SecurityFocus Linux Newsletter #96

John Boletta <[email protected]> Mon, 9 Sep 2002 13:39:17 -0600 (MDT)
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>

SecurityFocus Linux Newsletter #96
----------------------------------

This Issue Is Sponsored By: SpiDynamics

Aberdeen Alert! FREE Research Report on Web App Attacks Using ports 80 and
443 as expressways through network firewalls, hackers are free to probe
and breach web applications! 75% of today’s successful system hacks
involve Web Application vulnerabilities, not network security flaws.

Download this FREE Aberdeen Research Report!

http://www.spidynamics.com/mktg/aberdeen21/
-------------------------------------------------------------------------------

I. FRONT AND CENTER
     1. Configuring IPSec and Ike on Solaris, Part Two
     2. Justifying the Expense of IDS, Part Two: Calculating ROI for IDS
     3. Lobbying for Insecurity
     4. When Feds are the Crackers
     5. SecurityFocus DPP Program
     6. InforwarCon 2002
II. LINUX VULNERABILITY SUMMARY
     1. Abyss Web Server Administrative Console Unauthorized Access...
     2. Abyss Web Server Malicious HTTP Request Information Disclosure...
     3. PHPReactor Style Attribute HTML Injection Vulnerability
     4. Abyss Web Server Encoded Backslash Directory Traversal...
     5. Light Channel Name Arbitrary Command Execution Vulnerability
     6. Blazix Special Character Handling Server Side Script...
     7. Blazix Password Protected Directory Information Disclosure...
     8. Gaim Manual Browser Command Arbitrary Command Execution...
     9. Ultimate PHP Board Second 'admin' Account Vulnerability
     10. Linuxconf Local Buffer Overflow Vulnerability
     11. GDAM123 Filename Buffer Overflow Vulnerability
III. LINUX FOCUS LIST SUMMARY
     1. MD5 checksum's for Redhat 7.3 binaries? (Thread)
     2. Who: No users logged (Thread)
     3. Who: No users logged [Solved] (Thread)
IV. NEW PRODUCTS FOR LINUX PLATFORMS
     1. InsideOut Firewall Reporter
     2. PakSecured VPN Server
     3. Phoenix Adaptive Firewall
V. NEW TOOLS FOR LINUX PLATFORMS
     1. checkpassword-ldap v0.1
     2. Prelude Manager v0.8.3
     3. Prelude Log Monitoring Lackey v 0.8.1
VI. SPONSORSHIP INFORMATION




I. FRONT AND CENTER
-------------------
1. Configuring IPSec and Ike on Solaris, Part Two
By Ido Dubrawsky

This article is the second in a three-part series devoted to configuring
IPsec and IKE for Solaris. The first installment of this series covered
the underlying IPsec protocols as well as how the Internet Key Exchange
(IKE) works. This installment covers configuring IPsec to protect the
traffic between two Solaris hosts.

http://online.securityfocus.com/infocus/1625

2. Justifying the Expense of IDS, Part Two: Calculating ROI for IDS
by David Kinn and Kevin Timm

This article is the second of a two-part series exploring ways to justify
the financial investment in IDS protection. In part one of this series we
discussed general IDS types and expanded on the impact that the logical
location of a company's critical networked assets could have on the risk
equations. To this end we introduced the Cascading Threat Multiplier (CTM)
to expand on the Single Loss Expectancy (SLE) equation. We also reviewed
implementation and management costs based on various support profiles and
reviewed the commonly accepted risk equations. Finally, we left off with
the basic formula for calculating ROI for security, otherwise commonly
known as Return on Security Investment (ROSI).

http://online.securityfocus.com/infocus/1621

3. Lobbying for Insecurity
By Jon Lasser

The NSA's Linux security project was so good it almost made up for that
whole Echelon thing. Then politics entered the picture.

http://online.securityfocus.com/columnists/106

4. When Feds are the Crackers
By Mark Rasch

In medieval times, attackers would use a bell-shaped metal grenade or
"petard" to break enemy defenses. These unreliable devices frequently went
off unexpectedly, destroying not only the enemy, but the attacker. As
Shakespeare noted, "'tis the sport to have the enginer Hoist with his owne
petar."

http://online.securityfocus.com/columnists/105

5. SecurityFocus DPP Program

Attention Non-profit Organizations and Universities!! Sign-up now for
preferred pricing on the only global early-warning system for cyber
attacks - SecurityFocus DeepSight Threat Management System.

Click here for more information:
http://www.securityfocus.com/corporate/products/dpsection.shtml

6. InforwarCon 2002

InforwarCon 2002: Homeland Defense and Cyber-Terrorism, Washington, DC
September 4-5, 2002, optional workshops September 3 & 6. Presented by MIS
Training Institute and Interpact, Inc. Proven strategies for protecting
against threats to critical infrastructures and government systems.

Visit us at:
http://www.misti.com/08/iw02nl26inf.html


II. BUGTRAQ SUMMARY
-------------------
1. Abyss Web Server Administrative Console Unauthorized Access Vulnerability
BugTraq ID: 5548
Remote: Yes
Date Published: Aug 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5548
Summary:

Abyss Web Server is a freely available personal web server. It is
maintained by Aprelium Technologies and runs on Microsoft Windows
operating systems, as well as Linux.

A vulnerability has been reported for Abyss Web Server for both the Linux
and Microsoft Windows operating environments. Reportedly, it is possible
for an attacker to obtain access to Abyss Web Server's administrative
console without any need for authentication.

An attacker can exploit this vulnerability to change any, and all,
configuration parameters of Abyss Web Server, including the administrative
password. It will also enable the remote attacker to stop and restart the
Web server.

2. Abyss Web Server Malicious HTTP Request Information Disclosure Vulnerability
BugTraq ID: 5549
Remote: Yes
Date Published: Aug 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5549
Summary:

Abyss Web Server is a freely available personal web server. It is
maintained by Aprelium Technologies and runs on Microsoft Windows
operating systems, as well as Linux.

Reportedly, it is possible for attackers to obtain the contents of files
by appending a special character to HTTP requests to Abyss Web Server.

An attacker can exploit this vulnerability to obtain access to contents of
potentially sensitive files. Reportedly, by appending the '+' character,
Abyss Web Server will disclose the contents of some files to remote
attackers.

It has been reported possible to exploit this vulnerability to view the
contents of '.chl' files used for remote administration of the server. It
may be possible to view the contents of other executable files intended to
serve CGI requests. This has not, however, been confirmed.

This vulnerability has been reported for Abyss Web Server 1.0.3. It is not
known whether other versions are affected.

3. PHPReactor Style Attribute HTML Injection Vulnerability
BugTraq ID: 5569
Remote: Yes
Date Published: Aug 24 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5569
Summary:

php(Reactor) is an integrated system of web applications designed for
website maintenance. It will run on most Linux and Unix variants, in
addition to Microsoft Windows operating systems.

php(Reactor) does not sufficiently sanitize HTML from various fields (such
as in the body of a message or in profile fields).  It is possible to
inject arbitrary HTML and script code into these fields.  In particular,
the "STYLE" attribute in an arbitrary HTML tag is not properly sanitized.
Arbitrary HTML and script code injected in this manner will be displayed
to other users who visit the vulnerable website.

An attacker may potentially exploit this situation to cause arbitrary HTML
and script code to execute in the web client of a user of a vulnerable
website.  The attacker-supplied code will execute in the context of the
vulnerable website.

4. Abyss Web Server Encoded Backslash Directory Traversal Vulnerability
BugTraq ID: 5547
Remote: Yes
Date Published: Aug 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5547
Summary:

Abyss Web Server is a freely available personal web server. It is
maintained by Aprelium Technologies and runs on Microsoft Windows
operating systems, as well as Linux.

A directory traversal vulnerability has been reported for Abyss Web
Server. The issue is related to the failure to properly process the
backslash '\', encoded as '%5c', character, which may be used as a
directory delimiter under these platforms. By using the URL encoded
sequence '%2e%2e%5c', the web root may be escaped.

Exploitation can result in arbitrary system files being sent to a remote
attacker. This information may be of value in attempting further attacks
against the vulnerable system.

The directory traversal vulnerability was reported for Abyss Web Server
for both the Microsoft Windows and Linux operating environment. In a Linux
environment, it is only possible to escape immediately out of the web root
directory and into the Abyss folder; it is not possible for an attacker to
view files residing outside of the Abyss installation folder. However, in
a Windows environment the attacker is able to traverse outside of the
webroot and into all areas of the filesystem.

5. Light Channel Name Arbitrary Command Execution Vulnerability
BugTraq ID: 5555
Remote: Yes
Date Published: Aug 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5555
Summary:

Light is a freely available, open source IRC script for the EPIC IRC
client.  It is available for Unix, Linux, and Windows platforms.

Light contains a vulnerability which may allow the execution of arbitrary
code.

It has been discovered that Light does not properly handle some channel
names.  A channel containing embedded code in the channel name would, when
joined by a user of Light, result in the execution of the code in the
channel name.  This could allow an attacker to gain access to a system in
the security context of the Light user.

6. Blazix Special Character Handling Server Side Script Information Disclosure Vulnerability
BugTraq ID: 5566
Remote: Yes
Date Published: Aug 24 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5566
Summary:

Blazix is a freely available, open source web server written in Java.  It
is available for Linux and Microsoft Windows operating systems.

A problem with Blazix may make it possible for a remote user to gain
access to sensitive information.

Blazix does not properly handle some special characters when appended to
requests.  By passing a special character with a request to the web
server, it is possible for a user to gain access to the source of
server-side scripts.  This could result in information disclosure, and
could potentially be used to gain intelligence in launching an attack
against a system.

When a user passes a request to the web server that ends in either a plus
(+) or backslash (\), the web server may react unpredictably.  This type
of character appended to the name of a .jsp file has been reported to
reveal the contents of the .jsp file.

7. Blazix Password Protected Directory Information Disclosure Vulnerability
BugTraq ID: 5567
Remote: Yes
Date Published: Aug 25 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5567
Summary:

Blazix is a freely available, open source web server written in Java.  It
is available for Linux and Microsoft Windows operating systems.

A problem with Blazix may make it possible for a remote user to gain
access to sensitive information.

Blazix does not properly handle some special characters when appended to
requests.  By passing a special character with a request to the web
server, it is possible for a user to gain access to a listing of a
password protected directory.  This could result in information
disclosure, and could potentially be used to gain intelligence in
launching an attack against a system.

When a user passes a request to the web server that ends in either a plus
(+) or backslash (\), the web server may react unpredictably.  This type
of character appended to the name of a password-protected directory has
been reported to reveal the contents of the directory.

8. Gaim Manual Browser Command Arbitrary Command Execution Vulnerability
BugTraq ID: 5574
Remote: Yes
Date Published: Aug 27 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5574
Summary:

Gaim is an instant messaging client that supports numerous protocols. It
is available for Unix and Linux variant operating systems.

Gaim allows the user to define a 'Manual' browser option. When URL links
are recieved in instant messages, the user is able to click on the link in
order to pass the URL to a specified application.

The URL recieved is not properly sanitized. A malicious instant message
may include a URL with shell metacharacters, such as ';' or '|'. When
passed to the shell command intended to invoke the browser, this
characters will allow additional commands appended to the URL to be
executed.

Commands supplied will execute with the privileges of the user running
Gaim. It is likely that exploitation of this vulnerability could result in
the attacker gaining local access to the vulnerable system.

9. Ultimate PHP Board Second 'admin' Account Vulnerability
BugTraq ID: 5580
Remote: Yes
Date Published: Aug 27 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5580
Summary:

Ultimate PHP Board is a freely available, open source PHP bulletin board.
It is available for Unix, Linux, and Microsoft Operating Systems.

Ultimate PHP Board does not prevent the registration of names that could
be potentially confusing to users.

Under some circumstances, it may be possible to register an account that
could be confused with the 'Admin' user of the board.  Ultimate PHP Board
does not prevent the registration of the 'admin' account.  While the
'admin' account is a regular board member account, and the 'Admin' account
is that of the board administrator, it may be possible for a user to use
the account in a social engineering scenario to impersonate the
administrative user.

10. Linuxconf Local Buffer Overflow Vulnerability
BugTraq ID: 5585
Remote: No
Date Published: Aug 28 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5585
Summary:

Linuxconf is a Linux configuration utility from Solucorp. It is typically
installed as a setuid root utility for the management and configuration of
Linux operating systems.

A buffer overflow vulnerability has been reported for Linuxconf. The
vulnerability is due to bounds checking of the LINUXCONF_LANG environment
variable. An attacker who sets the LINUXCONF_LANG environment variable
with an overly large string will be able to cause the buffer overflow
condition.

An attacker can exploit this vulnerability by setting the LINUXCONF_LANG
variable to a value consisting of 964, or greater, characters and
executing /bin/linuxconf.

This will cause linuxconf to improperly allocate space on the system
stack. Thus, it is believed that an attacker could potentially exploit
this condition to overwrite stack variables with malicious
attacker-supplied values. It is highly possible that exploitation could
result in execution of malicious attacker-supplied code as the linuxconf
process.

In typical installations, linuxconf is a setuid root utility. A local
attacker, upon successful exploitation, is able to cause the server to
execute malicious code with root privileges.

11. GDAM123 Filename Buffer Overflow Vulnerability
BugTraq ID: 5578
Remote: No
Date Published: Aug 24 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5578
Summary:

GDAM123 is a command-line MP3 player supplied with GDAM real-time digital
DJ mixing software package.  GDAM is available for Unix and Linux
variants.

The GDAM123 player is prone to a buffer overflow condition when handling
overly long filenames.  Filenames are supplied via the command line and
used in a strcpy() operation.  It is possible to trigger the overflow by
supplying a filename that is over 1024 bytes in length, which will result
in corruption of stack variables.  If stack variables (such as the return
address) can be corrupted with attacker-supplied values, it is possible to
execute arbitrary code.

Under some circumstances, the player may be installed setuid root to allow
unprivileged users to run the player if access to certain devices is
required.  In a situation such as this, the buffer overflow may be
exploited to gain elevated privileges via the execution of arbitrary code.


III. LINUX FOCUS LIST SUMMARY
----------------------------
1. MD5 checksum's for Redhat 7.3 binaries? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/289802

2. Who: No users logged (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/289682

3. Who: No users logged [Solved] (Thread)
Relevant URL:

http://online.securityfocus.com/archive/91/289422

IV. NEW PRODUCTS FOR LINUX PLATFORMS
------------------------------------
1. InsideOut Firewall Reporter
by Stonylake Solutions
Platforms: Linux, Windows 2000, Windows 95/98, Windows NT
Relevant URL:
http://www.stonylakesolutions.com/insideout.asp
Summary:

InsideOut Firewall Reporter is an easy to use, powerful, real time,
browser based reporting application for firewall logs. It provides over
150 useful reports. Windows and Linux versions available. Visit the site
for a live demo.

2. PakSecured VPN Server
by Paktronix Systems
Platforms: N/A
Relevant URL:
http://www.paktronix.com/products/vpn.php
Summary:

The most popular enhancement option for the PakSecured Firewall is our
IPSec VPN. The PakSecured VPN connects any two or more networks together
across the Internet using full IPSec encryption technology. Topologies
range from point-to-point through partial-mesh and full-mesh all the way
to fully geared mesh networks with redundant stems. Policy Routing
structures within the Linux kernel enable advanced routing and selection
mechanisms for providing different VPN mesh structures thus maximizing
expensive bandwidth and providing automatic failover and priority routing.

3. Phoenix Adaptive Firewall
by Progressive Systems
Platforms: Linux, Propietary Hardware
Relevant URL:
http://www.progressive-systems.com/products/phoenix/
Summary:

The Phoenix Adaptive Firewall is a MLSI-based firewall available for Linux
distributions and as a stand alone appliance. Free software evaluations
and GUI demo available on-line.


V. NEW TOOLS FOR LINUX PLATFORMS
--------------------------------
1. checkpassword-ldap v0.1
by Dan Melomedman [email protected]
Relevant URL:
http://foobarco.net/checkpwd.html
Platforms: FreeBSD, Linux, NetBSD, OpenBSD, UNIX
Summary:

checkpassword-ldap searches a specified LDAP directory with a constructed
LDAP filter from a given prefix, username, and suffix, and fetches an
entry. It then compares a given password with the stored password, and
proceeds to run a program as specified if passwords match.

2. Prelude Manager v0.8.3
by yoann
Relevant URL:
http://www.prelude-ids.org/
Platforms: POSIX
Summary:

Prelude Manager is the main program of the Prelude Hybrid IDS suite. It is
a multithreaded server which handles connections from the Prelude sensors.
It is able to register local or remote sensors, let the operator configure
them remotely, receive alerts, and store alerts in a database or any
format supported by reporting plugins, thus providing centralized logging
and analysis. It also provides relaying capabilities for failover and
replication. The IDMEF standard is used for alert representation. Support
for filtering plugins allows you to hook in different places in the
Manager to define custom criteria for alert relaying and logging.

3. Prelude Log Monitoring Lackey v 0.8.1
by yoann
Relevant URL:
http://www.prelude-ids.org/
Platforms: POSIX
Summary:

The Prelude Log Monitoring Lackey (LML) is the host-based sensor program
part of the Prelude Hybrid IDS suite. It can act as a centralized log
collector for local or remote systems, or as a simple log analyzer (such
as swatch). It can run as a network server listening on a syslog port or
analyze log files. It supports logfiles in the BSD syslog format and is
able to analyze any logfile by using the PCRE library. It can apply
logfile-specific analysis through plugins such as PAX. It can send an
alert to the Prelude Manager when a suspicious log entry is detected.


VI. SPONSORSHIP INFORMATION
---------------------------
This Issue Is Sponsored By: SpiDynamics

Aberdeen Alert! FREE Research Report on Web App Attacks Using ports 80 and
443 as expressways through network firewalls, hackers are free to probe
and breach web applications! 75% of today’s successful system hacks
involve Web Application vulnerabilities, not network security flaws.

Download this FREE Aberdeen Research Report!

http://www.spidynamics.com/mktg/aberdeen21/
-------------------------------------------------------------------------------