SecurityFocus Microsoft Newsletter #206
Peter Laborge <[email protected]> 14 Sep 2004 21:00:39 -0000
| Newsgroups | gmane.comp.security.news.microsoft |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Microsoft Newsletter #206
----------------------------------------
This Issue is Sponsored By: SecurityFocus
Want to keep up on the latest security vulnerabilities? Don't have time to
visit a myriad of mailing lists and websites to read the news? Just add the
new SecurityFocus RSS feeds to your freeware RSS reader, and see all the
latest posts for Bugtraq and the SF Vulnernability database in one
convenient place. Or, pull in the latest news, columnists and feature
articles in the SecurityFocus aggregated news feed, and stay on top of
what's happening in the community!
http://www.securityfocus.com/rss/index.shtml
------------------------------------------------------------------------
I. FRONT AND CENTER
1. Metasploit Framework, Part 3
2. I Spy With My Little Eye
II. MICROSOFT VULNERABILITY SUMMARY
1. Ipswitch WhatsUp Gold Notification Instance Name Remote Buff...
2. Ipswitch WhatsUp Gold prn.htm Denial Of Service Vulnerabilit...
3. Keene Digital Media Server Cross-Site Scripting Vulnerabilit...
4. Keene Digital Media Server Admin Authentication Bypass Vulne...
5. UtilMind Solutions Site News Authentication Bypass Vulnerabi...
6. eZ/eZphotoshare Remote Denial Of Service Vulnerability
7. Cerulean Studios Trillian Client MSN Module Remote Buffer Ov...
8. Ulrik Petersen Emdros Database Engine Denial Of Service Vuln...
9. F-Secure Content Scanner Server Remote Denial of Service Vul...
10. Gearbox Software Halo Combat Evolved Game Server Remote Deni...
11. GetSolutions GetIntranet Multiple Remote Input Validation Vu...
12. GetSolutions GetInternet Multiple SQL Injection Vulnerabilit...
13. OpenOffice/StarOffice Local File Disclosure Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
1. RKDetect - behaviour based rootkit detection (update... (Thread)
2. Windows/Exchange security auditing tool (Thread)
3. How to Recovering files encrypted with Microsoft EFS... (Thread)
4. Windows2000 Security events (Thread)
5. Listing usernames via a null session on Windows XP (Thread)
6. XP-SP2 "Feature" (Thread)
7. Network Monitor/sniffer (Thread)
8. FW: Network Monitor/sniffer (Thread)
IV. NEW PRODUCTS FOR MICROSOFT PLATFORMS
1. Firewall RuleMaker
2. CAT Cellular Authentication Token and eAuthentication Servic...
3. KeyCaptor Keylogger
4. SpyBuster
5. FreezeX
6. NeoExec for Active Directory
V. NEW TOOLS FOR MICROSOFT PLATFORMS
1. IP Firewall Hook ATL/COM 1.2
2. IP Firewall Lite ATL/COM 1.2
3. Password Generator 2004 1.2.1628
4. Attack Tool Kit (ATK) 2.0
5. FREEping - Server pinging 1.0
6. Softros LAN Messenger 3.4
VI. UNSUBSCRIBE INSTRUCTIONS
VII. SPONSOR INFORMATION
I. FRONT AND CENTER
-------------------
1. Metasploit Framework, Part 2
By Pukhraj Singh and K.K. Mookhey
This third and final article in the Metasploit series covers the msfcli
scripting interface as well as the intuitive web interface to the
Framework. The article also discusses what's new with version 2.2, and then
introduces the exploit development process through an example.
http://www.securityfocus.com/infocus/1800
2. I Spy With My Little Eye
By Mark Rasch
Forget Congress' myopic efforts to outlaw spyware. What we really need is
better enforcement of existing computer crime laws.
http://www.securityfocus.com/columnists/266
II. MICROSOFT VULNERABILITY SUMMARY
-----------------------------------
1. Ipswitch WhatsUp Gold Notification Instance Name Remote Buff...
BugTraq ID: 11109
Remote: Yes
Date Published: Sep 03 2004
Relevant URL: http://www.securityfocus.com/bid/11109
Summary:
The Ipswitch WhatsUp Gold web interface is prone to a remotely exploitable buffer overflow vulnerability. This may be exploited by authenticated users of the interface to execute arbitrary code in the context of the program.
2. Ipswitch WhatsUp Gold prn.htm Denial Of Service Vulnerabilit...
BugTraq ID: 11110
Remote: Yes
Date Published: Sep 04 2004
Relevant URL: http://www.securityfocus.com/bid/11110
Summary:
Ipswitch WhatsUp Gold is prone to a remotely exploitable denial of service vulnerability when handling certain HTTP GET requests to the web interface by authenticated users.
3. Keene Digital Media Server Cross-Site Scripting Vulnerabilit...
BugTraq ID: 11111
Remote: Yes
Date Published: Sep 04 2004
Relevant URL: http://www.securityfocus.com/bid/11111
Summary:
Keene Digital Media Server is prone to multiple cross-site scripting vulnerabilities. These issues span multiple scripts. The source of the problem is that affected scripts do not sufficiently sanitize externally supplied data before rendering it to a client user. An attacker may exploit these issues by enticing a victim user to follow a malicious link.
These issues could be exploited to steal cookie-based authentication credentials or launch other attacks.
4. Keene Digital Media Server Admin Authentication Bypass Vulne...
BugTraq ID: 11112
Remote: Yes
Date Published: Sep 04 2004
Relevant URL: http://www.securityfocus.com/bid/11112
Summary:
Keene Digital Server is prone to an authentication bypass vulnerability. It is reported that remote unprivileged user may access administration pages without needing to authenticate as an administrator.
This may allow for unauthorized administrative actions.
This issue appears similar to one of the issues described in BID 10933 "Keene Digital Media Server Directory Traversal and Authentication Bypass Vulnerabilities".
5. UtilMind Solutions Site News Authentication Bypass Vulnerabi...
BugTraq ID: 11126
Remote: Yes
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11126
Summary:
Reportedly UtilMind Solutions Site News is affected by an authentication bypass vulnerability. This issue is due to an access validation error.
An unauthenticated attacker can leverage this issue to display and manipulate arbitrary news items.
6. eZ/eZphotoshare Remote Denial Of Service Vulnerability
BugTraq ID: 11129
Remote: Yes
Date Published: Sep 07 2004
Relevant URL: http://www.securityfocus.com/bid/11129
Summary:
eZ and eZphotoshare servers are reported prone to a remote denial of service vulnerability. A successful attacker can deny access to legitimate users of the application.
This vulnerability is reported to affect eZ version 3.4.0 and eZphotoshare version 1.2.1. Other versions might also be affected.
7. Cerulean Studios Trillian Client MSN Module Remote Buffer Ov...
BugTraq ID: 11142
Remote: Yes
Date Published: Sep 08 2004
Relevant URL: http://www.securityfocus.com/bid/11142
Summary:
Trillian is reported prone to a remote buffer overflow vulnerability. This issue occurs due to insufficient boundary checks performed by the application and may allow an attacker to execute arbitrary code on a vulnerable computer. This could ultimately lead to an attacker gaining unauthorized access to the computer.
The vulnerability affects the MSN module and requires an attacker to pose as an MSN server through means such as a man-in-the-middle attack.
Trillian version 0.74i is reported prone to this issue, however, it is likely that other versions are affected as well.
8. Ulrik Petersen Emdros Database Engine Denial Of Service Vuln...
BugTraq ID: 11143
Remote: Yes
Date Published: Sep 08 2004
Relevant URL: http://www.securityfocus.com/bid/11143
Summary:
It is reported that Emdros is prone to a denial of service vulnerability, due to a memory leak while running as a daemon.
This vulnerability is present in the 'mql' process. This process contains a memory leak, and if it is run as a daemon, a remote attacker has the ability to consume all available memory until the process crashes.
Versions prior to 1.1.20 are reported susceptible to this vulnerability.
9. F-Secure Content Scanner Server Remote Denial of Service Vul...
BugTraq ID: 11145
Remote: Yes
Date Published: Sep 09 2004
Relevant URL: http://www.securityfocus.com/bid/11145
Summary:
F-Secure Content Scanner Server is reported prone to a remote denial of service vulnerability. This issue presents itself when the application handles certain malformed packets. This vulnerability causes an unhandled exception in the process leading to a crash in the process.
F-Secure Anti-Virus for Microsoft Exchange and F-Secure Internet Gatekeeper are vulnerable to this issue.
10. Gearbox Software Halo Combat Evolved Game Server Remote Deni...
BugTraq ID: 11147
Remote: Yes
Date Published: Sep 09 2004
Relevant URL: http://www.securityfocus.com/bid/11147
Summary:
The Halo Combat Evolved game server is reported prone to a remote denial of service vulnerability.
A remote attacker may exploit this vulnerability to deny service for legitimate game players.
Patches are available to address the issue.
11. GetSolutions GetIntranet Multiple Remote Input Validation Vu...
BugTraq ID: 11149
Remote: Yes
Date Published: Sep 10 2004
Relevant URL: http://www.securityfocus.com/bid/11149
Summary:
Reportedly getSolutions getIntranet is affected by multiple remote input validation vulnerabilities. These issues are caused by a failure of the application to properly sanitize user-supplied input.
These issues may be leveraged to carry out SQL injection attacks, HTML injection attacks, arbitrary file uploads, privilege escalation, command execution in the context of the vulnerable application, and command execution in the context of the affected system.
12. GetSolutions GetInternet Multiple SQL Injection Vulnerabilit...
BugTraq ID: 11150
Remote: Yes
Date Published: Sep 10 2004
Relevant URL: http://www.securityfocus.com/bid/11150
Summary:
getInternet is vulnerable to multiple remote SQL injection vulnerabilities in the 'welcome.asp', 'checklogin.asp', and 'lostpassword.asp' scripts. These issues are due to a failure of the application to properly validate user-supplied input prior to including it in an SQL query.
An attacker may exploit these issues to manipulate and inject SQL queries onto the underlying database. It is possible to leverage this issue to steal database contents including administrator password hashes and user credentials as well as to make attacks against the underlying database.
13. OpenOffice/StarOffice Local File Disclosure Vulnerability
BugTraq ID: 11151
Remote: No
Date Published: Sep 10 2004
Relevant URL: http://www.securityfocus.com/bid/11151
Summary:
StarOffice and OpenOffice are reported prone to a local file disclosure vulnerability. This issue presents itself because the application creates insecure temporary files. Each time a user saves a file, a compressed copy of the file is saved in a temporary direcotry. This can allow a local attacker to disclose files of other users.
OpenOffice 1.1.2 and StarOffice 7.0 are reported prone to this vulnerability.
III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. RKDetect - behaviour based rootkit detection (update... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/375150
2. Windows/Exchange security auditing tool (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/375138
3. How to Recovering files encrypted with Microsoft EFS... (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/375133
4. Windows2000 Security events (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/375130
5. Listing usernames via a null session on Windows XP (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/375122
6. XP-SP2 "Feature" (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/374946
7. Network Monitor/sniffer (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/374925
8. FW: Network Monitor/sniffer (Thread)
Relevant URL:
http://www.securityfocus.com/archive/88/374870
IV. NEW PRODUCTS FOR MICROSOFT PLATFORMS
----------------------------------------
1. Firewall RuleMaker
By: The Net Memetic Pte Ltd
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Relevant URL: http://firewall.rulemaker.net
Summary:
Firewall RuleMaker is a Windows-based firewall configuration version control software product for managers of Cisco PIX and Netscreen firewalls.
2. CAT Cellular Authentication Token and eAuthentication Servic...
By: Mega AS Consulting Ltd
Platforms: Java, Linux, OpenBSD, Os Independent, SecureBSD, Solaris, UNIX, Windows 2000, Windows NT
Relevant URL: http://www.megaas.co.nz
Summary:
Low cost, easy to use Two Factor Authentication One Time Password token using the Cellular. Does not use SMS or communication, manages multiple OTP accounts - new technology. For any business that want a safer access to its Internet Services. More information at our site.
We also provide eAuthentication service for businesses that will not buy an Authentication product but would prefer to pay a monthly charge for authentication services from our our CAT Server.
3. KeyCaptor Keylogger
By: Keylogger Software
Platforms: MacOS, Windows 2000, Windows 95/98, Windows NT, Windows XP
Relevant URL: http://www.keylogger-software.com/keylogger/keylogger.htm
Summary:
KeyCaptor is your solution for recording ALL keystrokes of ALL users on your computer! Now you have the power to record emails, websites, documents, chats, instant messages, usernames, passwords, and MUCH MORE!
With our advanced stealth technology, KeyCaptor will not show in your processes list and cannot be stopped from running unless you say so!
4. SpyBuster
By: Remove Spyware
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Relevant URL: http://www.remove-spyware.com/spybuster.htm
Summary:
Our award winning spyware / adware scanner and removal software, SpyBuster will scan your computer for over 4,000 known spyware and adware applications. SpyBuster protects your computer from data stealing programs that can expose your personal information.
SpyBuster scanning technology allows for a quick and easy sweep, so you can resume your work in minutes.
5. FreezeX
By: Faronics Technologies USA Inc
Platforms: Windows 2000, Windows 95/98, Windows XP
Relevant URL: http://www.faronics.com/html/Freezex.asp
Summary:
FreezeX prevents all unauthorized programs, including viruses, keyloggers and spy ware from executing. Powerful and secure, FreezeX ensures that any new executable, program, or application that is downloaded, introduced via removable media or the network will never install
6. NeoExec for Active Directory
By: NeoValens
Platforms: Windows 2000, Windows XP
Relevant URL: http://www.neovalens.com
Summary:
NeoExec® is an operating system extension for Windows 2000/XP that allows the setting of privileges at the application level rather than at the user level.
NeoExec® is the ideal solution for applications that require elevated privileges to run as the privileges are granted to the application, not the user.
NeoExec® is the only solution on the market capable of modifying at runtime the processes' security context -- without requiring a second account as with RunAs and RunAs-derived products.
V. NEW TOOLS FOR MICROSOFT PLATFORMS
------------------------------------
1. IP Firewall Hook ATL/COM 1.2
By: Egemen Tas
Relevant URL: http://www.modemwall.com/tipfwhook.htm
Platforms: Windows 2000, Windows XP
Summary:
IP Firewall Hook is a *FREE and open source* ATL/COM component based on "Windows Firewall-Hook Driver" technology. It is a powerful packet filtering component for Windows 2000/XP. A sample application firewall is also provided with it.
2. IP Firewall Lite ATL/COM 1.2
By: Egemen Tas
Relevant URL: http://www.modemwall.com/tipfwlite.htm
Platforms: Windows 2000, Windows XP
Summary:
IP Firewall Lite is a *FREE and open source* ATL/COM component based on "Windows IP Filter Driver" technology. It is a powerful packet filtering component for Windows 2000/XP. A sample application firewall is also provided along with it.
3. Password Generator 2004 1.2.1628
By: Diplodock
Relevant URL: http://www.diplodock.com/Products/PasswordGenerator/default.aspx
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
Diplodock Password Generator 2004 is a professional, random password generator that can produce 100,000 passwords, serial numbers, registration codes, masked strings, and usernames of any length and character content in seconds. With features such as built-in dictionaries, customizable character groups, password options module, randomization settings module, word-choice, and character density controls, it is extremely flexible, and allows you to create passwords that wil
4. Attack Tool Kit (ATK) 2.0
By: Marc Ruef
Relevant URL: http://www.computec.ch/projekte/atk/
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
The acronym ATK stands for Attack Tool Kit. It was first developed to provide a very small and handy tool for Windows to realize fast checks for dedicated vulnerabilities. The special thing about ATK is that the tool is able to do the work without great interaction. But there is also always the possibility to vary and change the behaviour of the software. This concern the plugins, checking, enumeration and reporting.
5. FREEping - Server pinging 1.0
By: Tools4Ever
Relevant URL: http://www.tools4ever.com/products/free/freeping/
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
Free graphical ping utility with built-in statistics, background pinging and popup notification.
6. Softros LAN Messenger 3.4
By: Softros Systems Inc
Relevant URL: http://messenger.softros.com
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary:
Softros LAN Messenger is a instant LAN messaging software for home or office users. It does not require a server and is very easy to install and use.
With current version you will be able to:
1. Send and receive private messages.
2. Send and receive group messages.
3. Send and receive files.
4. Restrict Messenger's functions to users.
VI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
VII. SPONSOR INFORMATION
-----------------------
This Issue is Sponsored By: SecurityFocus
Want to keep up on the latest security vulnerabilities? Don't have time to
visit a myriad of mailing lists and websites to read the news? Just add the
new SecurityFocus RSS feeds to your freeware RSS reader, and see all the
latest posts for Bugtraq and the SF Vulnernability database in one
convenient place. Or, pull in the latest news, columnists and feature
articles in the SecurityFocus aggregated news feed, and stay on top of
what's happening in the community!
http://www.securityfocus.com/rss/index.shtml
------------------------------------------------------------------------