SecurityFocus Microsoft Newsletter #94
John Boletta <[email protected]> Mon, 8 Jul 2002 10:29:51 -0600 (MDT)
| Newsgroups | gmane.comp.security.news.microsoft |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Microsoft Newsletter #94
--------------------------------------
This newsletter is sponsored by: SecurityFocus DeepSight Threat Management
System
From June 24th - August 31st, 2002, SecurityFocus announces a FREE
two-week trial of the DeepSight Threat Management System: the only early
warning system providing customizable and comprehensive early warning of
cyber attacks and bulletproof countermeasures to prevent attacks before
they hit your network.
With the DeepSight Threat Management System, you can focus on proactively
deploying prioritized and specific patches to protect your systems from
attacks, rather than reactively searching dozens of Web sites or hundreds
of emails frantically trying to gather information on the attack and how
to recover from it.
Sign up today!
http://www.securityfocus.com/corporate/products/promo/tmstrial-ms.shtml
-------------------------------------------------------------------------------
I. FRONT AND CENTER
1. Clickwrap and Shrinkwrap Risks: The Security Concerns of...
2. Twenty Don'ts for ASP Developers
3. One of These Things is not Like the Others: The State of...
4. Secure i-World
5. Black Hat Briefings & Training
II. MICROSOFT VULNERABILITY SUMMARY
1. Windows Media Player Playlist HTML Script Execution Vulnerability
2. Windows Media Player WMDM Privilege Escalation Vulnerability
3. Macromedia JRun Administrative Authentication Bypass Vulnerability
4. Macromedia ColdFusion MX jrun.dll Buffer Overflow Vulnerability
5. F2HTML.PL SQL Injection Vulnerability
6. Macromedia Sitespring Database Engine Denial Of Service...
7. Macromedia JRun Source Disclosure Vulnerabilities
8. Betsie Parserl.PL Cross-Site Scripting Vulnerability
9. OmniHTTPD Long Request Buffer Overflow Vulnerability
10. AnalogX Proxy Socks4A Buffer Overflow Vulnerability
11. AnalogX Proxy Web Proxy Buffer Overflow Vulnerability
12. ArGoSoft Mail Server Directory Traversal Vulnerability
13. NEC Socks5 User Name Buffer Overflow Vulnerability
14. NEC Socks4 User Name Buffer Overflow Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
1. Strange event showing up... (Thread)
2. Replication on Sql Server 2k - Sql Server Agent Account (Thread)
3. Can I shut down individual TCP connections? (Thread)
4. SecurityFocus Microsoft Newsletter #93 (Thread)
IV. MICROSOFT PRODUCTS
1. pcProx Reader
2. Defender
3. AiS Watermark Pictures Protector
V. MICROSOFT TOOLS
1. ABC CHAOS
2. Advanced Lotus Password Recovery
3. aTrans
VI. SPONSORSHIP INFORMATION
I. FRONT AND CENTER
-------------------
1. Clickwrap and Shrinkwrap Risks: The Security Concerns of Licensing
Agreements
By Steven Robinson
This is the first of two articles that will discuss some security issues
surrounding software licenses and agreements for Web-based information
services. This article will discusses why security professionals need to
be particularly aware of some issues that these licensing agreements
present.
http://online.securityfocus.com/infocus/1602
2. Twenty Don'ts for ASP Developers
by Mark Burnett
Firewalls block hackers from directly connecting to your network shares.
Windows administrators keep their systems up-to-date with the latest
software patches to thwart worms such as Nimda and Code Red. And user
passwords are stronger than ever. But are we secure yet? While the
situation is much better than it was just a couple years ago, many
companies are still quite vulnerable to a number of attacks. Blocking
ports and installing patches has not stopped hackers, it has just forced
them to find new ways to break in. And chances are, the first place they
are going to look is your Web application.
http://online.securityfocus.com/infocus/1603
3. One of These Things is not Like the Others: The State of Anomaly
Detection
by Matthew Tanase
"To some, our observations can be summarized succinctly as "bugs happen".
That certainly is not news. But dismissing our results so cavalierly
misses the point. Yes, bugs happen. But bugs can be fixed -if they are
detected. The Internet is, as a whole, working remarkably well. Huge
software packages (i.e., X11R5) can be distributed electronically.
Connections span the globe. But the very success of the Internet makes
some bugs invisible." - Steven Bellovin
http://online.securityfocus.com/infocus/1600
4. Secure i-World
August 19-21, 2002, San Diego, CA
Optional Workshops August 17, 18, 21, & 22
Vendor Expo August 19 & 20
WebSec 2002, Online Privacy Conference, Secure i-World Expo
two innovative
conferences and one outstanding expo, all in one blockbuster event.
Please visit us at: http://www.secureiworld.com/06/sw02nl18inf.html
5. Attend Black Hat Briefings & Training
Attend Black Hat Briefings & Training, July 29 - August 1, Las Vegas, the
world's premier technical security event!
8 tracks, 12 training sessions, Richard Clarke keynote, 1500 delegates
from 30 nations, with a near cult following of both CSOs and "underground"
security experts.
See for yourself what the buzz is all about. www.blackhat.com
II. BUGTRAQ SUMMARY
-------------------
1. Windows Media Player Playlist HTML Script Execution Vulnerability
BugTraq ID: 5110
Remote: Yes
Date Published: Jun 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5110
Summary:
Microsoft Windows Media Player is distributed with multiple versions of
the Microsoft Windows Operating System. A vulnerability has been reported
affecting systems using Windows Media Player 6.4, 7.1, or Media Player for
Windows XP
A script execution vulnerability may allow an attacker to execute HTML
scripts on the system under the context of the user. These scripts can
perform any action that the user would be able to including modifying
security settings, adding and deleting files. The flaw lies in the
processing of a playlist that is saved after exiting.
Windows Media Player uses XML (Extensible Markup Language) playlists to
store information about media files. If a media file is opened with Media
Player, the associated playlist is automatically loaded into memory. After
Media Player has finished playing the media file and is shutdown, it
writes the XML playlist to a known location on the local hard drive.
Since the playlist is an XML file, it accepts HTML as input. Thus it is
possible for an attacker to cause Media Player to write malicious HTML
scripts to the local disk. This is exacerbated by the fact that Media
Player will write the malicious HTML scripts into a well known location.
An attacker can use this knowledge to execute malicious scripts on the
local machine with Local Computer security settings. Malicious scripts
will be executed with the privilege levels of the user currently logged on
to the system. The scripts are able to perform any actions that the user
is able to including modifying security settings, adding and deleting
files etc.
This vulnerability was originally described in Bugtraq ID 5107. Individual
vulnerabilities are being assigned unique Bugtraq IDs as analysis is
completed.
2. Windows Media Player WMDM Privilege Escalation Vulnerability
BugTraq ID: 5109
Remote: No
Date Published: Jun 27 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5109
Summary:
Microsoft Windows Media Player is distributed with multiple versions of
the Microsoft Windows Operating System.
A privilege escalation vulnerability has been reported that will allow an
attacker with local log-on privileges to gain access under the privilege
level of the operating system itself.
This vulnerabilty only affects Windows Media Player 7.1 on Windows 2000
systems, other Windows versions are not affected. The flaw lies in the use
by Windows Media Device Manager (WMDM). The WMDM will sometimes fail to
recognize an invalid device request. If that request is for a specific
device, WMDM processes it under the context of Local System.
This enables the attacker to have access to a local resource with Local
System privileges. An attacker can use this access to launch other
programs, add, delete or modify files and add administrators.
Direct physical access is required and Terminal service logins are not
affected by this vulnerability.
This vulnerability was originally described in Bugtraq ID 5107. Individual
vulnerabilities are being assigned unique Bugtraq IDs as analysis is
completed.
3. Macromedia JRun Administrative Authentication Bypass Vulnerability
BugTraq ID: 5118
Remote: Yes
Date Published: Jun 28 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5118
Summary:
Macromedia JRun is a J2EE application server for use with IIS 4/5 on the
Microsoft Windows operating systems.
Macromedia JRun includes a web-based administrative console which listens
on TCP port 8000. When this page is accessed, the user is prompted for an
administrative login. However, by submitting a malformed request for this
page, authentication can be bypassed.
This may be exploited by adding an extraneous '/' to a request for the
administrative authentication page. For this issue to be successfully
exploited, the attacker must make a properly formatted request for a
specific administrative function. The links on the administrative page
will just direct the attacker to the login page.
4. Macromedia ColdFusion MX jrun.dll Buffer Overflow Vulnerability
BugTraq ID: 5121
Remote: Yes
Date Published: Jun 28 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5121
Summary:
Macromedia has reported a buffer overflow condition in ColdFusion MX
server when used with Microsoft IIS.
The condition is reportedly present in `jrun.dll' and may be triggered
when malformed HTTP requests are received. The overflow occurs if a
request has HTTP header values exceeding 4096 bytes in length, or if a
template filename is greater than 8092 bytes in length.
At the very least, this condition may be exploited to cause a denial of
IIS service. Macromedia has stated that exploitation may cause IIS to
become unresponsive until it is manually restarted.
It is not yet known if attackers can exploit this vulnerability to execute
arbitrary code.
5. F2HTML.PL SQL Injection Vulnerability
BugTraq ID: 5123
Remote: No
Date Published: Jun 28 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5123
Summary:
f2html.pl is a Perl script which searches recursively through directories
looking for certain types of files, and then creates a HTML page
containing directory listings. It stores listings in a database. It will
run on most Unix and Linux variants as well as Microsoft Windows operating
systems.
The f2html.pl script does not sufficiently validate filenames before
passing them into SQL queries. In the instance that f2html.pl is used to
search a directory which may be accessible to untrusted local users, it
may be possible to launch a SQL injection attack via a maliciously crafted
filename.
An attacker may exploit this condition to modify the logic of SQL queries.
6. Macromedia Sitespring Database Engine Denial Of Service Vulnerability
BugTraq ID: 5132
Remote: Yes
Date Published: Jul 01 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5132
Summary:
Macromedia Sitespring is a J2EE compliant website production management
solution. The Macromedia Sitespring server runs on Microsoft Windows
operating systems.
A vulnerability has been reported in Macromedia Sitespring 1.2.0(277.1)
using Sybase runtime engine v7.0.2.1480. It is possible to crash the
Sybase runtime engine and Sitespring web services by sending a malformed
request to the database engine. The database engine is reported to crash
first when handling a malformed request, followed by the web services.
The database engine listens on TCP port 2500 by default.
Other versions may also be affected.
7. Macromedia JRun Source Disclosure Vulnerabilities
BugTraq ID: 5134
Remote: Yes
Date Published: Jul 01 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5134
Summary:
Macromedia JRun is a J2EE application server for use with IIS 4/5 on the
Microsoft Windows operating systems. It is also available for Unix and
Linux variants.
Macromedia JRun is prone to a number of source code disclosure issues.
These issues are reportedly due to improper handling of null characters.
Malformed requests containing variations of null characters may cause JRun
to serve .JSP files uninterpreted. One example of how this may be
exploited is to append a unicode null character to the end of a valid
request.
This may allow remote attackers to disclose the contents of arbitrary .JSP
files. Remote attackers may exploit this issue to gain access to
sensitive information contained in source files (such as database
credentials).
8. Betsie Parserl.PL Cross-Site Scripting Vulnerability
BugTraq ID: 5135
Remote: Yes
Date Published: Jul 01 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5135
Summary:
Betsie (BBC Education Text to Speech Internet Enhancer) is a script to
supports users of text to speech systems for web browsing. It is written
in Perl and will run on Microsoft Windows operating systems as well as
Unix and Linux variants.
Betsie is prone to a cross-site scripting vulnerability. This issue
exists in the parserl.pl script. The vulnerable script fails to sanitize
HTML tags from CGI parameters.
Attackers may exploit this condition via a malicious link to a site
running the vulnerable software. Successful exploitation will enable an
attacker to cause script code to be executed in the web browser of a user
who visits the malicious link. The attacker's script code will be
executed in the context of the site running the vulnerable software.
Attackers may exploit this condition to steal cookie-based authentication
credentials from legitimate users.
9. OmniHTTPD Long Request Buffer Overflow Vulnerability
BugTraq ID: 5136
Remote: Yes
Date Published: Jul 01 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5136
Summary:
OmniHTTPD is a webserver for Microsoft Windows operating systems.
OmniHTTPD is prone to a remotely exploitable buffer overflow condition.
This problem is in the handling of requests containing overly long
headers. In particular, this issue may be exploited if an overly long
HTTP Version header is sent to the webserver. The type of request does
not matter (GET, POST, etc.). This condition is known to occur when 4096+
bytes are sent in the header field.
Exploitation of this issue may cause a denial of service condition or
result in execution of arbitrary attacker-supplied instructions with the
privileges of the webserver process.
OmniHTTPD normally runs with SYSTEM privileges. If this issue is
successfully exploited by an attacker to execute arbitrary code, this may
result in a full compromise of the underlying host.
This issue was reported in version 2.09 of the software. Other versions
may also be affected.
10. AnalogX Proxy Socks4A Buffer Overflow Vulnerability
BugTraq ID: 5138
Remote: Yes
Date Published: Jul 01 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5138
Summary:
AnalogX Proxy is proxy server software for Microsoft Windows operating
systems.
AnalogX Proxy is prone to a buffer overflow condition when attempting to
handle malformed SOCKS4A requests (via TCP port 1080). This condition is
due to insufficient bounds checking of the hostname and may be reproduced
by sending a malformed request with a hostname of 140 bytes or more.
This may be exploited to create a denial of service condition. When the
malformed request is received by the proxy, an error message will appear
on the screen. Multiple malformed requests may cause the service to stop
responding. Additionally, it may be possible to exploit this issue to
execute arbitrary attacker-supplied instructions as the proxy server
process.
11. AnalogX Proxy Web Proxy Buffer Overflow Vulnerability
BugTraq ID: 5139
Remote: Yes
Date Published: Jul 01 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5139
Summary:
AnalogX Proxy is proxy server software for Microsoft Windows operating
systems.
AnalogX Proxy is prone to a buffer overflow condition when attempting to
handle malformed HTTP proxy requests (via TCP port 6588). Requests must
be specially crafted to contain a space character followed by 320+
non-space characters, followed by 2 carriage-return linefeeds (CRLF).
This may be exploited to create a denial of service condition. When the
malformed request is received by the proxy, an error message will appear
on the screen. Multiple malformed requests may cause the service to stop
responding. Additionally, it may be possible to exploit this issue to
execute arbitrary attacker-supplied instructions as the proxy server
process.
12. ArGoSoft Mail Server Directory Traversal Vulnerability
BugTraq ID: 5144
Remote: Yes
Date Published: Jul 03 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5144
Summary:
ArGoSoft Mail Server is an STMP, POP3 and Finger server for Microsoft
Windows environments. ArGoSoft has a built in web server to enable remote
access to mail.
A directory traversal issue has been reported in the web server, which
could allow remote users access to all files residing on the host.
Reportedly, submitting a request to either the images or mail attachment
directory, appended with '/..' character sequences, could disclose all
files residing in the requested directory and potentially disclose all
directories and files residing on the host.
Successful exploitation of this issue could lead to the disclosure of
sensitive information, which may be used in further attacks against the
host.
This issue is reported to exist in ArGoSoft Mail Server 1.8.1.5, earlier
versions may also be affected by this issue.
13. NEC Socks5 User Name Buffer Overflow Vulnerability
BugTraq ID: 5145
Remote: Yes
Date Published: Jul 03 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5145
Summary:
Socks5 is the freely available, open source proxy implementation developed
by NEC. It is available for Unix, Linux, and Microsoft operating
environments.
A problem with the implementation may make it possible for a remote user
to exploit a buffer overflow. The problem is in the handling of user
names.
Socks5 handles user names in an unsafe manner. A boundary condition error
in the software package may make it possible for users to send user names
of 132 bytes or greater, and cause memory corruption.
It is unknown whether this issue is a buffer overflow that may be
exploited to execute arbitrary code. Exploitation of this vulnerability
could minimally result in the crashing of the socks5 process, and denial
of service to legitimate users of the service.
In the event that this is an exploitable buffer overflow, this
vulnerability could be used to execute code with the privileges of the
socks5 process.
14. NEC Socks4 User Name Buffer Overflow Vulnerability
BugTraq ID: 5147
Remote: Yes
Date Published: Jul 03 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/5147
Summary:
Socks4 is the freely available, open source proxy implementation developed
by NEC. It is available for Unix, Linux, and Microsoft operating
environments.
A problem with the implementation may make it possible for a local user to
exploit a buffer overflow. The problem is in the handling of user names.
Socks4 handles user names in an unsafe manner. A boundary condition error
in the software package may make it possible for users to send user names
of 132 bytes or greater, and cause memory corruption.
It is unknown whether this issue is a buffer overflow that may be
exploited to execute arbitrary code. Exploitation of this vulnerability
could minimally result in the crashing of the socks4 process, and denial
of service to legitimate users of the service.
In the event that this is an exploitable buffer overflow, this
vulnerability could be used to execute code with the privileges of the
socks4 process.
III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Strange event showing up... (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
2. Replication on Sql Server 2k - Sql Server Agent Account (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
3. Can I shut down individual TCP connections? (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/[email protected]
4. SecurityFocus Microsoft Newsletter #93 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/6AA3020BB6C49E4EBDB055884742533201AA5F@dieppe.calgary.securityfocus.com
IV. NEW PRODUCTS FOR MICROSOFT PLATFORMS
----------------------------------------
1. pcProx Reader
by HID Corporation
Platforms: Windows 2000, Windows 95/98, Windows NT
Relevant URL:
http://www.hidcorp.com/products/proximityproducts/pcprox.html
Summary:
The pcProx Reader offers computer access control and secure logon
capability using existing HID proximity cards. PC or network access is
granted when a card is presented; without a card present, the system
self-locks using a secure, proximity-activated screen saver. The AIR ID ®
system includes HID's pcProx Reader and AIR ID software.
2. Defender
by PassGo Technologies
Platforms: Solaris, Windows 2000, Windows NT
Relevant URL:
http://www.passgo.com/products/defender/
Summary:
Defender uses standards-based challenge/response technology to create a
one-time password that is far more secure than static passwords. Its
easy-to-use tokens compute this one-time password when challenged by the
Defender Security Server. Then, without the authorized user's unique token
and PIN to activate the token, potential intruders cannot compute the
one-time password. Even if the password is captured, it doesn't pose a
threat because the password is never valid again.
3. AiS Watermark Pictures Protector
by AtomInterSoft
Platforms: Windows 2000, Windows NT, Windows XP
Relevant URL:
http://www.atomintersoft.com/products/watermark-protector/
Summary:
AiS Watermark Pictures Protector will help you to make a demo images from
your original images. It reads your image from file (BMP, GIF, Animated
GIF, JPEG, PNG and more), adds to the image some transparent or color text
and saves resulting image in a new file with the same format. The program
is useful for a computer painters, designers and bannermakers, which send
their works to a customer through the Internet to estimate your picture
quality. You can protect a number of pictures simultaneously.
V. MICROSOFT TOOLS
-------------------
1. ABC CHAOS v2.1
by Investment Resources Group
Relevant URL:
http://www.safechaos.com/abc.htm
Platforms: Windows 2000, Windows 95/98, Windows CE, Windows NT, Windows XP
Summary:
Easily encrypt files into your personal data archive. You can be confident
that the data is safely secured. The additional special protection
completely excludes an opportunity of selection of the password to the
encrypted information at use of the generator of the passwords and keys.
2. Advanced Lotus Password Recovery
by Elcom Ltd.
Relevant URL:
http://www.elcomsoft.com/alpr.html
Platforms: Windows 2000, Windows 95/98, Windows NT
Summary:
A program to recover lost or forgotten passwords to the files/documents
created in IBM/Lotus applications (all versions): Organizer, WordPro,
1-2-3 and Approach. The passwords are recovered instantly; multilingual
passwords are supported.
3. aTrans
by DataRescue Inc
Relevant URL:
http://www.datarescue.com/atrans2
Platforms: Windows 2000, Windows 95/98, Windows NT
Summary:
Easy to move, easy to use, P2P secure file transfer and chat on the
windows 32 platform. AES encryption / RSA authentication / Diffie-Hellman
EKE, on the fly compression, secure migration in a 400 kb self extracting
encrypted package.
VI. SPONSORSHIP INFORMATION
---------------------------
This newsletter is sponsored by: SecurityFocus DeepSight Threat Management
System
From June 24th - August 31st, 2002, SecurityFocus announces a FREE
two-week trial of the DeepSight Threat Management System: the only early
warning system providing customizable and comprehensive early warning of
cyber attacks and bulletproof countermeasures to prevent attacks before
they hit your network.
With the DeepSight Threat Management System, you can focus on proactively
deploying prioritized and specific patches to protect your systems from
attacks, rather than reactively searching dozens of Web sites or hundreds
of emails frantically trying to gather information on the attack and how
to recover from it.
Sign up today!
http://www.securityfocus.com/corporate/products/promo/tmstrial-ms.shtml
-------------------------------------------------------------------------------