Debasis Mohanty | 1 Oct 2005 05:59

RE: Re: Bypassing Personal Firewall (Zone Alarm Pro)Using DDE-IPC

Paul Laudanski
>> If you're still using version 3 its time to upgrade.  There is a version
6 out now.  
>> And in their press release, only the free is affected.

Funny !! Thanks for suggestion :P

-----Original Message-----
From: Paul Laudanski [mailto:zx <at> castlecops.com] 
Sent: Saturday, October 01, 2005 3:25 AM
To: Debasis Mohanty
Cc: warl0ck <at> linuxmail.org; full-disclosure <at> lists.grok.org.uk;
bugtraq <at> securityfocus.com
Subject: RE: [Full-disclosure] Re: Bypassing Personal Firewall (Zone Alarm
Pro)Using DDE-IPC

On Sat, 1 Oct 2005, Debasis Mohanty wrote:

> Paul Laudanski wrote:
> >> This "exploit" was tested by members at CastleCops and found to be
> untrue: 
> 
> Unfortunately not !! Besides Zone Alarm free version it has been 
> tested for ZA Pro 3x and it works like a charm. Again Symantec 
> SecurityFocus has probably tested this for ZA Pro 5.1. so they have 
> mentioned the vulnerable version here 
> http://securityfocus.com/bid/14966

If you're still using version 3 its time to upgrade.  There is a version 6
out now.  And in their press release, only the free is affected.
(Continue reading)

Martin Schulze | 1 Oct 2005 07:39
Favicon

[SECURITY] [DSA 833-1] New mysql-dfsg-4.1 packages fix arbitrary code execution


--------------------------------------------------------------------------
Debian Security Advisory DSA 833-1                     security <at> debian.org
http://www.debian.org/security/                             Martin Schulze
October 1st, 2005                       http://www.debian.org/security/faq
--------------------------------------------------------------------------

Package        : mysql-dfsg-4.1
Vulnerability  : buffer overflow
Problem type   : remote
Debian-specific: no
CVE ID         : CAN-2005-2558
BugTraq ID     : 14509

A stack-based buffer overflow in the init_syms function of MySQL, a
popular database, has been discovered that allows remote authenticated
users who can create user-defined functions to execute arbitrary code
via a long function_name field.  The ability to create user-defined
functions is not typically granted to untrusted users.

The following vulnerability matrix explains which version of MySQL in
which distribution has this problem fixed:

                     woody              sarge              sid
mysql             3.23.49-8.14           n/a               n/a
mysql-dfsg            n/a          4.0.24-10sarge1    4.0.24-10sarge1
mysql-dfsg-4.1        n/a          4.1.11a-4sarge2        4.1.14-2
mysql-dfsg-5.0        n/a                n/a            5.0.11beta-3

We recommend that you upgrade your mysql-dfsg-4.1 packages.
(Continue reading)

Martin Schulze | 1 Oct 2005 08:54
Favicon

[SECURITY] [DSA 834-1] New prozilla packages fix arbitrary code execution


--------------------------------------------------------------------------
Debian Security Advisory DSA 834-1                     security <at> debian.org
http://www.debian.org/security/                             Martin Schulze
October 1st, 2005                       http://www.debian.org/security/faq
--------------------------------------------------------------------------

Package        : prozilla
Vulnerability  : buffer overflow
Problem type   : remote
Debian-specific: no
CVE ID         : CAN-2005-2961

Tavis Ormandy discovered a buffer overflow in prozilla, a
multi-threaded download accelerator, which may be exploited to execute
arbitrary code.

For the old stable distribution (woody) this problem has been fixed in
version 1.3.6-3woody3.

The stable distribution (sarge) does not contain prozilla packages.

The unstable distribution (sid) does not contain prozilla packages.

We recommend that you upgrade your prozilla package.

Upgrade Instructions
--------------------

wget url
(Continue reading)

Martin Schulze | 1 Oct 2005 09:56
Favicon

[SECURITY] [DSA 835-1] New cfengine packages fix arbitrary file overwriting


--------------------------------------------------------------------------
Debian Security Advisory DSA 835-1                     security <at> debian.org
http://www.debian.org/security/                             Martin Schulze
October 1st, 2005                       http://www.debian.org/security/faq
--------------------------------------------------------------------------

Package        : cfengine
Vulnerability  : insecure temporary files
Problem type   : local
Debian-specific: no
CVE ID         : CAN-2005-2960

Javier Fernández-Sanguino Peña discovered several insecure temporary
file uses in cfengine, a tool for configuring and maintaining
networked machines, that can be exploited by a symlink attack to
overwrite arbitrary files owned by the user executing cfengine, which
is probably root.

For the old stable distribution (woody) these problems have been fixed in
version 1.6.3-9woody1.

For the stable distribution (sarge) these problems have been fixed in
version 1.6.5-1sarge1.

For the unstable distribution (sid) these problems have will be fixed soon.

We recommend that you upgrade your cfengine package.

Upgrade Instructions
(Continue reading)

Thierry Zoller | 1 Oct 2005 12:08

Re: Re: Bypassing Personal Firewall (Zone Alarm Pro)Using DDE-IPC

Dear Paul,

PL>  And in their press release, only the free is affected.
Which makes this discovery [ although a bit outdated ->
SendMessageApi() ] even more important, possibly a
few million users affected.

--

-- 
Thierry Zoller
Packet sniffer : http://www.sniff-em.com

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Martin Schulze | 1 Oct 2005 16:10
Favicon

[SECURITY] [DSA 836-1] New cfengine2 packages fix arbitrary file overwriting


--------------------------------------------------------------------------
Debian Security Advisory DSA 836-1                     security <at> debian.org
http://www.debian.org/security/                             Martin Schulze
October 1st, 2005                       http://www.debian.org/security/faq
--------------------------------------------------------------------------

Package        : cfengine2
Vulnerability  : insecure temporary files
Problem type   : local
Debian-specific: no
CVE ID         : CAN-2005-2960

Javier Fernández-Sanguino Peña discovered insecure temporary file use
in cfengine2, a tool for configuring and maintaining networked
machines, that can be exploited by a symlink attack to overwrite
arbitrary files owned by the user executing cfengine, which is
probably root.

The old stable distribution (woody) is not affected by this problem.

For the stable distribution (sarge) these problems have been fixed in
version 2.1.14-1sarge1.

For the unstable distribution (sid) these problems will be fixed soon.

We recommend that you upgrade your cfengine2 package.

Upgrade Instructions
--------------------
(Continue reading)

Debasis Mohanty | 1 Oct 2005 17:11

RE: Re: Bypassing Personal Firewall (Zone AlarmPro)Using DDE-IPC

I tested this earlier, SendMessage() / SetDlgItem() / SetWindowText()
doesn't work for the current version of ZA Products (ZA Pro / Internet Sec
Suit). 

This helps preventing the most wellknown windows local attack - Shatter
Attack.

However, I still can see a way out for their latest product... Will be
updated soon.

- Tr0y

-----Original Message-----
From: full-disclosure-bounces <at> lists.grok.org.uk
[mailto:full-disclosure-bounces <at> lists.grok.org.uk] On Behalf Of Thierry
Zoller
Sent: Saturday, October 01, 2005 3:39 PM
To: full-disclosure <at> lists.grok.org.uk
Subject: Re: [Full-disclosure] Re: Bypassing Personal Firewall (Zone
AlarmPro)Using DDE-IPC

Dear Paul,

PL>  And in their press release, only the free is affected.
Which makes this discovery [ although a bit outdated ->
SendMessageApi() ] even more important, possibly a few million users
affected.

--
Thierry Zoller
(Continue reading)

Thierry Zoller | 1 Oct 2005 17:33

Re: Re: Bypassing Personal Firewall (Zone AlarmPro)Using DDE-IPC


Dear Debasis,
DM> I tested this earlier, SendMessage() / SetDlgItem() / SetWindowText()
DM> doesn't work for the current version of ZA Products (ZA Pro / Internet Sec
DM> Suit).
I am not sure we are speaking about the same attack. When I was
speaking about SendMessage() I was refering to the presentation
at CCC2003, i.e shelling IE simulating a user through SendMessage()
Api.

DM> This helps preventing the most wellknown windows local attack - Shatter
DM> Attack.
AFAIK, it does not, the Shatter Attack doesn't necessarely rely on
SendMessage(), not to mention a driver shouldn't open a window at all
(not react to F1 messages either) <- if you read this and are a vendor
check for this.. gives SYSTEM rights occasionaly. (through
browse -> cmd.exe)

DM> However, I still can see a way out for their latest product... Will be
DM> updated soon.
Looking forward to it :)

--

-- 
Regards,
Thierry Zoller
mailto:Thierry <at> sniff-em.com

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
(Continue reading)

Jason Coombs | 1 Oct 2005 20:17

Careless Law Enforcement Computer Forensics Lacking InfoSec Expertise Causes Suicides

34 people have killed themselves in the U.K. after being accused of 
purchasing child pornography using their credit card numbers on the Web 
between 1996 and 1999; and thousands have been imprisoned around the 
world for allegedly doing the same. Two of the first, and still ongoing, 
large-scale investigations of credit card purchases of child pornography 
through the Internet are known as Operation Ore (U.K.) and Operation 
Site Key (U.S.) -- tens of thousands of suspects' credit card numbers 
were found in the databases used by the alleged e-commerce child porn 
ring, and law enforcement's careless misunderstanding of the Internet 
and infosec (circa 1999) resulted in every single one of the suspects 
being investigated and thousands have so far been prosecuted and convicted.

Was your credit card number in the Operation Ore / Operation Site Key 
database? How would you know unless and until you've been arrested?

Over the last few years I have seen numerous cases in which the computer 
forensic evidence proves that a third party intruder was in control of 
the suspect's computer. More often there is simply no way to know for 
sure what might have happened between 1996 and 1999 with respect to the 
computer seized by law enforcement at the time of arrest years later.

If security flaws, porn spyware, or mistakes by an unskilled end user 
resulted, over the years, in some child pornography being downloaded to 
a suspect's hard drive, even in 'thumbnail' graphic formats and 
recovered only using forensic data recovery tools that carve files out 
of unallocated clusters, then the suspect is routinely charged, since 
the presence of child pornography on a hard drive owned by a person who 
is accused of purchasing child pornography is the best evidence law 
enforcement has to prove guilt of these so-called 'electronic crimes 
against children' -- crimes that are proved by the mere existence of 
(Continue reading)

Florian Weimer | 1 Oct 2005 20:40
Picon

Re: Re: Bypassing Personal Firewall (Zone AlarmPro)Using DDE-IPC

* Debasis Mohanty:

> I tested this earlier, SendMessage() / SetDlgItem() / SetWindowText()
> doesn't work for the current version of ZA Products (ZA Pro / Internet Sec
> Suit). 
>
> This helps preventing the most wellknown windows local attack - Shatter
> Attack.

If I understand things correctly, in the attack Thierry describes, you
don't send window messages to windows of the Zone Alarm process (which
might be protected indeed), but to the Internet Explorer windows.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Gmane