Security News
-
Security Reviews
-
Exploits
-
Tools
-
UNIX Focus
-
Windows Focus
SecuriTeam
Beyond Security
SecuriTeam Home
Ask the Team
Mailing Lists
Advertising Info
Blogs
SecuriTeam in Your Inbox
New vulnerability?
New tool?
Tell us
Windows NT Focus Archive 1999
Select Year:
2008
2007
2006
2005
2004
2003
2002
2001
2000
1999
1998
December
1999
CamShot WebCam HTTP Server remote buffer overflow (GET)
AnalogXSimpleServer is vulnerable to a remote DoS attack (GET)
More info on the IIS escape character vulnerability
FTPPro stores sensitive information in the open
Viruses can bypass Virus checking under Windows 95/98/NT
Patch Available for the Escape Character Parsing Vulnerability
Patch Available for the Virtual Directory Naming Vulnerability
Patch Available for "Malformed TDS Packet Header" Vulnerability
Patch Available for the Syskey Keystream Reuse Vulnerability
Patch Available for "Malformed Security Identifier Request" Vulnerability
Security hole allows resetting the password of SA on SQL Server 7.0
Patch Available for the Server-side Page Reference Redirect Vulnerability
Patch Available for the Malformed Resource Enumeration Argument Vulnerability
Local users can trick others into running executables. (.CNT/.GID/.HLP)
Internet Explorer 5.0 vulnerable to a buffer overflow (vnd.ms.radio)
Windows NT Task Scheduler vulnerability explained
Patch Available for the Windows "Multithreaded SSL ISAPI Filter" Vulnerability
Patch Available for the "WPAD Spoofing" Vulnerability
November
1999
Patch Available for the "Legacy Credential Caching" Vulnerability
Patch Available for the "IE Task Scheduler" Vulnerability
Default Internet Explorer 5.0 security settings allows frame spoofing
Windows NT SUBSTituted drives vulnerability
NTMail vulnerable to the VRFY attack
APC's PowerChute Plus is vulnerable to DoS attack
NetBeans/ Forte' Java IDE vulnerability
NetTerm FTP Daemon contains security vulnerabilities
Internet Explorer 5.0 is vulnerable to XML HTTP redirect
Patch Available for the Javascript Redirect Vulnerability
SQL Server 7.0 Linked Server Password Vulnerability
IE 5.0 and WMP ActiveX leaks directory information
How to disable the content advisor password in IE4/5
Patch Available for the "File Access URL" Vulnerability
Patch Available for "Active Setup Control" Vulnerability
A partial workaround for the RFPoison DoS
Windows NT Printer spooler Service Vulnerabilities
CheckPoint Firewall-1 Source Logging security vulnerability
RDS attacks, is there finally a solution?
IE HTTP redirection problem
October
1999
URL Live! 1.0 WebServer vulnerable to dotdotdot traversing
WiredRed's e/pop program is vulnerable to session hijacking
The truth behind Windows 2000's Auto-Logon feature
Microsoft releases Service Pack 6 for Windows NT
Falcon Web Server Path Parsing hole
Gauntlet 5.0 for Windows NT is vulnerable to 'ftp proxy' attack
Patch Available for the "Virtual Machine Verifier" Vulnerability
Patch Available for Excel 'Symbolic Link' vulnerability
Internet Explorer vulnerable to a 'JavaScript redirect' bug that allows reading of local files
Patch Available for "Download Behavior" Vulnerability
Workaround Available for "IFRAME ExecCommand" Vulnerability
Internet Anywhere Mail Server is vulnerable to denial of service attacks
Infis - a sophisticate Windows NT virus
Patch Available for the "ImportExportFavorites" Vulnerability
"The Matrix" Screensaver is insecure
Omni-NFS/X Enterprise (nfsd.exe) Denial of Service
Internet Explorer 5 allows attackers to read local files
September
1999
Patch Available for the Domain Resolution and "FTP Download" Vulnerabilities
An analysis of the PPTP authentication extensions (MS-CHAPv2)
Patch Available for "Spoofed Route Pointer" Vulnerability
Vulnerability in the RasMan Service allows authenticated users to gain administrative privileges
HackerShield product found to contain a security vulnerability
Several POP3/SMTP servers are vulnerable to buffer overflows
Import-Export-Favorites vulnerability in Internet Explorer
Windows NT 4.0 does not delete Unattended Installation Files
Patch Available for the "Set Cookie Header Caching" vulnerability
Some Web servers are still vulnerable to the dotdotdot vulnerability
Patch Available for the Malformed Telnet Argument Vulnerability
Exploiting DCOM to gain Administrative rights on WinNT 4
Patch Available for the Fragmented IGMP Packet Vulnerability
Prevent Mail Bombs against MS Exchange Server
August
1999
IE5 FTP Passwords stored in clear text in Windows NT
Patch Available for the Scriptlet.typlib/Eyedog Vulnerability
Internet Explorer code that formats local drives
Internet Explorer code that formats local drives
Simple HTML code can be used to crash Internet Explorer
A flaw in IE 5.0 ActiveX control allows executing programs
aVirt Gateway Suite can be used to reveal NT RAS password
NT Predictable initial TCP sequence vulnerability revisited
IBM's customized GINA allows local users to gain administrative privileges
IIS is vulnerable to a Denial of Service attack due to AspUpload 1.4
Patch Available for the Office ODBC Vulnerabilities
Windows 9x/NT Long File Names Vulnerability Revisited
More information about the "Malformed HTTP Request Header" vulnerability
Patch Available for the "Malformed HTTP Request Header" Vulnerability
Patch Available for the Terminal Server Connection Request Flooding Vulnerability
IIS exposes the host's local IP address
July
1999
MS Office 97 ODBC vulnerability
IIS RDS vulnerability
Using https with IIS can be used to bring down the Server
Patch Available for "Encapsulated SMTP Address" Vulnerability
Bad Permissions on Passwords Stored by WebTrends Software
Kiss Of Death - a new Denial of Service attack
Write access to a user directory suffices to penetrate the user's account
June
1999
IIS Double-Byte Codepage vulnerability
Windows NT LSA can be crashed by a remote attacker
Patch Available for "Malformed HTR Request" Vulnerability
Windows 2000 FTP Server vulnerable to 'PASV' attack
IIS HTR hole allows attackers to execute arbitrary code
Ordinary users can easily bring Windows NT to its knees
PC Anywhere vulnerable to a Denial of Service attack
The Economist's Screen Saver creates a huge security hole
May
1999
Patch Available for RAS and RRAS Password Vulnerability
How to hide your computer from the "Network Neighborhood"
Counter WinCGI is vulnerable to a Denial of Service attack
NT ODBC Remote Compromise
Malformed Help File vulnerability allows the execution of arbitrary code (patch available)
Microsoft Site Server's AdSamples Directory Reveals ID and Password
Service Pack 5 is finally out
IIS 4.0 vulnerable to remote file viewing
Tripwire is now available for Windows NT
Windows NT Profiles can be used to insert Trojans into privileged accounts
April
1999
Service Pack 5 will enhance NT security
Windows NT protected by a Firewall is vulnerable to penetration during boot
DNS Spoofing and Windows NT DNS
March
1999
Case sensitivity vulnerability allows local users to obtain administrative rights
Security flaws in NT domain authentication
February
1999
ARCserve NT sends administrator password in clear text
IIS4 password attack
Microsoft's Point-To-Point Tunneling Protocol cracked
File mapping cache vulnerability allows local users to gain administrator privileges (patch available)
Hotfix Management How-To
NT 4.0 with Service Pack 4 is vulnerable to an empty password login
Network Forensic - NT Security Toolbox
Securing your IIS server
NTO Scanner - a port scanner for Windows NT
January
1999
SecureWire, a new breed of web security products
Securing your Windows NT installation
IIS Denial of Service attack patched
Windows 95/98 SMB Authentication vulnerability
Select Year:
2008
2007
2006
2005
2004
2003
2002
2001
2000
1999
1998
Security News
-
Security Reviews
-
Exploits
-
Tools
-
UNIX Focus
-
Windows Focus
All Sections
Security News
Unix focus
Exploits
Tools
Windows focus
Security Reviews
Apache HTTP Server mod_proxy_ftp Wildcard Characters Cross-Site Scripting
Microsoft ASP.NET ValidateRequest Filters Bypassing Allows XSS And HTML Injection Attacks
Dreambox DM500 Webserver Long URL Request Denial of Service
Multiple Vulnerabilities in AWStats Totals
Kyocera Mita Scanner File Utility (Multiple)
BSQL Hacker - Advanced SQL Injection Framework / Tool
vBulletin Cross Site Scripting Vulnerability (popup)
Novell iPrint Client ActiveX Control Multiple Vulnerabilities
Multiple Vendor libpurple MSN Protocol SLP Message Heap Overflow Vulnerability
Calendarix Basic Two SQL Injection Vulnerabilities
More ›››
Featured Articles
Microsoft ASP.NET ValidateRequest Filters Bypassing Allows XSS And HTML Injection Attacks
vBulletin Cross Site Scripting Vulnerability (popup)
Internet Explorer Zone Elevation Restrictions Bypass and Security Zone Restrictions Bypass (MS08-043)
MicroWorld MailScan - Multiple Vulnerabilities within Admin-Webinterface
Sun xVM VirtualBox Privilege Escalation Vulnerability
Vulnerabilities in DNS Allows Spoofing (MS08-037)
Vulnerabilities in Microsoft SQL Server Allows Elevation of Privilege (MS08-040)
Copyright © 1998-2007
Beyond Security
All rights reserved.
Terms of Use
Site Privacy Statement
.