OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
ISS Security Alert Summary AS03-37

From: X-Force (xforceiss.net)
Date: Mon Sep 15 2003 - 14:49:09 CDT


-----BEGIN PGP SIGNED MESSAGE-----

Internet Security Systems Security Alert Summary AS03-37
September 15, 2003

Latest Gigabit and 100Mbps IDS Test Results Available. The NSS Group,
one of the world’s foremost independent security testing facilities,
has released its study of the latest Gigabit and 100Mbps intrusion
detection solutions. Read how ISS’ RealSecure and Proventia solutions
came out on top.
http://www.iss.net/mktg/NSSGroupResults/

X-Force Vulnerability and Threat Database: http://xforce.iss.net/

To receive these Alert Summaries, as well as other Alerts and Advisories, subscribe to the Internet Security Systems Alert mailing list at:
https://atla-mm1.iss.net/mailman/listinfo/alert

This summary is available at the following address: http://xforce.iss.net/xforce/alerts/id/AS03-37
_____
Contents:
* 51 Reported Vulnerabilities
* Risk Factor Key
_____

Date Reported: 09/07/2003
Brief Description: Mah-Jong buffer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: Debian Linux 3.0, Mah-Jong Any version
Vulnerability: mah-jong-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/13117

Date Reported: 09/07/2003
Brief Description: Mah-Jong denial of service
Risk Factor: Low
Attack Type: Network Based
Platforms: Debian Linux 3.0, Mah-Jong Any version
Vulnerability: mah-jong-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/13118

Date Reported: 09/05/2003
Brief Description: WS_FTP Server long FTP command buffer overflow
Risk Factor: Medium
Attack Type: Host Based / Network Based
Platforms: Windows Any version, WS_FTP Server 3.x, WS_FTP
                    Server 4.x
Vulnerability: wsftp-ftp-command-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/13119

Date Reported: 09/08/2003
Brief Description: ICQ Web Front message field cross-site scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: ICQ Web Front Any version, Windows Any version
Vulnerability: icq-webfront-message-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/13120

Date Reported: 09/07/2003
Brief Description: Internet Services Daemon denial of service if large
                    number of requests received in one minute
Risk Factor: Low
Attack Type: Network Based
Platforms: InetD Any version, Linux Any version, Slackware
                    Linux 8.1, Slackware Linux 9.0, Slackware Linux
                    current, Unix Any version, Windows Any version
Vulnerability: inetd-requests-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/13121

Date Reported: 09/08/2003
Brief Description: FTP Desktop long server response heap overflow
Risk Factor: High
Attack Type: Network Based
Platforms: FTP Desktop 3.5, Unix Any version, Windows Any
                    version
Vulnerability: ftp-desktop-heap-overflow
X-Force URL: http://xforce.iss.net/xforce/xfdb/13122

Date Reported: 09/05/2003
Brief Description: Digital Scribe login.php or register.php cross-site
                    scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: Digital Scribe 1.3, Linux Any version, Unix Any
                    version, Windows Any version
Vulnerability: digitalscribe-login-register-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/13123

Date Reported: 09/08/2003
Brief Description: cmdftp store_line function heap overflow
Risk Factor: High
Attack Type: Network Based
Platforms: cmdftp prior to 0.641, Linux Any version
Vulnerability: cmdftp-storeline-heap-overflow
X-Force URL: http://xforce.iss.net/xforce/xfdb/13124

Date Reported: 09/07/2003
Brief Description: Apache::Gallery Inline::C could allow arbitrary
                    code execution
Risk Factor: High
Attack Type: Host Based
Platforms: Apache::Gallery Any version, Linux Any version,
                    Unix Any version, Windows Any version
Vulnerability: apachegallery-inlinec-execute-code
X-Force URL: http://xforce.iss.net/xforce/xfdb/13125

Date Reported: 09/08/2003
Brief Description: Microsoft ASP.NET could allow an attacker to bypass
                    Request Validation feature
Risk Factor: Medium
Attack Type: Network Based
Platforms: Microsoft ASP.NET Framework 1.1, Windows 2000 Any
                    version, Windows NT Any version
Vulnerability: ms-request-validation-bypass
X-Force URL: http://xforce.iss.net/xforce/xfdb/13126

Date Reported: 09/08/2003
Brief Description: Roger Wilco servers buffer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: BSD Any version, Linux Any version, Roger Wilco
                    Dedicated Server for Linux 0.27 and earlier, Roger
                    Wilco Dedicated Server for Win32 0.30a and earlier,
                    Roger Wilco Graphical Server 1.4.1.6 & earlier,
                    Windows Any version, Windows 2003 Server
Vulnerability: roger-wilco-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/13130

Date Reported: 09/08/2003
Brief Description: phpBB URL BBCode tags allow cross-site scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: Linux Any version, phpBB 2.0.6, Unix Any version,
                    Windows Any version
Vulnerability: phpbb-bbcode-tags-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/13132

Date Reported: 09/09/2003
Brief Description: Open Source Security Information Management
                    multiple scripts allow SQL injection
Risk Factor: Medium
Attack Type: Network Based
Platforms: Linux Any version, OSSIM prior to 0.3.1
Vulnerability: ossim-multiple-sql-injection
X-Force URL: http://xforce.iss.net/xforce/xfdb/13133

Date Reported: 09/09/2003
Brief Description: KokeshCMS edit.php script allows content to be
                    modified without authentication
Risk Factor: Medium
Attack Type: Network Based
Platforms: KokeshCMS prior to 0.2, Linux Any version, Unix Any
                    version
Vulnerability: kokesh-edit-content-modification
X-Force URL: http://xforce.iss.net/xforce/xfdb/13135

Date Reported: 09/09/2003
Brief Description: b2evolution cross-site scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: b2evolution prior to 0.8.2.2, Linux Any version,
                    Unix Any version, Windows Any version
Vulnerability: b2evolution-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/13136

Date Reported: 09/09/2003
Brief Description: GtkHTML denial of service
Risk Factor: Medium
Attack Type: Network Based
Platforms: Conectiva Linux 7.0, Conectiva Linux 8.0, Conectiva
                    Linux 9.0, GtkHTML prior to 1.1.10, Red Hat Linux
                    7.3, Red Hat Linux 8.0, Red Hat Linux 9
Vulnerability: gtkhtml-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/13137

Date Reported: 09/09/2003
Brief Description: b2evolution SQL injection
Risk Factor: Medium
Attack Type: Network Based
Platforms: b2evolution prior to 0.8.2.2, Linux Any version,
                    Unix Any version, Windows Any version
Vulnerability: b2evolution-sql-injection
X-Force URL: http://xforce.iss.net/xforce/xfdb/13138

Date Reported: 09/09/2003
Brief Description: Net-SNMP could allow a local attacker to bypass
                    security and access restricted MIB objects
Risk Factor: Medium
Attack Type: Host Based
Platforms: Linux Any version, Net-SNMP prior to 5.0.9
Vulnerability: netsnmp-mibobject-bypass-security
X-Force URL: http://xforce.iss.net/xforce/xfdb/13139

Date Reported: 09/08/2003
Brief Description: Roger Wilco long nickname buffer overflow
Risk Factor: Low
Attack Type: Network Based
Platforms: Roger Wilco Graphical server 1.4.1.2, Windows Any
                    version
Vulnerability: roger-wilco-nickname-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/13141

Date Reported: 09/08/2003
Brief Description: Roger Wilco Graphical server NETWORK.DLL denial of
                    service
Risk Factor: Low
Attack Type: Network Based
Platforms: Roger Wilco Graphical server 1.4.1.6, Windows Any
                    version
Vulnerability: roger-wilco-network-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/13142

Date Reported: 09/10/2003
Brief Description: RealOne Player .realnetworks configuration files
                    could allow access to configuration information
Risk Factor: Medium
Attack Type: Host Based
Platforms: Linux Any version, RealOne Player 9.0, Unix Any
                    version
Vulnerability: realoneplayer-config-file-access
X-Force URL: http://xforce.iss.net/xforce/xfdb/13143

Date Reported: 09/10/2003
Brief Description: WebX and WebX Lite "dot dot" directory traversal
Risk Factor: Medium
Attack Type: Network Based
Platforms: WebX Lite 1.1, WebX Server 1.1, Windows Any version
Vulnerability: webx-dotdot-directory-traversal
X-Force URL: http://xforce.iss.net/xforce/xfdb/13144

Date Reported: 09/09/2003
Brief Description: Escapade Scripting Engine multiple variables path
                    disclosure
Risk Factor: Medium
Attack Type: Network Based
Platforms: Escapade (ESP) Scripting Engine Any version,
                    Escapade (ESP) Scripting Engine Any version,
                    Escapade (ESP) Scripting Engine Any version, Linux
                    Any version, Unix Any version, Windows Any version
Vulnerability: escapade-multiple-path-disclosure
X-Force URL: http://xforce.iss.net/xforce/xfdb/13145

Date Reported: 09/10/2003
Brief Description: OpenBSD integer overflow
Risk Factor: High
Attack Type: Host Based
Platforms: OpenBSD 3.3 and earlier
Vulnerability: openbsd-integer-overflow
X-Force URL: http://xforce.iss.net/xforce/xfdb/13146

Date Reported: 09/09/2003
Brief Description: Escapade Scripting Engine page variable cross-site
                    scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: Escapade (ESP) Scripting Engine Any version,
                    Escapade (ESP) Scripting Engine Any version,
                    Escapade (ESP) Scripting Engine Any version, Linux
                    Any version, Unix Any version, Windows Any version
Vulnerability: escapade-page-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/13147

Date Reported: 09/10/2003
Brief Description: Gordano Messaging Suite sending "dot dot" to port
                    80 causes denial of service
Risk Factor: Low
Attack Type: Network Based
Platforms: Gordano Messaging Suite 9 build 3138, Linux Any
                    version, Unix Any version, Windows Any version
Vulnerability: gordano-dotdot-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/13148

Date Reported: 09/10/2003
Brief Description: Gordano Messaging Suite could allow access to the
                    Alertlist.mml file
Risk Factor: Medium
Attack Type: Network Based
Platforms: Gordano Messaging Suite 9 build 3138, Linux Any
                    version, Unix Any version, Windows Any version
Vulnerability: gordano-alertlist-file-access
X-Force URL: http://xforce.iss.net/xforce/xfdb/13149

Date Reported: 09/10/2003
Brief Description: Pine display_parameters buffer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: Conectiva Linux 7.0, Conectiva Linux 8.0, Conectiva
                    Linux 9.0, EnGarde Secure Linux 1.0.1, EnGarde
                    Secure Linux Community Edition, EnGarde Secure
                    Linux Professional Edition, Pine 4.56 and earlier,
                    Red Hat Advanced Workstation 2.1, Red Hat
                    Enterprise Linux 2.1AS, Red Hat Enterprise Linux
                    2.1ES, Red Hat Enterprise Linux 2.1WS, Red Hat
                    Linux 7.1, Red Hat Linux 7.2, Red Hat Linux 7.3,
                    Red Hat Linux 8.0, Red Hat Linux 9, Slackware Linux
                    8.1, Slackware Linux 9.0, Slackware Linux current,
                    SuSE eMail Server 3.1, SuSE eMail Server III Any
                    version, SuSE Linux 7.2, SuSE Linux 7.3, SuSE Linux
                    8.0, SuSE Linux 8.1, SuSE Linux 8.2, SuSE Linux
                    Connectivity Server Any version, SuSE Linux
                    Database Server Any version, SuSE Linux Desktop
                    1.0, SuSE Linux Enterprise Server 7, SuSE Linux
                    Enterprise Server 8, SuSE Linux Firewall Any
                    version, SuSE Linux Office Server Any version, Unix
                    Any version
Vulnerability: pine-display-parameters-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/13150

Date Reported: 09/10/2003
Brief Description: Pine rfc2231_get_param integer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: Conectiva Linux 7.0, Conectiva Linux 8.0, Conectiva
                    Linux 9.0, EnGarde Secure Linux 1.0.1, EnGarde
                    Secure Linux Community Edition, EnGarde Secure
                    Linux Professional Edition, Pine 4.56 and earlier,
                    Red Hat Advanced Workstation 2.1, Red Hat
                    Enterprise Linux 2.1AS, Red Hat Enterprise Linux
                    2.1ES, Red Hat Enterprise Linux 2.1WS, Red Hat
                    Linux 7.1, Red Hat Linux 7.2, Red Hat Linux 7.3,
                    Red Hat Linux 8.0, Red Hat Linux 9, Slackware Linux
                    8.1, Slackware Linux 9.0, Slackware Linux current,
                    SuSE eMail Server 3.1, SuSE eMail Server III Any
                    version, SuSE Linux 7.2, SuSE Linux 7.3, SuSE Linux
                    8.0, SuSE Linux 8.1, SuSE Linux 8.2, SuSE Linux
                    Connectivity Server Any version, SuSE Linux
                    Database Server Any version, SuSE Linux Desktop
                    1.0, SuSE Linux Enterprise Server 7, SuSE Linux
                    Enterprise Server 8, SuSE Linux Firewall Any
                    version, SuSE Linux Office Server Any version, Unix
                    Any version
Vulnerability: pine-rfc2231getparam-integer-overflow
X-Force URL: http://xforce.iss.net/xforce/xfdb/13151

Date Reported: 09/10/2003
Brief Description: FTGatePro ftgatedump.fts script allows a remote
                    attacker to obtain configuration information
Risk Factor: Medium
Attack Type: Network Based
Platforms: FTGatePro 1.2 build 1331, Windows Any version
Vulnerability: ftgatepro-ftgatedump-obtain-information
X-Force URL: http://xforce.iss.net/xforce/xfdb/13152

Date Reported: 09/10/2003
Brief Description: MySQL long password buffer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: Debian Linux 3.0, Linux Any version, MySQL 3.0.57
                    and earlier, MySQL 4.0.14 and earlier, Unix Any
                    version, Windows Any version
Vulnerability: mysql-password-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/13153

Date Reported: 09/10/2003
Brief Description: FTGatePro exportmbx.fts script could allow a remote
                    attacker to download mailboxes of a domain
Risk Factor: Medium
Attack Type: Network Based
Platforms: FTGatePro 1.2 build 1331, Windows Any version
Vulnerability: ftgatepro-exportmbx-script-access
X-Force URL: http://xforce.iss.net/xforce/xfdb/13154

Date Reported: 09/11/2003
Brief Description: saned SANE_NET_INIT memory consumption
Risk Factor: Low
Attack Type: Network Based
Platforms: Debian Linux 3.0, saned Any version
Vulnerability: saned-sanenetinit-memory-consumption
X-Force URL: http://xforce.iss.net/xforce/xfdb/13155

Date Reported: 09/11/2003
Brief Description: saned malloc denial of service
Risk Factor: Low
Attack Type: Network Based
Platforms: Debian Linux 3.0, saned Any version
Vulnerability: saned-malloc-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/13157

Date Reported: 09/11/2003
Brief Description: saned fails to properly validate RPC numbers
Risk Factor: Low
Attack Type: Network Based
Platforms: Debian Linux 3.0, saned Any version
Vulnerability: saned-improper-rpc-validation
X-Force URL: http://xforce.iss.net/xforce/xfdb/13158

Date Reported: 09/11/2003
Brief Description: saned debug messages denial of service
Risk Factor: Low
Attack Type: Network Based
Platforms: Debian Linux 3.0, saned Any version
Vulnerability: saned-debug-message-dos
X-Force URL: http://xforce.iss.net/xforce/xfdb/13159

Date Reported: 09/11/2003
Brief Description: saned could allow an attacker to cause the server
                    to consume memory
Risk Factor: Low
Attack Type: Network Based
Platforms: Debian Linux 3.0, saned Any version
Vulnerability: saned-memory-consumption
X-Force URL: http://xforce.iss.net/xforce/xfdb/13160

Date Reported: 09/10/2003
Brief Description: Microsoft Internet Explorer allows an attacker to
                    obtain cookies by opening Web site in _search
                    window
Risk Factor: High
Attack Type: Network Based
Platforms: Microsoft Internet Explorer 5.01, Microsoft
                    Internet Explorer 5.5, Microsoft Internet Explorer
                    6.0, Windows Any version
Vulnerability: ie-search-obtain-cookie
X-Force URL: http://xforce.iss.net/xforce/xfdb/13161

Date Reported: 09/10/2003
Brief Description: Microsoft Internet Explorer history.back function
                    allows an attacker to obtain information and
                    execute code
Risk Factor: High
Attack Type: Network Based
Platforms: Microsoft Internet Explorer 5.01, Microsoft
                    Internet Explorer 5.5, Microsoft Internet Explorer
                    6.0, Windows Any version
Vulnerability: ie-historyback-execute-code
X-Force URL: http://xforce.iss.net/xforce/xfdb/13162

Date Reported: 09/10/2003
Brief Description: Microsoft Internet Explorer window.open function
                    allows an attacker to obtain information and
                    execute code
Risk Factor: High
Attack Type: Network Based
Platforms: Microsoft Internet Explorer 5.01, Microsoft
                    Internet Explorer 5.5, Microsoft Internet Explorer
                    6.0, Windows Any version
Vulnerability: iewindowopen-execute-code
X-Force URL: http://xforce.iss.net/xforce/xfdb/13163

Date Reported: 09/11/2003
Brief Description: myPHPNuke PHP file include
Risk Factor: Medium
Attack Type: Network Based
Platforms: Linux Any version, myPHPNuke 1.8.8_7, Unix Any
                    version, Windows Any version
Vulnerability: myphpnuke-php-file-include
X-Force URL: http://xforce.iss.net/xforce/xfdb/13164

Date Reported: 09/10/2003
Brief Description: Microsoft Internet Explorer NavigateAndFind
                    function allows an attacker to obtain information
                    and execute code
Risk Factor: High
Attack Type: Network Based
Platforms: Microsoft Internet Explorer 5.01, Microsoft
                    Internet Explorer 5.5, Microsoft Internet Explorer
                    6.0, Windows Any version
Vulnerability: ie-navigateand find-execute-code
X-Force URL: http://xforce.iss.net/xforce/xfdb/13165

Date Reported: 09/10/2003
Brief Description: Microsoft Internet Explorer history.back function
                    allows attacker to obtain information from a site
                    loaded in a different frame and domain
Risk Factor: Medium
Attack Type: Network Based
Platforms: Microsoft Internet Explorer 5.01, Microsoft
                    Internet Explorer 5.5, Microsoft Internet Explorer
                    6.0, Windows Any version
Vulnerability: ie-historyback-obtain-information
X-Force URL: http://xforce.iss.net/xforce/xfdb/13166

Date Reported: 09/10/2003
Brief Description: Microsoft Internet Explorer could allow an attacker
                    to perform actions without the knowledge of the
                    victim
Risk Factor: Medium
Attack Type: Network Based
Platforms: Microsoft Internet Explorer 5.01, Microsoft
                    Internet Explorer 5.5, Microsoft Internet Explorer
                    6.0, Windows Any version
Vulnerability: ie-perform-actions
X-Force URL: http://xforce.iss.net/xforce/xfdb/13167

Date Reported: 09/11/2003
Brief Description: Invision Power Board FONT or COLOR tags cross-site
                    scripting
Risk Factor: Medium
Attack Type: Network Based
Platforms: Invision Power Board 1.2, Linux Any version, Unix
                    Any version, Windows Any version
Vulnerability: invision-font-color-xss
X-Force URL: http://xforce.iss.net/xforce/xfdb/13168

Date Reported: 09/12/2003
Brief Description: man getenv function MANPL buffer overflow
Risk Factor: High
Attack Type: Host Based
Platforms: Linux Any version, man 1.5m1 and earlier
Vulnerability: man-getenv-manpl-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/13170

Date Reported: 09/12/2003
Brief Description: Microsoft Windows Server 2003 can allow attacker to
                    bypass mechanism used to detect buffer overflows
Risk Factor: High
Attack Type: Network Based
Platforms: Windows Any version, Windows Server 2003 Datacenter
                    Edition, Windows Server 2003 Enterprise Edition,
                    Windows Server 2003 Standard Edition, Windows
                    Server 2003 Web Edition
Vulnerability: winserver2003-bypass-security-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/13171

Date Reported: 09/11/2003
Brief Description: Asterisk CDR SQL injection
Risk Factor: Medium
Attack Type: Network Based
Platforms: Asterisk prior to 9/9/2003, Linux Any version
Vulnerability: asterisk-cdr-sql-injection
X-Force URL: http://xforce.iss.net/xforce/xfdb/13172

Date Reported: 09/12/2003
Brief Description: Bandsite admin.php script allows admin accounts to
                    be added to gain unauthorized access
Risk Factor: High
Attack Type: Network Based
Platforms: Bandsite 1.5, Unix Any version, Windows Any version
Vulnerability: bandsite-admin-access
X-Force URL: http://xforce.iss.net/xforce/xfdb/13173

Date Reported: 09/12/2003
Brief Description: 4D WebStar password buffer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: 4D WebSTAR V 5.3.1, Mac OS Any version
Vulnerability: 4dwebstar-password-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/13174

Date Reported: 09/12/2003
Brief Description: MyServer MSCGI library GET request buffer overflow
Risk Factor: High
Attack Type: Network Based
Platforms: Linux Any version, MyServer 0.4.3 and earlier,
                    Windows 98, Windows 2000 Any version
Vulnerability: myserver-mscgi-get-bo
X-Force URL: http://xforce.iss.net/xforce/xfdb/13175

_____

Risk Factor Key:

     High Security issues that allow immediate remote, or local access
              or immediate execution of code or commands, with unauthorized
              privileges. Examples are most buffer overflows, backdoors,
              default or no password, and bypassing security on firewalls
              or other network components.
     Medium Security issues that have the potential of granting access or
              allowing code execution by means of complex or lengthy exploit
              procedures, or low risk issues applied to major Internet
              components. Examples are cross-site scripting, man-in-the-middle
              attacks, SQL injection, denial of service of major applications,
              and denial of service resulting in system information disclosure
              (such as core files).
     Low Security issues that deny service or provide non-system
              information that could be used to formulate structured attacks
              on a target, but not directly gain unauthorized access. Examples
              are brute force attacks, non-system information disclosure
              (configurations, paths, etc.), and denial of service attacks.

______

About Internet Security Systems (ISS)
Founded in 1994, Internet Security Systems (ISS) (Nasdaq: ISSX) is a pioneer and world leader in software and services that protect critical online resources from an ever-changing spectrum of threats and misuse. Internet Security Systems is headquartered in Atlanta, GA, with additional operations throughout the Americas, Asia, Australia, Europe and the Middle East.

Copyright (c) 2003 Internet Security Systems, Inc. All rights reserved worldwide.

Permission is hereby granted for the electronic redistribution of this document. It is not to be edited or altered in any way without the express written consent of the Internet Security Systems X-Force. If you wish to reprint the whole or any part of this document in any other medium excluding electronic media, please email xforceiss.net for permission.

Disclaimer: The information within this paper may change without notice. Internet Security Systems provides this information on an AS IS basis with NO warranties, implied or otherwise. Any use of this information is at the user’s risk. In no event shall Internet Security Systems be held liable for any damages whatsoever arising out of or in connection with the use or dissemination of this information.

X-Force PGP Key available on MIT's PGP key server and PGP.com's key server, as well as at http://xforce.iss.net/xforce/sensitive.php

Please send suggestions, updates, and comments to: X-Force xforceiss.net of Internet Security Systems, Inc.

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQCVAwUBP2XlXDRfJiV99eG9AQH54gP/df4jMLzbRi25efm+IphNztMrHo1ck9yT
l2FNz4A6xWARvHgL5IYB1XtjdTGAj4fqPe/MCymRL/1zHf3+juThphoeLOdg9rAA
emhiTa7inTwdvFLP6jgpWrdeK/+pyup4vY3NpYf+zIcEp7kjUUyEnSkPcU7bPfma
SbKQufo4rGY=
=YCuG
-----END PGP SIGNATURE-----