SecurityFocus Microsoft Newsletter #199

Peter Laborge <[email protected]> 27 Jul 2004 20:20:27 -0000
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #199
----------------------------------------

This Issue is Sponsored By: SecurityFocus 

Want to keep up on the latest security vulnerabilities? Don't have time to
visit a myriad of mailing lists and websites to read the news? Just add the
new SecurityFocus RSS feeds to your freeware RSS reader, and see all the
latest posts for Bugtraq and the SF Vulnernability database in one
convenient place. Or, pull in the latest news, columnists and feature
articles in the SecurityFocus aggregated news feed, and stay on top of
what's happening in the community!

http://www.securityfocus.com/rss/index.shtml

------------------------------------------------------------------------
I. FRONT AND CENTER
     1. Wireless Attacks and Penetration Testing (part 3 of 3)
     2. A Promise Falls in the Forest
II. MICROSOFT VULNERABILITY SUMMARY
     1. OllyDbg Debugger Messages Format String Vulnerability
     2. Medal Of Honor Allied Assault Remote Buffer Overflow Vulnera...
     3. Extropia WebStore Remote Command Execution Vulnerability
     4. MIT Software I-CAFE Multiple Vulnerabilities
     5. PHPNuke Multiple Input Validation Vulnerabilities
     6. CuteNews Comment HTML Injection Vulnerability
     7. PHPBB Multiple HTTP Response Splitting Vulnerabilities
     8. PHPBB Search.PHP "search_author" Cross-Site Scripting Vulner...
     9. PHP-Nuke Reviews Module "title" Parameter Cross-Site Scripti...
     10. Sysinternals PsTools Remote Unauthorized Access Vulnerabilit...
     11. SnapFiles Whisper FTP Surfer Long File Name Remote Buffer Ov...
     12. Opera Web Browser Cross-Domain Frame Loading Vulnerability
     13. Serena TeamTrack Remote Authentication Bypass Vulnerability
     14. Leigh Business Enterprises Web HelpDesk SQL Injection Vulner...
     15. Mensajeitor Tag Board Authentication Bypass Vulnerability
     16. Layton Technology HelpBox Multiple SQL Injection Vulnerabili...
     17. APC PowerChute Business Edition Unspecified Denial Of Servic...
     18. Imatix Xitami Server Side Includes Cross-Site Scripting Vuln...
     19. Samba Filename Mangling Method Buffer Overrun Vulnerability
     20. Imatix Xitami Malformed Header Remote Denial of Service Vuln...
III. MICROSOFT FOCUS LIST SUMMARY
     1. Proxy Server/ISA (Thread)
     2. Windows Update v5 and XPSP2RC2 (Thread)
     3. Browser Vulns (Thread)
     4. VPN (Thread)
     5. Microsoft Audit Collection System (Thread)
     6. SecurityFocus Microsoft Newsletter #198 (Thread)
     7. real world security though, was  Browser Vulns (Thread)
IV. NEW PRODUCTS FOR MICROSOFT PLATFORMS
     1. RSI
     2. WiSSH
     3. Firewall RuleMaker
     4. CAT Cellular Authentication Token and eAuthentication Servic...
     5. KeyCaptor Keylogger
     6. SpyBuster
V. NEW TOOLS FOR MICROSOFT PLATFORMS
     1. Lepton's Crack 20031130
     2. ModemWall 1.2
     3. BitCrypt Free 2.1
     4. e-Surveiller 1.5
     5. SecureAware 1.3.1
     6. CryptoHeaven v2.4.1
VI. UNSUBSCRIBE INSTRUCTIONS
VII. SPONSOR INFORMATION

I. FRONT AND CENTER
-------------------
1. Wireless Attacks and Penetration Testing (part 3 of 3)
By Jonathan Hassell

This third and final part of the wireless pen-test series looks at how to
mitigate the security risks outlined in the previous articles, and then
looks at some proposed solutions currently in front of the IETF.

http://www.securityfocus.com/infocus/1792


2. A Promise Falls in the Forest
By Mark Rasch

A federal court recently ruled that website privacy policies aren't
binding, because nobody reads them. The implications are far reaching for
contract law and the Internet. 

http://www.securityfocus.com/columnists/257

II. MICROSOFT VULNERABILITY SUMMARY
-----------------------------------
1. OllyDbg Debugger Messages Format String Vulnerability
BugTraq ID: 10742
Remote: Yes
Date Published: Jul 17 2004
Relevant URL: http://www.securityfocus.com/bid/10742
Summary:
OllyDbg is prone to a format string vulnerability.  

This issue is exposed when the application handles debugger messages that contain format specifiers.  

Debugging a  malicious program that is designed to exploit this issue could lead to an application crash or execution of arbitrary code in the context of the user running the debugger.

2. Medal Of Honor Allied Assault Remote Buffer Overflow Vulnera...
BugTraq ID: 10743
Remote: Yes
Date Published: Jul 17 2004
Relevant URL: http://www.securityfocus.com/bid/10743
Summary:
A remote buffer overflow vulnerability was reported in Medal of Honor Allied Assault.  

This issue may permit remote code execution in vulnerable game servers and clients.  However, it is reported that clients will only be affected in LAN games as Internet games  use the Gamespy protocol.  The issue also affects various expansion packs for the game.

3. Extropia WebStore Remote Command Execution Vulnerability
BugTraq ID: 10744
Remote: Yes
Date Published: Jul 17 2004
Relevant URL: http://www.securityfocus.com/bid/10744
Summary:
eXtropia WebStore is prone to a remote command execution vulnerability.  

This issue is due to insufficient input validation and may permit execution of commands in the context of the hosting Web server.

4. MIT Software I-CAFE Multiple Vulnerabilities
BugTraq ID: 10748
Remote: No
Date Published: Jul 19 2004
Relevant URL: http://www.securityfocus.com/bid/10748
Summary:
I-Cafe is prone to multiple vulnerabilities that may allow local users to gain unauthorized access to a vulnerable computer.

Successful exploitation of various issues can allow the attacker to disable the application, gain access to the local disk, and gain administrative access to the computer.

These issues were reported in I-Cafe version 2.6 revision 2004.72.  Other versions may be vulnerable as well.

5. PHPNuke Multiple Input Validation Vulnerabilities
BugTraq ID: 10749
Remote: Yes
Date Published: Jul 19 2004
Relevant URL: http://www.securityfocus.com/bid/10749
Summary:
It is reported that PHPNuke is susceptible to multiple cross-site scripting and SQL injection vulnerabilities.

This can allow for theft of cookie-based authentication credentials and other attacks.  Attackers may supply malicious parameters to manipulate the structure and logic of SQL queries.

These vulnerabilities were reported in version 7.3 of PHPNuke. Other versions may also be affected.

6. CuteNews Comment HTML Injection Vulnerability
BugTraq ID: 10750
Remote: Yes
Date Published: Jul 19 2004
Relevant URL: http://www.securityfocus.com/bid/10750
Summary:
CutePHP is reported prone to an HTML injection vulnerability.

The vulnerability exists due to insufficient sanitization of user-supplied input. Specifically, user-supplied input to comment posts are not sufficiently sanitized of malicious HTML code.

An attacker can exploit this vulnerability by adding HTML code within URI arguments. The hostile code may be rendered in the user's browser when the user views the entry.

Exploitation could permit an attacker to steal cookie-based authentication credentials or launch other attacks.

7. PHPBB Multiple HTTP Response Splitting Vulnerabilities
BugTraq ID: 10753
Remote: Yes
Date Published: Jul 19 2004
Relevant URL: http://www.securityfocus.com/bid/10753
Summary:
phpBB is reported prone to multiple HTTP response splitting vulnerabilities. The issues exist in the "privmsg.php" script and the "login.php" script. The vulnerabilities present themselves due to a flaw in the affected scripts that will allow an attacker to manipulate how GET requests are handled.

A remote attacker may exploit these vulnerabilities to influence or misrepresent how web content is served, cached or interpreted.

8. PHPBB Search.PHP "search_author" Cross-Site Scripting Vulner...
BugTraq ID: 10754
Remote: Yes
Date Published: Jul 19 2004
Relevant URL: http://www.securityfocus.com/bid/10754
Summary:
It is reported that one of the scripts included with phpBB is prone to a cross-site scripting vulnerability.  According to the author of the report, the script "search.php" returns the value of the HTML variable "search_author" to the client as its output without encoding it or otherwise removing potentially hostile content. 

It is reported that gpc magic quotes must be turned off in php.ini for this vulnerability to exist.

9. PHP-Nuke Reviews Module "title" Parameter Cross-Site Scripti...
BugTraq ID: 10755
Remote: Yes
Date Published: Jul 19 2004
Relevant URL: http://www.securityfocus.com/bid/10755
Summary:
PHP-Nuke 'reviews' module is prone to a cross-site scripting vulnerability.  This issue could allow an attacker to steal cookie-based authentication credentials.

An attacker can exploit this issue by creating a malicious link containing HTML and script code.  The attacker sends this link to a vulnerable user.  When the user follows the link, HTML and script renders in the user's browser.

10. Sysinternals PsTools Remote Unauthorized Access Vulnerabilit...
BugTraq ID: 10759
Remote: Yes
Date Published: Jul 20 2004
Relevant URL: http://www.securityfocus.com/bid/10759
Summary:
Reportedly Sysinternals PsTools are affected by a remote unauthorized access vulnerability.  This issue is due to a design error that causes a failure of the utilities to properly secure the affected computer.

A remote attacker might leverage this issue to gain administrator access to the affected computer.

11. SnapFiles Whisper FTP Surfer Long File Name Remote Buffer Ov...
BugTraq ID: 10761
Remote: Yes
Date Published: Jul 20 2004
Relevant URL: http://www.securityfocus.com/bid/10761
Summary:
Whisper FTP Surfer is reported prone to a remote buffer overflow vulnerability.  This issue presents itself due to insufficient boundary checks performed by the application when handling long file names.

This issue affects Whisper FTP Surfer 1.0.7, however, other versions may be vulnerable as well.

12. Opera Web Browser Cross-Domain Frame Loading Vulnerability
BugTraq ID: 10763
Remote: Yes
Date Published: Jul 20 2004
Relevant URL: http://www.securityfocus.com/bid/10763
Summary:
Opera Web Browser is reported prone to a cross-domain frame loading vulnerability. It is reported that if the name of a frame rendered in a target site is known, then an attacker may potentially render arbitrary HTML in the frame of the target site. 

Opera Web Browser versions 7.51 and prior are reported to be affected by this issue.

This issue was originally reported in Microsoft Internet Explorer in BID 10627 (Microsoft Internet Explorer Cross-Domain Frame Loading Vulnerability), however, further information has shown that Opera is affected by the same vulnerability.

13. Serena TeamTrack Remote Authentication Bypass Vulnerability
BugTraq ID: 10770
Remote: Yes
Date Published: Jul 21 2004
Relevant URL: http://www.securityfocus.com/bid/10770
Summary:
It has been reported that Serena TeamTrack is affected by remote authentication bypass vulnerability.  This issue is due to a design error that allows unauthenticated users to access sensitive scripts.

Successful exploitation of this issue will allow an attacker to gain access to sensitive information such as user names, software versions, user contact information, issues information and resolution information.  This issue can also be exploited to carry out cross-site scripting attacks.

14. Leigh Business Enterprises Web HelpDesk SQL Injection Vulner...
BugTraq ID: 10773
Remote: Yes
Date Published: Jul 21 2004
Relevant URL: http://www.securityfocus.com/bid/10773
Summary:
LBE Web HelpDesk is reported susceptible to an SQL injection vulnerability. This issue is due to improper sanitization of user-supplied data.

This issue may allow a remote attacker to manipulate query logic, potentially leading to unauthorized access to sensitive information or corruption of database data. SQL injection attacks may also potentially be used to exploit latent vulnerabilities in the underlying database implementation.

Versions 4.0.0.80 and prior are reported vulnerable to this issue.

15. Mensajeitor Tag Board Authentication Bypass Vulnerability
BugTraq ID: 10774
Remote: Yes
Date Published: Jul 21 2004
Relevant URL: http://www.securityfocus.com/bid/10774
Summary:
It has been reported that Mensajeitor Tag Board is affected by an authentication bypass vulnerability.  This issue is due to a failure of the application to properly handle authentication controls.

Successful exploitation of this issue will allow an attacker to post messages to the affected tag board as an administrator, reportedly facilitating HTML injection and attacks.

16. Layton Technology HelpBox Multiple SQL Injection Vulnerabili...
BugTraq ID: 10776
Remote: Yes
Date Published: Jul 21 2004
Relevant URL: http://www.securityfocus.com/bid/10776
Summary:
It is reported that HelpBox is susceptible to multiple SQL injection vulnerabilities. This issue is due to improper sanitization of user-supplied data. 

These problems present themselves when malicious SQL statements are passed to certain scripts.

Some scripts require administrative privileges to HelpBox. One script reportedly allows exporting any table in the SQL server.

These issues may allow a remote attacker to manipulate query logic, potentially leading to unauthorized access to sensitive information or corruption of database data. SQL injection attacks may also potentially be used to exploit latent vulnerabilities in the underlying database implementation.

HelpBox version 3.0.1 is reported vulnerable to these issues.

17. APC PowerChute Business Edition Unspecified Denial Of Servic...
BugTraq ID: 10777
Remote: Unknown
Date Published: Jul 21 2004
Relevant URL: http://www.securityfocus.com/bid/10777
Summary:
It is reported that APC PowerChute Business Edition is susceptible to an unspecified denial of service vulnerability.

Reportedly, all versions of the software between 6.0 and 7.0.1 contain a denial of service vulnerability that affects servers and agents. It does not affect the ability of the software to shutdown computers in the event of a power failure.

APC has released version 7.0.2 addressing this issue.

This BID will be updated as further information is disclosed.

18. Imatix Xitami Server Side Includes Cross-Site Scripting Vuln...
BugTraq ID: 10778
Remote: Yes
Date Published: Jul 22 2004
Relevant URL: http://www.securityfocus.com/bid/10778
Summary:
It is reported that Imatix Xitami is affected by a cross-site scripting vulnerability in the server side includes test script.  This issue is due to a failure of the application to properly sanitize user-supplied input.

Successful exploitation of this issue will allow an attacker to execute arbitrary script code in the browser of an unsuspecting user.  This may potentially be exploited to hijack web content or steal cookie-based authentication credentials from legitimate users.

19. Samba Filename Mangling Method Buffer Overrun Vulnerability
BugTraq ID: 10781
Remote: Yes
Date Published: Jul 22 2004
Relevant URL: http://www.securityfocus.com/bid/10781
Summary:
Samba is reported prone to an undisclosed buffer overrun vulnerability, the buffer overrun is reported to exist when Samba is handling file name mangling with the "hash" method.

It is conjectured that this vulnerability may present itself when the affected server handles a filename that is sufficient to trigger the vulnerability. To exploit this vulnerability, an attacker may require sufficient access so that they may write a file to a published samba share.

It is reported that the vulnerability does not exist in default Samba configurations; by default, Samba is configured to employ "hash2" name mangling. The "hash2" method is not vulnerable.

This vulnerability is reported to affect Samba version 3.0.0 and later.

20. Imatix Xitami Malformed Header Remote Denial of Service Vuln...
BugTraq ID: 10785
Remote: Yes
Date Published: Jul 22 2004
Relevant URL: http://www.securityfocus.com/bid/10785
Summary:
A vulnerability is identified in the handling of certain types of requests by Xitami. Because of this, it is possible for a remote attacker to deny service to legitimate users of a vulnerable server. 

Xitami 2.5c1 is reported prone to this issue, however, other versions may be affected as well.

III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Proxy Server/ISA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/370117

2. Windows Update v5 and XPSP2RC2 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/370015

3. Browser Vulns (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/369937

4. VPN (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/369677

5. Microsoft Audit Collection System (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/369558

6. SecurityFocus Microsoft Newsletter #198 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/369553

7. real world security though, was  Browser Vulns (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/369551

IV. NEW PRODUCTS FOR MICROSOFT PLATFORMS
----------------------------------------
1. RSI
By: Digital Labs, LLC
Platforms: Windows 2000, Windows NT, Windows XP
Relevant URL: http://www.digitallabs.net/rsi/
Summary: 

Remote System Information audits your network for critical hardware and software information and displays the results in a clear, exportable spreadsheet view.

Remote Registry technology provides the ability to dynamically scan your network without the need to install client software.

2. WiSSH
By: Digital Labs, LLC
Platforms: Windows 2000, Windows NT, Windows XP
Relevant URL: http://www.wissh.com
Summary: 

WiSSH (Windows over SSH) utilizes SSH tunneling technology to secure Microsoft's RDP protocol. Allows access to multiple hosts behind your network perimeter with only a single host's SSH port open to the Internet

3. Firewall RuleMaker
By: The Net Memetic Pte Ltd
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Relevant URL: http://firewall.rulemaker.net
Summary: 

Firewall RuleMaker is a Windows-based firewall configuration version control software product for managers of Cisco PIX and Netscreen firewalls.

4. CAT Cellular Authentication Token and eAuthentication Servic...
By: Mega AS Consulting Ltd
Platforms: Java, Linux, OpenBSD, Os Independent, SecureBSD, Solaris, UNIX, Windows 2000, Windows NT
Relevant URL: http://www.megaas.co.nz
Summary: 

Low cost, easy to use Two Factor Authentication One Time Password token using the Cellular. Does not use SMS or communication, manages multiple OTP accounts - new technology. For any business that want a safer access to its Internet Services. More information at our site.
 
We also provide eAuthentication service for businesses that will not buy an Authentication product but would prefer to pay a monthly charge for authentication services from our our CAT Server.

5. KeyCaptor Keylogger
By: Keylogger Software
Platforms: MacOS, Windows 2000, Windows 95/98, Windows NT, Windows XP
Relevant URL: http://www.keylogger-software.com/keylogger/keylogger.htm
Summary: 

KeyCaptor is your solution for recording ALL keystrokes of ALL users on your computer!  Now you have the power to record emails, websites, documents, chats, instant messages, usernames, passwords, and MUCH MORE!

With our advanced stealth technology, KeyCaptor will not show in your processes list and cannot be stopped from running unless you say so!

6. SpyBuster
By: Remove Spyware
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Relevant URL: http://www.remove-spyware.com/spybuster.htm
Summary: 

Our award winning spyware / adware scanner and removal software, SpyBuster will scan your computer for over 4,000 known spyware and adware applications. SpyBuster protects your computer from data stealing programs that can expose your personal information.

SpyBuster scanning technology allows for a quick and easy sweep, so you can resume your work in minutes.

V. NEW TOOLS FOR MICROSOFT PLATFORMS
------------------------------------
1. Lepton's Crack 20031130
By: Lepton and Nekromancer
Relevant URL: http://www.nestonline.com/lcrack/lcrack-20031130-beta.zip
Platforms: Linux, MacOS, Os Independent, UNIX, Windows 2000, Windows NT, Windows XP
Summary: 

Lepton's Crack is a generic password cracker. It is easily-customizable with a simple plugin system and allows system administrators to review the quality of the passwords being used on their systems. It can perform a dictionary-based (wordlist) attack as well as a brute force (incremental) password scan. It supports standard MD4 hash, standard MD5 hash, NT MD4/Unicode, Lotus Domino HTTP password (R4), and SHA-1 hash formats. LM (LAN Manager) plus appending and prepending

2. ModemWall 1.2
By: Egemen Tas
Relevant URL: http://www.modemwall.com
Platforms: Windows 2000, Windows XP
Summary: 

ModemWall is a dialing number filtering system for Windows 2000/XP (or later) operating systems. It is an agent designed to combat with unauthorized dialers (mostly known as porn dialers). ModemWall cuts off the problems caused by these dialers at the source : Prevent unauthorized numbers from being dialed regardless of the dialer which/who is trying to dial. With ModemWall, users can specify Authorized/Unauthorized numbers logically by using easy firewall like rules.

3. BitCrypt Free 2.1
By: Moshe Szweizer
Relevant URL: http://www.geocities.com/moshe_szweizer/index.html
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary: 

BitCrypt Free is a sophisticated tool allowing for encryption of plain text within bitmap image. While encrypting it modifies the individual pixel shadings of the image, and in this way incorporates the information related to the text being encoded. The modifications of the image are so small that the effect is not perceptible to the human eye.

4. e-Surveiller 1.5
By: SurveilleTech Software
Relevant URL: http://www.e-surveiller.com
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary: 

e-Surveiller is a powerful user-activity monitoring, logging and real-time surveillance software package. With it, you can monitor the activities of several computer users on standalone computers, on a local area network and on remote computers across the Internet. You view the screens of monitored users on a LAN or across the Internet in real-time! and it empowers you to save screen snapshots at any time. It stealthily records all keystrokes, web site visits, AOL, AIM,

5. SecureAware 1.3.1
By: Neupart A/S
Relevant URL: http://www.neupart.com
Platforms: Windows 2000, Windows NT, Windows XP
Summary: 

SecureAware is an information security management intranet for creating and communicating business-level security policies, procedures and awareness programs.

It drastically reduces the time and effort required to perform these tasks because it does not rely on text-based templates. Awareness content is automatically generated from your specific policy rules, combined with built-in generic security lessons.

6. CryptoHeaven v2.4.1
By: Marcin Kurzawa <[email protected]>
Relevant URL: http://www.cryptoheaven.com/
Platforms: UNIX, Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary: 

CryptoHeaven offers secure email and online file sharing/storage. Its main features are secure and highly encrypted services such as group collaboration, file sharing, email, online storage, and instant messaging. It integrates multi-user based security into email, instant messaging, and file storage and sharing in one unique package. It provides real time communication for text and data transfers in a multi-user secure environment. The security and usability of CryptoHeaven is well-balanced; even the no-so-technically oriented computer users can enjoy this crypto product with very high level of encryption.

VI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.
    
VII. SPONSOR INFORMATION
-----------------------

This Issue is Sponsored By: SecurityFocus 

Want to keep up on the latest security vulnerabilities? Don't have time to
visit a myriad of mailing lists and websites to read the news? Just add the
new SecurityFocus RSS feeds to your freeware RSS reader, and see all the
latest posts for Bugtraq and the SF Vulnernability database in one
convenient place. Or, pull in the latest news, columnists and feature
articles in the SecurityFocus aggregated news feed, and stay on top of
what's happening in the community!

http://www.securityfocus.com/rss/index.shtml

------------------------------------------------------------------------