SecurityFocus Linux Newsletter #89

John Boletta <[email protected]> Mon, 15 Jul 2002 07:21:38 -0600 (MDT)
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #89
--------------------------------

This Issue is Sponsored by: USENIX

Attend the 11th USENIX Security Symposium & Tutorial program, August 5-9,
2002 in San Francisco.

Featuring: Keynote speakers Howard Schmidt & Whitfield Diffie, FREE vendor
exhibition, INNOVATIVE techniques, the BEST tools and the LATEST research
in OS security, Sandboxing, Hacks/Attacks, Web security, Deploying Crypto,
Access control and more.  Only three weeks left to register!

Visit us at: http://www.usenix.org/sec02/secfoc

-------------------------------------------------------------------------------

I. FRONT AND CENTER
     1. Filtering E-Mail with Postfix and Procmail, Part Three
     2. Detecting and Containing IRC-Controlled Trojans: When Fire...
     3. Life After AV: If Anti-Virus is Obsolete, What Comes Next?
     4. National Information Security: Is Clarke the Right Man For...
     5. Black Hat Briefings & Training
     6. SecurityFocus DPP Program
II. LINUX VULNERABILITY SUMMARY
     1. BEA Systems WebLogic Server and Express Race Condition Denial...
     2. Kim Storm NN NNTP Error Message Format String Vulnerability
     3. Nagios Plugin Shell Character Arbitrary Command Execution...
     4. Linux Kernel Privileged File Descriptor Resource Exhaustion...
     5. Nathaniel Bray Yeemp Arbitrary File Modification Vulnerability
     6. KMMail Code Injection Vulnerability
     8. Icecast Server Directory Traversal Information Disclosure...
     9. iPlanet Web Server Search Component File Disclosure Vulnerability
     10. Apache Tomcat Servlet Mapping Cross Site Scripting Vulnerability
     11. GoAhead WebServer URL Encoded Slash Directory Traversal...
     12. GoAhead WebServer Error Page Cross Site Scripting Vulnerability
     13. Apache Tomcat DOS Device Name Cross Site Scripting Vulnerability
III. LINUX FOCUS LIST SUMMARY
     1. Receiving constant hits from random hosts (Thread)
     2. OpenSSH 3.4 rpm spec file for redhat (Thread)
IV. NEW PRODUCTS FOR LINUX PLATFORMS
     1. Extractor
     2. AntiViral Toolkit Pro (AVP) Z.E.S. Linux
     3. Firebox II FastVPN
V. NEW TOOLS FOR LINUX PLATFORMS
     1. Gnuzza v0.4.1
     2. BBIagent Router v1.5.0
     3. Jacksum v1.0.0
     4. Shilosh OS v0.1
VI. SPONSORSHIP INFORMATION



I. FRONT AND CENTER
-------------------
1. Filtering E-Mail with Postfix and Procmail, Part Three
By Brian Hatch

This is the third installment in a four-part series on filtering e-mail
with Postfix and Procmail. The first two parts of this series focused on
how you can stop receiving spam by configuring Postfix for spam
prevention. This segment will introduce you to the methods of stopping
spam with Procmail.

http://online.securityfocus.com/infocus/1606

2. Detecting and Containing IRC-Controlled Trojans: When Firewalls, AV,
and IDS Are Not Enough
by Corey Merchant and Joe Stewart, LURHQ Corporation Secure Operations
Center

This paper discusses IRC-based trojans as a distinctly underestimated
class of malicious activity, and how real time security event monitoring
is the key to identifying and containing similar compromises. It discusses
the general methodology used to discover, track, and stop such malicious
activity by presenting a real-world case study.

http://online.securityfocus.com/infocus/1605

3. Life After AV: If Anti-Virus is Obsolete, What Comes Next?
by Paul Schmehl

In a previous article, Past Its Prime: Is Anti-Virus Scanning Obsolete?, I
discussed the reasons why I believe that anti-virus scanning as we now
know it is obsolete and must be replaced. In this article, I will address
what I believe will be its replacement - behavioral blocking - including
what is currently available, and how behavioral blocking needs to function
for it to successfully defeat malicious code.

http://online.securityfocus.com/infocus/1604

4. National Information Security: Is Clarke the Right Man For the Job?
By Richard Forno

Richard Clarke's use of apocalyptic language to describe daily security
events calls into question his qualifications to act as the President's
Special Advisor on Cyberspace security.

http://online.securityfocus.com/columnists/94

5. Black Hat Briefings & Training

Attend Black Hat Briefings & Training, July 29 - August 1, Las Vegas, the
world's premier technical security event! 8 tracks, 12 training sessions,
Richard Clarke keynote, 1500 delegates from 30 nations, with a near cult
following of both CSOs and "underground" security experts.  See for
yourself what the buzz is all about.

Visit us at: http://www.blackhat.com

6. SecurityFocus DPP Program

Attention Non-profit Organizations and Universities!!
Sign-up now for preferred pricing on the only global early-warning system
for cyber attacks - SecurityFocus DeepSight Threat Management System.

Click here for more information:
http://www.securityfocus.com/corporate/products/dpsection.shtml


II. BUGTRAQ SUMMARY
-------------------
1. BEA Systems WebLogic Server and Express Race Condition Denial of Service Vulnerability
BugTraq ID: 5159
Remote: Yes
Date Published: Jul 04 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5159
Summary:

BEA Systems WebLogic Server is an enterprise level web and wireless
application server for Microsoft Windows and most Unix and Linux
distributions.

BEA WebLogic Express provides a platform for serving dynamic data to web
and wireless applications.

BEA has confirmed that a denial of service condition exists in WebLogic
Server and Express.  This condition exists due to a race condition error
in the server code.

2. Kim Storm NN NNTP Error Message Format String Vulnerability
BugTraq ID: 5160
Remote: Yes
Date Published: Jul 04 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5160
Summary:

Kim Storm nn is a menu based NNTP (Net News Transfer Protocol) news reader
designed for use with Unix and Linux variant operating environments.

It has been reported that versions 6.6.3 and earlier of nn are vulnerable
to a remote format string vulnerability. This may be exploited by remote
attackers to potentially execute arbitrary instructions with the
privileges of the nn process.

The vulnerability is a result of nn displaying error messages on the
vulnerable system without proper checks. The vulnerability occurs in the
nn_exitmsg() function.

To exploit this issue, the attacker must control a NNTP server to respond
with specially crafted error messages. The nn news client will, without
any checks, display this message on the vulnerable system. Attackers may
potentially take advantage of this condition to overwrite arbitrary
locations in memory with attacker-supplied instructions.

3. Nagios Plugin Shell Character Arbitrary Command Execution Vulnerability
BugTraq ID: 5174
Remote: Yes
Date Published: Jul 06 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5174
Summary:

Nagios is a freely available, open source watchdog software package.  It
is designed for the Linux and Unix Operating Environments.

Nagios may allow remote execution of commands through a plugin.

Nagios uses plugins on various systems.  These plugins report data to the
main Nagios server, making it possible for Nagios to generate reports and
alert administrators to issues.

Under some circumstances, it may be possible to generate an event that
causes a plugin to send maliciously formatted data to the Nagios server.
This data may contain things such as arbitrary commands and shell
metacharacters.  Upon receiving this data, any commands contained between
the metacharacters would be executed.

This problem could make it possible to execute arbitrary commands with the
privileges of the Nagios server process.  It may additionally allow a
remote user to gain local access to the affected host.

4. Linux Kernel Privileged File Descriptor Resource Exhaustion Vulnerability
BugTraq ID: 5178
Remote: No
Date Published: Jul 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5178
Summary:

The Linux kernel is a freely available, open source kernel originally
written by Linux Torvalds. It is the core of all Linux distributions.

Recent versions of the Linux kernel include a collection of file
descriptors which are reserved for usage by processes executing as the
root user. This is a security measure, designed to prevent the subversion
of standard IO channels by malicious user processes, and to reduce the
risk of resource exhaustion problems. By default, the size of this
collection is set to 10 file descriptors.

A user may consume some root file descriptors by calling various suid
programs. Although the details will be system specific, some suid
processes are common across almost all systems, such as 'passwd'.

A malicious user may consume all non-privileged file descriptors using a
simple exploit program written to do so. The user may then exhaust the
pool of reserved, privileged file descriptors by executing a number of
suid processes. As file descriptors are a global system resource, other
users will also be unable to open new file descriptors, creating a denial
of service condition.

It may be possible to exploit this issue to subvert standard IO file
descriptors inherited by privileged processes. A similar issue within
multiple BSD kernels is detailed in BID 4568. This method of exploitation
has not, however, been confirmed as possible for this vulnerability.

This issue has been reported in the Linux Kernel version 2.4.18. It is
likely that earlier versions of the kernel share this vulnerability.

5. Nathaniel Bray Yeemp Arbitrary File Modification Vulnerability
BugTraq ID: 5180
Remote: Yes
Date Published: Jul 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5180
Summary:

Yeemp is a decentralized instant messaging system similar to AIM (AOL
Instant Messenger) and Jabber. It uses GPG over SSL for encryption of
communications. It is designed for use with Unix and Linux variant
operating environments.

A vulnerability has been reported for Yeemp 0.5 that will allow a remote
attacker to create or modify arbitrary files on the vulnerable system. The
vulnerability occurs in the yeempd service which acts as a server for
Yeemp communications. The vulnerability is a result of the improper
sanitization of user supplied input.

An attacker may take advantage of this vulnerability to cause the yeempd
service to create or otherwise modify files with the permissions of the
user running the service.

It may be possible to exploit this vulnerability to create a denial of
service condition by corrupting sensitive system configuration files or
binaries. It may additionally be possible to gain elevated privileges on
the system by, for example, appending attacker specified data to
/etc/passwd, or by trojaning additional system binaries.

6. KMMail Code Injection Vulnerability
BugTraq ID: 5173
Remote: Yes
Date Published: Jul 06 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5173
Summary:

kmMail is a freely available, open source web-based mail software package
written with PHP.  It is available for the Unix, Linux, and Microsoft
Operating Environments.

Problems with kmMail could make it possible to execute arbitrary script
code in a vulnerable client.

kmMail does not sufficiently filter javascript from mails.  As a result,
when a user opens a mail in kmMail that contains javascript, the code
contained in the mail would be executed in the browser of the mail user.
Additionally, HTML included in the Subject: field is not filtered, and
could be rendered in the browser.

This could allow an attacker to send malicious javascript or HTML to an
unsuspecting user of kmMail, which would be executed in the security
context of the site hosting kmMail.

7. NcFTP Client PORT Allowed With Proxy Server Weakness
BugTraq ID: 5183
Remote: Yes
Date Published: Jul 06 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5183
Summary:

NcFTP is an FTP client. NcFTP is available for Linux, a wide range of Unix
based systems, Mac OS X and Microsoft Windows.

The NcFTP client may be vulnerable to an issue involving the usage of an
FTP proxy. By default, usage of the FTP PORT command is permitted when the
client is using an FTP proxy server.

This may allow an external, malicious server to hijack the connection by
connecting to the client system before the legitimate FTP server does. At
this point, it may be possible to access sensitive data by accepting a
file transfer, or inject malicious data into the client system.

In order to exploit this vulnerability, the remote attacker would require
information on the port specified by the server. This may be possible if
the attacker can sniff network connections, or if the attacker can make
guesses based on previously detected information.

8. Icecast Server Directory Traversal Information Disclosure Vulnerability
BugTraq ID: 5189
Remote: Yes
Date Published: Jul 09 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5189
Summary:

Icecast is a freely available, open source streaming audio server. Icecast
is available for the Unix, Linux, and Microsoft Windows platforms.

A directory traversal issue has been reported in some versions of Icecast
server. It may be possible for a remote attacker to escape the web root
and determine if a specific directory exists on the vulnerable server.

Reportedly, issuing an HTTP GET request for
"/file/../../../../../../../../directory/" will return different results
if the specified directory exists on the server filesystem. A '404 Not
Found' response is received for a nonexistant directory, and an empty '200
OK' reponse indicates the specified directory exists.

An attacker may exploit this vulnerability to gather intelligence about
the vulnerable system.

This issue may be related to a more severe directory traversal issue in
earlier versions of Icecast, documented as BID 2932.

9. iPlanet Web Server Search Component File Disclosure Vulnerability
BugTraq ID: 5191
Remote: Yes
Date Published: Jul 09 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5191
Summary:

iPlanet Webserver is a HTTP server product offered by Sun Microsystems.

iPlanet Web Server ships with a search engine component.  The iPlanet Web
Server search engine is prone to a file disclosure vulnerability.

The search engine component allows for a search query pattern file to be
defined.  However, the search engine has a command which will allow remote
users to supply a user-defined search query pattern file.  This
functionality is provided by the 'NS-query-pat' command.  It is possible
for remote attackers to exploit this functionality to request another file
in place of the search query pattern file.  A remote attacker can exploit
this condition by providing a relative path, using directory traversal
sequences, to an arbitrary file via the command.  If the server has
sufficient permissions to read the arbitrary file, then it will be
disclosed to the attacker.

This issue was reported for iPlanet Web Server on Microsoft Windows
operating systems.  Since the server typically runs in the SYSTEM context
on these operating systems, it may be possible for an attacker to disclose
the contents of arbitrary files.  It has not been confirmed whether this
vulnerability exists on other platforms that the software is compatible
with.  The search engine functionality does not appear to be available for
versions of the software on Linux platforms.

Netscape Enterprise Server 3.6 is also affected by this issue.

10. Apache Tomcat Servlet Mapping Cross Site Scripting Vulnerability
BugTraq ID: 5193
Remote: Yes
Date Published: Jul 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5193
Summary:

Apache Tomcat is a freely available, open source web server maintained by
the Apache Foundation. It is available for use on Unix and Linux variants
as well as Microsoft Windows operating environments.

A vulnerability has been reported for Apache Tomcat 4.0.3 on Microsoft
Windows and Linux platforms. Reportedly, it is possible for an attacker to
launch a cross site scripting attack.

When servlet mapping is enabled, it is possible to invoke various servlets
and cause Apache Tomcat to throw an exception. This will make cross site
scripting attacks possible.

The 'invoker' servlet is mapped to '/servlet/'. This mapping allows for
the execution of anonymous servlet classes that have not been defined in
the file, /tomcat-install-dir/conf/web.xml.

This may enable a remote attacker to steal cookie-based authentication
credentials from legitimate users of a host running Tomcat.

11. GoAhead WebServer URL Encoded Slash Directory Traversal Vulnerability
BugTraq ID: 5197
Remote: Yes
Date Published: Jul 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5197
Summary:

GoAhead WebServer is an Open Source embedded web server which supports
Active Server Pages, embedded javascript, and SSL authentication and
encryption. It is available for a variety of platforms including Microsoft
Windows and Linux variant operating systems.

A vulnerability has been reported for GoAhead WebServer 2.1. Reportedly,
it is possible to launch directory traversal attacks against GoAhead
WebServer. It is possible for remote attackers to access arbitrary files
residing on a vulnerable host.

It has been reported that it is possible to exploit this vulnerability to
access arbitrary files on the server through a directory traversal attack.
GoAhead WebServer correctly prevents attackers from using '../' sequences
for directory traversal attacks. However, it does not prevent attackers
from using URL encoded substitutions for the '/' character. Thus, an
attacker can make a request containing the URL encoded version of the '/'
character as follows:
http://target/..%5C..%5C..%5C..%5C..%5C..%5C/winnt/win.ini, where '%5C' is
the URL version of the '/' character.

Successful exploitation of this vulnerability could reveal sensitive data
which may be used to assist in further attacks against the host.

This vulnerabilty was reported for version 2.1 of GoAhead WebServer. It is
not known whether other versions are affected.

12. GoAhead WebServer Error Page Cross Site Scripting Vulnerability
BugTraq ID: 5198
Remote: Yes
Date Published: Jul 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5198
Summary:

GoAhead WebServer is an Open Source embedded web server which supports
Active Server Pages, embedded javascript, and SSL authentication and
encryption. It is available for a variety of platforms including Microsoft
Windows and Linux variant operating systems.

A vulnerability has been reported for GoAhead WebServer 2.1. Reportedly,
it is possible for attackers to launch cross site scripting attacks
against vulnerable systems.

GoAhead WebServer includes unsanitized requested URLs when displaying a
404 error page. An attacker may be able to trick a user into following a
link which includes malicious script code, and executing the attack.

Included script code will execute within the context of the hosted site.
This may enable a remote attacker to steal cookie-based authentication
credentials from legitimate users of a host running GoAhead WebServer.

This vulnerabilty was reported for version 2.1 of GoAhead WebServer. It is
not known whether other versions are affected.

13. Apache Tomcat DOS Device Name Cross Site Scripting Vulnerability
BugTraq ID: 5194
Remote: Yes
Date Published: Jul 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5194
Summary:

Apache Tomcat is a freely available, open source web server maintained by
the Apache Foundation. It is available for use on Unix and Linux variants
as well as Microsoft Windows operating environments.

A vulnerability has been reported for Apache Tomcat 4.0.3 on a Microsoft
Windows platform. Reportedly, it is possible for an attacker to launch a
cross site scripting attack.

When making a request for a DOS device file name, Tomcat will throw an
exception and respond with an error message. It is also possible for
information to be appended to the DOS device when making a request. An
example of this is as follows: tomcat-server/COM2.IMG%20src=
"Javascript:alert(document.domain)"

This may enable a remote attacker to steal cookie-based authentication
credentials from legitimate users of a host running Tomcat.

This vulnerability is related to BugTraq ID 5054, Apache Tomcat Web Root
Path Disclosure Vulnerability.


III. LINUX FOCUS LIST SUMMARY
-----------------------------
1. Receiving constant hits from random hosts (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

2. OpenSSH 3.4 rpm spec file for redhat (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]


IV. NEW PRODUCTS FOR LINUX PLATFORMS
-----------------------------------
1. Extractor
by WetStone Technologies
Platforms: Linux
Relevant URL:
http://www.wetstonetech.com/extractor.html
Summary:

WetStone Technologies, SM&A, the Computer Forensics Research and
Development Center (CFRDC), and the New York State Police Forensic
Investigation Center (NYSPFIC) have developed the Extractor, a Linux
RedHat® deleted file recovery tool. The technology can assist law
enforcement, government and commercial organizations in retrieving
maliciously or accidentally deleted files within the increasingly poplular
Linux operating system

2. AntiViral Toolkit Pro (AVP) Z.E.S. Linux
by Kaspersky Labs
Platforms: Linux
Relevant URL:
http://www.kasperskylabs.com/
Summary:

AntiViral Toolkit Pro (AVP) Z.E.S. Linux is a distributive package
containing Linux-based bootable rescue diskette with pre-installed
anti-virus software - AVP for Linux. It is a unique tool, which allows
fast and efficient restoring of booting ability of a computer affected by
a virus attack. It also makes possible to actively neutralise computer
viruses invisible for many anti-virus products on infected systems.

3. Firebox II FastVPN
by WatchGuard Technologies
Platforms: Linux
Relevant URL:
http://www.watchguard.com/products/fireboxIIfastvpn.asp
Summary:

The Firebox II FastVPN is the most powerful WatchGuard Firebox and
includes a custom encryption accelerator card for supporting intensive
3DES VPN encryption applications. Equipped with a security-hardened Linux
operating system, the reliable Firebox II FastVPN is dedicated to the
specialized task of Internet security. Solid state architecture removes
the risk of hard drive failure and disk crashes, and dual-image flash
memory enables fall-back to the previously transmitted policy. Three
independent network interfaces allow you to separate your protected office
network from the Internet while providing an optional public network for
hosting Web, e-mail or FTP servers. Each network interface is
independently monitored and visually displayed on the front of the Firebox
II. In addition to LEDs showing connectivity and Armed/Disarmed status,
Firebox II's also display three LEDs: TrafficMeter, LoadMeter and
ThroughputMeter. The triangular TrafficMeter displays LEDs for the
trusted, external and optional interfaces (green bars show the direction
of allowed traffic, red bars indicate denied traffic). The LoadMeter LEDs
display the load average of each Firebox II, up to 100Mb. Lastly, Sys
A/Sys B LEDs indicate whether your Firebox II is running your defined
security policy or if it is in configuration mode.


V. NEW TOOLS FOR LINUX PLATFORMS
--------------------------------
1. Gnuzza v0.4.1
by Timo Schulz [email protected]
Relevant URL:
http://www.winpt.org/cryptchat
Platforms: Linux, Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:

Gnuzza is a peer to peer (p2p) encrypted chat client for both Windows and
Linux. It features Diffie Hellman key exchange (selectable from 1024 to
4096 bit), user authentication, and offers the choice of 3DES, Blowfish,
Twofish, CAST5, and Rijndael as symmetric ciphers.

2. BBIagent Router v1.5.0
by BBIagent.Net
Relevant URL:
http://www.BBIagent.Net
Platforms: Linux
Summary:

BBIagent is a single floppy Linux-based router for sharing a broadband
Internet connection. It also serves as a firewall to prohibit intruders
from accessing your LAN. You can create your own BBIagent router software
(a diskette file image) on our server based on your hardware configuration
(NICs) and connection protocol (e.g. PPPoE, PPPoATM or DHCP). It is very
easy to install and use.

3. Jacksum v1.0.0
by jonelo
Relevant URL:
http://www.jonelo.de/java/jacksum/index.html
Platforms: Linux, MacOS, Os Independent, OS/2, POSIX, Solaris, SunOS,
UNIX, Windows 2000, Windows 95/98, Windows NT
Summary:

Jacksum is a free checksum utility entirely written in Java. It supports
most common checksum algorithms (Adler32, BSD sum, POSIX cksum, CRC-16,
CRC-32, MD2, MD5, SHA, and Unix System V sum).

4. Shilosh OS v0.1
by Stefan Ilivanov
Relevant URL:
http://sourceforge.net/projects/trinityos/
Platforms: Linux, POSIX, Windows 2000, Windows 95/98
Summary:

Shilosh OS provides a secure and stable operating system based on a highly
modified Linux kernel, with its own package system similar to BSD's
"ports". Compatible with x86 and Power PC, it is also 99% compatible with
Windows 9x. It is easy to use and includes complete documentation in many
languages.


VI. SPONSORSHIP INFORMATION
---------------------------
This Issue is Sponsored by: USENIX

Attend the 11th USENIX Security Symposium & Tutorial program, August 5-9,
2002 in San Francisco.

Featuring: Keynote speakers Howard Schmidt & Whitfield Diffie, FREE vendor
exhibition, INNOVATIVE techniques, the BEST tools and the LATEST research
in OS security, Sandboxing, Hacks/Attacks, Web security, Deploying Crypto,
Access control and more.  Only three weeks left to register!

Visit us at: http://www.usenix.org/sec02/secfoc

-------------------------------------------------------------------------------