California State University, Dominguez Hills
CSUDH Home Search Index
 IT-> Telecommunications-> Network Services
 Username  Password
Main Menu
· Home
· Downloads
· FAQ
· News
· Search
· Sections
· Topics

Security Focus
Vuln: MySQL MyISAM Table Privileges Secuity Bypass Vulnerability

Vuln: Oracle July 2008 Critical Patch Update Multiple Vulnerabilities

Vuln: Apache Tomcat Mod_JK.SO Arbitrary Code Execution Vulnerability

Vuln: Aprox CMS Engine 'index.php' SQL Injection Vulnerability

Bugtraq: Oracle Database Local Untrusted Library Path Vulnerability

spacer.gif
spacer.gif   CSUDH Wireless Network
Posted by: elazy on Monday, August 21, 2006 - 09:51 AM
  spacer.gif
  NSSRT Releases
2244 Reads

Connecting to the CSUDH Wireless Network is changing. A new network authentication and validation security system is in place to simplify login and to prevent infected wireless computer systems such as laptops or desktops from gaining access to the network and infecting other systems. This will ensure a safe, secure and reliable network for you.

Click here to find out more


Send this story to someone Printer-friendly page
 
spacer.gif
spacer.gif spacer.gif spacer.gif spacer.gif

spacer.gif
spacer.gif   CSUDH VPN Updated
Posted by: elazy on Monday, January 31, 2005 - 02:08 PM
  spacer.gif
  NSSRT Releases
4258 Reads

CSUDH Virtual Private Network Service Software and Instructions have been updated. It now includes Software and Instructions for MAC, Windows, LInux and Solaris clients. CSUDH VPN Service is designed to allow University Faculty and Staff to securely "tunnel" into campus over commodity networks, such as the Internet and access services as if they were on campus. The only two things you need to begin are the Cisco VPN software, which is available on this site, and a valid CSUDH email account. Please use the links below or on right to setup a VPN Connection to CSUDH
:
CSUDH VPN Setup


Send this story to someone Printer-friendly page
 
spacer.gif
spacer.gif spacer.gif spacer.gif spacer.gif

spacer.gif
spacer.gif   OpenSSL Critical DoS Alert
Posted by: elazy on Wednesday, March 17, 2004 - 07:45 PM
  spacer.gif
  NSSRT Security Alerts
4127 Reads

There are multiple vulnerabilities in different implementations of the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols. When processing an SSL/TLS ChangeCipherSpec message, OpenSSL may fail to check that a new cipher has been previously negotiated. This may result in a null pointer dereference. A remote attacker could perform a specially crafted SSL/TLS handshake with an application that utilizes OpenSSL (such as OpenSSH), triggering the null pointer dereference and causing the application to crash, which will result in at least a denial-of-service attack. Effectively all of this is done via simple scripts.
Affected Products:
OpenSSL prior to version 0.9.7d
Any Version of OpenSSH compiled against OpenSSL < 0.9.7d

Solution(Solaris8/9):

CSUDH Network Services Security Response Team has compiled a static package for Solaris 5.8 and Solaris 5.9 which includes OpenSSH v3.8.p1 built with OpenSSL v0.9.7d. It will install the software with UsePrivilegeSeparation enabled by default. The user and directory creation is fully automated within the package

Download it here:

ERLssh-Solaris-sparc-OpenSSH_3.8p1.pkg.gz


Solaris 8: Verify that you have the following patch:
Patch ID 112438 for SPARC
Patch ID 112439 for Intel

To Install, su to root, gunzip the package
Execute pkgadd -d /path/tothe/package


Read more... (257 bytes more) Send this story to someone Printer-friendly page
 
spacer.gif
spacer.gif spacer.gif spacer.gif spacer.gif

spacer.gif
spacer.gif   New Virus Alert - High Risk
Posted by: elazy on Tuesday, January 27, 2004 - 09:46 AM
  spacer.gif
  NSSRT Security Alerts
4025 Reads

This is a mass-mailing worm that arrives as an attachment with the file extension .bat, .cmd, .exe, .pif, .scr, or .zip. The worm sets up a backdoor into the system by opening TCP ports in the range of 3127 - 3198. This can potentially allow an attacker to connect to the computer and use it to gain access to its network resources. CSUDH Network Services recommends using the newly updated Stinger from McAfee to combat the issue.
1. Click here to Download Stinger

2. When prompted, choose to save the file to a convenient location on your hard disk (such as your Desktop folder).
3. When the download is complete, navigate to the folder that contains the downloaded Stinger.exe file, and run it.
3.1 Windows XP/ME Users Read This First!
4. Click the Scan Now button to begin scanning
5. Stinger will repair all infected files found.


Send this story to someone Printer-friendly page
 
spacer.gif
spacer.gif spacer.gif spacer.gif spacer.gif

spacer.gif
spacer.gif   Exchange 2003 User Migration
Posted by: elazy on Wednesday, November 19, 2003 - 05:07 PM
  spacer.gif
  x
4901 Reads


Microsoft™

Exchange 2003 Overview
  1. Client enhancements were one of the main product goals for Exchange 2003. Microsoft has done a lot of work to make OWA more like desktop Outlook than ever before.
  2. OWA 2003 includes a lot of small improvements, such as recalling the user's preferred size for item windows, the ability to mark a message in the Inbox as read or unread, a default signature, a command for adding a recipient to the user's Contacts folder, and a simple rules editor for creating server-based rules from existing messages. Keyboard shortcuts such as Ctrl+R for reply and Ctrl+Shift+F for forward help make OWA more like desktop Outlook.
  3. Spell check is another feature that OWA users have wanted for years. Up until now, it has been available only through third-party tools.
  4. Another long-desired feature is the ability to resolve names against the Global Address List (GAL). The LDAP lookups are very fast for users and groups.
  5. Security issues are important in Exchange 2003, and OWA has its share of improvements. OWA 2003 adds support for sending and receiving encrypted and digitally signed messages with Secure MIME (S/MIME). As in Outlook 11, the reading pane automatically blocks images, sounds, and other external content in email messages. This feature not only conserves bandwidth but also thwarts spammers who use so-called Web beacons—invisible images—to confirm valid email addresses. If the message contains a picture that you do need to see, you can click the "Click here to unblock content" link in the reading pane.
Click Here To Read The whole Story


Send this story to someone Printer-friendly page
 
spacer.gif
spacer.gif spacer.gif spacer.gif spacer.gif

spacer.gif
spacer.gif   Critical Vulnerability in Exchange Server
Posted by: elazy on Thursday, October 16, 2003 - 10:14 AM
  spacer.gif
  NSSRT Security Alerts
3872 Reads

Vulnerability in Exchange Server Could Allow Arbitrary Code Execution
Issued: October 15, 2003
Summary:

Impact of Vulnerability: Remote Code Execution
Maximum Severity Rating: Critical

Recommendation: System administrators should apply the security patch to Exchange servers immediately. Multiple patches released, please see Microsoft's website

Affected Software:
Microsoft Exchange Server 5.5, Service Pack 4 - Download Patch
Microsoft Exchange 2000 Server, Service Pack 3 - Download Patch

Non Affected Software:
Microsoft Exchange Server 2003


Send this story to someone Printer-friendly page
 
spacer.gif
spacer.gif spacer.gif spacer.gif spacer.gif

spacer.gif
spacer.gif   Another Windows RPC DCOM vulnerability
Posted by: elazy on Saturday, October 11, 2003 - 01:16 PM
  spacer.gif
  NSSRT Security Alerts
4671 Reads

Bad news on Windows RPC DCOM vulnerability:
It was reported and confirmed that Windows XP SP1 with all security fixes installed, including MS Patch MS03-039 is still vulnerable to variant of the same RPC DCOM issue. Windows 2000/2003 has not been tested yet.
Currently, this is only a denial of service exploit, however code execution is most probably on it's way.
Microsoft has been notified, awaiting confirmation.

Interim Solution from NSSRT:

Turn Off DCOM in 4 easy steps:
 • Click HERE to download a registry fix to turn off DCOM
 • Click Open in the download dialog box.
 • When asked to import or merge the registry, click Yes
 • Restart computer


Read more... (885 bytes more) Send this story to someone Printer-friendly page
 
spacer.gif
spacer.gif spacer.gif spacer.gif spacer.gif

spacer.gif
spacer.gif   Multiple Vulnerabilities in SSL and OpenSSH
Posted by: elazy on Friday, October 03, 2003 - 02:38 PM
  spacer.gif
  NSSRT Security Alerts
3852 Reads

There are multiple vulnerabilities in different implementations of the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols. Additionally, there is a remotely exploitable vulnerability in a general buffer management function in versions of OpenSSH prior to 3.7.1p2. This may allow a remote attacker to corrupt heap memory which could cause a denial-of-service condition. It may also be possible for an attacker to execute arbitrary code.

Affected Products:
OpenSSH prior to version 3.7.1p2
OpenSSL prior to version 0.9.7c

Solution:

CSUDH Network Services Security Response Team has compiled a static package for Solaris 5.8 and Solaris 5.9 which includes OpenSSH v3.7.1p2 built with OpenSSL v0.9.7c. It will install the software with UsePrivilegeSeparation enabled by default. The user and directory creation is fully automated within the package

Download it here:

ERLssh-3.7.1p2-ssl-0.9.7c-sparc8-csudh.gz


Solaris 8: Verify that you have the following patch:
Patch ID 112438 for SPARC
Patch ID 112439 for Intel

To Install, su to root, gunzip the package
Execute pkgadd -d /path/tothe/package


Send this story to someone Printer-friendly page
 
spacer.gif
spacer.gif spacer.gif spacer.gif spacer.gif

spacer.gif
spacer.gif   TFTPd Virus Carrier Auto Detection and Removal Operation Results
Posted by: elazy on Thursday, September 25, 2003 - 11:03 AM
  spacer.gif
  NSSRT Releases
3796 Reads

Total Hit Count 919
Total Infected TFTPd Host Carriers 520
Total Disinfected Hosts 470
Operation Success Rate:  90.3%
    

Send this story to someone Printer-friendly page
 
spacer.gif
spacer.gif spacer.gif spacer.gif spacer.gif

spacer.gif
spacer.gif   Buffer Overrun In RPCSS MS03-039
Posted by: elazy on Thursday, September 18, 2003 - 03:18 PM
  spacer.gif
  NSSRT Security Alerts
4158 Reads

A security issue has been identified that could allow an attacker to remotely compromise a computer running Microsoft® Windows® and gain complete control over it. To help protect your computer, as well as the University Community, CSUDH Network Services Security Response Team (NSSRT) has released an Online Detection and removal Tool targeted for this particular critical vulnerability. It detects all currenly known Microsoft DCOM related issues. Click HERE to check your computer.

Read more... (784 bytes more) Send this story to someone Printer-friendly page
 
spacer.gif
spacer.gif spacer.gif spacer.gif spacer.gif

spacer.gif spacer.gif spacer.gif spacer.gif spacer.gif
BlockRTop.gif spacer.gif spacer.gif
  Tutorials and Howtos

· Wireless access to CSUDH
· CSUDH VPN Setup
· AntiSpam AntiVirus Setup
· Linux Security
· FreeBSD Security
· Solaris Security
· Samba Howto
· UNIX Security Audit
· Exchange/PIX Tutorial


  spacer.gif
BlockRBott.gif spacer.gif spacer

spacer.gif spacer.gif spacer.gif spacer.gif spacer.gif
BlockRTop.gif spacer.gif spacer.gif
  Other Stories

· CSUDH Wireless Network (Aug 21, 2006)
· CSUDH VPN Updated (Jan 31, 2005)
· OpenSSL Critical DoS Alert (Mar 17, 2004)
· New Virus Alert - High Risk (Jan 27, 2004)
· Exchange 2003 User Migration (Nov 19, 2003)
· Critical Vulnerability in Exchange Server (Oct 16, 2003)
· Another Windows RPC DCOM vulnerability (Oct 11, 2003)
· Multiple Vulnerabilities in SSL and OpenSSH (Oct 03, 2003)
· TFTPd Virus Carrier Auto Detection and Removal Operation Results (Sep 25, 2003)
· Buffer Overrun In RPCSS MS03-039 (Sep 18, 2003)

  spacer.gif
BlockRBott.gif spacer.gif spacer

Footerdot.gif
NSSRT :: Network Services Security Response Team   

     California State University, Dominguez Hills :: Information Technology Department
Telecommunications :: Network Services
1000 E. Victoria Street :: Carson, California 90747 :: (310) 243-3696