TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------


> Internet Scanner XPU 5.1 is now available from the ISS Download Center:
> <http://www.iss.net/eval/eval.php>.  
> 
> This XPU delivers 25 new vulnerability checks.  These checks address a
> number of high-risk vulnerabilities including a check for the Internet
> Explorer vulnerability utilized by the Nimda Worm.  Other vulnerabilities
> covered by this XPU include checks for an Oracle buffer overflow, telnet
> buffer overflow, Cisco IOS authentication bypass, and SSH unauthorized
> access.
> 
> 
> PROTECTION BENEFITS OF XPU 5.1
> 
> *     Web Servers.  XPU 5.1 contains checks for three IIS web server
> vulnerabilities.  The XPU also has web scan checks to address
> vulnerabilities that affect iPlanet, IBM WebSphere, and Jakarta Tomcat web
> servers.
> *     Platform Protection.  XPU 5.1 contains six checks to identify
> vulnerabilities in the Cisco IOS operating system.  Checks for Solaris and
> Windows vulnerabilities are also included in the XPU.
> *     Application Protection.  In addition to web server checks, XPU 5.1
> contains an Oracle buffer overflow check, a telnet buffer overflow check,
> and an SSH unauthorized access check.  The XPU also has checks applicable
> to Lotus Domino servers and Qpopper mail servers.  
> *     Other Malicious Code.  The XPU contains two backdoor checks and a
> check for an Internet Explorer vulnerability that allows malicious code to
> be executed. 
> 
> 
> VERSIONS/PLATFORMS
> 
> XPU 5.1 is for use with Internet Scanner 6.2.  Internet Scanner 6.2 is
> available on the ISS Download Center:  <http://www.iss.net/eval/eval.php>.
> 
> 
> 
> NEW CHECKS 
> 
> New checks included in XPU 5.1 are listed below.  To learn more about the
> vulnerabilities these checks address please see the X-Force section of the
> ISS web site at <http://xforce.iss.net/> and search by the VulnID.  
> 
> Risk  VulnID      Check Name                      Category
> ====  ====== ==========                           ========
> High     6992 BackdoorCodered2                Backdoors
> High     7073 Vscan2001Trojan*                        Backdoors
> High     6749 CiscoIosAdminAccess             Router/Switch
> High     6180 CiscoIosCableDocsis*                    Router/Switch
> High     6178 CiscoIosSnmpServerCommunity*            Router/Switch
> High     6179 CiscoSnmpVacm*                          Router/Switch
> High     6029 IisCmdaspGainPrivs              Web Scan
> High     6793 JavaServletCrosssiteScripting   Web Scan
> High     6554 NetscapeEnterpriseUriBo         Web Scan
> High     6510 PostqueryHttpPostBo             Web Scan
> High     6758 OracleTnsListenerBo             Daemons
> High     6629 SolarisYppasswdBo               Daemons
> High     6868 SshPasswordLengthUnauthAccess   Daemons
> High     6875 TelnetdOptionTelrcvBo           Daemons
> High     6647 QpopperUsernameBo               E-mail
> High     6062 WinDdeElevatePrivileges*                NT Patches
> High     6517 WinntIndexserverSearchBo*       NT Patches
> High     6306         IeMimeExecuteCode*                      NT Critical
> Issues
> Medium   6931 Win2kSp2*                               NT Patches
> Medium   6171 IisMalformedUrlDos*                     NT Patches
> Medium   6742 IisUnicodeAspDisclosure         Web Scan
> Medium   6169 CiscoIosModifySnmp*                     Router/Switch
> Medium   6589 CiscoIosTcpDos*                         Router/Switch
> Medium   5488 LotusDominoSmtpEnvid            Daemons
> Medium   6422 SolarisFtpShadowRecovery        Daemons
> 
> * next to check name above indicates that administrative privileges on
> scanned hosts are required to run check.
> 
> 
> IMPROVED CHECKS
> 
> A number of checks have also been improved in XPU 5.1.
> 
> Risk  VulnID      Check Name                      Category
> ====  ======  ==========                          ========
> High          6233        NetscapeDirectoryServerBo   Daemons
> High          6554        NetscapeEnterpriseUriBo     Web Scan
> High          4204        IisVirtualUncShare          Web Scan
> Medium 6800        IisDeviceAspDos            Web Scan
> Low           4558        IisStandaloneServer                 Web Scan
> High          51            Fpnwclnt                  NT Critical Issues
> Medium        5013        OutlookCacheBypass          NT Patches
> Medium        6172        ExchangeMalformedUrlDos     NT Patches
> Medium        4194        ECWareDos                           CGI-Bin
> 
> 
> For more information on the release of Internet Scanner, please contact
> the following:
> 
> *     For additional product information:
>       -       http://www.iss.net/db_data/xpu/IS.php
>       -       Jamie Lau, X-Press Updates Product Manager, [EMAIL PROTECTED]
> <mailto:[EMAIL PROTECTED]>
> 
> *     For sales information:
>       -       [EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]>
>       -       888-901-7477 (North America)
> 
> *     For education, consulting and support information, including ISS
> SecureU training on Internet Scanner:
>       -       Lisa Weinstein, Marketing Programs Manager, Consulting &
> Education
>               [EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]>
>       -       ISS SecureU training -
> <http://education.iss.net/namerica.php>
>       -       Technical Support, [EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]>,
> 888-447-4861 (North America)
> 


Reply via email to