SecurityFocus Microsoft Newsletter #86

John Boletta <[email protected]>
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #86
--------------------------------

This newsletter is sponsored by SecurityFocus (www.securityfocus.com)

Attention Non-profits and Universities: Sign-up now for preferred pricing
on the only global early-warning system for cyber attacks - SecurityFocus
ARIS Threat Management System.

Click here for more info
http://www.securityfocus.com/corporate/products/pdpsection.shtml

-------------------------------------------------------------------------------


I. FRONT AND CENTER
     1. Securing Exchange 2000, Part Two
     2. IDS Evasion Techniques and Tactics
     3. Slot Machine Justice for Melissa Author
     4. Information Resilience and Homeland Security
     5. Patch Management Done Right
II. MICROSOFT VULNERABILITY SUMMARY
     1. ACD Systems ACDSee Photo Album File Description Buffer...
     2. Microsoft MSN Messenger Font Tag Denial Of Service Vulnerability
     3. MDaemon Default Mail System Account Vulnerability
     4. MDaemon Weak Password Encoding Vulnerability
     5. MDaemon WorldClient Folder Creation Buffer Overflow Vulnerability
     6. Lysias Lidik Webserver  Directory Traversal Vulnerability
     7. WorldClient Arbitrary File Deletion Vulnerability
     8. Critical Path InJoin Directory Server Cross-Site Scripting...
     9. Critical Path InJoin Directory Server File Disclosure...
     10. Microsoft MSN Chat Control Remote Buffer Overflow Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
     1. Windows 200 VPN (Thread)
     2. 2K Server locking 98 users out (Thread)
     3. FTP tagging (Thread)
     4. FTP tagging (Thread)
     5. 2K Server locking 98 users out (Thread)
     6. Publishing Nimda Logs - Summary (Thread)
     7. Publishing Nimda Logs (Thread)
     8. SecurityFocus Microsoft Newsletter #85 (Thread)
     9. Publishing Nimda Logs (Thread)
     10. Macromedia Flash Activex Buffer overflow (Thread)
     11. HfNetChk Message: File versions greater than expected: (Thread)
     12. 'rooted' NT/2K boxen? (Thread)
     13. 'rooted' NT/2K boxen? (Thread)
     14. Rolling out patches (Thread)
IV. NEW PRODUCTS FOR MICROSOFT PLATFORMS
     1. VigilEnt User Manager/Password Management
     2. HushMail Professional
     3. SuperScout Email Filter
V. NEW TOOLS FOR MICROSOFT PLATFORMS
     1. OpenAI v0.2
     2. EtherFlood v1.1
     3. SecureCFM v1.0
     4. WmiEvt.pl v3.17
VI. SPONSORSHIP INFORMATION


I. FRONT AND CENTER
-------------------
1. Securing Exchange 2000, Part Two
By Chris Weber

This is the second installment in the two-part series on securing Exchange
2000. This article will focus on secure configuration and administration
of Exchange 2000, including locking down Exchange, and an analysis of some
publicized vulnerabilities.

http://online.securityfocus.com/infocus/1578

2.  IDS Evasion Techniques and Tactics
by Kevin Timm

Blackhats, security researchers and network intrusion detection system
(NIDS) developers have continually played a game of point-counterpoint
when it comes to NIDS technology. The BlackHat community continually
develops methods to evade or bypass NIDS sensors while NIDS vendors
continually counter act these methods with patches and new releases. Due
to the inherent complexities involved in capturing, analyzing and
understanding network traffic there are several common techniques that can
be used to exploit inherent weaknesses in NIDSs.

http://online.securityfocus.com/infocus/1577

3. Slot Machine Justice for Melissa Author
By Mark Rasch

Under capricious computer crime sentencing rules, virus-writer David Smith
managed to get the right prison term for all the wrong reasons.

http://online.securityfocus.com/columnists/81

4. Information Resilience and Homeland Security
By Richard Forno

Freedom of information may be a double-edged sword, but restricting
information has only one edge - and it cuts off the lifeblood of a healthy
democracy.

http://online.securityfocus.com/columnists/80

5. Patch Management Done Right
By Tim Mullen

There is no getting around the fact that the even the nominal use of
Microsoft products requires regular component upgrades and patches. When
you are a card-carrying Microsoft supporter like I am, and your
infrastructure runs the gamut of their product offerings, updating servers
and workstations can get downright ugly. Just maintaining the critical
updates containing security rollups and patches can be taxing.

http://online.securityfocus.com/columnists/79


II. BUGTRAQ SUMMARY
-------------------
1. ACD Systems ACDSee Photo Album File Description Buffer Overflow Vulnerability
BugTraq ID: 4719
Remote: Yes
Date Published: May 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4719
Summary:

ACDSee is an image viewing, conversion and management tool for Microsoft
Windows based machines. ACDSee defines a Photo Album file format,
associated with the .ais file extension.

The .ais file is text formatted, with each line containing an absolute
path and image followed by a description. Reportedly, including a
description longer than 256 characters may cause a buffer overflow
condition in ACDSee.

Allegedly, while the image files will load and display properly, ACDSee
will crash when the file properties are viewed. In the event that this is
caused by a buffer overflow, it may prove possible to execute arbitrary
code through exploitation of this vulnerability. This possibility has not,
however, been confirmed.

There have been conflicting reports about the existence of this flaw.

2. Microsoft MSN Messenger Font Tag Denial Of Service Vulnerability
BugTraq ID: 4675
Remote: Yes
Date Published: May 06 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4675
Summary:

MSN Messenger is an instant messenging client for Microsoft Windows
systems, based on the Passport system.

A vulnerability has been reported in some versions of MSN Messenger. Under
some circumstances, it may be possible to crash the client when it
receives an instant message with a misformatted font variable in the
message header.  By including a large amount of data in the field that
typically contains the font name, and sending the message to a remote
user, it is possible to crash a remote user's client.

This problem makes it possible for remote users to crash the MSN Messenger
clients of other users.  This problem may be due to a buffer overflow
vulnerability, creating the possibility of remote code execution.  This
possibility is currently unconfirmed.

3. MDaemon Default Mail System Account Vulnerability
BugTraq ID: 4685
Remote: Yes
Date Published: May 07 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4685
Summary:

MDaemon is a Microsoft Windows based mail server product.

MDaemon ships with a default mail system account.  The username and
password of this account are hard-coded into the program, and set by the
system during installation.

The username is 'MDaemon' and the password is 'MServer'.  This default
account is used internally by the software and is not intended to be used
as a normal mail user.

1. Mailscanner for Postfix v0.0.6pl1
2. File::Scan v0.24
3. DreamSys Server Monitor v3.1

The system does not prompt administrators to change the default MDaemon
password after installation.  Therefore, this account may be abused by
remote attackers.

4. MDaemon Weak Password Encoding Vulnerability
BugTraq ID: 4686
Remote: No
Date Published: May 07 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4686
Summary:

MDaemon is a Microsoft Windows based mail server product.

Encoding for the MDaemon password file (userlist.dat) may be easily
broken.  Each character in the password file is shifted using a static
offset and then base64 encoded.

Local attackers with read access to the password file may trivially decode
the passwords for MDaemon mail users.

5. MDaemon WorldClient Folder Creation Buffer Overflow Vulnerability
BugTraq ID: 4689
Remote: Yes
Date Published: May 07 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4689
Summary:

MDaemon is an integrated mail transport agent, webmail, and mail
anti-virus package.  It is available for Microsoft Windows operating
systems.

A problem with the package could make it possible for a remote user to
execute arbitrary code.  The problem is in the handling of long data
strings.

It may be possible for a remote user to take advantage of a buffer
overflow in the MDaemon software package.  The WorldClient.cgi program
packaged with MDaemon does not properly check bounds on user-supplied
data.  During the process of creating a folder with a long name, it is
possible to exploit a buffer overflow in the CGI that could result in the
overwriting of process memory, and execution of attacker-supplied
instructions.

It should be noted that exploitation of this vulnerability will result in
the execution of code with SYSTEM privileges on a Windows system.
Additionally, an attacker exploiting this vulnerability must be
authenticated through a regular account on MDaemon system.  Exploitation
of this vulnerability will result in a remote attacker gaining local
administrative privileges on a vulnerable system.

It has been confirmed by SecurityFocus staff that this vulnerability may
be exploited both via a web browser, or a connection through a client
program such as netcat or telnet.

6. Lysias Lidik Webserver  Directory Traversal Vulnerability
BugTraq ID: 4691
Remote: Yes
Date Published: May 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4691
Summary:

Lysias Lidik Webserver is a small webserver built for the Microsoft
Windows platform.

The current version of Lidik is a beta version. This version has a
vulnerability that allows for remote directory traversal.

The webserver does not parse '.../' character sequences from the URL.  A
remote attacker may be able to view and download any file on the webserver
by entering a carefully crafted request.

The attacker is not able to view directories with a space in the directory
name by including the space in the URL.  Such directories may be accessed
by using their DOS 8.3 filename format.

Entering http://localhost/.../...//Progra~1/ as the URL will allow the
attacker to browse the 'Program Files' directory.

7. WorldClient Arbitrary File Deletion Vulnerability
BugTraq ID: 4687
Remote: Yes
Date Published: May 07 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4687
Summary:

WorldClient is a web interface packaged with MDaemon, an email server for
Microsoft Windows.

A vulnerability exists in WorldClient (version 5.0.5 and older) that
allows for an attacker to delete an arbitrary file on the webserver it
resides on.

The vulnerability occurs when a user chooses to delete an attachment from
their folder. Checks aren't made on the filename to prevent directory
traversal. Thus a user is able to carefully craft a request that will
cause any file writeable by the webserver process to be deleted.

If critical files are deleted, a denial of service may occur.

8. Critical Path InJoin Directory Server Cross-Site Scripting Vulnerability
BugTraq ID: 4717
Remote: Yes
Date Published: May 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4717
Summary:

Critical Path provides an LDAP (Lightweight Directory Access Protocol)
Directory Server called InJoin.  InJoin Directory is provided for
Microsoft Windows operating systems and Unix variants. InJoin Directory
Server includes a web-based administrative interface entitled iCon.  The
iCon service listens on port 1500.

A cross-site scripting vulnerability has been reported in the iCon
component of InJoin Directory Server.

HTML code is not filtered from URL parameters that are used as output in
the web-based administrative interface.  This enables an attacker to
inject malicious script code into a link to the administrative interface.
When this link is visited by an authenticated administrative user, the
attacker's script code will be executed in the browser of that user, in
the security context of the site running the interface.

Successful exploitation may allow the attacker to steal cookie-based
authentication credentials from the administrative user.  An attacker may
use these credentials to hijack the session of the administrative user.

9. Critical Path InJoin Directory Server File Disclosure Vulnerability
BugTraq ID: 4718
Remote: Yes
Date Published: May 10 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4718
Summary:

Critical Path provides an LDAP (Lightweight Directory Access Protocol)
Directory Server called InJoin.  InJoin Directory Server is provided for
Microsoft Windows operating systems and Unix variants.  iCon is the
administrative web interface for the InJoin Directory Server.

An attacker with a valid administrative username and password is able to
view any file on the system that is accessible to the owner of the iCon
process.

The iCon web administrative interface listens on TCP port 1500 and is run
with the permissions of an 'ids' user. By connecting to this port using a
web browser and entering a correct administrator username and password, an
attacker is able to remotely administer the Directory Server and view log
entries. The log entry parameter, passed to the module via URL, does not
provide adequate checks to limit which files are opened and displayed to
the client.

An attacker is able to view the contents of any file by explicitly
specifying the full pathname of a file in the URL. However, only those
files that a accessible by the owner of the iCon process, will be
disclosed.

10. Microsoft MSN Chat Control Remote Buffer Overflow Vulnerability
BugTraq ID: 4707
Remote: Yes
Date Published: May 08 2002 12:00A
Relevant URL:
http://www.securityfocus.com/bid/4707
Summary:

The Microsoft MSN Chat Control is an ActiveX object used to provide chat
functionality. It is included by default with a number of Microsoft
products, including recent versions of MSN Messenger.

The MSN Chat ActiveX control is vulnerable to a buffer overflow. If a
malicious, oversized parameter is passed to this object, stack memory will
be overwritten, including stack frame information. It is possible to
exploit this condition to execute arbitrary code as the process.

This vulnerability may be exploited by invoking the vulnerable control
through HTML.  As such, this problem may be exploited when a user views a
web page, HTML formatted email or any other process which causes HTML to
be rendered by Internet Explorer.

It should be noted that as the vulnerable component was originally signed
by Microsoft, it is possible for a malicious server to host the vulnerable
component for download. Unpatched users may then accept and trust the
component.


III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Windows 200 VPN (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

2. 2K Server locking 98 users out (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

3. FTP tagging (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

4. FTP tagging (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

5. 2K Server locking 98 users out (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/Pine.WNT.4.44.0205081055310.-46145483-100000@dave

6. Publishing Nimda Logs - Summary (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

7. Publishing Nimda Logs (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

8. SecurityFocus Microsoft Newsletter #85 (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

9. Publishing Nimda Logs (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/9D884881F5E1F24FB845967851720FC302C9BB38@red-msg-12.redmond.corp.microsoft.com

10. Macromedia Flash Activex Buffer overflow (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

11. HfNetChk Message: File versions greater than expected: (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

12. 'rooted' NT/2K boxen? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

13. 'rooted' NT/2K boxen? (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/[email protected]

14. Rolling out patches (Thread)
Relevant URL:

http://online.securityfocus.com/archive/88/5DDDFEB53CECD211A8410001FA7E99600C0A4000@xcem-casfo-10.wellsfargo.com


IV.NEW PRODUCTS FOR MICROSOFT PLATFORMS
----------------------------------------
1. VigilEnt User Manager/Password Management
by PentaSafe
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Relevant URL:
http://www.pentasafe.com/products/vum.htm
Summary:

VigilEnt User Manager provides users with access to multiple systems while
increasing enterprise security through the enforcement of stronger
password policy. Instead of having to go through the tedious process of
logging into each application to conduct password changes, VigilEnt User
Manager's password synchronization capabilities allow an end user to
initiate a password change across all their systems and applications with
a single action from the Web-based interface. Once a password has been
validated, the password change request is disseminated to all applicable
user login systems ensuring a synchronized enterprise-wide password. The
password change process is complete when users are notified of successful
changes.

2. HushMail Professional
by Hush Communications
Platforms: Windows 2000
Relevant URL:
http://www.hush.com/solutions/hushmail_professional/
Summary:

HushMail Professional for Outlook 2000 protects your electronic
communications without requiring you to change Microsoft Outlook 2000,
enabling you to enjoy the full protection of Hush's state-of-the-art
encryption and key-serving technology while in your familiar email
environment. Features include: Fully encrypted email solution ,Transparent
key management ,All your usual email features with added state-of-the-art
security ,No change to current Email service ,No change to current Email
address ,User can secure more than one account ,User may select whether or
not they want to encrypt a message ,Easy to view whether an incoming
message was encrypted/signed ,Easy to install ,Easy to operate ,OpenPGP
support


3. SuperScout Email Filter
by SurfControl
Platforms: Windows 2000, Windows 95/98, Windows NT
Relevant URL:
http://www.surfcontrol.com/business/products/superscout_email/
Summary:

SuperScout Email Filter protects against such dangers by giving you the
information and tools to implement as well as enforce an email Acceptable
Use Policy that can help to: Increase Security, Limit Legal Liability, and
Improve Productivity


V. NEW TOOLS FOR MICROSOFT PLATFORMS
------------------------------------
1. OpenAI v0.2
by thornhalo [email protected]
Relevant URL:
http://openai.sourceforge.net/downloads.html
Platforms: Linux, POSIX, Solaris, SunOS, Windows 2000, Windows 95/98,
Windows NT, Windows XP
Summary:

The OpenAI site is centered around an Open Source project and community
involving artificial intelligence. The project itself is the creation of a
set of tools that are considered to be models of human intelligence or
biomimicry. These tools are intended to be integrated into applications or
used stand alone for research.

2. EtherFlood v1.1
by Arne Vidstrom [email protected]
Relevant URL:
http://ntsecurity.nu/toolbox/etherflood/
Platforms: Windows 2000, Windows XP
Summary:

EtherFlood floods a switched network with Ethernet frames with random
hardware addresses. The effect on some switches is that they start sending
all traffic out on all ports so you can sniff all traffic on the network.

3. SecureCFM v1.0
by Dimitri Muringer
Relevant URL:
http://scfm.sourceforge.net/
Platforms: Linux, Windows 95/98, Windows NT, Windows XP
Summary:

SecureCFM is dedicated to the audit of ColdFusion source code (CFML), in
order to detect then correct possible Cross Site Scripting
vulnerabilities.

4. WmiEvt.pl v3.17
by H. Carvey [email protected]
Relevant URL:
http://patriot.net/%7Ecarvdawg/scripts/wmievt.pl
Platforms: Windows NT
Summary:

This script uses WMI to watch the Win2K EventLog for new events. It will
also work on NT if the WMI classes are installed. The benefit is that is
uses NO POLLING to look for new events. It can form the basis of more
involved scripts such as syslog clients, etc.


VI. SPONSORSHIP INFORMATION
---------------------------
This newsletter is sponsored by SecurityFocus (www.securityfocus.com)

Attention Non-profits and Universities: Sign-up now for preferred pricing
on the only global early-warning system for cyber attacks - SecurityFocus
ARIS Threat Management System.

Click here for more info
http://www.securityfocus.com/corporate/products/pdpsection.shtml

-------------------------------------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.