<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.0.4" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Virus Alerts</title>
	<link>http://www.captivereefing.com/virusblog</link>
	<description>Virus, worm, exploit and alerts.</description>
	<pubDate>Thu, 31 Jul 2008 13:41:19 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.4</generator>
	<language>en</language>
			<item>
		<title>RE: All of the things you need to learn to be a pen-tester (Re: Pen t est basic needs)</title>
		<link>http://www.captivereefing.com/virusblog/2008/07/31/re-all-of-the-things-you-need-to-learn-to-be-a-pen-tester-re-pen-t-est-basic-needs-7/</link>
		<comments>http://www.captivereefing.com/virusblog/2008/07/31/re-all-of-the-things-you-need-to-learn-to-be-a-pen-tester-re-pen-t-est-basic-needs-7/#comments</comments>
		<pubDate>Thu, 31 Jul 2008 13:41:19 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Threats</category>
		<guid isPermaLink="false">http://www.captivereefing.com/virusblog/2008/07/31/re-all-of-the-things-you-need-to-learn-to-be-a-pen-tester-re-pen-t-est-basic-needs-7/</guid>
		<description><![CDATA[U will probably need to &#8220;morphine&#8221; your evil apps before you run them on an AV protected machine - download morphine from hxdef.org; might as well pick up a copy of hf&#8217;s rootkit while your there&#8230;
Richard
- every1 say: &#8220;thankyou HF!&#8221;
&#8212;&#8211;Original Message&#8212;&#8211;
From: Matt Reid [mailto:matthew@servepath.com]
Sent: Saturday, 6 August 2005 8:06 AM
To: Omar Herrera; pen-test@securityfocus.com
Subject: Re: All [...]]]></description>
			<content:encoded><![CDATA[<p>U will probably need to &#8220;morphine&#8221; your evil apps before you run them on an AV protected machine - download morphine from hxdef.org; might as well pick up a copy of hf&#8217;s rootkit while your there&#8230;<br />
Richard<br />
- every1 say: &#8220;thankyou HF!&#8221;<br />
&#8212;&#8211;Original Message&#8212;&#8211;<br />
From: Matt Reid [mailto:matthew@servepath.com]<br />
Sent: Saturday, 6 August 2005 8:06 AM<br />
To: Omar Herrera; pen-test@securityfocus.com<br />
Subject: Re: All of the things you need to learn to be a pen-tester (Re: Pen t est basic needs)<br />
Hi all,<br />
Here is a basic list of some progs to use for pen-testing. If anyone<br />
wants to add some on here in the respective categories we could get a<br />
really good list going for pen-testers!<br />
-Matt Reid<br />
*Port Scanners*<br />
Amap – versioning port scanner<br />
NMap – general purpose port scanner<br />
pPscan – proxy port scanner<br />
*<br />
Vuln Scanners*<br />
Nessus – general vul. scanner<br />
DNAscan – for ASP<br />
Owa – Outlook Web<br />
Nikto – http vulns<br />
*Brute Forcers &#038; Crackers*<br />
John the Ripper – password cracker<br />
WlGen – word list generator<br />
Hydra – multi-protocol authentication brute forcer<br />
*DNS enumeration*<br />
Ghba – RDNS scanner<br />
Dig – DNS lookup util<br />
Nslookup – interactive name server query engine<br />
*Loggers*<br />
Tcpdump – network traffic dumper<br />
Ethereal – network traffic analyzer – use in conjunction with tcpdump<br />
Kismet – wifi traffic analyzer<br />
*Dicts [to concat into larger file]*<br />
Argon – 2GB dict file<br />
Cracklib -  another good one<br />
Word.lst  - word list<br />
*Trojans &#038; Rootkits*<br />
BackOrifice - Back Orifice is not a virus. It is in essence a remote<br />
administration tool.<br />
LRK – Linux-kernel Root Kit<br />
Netbus - NetBus runs under the NT operating system as well as Win95/98<br />
*Firewall Throughpass*<br />
Firewalk – trace packets through firewall filters<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You Don&#8217;t<br />
Learn the hacker&#8217;s secrets that compromise wireless LANs. Secure your<br />
WLAN by understanding these threats, available hacking tools and proven<br />
countermeasures. Defend your WLAN against man-in-the-Middle attacks and<br />
session hijacking, denial-of-service, rogue access points, identity<br />
thefts and MAC spoofing. Request your complimentary white paper at:<br />
http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+<br />
CryptoMail provides free end-to-end message encryption.<br />
http://www.cryptomail.org/   Ensure your right to privacy.<br />
Traditional email messages are not secure.  They are sent as<br />
clear-text and thus are readable by anyone with the motivation<br />
to acquire a copy.<br />
!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+!+</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You Don&#8217;t</p>
<p>Learn the hacker&#8217;s secrets that compromise wireless LANs. Secure your<br />
WLAN by understanding these threats, available hacking tools and proven<br />
countermeasures. Defend your WLAN against man-in-the-Middle attacks and<br />
session hijacking, denial-of-service, rogue access points, identity<br />
thefts and MAC spoofing. Request your complimentary white paper at:</p>
<p>http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.captivereefing.com/virusblog/2008/07/31/re-all-of-the-things-you-need-to-learn-to-be-a-pen-tester-re-pen-t-est-basic-needs-7/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>RE: ftp server windows</title>
		<link>http://www.captivereefing.com/virusblog/2006/01/22/re-ftp-server-windows-6/</link>
		<comments>http://www.captivereefing.com/virusblog/2006/01/22/re-ftp-server-windows-6/#comments</comments>
		<pubDate>Sun, 22 Jan 2006 13:00:00 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Threats</category>
		<guid isPermaLink="false">http://www.captivereefing.com/virusblog/2006/01/22/re-ftp-server-windows-6/</guid>
		<description><![CDATA[IIS has a simple and not particularly  secure firewall. It is a hell of
a lot better but it is definitely not up there for security
Vs-ftp is considered good if patches (like everything)
IIS FTP has had numerous vulnerabilities, especially in the past - the
default proxy forwarding was a good one 
CSW
&#8212;&#8211;Original Message&#8212;&#8211;
From: Roger A. Grimes [...]]]></description>
			<content:encoded><![CDATA[<p>IIS has a simple and not particularly  secure firewall. It is a hell of<br />
a lot better but it is definitely not up there for security</p>
<p>Vs-ftp is considered good if patches (like everything)</p>
<p>IIS FTP has had numerous vulnerabilities, especially in the past - the<br />
default proxy forwarding was a good one </p>
<p>CSW</p>
<p>&#8212;&#8211;Original Message&#8212;&#8211;<br />
From: Roger A. Grimes [mailto:roger@banneretcs.com]<br />
Sent: 23 July 2005 2:54<br />
To: Leon; security-basics@securityfocus.com<br />
Subject: RE: ftp server windows</p>
<p>IIS&#8217;s FTP is an excellent, secure FTP server. I don&#8217;t know of any<br />
exploits against it ever other than one obscure client-side<br />
cross-scripting type of attack that was never publicly exploited.</p>
<p>I&#8217;ve been running it for years and never a single problem.</p>
<p>Roger</p>
<p>************************************************************************<br />
***<br />
*Roger A. Grimes, Banneret Computer Security, Computer Security<br />
Consultant *CPA, CISSP, MCSE: Security (NT/2000/2003/MVP), CNE (3/4),<br />
CEH, CHFI<br />
*email: roger@banneretcs.com<br />
*cell: 757-615-3355<br />
*Author of Malicious Mobile Code:  Virus Protection for Windows by<br />
O&#8217;Reilly *http://www.oreilly.com/catalog/malmobcode<br />
*Author of Honeypots for Windows (Apress)<br />
*http://www.apress.com/book/bookDisplay.html?bID=281<br />
************************************************************************<br />
****</p>
<p>&#8212;&#8211;Original Message&#8212;&#8211;<br />
From: Leon [mailto:roastin@yahoo.com]<br />
Sent: Thursday, July 21, 2005 8:19 PM<br />
To: security-basics@securityfocus.com<br />
Subject: ftp server windows</p>
<p>Does anyone know of a good ftp sever for windows with a good security<br />
track record.  WS_FTP is out because of the last vuln where not only did<br />
they not address the issue when it was posted on bugtraq but it took<br />
them close to 3 weeks to come up with a patch.</p>
<p>I have been told about serv-u and bulletproof.  Are there any others<br />
that I should be aware of (with a good history any can google ftp server<br />
windows).</p>
<p>Thanks</p>
<p>____________________________________________________<br />
Start your day with Yahoo! - make it your home page<br />
http://www.yahoo.com/r/hs
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.captivereefing.com/virusblog/2006/01/22/re-ftp-server-windows-6/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>New SecurityFocus article: Sony&#8217;s legal issues</title>
		<link>http://www.captivereefing.com/virusblog/2005/11/14/new-securityfocus-article-sonys-legal-issues/</link>
		<comments>http://www.captivereefing.com/virusblog/2005/11/14/new-securityfocus-article-sonys-legal-issues/#comments</comments>
		<pubDate>Mon, 14 Nov 2005 22:14:10 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Threats</category>
		<guid isPermaLink="false">http://www.captivereefing.com/virusblog/2005/11/14/new-securityfocus-article-sonys-legal-issues/</guid>
		<description><![CDATA[The following column was published on SecurityFocus today:
Sony&#8217;s legal issues
by Mark Rasch
2005-11-14
Sony is in the spotlight over the rootkit they distribute on some of
their music CDs, and it bring up interesting legal issues relating to
EULAs and enforcement by the FTC.
http://www.securityfocus.com/columnists/369

]]></description>
			<content:encoded><![CDATA[<p>The following column was published on SecurityFocus today:</p>
<p>Sony&#8217;s legal issues<br />
by Mark Rasch<br />
2005-11-14</p>
<p>Sony is in the spotlight over the rootkit they distribute on some of<br />
their music CDs, and it bring up interesting legal issues relating to<br />
EULAs and enforcement by the FTC.</p>
<p>http://www.securityfocus.com/columnists/369
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.captivereefing.com/virusblog/2005/11/14/new-securityfocus-article-sonys-legal-issues/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Sophos Anti-Virus IDE alert: W32/Rbot-AXG</title>
		<link>http://www.captivereefing.com/virusblog/2005/11/14/sophos-anti-virus-ide-alert-w32rbot-axg/</link>
		<comments>http://www.captivereefing.com/virusblog/2005/11/14/sophos-anti-virus-ide-alert-w32rbot-axg/#comments</comments>
		<pubDate>Mon, 14 Nov 2005 22:09:57 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Threats</category>
		<guid isPermaLink="false">http://www.captivereefing.com/virusblog/2005/11/14/sophos-anti-virus-ide-alert-w32rbot-axg/</guid>
		<description><![CDATA[Name: W32/Rbot-AXG
Type: Win32 worm
Date: 14 November 2005
Sophos has issued protection for W32/Rbot-AXG.
At the time of writing, Sophos has received a small number of
reports of this worm from the wild.
Customers using EM Library, Enterprise Console, PureMessage or
any of our Sophos small business solutions will be automatically
protected at their next scheduled update.
Information about W32/Rbot-AXG can be found [...]]]></description>
			<content:encoded><![CDATA[<p>Name: W32/Rbot-AXG<br />
Type: Win32 worm<br />
Date: 14 November 2005</p>
<p>Sophos has issued protection for W32/Rbot-AXG.</p>
<p>At the time of writing, Sophos has received a small number of<br />
reports of this worm from the wild.</p>
<p>Customers using EM Library, Enterprise Console, PureMessage or<br />
any of our Sophos small business solutions will be automatically<br />
protected at their next scheduled update.</p>
<p>Information about W32/Rbot-AXG can be found at:<br />
http://www.sophos.com/virusinfo/analyses/w32rbotaxg.html</p>
<p>The W32/Rbot-AXG virus identity file (IDE) includes detection for:</p>
<p>Troj/BWCon-A<br />
http://www.sophos.com/virusinfo/analyses/trojbwcona.html<br />
Troj/Dupa-B<br />
http://www.sophos.com/virusinfo/analyses/trojdupab.html<br />
Dial/Dialprog-C<br />
http://www.sophos.com/virusinfo/analyses/dialdialprogc.html<br />
Dial/Dialprog-B<br />
http://www.sophos.com/virusinfo/analyses/dialdialprogb.html<br />
Troj/BagleDl-AD<br />
http://www.sophos.com/virusinfo/analyses/trojbagledlad.html<br />
Troj/Neclipse-A<br />
http://www.sophos.com/virusinfo/analyses/trojneclipsea.html<br />
Troj/Rezim-A<br />
http://www.sophos.com/virusinfo/analyses/trojrezima.html<br />
Troj/VBbot-E<br />
http://www.sophos.com/virusinfo/analyses/trojvbbote.html<br />
Troj/LdPinch-UE<br />
http://www.sophos.com/virusinfo/analyses/trojldpinchue.html<br />
W32/Sober-U<br />
http://www.sophos.com/virusinfo/analyses/w32soberu.html<br />
W32/Rbot-AXH<br />
http://www.sophos.com/virusinfo/analyses/w32rbotaxh.html</p>
<p>Customers with 3.xx or lower versions of Sophos Anti-Virus, </p>
<p>who are not running EM Library, can manually download the IDE</p>
<p>for W32/Rbot-AXG from:</p>
<p>http://www.sophos.com/downloads/ide/rbot-axg.ide</p>
<p>Read about how to use IDE files at</p>
<p>http://www.sophos.com/support/knowledgebase/article/363.html</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
To unsubscribe, email: notification-unsubscribe@lists.sophos.com<br />
For additional commands, email: notification-faq@lists.sophos.com
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.captivereefing.com/virusblog/2005/11/14/sophos-anti-virus-ide-alert-w32rbot-axg/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Re: banner hiding</title>
		<link>http://www.captivereefing.com/virusblog/2005/11/14/re-banner-hiding-2/</link>
		<comments>http://www.captivereefing.com/virusblog/2005/11/14/re-banner-hiding-2/#comments</comments>
		<pubDate>Mon, 14 Nov 2005 21:36:21 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Threats</category>
		<guid isPermaLink="false">http://www.captivereefing.com/virusblog/2005/11/14/re-banner-hiding-2/</guid>
		<description><![CDATA[Add the following line to the magnus.conf
ServerString &#8220;&#8221;
jskumar67@gmail.com wrote:
>Hi folks,
>Any idea how to configure Sun One web server to hide its banner.
>
>
>
 &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-
 This email message and any attachment(s) is intended only for the
 person(s) or entity(entities) to whom it is addressed. The
 information it contains may be classified as IN CONFIDENCE and may be
 [...]]]></description>
			<content:encoded><![CDATA[<p>Add the following line to the magnus.conf</p>
<p>ServerString &#8220;&#8221;</p>
<p>jskumar67@gmail.com wrote:</p>
<p>>Hi folks,<br />
>Any idea how to configure Sun One web server to hide its banner.<br />
><br />
><br />
></p>
<p> &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
 This email message and any attachment(s) is intended only for the<br />
 person(s) or entity(entities) to whom it is addressed. The<br />
 information it contains may be classified as IN CONFIDENCE and may be<br />
 legally privileged. If you are not the intended recipient any use,<br />
 disclosure or copying of the message or attachment(s) is strictly<br />
 prohibited. If you have received this message in error please<br />
 notify us immediately and destroy it and any attachment(s).<br />
 Thank you. The Ministry of Social Development accepts no<br />
 responsibility for changes made to this message or to any<br />
 attachment(s) after transmission from the Ministry.<br />
 &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.captivereefing.com/virusblog/2005/11/14/re-banner-hiding-2/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>[security bulletin] HPSBUX02075 SSRT051074 - HP-UX Running xterm Local Unauthorized Access</title>
		<link>http://www.captivereefing.com/virusblog/2005/11/14/security-bulletin-hpsbux02075-ssrt051074-hp-ux-running-xterm-local-unauthorized-access/</link>
		<comments>http://www.captivereefing.com/virusblog/2005/11/14/security-bulletin-hpsbux02075-ssrt051074-hp-ux-running-xterm-local-unauthorized-access/#comments</comments>
		<pubDate>Mon, 14 Nov 2005 19:49:26 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Threats</category>
		<guid isPermaLink="false">http://www.captivereefing.com/virusblog/2005/11/14/security-bulletin-hpsbux02075-ssrt051074-hp-ux-running-xterm-local-unauthorized-access/</guid>
		<description><![CDATA[&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;
Hash: SHA1
SUPPORT COMMUNICATION - SECURITY BULLETIN
Document ID: c00555516
Version: 1
HPSBUX02075 SSRT051074 - HP-UX Running xterm Local Unauthorized
                         Access
NOTICE: The information in this Security Bulletin should be acted
upon as soon [...]]]></description>
			<content:encoded><![CDATA[<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br />
Hash: SHA1</p>
<p>SUPPORT COMMUNICATION - SECURITY BULLETIN</p>
<p>Document ID: c00555516<br />
Version: 1</p>
<p>HPSBUX02075 SSRT051074 - HP-UX Running xterm Local Unauthorized<br />
                         Access</p>
<p>NOTICE: The information in this Security Bulletin should be acted<br />
upon as soon as possible.</p>
<p>Release Date: 2005-11-11<br />
Last Updated: 2005-11-13</p>
<p>Potential Security Impact: Local unauthorized access</p>
<p>Source: Hewlett-Packard Company,<br />
        HP Software Security Response Team</p>
<p>VULNERABILITY SUMMARY<br />
A potential security vulnerability has been identified with HP-UX<br />
running xterm.  The vulnerability could be exploited by a local<br />
user to gain unauthorized access.</p>
<p>References: none</p>
<p>SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.<br />
HP-UX B.11.00, B.11.11, B.11.23.</p>
<p>BACKGROUND</p>
<p>To determine if an HP-UX system has an affected version,<br />
search the output of &#8220;swlist -a revision -l fileset&#8221;<br />
for one of the filesets listed below. For affected systems<br />
verify that the recommended action has been taken.</p>
<p>AFFECTED VERSIONS</p>
<p>HP-UX B.11.00<br />
=============<br />
X11.X11-RUN-CL<br />
action: remove PHSS_32109 if installed</p>
<p>HP-UX B.11.11<br />
=============<br />
X11.X11-RUN-CL<br />
action: remove PHSS_30791 if installed</p>
<p>HP-UX B.11.11<br />
=============<br />
X11.X11-RUN-CL<br />
action: remove PHSS_33589 if installed</p>
<p>HP-UX B.11.23<br />
=============<br />
X11.X11-RUN-CL<br />
action: remove PHSS_31833 if installed</p>
<p>HP-UX B.11.23<br />
=============<br />
X11.X11-RUN-CL<br />
action: remove PHSS_32366 if installed</p>
<p>END AFFECTED VERSIONS</p>
<p>RESOLUTION</p>
<p>Until patches are provided to resolve the issue avoid using the<br />
potentially vulnerable versions of /usr/bin/X11/xterm.</p>
<p>One solution is to remove the patches listed in the Background<br />
section (above).  The patches listed are the only patches<br />
containing the potentially vulnerable xterm.</p>
<p>An alternative to removing the patches is to use<br />
/usr/contrib/bin/X11R5/xterm.</p>
<p>For example:</p>
<p>cp /usr/bin/X11/xterm /usr/bin/X11/xterm.nosuid<br />
chmod 555 /usr/bin/X11/xterm.nosuid<br />
cp /usr/contrib/bin/X11R5/xterm /usr/bin/X11/xterm</p>
<p>MANUAL ACTIONS: Yes - NonUpdate<br />
Remove the patches listed in the Background section<br />
or use /usr/contrib/bin/X11R5/xterm.</p>
<p>PRODUCT SPECIFIC INFORMATION</p>
<p>HP-UX Security Patch Check: Security Patch Check revision B.02.00<br />
analyzes all HP-issued Security Bulletins to provide a subset of<br />
recommended actions that potentially affect a specific HP-UX<br />
system. For more information:<br />
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi<br />
displayProductInfo.pl?productnumber=B6834AAtN</p>
<p>UPDATE HISTORY<br />
Initial release: 13 November 2005</p>
<p>Support: For further information, contact normal HP Services<br />
support channel.</p>
<p>Report: To report a potential security vulnerability with any HP<br />
supported product, send Email to: security-alert@hp.com.  It is<br />
strongly recommended that security related information being<br />
communicated to HP be encrypted using PGP, especially exploit<br />
information.  To get the security-alert PGP key, please send an<br />
e-mail message as follows:<br />
  To: security-alert@hp.com<br />
  Subject: get key</p>
<p>Subscribe: To initiate a subscription to receive future HP<br />
Security Bulletins via Email:<br />
http://h30046.www3.hp.com/driverAlertProfile.php?regioncode=NA&#038;<br />
langcode=USENG&#038;jumpid=in_SC-GEN__driverITRC&#038;topiccode=ITRC</p>
<p>On the web page: ITRC security bulletins and patch sign-up<br />
Under Step1: your ITRC security bulletins and patches<br />
  - check ALL categories for which alerts are required and<br />
    continue.<br />
Under Step2: your ITRC operating systems<br />
  - verify your operating system selections are checked and<br />
    save.</p>
<p>To update an existing subscription:<br />
http://h30046.www3.hp.com/subSignIn.php<br />
Log in on the web page:<br />
  Subscriber&#8217;s choice for Business: sign-in.<br />
On the web page:<br />
  Subscriber&#8217;s Choice: your profile summary<br />
    - use Edit Profile to update appropriate sections.</p>
<p>To review previously published Security Bulletins visit:<br />
http://www.itrc.hp.com/service/cki/secBullArchive.do</p>
<p>* The Software Product Category that this Security Bulletin<br />
relates to is represented by the 5th and 6th characters of the<br />
Bulletin number in the title:</p>
<p>    GN = HP General SW,<br />
    MA = HP Management Agents,<br />
    MI = Misc. 3rd party SW,<br />
    MP = HP MPE/iX,<br />
    NS = HP NonStop Servers,<br />
    OV = HP OpenVMS,<br />
    PI = HP Printing &#038; Imaging,<br />
    ST = HP Storage SW,<br />
    TL = HP Trusted Linux,<br />
    TU = HP Tru64 UNIX,<br />
    UX = HP-UX,<br />
    VV = HP Virtual Vault</p>
<p>System management and security procedures must be reviewed<br />
frequently to maintain system integrity. HP is continually<br />
reviewing and enhancing the security features of software products<br />
to provide customers with current secure solutions.</p>
<p>&#8220;HP is broadly distributing this Security Bulletin in order to<br />
bring to the attention of users of the affected HP products the<br />
important security information contained in this Bulletin. HP<br />
recommends that all users determine the applicability of this<br />
information to their individual situations and take appropriate<br />
action. HP does not warrant that this information is necessarily<br />
accurate or complete for all user situations and, consequently, HP<br />
will not be responsible for any damages resulting from user&#8217;s use<br />
or disregard of the information provided in this Bulletin. To the<br />
extent permitted by law, HP disclaims all warranties, either<br />
express or implied, including the warranties of merchantability<br />
and fitness for a particular purpose, title and non-infringement.&#8221;</p>
<p>(c)Copyright 2005 Hewlett-Packard Development Company, L.P.<br />
Hewlett-Packard Company shall not be liable for technical or<br />
editorial errors or omissions contained herein. The information<br />
provided is provided &#8220;as is&#8221; without warranty of any kind. To the<br />
extent permitted by law, neither HP nor its affiliates,<br />
subcontractors or suppliers will be liable for incidental, special<br />
or consequential damages including downtime cost; lost profits;<br />
damages relating to the procurement of substitute products or<br />
services; or damages for loss of data, or software restoration.<br />
The information in this document is subject to change without<br />
notice. Hewlett-Packard Company and the names of Hewlett-Packard<br />
products referenced herein are trademarks of Hewlett-Packard<br />
Company in the United States and other countries. Other product<br />
and company names mentioned herein may be trademarks of their<br />
respective owners.</p>
<p>&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br />
Version: PGP 8.1</p>
<p>iQA/AwUBQ3h8SOAfOvwtKn1ZEQL6wACffte15IwZ6jsPyDyXqSgZjHJewfwAn2FE<br />
KwTYRaYJm6FFCnsglWA5N06N<br />
=N5A/<br />
&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.captivereefing.com/virusblog/2005/11/14/security-bulletin-hpsbux02075-ssrt051074-hp-ux-running-xterm-local-unauthorized-access/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>RE: Odd identd behavior</title>
		<link>http://www.captivereefing.com/virusblog/2005/11/14/re-odd-identd-behavior-5/</link>
		<comments>http://www.captivereefing.com/virusblog/2005/11/14/re-odd-identd-behavior-5/#comments</comments>
		<pubDate>Mon, 14 Nov 2005 19:46:17 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Threats</category>
		<guid isPermaLink="false">http://www.captivereefing.com/virusblog/2005/11/14/re-odd-identd-behavior-5/</guid>
		<description><![CDATA[?lit?-Cr?w Rulez

]]></description>
			<content:encoded><![CDATA[<p>?lit?-Cr?w Rulez
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.captivereefing.com/virusblog/2005/11/14/re-odd-identd-behavior-5/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Beta product testing</title>
		<link>http://www.captivereefing.com/virusblog/2005/11/14/beta-product-testing/</link>
		<comments>http://www.captivereefing.com/virusblog/2005/11/14/beta-product-testing/#comments</comments>
		<pubDate>Mon, 14 Nov 2005 19:36:05 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Threats</category>
		<guid isPermaLink="false">http://www.captivereefing.com/virusblog/2005/11/14/beta-product-testing/</guid>
		<description><![CDATA[Hello,
I&#8217;m looking to get blunt feedback from security analysts on beta product
releases, but before I describe the product or make a call for beta
testers I have a few general questions:
*	Who are the leading contracted security testing companies, and
what&#8217;s the advantage of using them?
*	Who are the leading non-contracted security testing companies?
*	Are there lists dedicated to testing [...]]]></description>
			<content:encoded><![CDATA[<p>Hello,</p>
<p>I&#8217;m looking to get blunt feedback from security analysts on beta product<br />
releases, but before I describe the product or make a call for beta<br />
testers I have a few general questions:</p>
<p>*	Who are the leading contracted security testing companies, and<br />
what&#8217;s the advantage of using them?<br />
*	Who are the leading non-contracted security testing companies?<br />
*	Are there lists dedicated to testing security products?<br />
*	On which lists is it permissible to post calls for beta testers?</p>
<p>Thanks in advance,</p>
<p>Bill Stout</p>
<p>www.greenborder.com
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.captivereefing.com/virusblog/2005/11/14/beta-product-testing/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>MD4 and MD5 collision generators</title>
		<link>http://www.captivereefing.com/virusblog/2005/11/14/md4-and-md5-collision-generators/</link>
		<comments>http://www.captivereefing.com/virusblog/2005/11/14/md4-and-md5-collision-generators/#comments</comments>
		<pubDate>Mon, 14 Nov 2005 19:11:35 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Threats</category>
		<guid isPermaLink="false">http://www.captivereefing.com/virusblog/2005/11/14/md4-and-md5-collision-generators/</guid>
		<description><![CDATA[I am releasing my collision generators for MD4 and MD5.  They have
significant time improvements over the ones described in the papers by
Wang, et al.
MD4 collisions can be generated almost instantly, MD5 can be generated in
approximately 45 minutes on my p4 1.6ghz (on average).
http://www.stachliu.com/collisions.html
Enjoy
-Patrick Stach
PS. Please do not reply to this address.

]]></description>
			<content:encoded><![CDATA[<p>I am releasing my collision generators for MD4 and MD5.  They have<br />
significant time improvements over the ones described in the papers by<br />
Wang, et al.</p>
<p>MD4 collisions can be generated almost instantly, MD5 can be generated in<br />
approximately 45 minutes on my p4 1.6ghz (on average).</p>
<p>http://www.stachliu.com/collisions.html</p>
<p>Enjoy<br />
-Patrick Stach</p>
<p>PS. Please do not reply to this address.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.captivereefing.com/virusblog/2005/11/14/md4-and-md5-collision-generators/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Re: Odd identd behavior</title>
		<link>http://www.captivereefing.com/virusblog/2005/11/14/re-odd-identd-behavior-4/</link>
		<comments>http://www.captivereefing.com/virusblog/2005/11/14/re-odd-identd-behavior-4/#comments</comments>
		<pubDate>Mon, 14 Nov 2005 18:40:00 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Threats</category>
		<guid isPermaLink="false">http://www.captivereefing.com/virusblog/2005/11/14/re-odd-identd-behavior-4/</guid>
		<description><![CDATA[On 11/14/05, Christopher E. Cramer  wrote:
>
> Mike,
>
> This looks like the output from an FTP server.  If I had to guess, I would
> say that this looks like someone compromised a machine and installed a
> warez ftp server on the identd port.
>
> -c
>
> &#8211;
> Christopher E. Cramer, Ph.D.
> University Information Technology Security Officer
> [...]]]></description>
			<content:encoded><![CDATA[<p>On 11/14/05, Christopher E. Cramer <chris.cramer@duke.edu> wrote:<br />
><br />
> Mike,<br />
><br />
> This looks like the output from an FTP server.  If I had to guess, I would<br />
> say that this looks like someone compromised a machine and installed a<br />
> warez ftp server on the identd port.<br />
><br />
> -c<br />
><br />
> &#8211;<br />
> Christopher E. Cramer, Ph.D.<br />
> University Information Technology Security Officer<br />
> Duke University,  Office of Information Technology<br />
> 334 Blackwell St., Suite 2106, Durham, NC 27701<br />
> PH: 919-660-7003  FAX: 919-668-2953  CELL: 919-210-0528<br />
></p>
<p>You&#8217;re right, it does look like that. I didn&#8217;t even think that it<br />
might be a standard service running on a different port.</p>
<p>I don&#8217;t own these machines, so I don&#8217;t really want to connect to these<br />
servers to find out if it really is ftp. It does seem likely that they<br />
are warez servers.</p>
<p>Thanks,<br />
Mike
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.captivereefing.com/virusblog/2005/11/14/re-odd-identd-behavior-4/feed/</wfw:commentRSS>
		</item>
	</channel>
</rss>
