SecurityFocus Microsoft Newsletter #93

John Boletta <[email protected]> Mon, 1 Jul 2002 11:51:14 -0600 (MDT)
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #93
--------------------------------------

This newsletter is sponsored by: SecurityFocus DeepSight Threat Management
System

From June 24th - August 31st, 2002, SecurityFocus announces a FREE
two-week trial of the DeepSight Threat Management System: the only early
warning system providing customizable and comprehensive early warning of
cyber attacks and bulletproof countermeasures to prevent attacks before
they hit your network.

With the DeepSight Threat Management System, you can focus on proactively
deploying prioritized and specific patches to protect your systems from
attacks, rather than reactively searching dozens of Web sites or hundreds
of emails frantically trying to gather information on the attack and how
to recover from it.

Sign up today!

http://www.securityfocus.com/corporate/products/promo/tmstrial-ms.shtml

-------------------------------------------------------------------------------

I. FRONT AND CENTER
     1. Black Hat Briefings & Training
     2. No Stone Unturned, Part Five
     3. Irresponsible Disclosure
     4. The Domestic Spying Renaissance
II. MICROSOFT VULNERABILITY SUMMARY
     1. YaBB Invalid Topic Error Page Cross Site Scripting Vulnerability
     2. BEA Systems WebLogic Access Controls Bypass Vulnerability
     3. Apache Tomcat Null Character Malformed Request Denial Of...
     4. Pirch IRC Client Malformed Link Denial of Service Vulnerability
     5. GameCheats Advanced Web Server Malformed HTTP Request Denial Of...
     6. DPGS Form Field Input Validation Vulnerability
     7. Working Resources BadBlue EXT.DLL Cross Site Scripting...
     8. SalesCart Shop.MDB Customer Database Disclosure Vulnerability
     9. Microsoft Internet Explorer CLASSID Denial of Service...
     10. APC PowerChute Plus Insecure Shared Folder Permission...
     11. PHPSquidPass Index.PHP Unauthorized User Deletion Vulnerability
     12. Caucho Technology Resin Server Example Servlet Path Disclosure...
III. MICROSOFT FOCUS LIST SUMMARY
     1. secedit.sdb behavior in W2K (Thread)
     2. SecurityFocus Microsoft Newsletter #92 (Thread)
     3. Null session and Exchange2K (Thread)
     4. Locking Down Windows 2000 Workstation (Thread)
     5. Microsoft Software Update Services (Thread)
IV. MICROSOFT PRODUCTS
     1. East-Tec FormatSecure
     2. IronMail
     3. AiS AliveProxy Professional
V.  MICROSOFT TOOLS
     1. Toolkit for OpenSSH Key Administration v0.5 beta
     2. rc5pipe v1.1
     3. IDScenter v1.09 b2
     4. Apache Chunked Scanner v1.0.0
VI. SPONSORSHIP INFORMATION





I. FRONT AND CENTER
-------------------
1. Black Hat Briefings & Training

Attend Black Hat Briefings & Training, July 29 - August 1, Las Vegas, the
world's premier technical security event! 8 tracks, 12 training sessions,
Richard Clarke keynote, 1500 delegates from 30 nations, with a near cult
following of both CSOs and "underground" security experts.  See for
yourself what the buzz is all about.

Visit us at: http://www.blackhat.com

2. No Stone Unturned, Part Five
by H. Carvey

This is the fifth and final installment of a five-part series describing
the (mis)adventures of a sysadmin named Eliot and his haphazard journey in
discovering "The Way" of incident response. As we left off last time,
Eliot had started putting together a toolkit to help with incident
response and analysis. He had had an opportunity to give the kit a quick
test and had been satisfied with the results, but the toolkit was not
quite finished.

http://online.securityfocus.com/infocus/1597

3. Irresponsible Disclosure
By Jon Lasser

Internet Security Systems violated community standards and common sense
with its surprise Apache bug announcement.

http://online.securityfocus.com/columnists/91

4. The Domestic Spying Renaissance
By Mark Rasch

Earlier this month, Attorney General Ashcroft announced that he was
essentially removing the shackles from the FBI, and permitting agents to
engage in surveillance -- including certain Internet surveillance -- of
political, social or ethnic groups, without either probable cause or
reasonable suspicion that any of these groups had been or were likely to
be engaged in any form of criminal activity.

http://online.securityfocus.com/columnists/90


II. BUGTRAQ SUMMARY
-------------------
1. YaBB Invalid Topic Error Page Cross Site Scripting Vulnerability
BugTraq ID: 5078
Remote: Yes
Date Published: Jun 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5078
Summary:

YaBB (Yet Another Bulletin Board) is freely available web forum software
that is written in Perl. YaBB will run on most Unix/Linux variants, MacOS,
and Microsoft Windows 9x/ME/NT/2000/XP platforms.

It is possible for attackers to construct a URL that will cause scripting
code to be embedded in error pages.

YaBB fails to check URLs for the presence of script commands when
generating error pages, allowing attacker supplied code to execute. As a
result, when an innocent user follows such a link, the script code will
execute within the context of the hosted site.

Successful exploitation of this vulnerability could enable an attacker to
execute code in the security context of a trusted site. This vulnerability
may be exploited to steal cookie-based authentication credentials from
legitimate users of YaBB.

It should be noted that this issue was tested on YaBB 1 Gold SP1, other
versions may also be affected by this issue.

2. BEA Systems WebLogic Access Controls Bypass Vulnerability
BugTraq ID: 5089
Remote: Yes
Date Published: Jun 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5089
Summary:

BEA Systems WebLogic Server is a web and wireless application server for
Microsoft Windows and most Unix and Linux distributions.

A vulnerability has been announced in WebLogic. A remote attacker may
bypass access control measures, and view restricted resources. This may be
accomplished by submitting a maliciously constructed URL for the resource
in question to the WebLogic server.

Access control measures may be bypassed if the URL requested contains
multiple forward slashes (/) immediately before the protected resource.
Exploitation of this vulnerability may allow a remote attacker access to
sensitive JSP or servlet pages.

3. Apache Tomcat Null Character Malformed Request Denial Of Service Vulnerability
BugTraq ID: 5067
Remote: Yes
Date Published: Jun 20 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5067
Summary:

Apache Tomcat is a freely available, open source web server maintained by
the Apache Foundation. It is available for use on Unix and Linux variants
as well as Microsoft Windows operating environments.

A vulnerability has been reported for Apache Tomcat 4.0.3 on a Microsoft
Windows platform. Reportedly, it is possible for a remote attacker to make
requests consisting of a large number of null characters to Tomcat that
will cause the web service to stop responding.

An attacker needs to make approximately 75 requests, consisting of a large
number of null characters, to the web service. This will exhaust all
available threads for Tomcat leading to the denial of service condition.

An attacker may take advantage of this vulnerability to deny service to
legitimate users.

4. Pirch IRC Client Malformed Link Denial of Service Vulnerability
BugTraq ID: 5079
Remote: Yes
Date Published: Jun 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5079
Summary:

Pirch IRC is an internet relay chat client designed for Microsoft Windows
environments. Pirch is subject to a denial of service.

Reportedly, this issue results due to the way Pirch handles malformed
links.

If a link containing arbitrary data is sent to an IRC user using Pirch,
upon accessing the link, it is possible that the client will stop
responding. This issue may be the result of an unchecked buffer. If this
is the case, there is a possibility that arbitrary code may be executed on
the vulnerable target. However, this has not yet been confirmed.

It should be noted that malicious links used to exploit this issue could
be links to other IRC channels, websites etc.

In addition, this condition has been reported to arise when links with a
large number of elements are processed. For example, a long sequence of
channel names may be transmitted in a channel, or as part of a private
conversation. Further technical details are not available at this time.

This issue was reported to exist in Pirch 98, earlier versions may also be
susceptible to this issue.

5. GameCheats Advanced Web Server Malformed HTTP Request Denial Of Service Vulnerability
BugTraq ID: 5080
Remote: Yes
Date Published: Jun 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5080
Summary:

Advanced Web Server Professional is a web server developed by GameCheats.
It is freely available for use on the Microsoft Windows operating
environment.

Reportedly, version 1.030000 of the web server is prone to a denial of
service condition when servicing malformed requests. The vulnerability
occurs when various invalid HTTP requests are made to the web server.

A remote attacker needs to make approximately 100 invalid HTTP requests to
the web server. This will exhaust all available threads for Tomcat leading
to the denial of service condition.

Reportedly, requests consisting of only a single carriage return / line
feed sequence are sufficient to exploit this vulnerability.

An attacker may take advantage of this vulnerability to deny service to
legitimate users.

6. DPGS Form Field Input Validation Vulnerability
BugTraq ID: 5081
Remote: Yes
Date Published: Jun 21 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5081
Summary:

Duma Photo Gallery System (DPGS) is web-based software for managing
photographs.  It is written in Perl and will run on most Unix and Linux
variants as well as Microsoft Windows operating systems.

DPGS does not sufficiently validate form field input.  Specifically, this
vulnerability is due to insufficient filtering of input supplied to the
Perl open() function.  This may allow remote attackers to disclose the
contents of arbitrary web-readable files via directory traversals.
Requesting a web-readable file by supplying a relative path to the file
using dot-dot-slash sequences (../) is all that is required to exploit
this issue.

It has also been reported that this lack of sufficient input validation
may also be exploited to overwrite any files which are writeable by the
webserver process.  This is due to insufficient filtering of null
characters (\0) from the same form fields that are affected by the file
disclosure issue.

Exploitation of this vulnerability may be extended to affect arbitrary
system files on some webservers running under Microsoft Windows, if the
webserver is run with SYSTEM privileges.

It should be noted that DPGS is no longer being maintained, so a
vendor-supplied fix is unlikely.

7. Working Resources BadBlue EXT.DLL Cross Site Scripting Vulnerability
BugTraq ID: 5086
Remote: Yes
Date Published: Jun 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5086
Summary:

BadBlue is a P2P file sharing application distributed by Working
Resources.  It is designed for use on Microsoft Windows operating systems.

A problem with the application could make it possible to launch a
cross-site scripting attack.

When started, BadBlue launches a web server on a client system.  When a
user executes a search using the search interface provided with BadBlue,
the ext.dll library is used by BadBlue to handle the request.  This
interface may be reached by users of the local system, as well as remote
users.

The ext.dll library does not sufficiently sanitize input.  Because of
this, it is possible for a user to create a custom URL containing script
code that, when viewed in a browser by another user, will result in the
execution of the script code.  This could allow for the execution of
malicious javascript in the context of a trusted site.

This problem makes it possible to execute javascript in the context of an
arbitrary BadBlue server.

8. SalesCart Shop.MDB Customer Database Disclosure Vulnerability
BugTraq ID: 5087
Remote: Yes
Date Published: Jun 23 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5087
Summary:

SalesCart is an E-Commerce package designed to integrate Microsoft
FrontPage with an online shopping cart system.  It is available for
Microsoft operating systems.

A problem with SalesCart could lead to the disclosure of sensitive
information.

SalesCart does not sufficiently secure customer information.  When a user
accesses the site and enters personal information, the data is stored in
the shop.mdb file.  This file may be accessed by remote users.

This problem could result in a disclosure of sensitive information, such
as name, company name, address, e-mail address, phone number, and credit
card number.  This data has been discovered to be stored in the following
locations accessible from the web:

http://www.example.com/fpdb/shop.mdb
http://www.example.com/shoponline/fpdb/shop.mdb

9. Microsoft Internet Explorer CLASSID Denial of Service Vulnerability
BugTraq ID: 5094
Remote: Yes
Date Published: Jun 25 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5094
Summary:

Microsoft Internet Explorer contains a vulnerability that may allow for
malicious webmasters to cause a visitor's web browser to stop responding.

A CLASSID is a unique identifier that provides information to the default
COM handler. It is possible to include a CLASSID value as part of an
OBJECT tag under some versions of Internet Explorer.

If a web page contains a specific CLASSID value and an IE user attempts to
view the page, IE has been reported to crash. The reported offending
CLASSID is CLSID:00022613-0000-0000-C000-000000000046, however there may
be other CLASSID values which could exploit this issue.

This issue has been reported to occur when vulnerable versions of Internet
Explorer are running under Windows 2000 or XP. It is not currently known
if this issue is related to properties of the underlying operating system.

A restart of the browser may be required in order to regain normal
functionality.

10. APC PowerChute Plus Insecure Shared Folder Permission Vulnerability
BugTraq ID: 5069
Remote: Yes
Date Published: Jun 20 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5069
Summary:

APC PowerChute PLUS is a software package that will safely shutdown
computer systems locally or accross a network when UPS power starts to
fail. It is intended for use with Unix and Linux variant as well as
Microsoft Windows operating environments.

A vulnerability has been reported for PowerChute PLUS 5.0.2 for use with
Microsoft Windows. PowerChute Plus installs to the 'Program
Files\Pwrchute' folder. It also enables the installation folder to be
shared as PWRCHUTE with world writeable permissions without any user
notification.

If file sharing is enabled on these machines, remote attackers have access
to the shared folder. This may enable attackers install various tools to
compromise the vulnerable system or use it as a site for attacks against
other systems. If the PowerChute binaries are trojaned or replaced with a
backdoor, they may be inadvertently executed by legitimate users of the
system.

11. PHPSquidPass Index.PHP Unauthorized User Deletion Vulnerability
BugTraq ID: 5090
Remote: Yes
Date Published: Jun 24 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5090
Summary:

phpSquidPass is a tool designed for users to change user authentication
files for the squid web proxy. It is implemented in PHP and should be
available for use with Unix and Linux variants as well as Microsoft
Windows operating environments.

phpSquidPass may allow a malicious user of the system to overwrite
additional accounts. When a password is updated, the proxy_users file is
searched for the provided username, and that account is updated. Due to an
error in the program, usernames ending with the supplied username will
also be modified. In this case, both the username and password are
overwritten.

This effectively deletes the additional account. A malicious user may be
able to take advantage of this vulnerability to create a denial of service
condition for other users of the system. The ability to exploit this
vulnerability is, however, dependant on the possession of a valid user
account which is a substring of another username.

12. Caucho Technology Resin Server Example Servlet Path Disclosure Vulnerability
BugTraq ID: 5095
Remote: Yes
Date Published: Jun 25 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5095
Summary:

A vulnerability has been reported in Resin Server, deployed on a Microsoft
Windows platform, that may allow remote attackers to view sensitive path
information.

Caucho Technology's Resin ships with a number of java servlets which may
reveal sensitive path information. Submitting a HTTP request for some
servlets, will return a page revealing the absolute path to the servlet
installation. This behavior has been reported in the HelloServlet servlet,
included in the examples directory.

This information will give the attacker filesystem structure information
of the host running Resin. Disclosure of this type of sensitive
information may aid in further attacks against the host running the
vulnerable software.

This issue has been reported in Resin 2.0.5 - 2.1.2.


III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. secedit.sdb behavior in W2K (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

2. SecurityFocus Microsoft Newsletter #92 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/6AA3020BB6C49E4EBDB055884742533201AA14@dieppe.calgary.securityfocus.com

3. Null session and Exchange2K (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/7DDAF43D1E128F45A30CB40978B67948D9D0AE@pgamh02.venturipartners.com

4. Locking Down Windows 2000 Workstation (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAAEMtrQbCw6UWlUXn1i/[email protected]

5. Microsoft Software Update Services (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]


IV.NEW PRODUCTS FOR MICROSOFT PLATFORMS
----------------------------------------
1. East-Tec FormatSecure
by EAST Technologies
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Relevant URL:
http://www.east-tec.com/erprod/formatsc/index.htm
Summary:

East-Tec FormatSecure, in addition to formatting the drive, will securely
wipe the entire contents of the drive in order to stop software and
hardware tools from recovering any data. East-Tec FormatSecure is a
component of our family of products designed for the entire family of
Windows operating systems (Windows 95/98/Me/NT/2000/XP) to completely
eliminate sensitive data from your computer.

2. IronMail
by CipherTrust
Platforms: N/A
Relevant URL:
http://www.ciphertrust.com/ironmail/index.htm
Summary:

Designed as a single-purpose security appliance, IronMail sits between
your network firewall and your mail servers. IronMail augments your
general-purpose network firewall by adding a second layer of
email-specific protection. Developed to support leading mail servers and
mail clients, IronMail acts as armor for your mail server(s), preventing
attacks and intrusion.

3. AiS AliveProxy Professional
by AtomInterSoft
Platforms: Windows 2000, Windows 95/98, Windows NT
Relevant URL:
http://www.atomintersoft.com/products/alive-proxy/
Summary:

AiS AliveProxy Pro extracts proxy servers addresses from specified
Internet pages, or files, checks the type (transparent or anonymous), and
measures connection speed, tracerout and timeout. Result of its work is a
list of "alive" proxies, without duplicates. High-efficiency
multy-threaded engine allow you to check more than 100 proxy per second.
High-speed export proxy from URLs or files. Export/Import data from/to
XML,Excel, TXT, HTML, RTF


V.  MICROSOFT TOOLS
-------------------
1. Toolkit for OpenSSH Key Administration v0.5 beta
by Gianugo Rabellino
Relevant URL:
http://toska.sourceforge.net
Platforms: Os Independent
Summary:

TOSKA (Toolkit for OpenSSH Key Administration) provides a way for network
administrators to centralize their SSH key management. It can manage a
database of public keys via a GUI (and an upcoming command line
interface), dynamically enabling on a per-key, per-user, and per-host
basis.

2. rc5pipe v1.1
by Doug
Relevant URL:
http://online.securityfocus.com/tools/2730
Platforms: UNIX, Windows 2000, Windows 95/98, Windows NT
Summary:

rc5pipe is a security program for encrypting and decrypting text via UNIX
pipes. It uses the 128-bit RC5 encryption algorithm and takes advantage of
padding, and is especially useful if combined with netcat.

3. IDScenter v1.09 b2
by Ueli Kistler
Relevant URL:
http://www.packx.net/packx/html/en/idscenter/index-idscenter.htm
Platforms: Windows 2000, Windows 95/98, Windows NT
Summary:

Snort IDScenter is a GUI for Snort IDS on Windows platforms. Configuration
and management of the IDS can be done using IDScenter. Main features are:
- Snort configuration wizard (variables, preprocessor plugins, output
plugins, rulesets)  - Alert notification via e-mail, sound or only visual
notification - Alert file monitoring (up to 10 files)  - MySQL alert
detection - Log rotation (compressed archiving of log files)  - AutoBlock
(using NetworkICE BlackICE Defender you can block attackers IP's that
Snort logged)  - Integrated log viewer (supports text files, XML and
HTML/webpages)  - Program execution if an attack was detected - Test
configuration feature: fast testing of your IDS configuration, and more .

4. Apache Chunked Scanner v1.0.0
by eEye Digital Security
Relevant URL:
http://www.eeye.com/html/Research/Tools/apachechunked.html
Platforms: N/A
Summary:

The Retina Apache Chunked Scanner is a tool created by eEye that is able
to scan up to 254 IP addresses at once and determine if any are vulnerable
to the recent Apache Chunked Encoding overflow. If an IP address is found
to be vulnerable to the Apache Chunked Encoding attack, then the Retina
Apache Chunked Scanner will flag the IP address. Administrators can then
double-click on the IP address to be taken to a website with information
on how to fix the vulnerability.


VI. SPONSORSHIP INFORMATION
---------------------------
This newsletter is sponsored by: SecurityFocus DeepSight Threat Management
System

From June 24th - August 31st, 2002, SecurityFocus announces a FREE
two-week trial of the DeepSight Threat Management System: the only early
warning system providing customizable and comprehensive early warning of
cyber attacks and bulletproof countermeasures to prevent attacks before
they hit your network.

With the DeepSight Threat Management System, you can focus on proactively
deploying prioritized and specific patches to protect your systems from
attacks, rather than reactively searching dozens of Web sites or hundreds
of emails frantically trying to gather information on the attack and how
to recover from it.

Sign up today!

http://www.securityfocus.com/corporate/products/promo/tmstrial-ms.shtml

-------------------------------------------------------------------------------