SecurityFocus Linux Newsletter #90

John Boletta <[email protected]> Mon, 22 Jul 2002 11:28:32 -0600 (MDT)
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #90
----------------------------------

This newsletter is sponsored by: SecurityFocus DeepSight Threat Management
System

From June 24th - August 31st, 2002, SecurityFocus announces a FREE
two-week trial of the DeepSight Threat Management System: the only early
warning system providing customizable and comprehensive early warning of
cyber attacks and bulletproof countermeasures to prevent attacks before
they hit your network.

With the DeepSight Threat Management System, you can focus on proactively
deploying prioritized and specific patches to protect your systems from
attacks, rather than reactively searching dozens of Web sites or hundreds
of emails frantically trying to gather information on the attack and how
to recover from it.

Sign up today!
http://www.securityfocus.com/corporate/products/promo/tmstrial-lx.shtml
-------------------------------------------------------------------------------

I. FRONT AND CENTER
     1. Justifying the Expense of IDS, Part One: An Overview of ROIs...
     2. Assessing Internet Security Risk, Part Two: an Internet...
     3. The Devil And The Deep Blue Sea
     4. Crypto Controls are Spreading Internationally
     5. The Realities of Disclosure
     6. Black Hat Briefings & Training
     7. SecurityFocus DPP Program
     8. Meeting IT Security Benchmarks Through IT Audits
II. LINUX VULNERABILITY SUMMARY
     1. W3C Jigsaw Device Name Path Disclosure Vulnerability
     2. Multiple Vendor CDE ToolTalk Database Server Null Write...
     3. Multiple Vendor CDE ToolTalk Database Server Symbolic Link...
     4. Novell NetMail ModWeb Buffer Overflow Vulnerability
     5. IMHO Webmail Account Hijacking Vulnerability
     6. Novell NetMail IMAP Agent Denial Of Service Vulnerability
     7. Novell NetMail WebAdmin Buffer Overflow Vulnerability
     8. Thorsten Korner 123tkShop Arbitrary File Include Vulnerability
     9. Thorsten Korner 123tkShop SQL Injection Vulnerability
     10. Caucho Technology Resin Server Device Name Path Disclosure...
     11. Apache httpd 2.0 CGI Error Path Disclosure Vulnerability
     12. AOL Instant Messenger Unauthorized Actions Vulnerability
III. LINUX FOCUS LIST SUMMARY
     1. Announcement (Thread)
     2. Forward ftp request to another server (Thread)
     3. amanda backups and firewalling (Thread)
     4. Forward ftp request another server (Thread)
IV. NEW PRODUCTS FOR LINUX PLATFORMS
     1. SelectAccess
     2. BRU Backup and Restore Utility
     3. NetMAX Firewall
V. NEW TOOLS FOR LINUX PLATFORMS
     1. Visual Interactive Datapipe (Vida) v0.6
     2. SQL Server Password Auditing Tool v1.0.1
     3. Tiny Honeypot v0.4.3
VI. SPONSORSHIP INFORMATION


I. FRONT AND CENTER
-------------------
1. Justifying the Expense of IDS, Part One: An Overview of ROIs for IDS
By Kevin Timm

A positive return on investment (ROI) of intrusion detection systems (IDS)
is dependent upon an organization's deployment strategy and how well the
successful implementation and management of the technology helps the
organization achieve the tactical and strategic objectives it has
established. For organizations interested in quantifying the IDS's value
prior to deploying it, their investment decision will hinge on their
ability to demonstrate a positive ROI.

http://online.securityfocus.com/infocus/1608

2. Assessing Internet Security Risk, Part Two: an Internet Assessment
Methodology
by Charl van der Walt

This article is the second in a series that is designed to help readers to
assess the risk that their Internet-connected systems are exposed to. In
the first installment, we established the reasons for doing a technical
risk assessment. In this installment, we'll start discussing the
methodology that we follow in performing this kind of assessment.

http://online.securityfocus.com/infocus/1607

3. The Devil And The Deep Blue Sea
By Jon Lasser

Why Microsoft's Palladium project threatens to send Linux and open-source
into exile.

http://online.securityfocus.com/columnists/96

4. Crypto Controls are Spreading Internationally
By David Banisar

Five years ago, when the Organization for Economic Cooperation and
Development (OECD) released their guidelines for cryptography policy,
crypto advocates cheered and declared victory. After a hard fought battle,
we had forced the OECD to back away from the U.S. government's efforts to
restrict encryption worldwide. After the guidelines, countries around the
world issued crypto policies that called for the free and unfettered use
of encryption products to promote e-commerce and protect privacy.
Eventually, even the U.S. gave up anddropped most export controls. In the
last EPIC Cryptography and Privacy survey, written in 2000, there were
only a handful of nations that still restricted crypto, like Burma,
Belarus, and Russia -- countries you really didn't want to go to anyway.

http://online.securityfocus.com/columnists/95

5. The Realities of Disclosure
by Michael Morgenstern, Tom Parker

Four months ago, we published a SecurityFocus guest feature entitled It's
Time to be Responsible (March 1, 2002) calling for greater consensus in
the computer security arena on policies of vulnerability disclosure. Since
that time little positive movement has occurred, to the detriment of all
involved parties. Microsoft's consortium remains a black hole;
vulnerabilities (and exploits) continue to be released without control;
and everyone suffers - vendors and users included. Thankfully, not all
movement has been entirely negative. Unfortunately, Steve Christey and
Chris Wysopol's RFC of February 2002 was only tepidly received, despite
calling for positive and proactive measures. We surmise that no concrete
movement has occurred due mostly to the segregated computer communities
and the lack of any consensus on these matters. It is high time the
computer cognoscenti finally comes together and advocates responsible
disclosure practices.

http://online.securityfocus.com/guest/14155

6. Black Hat Briefings & Training

Attend Black Hat Briefings & Training, July 29 - August 1, Las Vegas, the
world's premier technical security event! 8 tracks, 12 training sessions,
Richard Clarke keynote, 1500 delegates from 30 nations, with a near cult
following of both CSOs and "underground" security experts.  See for
yourself what the buzz is all about.

Visit us at: http://www.blackhat.com

7. SecurityFocus DPP Program

Attention Non-profit Organizations and Universities!!
Sign-up now for preferred pricing on the only global early-warning system
for cyber attacks - SecurityFocus DeepSight Threat Management System.

Click here for more information:
http://www.securityfocus.com/corporate/products/dpsection.shtml

8. Meeting IT Security Benchmarks Through IT Audits
August 8-9, 2002, Washington, DC.
By Information Technology Research Associates
Agenda: www.frallc.com (see InfoTech Events)

Have your IT security solutions kept pace with evolving threats?  Until
you conduct a thorough IT security audit, you won't know until after a
breach has occurred. To help you achieve the most ROI on your security
investment, ITRA is proud to present a step-by-step practical guide to
auditing your enterprise's IT security. For more information, call
800-280-8440.


II. BUGTRAQ SUMMARY
-------------------
1. W3C Jigsaw Device Name Path Disclosure Vulnerability
BugTraq ID: 5251
Remote: Yes
Date Published: Jul 17 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5251
Summary:

Jigsaw is an HTTP server produced by W3C. It is implemented in Java, and
will run on a wide range of systems, including Microsoft Windows, Linux
and other Unix based systems.

A vulnerability has been reported in some versions of Jigsaw running under
Microsoft Windows. Requesting '/aux' will result in an error condition.
Requesting '/aux' a second time will result in an error page which
includes the full path of the webroot.

It may also be possible to trigger this condition by requesting other
MS-DOS devices.

Exploitation of this vulnerability may aid an attacker in gathering
information about the vulnerable system. This data may, in turn, be of
value in exploiting further vulnerabilities.

2. Multiple Vendor CDE ToolTalk Database Server Null Write Vulnerability
BugTraq ID: 5082
Remote: Yes
Date Published: Jul 11 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5082
Summary:

CDE ships with a daemon called the ToolTalk database server.  The ToolTalk
database server allows for programs designed for use in CDE to communicate
with each other. It is enabled by default on most systems shipped with
CDE.

The ToolTalk database server is vulnerable to a condition that may allow
for NULL words to be written to arbitrary locations in memory.  The
vulnerability is due to an input validation error in the _TT_ISCLOSE
procedure, used by ToolTalk clients to close open ToolTalk databases.

The _TT_ISCLOSE RPC accepts as a parameter a file descriptor.  This
integer value is used as an index for writing to structures in server
memory.  There are no checks to restrict the range of the index value.
Consequently, malicious file descriptor values supplied by remote clients
may cause writes to occur far beyond the table in memory.  The only value
written is a NULL word, limiting the consequences.

Unfortunately there are several other conditions which may allow for
complex attacks, potentially resulting in remote deletion/creation of
arbitrary files or code/command execution.

It should be noted that the only authentication required is
client-supplied AUTH_UNIX credentials. AUTH_UNIX credentials may be
trivially spoofed by attackers.

3. Multiple Vendor CDE ToolTalk Database Server Symbolic Link Vulnerability
BugTraq ID: 5083
Remote: Yes
Date Published: Jul 11 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5083
Summary:

CDE ships with a daemon called the ToolTalk database server.  The ToolTalk
database server allows for programs designed for use in CDE to communicate
with each other. It is enabled by default on most systems shipped with
CDE.

The ToolTalk database server is vulnerable to a symbolic link
vulnerability that is exploitable by attackers with access to the
filesystem.

The server logs transactions to logfiles created with predictable
filenames based on the path/name of the ToolTalk database supplied by the
client.  When writing to the logfile, the server does not check to ensure
that it is not a symbolic link.  If an attacker creates a symbolic link on
the filesystem before the log file is created by the server, transaction
data will be written to the destination file as root.

Exploitation of this vulnerability may result in a denial of service if
sensitive files are corrupted.  As client-supplied data is written to the
file, it may also be possible for this vulnerability to be exploited to
elevate privileges.

4. Novell NetMail ModWeb Buffer Overflow Vulnerability
BugTraq ID: 5230
Remote: Yes
Date Published: Jul 15 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5230
Summary:

Novell NetMail is an e-mail and calendaring system for use with Microsoft
Windows and Linux and Unix variant operating systems.

A vulnerability has been reported for Novell Netmail versions 3.1 and
3.0.3. A buffer overflow condition exists in the vulnerable versions of
the software that may allow a remote attacker to obtain root privileges.

The vulnerabilty exists in the ModWeb module of Netmail. When certain data
is received by the ModWeb module, the buffer overflow condition is
triggered. This may allow, under certain circumstances, for an attacker to
supply malicious code that may be executed by the vulnerable process.

In situations like this, it is possible for a remote attacker to obtain
root privileges.

5. IMHO Webmail Account Hijacking Vulnerability
BugTraq ID: 5238
Remote: Yes
Date Published: Jul 15 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5238
Summary:

IMHO is a webmail module for Roxen webserver.  It will run on any
operating system Roxen is compatible with, including Linux and Unix
variants as well as Microsoft Windows.

A vulnerability has been reported in the IMHO Roxen webmail module which
may enable a malicious user of the webmail system to gain access to the
account of another user.  This issue is in part due to a Roxen
configuration error which may cause potentially sensitive information to
be leaked in error pages.  In this instance, the REFERER may be leaked to
an attacker, which the attacker may use to access another webmail account.

6. Novell NetMail IMAP Agent Denial Of Service Vulnerability
BugTraq ID: 5232
Remote: Yes
Date Published: Jul 15 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5232
Summary:

Novell NetMail is an e-mail and calendaring system for use with Microsoft
Windows and Linux and Unix variant operating systems.

A vulnerability has been reported for Novell Netmail versions 3.1 and
3.0.3. The IMAP (Internet Message Access Protocol) Agent is prone to a
denial of service condition when certain malformed data is received.

When certain data is received by the IMAP Agent, the Agent may crash. This
leads to a denial of service condition. Repeated attacks against a
vulnerable system will cause the server to reboot in a Novell NetWare
environment.

A manual restart of the IMAP Agent is required for services to resume.

It has been reported that this issue is the result of a buffer overflow
condition. If that is the case, it may prove possible to exploit this
vulnerability to execute arbitrary code as the IMAP Agent process. This
possibility has not, however, been confirmed.

7. Novell NetMail WebAdmin Buffer Overflow Vulnerability
BugTraq ID: 5231
Remote: Yes
Date Published: Jul 15 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5231
Summary:

Novell NetMail is an e-mail and calendaring system for use with Microsoft
Windows and Linux and Unix variant operating systems.

A vulnerability has been reported for Novell Netmail versions 3.1 and
3.0.3. A buffer overflow condition exists in the vulnerable versions of
the software that may allow a remote attacker to obtain root privileges.

The vulnerabilty exists in the WebAdmin module of Netmail. WebAdmin is
used by administrators of Netmail to configure and change parameters
necessary for operation. When certain data is received by the WebAdmin
module, the buffer overflow condition is triggered. This may allow, under
certain circumstances, for an attacker to supply malicious code that may
be executed by the vulnerable process.

In situations like this, it is possible for a remote attacker to obtain
root privileges.

8. Thorsten Korner 123tkShop Arbitrary File Include Vulnerability
BugTraq ID: 5243
Remote: Yes
Date Published: Jul 16 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5243
Summary:

123tkShop is a a freely available, open source e-business application
written using PHP. It will run on most Linux and Unix variants, in
addition to Microsoft Windows operating systems.

A vulnerability has been reported for 123tkShop for versions prior to
0.3.1. Reportedly, an attacker may be able to read arbitrary files on the
vulnerable system with the privilege level of the 123tkShop process.

Almost all PHP files distributed with 123tkShop include other files
dynamically. Most of them are included with a statement like:
include("path/$var/file.inc.php");

If 'register_globals' is enabled in the local PHP configuration file, a
remote attacker may be able to subvert the contents of the variable
interpolated into the include statement. Through the usage of '../'
character sequences, an arbitrary file location may be specified.

If the 'magic_quotes_gcp' configuration parameter is disabled, the
attacker may additionally include a null character in this variable,
terminating the string and allow the specification of an arbitrary system
file. This file will then be disclosed to the remote user.

9. Thorsten Korner 123tkShop SQL Injection Vulnerability
BugTraq ID: 5244
Remote: Yes
Date Published: Jul 16 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5244
Summary:

123tkShop is a a freely available, open source e-business application
written using PHP. It will run on most Linux and Unix variants, in
addition to Microsoft Windows operating systems.

A vulnerability has been reported for 123tkShop. Reportedly, 123tkShop
suffers from a SQL injection vulnerability. User supplied data is used to
construct SQL statements, and special characters such as ''' and '"' are
not properly escaped. An attacker may be able to pass malicious data to
the system which modifies SQL queries.

If 'magic_quotes_gcp' is disabled in PHP configuration file, php.ini, it
is possible for an intruder to inject malicious SQL code into queries to
123tkShop.

This may be exploited by the attacker to view or modify the contents of
sensitive database files.

10. Caucho Technology Resin Server Device Name Path Disclosure Vulnerability
BugTraq ID: 5252
Remote: Yes
Date Published: Jul 17 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5252
Summary:

Resin is a XML-based application server.  It is available for Microsoft
Windows operating systems, in addition to Linux and Unix variants.

Resin discloses sensitive information when handling malformed web
requests.  When a request for certain MS-DOS device names is made, the
server will respond with an error page that contains the absolute path to
the webroot directory.

This type of sensitive information may be used in further attacks on the
host.

This issue has been reported in Resin running on Microsoft Windows
platforms.

11. Apache httpd 2.0 CGI Error Path Disclosure Vulnerability
BugTraq ID: 5256
Remote: Yes
Date Published: Jul 17 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5256
Summary:

The Apache Software Foundation httpd is a popular HTTP server available
for Linux, Unix and Microsoft Windows based systems.

A minor information disclosure vulnerability has been reported in Apache
httpd versions 2.0 to 2.0.35.  A bug in the implementation of the
ap_log_rerror() procedure, used to log server errors, may result in
disclosure of absolute path information to remote clients.  An absolute
path on the webserver may be considered sensitive information.  According
to Apache, the vulnerability can be triggered by faulty CGI scripts.

Exploitation of this vulnerability may allow for attackers to map the
filesystem of the target server.  This intelligence may allow for more
successful attacks.

Unfortunately further technical details, such as the CGI error required to
cause the condition, are not known.

12. AOL Instant Messenger Unauthorized Actions Vulnerability
BugTraq ID: 5246
Remote: Yes
Date Published: Jul 16 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5246
Summary:

AIM (AOL Instant Messenger) is an instant messenging client for Microsoft
Windows, MacOS, and other platforms.

AIM is prone to an issue which may allow maliciously crafted HTML to
perform unauthorized actions on behalf of a user of the vulnerable client.

AIM installs a handler for "aim:" URIs.  The "aim:" URIs can be used to
perform configuration changes and other actions specific to the AIM
client.  Actions that may be performed include adding entries to the buddy
list, adding a new group, etc.  Once the handler is invoked, the specified
action will be carried out without prompting or notifying the user.

The attacker may exploit this vulnerability by obscuring a "aim:" link and
enticing the victim to click on it.  More dangerously, it has been
reported that this can be exploited automatically once a victim visits a
website if the attacker uses HTTP REFRESH to reload pages as "aim:" URIs.

This issue was reported for versions of AIM running on Microsoft Windows
and MacOS.  The Linux version of the client is not affected by this
vulnerability.


III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. Announcement (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

2. Forward ftp request to another server (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected]

3. amanda backups and firewalling (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/[email protected] (added by vader.se.ilan.cogent.net)

4. Forward ftp request another server (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/1026885075.9341.19.camel@elendil


IV. NEW PRODUCTS FOR LINUX PLATFORMS
------------------------------------
1. SelectAccess
by Baltimore Technologies
Platforms: Linux, Solaris, SunOS, UNIX, Windows 2000, Windows NT
Relevant URL:
http://www.baltimoretechnologies.com/selectaccess/index.asp
Summary:

SelectAccess enables businesses to capitalize on the potential of
extranets, intranets and portals by providing web-based single sign-on for
a seamless user experience. SelectAccess greatly reduces administration
cost and complexity by providing a unified approach to defining
authorization policies and securely managing role-based access to on-line
resources.

2. BRU Backup and Restore Utility
by Enhanced Software Technologies
Platforms: Solaris
Relevant URL:
http://www.bru.com/
Summary:

BRU has been providing Backup You Can Trust[SM] to the Unix community
since 1985 and for Linux since 1994. This software is provides a backup
solution to UNIX/Linux on multiple platforms and architectures.

3. NetMAX FireWall
by Cybernet Systems
Platforms: FreeBSD, Linux, MacOS, Windows NT
Relevant URL:
http://www.netmax.com/products/index.html
Summary:

NetMAX FireWall is a firewall and a router in one integrated product. The
NetMAX FireWall includes and easily installs all necessary software in
about 15 minutes. The product includes a Linux operating system based on
the Red Hat distribution or FreeBSD, the packet firewall package, and the
routing package. All of the services are pre-configured and integrated
into the FireWall product. The point and click HTML based interface makes
running a server as easy as browsing the web.


V. NEW TOOLS FOR LINUX PLATFORMS
--------------------------------
1. Visual Interactive Datapipe (Vida) v0.6
by embyte
Relevant URL:
http://vidatapipe.sourceforge.net
Platforms: Linux, UNIX
Summary:

Visual Interactive Datapipe (Vida) is an interactive visual datapipe for
all *nix systems, which allows socket communications to be redirected over
pipes. It features an ncurses interface that allows the creation of
multiple datapipes, each supporting multiple connections. It is possible
to sniff and log traffic in various ways, hijack piped connections,
perform DNS hijacking on switched LANs, and much more.

2. SQL Server Password Auditing Tool v1.0.1
by Patrik Karlsson
Relevant URL:
http://www.cqure.net/tools10.html
Platforms: Linux, UNIX, Windows 2000, Windows 95/98, Windows NT, Windows
XP
Summary:

This tool should be used to audit the strength of Microsoft SQL Server
passwords offline. The tool can be used either in BruteForce mode or in
Dictionary attack mode. The performance on a 1 Ghz pentium (256mb) is
around 750 000 guesses/sec.

To be able to perform an audit one needs the password hashes that are
stored in the sysxlogins table int the master database. The program needs
to have them formated in a textfile accordingly (look at the included file
hashes.txt)

3. Tiny Honeypot v0.4.3
by George Bakos
Relevant URL:
http://alpinista.dyndns.org/files/thp/
Platforms: Linux, POSIX
Summary:

Tiny Honeypot (thp) is a simple honey pot program based on iptables
redirects and an xinetd listener. It listens on every TCP port not
currently in use, logging all activity and providing some feedback to the
attacker. The responders are entirely written in Perl, and provide just
enough interaction to fool most automated attack tools, as well as quite a
few humans, at least for a little while. With appropriate limits
(default), thp can reside on production hosts with negligible impact on
performance.


VI. SPONSORSHIP INFORMATION
---------------------------
This newsletter is sponsored by: SecurityFocus DeepSight Threat Management
System

From June 24th - August 31st, 2002, SecurityFocus announces a FREE
two-week trial of the DeepSight Threat Management System: the only early
warning system providing customizable and comprehensive early warning of
cyber attacks and bulletproof countermeasures to prevent attacks before
they hit your network.

With the DeepSight Threat Management System, you can focus on proactively
deploying prioritized and specific patches to protect your systems from
attacks, rather than reactively searching dozens of Web sites or hundreds
of emails frantically trying to gather information on the attack and how
to recover from it.

Sign up today!
http://www.securityfocus.com/corporate/products/promo/tmstrial-lx.shtml
-------------------------------------------------------------------------------