SecurityFocus Linux Newsletter #155
John Boletta <[email protected]> Mon, 27 Oct 2003 13:58:22 -0700 (MST)
| Newsgroups | gmane.comp.security.news.linux |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Linux Newsletter #155
------------------------------------
This Issue Sponsored by: RSA Conference 2004
Network with over 10,000 of the brightest minds in information security at
the largest, most highly-anticipated industry event of the year. Don't
miss RSA Conference 2004! Choose from over 200 class sessions and see
demos from more than 250 industry vendors. If your job touches security,
you need to be here. Learn more or register at:
http://www.securityfocus.com/sponsor/RSA_linux-secnews_031027
and use priority code SF4.
------------------------------------------------------------------------
I. FRONT AND CENTER
1. Fighting Internet Worms With Honeypots
2. Web Security Appliance With Apache and mod_security
3. Joe Average User Is In Trouble
II. LINUX VULNERABILITY SUMMARY
1. Eric S. Raymond Fetchmail Unspecified Denial of Service Vuln...
2. Oracle Database Server Oracle Binary Local Buffer Overflow V...
3. Oracle Database Server OracleO Binary Local Buffer Overflow ...
4. Multiple GDM Local Denial Of Service Vulnerabilities
5. Geeklog Forgot Password SQL Injection Vulnerability
6. CPCommerce Functions Remote File Include Vulnerability
7. Opera HREF Malformed Server Name Heap Corruption Vulnerabili...
8. Emule Web Control Panel HTTP Login Long Password Denial of S...
9. DeskPro Multiple SQL Injection Vulnerabilities
10. DansGuardian Denied URL Cross-Site Scripting Vulnerability
11. Sylpheed-Claws Mail Client SMTP Error Reporting Format Strin...
12. Sun Java Virtual Machine Slash Path Security Model Circumven...
III. LINUX FOCUS LIST SUMMARY
1. NFS replacements for Linux (Thread)
2. AntiVirus for Red Hat 9? (Thread)
3. Fw: AntiVirus for Red Hat 9? (Thread)
4. New Articles on SecurityFocus (Thread)
5. Synflooding a Linux (Thread)
6. New SecurityFocus Article (Thread)
7. [despammed] Synflooding a Linux (Thread)
IV. NEW PRODUCTS FOR LINUX PLATFORMS
1. Sophos Anti-Virus
2. Gordano Messaging Suite
3. LANDesk Management Suite 7
4. ActiveScout Enterprise
5. Immunity CANVAS
6. SecretAgent
V. NEW TOOLS FOR LINUX PLATFORMS
1. AntiSpam Mail Filter v1.2
2. Astaro Security Linux (Stable 4.x) v4.016
3. libstatgrab v0.7
4. Anti-Spam SMTP Proxy v1.0.6
5. Pixilate v0.4
6. PinePGP 0.18.0
VI. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. Fighting Internet Worms With Honeypots
By Laurent Oudot
This paper will evaluate the usefulness of using honeypots to fight
Internet worms, including a discussion on capturing a worm, redirecting
worm traffic to fake services, launching counter attacks to clean infected
hosts, and finally removing the worm or negating its effects.
http://www.securityfocus.com/infocus/1740
2. Web Security Appliance With Apache and mod_security
By Ivan Ristic
This article will demonstrate how you can build your own application
gateway with little effort, using open source components that are widely
available.
http://www.securityfocus.com/infocus/1739
3. Joe Average User Is In Trouble
By Scott Granneman
As security professionals we're at the forefront, like it or not, and it's
up to us to help lessen the myriad of user problems we see around us.
http://www.securityfocus.com/columnists/193
II. LINUX VULNERABILITY SUMMARY
-------------------------------
1. Eric S. Raymond Fetchmail Unspecified Denial of Service Vuln...
BugTraq ID: 8843
Remote: Yes
Date Published: Oct 16 2003
Relevant URL: http://www.securityfocus.com/bid/8843
Summary:
Fetchmail is a freely available, open source mail retrieval utility. It is
maintained by Eric S. Raymond.
A vulnerability has been reported to be present in the software that may
allow an attacker to cause a denial of service condition in Fetchmail
6.2.4. It has been reported that the problem presents itself when a
specially crafted e-mail message is sent to fetchmail. The precise nature
of this vulnerability is not known at the moment due to a lack of details,
however exploitation of this issue may allow an attacker to cause the
software to crash. Although unconfirmed, it may be possible to execute
arbitrary code on a vulnerable system.
This vulnerability may be related to known issues, however this has not
been confirmed by Symantec. This BID and any other applicable BIDs will be
updated, as further information is available.
Fetchmail 6.2.4 has been reported to be prone to this issue however other
versions may be vulnerable as well.
2. Oracle Database Server Oracle Binary Local Buffer Overflow V...
BugTraq ID: 8844
Remote: No
Date Published: Oct 17 2003
Relevant URL: http://www.securityfocus.com/bid/8844
Summary:
Oracle is a commercial database product, which is available for a number
of platforms including Microsoft Windows and Unix and Linux variants.
Oracle Database Server 'oracle' binary has been reported prone to a local
buffer overflow vulnerability.
The issue likely presents itself due to a lack of sufficient boundary
checks performed on command line arguments passed to the affected binary.
It has been reported that a local attacker may overflow the bounds of an
insufficient reserved buffer in oracle process memory by passing data
>=9850 bytes to the affected binary as a command line argument. Data that
exceeds the size of the affected buffer will corrupt memory that is
adjacent to the aforementioned buffer. Because variables that are crucial
to controlling execution flow of the affected binary are saved in memory
space that an attacker can corrupt, the attacker may influence oracle
execution flow into attacker-controlled memory. Ultimately this condition
could lead to the execution of arbitrary instructions in the context of
the vulnerable binary, which has been reported to be setuid Oracle user.
It should be noted that while this vulnerability has been reported to
affect Oracle 9i Release 2 Patch Set 3 Version 9.2.0.4.0 for Linux x86
other versions and platforms might also be affected.
3. Oracle Database Server OracleO Binary Local Buffer Overflow ...
BugTraq ID: 8845
Remote: No
Date Published: Oct 17 2003
Relevant URL: http://www.securityfocus.com/bid/8845
Summary:
Oracle is a commercial database product, which is available for a number
of platforms including Microsoft Windows and Unix and Linux variants.
Oracle Database Server 'oracleO' binary has been reported prone to a local
buffer overflow vulnerability.
The issue likely presents itself due to a lack of sufficient boundary
checks performed on command line arguments passed to the affected binary.
It has been reported that a local attacker may overflow the bounds of an
insufficient reserved buffer in oracle process memory by passing excessive
data to the affected binary as a command line argument. Data that exceeds
the size of the affected buffer will corrupt memory that is adjacent to
the aforementioned buffer. Because variables that are crucial to
controlling execution flow of the affected binary are saved in memory
space that an attacker may corrupt, the attacker may influence oracle
execution flow into attacker-controlled memory. Ultimately this condition
could lead to the execution of arbitrary instructions in the context of
the vulnerable binary, which has been reported to be setuid Oracle user.
It should be noted that while this vulnerability has been reported to
affect Oracle 9i Release 2 Patch Set 3 Version 9.2.0.4.0 for Linux x86
other versions and platforms might also be affected.
4. Multiple GDM Local Denial Of Service Vulnerabilities
BugTraq ID: 8846
Remote: No
Date Published: Oct 17 2003
Relevant URL: http://www.securityfocus.com/bid/8846
Summary:
Gnome Display Manager (GDM) is a utility harnessed by Gnome to manage
various functions when interfacing with X.
GDM has been reported prone to multiple denial of service vulnerabilities
that may be triggered by a local attacker.
It has been reported that GDM does not perform sufficient restrictions on
data that it receives. A local attacker may send excessive amounts of data
to GDM and cause memory resources to be exhausted until the kernel
terminates the process of the affected GDM.
Additionally a separate issue has been reported to affect GDM that may be
exploited by a local attacker to trigger a denial of service of the GDM
utility. The issue has been reported to present itself due to an error
while handling queries, for example version queries or authentication
responses. It has been reported that an attacker may invoke a query
request against GDM and not read the reply, thus triggering GDM into
filling its send buffer. This will have the affect of preventing GDM from
accepting new logins.
A local attacker may exploit these vulnerabilities to deny service to GDM
for legitimate users.
Explicit details regarding this vulnerability are not currently available,
this BID will be updated when further details are released or when more
exhaustive investigation into this condition has been completed.
5. Geeklog Forgot Password SQL Injection Vulnerability
BugTraq ID: 8849
Remote: Yes
Date Published: Oct 19 2003
Relevant URL: http://www.securityfocus.com/bid/8849
Summary:
Geeklog is open-source weblog software. It is written in PHP and will run
on most Unix and Linux variants, as well as Microsoft Windows operating
systems.
An SQL injection vulnerability has been reported in the Geeklog "forgot
password" feature (introduced in Geeklog 1.3.8). This feature allows for
user passwords to be reset.
Due to insufficient sanitization of user-supplied input, it is possible
for remote attacks to influence database queries. In particular, a SELECT
query is made by the software when a user attempts to use the feature to
change a password. It is possible for a remote attacker to include
malicious SQL syntax as an argument for the $rid variable, which
represents the requesting user's ID. It has been demonstrated that this
could be exploited to reset any user's password, including the
administrator.
Due to the nature of this vulnerability, direct attacks against the
database are also possible such as manipulating queries to disclose
sensitive information or attempts to exploit latent vulnerabilities in the
database itself.
6. CPCommerce Functions Remote File Include Vulnerability
BugTraq ID: 8851
Remote: Yes
Date Published: Oct 19 2003
Relevant URL: http://www.securityfocus.com/bid/8851
Summary:
cpCommerce is open-source e-commerce software. It is implemented in PHP
and available for Microsoft Windows and Unix/Linux variants.
cpCommerce may allow remote users to influence the include path for PHP
scripts, resulting in execution of arbitrary code.
The vulnerability exists in the _functions.php script, which makes the
following require_once() calls:
require_once("{$prefix}_config.php");
require_once("{$prefix}_gateways.php");
If certain PHP configuration directives are enabled, then it is possible
for remote attackers to control the $prefix variable and specify an
include path that points to a malicious PHP script on a remote,
attacker-controlled server. If successfully exploited, an
attacker-specified PHP script will be executed in the context of the web
server process.
7. Opera HREF Malformed Server Name Heap Corruption Vulnerabili...
BugTraq ID: 8853
Remote: Yes
Date Published: Oct 20 2003
Relevant URL: http://www.securityfocus.com/bid/8853
Summary:
Opera is a web browser available for a number of platforms, including
Microsoft Windows, Linux and Unix variants and Apple MacOS. Opera also
includes the M2 Mail Client, which is a fully featured e-mail client that
supports HTML e-mail.
A vulnerability has been discovered in Opera that could lead to remote
code execution. The issue is said to occur when rendering malformed HTML
HREF server name parameters. Specifically, an illegally escaped server
name of excessive length may trigger a buffer overrun within heap memory.
This could potentially allow an attacker to corrupt heap memory management
structures, possibly leading to the execution flow of the program being
controlled when the memory is later freed.
Successful exploitation of this issue could lead to an attacker executing
arbitrary code on a users system, simply by the victim opening a web site
or HTML e-mail.
It should be noted that, due to the differing heap management algorithms
used across operating systems, it is currently unknown whether or not this
issue can be exploited on all affected platforms.
This vulnerability has been reported to reside in Opera 7.11 and 7.20,
however earlier versions may also be affected.
8. Emule Web Control Panel HTTP Login Long Password Denial of S...
BugTraq ID: 8854
Remote: Yes
Date Published: Oct 20 2003
Relevant URL: http://www.securityfocus.com/bid/8854
Summary:
eMule is a freely available, open source peer-to-peer file sharing
application. eMule uses the eDonkey file sharing protocol. It is available
for the BSD, Linux, Microsoft Windows operating systems. eMule includes a
web control panel that allows users to login to the server over the web.
It has been reported that the eMule Web Control Panel HTTP login mechanism
may be prone to denial of service attacks. Reports indicate that the eMule
program expects that login credentials will be received only from the
trusted login form. Specifically, no more then 12 password characters are
expected to be received, and as such eMule does not carry out bounds
checking on this data. However, the eMule login mechanism is said to not
validate the origin of login form information received.
As a result, an attacker may be capable of constructing malicious HTML
form data to transmit excessive password data to the program. Due to
insufficient bounds checking, this will effectively cause memory
corruption and trigger a denial of service. Reports indicated that
password data in excess of 500 to 1000 bytes may be required to trigger
the issue.
It should be noted that, due to the nature of this vulnerability, this
could theoretically lead to arbitrary code execution. This has not been
confirmed however.
9. DeskPro Multiple SQL Injection Vulnerabilities
BugTraq ID: 8856
Remote: Yes
Date Published: Oct 20 2003
Relevant URL: http://www.securityfocus.com/bid/8856
Summary:
DeskPro is a commercially-available contact management software package.
It is available for the Unix, Linux, and Microsoft Platforms.
Multiple Vulnerabilities have been reported to exist in DeskPro that may
allow a remote attacker to inject malicious SQL syntax into database
queries. The source of these issues is insufficient sanitization of
user-supplied input.
The problems are reported to exist in various parameters such as cat,
article, and ticketid of the faq.php and view.php modules. It has also
been reported that an attacker may log on to the system as an
administrator by using 'admin' as the Email value and supplying 'or''=' as
the password. These issues exist because vulnerable parameters are not
sanitized for user-supplied input before it is included in the database. A
remote attacker may exploit this issue to influence SQL query logic while
attempting to authenticate to the server.
A malicious user may influence database queries in order to view or modify
sensitive information, potentially compromising the software or the
database. The consequences of exploitation may vary depending on the
underlying database implementation.
DeskPro version 1.1.0 and prior have been reported to be prone to this
issue, however other versions may also be affected.
10. DansGuardian Denied URL Cross-Site Scripting Vulnerability
BugTraq ID: 8876
Remote: Yes
Date Published: Oct 22 2003
Relevant URL: http://www.securityfocus.com/bid/8876
Summary:
DansGuardian is a content filtering software package. It is available for
Unix, Linux, and Microsoft operating systems.
A problem has been reported in the handling of some types of input to
DansGuardian. This problem may permit an attacker to launch cross-site
scripting attacks.
The problem is in the filtering of the DENIEDURL parameter. When HTML is
passed to the parameter, the script renders the HTML in the security
context of the site hosting DansGuardian. An attacker exploiting this
issue could potentially steal sensitive information such as cookie
authentication credentials, or launch other types of browser-based
attacks.
11. Sylpheed-Claws Mail Client SMTP Error Reporting Format Strin...
BugTraq ID: 8877
Remote: Yes
Date Published: Oct 22 2003
Relevant URL: http://www.securityfocus.com/bid/8877
Summary:
Sylpheed-Claws is a branch of the Sylpheed mail client, designed to
implement and test less stable features. Both code bases are regularly
updated to match each others behavior. Sylpheed-Claws is available for the
Linux operating system.
It has been reported that Sylpheed-Claws is prone to a format string bug
when handling error messages received from an SMTP server. These errors
are typically generated when an action cannot be carried out correctly or
an incorrect command has been received, however an attacker may be capable
of transmitting an error message immediately upon connection.
The problem specifically occurs within the 'send_message.c' source file,
which includes a call to the 'alertpanel_error_log' function when handling
error messages. This function takes formatted arguments and reports the
error message; however when an error message is encountered the function
is incorrectly called without a format specifier, but is passed the SMTP
server-supplied error data. As a result, a malformed SMTP server may be
capable of having arbitrary format specifiers interpreted by the
Sylpheed-Claws mail client, ultimately allowing for code execution.
All code executed in this manner would be run with the privileges of the
user invoking the affected mail client program.
It has been confirmed that the Sylpheed mail client is also affected by
this vulnerability. This issue has been addressed in version 0.9.7.
12. Sun Java Virtual Machine Slash Path Security Model Circumven...
BugTraq ID: 8879
Remote: Yes
Date Published: Oct 22 2003
Relevant URL: http://www.securityfocus.com/bid/8879
Summary:
The Java Virtual Machine (JVM) is a component of the Sun Java
infrastructure that performs the handling of Java applets and other
programs. It is available for Unix, Linux, and Microsoft platforms.
A vulnerability has been identified in the Sun Java Virtual Machine
packaged with JRE and SDK. This issue results in the circumvention of the
Java Security Model, and can permit an attacker to execute arbitrary code
on vulnerable hosts.
The problem is in the handling of security checks on classes. Due to an
error in the loadClass method of the sun.applet.AppletClassLoader
implementation, the JVM does not sufficiently handle one of the syntaxes
used to invoke classes. When classes are invoked by an applet using dot
notation, such as sun.java.class, the checkPackageAccess method of
securitymanager performs reliably, throwing an exception when an applet
attempts to load an unauthorized class.
However, when an applet attempts to load a class using the supported slash
notation, such as sun/java/class, the checkPackageAccess method of
securitymanager does not properly check the name of the requested class.
The applet thus could circumvent the security model, calling classes
outside of the sandbox imposed by the Java security model, and gain access
to prohibited classes. A malicious applet could use this vulnerability to
execute arbitrary code of any type, resulting in unauthorized access to
the vulnerable system with the privileges of the user that has loaded the
malicious Java applet.
III. LINUX FOCUS LIST SUMMARY
-----------------------------
1. NFS replacements for Linux (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/342523
2. AntiVirus for Red Hat 9? (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/342515
3. Fw: AntiVirus for Red Hat 9? (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/342388
4. New Articles on SecurityFocus (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/342386
5. Synflooding a Linux (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/341918
6. New SecurityFocus Article (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/341898
7. [despammed] Synflooding a Linux (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/341782
IV. NEW PRODUCTS FOR LINUX PLATFORMS
------------------------------------
1. Sophos Anti-Virus
By: Sophos
Platforms: AIX, DOS, FreeBSD, HP-UX, Linux, MacOS, Netware, OS/2, Solaris,
UNIX, VMS, Windows 3.x, Windows 95/98, Windows NT
Relevant URL: http://www.sophos.com/products/sav/
Summary:
Sophos Anti-Virus is a unique solution to the virus problem, providing
true cross-platform protection in a single, fully integrated product. The
network-centric design provides a host of benefits for the protection of
servers, workstations and portables. Sophos's ground-breaking architecture
maximises protection, while minimising performance and administrative
overheads.
2. Gordano Messaging Suite
By: Gordano
Platforms: AIX, Linux, Solaris, Windows 2000, Windows NT, Windows XP
Relevant URL: http://www.gordano.com/
Summary:
Gordano's Messaging Suite provides robust and secure email, instant and
SMS messaging for small, medium and large businesses.
3. LANDesk Management Suite 7
By: LANDesk Software
Platforms: AIX, HP-UX, Linux, MacOS, Solaris, Windows 2000, Windows 95/98,
Windows NT, Windows XP
Relevant URL: http://www.landesk.com/products/ilms/
Summary:
LANDesk Management Suite 7 is a comprehensive, integrated management
solution that's easy to use. Enabling proactive management of desktops,
server and mobile devices across heterogeneous IT environments.
- Keep up with security patches and virus updates
- Efficiently install and maintain software on the desktop
- Decrease software license costs and respond to audits
- Reduce the cost of helpdesk support
- Discover and manage hardware and software assets
- Migrate many users and their profiles to new operating systems
4. ActiveScout Enterprise
By: ForeScout Technologies
Platforms: Linux, Solaris, Windows 2000, Windows 95/98, Windows NT
Relevant URL: http://www.forescout.com/enterprise.html
Summary:
ActiveScout Enterprises actively protects a network with multiple access
points. In addition to the identification of attackers and automatic
action to stop them, this solution offers full management capabilities,
from configuration and reporting, to the sharing of threat information
between multiple deployed scouts.
5. Immunity CANVAS
By: Immunity, Inc.
Platforms: Linux, Windows 2000
Relevant URL: http://www.immunitysec.com/CANVAS/
Summary:
Immunity CANVAS is 100% pure Python, and every license includes full
access to the entire CANVAS codebase. Python is one of the easiest
languages to learn, so even novice programmers can be productive on the
CANVAS API, should they so chose.
Immunity CANVAS is both a valuable demonstration tool for enterprise
information security teams or system adminstrators, and an advanced
development platform for exploit developers, or people learning to become
exploit developers.
6. SecretAgent
By: Information Security Corporation (ISC)
Platforms: Linux, MacOS, UNIX, Windows 2000, Windows 95/98, Windows NT,
Windows XP
Relevant URL: http://www.infoseccorp.com/products/secretagent/contents.htm
Summary:
SecretAgent is a file encryption and digital signature utility, supporting
cross-platform interoperability over a wide range of platforms: Windows,
Linux, Mac OS X, and UNIX systems.
It's the perfect solution for your data security requirements, regardless
of the size of your organization.
Using the latest recognized standards in encryption and digital signature
technology, SecretAgent ensures the confidentiality, integrity, and
authenticity of your data.
V. NEW TOOLS FOR LINUX PLATFORMS
--------------------------------
1. AntiSpam Mail Filter v1.2
By: Timo Roehling
Relevant URL: http://sourceforge.net/projects/antispam-filter
Platforms: Linux
Summary:
AntiSpam Mail Filter is yet another Bayesian filter, designed for use with
Exim.
2. Astaro Security Linux (Stable 4.x) v4.016
By: astaro
Relevant URL: http://www.astaro.com/
Platforms: Linux, POSIX
Summary:
Astaro Security Linux is a firewall solution. It does stateful packet
inspection filtering, content filtering, user authentication, virus
scanning, VPN with IPSec and PPTP, and much more. With its Web-based
management tool, WebAdmin, and the ability to pull updates via the
Internet, it is pretty easy to manage. It is based on a special hardened
Linux 2.4 distribution where most daemons are running in change-roots and
are protected by kernel capabilities.
3. libstatgrab v0.7
By: Pete Saunders <[email protected]>
Relevant URL: http://www.i-scream.org/libstatgrab/
Platforms: FreeBSD, Linux, POSIX, Solaris, SunOS
Summary:
The libstatgrab library provides an easy-to-use interface for accessing
system statistics and information. Available statistics include CPU, Load,
Memory, Swap, Disk I/O, and Network I/O. It was developed to work on
Linux, FreeBSD, and Solaris. The package also includes two tools: saidar
provides a curses-based interface for viewing live system statistics, and
statgrab is a sysctl-like interface to the statistics.
4. Anti-Spam SMTP Proxy v1.0.6
By: John Hanna
Relevant URL: http://assp.sourceforge.net/
Platforms: BSDI, Linux, MacOS, Os Independent, OS/2, Perl (any system
supporting perl), POSIX, Windows 2000, Windows NT
Summary:
The Anti-Spam SMTP Proxy (ASSP) Server project aims to create an open
source platform independent SMTP Proxy server which implements whitelists
and Bayesian filtering to help stop unsolicited commercial email (UCE).
Anti-spam tools should be adaptive to new spam and customized for each
site's email patterns. This easy to use tool works with any mail transport
and achieves these goals requiring no operator intervention after the
initial setup phase.
5. Pixilate v0.4
By: Kirby Kuehl <[email protected]>
Relevant URL: http://winfingerprint.sourceforge.net/pixilate.php
Platforms: FreeBSD, Linux, NetBSD, OpenBSD
Summary:
Pixilate is a packet generation tool based off of Libnet 1.1.0 (Older
Libnet 1.0.x versions will not work). Pixilate generates packets by
parsing a file that contains ACLs in either Cisco IOS format (using the -r
option) or in Cisco PIX 6.2x format. Currently TCP, UDP, IGMP, and various
types of ICMP packets are built with the appropriate source and
destination for each rule. "any" as a source generates a random source
address and "any" as a destination will send the packet to the user
supplied destination (-d option). For more information, see the pixilate
manpage.
6. PinePGP 0.18.0
By: Peter Hanecak, [email protected]
Relevant URL: http://www.megaloman.com/~hany/software/pinepgp/
Platforms: Linux
Summary:
PinePGP provides PGP and GnuPG filters for pine. PGP versions 2.6.x, 5.x,
and 6.5.x are supported.
VI. SPONSOR INFORMATION
-----------------------
This Issue Sponsored by: RSA Conference 2004
Network with over 10,000 of the brightest minds in information security at
the largest, most highly-anticipated industry event of the year. Don't
miss RSA Conference 2004! Choose from over 200 class sessions and see
demos from more than 250 industry vendors. If your job touches security,
you need to be here. Learn more or register at
http://www.securityfocus.com/sponsor/RSA_linux-secnews_031027
and use priority code SF4.
------------------------------------------------------------------------