SecurityFocus Linux Newsletter #160
Kelly Martin <[email protected]> Mon, 1 Dec 2003 11:19:14 -0700 (MST)
| Newsgroups | gmane.comp.security.news.linux |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Linux Newsletter #160
------------------------------------
This Issue is Sponsored by: Astaro
Using Integrated Security Platforms to Improve Network Security and Reduce
Cost of Ownership
With an average cost of $226,000 for an external security breach and
$81,000 for a virus infection, the number and diversity of network attacks
increase while budget and staffing constraints make certain prevention
approaches unrealistic for many organizations. Examine the pros and cons
of available options and read an assessment of current security issues and
associated risks.
http://www.securityfocus.com/sponsor/Astaro_linux-secnews_031201
------------------------------------------------------------------------
I. FRONT AND CENTER
1. Fighting Spammers With Honeypots: Part 1
2. Fighting Spammers With Honeypots: Part 2
3. Ending the Free Lunch
4. The Wells Fargo Example
5. Exploiting Cisco Routers: Part 2
II. LINUX VULNERABILITY SUMMARY
1. Imatix Xitami Post Request Header Remote Denial Of Service V...
2. PrimeBase SQL Database Server Administrative Server Password...
3. Opera Skin Zip File Buffer Overflow Vulnerability
4. GEdit Large IOStream File Memory Corruption Vulnerability
5. Linux IPRoute Spoofed Kernel Messages Denial Of Service Vuln...
6. Pan Long Author Address Denial Of Service Vulnerability
7. SIRCD Server Operator Privilege Escalation Vulnerability
8. Monit HTTP Content-Length Parameter Denial of Service Vulner...
9. Monit Overly Long HTTP Request Buffer Overrun Vulnerability
10. My_EGallery Module Remote Include Command Injection Vulnerab...
11. ISC BIND Negative Cache Poison Denial Of Service Vulnerabili...
12. phpBB search.php SQL Injection Vulnerability
III. LINUX FOCUS LIST SUMMARY
1. Administrivia: Your responses (Thread)
2. New SecurityFocus articles (Thread)
IV. NEW PRODUCTS FOR LINUX PLATFORMS
1. Immunity CANVAS
2. SecretAgent
3. Cyber-Ark Inter-Business Vault
4. EnCase Forensic Edition
5. KeyGhost SX
6. SafeKit
V. NEW TOOLS FOR LINUX PLATFORMS
1. Sentry Firewall CD-ROM v1.5.0-rc7(dev)
2. SILC (Secure Internet Live Conferencing)(client) v1.0
3. ThePacketMaster Linux Security Server v1.0.1
4. Fast Logging Project for Snort v1.0
5. CryptoFS v0.3.0
6. Linux-VServer v1.1.6
VI. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. Fighting Spammers With Honeypots: Part 1
By Laurent Oudot
This paper will evaluate the usefulness of using honeypots to fight
spammers on several fronts. Part one discusses the methods spammers use to
harvest addresses, maintain stealth and manipulate open mail relays on the
Internet. Then honeypots will be considered that create fake email
addresses to be harvested, identify and track spammers, and simulate open
proxies for spammers to use.
http://www.securityfocus.com/infocus/1747
2. Fighting Spammers With Honeypots: Part 2
By Laurent Oudot
Part two continues the discussion of open proxies, describes creating fake
open mail relays with various honeypots, discusses architecture decisions,
and then provides some recent test results that proved very successful. A
honeypot can clearly be used to detect, slow and stop spam-related
activities while promoting a clean Internet -- but more people must pitch
in for them to truly make a difference.
http://www.securityfocus.com/infocus/1748
3. Ending the Free Lunch
By Hal Flynn
Linux vendors spend money building security bug fixes. How much longer
will they give them away for free?
http://www.securityfocus.com/columnists/200
4. The Wells Fargo Example
By Mark Rasch
Companies should protect consumer data better than Wells Fargo did, but in
cleaning up its laptop data spill the bank blazed a trail worth following.
http://www.securityfocus.com/columnists/201
5. Exploiting Cisco Routers: Part 2
By Mark Wolfgang
This is the second of a two-part series that focuses on identifying and
then exploiting vulnerabilities and poor configurations in Cisco routers.
This article will look at what we can do once we've gotten in.
http://www.securityfocus.com/infocus/1749
II. LINUX VULNERABILITY SUMMARY
-------------------------------
1. Imatix Xitami Post Request Header Remote Denial Of Service V...
BugTraq ID: 9083
Remote: Yes
Date Published: Nov 21 2003
Relevant URL: http://www.securityfocus.com/bid/9083
Summary:
Xitami is a freely available web server package distributed by Imatix. It
is available for the Unix, Linux, and Microsoft platforms.
A problem has been identified in the handling of certain types of requests
by Imatix Xitami. Because of this, it is possible for a remote attacker
to deny service to legitimate users of a vulnerable server.
When an attacker crafts POST request with a header containing certain
malformed fields, it is possible to force the Xitami server into an
endless loop in execution. This typically results in the Xitami server
crashing, resulting in a denial of service, and requiring a manual restart
of the server to resume normal service.
2. PrimeBase SQL Database Server Administrative Server Password...
BugTraq ID: 9087
Remote: No
Date Published: Nov 22 2003
Relevant URL: http://www.securityfocus.com/bid/9087
Summary:
PrimeBase SQL Database Server is a database implementation that is
available for Unix, Linux, and Microsoft Windows platforms.
A problem has been reported in the storage of credentials in PrimeBase SQL
Database Server. Because of this, it may be possible for an attacker to
gain unauthorized access to resources.
The problem is in the storage of authentication credentials. The
administrative server included with PrimeBase SQL Database Server does not
store authentication credentials in a secure format, keeping them in a
plain text file. This problem is compounded by the fact that file is
created with a default umask that permits world read access to the file.
This issue may permit an attacker with shell-level access to a system
hosting the server to gain access to the database server administrative
interface.
3. Opera Skin Zip File Buffer Overflow Vulnerability
BugTraq ID: 9089
Remote: Yes
Date Published: Nov 22 2003
Relevant URL: http://www.securityfocus.com/bid/9089
Summary:
Opera is a web browser available for a number of operating systems,
including the Microsoft Windows, Linux, Unix, and Apple MacOS platforms.
A problem has been identified in the handling of zipped skin files by
Opera. Because of this, it may be possible for an attacker to gain
unauthorized access to a system using the vulnerable browser.
The problem is in the handling of specially crafted zip files. When a
skin zip file with data appended after the zipped data is downloaded by
Opera, the data contained after the zip data results in a boundary
condition error. This could be exploited to overwrite sensitive process
memory, potentially resulting in the modifying of program flow and
execution of attacker-supplied instructions.
It should be noted that exploitation of this vulnerability may result in
the execution of code with the privileges of the Opera browser user.
4. GEdit Large IOStream File Memory Corruption Vulnerability
BugTraq ID: 9090
Remote: No
Date Published: Nov 23 2003
Relevant URL: http://www.securityfocus.com/bid/9090
Summary:
gEdit is a freely available, open source text processing application. It
is available for the Unix and Linux platforms.
A problem has been reported in the handling of certain file types by
gEdit. Because of this, it may be possible to cause memory corruption.
The problem is in the handling of files with long strings. When a file
with long strings and no terminators is opened with gEdit, a memory
corruption error occurs. This problem is likely a buffer overflow, though
this has not been confirmed.
In the event that this is an exploitable overflow, it could be possible to
execute arbitrary code by embedding arbitrary instructions in a
maliciously crafted file. Any instructions executed through gEdit would
be with the privileges of the gEdit user.
5. Linux IPRoute Spoofed Kernel Messages Denial Of Service Vuln...
BugTraq ID: 9092
Remote: No
Date Published: Nov 24 2003
Relevant URL: http://www.securityfocus.com/bid/9092
Summary:
iproute is a freely available, open source network suite for the Linux
platform.
A problem has been discovered in iproute when handling messages from the
kernel. Because of this, it may be possible for an attacker to deny
service to legitimate users of a system.
The problem is in the checking of the origins of messages from the kernel.
By creating specially crafted messages, it is possible to send spoofed
messages on the kernel netlink interface that will fool iproute into
reacting unpredictably. This could lead to loss of proper routing tables,
or other types of routing attacks.
6. Pan Long Author Address Denial Of Service Vulnerability
BugTraq ID: 9093
Remote: Yes
Date Published: Nov 24 2003
Relevant URL: http://www.securityfocus.com/bid/9093
Summary:
Pan is a freely available, open source news reading utility. It is
available for the Unix and Linux platforms.
A problem has been reported in the handling of addresses in Pan. Because
of this, it is possible for a remote attacker to deny service to
legitimate users of an application.
The problem is in the handling of news posts containing long author e-mail
addresses. When the program encounters such an article, it becomes
unstable and crashes. The program will continue to crash each time an
attempt to read the malicious article is made.
7. SIRCD Server Operator Privilege Escalation Vulnerability
BugTraq ID: 9097
Remote: Yes
Date Published: Nov 20 2003
Relevant URL: http://www.securityfocus.com/bid/9097
Summary:
sircd is an IRC server daemon, for Linux and Unix platforms.
sircd has been reported prone to a privilege escalation vulnerability. The
issue has been reported to exist in s_client.c. It has been reported that
any user logged on to the sircd server, may set their usermode to +o, or
operator mode.
An attacker may exploit this condition to hijack IRC channels or
impersonate users, these privileges may aid the attacker in further
attacks launched against the target server.
It should be noted that although sircd versions 0.5.2 and 0.5.3 have been
reported vulnerable other versions might also be affected.
8. Monit HTTP Content-Length Parameter Denial of Service Vulner...
BugTraq ID: 9098
Remote: Yes
Date Published: Nov 24 2003
Relevant URL: http://www.securityfocus.com/bid/9098
Summary:
Monit is a utility for the Linux and Unix operating systems that is
designed to monitor processes, devices, files, and directories. The
application makes use of an HTTPS interface to allow remote users to
monitor system statistics.
A vulnerability has been discovered in Monit 4.1 and earlier that could
potentially allow an anonymous attacker to crash the daemon process. The
problem occurs due to Monit failing to sanitize a specific HTTP parameter
before passing its values to a memory allocation function.
Specifically, Monit does not verify the sanity of the Content-Length HTTP
parameter before passing it as an argument to the xmalloc() function. As a
result, passing a negative value as the Content-Length will cause the
value to be cast as unsigned by the aforementioned function, causing the
value to be interpreted as an excessively large value. This will likely
cause the xmalloc() function to unexpectedly fail, resulting in the daemon
crashing.
Although unconfirmed, the crash may in fact occur due to the program
failing to handle NULL values returned from xmalloc(), possibly resulting
in a NULL pointer dereference.
9. Monit Overly Long HTTP Request Buffer Overrun Vulnerability
BugTraq ID: 9099
Remote: Yes
Date Published: Nov 24 2003
Relevant URL: http://www.securityfocus.com/bid/9099
Summary:
Monit is a utility for the Linux and Unix operating systems that is
designed to monitor processes, devices, files, and directories. The
application makes use of an HTTPS interface to allow remote users to
monitor system statistics.
A buffer overrun vulnerability has been discovered in Monit 4.1 and
earlier that could potentially allow a remote attacker to execute
arbitrary code with root privileges. The problem occurs due to Monit
failing to carry out sufficient bounds checking when handling HTTP request
data.
An attacker could potentially exploit this condition to overwrite
sensitive process memory variables, allowing for the execution flow of
Monit to be controlled. Successful exploitation of this vulnerability
could lead to an attacker gaining remote root access to an affected
system.
10. My_EGallery Module Remote Include Command Injection Vulnerab...
BugTraq ID: 9113
Remote: Yes
Date Published: Nov 26 2003
Relevant URL: http://www.securityfocus.com/bid/9113
Summary:
My_eGallery is a freely available, open source PostNuke module. It is
available for the Unix and Linux platforms.
A vulnerability has been identified in the handling of input by
My_eGallery. Because of this, it may be possible for a remote user to
gain unauthorized access to a system using the vulnerable software.
It is possible to influence the include path of certain files, which could
lead to an attacker including arbitrary PHP files from an external system.
Upon inclusion, commands contained in the attacker-supplied includes would
be executed on the local system. It has been reported that the problem
may exist in multiple scripts including the 'basepath' parameter of
'displayCategory.php'.
Commands executed through this vulnerability could permit an attacker to
gain access to a vulnerable system with the privileges of the web server
process.
11. ISC BIND Negative Cache Poison Denial Of Service Vulnerabili...
BugTraq ID: 9114
Remote: Yes
Date Published: Nov 26 2003
Relevant URL: http://www.securityfocus.com/bid/9114
Summary:
ISC BIND is a server program that implements the domain name service
protocol. It is widely used on the Internet.
BIND has been reported prone to a DNS cache poisoning vulnerability; this
issue is due to negative answers being cached from an incorrect source. A
remote attacker who has control of a DNS server capable of serving
authoritative negative responses may exploit this issue. Ultimately if the
vulnerable BIND DNS server queries the malicious attacker-controlled name
server, authoritative negative responses that should not be accepted will
poison the cache of the vulnerable BIND server. This will result in the
inability of resolver procedures to resolve the domains specified in the
negative records. It has been reported that this denial of service effect
will last until the bad DNS record expires from the DNS cache. An attacker
may ensure that a high TTL value is used, so that the malicious record
remains in the target DNS server cache for as long as possible.
The vendor has stated the fixes were added to affected versions as
anti-cache poisoning measures to negative answers.
A remote attacker may exploit this vulnerability to deny service to
affected servers for legitimate users. There may also be other
consequences associated with this vulnerability, though this has not been
confirmed.
This BID will be updated when further explicit information relating to
this vulnerability is made public.
12. phpBB search.php SQL Injection Vulnerability
BugTraq ID: 9122
Remote: Yes
Date Published: Nov 27 2003
Relevant URL: http://www.securityfocus.com/bid/9122
Summary:
phpBB is an open-source web forum application that is written in PHP and
supported by a number of database products. It will run on most Unix and
Linux variants, as well as Microsoft Windows operating systems.
A vulnerability has been reported to exist in the software that may a
remote user to inject malicious SQL syntax into database queries. The
problem reportedly exists in the 'search_id' parameter of search.php
script. This issue is caused by insufficient sanitization of
user-supplied data. A remote attacker may exploit this issue to influence
SQL query logic to disclose sensitive information that could be used to
gain unauthorized access.
A malicious user may influence database queries in order to view or modify
sensitive information potentially compromising the software or the
database.
phpBB version 2.06 has been prone to this issue, however other versions
may be affected as well.
III. LINUX FOCUS LIST SUMMARY
-----------------------------
1. Administrivia: Your responses (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/345796
2. New SecurityFocus articles (Thread)
Relevant URL:
http://www.securityfocus.com/archive/91/345794
IV. NEW PRODUCTS FOR LINUX PLATFORMS
------------------------------------
1. Immunity CANVAS
By: Immunity, Inc.
Platforms: Linux, Windows 2000
Relevant URL: http://www.immunitysec.com/CANVAS/
Summary:
Immunity CANVAS is 100% pure Python, and every license includes full
access to the entire CANVAS codebase. Python is one of the easiest
languages to learn, so even novice programmers can be productive on the
CANVAS API, should they so chose.
Immunity CANVAS is both a valuable demonstration tool for enterprise
information security teams or system adminstrators, and an advanced
development platform for exploit developers, or people learning to become
exploit developers.
2. SecretAgent
By: Information Security Corporation (ISC)
Platforms: Linux, MacOS, UNIX, Windows 2000, Windows 95/98, Windows NT,
Windows XP
Relevant URL: http://www.infoseccorp.com/products/secretagent/contents.htm
Summary:
SecretAgent is a file encryption and digital signature utility, supporting
cross-platform interoperability over a wide range of platforms: Windows,
Linux, Mac OS X, and UNIX systems.
It's the perfect solution for your data security requirements, regardless
of the size of your organization.
Using the latest recognized standards in encryption and digital signature
technology, SecretAgent ensures the confidentiality, integrity, and
authenticity of your data.
3. Cyber-Ark Inter-Business Vault
By: Cyber-Ark
Platforms: Linux, Windows 2000, Windows NT, Windows XP
Relevant URL:
http://www.cyber-ark.com/datasecuritysoftware/inter-business_vault.htm
Summary:
Based on Cyber-Ark Software's Vaulting Technology, the Inter-Business
Vault, an information security solution that enables organizations to
safely overcome traditional network boundaries in order to securely share
business information among customers, business partners, and remote
branches. It provides a seamless, LAN-like experience over the Internet
that includes all the security, performance, accessibility, and ease of
administration required to allow organizations to share everyday
information worldwide. To learn more about these core attributes of the
Inter-Business Vault click on the relevant link below:
4. EnCase Forensic Edition
By: Guidance Software Inc.
Platforms: DOS, FreeBSD, Linux, MacOS, NetBSD, OpenBSD, PalmOS, Solaris,
UNIX, Windows 2000, Windows 95/98, Windows NT, Windows XP
Relevant URL:
http://www.guidancesoftware.com/products/EnCaseForensic/index.shtm
Summary:
EnCase Forensic Edition Version 4 delivers the most advanced features for
computer forensics and investigations. With an intuitive GUI and superior
performance, EnCase Version 4 provides investigators with the tools to
conduct large-scale and complex investigations with accuracy and
efficiency. Guidance Software?s award winning solution yields completely
non-invasive computer forensic investigations while allowing examiners to
easily manage large volumes of computer evidence and view all relevant
files, including "deleted" files, file slack and unallocated space.
The integrated functionality of EnCase allows the examiner to perform all
functions of the computer forensic investigation process. EnCase's
EnScript, a powerful macro-programming language and API included within
EnCase, allows investigators to build customized and reusable forensic
scripts.
5. KeyGhost SX
By: KeyGhost Ltd
Platforms: BeOS, DOS, Linux, OS/2, Solaris, SunOS, Windows 2000, Windows
95/98, Windows NT, Windows XP
Relevant URL: http://www.keyghost.com/SX/
Summary:
KeyGhost SX discreetly captures and records all keystrokes typed,
including chat conversations, email, word processor, or even activity
within an accounting or specialist system. It is completely undetectable
by software scanners and provides you with one of the most powerful
stealth surveillance applications offered anywhere.
Because KeyGhost uses STRONG 128-Bit encryption to store the recorded data
in it?s own internal memory (not on the hard drive), it is impossible for
a network intruder to gain access to any sensitive data stored within the
device.
6. SafeKit
By: Evidian Inc.
Platforms: AIX, HP-UX, Linux, Solaris, Windows 2000
Relevant URL: http://www.evidian.com/safekit/index.htm
Summary:
Evidian's SafeKit technology makes it possible to render any application
available 24 hours per day. With no extra hardware: just use your existing
servers and install this software-only solution.
This provides ultimate scalability. As your needs grow, all you need to do
is add more standard servers into the cluster. With the load balancing
features of SafeKit, you can distribute applications over multiple
servers. If one system fails completely, the others will continue to serve
your users.
V. NEW TOOLS FOR LINUX PLATFORMS
--------------------------------
1. Sentry Firewall CD-ROM v1.5.0-rc7(dev)
By: Obsid
Relevant URL: http://www.SentryFirewall.com/
Platforms: Linux
Summary:
Sentry Firewall CD-ROM Version 1.0 is a Linux based bootable CD-ROM
suitable for use as an inexpensive and easy to maintain Firewall or
IDS(Intrusion Detection System) Node. The system is designed to be
immediately configurable for a variety of different operating environments
via a configuration file located on a floppy disk or a local hard drive.
2. SILC (Secure Internet Live Conferencing)(client) v1.0
By: priikone
Relevant URL: http://silcnet.org/
Platforms: Linux, UNIX
Summary:
SILC Client package is intended for end users who are looking for a good
and full featured SILC client. The SILC Client package currently includes
Irssi-SILC client that supports all SILC features, themes and much more.
It is curses based but has a possibility of adding various other frontends
to it. The Irssi-SILC client's user interface is based on the Irssi client
(see Irssi project).
3. ThePacketMaster Linux Security Server v1.0.1
By: thepacketmaster
Relevant URL: http://www.thepacketmaster.com/
Platforms: Linux
Summary:
ThePacketMaster Linux Security Server is a CD- based security auditing
tool that boots and runs penetration testing and forensic analysis tools.
It is handy for security auditors. Some tools included are nessus,
ethereal, The Coroner's Toolkit, chntpw, and minicom. It includes modules
for any Linux 2.4.20 SCSI driver.
4. Fast Logging Project for Snort v1.0
By: DG <[email protected]>
Relevant URL: http://www.geschke-online.de/FLoP
Platforms: Linux, Solaris, SunOS
Summary:
FLoP is designed to gather alerts with a payload from distributed Snort
sensors at a central server, and to store them in a database (PostgreSQL
and MySQL are supported). On the sensor, the output is written via a Unix
domain socket to a process called sockserv. This process is threaded; one
receives and buffers the alert packets, and the other thread forwards them
to a central server. With this approach, the output is decoupled from
Snort, which can proceed in sniffing instead of waiting for the output
plugins. At the central server, a process called servsock gathers all
alerts from the remote sensors and feeds them via a Unix domain socket to
the database. All alerts are buffered to avoid blocking due to a hanging
database access (or a slow network on the senor side). A short description
of alerts with high priority together with the database ID can be sent via
email to a list of recipients.
5. CryptoFS v0.3.0
By: Christoph Hohmann
Relevant URL: http://reboot.animeirc.de/cryptofs/
Platforms: Linux
Summary:
CryptoFS is a encryption filesystem for the Linux Userland Filesystem.
Files written to the mount point will be stored encrypted (data and
filename) in a directory on a normal filesystem.
6. Linux-VServer v1.1.6
By: Herbert Pƶtzl
Relevant URL: http://www.linux-vserver.org/
Platforms: Linux
Summary:
Linux-VServer allows you to create virtual private servers and security
contexts which operate like a normal Linux server, but allow many
independent servers to be run simultaneously in one box at full speed. All
services, such as ssh, mail, Web, and databases, can be started on such a
VPS, without modification, just like on any real server. Each virtual
server has its own user account database and root password and doesn't
interfere with other virtual servers.
VI. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored by: Astaro
Using Integrated Security Platforms to Improve Network Security and Reduce
Cost of Ownership
With an average cost of $226,000 for an external security breach and
$81,000 for a virus infection, the number and diversity of network attacks
increase while budget and staffing constraints make certain prevention
approaches unrealistic for many organizations. Examine the pros and cons
of available options and read an assessment of current security issues and
associated risks.
http://www.securityfocus.com/sponsor/Astaro_linux-secnews_031201
------------------------------------------------------------------------