SecurityFocus.com Newsletter #123 2001$BG/(B12$B7n(B10$BF|(B->2001$BG/(B12$B7n(B14$BF|(B



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
$B1F;3(B@$B%i%C%/$G$9!#(B
SecurityFocus.com Newsletter $BBh(B 123 $B9f$NOBLu$r$*FO$1$7$^$9!#(B
$BLu$N$J$$9`L\$K$D$$$F$O!VF|K\8lLu$J$7!W$H$7$F6hJL$7$F$"$j$^$9!#(B
- ---------------------------------------------------------------------------
SecurityFocus.com Newsletter $B$K4X$9$k(BFAQ:
http://www.securityfocus.com/popups/forums/securityfocusnews/intro.shtml
BugTraq-JP $B$K4X$9$k(B FAQ:
http://www.securityfocus.com/popups/forums/bugtraq-jp/faq.shtml
- ---------------------------------------------------------------------------
$B0zMQ$K4X$9$kHw9M(B:
$B!&$3$NOBLu$O(B Security-Focus.com $B$N5v2D$r3t<02qe$G9T$o(B
 $B$l$F$$$^$9!#(B
$B!&(BSecurityFocus.com Newsletter $B$NOBLu$r(B Netnews, Mailinglist,
 World Wide Web, $B=q@R(B, $B$=$NB>$N5-O?G^BN$G0zMQ$5$l$k>l9g$K$O%a!<%k$n(b
 $BA4J80zMQ$r$*4j$$$7$^$9!#(B
$B!&F|K\8lHG%K%e!<%9%l%?!<(b 1 $B9f$+$i(B 3 $B9f$^$G$K$O$3$NHw9M$,IU$$$F$$$^$;(B
 $B$s$,=`MQ$9$k$b$N$H$7$^$9!#(B
$B!&$^$?!"(BSecurity-Focus.com $BDs6!$N(B BugTraq-JP $B%"!<%+%$%v(b [*1] $B$X$N$$$+(B
 $B$J$k7A<0$n%o%$%q!<%j%s%/$b>e5-$K=`$8$F$/$@$5$$!#(B
1) http://www.securityfocus.com/archive/79
- ---------------------------------------------------------------------------
- ---------------------------------------------------------------------------
$B$3$NOBLu$K4X$9$kHw9M(B:
$B!&$3$NOBLu$NE,MQ@.2L$K$D$$$F3t<02ql9g!"(BBUGTRAQ-JP $B$X(B Errata $B$H$7$F=$@5(B
 $BHG$r$4Ej9FD:$/$+!"Lul9g$K$O=$@5HG$r$G$-$k$@$1?WB.$KH/9T$7$^$9!#(B
- ---------------------------------------------------------------------------
- ---------------------------------------------------------------------------
$B86HG(B:
Date: 2001$BG/(B12$B7n(B17$BF|(B 13:06:31 -0700 (MST)
Message-ID: <Pine.GSO.4.30.0112171306020.26310-100000@mail.securityfocus.com>
SecurityFocus Newsletter #123
- ------------------------------
This Issue is Sponsored by VeriSign - The Internet Trust Company
I. FRONT AND CENTER($BF|K\8lLu$J$7(B)
 1. Advertising Information
 2. A Simple Oracle Host-Based Scanner
 3. Incident Management with Law Enforcement
 4. Palm OS: A Platform for Malicious Code?
 5. White House CyberSecurity - Jobs, Research, and Rhetoric, but...
II. BUGTRAQ SUMMARY
 1. Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability
 2. Volition Red Faction Game Server/Client Denial Of Service...
 3. Kebi WebMail Unauthenticated Administration Vulnerability
 4. Lotus Domino bad URL database Denial of Service Vulnerability
 5. XFree86 fbglyph Denial of Service Vulnerability
 6. XTerm Title Bar Buffer Overflow Vulnerability
 7. Denicomp Winsock RSHD/NT Standard Error Denial of Service...
 8. Microsoft IIS False Content-Length Field DoS Vulnerability
 9. CSVForm Remote Arbitrary Command Execution Vulnerability
 10. FreeBSD AIO Library Cross Process Memory Write Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
 1. Washington Earmarks Megabucks for Cyber Security
 2. Is Open-Source Security Software Safe?
IV. SECURITYFOCUS TOP 6 TOOLS
 1. MRTG-eth-probe v1.5.4
 2. XCmail v1.5beta-2001$BG/(B12$B7n(B14$BF|(B
 3. pcAudit
 4. OpenSC v0.3.2
 5. CryptoHeaven v1.0
 6. OpenNA Linux v1b
I. FRONT AND CENTER($BF|K\8lLu$J$7(B)
- ---------------------------------
II. BUGTRAQ SUMMARY
- -------------------
1. Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability
BugTraq ID: 3652
$B%j%b!<%h$+$i$n:f8=@-(b: $B$"$j(B
$B8xI=F|(B: Dec 07 2001 12:00A
$B4XO"$9$k(BURL:
http://www.securityfocus.com/bid/3652
$B$^$H$a(B:
Internet Protocol Security (IPSec) $B$O(B IP $B$rMxMQ$9$k%M%C%H%o!<%/fb$n%h%i(b
$B%U%#%C%/$KBP$7!"G'>Z5!9=$H0E9f5!9=$rDs6!$9$k%W%m%H%3%k$G$"$k!#(BInternet
Key Exchange (IKE) $B$O(B IPSec $BI8=`$H6&$KMxMQ$5$l$k4IM}MQ%W%m%H%3%k$NI8=`(B
$B$G$"$k!#(BIKE $B$O(B $BIU2C5!G=$r(B IPSec $BI8=`$XIU$12C$(!"%]!<%hhv9f(b 500 $B$G(B UDP
$B$N%3%M%/%7%g%s$r%G%U%)%k%H$GBT$A]$H$J$C$?%[%9%H$OA4$F$NMxMQ2DG=$J%7%9%F%`;q8;$rMxMQ$7?T$/$7$F$7$^(B
$B$&$N$G$"$k!#(B
$BDL>oF0:n$X$NI|5l$r9T$&$?$a$K$O%7%9%F%`$N:F5/F0$,I,MW$G$"$k$H9M$($i$l$k!#(B
$B$J$*!"$3$NLdBj$O(B UDP $B$=$N$b$N$KB8:_$9$k!"@x:_E*$J860x$KM3Mh$9$k$H9M$($i(B
$B$l$kE@$OCm5-$5$l$k$Y$-$G$"$k!#(B
2. Volition Red Faction Game Server/Client Denial Of Service Vulnerability
BugTraq ID: 3651
$B%j%b!<%h$+$i$n:f8=@-(b: $B$"$j(B
$B8xI=F|(B: Dec 07 2001 12:00A
$B4XO"$9$k(BURL:
http://www.securityfocus.com/bid/3651
$B$^$H$a(B:
Red Faction $B$O(B Vilition $B$K$h$C$F3+H/$5$l!"(BTHQ $B$K$h$jHNGd$5$l$F$$$k!">&(B
$B6HE*$KDs6!$5$l$F$$$k(B 3D $BBP@o%7%e!<%f%#%s%0%2!<%`$g$"$k!#(b
$B$3$N%=%U%H%&%'%"$O(B 32 $B?M$N%W%l%$%d!<$^$g$,(b LAN $B$J$$$7(B TCP/IP $B%M%C%H%o!<(b
$B%/$r2p$7$F%2!<%`$r9t$($kmm$k@_7w$5$l$f$$$k!#%g%u%)%k%h>uBV$G!"(BRed Faction
$B%2!<%`%5!<%p$h%2!<%`%/%i%$%"%s%h$o%]!<%hhv9f(b 7755 $B$rMxMQ$7$FDL?.$r9T$C(B
$B$F$$$k!#%3%M%/%7%g%s$rBT$AJ}$,%/%i%C%7%e$7$F$7$^$&$N$G$"(B
$B$k!#(B
$B$3$N967b$N1F6A$roF0:n$XI|5l$9$k$?$a$K$O:F5/F0$5(B
$B$l$M$P$J$i$J$$!#(B
3. Kebi WebMail Unauthenticated Administration Vulnerability
BugTraq ID: 3655
$B%j%b!<%h$+$i$n:f8=@-(b: $B$"$j(B
$B8xI=F|(B: Dec 08 2001 12:00A
$B4XO"$9$k(BURL:
http://www.securityfocus.com/bid/3655
$B$^$H$a(B:
Kebi Webmail $B$O(B Kebi Community $B$,Ds6!$9$kMM!9$J%=%U%H%&%'%"Fb$N%3%s%]!<(b
$B%M%s%H$H$7$FDs6!$5$l$F$$$k!"%O%s%0%k$G$N(B Web $B%a!<%k4d6-$rds6!$9$k%=%u%h(b
$B%&%'%"$G$"$k!#$3$N%=%U%H%&%'%"$K$O%G%U%)%k%H>uBV$G!"$$$+$J$k%[%9%H$+$i(B
$B$N%"%/%;%9$,2DG=$J%G%#%l%/%H%jFb$K!"4IM}uBV$K$7$?$^$^$G$"$k$HJs9p$5$l$F$$$k!#Js9p$K$h$k$H!"4IM}http://server/a/)$B!#$3$N$?$a!">pJs$NO31L$N2DG=(B
$B@-$H(B Web$B%a!<%k$k4x$9$k5!g=$ng'>Z$r9T$&;v$N$J$$2~JQ$,A[Dj$5$l$k!#(B
$B8=:_$3$NLdBj$K4X$7$F$O$3$l0J>e$N>pJs$O4s$;$i$l$F$$$J$$!#(B
$B$3$N%=%U%H%&%'%"$O4Z9q@=$G$"$k!#(B
4. Lotus Domino bad URL database Denial of Service Vulnerability
BugTraq ID: 3656
$B%j%b!<%h$+$i$n:f8=@-(b: $B$"$j(B
$B8xI=F|(B: Dec 08 2001 12:00A
$B4XO"$9$k(BURL:
http://www.securityfocus.com/bid/3656
$B$^$H$a(B:
Lotus Domino 5.0.5 $B$*$h$S(B 5.0.8 ($B%U%i%s%98lHG(B) $B$O!"FCJL$KAH$_N)$F$i$l$?(B
$B0-0U$"$k(B URL $B$r(B Web $B%5!<%p$km?$($k;v$g(b DoS $B$K4Y$i$;$i$l$F$7$^$&LdBj$rJz(B
$B$($F$$$k!#%G!<%?%y!<%9l>$NA0$K(B /./ $B$r(B URL $BFb$K4^$`MM$KAH$_N)$F$?>e$G%"(B
$B%/%;%9$r9T$&;v$K$h$j!"Ev3:%G!<%?%y!<%9$ol58z$k$j$c$f$7$^$&$n$g$"$k!#(b
$BNc(B: http://server/./webadmin.nsf
$B%5!<%p$x$n967b$r@.n)$5$;$k$?$a$k$o!"%g!<%?%y!<%9$oi,$:!"967b;~$kmxmq$5(b
$B$l$F$$$J$$>uBV$G$J$1$l$P$J$i$J$$!#$3$N(B DoS $B>uBV$r2DG=$K$9$k@53N$J;EAH$_(B
$B$O!"8=:_$N=jCN$i$l$F$$$J$$!#(B
$BJs9p$K5r$k$H!"%U%i%s%98lHG$O$3$NLdBj$N1F6A$r$N8@8lHG$bF1MM$K$3$NLdBj$N1F6A$r5. XFree86 fbglyph Denial of Service Vulnerability
BugTraq ID: 3657
$B%j%b!<%h$+$i$n:f8=@-(b: $BL$>\(B
$B8xI=F|(B: Dec 08 2001 12:00A
$B4XO"$9$k(BURL:
http://www.securityfocus.com/bid/3657
$B$^$H$a(B:
XFree86 4.x $B$O@x:_E*$K%a%b%jFbMF$NGK2u$J$$$7%P%C%U%!%*!<%p!<%u%m!<$r@8(b
$B$8$k967b$N1F6A$r/$J$/$H$b(B DoS $B$K4Y$k;v$,<($5(b
$B$l$F$$$k!#$^$?$3$NLdBj$NDs<($o!"(bx $B%5!<%p$ru67$K$*$$$FJs9p$5$l$F$$$k!#(B
1. Konqueror $B%V%i%&%6$,Hs>o$KD9$$J8;zNs$r3hF0>uBV$N%V%i%&%6%&%$%s%I%&Fb(B
 $B$G2rl9g(B
 ($B8@$$49$($k$J$i$P!"%j%b!<%h%5%$%h$x%v%i%&%6fb$+$i$3$l$ij8;zns$r%z!<(b
 $B%9%H$9$k;v$r0UL#$7$F$$$k(B)
2. Konqueror $B$N%U%!%$%k%^%M!<%8%cfb$gd9$$%u%!%$%kl>$,%@%V%k%/%j%C%/$5$l(B
 $B$?>l9g(B
$B5;=QE*$J>\:Y>pJs$O$^$@8x3+$5$l$F$$$J$$$,!"(Bfbglyph.c $BMQ$N%Q%C%A$,4{$KDs(B
$B6!$5$l$F$$$k!#(B
6. XTerm Title Bar Buffer Overflow Vulnerability
BugTraq ID: 3663
$B%j%b!<%h$+$i$n:f8=@-(b: $B$J$7(B
$B8xI=F|(B: Dec 08 2001 12:00A
$B4XO"$9$k(BURL:
http://www.securityfocus.com/bid/3663
$B$^$H$a(B:
XFree86 $B$O%U%j!<$gds6!$5$l$f$$$k(b X Window System $B$N/$J$/$H$b!"$3$N%=%U%H%&%'%"Fb$K4^$^$l$k(B X Server $B$O!"%j%b!<%h$n%f!<%6(b
$B$,%P%C%U%!%*!<%p!<%u%m!<$rmxmq$7$?967b$r2dg=$h$9$kldbj$rjz$($f$$$k!#ld(b
$BBj$O(B -title $B%*%W%7%g%s$G;XDj$5$l$kJ8;zNs$No$K(B
$BD9$$J8;zNs$,;XDj$5$l$k:]!"%;%0%a%s%F!<%7%g%s%u%)%k%h$r@8$8$k%p%c%u%!%*!<(b
$B%P!<%u%m!<$,@8$8$k$n$g$"$k!#(b
$B$3$NLdBj$K$h$j!"967be=q$-$,2DG=$G$"$j!"$3$N967b$r9T$&;v$K$h$j!"967buBV$G%$%s%9%H!<%k$5$l$f$$$k7. Denicomp Winsock RSHD/NT Standard Error Denial of Service Vulnerability
BugTraq ID: 3659
$B%j%b!<%h$+$i$n:f8=@-(b: $B$"$j(B
$B8xI=F|(B: Dec 10 2001 12:00A
$B4XO"$9$k(BURL:
http://www.securityfocus.com/bid/3659
$B$^$H$a(B:
Winsock RSHD/NT $B$O(B Windows NT $B$*$h$S(B Windows 2000 $B8~$1$N%j%b!<%h%7%'%k(b
$B$rDs6!$9$k%G!<%b%s%w%m%0%i%`$g$"$k!#$3$n%=%u%h%&%'%"$oi8=`e*$j(b UNIX $B$N(B
rsh $B$H(B rcp $B%3%^%s%I$rMxMQ$9$k!#(Brsh ($B8@$$49$($k$J$i$P!"(B"remote shell")
$B$OBP1~$9$k%5!<%p$g$"$k(b rshd $B$,2TF0Cf$N!"B>$N%7%9%F%`>e$GHsBPOCE*$J%W%m(B
$B%0%i%`$NuBV$G$O!";XDj$5$l$?%W%m%0%i%`$X$N%"%/%;%9$HuBV(B ($B%G%U%)%k%H$G$O%]!<%hhv9f(b 514 $B$G$"(B
$B$k(B)$B$G$O!"(Brsh $B$OI8=`%(%i!<=pno$kmxmq$5$l$k%g!<%?$raw?.$9$k$?$a$k!"%g!<%b(b
$B%s$KBP$7$F$"$k%]!<%hhv9f$rm?$($k;emm$k$j$c$f$$$k!#$3$n%]!<%hhv9f$,e,@5(b
$B$JHV9f$G$O$J$$>l9g!"(BWinsock RSHD/NT $B$O$3$NITE,@5$JHV9f$@$1$G$O$J$/!"(B10
24 $BHV0J2<$na4$f$n%]!<%hhv9f$x$n@\b3$r;n$_$k$n$g$"$k(b($b;n$_$kbp>]$N%]!<%h(b
$BHV9f$OIi$N%]!<%hhv9f$b4^$^$l$k(b)$b!#$3$n:]!"(bcpu $B;q8;$N>CHq$,9T$o$l!"7k2L$H(B
$B$7$F(B DoS $B$K4Y$k2DG=@-$,$"$k!#(B
$BDL>oF0:n$X$NI|5l$O%5!<%s%9$n:f5/f0$,i,mw$g$"$k$h9m$($i$l$k!#(b
8. Microsoft IIS False Content-Length Field DoS Vulnerability
BugTraq ID: 3667
$B%j%b!<%h$+$i$n:f8=@-(b: $B$"$j(B
$B8xI=F|(B: Dec 11 2001 12:00A
$B4XO"$9$k(BURL:
http://www.securityfocus.com/bid/3667
$B$^$H$a(B:
Microsoft IIS 5.0 $B$O!"FCJL$K0-0U$r;}$C$FAH$_N)$F$i$l$?(B HTTP $B$N(B GET $B%a%=%C(B
$B%I$,M?$($i$l$k:]!"(BDoS $B$K4Y$kLdBj$rJz$($F$$$k5?$$$,$"$k!#(B
IIS 5.0 $B$XIi$ND9$$CM$r;}$D(B "Content-Length" $B%U%#!<%k%i$r;}$d$h$&$k!"0u(b
$B?^$r;}$C$FAH$_N)$F$i$l$?(B HTTP $B$N(B GET $B%a%=%C%I$,M?$($i$l$k:]!"DL>o$"$jF@(B
$B$J$$?6$kIq$$$,H/@8$9$k!#$3$N:]%5!<%p$o%3%m%/%7%g%s$r3nn)$5$;$?$^$^$n>u(B
$BBV$KJ]$A!"%?%$%`%"%&%H$rH/@8$5$;$:!"$=$l$K$b4X$o$i$:1~Ez$r9T$o$J$$>uBV(B
$B$K4Y$k$N$G$"$k!#$3$NLdBj$O(B Web $B%5!<%p$r(b DoS $B>uBV$K4Y$i$;$k$?$a$KMxMQ$5(B
$B$l$k@x:_E*$J2DG=@-$,$"$k!#(B
$B$3$NM=B,ITG=$J5sF0$,!"$$$:$l$+$N7ABV$rMxMQ$7$F(B DoS $B$K4Y$i$;$k$?$a$N967b(B
$B$KMxMQ$5$l$F$7$^$C$?>l9g!"0J8e!"DL>oF0:n$XI|5l$5$;$k$?$a$K$O%5!<%p$n:f(b
$B5/F0$,I,MW$G$"$k!#(B
9. CSVForm Remote Arbitrary Command Execution Vulnerability
BugTraq ID: 3668
$B%j%b!<%h$+$i$n:f8=@-(b: $B$"$j(B
$B8xI=F|(B: Dec 11 2001 12:00A
$B4XO"$9$k(B URL:
http://www.securityfocus.com/bid/3668
$B$^$H$a(B:
CSVForm $B$O!"(BCGI $B7PM3$G$N(B CSV $B7A<0$n%f%-%9%h%u%!%$%k$nf~no$r@07a$9$k$?$a(b
$B;HMQ$K$5$l$k(B Perl $B$G5-=R$5$l$?(B CGI $B%9%/%j%W%H$G$"$k!#$3$N%=%U%H%&%'%"$O(B
$B0lHLE*$K!"%G!<%?%y!<%9$x%g!<%?$r%$%s%]!<%h$9$ka0$k;hmq$5$l$k!#(b
CSVForm $B$OF~NO%Q%i%a!<%?$h$7$f!"%+%s%^6h@z$j$n%g!<%?$g9=@.$5$l$k%u%!%$(b
$B%k$ruBV$G!"0-0U$r;}$C$FAH$_N)$F$i$l$?(B URL
$B$,%9%/%j%W%H$KM?$($i$l$?:]!"%7%'%k%3%^%s%I$O%U%!%$%k$r3+$/%3%^%s%I$,=h(B
$BM}$5$l$k4V!"%7%'%k$K0z$-EO$5$l$F$7$^$&$N$G$"$k!#(B
$B%7%'%k%3%^%s%I$O(B Web $B%5!<%p$ro(B nobody $B$N8"8B$Ge$GG$0U$N%3%^%s%I$r10. FreeBSD AIO Library Cross Process Memory Write Vulnerability
BugTraq ID: 3661
$B%j%b!<%h$+$i$n:f8=@-(b: $B$J$7(B
$B8xI=F|(B: Dec 10 2001 12:00A
$B4XO"$9$k(B URL:
http://www.securityfocus.com/bid/3661
$B$^$H$a(B:
aio.h $B$H$=$l$K4XO"$9$k%U%!%$%k$O!"(BPOSIX $BI8=`$NHsF14|(B I/O $B$ru672<$k$*$$$f$o!"(bexecve $B$r8F$S=P$7$F$$$k4V!"F~NO%=%1%C%H$+$i$NFI(B
$B$_=P$7>uBV$,7QB3$5$l$?$^$^$K$J$k2DG=@-$,$"$k!#:G=*E*$K$O!"FI$_=P$7>uBV(B
$B$O7QB3$5$l!"?7$7$$%W%m%;%9$N%a%b%j6u4V$KFbMF$,=q$-9~$^$l$F$7$^$&;v$K7R(B
$B$,$C$F$7$^$&!#(B
$B$3$NLdBj$r0-0U$"$k%m!<%+%k%f!<%6$omxmq2dg=$g$"$k!#$^$:!"hsf14|(b I/O $B%3!<(b
$B%k$rMxMQ$9$k%W%m%0%i%`$,:n@.$5$l!"(Bsuid $B%S%C%H$,@_Dj$5$l$F$$$k%P%$%J%j$r(B
execve $B$r2p$7$F8F$S=P$9!#0lEY(B suid $B%S%C%H$,@_Dj$5$l$?%W%m%;%9$,3+;O$5$l(B
$B$k$J$i$P!":G=i$NHsF14|(B I/O $B%3!<%k$+$ifi$_=p$5$l$k%g!<%?$o!"(bsuid $B%W%m%;(B
$B%9$N%a%b%j6u4V$NG$0U$N0LCV$K=q$-9~$a$k2DG=@-$,$"$k!#(B
$B$3$l$O!"$9$J$o$A!"(Broot $B%f!<%6$h$7$fg$0u$n%w%m%0%i%`$n1. Washington Earmarks Megabucks for Cyber Security
$BCxhttp://www.securityfocus.com/news/298
2. Is Open-Source Security Software Safe?
$BCxhttp://www.securityfocus.com/news/297
IV. SECURITYFOCUS TOP 6 TOOLS
- -----------------------------
1. MRTG-eth-probe v1.5.4
$B:nhttp://www.sourceforge.net/projects/mrtg-eth/
$B%W%i%C%H%U%)!<%`(b: Linux
$B$^$H$a(B:
MRTG-eth-probe $B$O!"(BSNMP $B%W%m%H%3%k$r%5%]!<%h$7$f$$$j$$%m%c%h%o!<%/%g%p(b
$B%$%9$NE}7W>pJs$r@8@.$9$k$?$a$K(B Multi Router Traffic Grapher $BMQ$N%W%m!<(b
$B%V$rDs6!$7$^$9!#(B/proc/net/dev ($B$"$k$$$O!"@_Dj$5$l$?B>$N%U%!%$%k(B) $B$+$i%$(B
$B%s%?!<%u%'%$%9$n>uBV$rFI$_=P$7!"%U%!%$%k$r2r@O$7(BMRTG $B$KE,$7$?=PNO$r@8@.(B
$B$7$^$9!#(BSSH $B7PM3$G%j%b!<%h$+$i$n%g!<%?$nfi$_=p$7$b%5%]!<%h$5$l$f$$$^$9!#(b
2. XCmail v1.5beta-2001$BG/(B12$B7n(B14$BF|(B
$B:nhttp://www.js-home.org/XCmail/download/index.php
$B%W%i%C%H%U%)!<%`(b: IRIX$B!"(BUNIX
$B$^$H$a(B:
XCmail$B$O!"(BXclasses $B$H$$$&(B X11 $B$N%l%$%"%&%H%i%$%V%i%j$r;HMQ$7$F$$$k!"(B
MIME$B$r2rA[%U%)%k%@!W$N%3%s(B
$B%;%W%H$J$I!"B??t$NAH$_9~$_5!G=$,$"$j$^$9!#$^$?!"5!G=$r3HD%$9$k$?$a$K30(B
$BIt%W%m%0%i%`$N;HMQ$b2DG=$G$9!#(BXCmail $B$O%W%i%0%$%s%$%s%?!<%u%'%$%9$r;hmq(b
$B$7$F3HD%$b$G$-$^$9!#(B
3. pcAudit
$B:nhttp://www.isa-llc.com/downloads/audit.php
$B%W%i%C%H%U%)!<%`(b: Windows 2000$B!"(BWindows 95/98$B!"(BWindows NT$B!"(BWindows XP
$B$^$H$a(B:
pcAudit $B$O!"(BInternet Security Alliance $B$K$h$C$F3+H/$5$l$?%Q!<%=%j%k%3%s(b
$B%T%e!<%?mq$n%;%-%e%j%f%#4f::%w%m%0%i%`$g$9!#%f!<%6$o!"%q!<%=%j%k%3%s%t(b
$B%e!<%?$k30it$n?/f~l9g$b2DG=$G$9!#(B
4. OpenSC v0.3.2
$B:nhttp://jemmari.tky.hut.fi/opensc/
$B%W%i%C%H%U%)!<%`(b: Linux
$B$^$H$a(B:
OpenSC $B$O!"%P%C%/%(%s%I$K(B PC/SC Lite $B$r;HMQ$9$k(B SmartCard $B%i%$%V%i%j$H!"(B
$B$=$N%i%$%V%i%j$r;HMQ$9$k%"%W%j%1!<%7%g%s$+$i9=@.$5$l$^$9!#8=:_$n$h$3$m!"(b
Finnish Electronic Identity (FINEID) $B$N%+!<%i$g$n$_%f%9%h$5$l$f$$$^$9$,!"(b
PKCS#15 $BBP1~$N%9%^!<%h%+!<%i$g$"$l$pb>$N%+!<%i$g$bf0:n$7$^$9!#$^$?!"(bwww
$BG'>Z$N$?$a$N(B Netscape PKCS#11 $B%b%8%e!<%k!"(bpam $B%b%8%e!<%k!"(bopenssh $B$N%5(B
$B%]!<%h$,5. CryptoHeaven v1.0
$B:nhttp://www.cryptoheaven.com/Download/Download.htm
$B%W%i%C%H%U%)!<%`(b: UNIX$B!"(BWindows 2000$B!"(BWindows 95/98$B!"(BWindows NT$B!"(BWindows XP
$B$^$H$a(B:
$B$3$N%=%U%H%&%'%"$O!"%0%k!<%w$g9b$$%;%-%e%j%f%#%l%y%k$rmw5a$5$l$ff/$/i,(b
$BMW$N$"$kJ}$N$?$a$K:n@.$5$l$^$7$?!#%^%k%A%f!<%6bp1~$n%;%-%e%j%f%#$ree;r(b
$B%a!<%k!"%$%s%9%?%s%h%a%c%;!<%8!"%u%!%$%k6&m-!"%*%s%i%$%s%u%!%$%k$nj]b8(b
$B$KDs6!$9$k$?$a$KE}9g$7!"0l$D$N%Q%C%1!<%8$k$^$h$a>e$2$?%;%-%e%"%*%s%i%$(B
$B%s%7%9%F%`$G$9!#%^%k%A%f!<%64v$g%;%-%e%"$j4d6-$g%f%-%9%h$d%g!<%?$n%j%"(b
$B%k%?%$%`DL?.$r2DG=$H$7$^$9!#(B
6. OpenNA Linux v1b
$B:nhttp://www.openna.com/products/os/download-os.htm
$B%W%i%C%H%U%)!<%`(b: Linux
$B$^$H$a(B:
OpenNA Linux $B$O$-$o$a$F%;%-%e%"$G!"9bB.!"$+$D6aBeE*$J(B Linux $B%*%Z%l!<%f(b
$B%#%s%0%7%9%F%`$G$9!#9b$$%l%Y%k$N%;%-%e%j%F%#$rMW5a$5$l$k4D6-$G!"%_%C%7(B
$B%g%s%/%j%F%#%+%k$J%?%9%/$r9T$&$?$a$K(B Linux $B$r%$%s%9%H!<%k$7!"2tf0$5$;$?(b
$B$$%f!<%6$k$*>)$a$G$9!#(B
- --
$BLu(B: $B:d0f=g9T(B(SAKAI Yoriyuki), $B1F;3E0:H(B(KAGEYAMA Tetsuya)
$B4F=$(B: $B:d0f=g9T(B(SAKAI Yoriyuki)
LAC Co., Ltd.
http://www.lac.co.jp/security/
-----BEGIN PGP SIGNATURE-----
Version: PGP for Personal Edition 5.5.5J
Comment: KAGEYAMA Tetsuya
iQA/AwUBPCIqPc32EXDdoEFfEQKBjQCeO2zbKRFfAtz75456MT2rGzGm3OcAoJfW
L3HY6e1DRFv+82QBRVC6xfkZ
=WUKi
-----END PGP SIGNATURE-----

AltStyle $B$K$h$C$FJQ49$5$l$?%Z!<%8(b (->$B%*%j%8%J%k(B) /