Re: [Full-disclosure] Ubuntu, duckduckgo, and additional info

2014-01-15 Thread Daniel Wood
There is a reddit post regarding this. Please see http://www.reddit.com/r/Ubuntu/comments/1jek5d/why_am_i_seeing_canonical_when_i_search_using/ Daniel On Jan 14, 2014, at 6:41 AM, silence_is_b...@hushmail.com wrote: Any particular reason when setting duckduckgo as the default search and

[Full-disclosure] CVE-2013-6429 Fix for XML External Entity (XXE) injection (CVE-2013-4152) in Spring Framework was incomplete

2014-01-15 Thread Pivotal Security Team
Severity: Important Vendor: Spring by Pivotal Versions Affected: - Spring MVC 3.0.0 to 3.2.4 - Spring MVC 4.0.0.M1-4.0.0.RC1 - Earlier unsupported versions may be affected Description: Spring MVC's SourceHttpMessageConverter also processed user provided XML and neither disabled XML external

[Full-disclosure] CVE-2013-6430 Possible XSS when using Spring MVC

2014-01-15 Thread Pivotal Security Team
Severity: Low Vendor: Spring by Pivotal Versions Affected: - Spring MVC 3.0.0 to 3.2.1 - Earlier unsupported versions may be affected Description: The JavaScriptUtils.javaScriptEscape() method did not escape all characters that are sensitive within either a JS single quoted string, JS double

Re: [Full-disclosure] Ubuntu, duckduckgo, and additional info

2014-01-15 Thread Gabriel Weinberg
Any particular reason when setting duckduckgo as the default search and searching from the url bar we get an additional nugget of info sent? We use the t=partner parameter to anonymously count the number of searches for revenue sharing. We have 90+ partners doing this, mainly open source

Re: [Full-disclosure] Ubuntu, duckduckgo, and additional info

2014-01-15 Thread silence_is_best
On 01/14/2014 at 6:22 PM, Seth Arnold wrote:On Tue, Jan 14, 2014 at 05:41:42AM -0700, silence_is_b...@hushmail.com wrote: Any particular reason when setting duckduckgo as the default search and searching from the url bar we get an additional nugget of info sent? Case in point: GET

[Full-disclosure] Collabtive Sql Injection

2014-01-15 Thread YOGESH PHADTARE
##=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+## || || || Advisory : Collabtive Sql Injection|| || Affected Version : 1.1 || || Vendor

[Full-disclosure] [SECURITY] [DSA 2844-1] djvulibre security update

2014-01-15 Thread Raphael Geissert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2844-1 secur...@debian.org http://www.debian.org/security/ Raphael Geissert January 15, 2014

[Full-disclosure] Cisco Security Advisory: Multiple Vulnerabilities in Cisco Secure Access Control System

2014-01-15 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Cisco Security Advisory: Multiple Vulnerabilities in Cisco Secure Access Control System Advisory ID: cisco-sa-20140115-csacs Revision 1.0 For Public Release 2014 January 15 12:00 UTC (GMT

Re: [Full-disclosure] Ubuntu, duckduckgo, and additional info

2014-01-15 Thread silence_is_best
On 01/15/2014 at 5:08 AM, Gabriel Weinberg wrote: Any particular reason when setting duckduckgo as the default search and searching from the url bar we get an additional nugget of info sent? We use the t=partner parameter to anonymously count the number of searches for revenue sharing. We have

[Full-disclosure] [Security-news] SA-CORE-2014-001 - Drupal core - Multiple vulnerabilities

2014-01-15 Thread security-news
View online: https://drupal.org/SA-CORE-2014-001 * Advisory ID: DRUPAL-SA-CORE-2014-001 * Project: Drupal core [1] * Version: 6.x, 7.x * Date: 2014-January-15 * Security risk: Highly critical [2] * Exploitable from: Remote * Vulnerability: Multiple vulnerabilities

[Full-disclosure] [Security-news] SA-CONTRIB-2014-002 - Anonymous Posting - Cross Site Scripting (XSS)

2014-01-15 Thread security-news
View online: https://drupal.org/node/2173321 * Advisory ID: DRUPAL-SA-CONTRIB-2014-002 * Project: Anonymous Posting [1] (third-party module) * Version: 7.x * Date: 2014-01-15 * Security risk: Moderately critical [2] * Exploitable from: Remote * Vulnerability: Cross Site

Re: [Full-disclosure] Ubuntu, duckduckgo, and additional info

2014-01-15 Thread Seth Arnold
On Wed, Jan 15, 2014 at 05:47:24AM -0700, silence_is_b...@hushmail.com wrote: I see thank you. My distribution.id nuke did nothingany way to disable this? It's all about choice after all right ;) Depends upon the browser. For Firefox, see:

Re: [Full-disclosure] Ubuntu, duckduckgo, and additional info

2014-01-15 Thread Jordon Bedwell
On Wed, Jan 15, 2014 at 6:47 AM, silence_is_b...@hushmail.com wrote: I see thank you. My distribution.id nuke did nothingany way to disable this? It's all about choice after all right ;) Settings Manage Search Engines Add ___ Full-Disclosure

[Full-disclosure] EE BrightBox router hacked - bares all if you ask nicely

2014-01-15 Thread Scott Helme
The BrightBox router is the standard equipment issued by UK ISP Everything Everywhere (EE) to its subscribers. The device not only leaks sensitive data but is remotely exploitable too. An attacker even has the ability to take control of your account as the router leaks your ISP account