www.securityfocus.com)

Attention Non-profits and Universities: Sign-up now for preferred pricing
on the only global early-warning system for cyber attacks - SecurityFocus
Deepsight Analyzer.

Click here for more info
http://www.securityfocus.com/corporate/products/pdpsection.shtml

-------------------------------------------------------------------------------