SecurityFocus Microsoft Newsletter #200
Peter Laborge <[email protected]> 3 Aug 2004 21:29:30 -0000
| Newsgroups | gmane.comp.security.news.microsoft |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Microsoft Newsletter #200
----------------------------------------
This Issue is Sponsored By: SecurityFocus
Want to keep up on the latest security vulnerabilities? Don't have time to
visit a myriad of mailing lists and websites to read the news? Just add the
new SecurityFocus RSS feeds to your freeware RSS reader, and see all the
latest posts for Bugtraq and the SF Vulnernability database in one
convenient place. Or, pull in the latest news, columnists and feature
articles in the SecurityFocus aggregated news feed, and stay on top of
what's happening in the community!
http://www.securityfocus.com/rss/index.shtml
------------------------------------------------------------------------
I. FRONT AND CENTER
1. Data Driven Attacks Using HTTP Tunneling
2. Email Privacy is Lost
II. MICROSOFT VULNERABILITY SUMMARY
1. PostNuke Install Script Administrator Password Disclosure Vu...
2. Mozilla Firefox Refresh Security Property Spoofing Vulnerabi...
3. Subversion 'mod_authz_svn' Access Control Bypass Vulnerabili...
4. PostNuke Reviews Module Cross-Site Scripting Vulnerability
5. Invision Power Board Index.php Query String Cross-Site Scrip...
6. Microsoft Internet Explorer Style Tag Comment Memory Corrupt...
7. Hitachi Web Page Generator Unspecified Denial Of Service Vul...
8. Verylost LostBook Message Entry HTML Injection Vulnerability
9. MyServer Multiple Remote math_sum.mscgi Example Script Vulne...
10. Mozilla Firefox XML User Interface Language Browser Interfac...
III. MICROSOFT FOCUS LIST SUMMARY
1. ezmlm warning (Thread)
2. ISA/VPN comparison (Thread)
3. Microsoft to release out-of-cycle patch (Thread)
4. SecurityFocus Microsoft Newsletter #199 (Thread)
5. Windows Update v5 and XPSP2RC2 (Thread)
6. Proxy Server/ISA (Thread)
IV. NEW PRODUCTS FOR MICROSOFT PLATFORMS
1. RSI
2. WiSSH
3. Firewall RuleMaker
4. CAT Cellular Authentication Token and eAuthentication Servic...
5. KeyCaptor Keylogger
6. SpyBuster
V. NEW TOOLS FOR MICROSOFT PLATFORMS
1. DiskLogon 1.0.17.112
2. UndeleteSMS 1.0
3. Macshift 1.0
4. Advanced LAN Scanner 1.0
5. Firewall Builder 2.0
6. Lepton's Crack 20031130
VI. UNSUBSCRIBE INSTRUCTIONS
VII. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. Data Driven Attacks Using HTTP Tunneling
By Ido Dubrawsky
In this article we will look at a means to bypass the access control
restrictions of a company's router or firewall. This information is
intended to provide help for those who are legitimately testing the
security of a network (whether they are in-house expertise or outside
consultants).
http://www.securityfocus.com/infocus/1793
2. Email Privacy is Lost
By Scott Granneman
As if the common use of "web bugs" inside spam was not enough, companies
are using new techniques to watch and track the private emails you read,
forward, print, and more.
http://www.securityfocus.com/columnists/258
II. MICROSOFT VULNERABILITY SUMMARY
-----------------------------------
1. PostNuke Install Script Administrator Password Disclosure Vu...
BugTraq ID: 10793
Remote: Yes
Date Published: Jul 24 2004
Relevant URL: http://www.securityfocus.com/bid/10793
Summary:
It is reported that PostNuke may disclose administrator authentication credentials to remote attackers. This issue presents itself because the application fails to remove the install script 'install.php' after installation. This can allow an attacker to gain unauthorized access to the content management system. The attacker may then carry out further attacks against other users or the computer running the vulnerable application.
2. Mozilla Firefox Refresh Security Property Spoofing Vulnerabi...
BugTraq ID: 10796
Remote: Yes
Date Published: Jul 26 2004
Relevant URL: http://www.securityfocus.com/bid/10796
Summary:
Mozilla Firefox may permit malicious Web pages to spoof security properties of a trusted site.
An attacker can exploit this issue to spoof the URI and SSL certificate of a site trusted by an unsuspecting user. The attacker can then use this spoofing to steal sensitive or private information, facilitating phishing attacks
3. Subversion 'mod_authz_svn' Access Control Bypass Vulnerabili...
BugTraq ID: 10800
Remote: Yes
Date Published: Jul 26 2004
Relevant URL: http://www.securityfocus.com/bid/10800
Summary:
Subversion is reported to contain access control bypass vulnerabilities in its 'mod_authz_svn' Apache module.
These access control vulnerabilities present themselves when users have mixed access to a repository.
These vulnerabilities exist in several server operations, such as COPY and DELETE. These operations fail to properly implement the operator assigned access controls, allowing users improper access to repositories.
These issues are only present when using the WebDAV access method with the Apache 'mod_authz_svn' module, with the 'AuthzSVNAccessFile' configuration directive.
The vulnerabilities are present in version 1.0.5 and prior. Versions 1.0.6 and 1.1.0-rc1 have been released to address these vulnerabilities.
4. PostNuke Reviews Module Cross-Site Scripting Vulnerability
BugTraq ID: 10802
Remote: Yes
Date Published: Jul 26 2004
Relevant URL: http://www.securityfocus.com/bid/10802
Summary:
PostNuke is reported prone to a cross-site scripting vulnerability. This issue affects the 'title' parameter of 'Reviews' script. Exploitation of this issue could allow for theft of cookie-based authentication credentials. Other attacks are also possible.
It should be noted, that although this vulnerability has been reported to affect PostNuke version 0.726-3 and 0.75-RC3, other versions might also be affected.
5. Invision Power Board Index.php Query String Cross-Site Scrip...
BugTraq ID: 10804
Remote: Yes
Date Published: Jul 26 2004
Relevant URL: http://www.securityfocus.com/bid/10804
Summary:
A vulnerability has been reported to exist in Invision Power Board that may allow a remote user to launch cross-site scripting attacks.
This vulnerability makes it possible for an attacker to construct a malicious link containing HTML or script code that may be rendered in a user's browser upon visiting that link. This attack would occur in the security context of the site.
Successful exploitation of this attack may allow an attacker to steal cookie-based authentication credentials. Other attacks are also possible.
6. Microsoft Internet Explorer Style Tag Comment Memory Corrupt...
BugTraq ID: 10816
Remote: Yes
Date Published: Jul 28 2004
Relevant URL: http://www.securityfocus.com/bid/10816
Summary:
A vulnerability identified in Internet Explorer may allow an attacker to cause the application to crash. It is reported that the issue presents itself when a comment character sequence that is not terminated is encountered after a STYLE tag.
This issue could be exploited by a remote attacker to cause a denial of service condition in the browser. The attacker would likely create a malicious HTML page and host it on a site. The attacker would then attempt to entice a user to visit the malicious page to carry out a
successful attack.
7. Hitachi Web Page Generator Unspecified Denial Of Service Vul...
BugTraq ID: 10817
Remote: Yes
Date Published: Jul 28 2004
Relevant URL: http://www.securityfocus.com/bid/10817
Summary:
It is reported that Web Page Generator contains an unspecified denial of service vulnerability. This vulnerability is only reported to affect the Microsoft Windows version of the application.
Reportedly, sending multiple invalid requests to the affected application can potentially cause the application to crash.
A remote attacker can exploit this vulnerability to crash Web Page Generator, denying service to legitimate users.
No further information is available at this time. This BID will be updated as more information is disclosed.
8. Verylost LostBook Message Entry HTML Injection Vulnerability
BugTraq ID: 10825
Remote: Yes
Date Published: Jul 29 2004
Relevant URL: http://www.securityfocus.com/bid/10825
Summary:
Reportedly Verylost lostBook is affected by an HTML injection vulnerability in its message entry functionality. This issue is due to a failure of the application to properly validate and sanitize user-supplied input before including it in dynamically generated web page content.
This may allow an attacker inject malicious HTML and script code into the application. An unsuspecting user viewing the post will have the attacker-supplied script code executed within their browser in the context of the vulnerable site. This issue may be leverage to steal cookie based authentication credentials. Other attacks are also possible.
9. MyServer Multiple Remote math_sum.mscgi Example Script Vulne...
BugTraq ID: 10831
Remote: Yes
Date Published: Jul 30 2004
Relevant URL: http://www.securityfocus.com/bid/10831
Summary:
Reportedly MyServer is affected by multiple remote vulnerabilities in the 'math_sum.mscgi' example script. These issues are due to a boundary condition error and a failure to properly sanitize user-supplied URI input.
An attacker could exploit the boundary condition issue to execute arbitrary code on the affected computer with the privileges of the user that started the affected application. The input validation issue could be leveraged to carry out cross-site scripting attacks against the affected computer.
These issues are reported to affect MyServer version 0.6.2, it is likely other versions are also affected.
10. Mozilla Firefox XML User Interface Language Browser Interfac...
BugTraq ID: 10832
Remote: Yes
Date Published: Jul 30 2004
Relevant URL: http://www.securityfocus.com/bid/10832
Summary:
Mozilla Firefox is reported prone to an interface spoofing vulnerability. The issue presents itself because JavaScript code is allowed to hide the Mozilla Firefox interface and status bar by default. A fake Mozilla firefox interface may be created using the XML User Interface Language API, this interface may aid in phishing style attacks.
This misrepresentation may fool a user into trusting a malicious site, which would likely ask the user to submit sensitive or private information.
III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. ezmlm warning (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/370651
2. ISA/VPN comparison (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/370560
3. Microsoft to release out-of-cycle patch (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/370388
4. SecurityFocus Microsoft Newsletter #199 (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/370301
5. Windows Update v5 and XPSP2RC2 (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/370300
6. Proxy Server/ISA (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/370135
IV. NEW PRODUCTS FOR MICROSOFT PLATFORMS
----------------------------------------
1. RSI
By: Digital Labs, LLC
Platforms: Windows 2000, Windows NT, Windows XP
Relevant URL: http://www.digitallabs.net/rsi/
Summary:
Remote System Information audits your network for critical hardware and software information and displays the results in a clear, exportable spreadsheet view.
Remote Registry technology provides the ability to dynamically scan your network without the need to install client software.
2. WiSSH
By: Digital Labs, LLC
Platforms: Windows 2000, Windows NT, Windows XP
Relevant URL: http://www.wissh.com
Summary:
WiSSH (Windows over SSH) utilizes SSH tunneling technology to secure Microsoft's RDP protocol. Allows access to multiple hosts behind your network perimeter with only a single host's SSH port open to the Internet
3. Firewall RuleMaker
By: The Net Memetic Pte Ltd
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Relevant URL: http://firewall.rulemaker.net
Summary:
Firewall RuleMaker is a Windows-based firewall configuration version control software product for managers of Cisco PIX and Netscreen firewalls.
4. CAT Cellular Authentication Token and eAuthentication Servic...
By: Mega AS Consulting Ltd
Platforms: Java, Linux, OpenBSD, Os Independent, SecureBSD, Solaris, UNIX, Windows 2000, Windows NT
Relevant URL: http://www.megaas.co.nz
Summary:
Low cost, easy to use Two Factor Authentication One Time Password token using the Cellular. Does not use SMS or communication, manages multiple OTP accounts - new technology. For any business that want a safer access to its Internet Services. More information at our site.
We also provide eAuthentication service for businesses that will not buy an Authentication product but would prefer to pay a monthly charge for authentication services from our our CAT Server.
5. KeyCaptor Keylogger
By: Keylogger Software
Platforms: MacOS, Windows 2000, Windows 95/98, Windows NT, Windows XP
Relevant URL: http://www.keylogger-software.com/keylogger/keylogger.htm
Summary:
KeyCaptor is your solution for recording ALL keystrokes of ALL users on your computer! Now you have the power to record emails, websites, documents, chats, instant messages, usernames, passwords, and MUCH MORE!
With our advanced stealth technology, KeyCaptor will not show in your processes list and cannot be stopped from running unless you say so!
6. SpyBuster
By: Remove Spyware
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Relevant URL: http://www.remove-spyware.com/spybuster.htm
Summary:
Our award winning spyware / adware scanner and removal software, SpyBuster will scan your computer for over 4,000 known spyware and adware applications. SpyBuster protects your computer from data stealing programs that can expose your personal information.
SpyBuster scanning technology allows for a quick and easy sweep, so you can resume your work in minutes.
V. NEW TOOLS FOR MICROSOFT PLATFORMS
------------------------------------
1. DiskLogon 1.0.17.112
By: DiskLogon Development Team
Relevant URL: http://www.disklogon.com/DiskLogon.exe
Platforms: Windows 2000, Windows XP
Summary:
DiskLogon, like a Smart Card logon, is a software that enables you to log on to your computer with a removable disk.
DiskLogon saves you the trouble of entering your user name and password every time you log on. All you have to do is to plug in your removable disk, and you can log on to your computer quickly and safely. When you plug out your removable disk, your computer will automatically lock up you're your safety.
2. UndeleteSMS 1.0
By: Arne Vidstrom
Relevant URL: http://vidstrom.net/downloads/undeletesms.exe
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
UndeleteSMS can recover deleted SMS messages from a GSM SIM card.
3. Macshift 1.0
By: Nathan True
Relevant URL: http://students.washington.edu/natetrue/macshift/macshift.zip
Platforms: Windows 2000, Windows XP
Summary:
Macshift is a free and open-source tool to change the MAC address of any network adapter under Windows 2k / XP. It has a simple scriptable commandline interface.
4. Advanced LAN Scanner 1.0
By: Famatech
Relevant URL: http://www.radmin.com/download/lscan1b1.exe
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
Advanced Lan Scanner is a fast, small, easy-to-use, highly configurable network scanner for Win32. Advanced Lan Scanner uses multithreading technique, that gives it ability to scan more than 1000 elements per second. If used to scan ports, Advanced Lan Scanner can check all 65536 ports in less that minute. Advanced LAN Scanner performs exact scan upon each computer you wish, extracting users, services, shares and a lot of over useful information.
5. Firewall Builder 2.0
By: Vadim Kurland
Relevant URL: http://www.fwbuilder.org/
Platforms: FreeBSD, Linux, MacOS, Solaris, Windows 2000, Windows XP
Summary:
Firewall Builder consists of a GUI and set of policy compilers for various firewall platforms. It helps users maintain a database of objects and allows policy editing using simple drag-and-drop operations. The GUI and policy compilers are completely independent, and support for a new firewall platform can be added to the GUI without any changes to the program (only a new policy compiler is needed). This provides for a consistent abstract model and the same GUI for different firewall platforms. It currently supports iptables, ipfilter, and OpenBSD pf.
6. Lepton's Crack 20031130
By: Lepton and Nekromancer
Relevant URL: http://www.nestonline.com/lcrack/lcrack-20031130-beta.zip
Platforms: Linux, MacOS, Os Independent, UNIX, Windows 2000, Windows NT, Windows XP
Summary:
Lepton's Crack is a generic password cracker. It is easily-customizable with a simple plugin system and allows system administrators to review the quality of the passwords being used on their systems. It can perform a dictionary-based (wordlist) attack as well as a brute force (incremental) password scan. It supports standard MD4 hash, standard MD5 hash, NT MD4/Unicode, Lotus Domino HTTP password (R4), and SHA-1 hash formats. LM (LAN Manager) plus appending and prepending
VI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
VII. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored By: SecurityFocus
Want to keep up on the latest security vulnerabilities? Don't have time to
visit a myriad of mailing lists and websites to read the news? Just add the
new SecurityFocus RSS feeds to your freeware RSS reader, and see all the
latest posts for Bugtraq and the SF Vulnernability database in one
convenient place. Or, pull in the latest news, columnists and feature
articles in the SecurityFocus aggregated news feed, and stay on top of
what's happening in the community!
http://www.securityfocus.com/rss/index.shtml
------------------------------------------------------------------------