SecurityFocus Microsoft Newsletter #205

Peter Laborge <[email protected]> 9 Sep 2004 16:39:04 -0000
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #205
----------------------------------------

This issue sponsored by: Qualys

Can you find every rogue device on your network?
 
Entry points into your network aren't always obvious. FreeMap finds access
points to the discovered network by accurately characterizing devices,
including: access gateways, routers or other types of equipment. 

Take advantage of this free tool! There's nothing to install or buy. Click
on the link below to run your FreeMap.
http://www.securityfocus.com/sponsor/Qualys_ms-secnews_040907

------------------------------------------------------------------------
I. FRONT AND CENTER
     1. Metasploit Framework, Part 2
     2. Feast of Egos
II. MICROSOFT VULNERABILITY SUMMARY
     1. Ipswitch WS_FTP Server CD Command Malformed File Path Remote...
     2. Symantec PowerQuest DeployCenter Boot Disk Plaintext Passwor...
     3. Titan FTP Server CWD Command Remote Heap Overflow Vulnerabil...
     4. ACLogic CesarFTP Buffer Overflow Vulnerability
     5. Xedus Web Server Multiple Vulnerabilities
     6. CDRTools RSH Environment Variable Privilege Escalation Vulne...
     7. Diebold GEMS Central Tabulator Vote Database Integrity Compr...
     8. MIT Kerberos 5 Multiple Double-Free Vulnerabilities
     9. MIT Kerberos 5 ASN.1 Decoder Denial Of Service Vulnerability
     10. Newtelligence DasBlog Request Log HTML Injection Vulnerabili...
     11. PHPWebSite Multiple Input Validation Vulnerabilities
     12. Opera Web Browser Empty Embedded Object JavaScript Denial Of...
     13. Kerio Personal Firewall Application Security Bypass Vulnerab...
     14. Altnet ADM ActiveX Control Remote Buffer Overflow Vulnerabil...
     15. Ipswitch IMail Server Multiple Buffer Overflow Denial Of Ser...
     16. Nullsoft Winamp ActiveX Control Remote Buffer Overflow Vulne...
     17. Ipswitch WhatsUp Gold Notification Instance Name Remote Buff...
     18. Ipswitch WhatsUp Gold prn.htm Denial Of Service Vulnerabilit...
     19. Keene Digital Media Server Cross-Site Scripting Vulnerabilit...
     20. Keene Digital Media Server Admin Authentication Bypass Vulne...
III. MICROSOFT FOCUS LIST SUMMARY
     1. XP-SP2 "Feature" (Thread)
     2. Windows/Exchange security auditing tool (Thread)
     3. SecurityFocus Microsoft Newsletter #204 (Thread)
IV. NEW PRODUCTS FOR MICROSOFT PLATFORMS
     1. Firewall RuleMaker
     2. CAT Cellular Authentication Token and eAuthentication Servic...
     3. KeyCaptor Keylogger
     4. SpyBuster
     5. FreezeX
     6. NeoExec for Active Directory
V. NEW TOOLS FOR MICROSOFT PLATFORMS
     1. Attack Tool Kit (ATK) 2.0
     2. FREEping - Server pinging 1.0
     3. Softros LAN Messenger 3.4
     4. Healthmonitor 1.9
     5. Mutilate File Wiper 2.90
     6. K-MAC 1.0.0.4
VI. UNSUBSCRIBE INSTRUCTIONS
VII. SPONSOR INFORMATION

I. FRONT AND CENTER
-------------------
1. Metasploit Framework, Part 2
By Pukhraj Singh and K.K. Mookhey

Newly updated. This article provides insight into the Metasploit Framework,
a very useful tool for the penetration tester. Part two of three.

http://www.securityfocus.com/infocus/1790


2. Feast of Egos
By Tim Mullen

Eager to tarnish Microsoft's shiny new Service Pack 2, the security press
managed to spin the most thin and marginal issues into "gaping holes" and
"security craters." 

http://www.securityfocus.com/columnists/265

II. MICROSOFT VULNERABILITY SUMMARY
-----------------------------------
1. Ipswitch WS_FTP Server CD Command Malformed File Path Remote...
BugTraq ID: 11065
Remote: Yes
Date Published: Aug 30 2004
Relevant URL: http://www.securityfocus.com/bid/11065
Summary:
WS_FTP Server is reported prone to a remote denial of service vulnerability.  This issue presents itself when the application processes a malformed file path through the 'cd' command.  

WS_FTP Server version 5.0.2 is reported prone to this issue, however, other versions may be affected as well.

2. Symantec PowerQuest DeployCenter Boot Disk Plaintext Passwor...
BugTraq ID: 11068
Remote: No
Date Published: Aug 30 2004
Relevant URL: http://www.securityfocus.com/bid/11068
Summary:
Symantec PowerQuest DeployCenter is reportedly affected by a boot disk plaintext password disclosure vulnerability.  This issue is due to a failure of the application to handle exceptional conditions.

This issue will allow an attacker to steal a password to the remote computer that the offending boot disk is designed to access, facilitating further attacks against the affected computer.

3. Titan FTP Server CWD Command Remote Heap Overflow Vulnerabil...
BugTraq ID: 11069
Remote: Yes
Date Published: Aug 30 2004
Relevant URL: http://www.securityfocus.com/bid/11069
Summary:
Titan FTP server is reported prone to a remote heap overflow vulnerability.  This issue exists due to insufficient boundary checks performed by the application and may result in arbitrary code execution.

The issue presents itself when the server processes user-supplied data passed through the 'cwd' command.

All versions of Titan FTP server are considered vulnerable to this issue.

4. ACLogic CesarFTP Buffer Overflow Vulnerability
BugTraq ID: 11070
Remote: Yes
Date Published: Aug 30 2004
Relevant URL: http://www.securityfocus.com/bid/11070
Summary:
It is reported that CesarFTP is susceptible to a buffer overflow vulnerability. This vulnerability is due to a lack of proper bounds checking in the application. This leads to a buffer of fixed size being overrun, corrupting the contents of adjacent memory regions.

It is reported that this vulnerability is exploitable before authenticating to the FTP server, allowing anonymous attackers to either crash the FTP server, or possibly to execute arbitrary code in the context of the FTP server process.

5. Xedus Web Server Multiple Vulnerabilities
BugTraq ID: 11071
Remote: Yes
Date Published: Aug 30 2004
Relevant URL: http://www.securityfocus.com/bid/11071
Summary:
It is reported that Xedus is susceptible to multiple vulnerabilities.

The first reported issue is a denial of service vulnerability. The affected application is unable to service multiple simultaneous connections, denying access to the hosted site for legitimate users.

The second reported issue is a cross-site scripting vulnerability in included sample scripts. This vulnerability is due to a failure of the application to properly sanitize user-supplied URI input before including it in the output of the scripts.

The third reported issue is a directory traversal vulnerability. The affected application will reportedly serve documents located outside of the configured web root. This may allow an attacker the ability to read arbitrary, potentially sensitive files on the hosting computer with the privileges of the web server. This may aid malicious users in further attacks.

These vulnerabilities are reported to exist in version 1.0 of Xedus.

6. CDRTools RSH Environment Variable Privilege Escalation Vulne...
BugTraq ID: 11075
Remote: No
Date Published: Aug 31 2004
Relevant URL: http://www.securityfocus.com/bid/11075
Summary:
CDRTools is reportedly vulnerable to an RSH environment variable privilege escalation vulnerability.  This issue is due to a failure of the application to properly implement security controls when executing an application specified by the RSH environment variable.

An attacker may leverage this issue to gain superuser privileges on a computer running the affected software.

7. Diebold GEMS Central Tabulator Vote Database Integrity Compr...
BugTraq ID: 11076
Remote: Yes
Date Published: Aug 31 2004
Relevant URL: http://www.securityfocus.com/bid/11076
Summary:
It is reported that the GEMS Central Tabulator stores received votes in three segregated regions of an Access database.  The GEMs system harvests data from each of these database regions in order to generate reports.

All of the tables in these separate database regions are linked together in an attempt to prevent database tampering, by ensuring that the table data corresponds to table data in other database regions.

The Diebold GEMS Central Tabulator is reported prone to a vulnerability, where a two-digit code can be entered into a hidden location to de-link the tables in the GEMS database. This will permit an attacker to add sets of fake votes.

8. MIT Kerberos 5 Multiple Double-Free Vulnerabilities
BugTraq ID: 11078
Remote: Yes
Date Published: Aug 31 2004
Relevant URL: http://www.securityfocus.com/bid/11078
Summary:
There are multiple double-free vulnerabilities reported to exist in MIT Kerberos 5.

All vulnerabilities stem from inconsistent memory handling routines in the krb5 library.

These vulnerabilities are exploitable in various ways:
- An attacker can execute arbitrary code in the context of a KDC server process, potentially compromising the entire Kerberos realm.
- An attacker can execute arbitrary code in the context of a krb524d server process, potentially compromising the entire Kerberos realm if it is running on the same computer as a KDC.
- An attacker can execute arbitrary code in the context of various other server processes utilizing the krb5 library.
- An attacker impersonating a KDC or application server may be able to execute arbitrary code in the context of a client process attempting to authenticate.

Versions up to and including 1.3.4 are reported vulnerable.

9. MIT Kerberos 5 ASN.1 Decoder Denial Of Service Vulnerability
BugTraq ID: 11079
Remote: Yes
Date Published: Aug 31 2004
Relevant URL: http://www.securityfocus.com/bid/11079
Summary:
It is reported that MIT Kerberos V is susceptible to a denial of service vulnerability in its ASN.1 decoder.

This vulnerability presents itself when the krb5 library attempts to decode a malformed ASN.1 buffer.

As a result of this vulnerability, a remote attacker may be able to deny all Kerberos service in a realm by sending malicious UDP packets to all KDCs (Key Distribution Center). The affected KDCs would then stop servicing further authentication requests. All services utilizing Kerberos for authentication would fail to allow further requests.

MIT Kerberos V versions 1.2.2 through to 1.3.4 are reportedly affected by this vulnerability.

10. Newtelligence DasBlog Request Log HTML Injection Vulnerabili...
BugTraq ID: 11086
Remote: Yes
Date Published: Sep 01 2004
Relevant URL: http://www.securityfocus.com/bid/11086
Summary:
DasBlog is reportedly susceptible to an HTML injection vulnerability in its request log. This vulnerability is due to a failure of the application to properly sanitize user-supplied input data before using it in the generation of dynamic web pages.

This may allow an attacker to inject malicious HTML and script code into the application. An administrator displaying the 'Activity and Events Viewer' will have the attacker-supplied script code executed within their browser in the context of the vulnerable site. This issue may be leverage to steal cookie based authentication credentials. Other attacks are also possible.

Although this issue reportedly affects versions 1.3 through 1.6 of the affected software.

11. PHPWebSite Multiple Input Validation Vulnerabilities
BugTraq ID: 11088
Remote: Yes
Date Published: Sep 01 2004
Relevant URL: http://www.securityfocus.com/bid/11088
Summary:
It is reported that phpWebSite is susceptible to multiple cross-site scripting, HTML injection and SQL injection vulnerabilities.

The cross-site scripting issue is present in a parameter of the comments module script. An attacker can exploit these issues by creating a malicious link to the vulnerable module containing HTML and script code and send this link to a vulnerable user. When the user follows the link, the attacker-supplied code renders in the user's browser.

An SQL injection issue exists in the application as well. This issue affects a parameter of the calendar module script. This issue may be exploited to cause sensitive information to be disclosed to a remote attacker.

Finally, a HTML Injection vulnerability is reported to affect the application. The problem is said to occur in the notes module due to a lack of sufficient sanitization performed on user supplied data.

Attackers may potentially exploit this issue to manipulate web content, take unauthorized site actions in the context of the victim, or to steal cookie-based authentication credentials.

These vulnerabilities were reported in phpWebsite 0.9.3-4, previous versions are also reported to be vulnerable.

12. Opera Web Browser Empty Embedded Object JavaScript Denial Of...
BugTraq ID: 11090
Remote: Yes
Date Published: Sep 01 2004
Relevant URL: http://www.securityfocus.com/bid/11090
Summary:
Opera is a web browser available for a number of platforms, including Microsoft Windows, Linux and Unix variants and Apple MacOS.

Opera Web Browser is reported to be susceptible to a JavaScript denial of service vulnerability. This vulnerability presents itself when Opera attempts to execute a specific JavaScript command. Upon executing this command, Opera will reportedly crash.

This vulnerability was reported to exist in version 7.23 of Opera for Microsoft Windows. Other versions are also likely affected. Version 7.54 does not seem to be susceptible.

13. Kerio Personal Firewall Application Security Bypass Vulnerab...
BugTraq ID: 11096
Remote: No
Date Published: Sep 02 2004
Relevant URL: http://www.securityfocus.com/bid/11096
Summary:
A vulnerability is reported to affect Kerio Personal Firewall (KPF) 'Application Security' functionality that could permit an executable that is run by an administrator to disable KPF 'Application Security' functionality.

It is reported that (KPF) 'Application Security' functionality employs a modified Service Description Table in order to function. It is possible to restore the Service Description Table to its original state. A malicious application that is run by an administrator can read an intact SDT table from kernel memory and restore the SDT table in the running kernel by writing to kernel memory space. This will disable Kerio Personal Firewall (KPF) 'Application Security' functionality.

14. Altnet ADM ActiveX Control Remote Buffer Overflow Vulnerabil...
BugTraq ID: 11101
Remote: Yes
Date Published: Sep 03 2004
Relevant URL: http://www.securityfocus.com/bid/11101
Summary:
Altnet is reported prone to a remote buffer overflow vulnerability.  This issue presents itself in an ActiveX control installed by the application. Reportedly, a malicious attacker can exploit this issue to execute arbitrary code.

15. Ipswitch IMail Server Multiple Buffer Overflow Denial Of Ser...
BugTraq ID: 11106
Remote: Yes
Date Published: Sep 03 2004
Relevant URL: http://www.securityfocus.com/bid/11106
Summary:
It is reported that IMail is susceptible to multiple buffer overflow denial of service vulnerabilities.

These vulnerabilities allow a remote attacker to crash the affected application, denying service to legitimate users. It is conjectured that it may be possible for an attacker to execute arbitrary code in the context of the affected server application.

Versions of the application prior to 8.13 are reported affected by these vulnerabilities.

16. Nullsoft Winamp ActiveX Control Remote Buffer Overflow Vulne...
BugTraq ID: 11107
Remote: Yes
Date Published: Sep 03 2004
Relevant URL: http://www.securityfocus.com/bid/11107
Summary:
Nullsoft Winamp ActiveX Control is alleged to be prone to a remote buffer overflow vulnerability.  This issue presents itself in an ActiveX control installed by the application. Reportedly, a malicious attacker can exploit this issue to execute arbitrary code.

17. Ipswitch WhatsUp Gold Notification Instance Name Remote Buff...
BugTraq ID: 11109
Remote: Yes
Date Published: Sep 03 2004
Relevant URL: http://www.securityfocus.com/bid/11109
Summary:
The Ipswitch WhatsUp Gold web interface is prone to a remotely exploitable buffer overflow vulnerability.  This may be exploited by authenticated users of the interface to execute arbitrary code in the context of the program.

18. Ipswitch WhatsUp Gold prn.htm Denial Of Service Vulnerabilit...
BugTraq ID: 11110
Remote: Yes
Date Published: Sep 04 2004
Relevant URL: http://www.securityfocus.com/bid/11110
Summary:
Ipswitch WhatsUp Gold is prone to a remotely exploitable denial of service vulnerability when handling certain HTTP GET requests to the web interface by authenticated users.

19. Keene Digital Media Server Cross-Site Scripting Vulnerabilit...
BugTraq ID: 11111
Remote: Yes
Date Published: Sep 04 2004
Relevant URL: http://www.securityfocus.com/bid/11111
Summary:
Keene Digital Media Server is prone to multiple cross-site scripting vulnerabilities.  These issues span multiple scripts.  The source of the problem is that affected scripts do not sufficiently sanitize externally supplied data before rendering it to a client user.  An attacker may exploit these issues by enticing a victim user to follow a malicious link.

These issues could be exploited to steal cookie-based authentication credentials or launch other attacks.

20. Keene Digital Media Server Admin Authentication Bypass Vulne...
BugTraq ID: 11112
Remote: Yes
Date Published: Sep 04 2004
Relevant URL: http://www.securityfocus.com/bid/11112
Summary:
Keene Digital Server is prone to an authentication bypass vulnerability.  It is reported that remote unprivileged user may access administration pages without needing to authenticate as an administrator.  

This may allow for unauthorized administrative actions.

This issue appears similar to one of the issues described in BID 10933 "Keene Digital Media Server Directory Traversal and Authentication Bypass Vulnerabilities".

III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. XP-SP2 "Feature" (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/374466

2. Windows/Exchange security auditing tool (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/374451

3. SecurityFocus Microsoft Newsletter #204 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/373692

IV. NEW PRODUCTS FOR MICROSOFT PLATFORMS
----------------------------------------
1. Firewall RuleMaker
By: The Net Memetic Pte Ltd
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Relevant URL: http://firewall.rulemaker.net
Summary: 

Firewall RuleMaker is a Windows-based firewall configuration version control software product for managers of Cisco PIX and Netscreen firewalls.

2. CAT Cellular Authentication Token and eAuthentication Servic...
By: Mega AS Consulting Ltd
Platforms: Java, Linux, OpenBSD, Os Independent, SecureBSD, Solaris, UNIX, Windows 2000, Windows NT
Relevant URL: http://www.megaas.co.nz
Summary: 

Low cost, easy to use Two Factor Authentication One Time Password token using the Cellular. Does not use SMS or communication, manages multiple OTP accounts - new technology. For any business that want a safer access to its Internet Services. More information at our site.
 
We also provide eAuthentication service for businesses that will not buy an Authentication product but would prefer to pay a monthly charge for authentication services from our our CAT Server.

3. KeyCaptor Keylogger
By: Keylogger Software
Platforms: MacOS, Windows 2000, Windows 95/98, Windows NT, Windows XP
Relevant URL: http://www.keylogger-software.com/keylogger/keylogger.htm
Summary: 

KeyCaptor is your solution for recording ALL keystrokes of ALL users on your computer!  Now you have the power to record emails, websites, documents, chats, instant messages, usernames, passwords, and MUCH MORE!

With our advanced stealth technology, KeyCaptor will not show in your processes list and cannot be stopped from running unless you say so!

4. SpyBuster
By: Remove Spyware
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Relevant URL: http://www.remove-spyware.com/spybuster.htm
Summary: 

Our award winning spyware / adware scanner and removal software, SpyBuster will scan your computer for over 4,000 known spyware and adware applications. SpyBuster protects your computer from data stealing programs that can expose your personal information.

SpyBuster scanning technology allows for a quick and easy sweep, so you can resume your work in minutes.

5. FreezeX
By: Faronics Technologies USA Inc
Platforms: Windows 2000, Windows 95/98, Windows XP
Relevant URL: http://www.faronics.com/html/Freezex.asp
Summary: 

FreezeX prevents all unauthorized programs, including viruses, keyloggers and spy ware from executing. Powerful and secure, FreezeX ensures that any new executable, program, or application that is downloaded, introduced via removable media or the network will never install

6. NeoExec for Active Directory
By: NeoValens
Platforms: Windows 2000, Windows XP
Relevant URL: http://www.neovalens.com
Summary: 

NeoExec® is an operating system extension for Windows 2000/XP that allows the setting of privileges at the application level rather than at the user level.

NeoExec® is the ideal solution for applications that require elevated privileges to run as the privileges are granted to the application, not the user.

NeoExec® is the only solution on the market capable of modifying at runtime the processes' security context -- without requiring a second account as with RunAs and RunAs-derived products.

V. NEW TOOLS FOR MICROSOFT PLATFORMS
------------------------------------
1. Attack Tool Kit (ATK) 2.0
By: Marc Ruef
Relevant URL: http://www.computec.ch/projekte/atk/
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary: 

The acronym ATK stands for Attack Tool Kit. It was first developed to provide a very small and handy tool for Windows to realize fast checks for dedicated vulnerabilities. The special thing about ATK is that the tool is able to do the work without great interaction. But there is also always the possibility to vary and change the behaviour of the software. This concern the plugins, checking, enumeration and reporting.

2. FREEping - Server pinging 1.0
By: Tools4Ever
Relevant URL: http://www.tools4ever.com/products/free/freeping/
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary: 

Free graphical ping utility with built-in statistics, background pinging and popup notification.

3. Softros LAN Messenger 3.4
By: Softros Systems Inc
Relevant URL: http://messenger.softros.com
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary: 

Softros LAN Messenger is a instant LAN messaging software for home or office users. It does not require a server and is very easy to install and use.

With current version you will be able to:
1. Send and receive private messages.
2. Send and receive group messages.
3. Send and receive files.
4. Restrict Messenger's functions to users.

4. Healthmonitor 1.9
By: Vittorio Pavesi
Relevant URL: http://healthmonitor.sourceforge.net
Platforms: Windows 2000, Windows NT, Windows XP
Summary: 

HealthMonitor is a free powerful and featureful monitoring tool for Windows.
It works as a Windows Service and check system status (event viewer, disk free space, services status, performance....) and notify the administration by E-Mail or by NET SEND; a database logging feature is also available. It is under constant development, and releases are usually frequent. The latest news regarding HealthMonitor can be found on Sourceforge.

5. Mutilate File Wiper 2.90
By: Craig Christensen, [email protected]
Relevant URL: http://mutilatefilewiper.com
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary: 

Delete your sensitive files permanently. Mutilate File Wiper prevents recovery of deleted files from your hard drive by data recovery or forensic software. Choose one of three security levels or configure a customizable level for up to 297 overwrite passes. Mutilate supports complete folder shredding including subfolders. With Mutilate's disk free space wiper, you can even use Mutilate to permanently erase previously deleted files on your hard drive.

6. K-MAC 1.0.0.4
By: M. Neset KABAKLI
Relevant URL: http://www.neset.com
Platforms: Windows 2000, Windows NT, Windows XP
Summary: 

K-MAC is an ethernet MAC address changer for Windows. It's very useful for dealing with MAC filters and other MAC based controls.

VI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.
    
VII. SPONSOR INFORMATION
-----------------------

This issue sponsored by: Qualys

Can you find every rogue device on your network?
 
Entry points into your network aren't always obvious. FreeMap finds access
points to the discovered network by accurately characterizing devices,
including: access gateways, routers or other types of equipment. 

Take advantage of this free tool! There's nothing to install or buy. Click
on the link below to run your FreeMap.
http://www.securityfocus.com/sponsor/Qualys_ms-secnews_040907

------------------------------------------------------------------------