[Full-disclosure] FW: iis bug

2012-04-01 Thread yuange
the exp file. /* iisexp41.c ver4.1 copy by @yuange1975 2012.4.1 假作真时真亦假。 http://weibo.com/yuange1975 http://twitter.com/yuange75 http://hi.baidu.com/yuange1975/blog/item/ac368655017819dbb745aeee.html */ #include stdio.h #include stdlib.h#include winsock2.h #include windows.h #include

[Full-disclosure] March 2012 mini Threat Intelligence report

2012-04-01 Thread Almaz
Is available at http://demyo.com/downloads/threat-intelligence/demyo_inc_-_ti_report_-_mar.pdf -- Almantas Kakareka, CISSP, GSNA, GSEC, CEH CTO Demyo, Inc. Miami, FL, USA Phone: +1 201 665 +1 786 203 3948 Email: al...@demyo.com Twitter: @DemyoSec

[Full-disclosure] Flatnux CMS 2011 08.09.2 - Multiple Web Vulnerabilities

2012-04-01 Thread Research
Title: == Flatnux CMS 2011 08.09.2 - Multiple Web Vulnerabilities Date: = 2012-04-01 References: === http://www.vulnerability-lab.com/get_content.php?id=487 VL-ID: = 487 Introduction: = Flatnux is no database CMS for accessible websites, corporate websites,

[Full-disclosure] ME Firewall Analyzer v7.2 - Cross Site Vulnerabilities

2012-04-01 Thread Research
Title: == ME Firewall Analyzer v7.2 - Cross Site Vulnerabilities Date: = 2012-04-01 References: === http://www.vulnerability-lab.com/get_content.php?id=437 VL-ID: = 437 Introduction: = ManageEngine® Firewall Analyzer is a web based tool for change

[Full-disclosure] Swedish Army Web Database - SQL Injection Vulnerability

2012-04-01 Thread Research
Title: == Swedish Army Web Database - SQL Injection Vulnerability Date: = 2012-04-01 References: === http://www.vulnerability-lab.com/get_content.php?id=472 VL-ID: = 472 Introduction: = The Swedish Armed Forces (Swedish: Försvarsmakten) is a Swedish

[Full-disclosure] HITB2011KUL - Skype Vulnerabilities 0Day Exploitation PART 1

2012-04-01 Thread Research
Title: == HITB2011KUL - Skype Vulnerabilities 0Day Exploitation PART 1 Date: = 2012-03-31 References: === Download: http://www.vulnerability-lab.com/resources/videos/394.wmv View: http://www.youtube.com/watch?v=K4g86hVQ1wk VL-ID: = 394 Abstract:

[Full-disclosure] So, so you think you can tell April 1 joke from a 0day?

2012-04-01 Thread Georgi Guninski
So, so you think you can tell April 1 joke from a 0day? On Sun, 1 Apr 2007 03:26:30 -0400 (EDT) someone posted a message to fd with subject April 1 joke [1] The body of the message appeared to me as not obfuscated vim 0day. vim:

[Full-disclosure] STEP Security

2012-04-01 Thread J. Oquendo
Interweb Re-Engineering Task Force J. Oquendo Request for Comments 4012012 E-Fensive Security Strategies Category: Informational Expires: 2020 STEP by STEP Security Status of this Memo This Internet-Draft is submitted in

Re: [Full-disclosure] STEP Security

2012-04-01 Thread Memory Vandal
This in draft?! man, i been using this protocol for ages. i been calling it unplug-and-safe (UPnS) and its standard operating procedure (SOP) in my workplace. must try for everyone, solves any security issue in a sec. MemoryVandal On Sun, Apr 1, 2012 at 8:36 PM, J. Oquendo s...@infiltrated.net

[Full-disclosure] An April Fools' Day Android Payload

2012-04-01 Thread Dan Rosenberg
/* * Android Arbitrary File Removal Payload * by Dan Rosenberg (@djrbliss) * * Android differentiates between system applications and user-installed * applications, where the former are OEM-shipped and installed in /system/app * rather than /data/app (this has nothing to do with the

Re: [Full-disclosure] STEP Security

2012-04-01 Thread Nick FitzGerald
Interweb Re-Engineering Task Force J. Oquendo Request for Comments 4012012 E-Fensive Security Strategies Category: Informational Expires: 2020 Really? You went to all that trouble to do an extended textual version of the funnier, and much more succint:

Re: [Full-disclosure] STEP Security

2012-04-01 Thread Jeff Kell
Or http://dilbert.com/strips/comic/1996-09-07/ Jeff On 4/1/2012 6:51 PM, Nick FitzGerald wrote: Interweb Re-Engineering Task Force J. Oquendo Request for Comments 4012012 E-Fensive Security Strategies Category: Informational Expires: 2020 Really? You

[Full-disclosure] Amongst data breaches and misc 'leakage', not necessarily digital, DEFCON CTF continues at DEFCON XX

2012-04-01 Thread Vulcan DDtek
FOR IMMEDIATE RELEASE 1 APRIL 2012 DEFCON CTF QUALIFIER ANNOUNCED Defense Diutinus Technologies Corp (ddtek) is pleased to announce the round of qualification for DEFON 20 CTF... DEFCON XX, it's two-thirds sheepornographic! In case you have been under a rock, DEFCON 20 is poised to be the

Re: [Full-disclosure] iis bug

2012-04-01 Thread yuange
ver4.1.1 /* iisexp41.c ver4.1 copy by @yuange1975 2012.4.1 iisexp411.c ver4.1.1 copy by @yuange1975 2012.4.2 1.Changing the input parameters 2.To increase the receive data 假作真时真亦假。True Mingled also false. http://weibo.com/yuange1975 http://twitter.com/yuange75