<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bugtraq</title>
    <link>http://seclists.org/#bugtraq</link>
    <atom:link href="http://seclists.org/rss/bugtraq.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>The premier general security mailing list. Vulnerabilities are often announced here first, so check frequently!</description>
    <pubDate>Tue, 09 Feb 2010 00:45:05 GMT</pubDate>
    <lastBuildDate>Tue, 09 Feb 2010 00:45:05 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>[CORE-2010-0121] Multiple Vulnerabilities with 8.3 Filename Pseudonyms in Web Servers</title>
    <link>http://seclists.org/bugtraq/2010/Feb/91</link>
    <description>&lt;p&gt;Posted by CORE Security Technologies Advisories on Feb 08&lt;/p&gt;      Core Security Technologies - CoreLabs Advisory&lt;br&gt;
           &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.coresecurity.com/corelabs/&quot;&gt;http://www.coresecurity.com/corelabs/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Multiple Vulnerabilities with 8.3 Filename Pseudonyms in Web Servers&lt;br&gt;
&lt;br&gt;
1. *Advisory Information*&lt;br&gt;
&lt;br&gt;
Title: Multiple Vulnerabilities with 8.3 Filename Pseudonyms in Web Servers&lt;br&gt;
Advisory Id: CORE-2010-0121&lt;br&gt;
Advisory URL:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.coresecurity.com/content/filename-pseudonyms-vulnerabilities&quot;&gt;http://www.coresecurity.com/content/filename-pseudonyms-vulnerabilities&lt;/a&gt;&lt;br&gt;
Date published: 2010-02-05&lt;br&gt;
Date of last update: 2010-02-05...&lt;br&gt;</description>
    <pubDate>Tue, 09 Feb 2010 00:33:30 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Feb/91</guid>
  </item>
  <item>
    <title>[Hacking Event] Night Da Hack 2010 : Call For Proposals</title>
    <link>http://seclists.org/bugtraq/2010/Feb/90</link>
    <description>&lt;p&gt;Posted by m . mahdjoub on Feb 08&lt;/p&gt;- Night Da Hack 2010&lt;br&gt;
&lt;br&gt;
Date: June 19-20 2010&lt;br&gt;
Time: 4 PM - 7 AM&lt;br&gt;
Location: Paris, France&lt;br&gt;
&lt;br&gt;
What is Night da Hack?&lt;br&gt;
“Night da Hack” comes from a rough translation from French “Nuit du Hack”. Started in 2003 by Hackerz Voice team, and &lt;br&gt;
inspired by world famous DEF CON, “Nuit du Hack” is one of the oldest French underground hacking conference.&lt;br&gt;
&lt;br&gt;
Around computer security related talks, workshops and contests, Night da Hack aims at bringing...&lt;br&gt;</description>
    <pubDate>Tue, 09 Feb 2010 00:29:11 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Feb/90</guid>
  </item>
  <item>
    <title>JDownloader Remote Code Execution</title>
    <link>http://seclists.org/bugtraq/2010/Feb/89</link>
    <description>&lt;p&gt;Posted by Matthias -apoc- Hecker on Feb 08&lt;/p&gt;-- Product&lt;br&gt;
&lt;br&gt;
JDownloader[1] is an open source download manager for One-Click-&lt;br&gt;
Filehoster like Rapidshare or Megaupload. The Click'n'Load[2] interface&lt;br&gt;
allows external applications and websites to send URLs to the local&lt;br&gt;
running JDownloader. With Click'n'Load2 [3] it is possible to sent&lt;br&gt;
AES-CBC encrypted URLs (for some kind of link 'obfuscation').&lt;br&gt;
The encrypted payload _and_ key are sent with an HTTP-POST submit on&lt;br&gt;
localhost port 9666 (default port,...&lt;br&gt;</description>
    <pubDate>Tue, 09 Feb 2010 00:24:00 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Feb/89</guid>
  </item>
  <item>
    <title>Re: Samba Remote Zero-Day Exploit</title>
    <link>http://seclists.org/bugtraq/2010/Feb/88</link>
    <description>&lt;p&gt;Posted by Stefan Kanthak on Feb 08&lt;/p&gt;Dan Kaminsky wrote on February 06, 2010 6:43 PM:&lt;br&gt;
&lt;br&gt;
OUCH!&lt;br&gt;
No, creating junctions (as well as the Vista introduced symlinks)&lt;br&gt;
DOESN'T need admin rights!&lt;br&gt;
&lt;br&gt;
[snip]&lt;br&gt;
&lt;br&gt;
Stefan&lt;br&gt;</description>
    <pubDate>Tue, 09 Feb 2010 00:10:10 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Feb/88</guid>
  </item>


  <item>
    <title>Re: Samba Remote Zero-Day Exploit</title>
    <link>http://seclists.org/bugtraq/2010/Feb/87</link>
    <description>&lt;p&gt;Posted by Dan Kaminsky on Feb 08&lt;/p&gt;You need admin rights to create junctions. At that point, path  &lt;br&gt;
constraints aren't relevant, just psexec and get not only arbitrary  &lt;br&gt;
path but arbitrary code.&lt;br&gt;
&lt;br&gt;
The fix is to do what everybody with a directory traversal bug has to  &lt;br&gt;
do, block out of path relative directories. In this specific case,  &lt;br&gt;
prevent the creation of symlinks where the target is out of the SMB  &lt;br&gt;
share's range. (Still allow navigation to such symlinks if one exists,...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 23:29:35 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Feb/87</guid>
  </item>
  <item>
    <title>Re: Samba Remote Zero-Day Exploit</title>
    <link>http://seclists.org/bugtraq/2010/Feb/86</link>
    <description>&lt;p&gt;Posted by Kingcope on Feb 08&lt;/p&gt;Hello Paul,&lt;br&gt;
&lt;br&gt;
First and foremost I did not know about the configuration setting which&lt;br&gt;
closes the bug when i posted the advisory. So this was my mistake.&lt;br&gt;
But for the most servers which are not entirely hardened (and my&lt;br&gt;
assumption is that this applies to many servers in internal networks)&lt;br&gt;
the traversal can be a serious issue, because a samba user (even nobody)&lt;br&gt;
can create the symlinks. It would in my point of view be more secure to&lt;br&gt;
only allow...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 22:55:21 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Feb/86</guid>
  </item>
  <item>
    <title>RE: Samba Remote Zero-Day Exploit</title>
    <link>http://seclists.org/bugtraq/2010/Feb/85</link>
    <description>&lt;p&gt;Posted by Michael Wojcik on Feb 08&lt;/p&gt;symlinks&lt;br&gt;
&lt;br&gt;
And at least since Vista, it also supports symlinks, which are designed&lt;br&gt;
to mimic Unix symlinks, and can point to files or directories. Junctions&lt;br&gt;
and symlinks can cross volumes; symlinks can also refer to files or&lt;br&gt;
directories on network filesystems.&lt;br&gt;
&lt;br&gt;
Junctions (which Microsoft also sometimes refers to as &amp;quot;soft links&amp;quot;) and&lt;br&gt;
symlinks are implemented with NTFS reparse points, just like mounts. You&lt;br&gt;
can see some of the differences...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 22:07:45 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Feb/85</guid>
  </item>
  <item>
    <title>Re: Samba Remote Zero-Day Exploit</title>
    <link>http://seclists.org/bugtraq/2010/Feb/84</link>
    <description>&lt;p&gt;Posted by paul . szabo on Feb 08&lt;/p&gt;Dear Kingcope,&lt;br&gt;
&lt;br&gt;
The samba server follows symlinks by default. There are options&lt;br&gt;
(&amp;quot;follow symlinks&amp;quot;, &amp;quot;wide links&amp;quot;) for turning it off:&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.samba.org/samba/docs/using_samba/ch08.html#samba2-CHP-8-SECT-1.2&quot;&gt;http://www.samba.org/samba/docs/using_samba/ch08.html#samba2-CHP-8-SECT-1.2&lt;/a&gt;&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#FOLLOWSYMLINKS&quot;&gt;http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#FOLLOWSYMLINKS&lt;/a&gt;&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#WIDELINKS&quot;&gt;http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#WIDELINKS&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
The &amp;quot;problem&amp;quot; at your installation seems a...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 21:35:47 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Feb/84</guid>
  </item>
  <item>
    <title>[security bulletin] HPSBUX02503 SSRT100019 rev.1 - HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other</title>
    <link>http://seclists.org/bugtraq/2010/Feb/83</link>
    <description>&lt;p&gt;Posted by security-alert on Feb 08&lt;/p&gt;SUPPORT COMMUNICATION - SECURITY BULLETIN&lt;br&gt;
&lt;br&gt;
Document ID: c01997760&lt;br&gt;
Version: 1&lt;br&gt;
&lt;br&gt;
HPSBUX02503 SSRT100019 rev.1 - HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other&lt;br&gt;
&lt;br&gt;
Vulnerabilities&lt;br&gt;
&lt;br&gt;
NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.&lt;br&gt;
&lt;br&gt;
Release Date: 2010-02-08&lt;br&gt;
Last Updated: 2010-02-08&lt;br&gt;
&lt;br&gt;
Potential Security Impact: Remote Increase in privilege, Denial of Service and other vulnerabilities...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 21:00:50 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Feb/83</guid>
  </item>
  <item>
    <title>[security bulletin] HPSBMA02487 SSRT100024 rev.1 - HP Operations Agent Running on Solaris 10, Remote Unauthorized Access</title>
    <link>http://seclists.org/bugtraq/2010/Feb/82</link>
    <description>&lt;p&gt;Posted by security-alert on Feb 08&lt;/p&gt;SUPPORT COMMUNICATION - SECURITY BULLETIN&lt;br&gt;
&lt;br&gt;
Document ID: c02002298&lt;br&gt;
Version: 1&lt;br&gt;
&lt;br&gt;
HPSBMA02487 SSRT100024 rev.1 - HP Operations Agent Running on Solaris 10, Remote Unauthorized Access&lt;br&gt;
&lt;br&gt;
NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.&lt;br&gt;
&lt;br&gt;
Release Date: 2010-02-08&lt;br&gt;
Last Updated: 2010-02-08&lt;br&gt;
&lt;br&gt;
Potential Security Impact: Remote unauthorized access&lt;br&gt;
&lt;br&gt;
Source: Hewlett-Packard Company, HP Software Security Response Team...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 20:53:22 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Feb/82</guid>
  </item>
  <item>
    <title>[ MDVSA-2010:034 ] kernel</title>
    <link>http://seclists.org/bugtraq/2010/Feb/81</link>
    <description>&lt;p&gt;Posted by security on Feb 08&lt;/p&gt; _______________________________________________________________________&lt;br&gt;
&lt;br&gt;
 Mandriva Linux Security Advisory                         MDVSA-2010:034&lt;br&gt;
 &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.mandriva.com/security/&quot;&gt;http://www.mandriva.com/security/&lt;/a&gt;&lt;br&gt;
 _______________________________________________________________________&lt;br&gt;
&lt;br&gt;
 Package : kernel&lt;br&gt;
 Date    : February 8, 2010&lt;br&gt;
 Affected: 2009.0, Enterprise Server 5.0&lt;br&gt;
 _______________________________________________________________________&lt;br&gt;
&lt;br&gt;
 Problem Description:&lt;br&gt;
&lt;br&gt;
 Some...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 20:42:42 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Feb/81</guid>
  </item>
  <item>
    <title>Re: [Full-disclosure] Samba Remote Zero-Day Exploit</title>
    <link>http://seclists.org/bugtraq/2010/Feb/80</link>
    <description>&lt;p&gt;Posted by Thierry Zoller on Feb 08&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://blog.metasploit.com/2010/02/exploiting-samba-symlink-traversal.html&quot;&gt;http://blog.metasploit.com/2010/02/exploiting-samba-symlink-traversal.html&lt;/a&gt;&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 20:31:45 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Feb/80</guid>
  </item>
  <item>
    <title>Re: [Full-disclosure] Samba Remote Zero-Day Exploit</title>
    <link>http://seclists.org/bugtraq/2010/Feb/79</link>
    <description>&lt;p&gt;Posted by Thierry Zoller on Feb 08&lt;/p&gt;Hi Paul,&lt;br&gt;
&lt;br&gt;
Facts :&lt;br&gt;
- Several distributions run with vulnerable settings per default&lt;br&gt;
  if there is a &amp;quot;misconfiguration&amp;quot; it is part of the vendor.&lt;br&gt;
- Your not supposed to be able to traverse dirs.&lt;br&gt;
&lt;br&gt;
Consequence it is a vulnerability, whether you can mitigate it is&lt;br&gt;
a different piece of cake.&lt;br&gt;
&lt;br&gt;
Next time somebody creates an IE8 0day that relies on javascript,&lt;br&gt;
will  you  scream  &amp;quot;misconfiguration!&amp;quot;  ?  Of course you could disable...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 20:21:42 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Feb/79</guid>
  </item>
  <item>
    <title>Re: Samba Remote Zero-Day Exploit</title>
    <link>http://seclists.org/bugtraq/2010/Feb/78</link>
    <description>&lt;p&gt;Posted by Dan Kaminsky on Feb 08&lt;/p&gt;On Feb 6, 2010, at 5:26 PM, &amp;quot;Stefan Kanthak&amp;quot; &amp;lt;stefan.kanthak () nexgo de&amp;gt;  &lt;br&gt;
wrote:&lt;br&gt;
&lt;br&gt;
Really?  Try. Especially remotely over SMB w/o remote interactive.&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 20:10:34 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Feb/78</guid>
  </item>
  <item>
    <title>Re: Samba Remote Zero-Day Exploit</title>
    <link>http://seclists.org/bugtraq/2010/Feb/77</link>
    <description>&lt;p&gt;Posted by paul . szabo on Feb 08&lt;/p&gt;Dear Kingcope,&lt;br&gt;
&lt;br&gt;
Correct.&lt;br&gt;
&lt;br&gt;
Maybe what you want is for Samba to add and support an option like&lt;br&gt;
&amp;quot;allow create symlink&amp;quot; (with default &amp;quot;no&amp;quot;). I myself do not think it&lt;br&gt;
would be useful... would surely be a few lines of code only, so if you&lt;br&gt;
want to submit a patch to the Samba team... or just patch your own&lt;br&gt;
servers (as I do, see &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.maths.usyd.edu.au/u/psz/samba/&quot;&gt;http://www.maths.usyd.edu.au/u/psz/samba/&lt;/a&gt;).&lt;br&gt;
&lt;br&gt;
Cheers, Paul&lt;br&gt;
&lt;br&gt;
Paul Szabo   psz () maths usyd edu au...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 19:39:22 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Feb/77</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
