SecurityFocus Microsoft Newsletter #97
John Boletta <[email protected]> Mon, 29 Jul 2002 10:16:01 -0600 (MDT)
| Newsgroups | gmane.comp.security.news.microsoft |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Microsoft Newsletter #97
-------------------------------------
This newsletter is sponsored by: SecurityFocus DeepSight Threat Management
System
From June 24th - August 31st, 2002, SecurityFocus announces a FREE
two-week trial of the DeepSight Threat Management System: the only early
warning system providing customizable and comprehensive early warning of
cyber attacks and bulletproof countermeasures to prevent attacks before
they hit your network.
With the DeepSight Threat Management System, you can focus on proactively
deploying prioritized and specific patches to protect your systems from
attacks, rather than reactively searching dozens of Web sites or hundreds
of emails frantically trying to gather information on the attack and how
to recover from it.
Sign up today!
http://www.securityfocus.com/corporate/products/promo/tmstrial-ms.shtml
-------------------------------------------------------------------------------
I. FRONT AND CENTER
1. Detecting and Removing Malicious Code
2. High-Flying Schmidt
3. Black Hat Briefings & Training
4. Secure i-World
5. SecurityFocus DPP Program
II. MICROSOFT VULNERABILITY SUMMARY
1. Adobe eBook Reader File Restoration Privilege Escalation...
2. Sun PC NetLink Backup Restoration ACL Permissions Vulnerability
3. Trend Micro InterScan VirusWall Space Gap Scan Bypass...
4. MERCUR Mailserver Control-Service Buffer Overflow Vulnerability
5. Nullsoft Winamp Skin Predictable File Location Vulnerability
6. Geeklog HTML Attribute Cross Site Scripting Vulnerability
7. Geeklog Email Composition CRLF Injection Vulnerability
8. Microsoft Outlook Express SMTP Over TLS Information Disclosure...
9. Working Resources BadBlue HTTP 302 Message Cross-Site Scrpting...
10. Microsoft Outlook Express Spoofable File Extensions Vulnerability
11. PHP HTTP POST Incorrect MIME Header Parsing Vulnerability
12. PHP Interpreter Direct Invocation Denial Of Service Vulnerability
13. Pablo Software Solutions FTP Server File/Directory Disclosure...
14. SmartMax MailMax Popmax Buffer Overflow Vulnerability
15. ICQ 2001/2002 Malformed Message Denial Of Service Vulnerability
16. SecureCRT SSH1 Identifier String Buffer Overflow Vulnerability
17. Sun Java Web Start JNLP Predictable File Location Vulnerability
18. Working Resources BadBlue Administrative Interface Arbitrary...
19. Multiple Vendor Web Browser JavaScript Modifier Keypress Event...
20. Mozilla JavaScript URL Host Spoofing Arbitrary Cookie Access...
21. TightVNC Repeated Challenge Replay Attack Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
1. need help with ActiveX remote counters (Thread)
2. Exporting GPOs from Active Directory (Thread)
3. Securing IIS Using, MS Security Tool Kit & Scripting (Thread)
4. Problems with IIS and Certification Services (Thread)
5. SecurityFocus Microsoft Newsletter #96 (Thread)
6. Make all directories reinherrit ACLs (Thread)
7. write permissions for IIS (Thread)
8. Terminal Services Auditing not working (Thread)
9. local security policy (Thread)
10. Need security proposal for Win2K upgrade... (Thread)
IV. MICROSOFT PRODUCTS
1. SecureStack
2. AppDetective for Oracle
3. iBroker SecureWeb Application Firewall
V. MICROSOFT TOOLS
1. Sniff'em
2. WinARP Watch
3. GNOME Workstation Command Center
VI. SPONSORSHIP INFORMATION
I. FRONT AND CENTER
-------------------
1. Detecting and Removing Malicious Code
by Matthew Tanase
Has it happened yet? The phone call, the e-mail, the page, or maybe you
discovered it yourself. Something wasn't right: sluggish performance, too
much network activity, a missing file. After a little investigating, the
realization - you've been cracked. If this isn't familiar to you yet, odds
are it will be in the future. Crackers have access to countless variations
of malicious code: automated rootkits, trojans, viruses and specific
exploits, all designed to breach your security. Detecting and removing
these programs can be a daunting task, with little room for wasted time or
error. In this article, I'll explain techniques readers can use to get
their system back on-line and prevent it from happening again.
http://online.securityfocus.com/infocus/1610
2. High-Flying Schmidt
By George Smith
Unstoppable viruses, massive blackouts, hacked pacemakers? The
government's number two cyber security guy wasn't this apocalyptic when he
worked for Microsoft.
http://online.securityfocus.com/columnists/97
3. Black Hat Briefings & Training
Attend Black Hat Briefings & Training, July 29 - August 1, Las Vegas, the
world's premier technical security event! 8 tracks, 12 training sessions,
Richard Clarke keynote, 1500 delegates from 30 nations, with a near cult
following of both CSOs and "underground" security experts. See for
yourself what the buzz is all about.
Visit us at: http://www.blackhat.com
4. WebSec 2002, the Online Privacy Conference
MIS Training Institute presents Secure i-World, featuring WebSec 2002, the
Online Privacy Conference, and Secure i-World Expo -- two innovative
conferences and an outstanding expo, all in one blockbuster event.
Secure i-World will be held in San Diego, CA on August 19-21, 2002, with
optional workshops August 17, 18, 21, and 22. The vendor expo will be
August 19 and 20.
For more information and to register for the industrys premier security
event visit http://www.secureiworld.com/07/sw02nl21inf.html.
5. SecurityFocus DPP Program
Attention Non-profit Organizations and Universities!!
Sign-up now for preferred pricing on the only global early-warning system
for cyber attacks - SecurityFocus DeepSight Threat Management System.
Click here for more information:
http://www.securityfocus.com/corporate/products/dpsection.shtml
II. BUGTRAQ SUMMARY
-------------------
1. Adobe eBook Reader File Restoration Privilege Escalation Vulnerability
BugTraq ID: 5273
Remote: No
Date Published: Jul 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5273
Summary:
Adobe eBook Reader is a client side application which is able to view
Adobe eBooks, available for Microsoft Windows and Macintosh OS 9. eBooks
are electronic books which provide some protection for content. Users may
be able to view a book, but have limited publisher defined privileges to
copy content. It is possible to define quotas, such as only allowing a
user to print or copy a specific number of pages within a given time
period.
It has been reported possible to bypass some quota restrictions. eBook
maintains some information about the past actions of the local user for a
given book in a number of local files. These files may be copied and later
restored from these copies. Restoration will effectively restore the eBook
data to it's original state, without any loss in functionality.
A user may thus backup specific local files, print or copy protected
content, and then restore the local files. There will be no record of the
printing or copying actions, and any non-zero quota may be effectively
bypassed entirely.
This vulnerability has been reported in versions of eBook Reader for
Microsoft Windows. It may, however, exist on other platforms.
2. Sun PC NetLink Backup Restoration ACL Permissions Vulnerability
BugTraq ID: 5281
Remote: No
Date Published: Jul 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5281
Summary:
Sun PC NetLink is a server software package designed to provide a number
of services to Microsoft Window's based machines. PC NetLink is able to
perform network backup operations.
An issue has been reported with Access Control List (ACL) permissions
applied to files which are restored from backup. Under some conditions,
file permissions will be reset to default values instead of the values
possessed before backup. As a result, files which are restored from backup
may have weaker access restrictions than anticipated.
This condition is related to symbolic links. This behavior may occur when
processing files which are symbolic links, or which reside within a
directory which is a symbolic link, or which reside on a share which is a
symbolic link.
If ACL permissions are modified by this vulnerability, malicious local
users may gain access to sensitive files.
3. Trend Micro InterScan VirusWall Space Gap Scan Bypass Vulnerability
BugTraq ID: 5259
Remote: Yes
Date Published: Jul 18 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5259
Summary:
Trend Micro InterScan VirusWall is a high performance internet gateway
virus scanning package. It is capable of scanning incoming content over
HTTP, SMTP and FTP for viruses and other malicious code.
A vulnerability has been reported in VirusWall 3.52 builds prior to 1466.
Reportedly, it is possible to bypass the scanning mechanism of VirusWall
by adding extraneous spaces in certain email HTTP header fields.
A malicious email server may add extraneous whitespace in certain email
headers. This would cause VirusWall to ignore the malicious email and not
scan it. However, many popular email client programs, including Outlook,
will ignore this header and display the content regardless. This may allow
malicious content to bypass VirusWall and still be interpreted by a client
system.
An attacker can make the following modifications to the following fields and bypass email scanning by VirusWall:
1) Replace "Content-Type:" with "Content-Type :"
2) Replace "Content-Transfer-Encoding:" with "Content-Transfer-Encoding :"
3) Replace ' boundary="----=_NextPart_000_000E_01C2100B.F369D840"' with 'boundary=----=_NextPart_000_000E_01C2100B.F369D840 '
4) Replace ' boundary="----=_NextPart_000_000E_01C2100B.F369D840"' with 'boundary= ----=_NextPart_000_000E_01C2100B.F369D840'
This vulnerability has been reported for VirusWall 3.52 build 1375 on
Microsoft Windows platforms. It is not known whether other platforms are
affected.
4. MERCUR Mailserver Control-Service Buffer Overflow Vulnerability
BugTraq ID: 5261
Remote: Yes
Date Published: Jul 18 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5261
Summary:
MERCUR Mailserver is an e-mail server for Microsoft Windows operating
systems.
MERCUR Mailserver is prone to a remotely exploitable buffer overflow
condition. The condition is due to insufficient bounds checking in the
Control-Service component, which listens on TCP port 32000 by default.
It is possible to corrupt process memory by supplying an overly long
username/password. Attackers may exploit this condition to overwrite stack
variables (including the return address) and execute arbitrary
instructions with the privileges of the mailserver.
Since the server will typically run with SYSTEM privileges, exploitation
of this vulnerability will result in a full compromise of the host.
5. Nullsoft Winamp Skin Predictable File Location Vulnerability
BugTraq ID: 5266
Remote: Yes
Date Published: Jul 18 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5266
Summary:
Nullsoft Winamp is a skinable media player for Microsoft Windows
supporting MP3 and other filetypes. By default, Winamp skin files are
given the .wsz extension.
When installed, a skin file is placed in a predictable location within the
installation directory of Winamp. An attacker may exploit this
vulnerability to place malicious content in a known location. A URL
reference to the file may then cause malicious content or code to be
executed within local context.
It has been demonstrated that a .mht file may be renamed as a .wsz file
and deposited in this way. If referenced through some browsers with the
protocol specified as mhtml, attached executable content may be
automatically dropped to a defined directory on the local system, and then
referenced in turn.
The ability to plant a file on the victim filesystem may also be leveraged
in conjunction with other vulnerabilities such as that described by
Bugtraq ID 3867.
6. Geeklog HTML Attribute Cross Site Scripting Vulnerability
BugTraq ID: 5270
Remote: Yes
Date Published: Jul 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5270
Summary:
Geeklog is freely available, open-source weblog software. It is written in
PHP and will run on most Unix and Linux variants, as well as Microsoft
Windows NT/2000. Geeklog is backended by MySQL.
A cross site scripting vulnerability has been reported for Geeklog
1.3.5sr1. Reportedly, Geeklog does not properly sanitize user supplied
input before being included when posting comments or writing stories.
Geeklog makes efforts to sanitize some malicious user supplied input by
stripping out HTML elements that are used for scripting. However, Geeklog
does not properly remove HTML attributes that are used for the same
purpose.
It is possible for an attacker to include malicious HTML code using the
HTML attributes. As an example, if an attacker were to supply malicious
HTML code as part of an onMouseOver JavaScript event, the malicious code
would not be properly sanitized.
An attacker may construct a link containing dangerous HTML code and send
it to a vulnerable user. If a user of the site follows this link, the
script code will be rendered, and execute within the context of the
vulnerable site. It may be possible to access sensitive data such as
authentication credentials, or to take actions as a validated user on the
hosted forum.
This issue may potentially be exploited to hijack web content or steal
cookie-based authentication credentials from legitimate users.
7. Geeklog Email Composition CRLF Injection Vulnerability
BugTraq ID: 5271
Remote: Yes
Date Published: Jul 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5271
Summary:
Geeklog is freely available, open-source weblog software. It is written in
PHP and will run on most Unix and Linux variants, as well as Microsoft
Windows NT/2000. Geeklog is backended by MySQL.
A vulnerability has been reported for Geeklog that may allow an attacker
to include extra email headers when composing email to other Geeklog
users.
Geeklog prevents the disclosure of a user's real email address for privacy
reasons. However an attacker is able to obtain a user's real email address
by including extra headers when composing an email using Geeklog's 'Send
Email' facility.
It is possible for an attacker to include extra email header fields when
composing an email. An attacker does this by appending a CRLF sequence
followed by an email header field to the subject field.
An attacker can use this method to obtain a user's real email address.
8. Microsoft Outlook Express SMTP Over TLS Information Disclosure Vulnerability
BugTraq ID: 5274
Remote: Yes
Date Published: Jul 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5274
Summary:
Microsoft Outlook Express is a mail client for the Microsoft Windows
operating system. Outlook Express includes support for secure SMTP
communications using TLS, as defined in RFC 2487.
Under TLS, it is possible for a client and server to successfully
negotiate an encrypted connection without authentication. In this case,
transmitted data will be properly encrypted, but the identity of the
client and server are not securely defined.
Reportedly, Outlook Express will allow this condition to occur with no
further warning to the end user. This may prevent the detection of a
malicious mail server when TLS authentication is expected. If this
happens, the client may send additional sensitive information through SMTP
to the server. In particular, SMTP AUTH authentication information may be
communicated to the unknown server.
The malicious server may be able to use this information to perform a
man-in-the-middle attack, monitoring or subverting SMTP traffic with the
legitimate SMTP server.
This behavior has been reported in Outlook Express. It is possible,
however, that additional SMTP clients share this behavior.
9. Working Resources BadBlue HTTP 302 Message Cross-Site Scrpting Vulnerability
BugTraq ID: 5275
Remote: Yes
Date Published: Jul 19 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5275
Summary:
BadBlue is a P2P file sharing application distributed by Working
Resources. It is available for Microsoft Windows operating systems.
A problem with BadBlue could make it possible for users to launch
cross-site scripting attacks.
Upon passing a vulnerable BadBlue server a request for a either a file
path that does not exist or a directory that does exist, both of which are
not appended with a slash (/), BadBlue returns an HTTP 302 (found)
response.
BadBlue does not sufficiently sanitize input when returning a 302
response. When a user sends a request to the server that illicits a 302
response, any HTML contained within the response is returned to the user.
This could make it possible to launch cross-site scripting attacks that
would allow execution of code in the security context of the vulnerable
BadBlue server.
10. Microsoft Outlook Express Spoofable File Extensions Vulnerability
BugTraq ID: 5277
Remote: Yes
Date Published: Jul 20 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5277
Summary:
Microsoft Outlook Express is prone to an issue which when successfully
exploited may cause an unsuspecting web user to execute files of an
entirely different type than they appear to be.
It is possible for a malicious user, sending email via a mail agent
capable of manipulating the MIME headers, to spoof file extensions for
users of Outlook Express. For example, an .exe file can be made to look
like a .txt (or other seemingly harmless file type) file in the attachment
list.
When including a certain strings of characters between the filename and
the actual file extension, Outlook Express will display the specified
misleading file extension type. The source of this issue is that Outlook
Express trusts the filename in the MIME Header, as opposed to relying upon
the Header Content-Type for information about what type of file it is.
The end result is that an attacker is able to entice a user to open or
save files of arbitrary types to their local system. It should be noted
that this vulnerability could be used to bypass file type filters, change
the attachment icon to the default icon, spoof the size of the attachment,
or spoof the file extension of the attachment when opened.
It is also worth mention that this vulnerability is similar in nature to
both Bugtraq ID 3597 and Bugtraq ID 4087, and may be related to the same
component.
11. PHP HTTP POST Incorrect MIME Header Parsing Vulnerability
BugTraq ID: 5278
Remote: Yes
Date Published: Jul 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5278
Summary:
PHP is a general purpose scripting language that is used for Web
development. It is available for various platforms including Linux and
Unix variants as well as Microsoft Windows operating systems.
A vulnerability has been reported for PHP versions 4.2.0 and 4.2.1. It is
possible for a remote attacker to cause the PHP interpreter to crash the
web server on a vulnerable system and execute malicious, attacker supplied
code.
The vulnerability is the result of the PHP interpreter incorrectly parsing
MIME headers when HTTP POST commands are received. When PHP receives a
malformed POST request, it generates an error condition that is improperly
handled.
When a HTTP POST command is received, a memory structure is appended to a
linked list of MIME headers. The memory allocated for this structure is
freed when the POST command is successful. When a malformed POST request
is made, an uninitialised memory structure is appended to the list of MIME
headers. Attempting to free this memory will have negative consequences
for a vulnerable system.
This vulnerability has different effects on different architectures. It
has been reported that PHP will crash when it tries to free the memory
structure on an IA32 (x86) architecture. The IA32 architecture has been
verified to be safe from the execution of arbitrary code. However, it is
still possible to crash PHP as well as the web server on vulnerable
systems.
It has also been reported that on Sparc architectures, an attacker may
have greater control about how memory is freed. Arbitrary code execution
on the Sparc architecture is possible.
An attacker may take advantage of this vulnerability to cause the PHP
interpreter to crash leading to a denial of service or cause the
vulnerable web server to execute malicious, attacker supplied code. It may
also be possible for the attacker to gain elevated privileges.
12. PHP Interpreter Direct Invocation Denial Of Service Vulnerability
BugTraq ID: 5280
Remote: Yes
Date Published: Jul 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5280
Summary:
It is possible, under some circumstances, for remote attackers to invoke
the PHP interpreter from the web.
When PHP is installed with Apache, an alias/virtual path is created for
the PHP interpreter and this alias is used internally when a CGI path is
resolved. To prevent the interpreter from being invoked remotely for
malicious purposes the cgi.force_redirect directive was introduced, and it
is enabled by default. However, it is still possible to invoke the
interpreter by name without command line arguments from the web despite
the cgi.force_redirect directive.
When the interpreter is invoked with no command line options, it will
hang. Attackers may repeatedly request the PHP interpreter to cause a
denial of service via resource exhaustion.
This is reported to be a problem with PHP and Apache on Microsoft Windows
platforms. It may be possible to reproduce this condition in other
environments as well.
13. Pablo Software Solutions FTP Server File/Directory Disclosure Vulnerability
BugTraq ID: 5283
Remote: Yes
Date Published: Jul 22 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5283
Summary:
Pablo Software Solutions FTP Server is freely available software for
Microsoft Windows operating systems.
Pablo Software Solutions FTP Server is prone to directory traversal
attacks, potentially resulting in disclosure of the contents of
directories and files on the host running the software.
An attacker may exploit this condition to escape the FTP root directory
using normal FTP commands and browse the contents of arbitrary directories
and files (provided they are readable by the FTP server). A remote
attacker must have anonymous access or a user account with the FTP server
to exploit this issue.
Since the software typically runs with SYSTEM privileges (or the
equivalent of SYSTEM privileges on Microsoft Windows 9x platforms), this
vulnerability may expose sensitive system files to remote attackers.
14. SmartMax MailMax Popmax Buffer Overflow Vulnerability
BugTraq ID: 5285
Remote: Yes
Date Published: Jul 23 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5285
Summary:
Smartmax MailMax is an email server for Microsoft Windows operating
systems.
Reportedly, MailMax 4.8 is vulnerable to buffer overflow attacks against
its POP3 (Post Office Protocol 3) daemon, popmax. The vulnerability occurs
due to improper bounds checking of the 'USER' argument.
It is possible for an attacker to cause the buffer overflow condition in
popmax by submitting an overly large value for the 'USER' argument. This
will cause popmax to crash and execute attacker supplied code.
As popmax is an email server, it will typically run with SYSTEM
privileges. Total system compromise is possible.
15. ICQ 2001/2002 Malformed Message Denial Of Service Vulnerability
BugTraq ID: 5295
Remote: Yes
Date Published: Jul 24 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5295
Summary:
ICQ is an instant messenger client for Microsoft Windows systems and other
platforms. ICQ versions 2001/2002 include support for sending and
receiving graphical emoticons.
ICQ clients versions 2001/2002 are prone to a remotely exploitable denial
of service condition. It is possible to produce this condition by sending
a client a large number of graphical emoticons. It should be noted that
the attacker cannot exploit this using the normal ICQ client, as the
client restricts the number of emoticons that may be sent in messages.
An attacker would have to contrive a way to craft malformed ICQ messages.
It has been reported that exploitability of this condition may be
dependant on the size of a targetted user's ICQ history file.
16. SecureCRT SSH1 Identifier String Buffer Overflow Vulnerability
BugTraq ID: 5287
Remote: Yes
Date Published: Jul 23 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5287
Summary:
SecureCRT is a commercial SSH client for Microsoft Windows operating
systems.
The SecureCRT client is prone to a buffer overflow condition when
attempting to handle an overly long SSH1 protocol identifier string. The
vulnerability is apparently due to insufficient bounds checking in the
error-handling code when the client processes the SSH1 protocol identifier
string. This issue reportedly may allow a malicious server to cause
memory corruption on the client system, potentially overwriting stack
variables with attacker-supplied data.
Exploitation of this issue may allow an attacker to execute arbitrary code
or may cause the client to crash.
This issue was reported in versions 3.4.x and 4.0 beta. SecurityFocus
analysis has determined that this issue may not be present in earlier
versions.
17. Sun Java Web Start JNLP Predictable File Location Vulnerability
BugTraq ID: 5263
Remote: Yes
Date Published: Jul 18 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5263
Summary:
Sun's Java Web Start is a platform for deploying Java applications through
the web. Web Start is implemented in Java, and thus available for most
major platforms, including Microsoft Windows and Linux.
Java applications deployed through Web Start may be described by a Java
Network Launching Protocol (JNLP) file, an XML document which describes
the application and provides references to additional resources such as
image files. An error has been reported in the way Java Web Start handles
JNLP files.
Image files referenced in a JNLP file are stored in a predictable
location. An attacker may create a malicious JNLP file which will place
arbitrary files in a known location. A URL reference to the file may then
cause malicious content or code to be executed within local context.
It has been demonstrated that a .mht file may be renamed as a .gif file
and deposited in this way. If referenced through some browsers with the
protocol specified as mhtml, attached executable content may be
automatically dropped to a defined directory on the local system, and then
referenced in turn.
This behavior has been reported on Web Start installed under Microsoft
Windows. Other versions may share this behavior.
The ability to plant a file on the victim filesystem may also be leveraged
in conjunction with other vulnerabilities such as that described by
Bugtraq ID 3867.
18. Working Resources BadBlue Administrative Interface Arbitrary File Access Vulnerability
BugTraq ID: 5276
Remote: Yes
Date Published: Jul 20 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5276
Summary:
BadBlue is a P2P file sharing application distributed by Working
Resources. It is available for Microsoft Windows operating systems.
A problem with BadBlue could make it possible for a remote user to gain
access to sensitive files.
BadBlue Enterprise Edition is administered via a web interface. Access to
this web interface is restricted to the system the BadBlue server is
installed on. This access control is enforced by the administrative
server listening only on the loopback interface.
BadBlue does not sufficiently control access to the administrative
interface. It is possible to remotely add the entire drive of a system
running a vulnerable BadBlue implementation via a maliciously crafted web
page containing a form POST method. This would allow remote users to via
the contents of the drive with the privileges of the BadBlue server.
19. Multiple Vendor Web Browser JavaScript Modifier Keypress Event Subversion Vulnerability
BugTraq ID: 5290
Remote: Yes
Date Published: Jul 23 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5290
Summary:
An issue has been reported with the JavaScript implementation of multiple
web browsers, including Microsoft Internet Explorer and Opera. Malicious
JavaScript may subvert some keypress events, with consequences including
the disclosure of arbitrary local files to a remote server.
Through JavaScript, it is possible to define an event handler for the
'onkeydown' event, which fires when a key is pressed by the end user. It
is possible to have this event recognize the usage of the 'Control'
modifier key.
When this condition occurs, malicious script code may modify the event
property indicating which primary key has been pressed. By changing this
key to 'V', it is possible to create the 'Ctrl-V' key combination,
normally associated with the paste operation.
As the script also has control over the clipboard contents for the page,
and the document element with current focus, it is possible to further
subvert the event and place arbitrary content in an HTML form element. In
particular, an arbitrary local filename may be pasted into a file upload
form field.
If the form is then submitted through JavaScript, the attacker specified
file will be uploaded to the specified server without further user
interaction.
Exploitation of this vulnerability may result in the disclosure of
sensitive information to a remote attacker.
It may also be possible to discover the full path of the temporary file
directory used by Internet Explorer, by downloading the file
'..\LOCALS~1\TEMPOR~1\CONTENT.IE5\index.dat'. In this case, the
information may be used in conjunction with the issues discussed in BID
3867 to execute arbitrary code as the vulnerable user.
Other attacks based on script interaction with the cut and paste
functionality of Windows may also be possible.
It has been reported that it is also possible to recognize and subvert
keypress events based on the 'Shift' key. In particular, Shift-Ins is a
common keyboard shortcut for the paste operation. This may simplify the
social engineering aspect of this vulnerability by exploiting a more
commonly used key. It is likely that modifiers such as 'Alt' may also be
intercepted.
It has been reported that the Opera Web Browser 6.0.1 is also vulnerable
to this issue. It is possible that other versions of Opera share this
vulnerability, this has not however been confirmed.
20. Mozilla JavaScript URL Host Spoofing Arbitrary Cookie Access Vulnerability
BugTraq ID: 5293
Remote: Yes
Date Published: Jul 24 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5293
Summary:
Mozilla is an open source web browser available for a number of platforms,
including Microsoft Windows and Linux. An issue has been reported in the
Mozilla web browser which may allow script code to access cookie data
associated with arbitrary domains.
Mozilla supports javascript: URLs, which can be used to execute JavaScript
functions directly. Normally the domain of such functions is restricted,
and cookie data associated with other sites may not be accessed.
It has been reported possible to create a javascript: URL which appears to
start with a valid domain. Malicious script code may specify an arbitrary
domain, and will be able to access cookie data associated with that
domain.
It is possible to exploit this vulnerability by creating a javascript: URL
which starts with a javascript comment of the form '//host\n', followed by
arbitrary script code. Other avenues of exploitation may, however, be
possible.
Exploitation of this vulnerability may result in a remote attacker gaining
access to sensitive cookie data, including authentication credentials.
21. TightVNC Repeated Challenge Replay Attack Vulnerability
BugTraq ID: 5296
Remote: Yes
Date Published: Jul 24 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5296
Summary:
TightVNC is a Virtual Network Computing (VNC) client and server, available
for a number of platforms including Microsoft Windows and Linux. An error
has been reported in some versions of the TightVNC server.
When a VNC connection is established, a DES challenge-response cycle is
used in order to prevent the transmission of plaintext password data. An
attacker able to view network traffic should not gain sufficient
information to authenticate as the valid user.
TightVNC, however, has been reported to repeat a given DES challenge if
multiple connections are initiated in rapid sequence. A network
eavesdropper may repeat a previously witnessed response, and authenticate
as a valid user. Exploitation will, however, be highly dependent on the
timing of an attack.
This behavior has been reported in version 1.2.1 of TightVNC for Unix.
Other versions may share this vulnerability, this has not however been
confirmed.
III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. need help with ActiveX remote counters (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/284316
2. Exporting GPOs from Active Directory (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/284057
3. Securing IIS Using, MS Security Tool Kit & Scripting (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/283838
4. Problems with IIS and Certification Services (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/283825
5. SecurityFocus Microsoft Newsletter #96 (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/283629
6. Make all directories reinherrit ACLs (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/283614
7. write permissions for IIS (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/283559
8. Terminal Services Auditing not working (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/283323
9. local security policy (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/283321
10. Need security proposal for Win2K upgrade... (Thread)
Relevant URL:
http://online.securityfocus.com/archive/88/283269
IV. MICROSOFT PRODUCTS
----------------------
1. SecureStack
by SecureWave
Platforms: Windows 2000, Windows NT
Relevant URL:
http://www.securewave.com/products/securestack/secure_stack.html
Summary:
SecureStack is a definitive solution that will protect mission critical
Windows NT4/2000 servers from all types of Buffer Overflow attacks.
2. AppDetective for Oracle
by Application Security, Inc. (ASI)
Platforms: Windows 2000, Windows NT, Windows XP
Relevant URL:
http://www.appsecinc.com/products/appdetective/oracle/
Summary:
AppDetective for Oracle is a network-based, penetration
testing/vulnerability assessment scanner that locates and assesses the
security strength of database and groupware applications within your
network. Armed with a revolutionary security methodology together with an
extensive knowledgebase of vulnerabilities, AppDetective for Oracle will
locate, examine, report, and help fix your security holes and
misconfigurations at your command.
3. iBroker SecureWeb Application Firewall
by Multinet, Inc.
Platforms: Linux, UNIX, Windows 2000, Windows NT
Relevant URL:
http://elitesecureweb.com/dta/products/solutions.html
Summary:
iBroker SecureWeb allows you to protect Web applications from all known
and unknown attacks. iBroker SecureWeb wraps around IIS and Apache Web
servers and works as plug-in within it, verifying and analyzing incoming
and outgoing Web server data for any possible security breaches. It
creates an application firewall, which overcomes limitations of Intrusion
Detection Systems and Conventional Network Firewalls. iBroker SecureWeb is
the most powerful proactive HTTP application firewall.
V. MICROSOFT TOOLS
-------------------
1. Sniff'em
by YASC
Relevant URL:
http://www.sniff-em.com/sniffem.download.html
Platforms: Linux, Windows 2000, Windows 95/98, Windows NT
Summary:
Sniff'em is a performance minded Windows based Packetsniffer, a new
network management tool designed from the ground up with ease and
functionality in mind
2. WinARP Watch v1.0
by Andreas Vernersson [email protected]
Relevant URL:
http://jota.sm.luth.se/~andver-8/warp/
Platforms: Windows 2000, Windows 95/98, Windows XP
Summary:
WinARP Watch is a program that monitors Windows ARP cache. The ARP cache
contains IP/MAC translations so that every time an IP packet are to be
sent, the MAC address doesn't have to queried through a broadcast, instead
it uses the cached address.
The problem with this is that someone can send faked ARP responses, which
gets stored in the cache too. Which is called ARP poisoning and that is no
good for you.
So this program watches the cache and stores every new IP/MAC combination
to it's own lists. If a combination is already known, the program compares
it with the cache to see if has changed.
3. GNOME Workstation Command Center v0.9.7
by Brent Ely [email protected]
Relevant URL:
http://gwcc.sourceforge.net/
Platforms: Linux, UNIX
Summary:
GWCC allows users to execute network utilities (ping, nslookup,
traceroute), workstation commands (netstat, df, lpr), and do cool things
like process grep from a single tabbed window. Command flags are highly
configurable, results windows are savable and printable, and there is a
System Stats tab showing you process info, current users, Apache server
status, Samba status, and more.
VI. SPONSORSHIP INFORMATION
---------------------------
This newsletter is sponsored by: SecurityFocus DeepSight Threat Management
System
From June 24th - August 31st, 2002, SecurityFocus announces a FREE
two-week trial of the DeepSight Threat Management System: the only early
warning system providing customizable and comprehensive early warning of
cyber attacks and bulletproof countermeasures to prevent attacks before
they hit your network.
With the DeepSight Threat Management System, you can focus on proactively
deploying prioritized and specific patches to protect your systems from
attacks, rather than reactively searching dozens of Web sites or hundreds
of emails frantically trying to gather information on the attack and how
to recover from it.
Sign up today!
http://www.securityfocus.com/corporate/products/promo/tmstrial-ms.shtml
-------------------------------------------------------------------------------