CALL FOR PAPERS - SANTA DIED LAST YEAR

2002-10-14 Thread staff
Dear BQ moderator, please forward this CFP to the list. [-]=[-] , , / \ . , / \ |/\ \ |\_,_/| / /\| TELL SANTA TO FSCK OFF - PHRACK MAGAZINE || \ |.- -.| / || IS BRINGING THE

Input requested for second edition of Firewalls and Internet Security

2002-10-14 Thread Steve Bellovin
We've just about finished the draft manuscript for the second edition of Firewalls and Internet Security (this time by Bill Cheswick, Steve Bellovin, and Avi Rubin). Given the tremendous change in the market (including both the prevalence of commercial firewalls and widespread easy access to

GLSA: nss_ldap

2002-10-14 Thread Daniel Ahlberg
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - GENTOO LINUX SECURITY ANNOUNCEMENT - - PACKAGE        :nss_ldap SUMMARY        :Buffer overflow DATE        

GLSA: heimdal

2002-10-14 Thread Daniel Ahlberg
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - GENTOO LINUX SECURITY ANNOUNCEMENT - - PACKAGE : heimdal SUMMARY : remote command execution EXPLOIT :

GLSA: net-snmp

2002-10-14 Thread Daniel Ahlberg
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - GENTOO LINUX SECURITY ANNOUNCEMENT - - PACKAGE        :net-snmp SUMMARY        :Denial of service DATE      

ECHU Alert #3 : Meunity 1.1 script injection vulnerability

2002-10-14 Thread das
-- | Meunity 1.1 script injection vulnerability | -- PROGRAM: Meunity Community System VULNERABLE VERSIONS: all IMMUNE VERSIONS: none SEVERITY: really high Tested version == Meunity Community

Researcher seeking 'phage' and other security mailing list archives

2002-10-14 Thread Curator at Security Digest Archive
I am a researcher constructing a history of computer security digests for which I have so far made positive steps in recovering copies of various 1980s mailing lists and locating key protagonists. You are welcome to view the work in progress at http://securitydigest.org. I am trying to

Directory traversal in Daniel Arenz' Mini Server

2002-10-14 Thread Marc Ruef
Hi! There is a directory traversal flaw in Daniel Arenz' Mini Server 2.1.6 (tested on Windows XP Professional). It could be that prior versions are also affected. It's possible to show every by the web server readable file on the target system by using one of the following URLs:

[SECURITY] [DSA 174-1] New heartbeat packages fix buffer overflows

2002-10-14 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 174-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze October 14th, 2002

GLSA: sendmail

2002-10-14 Thread Daniel Ahlberg
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - GENTOO LINUX SECURITY ANNOUNCEMENT - - PACKAGE        :sendmail SUMMARY        :smsrh bypass vulnerabilites

Pyramid Research Project - ghttpd security advisorie

2002-10-14 Thread pyramid-rp
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -=- SECURITY ADVISORY PYR/\MID, Research Project - 100702 Members: Apm, flea, thread Title: GazTek HTTP Daemon v1.4-3 Buffer Overflow

J2EE EJB privacy leak and DOS.

2002-10-14 Thread Sylvia
Hi, I've contacted Sun twice about this, and they've not responded to me. The EJB security model associates roles with users, and controls their access to object methods based on those roles. Where the object is a stateful session object, any user can access it, provided they have the

[RHSA-2002:194-18] Command execution vulnerability in dvips

2002-10-14 Thread bugzilla
- Red Hat, Inc. Red Hat Security Advisory Synopsis: Command execution vulnerability in dvips Advisory ID: RHSA-2002:194-18 Issue date:2002-09-04 Updated on:2002-10-08 Product:

Pyramid Research Project - atphttpd security advisorie

2002-10-14 Thread pyramid-rp
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -=- SECURITY ADVISORY PYR/\MID, Research Project - 101002 Members: Apm, flea, thread Title: ATP HTTP Daemon v0.4b Buffer Overflow

SuSE Security Announcement: Heartbeat (SuSE-SA:2002:037)

2002-10-14 Thread Olaf Kirch
-BEGIN PGP SIGNED MESSAGE- __ SuSE Security Announcement Package:heartbeat Announcement-ID:SuSE-SA:2002:037 Date:

Long URL causes TelCondex SimpleWebServer to crash

2002-10-14 Thread Marc Ruef
Hi! I've found a vulnerability in TelCondex SimpleWebServer 2.06.20817 Build 3128 (tested on Windows XP Professional). It could be that prior versions are also affected. It's possible to crash the web server application with a long URL (starting from 539 Chars)[1]. You'll see a popup message on

Re: phpBB2 Showing users ip adresses

2002-10-14 Thread nick84
In-Reply-To: [EMAIL PROTECTED] If anyone wanted to get board readers/posters IP addresses on any phpBB (and most other bulletin boards), another easy way would be to simply set up your profile with an off-site avatar. I.e. in the “Link to off-site Avatar:” box on the profile page, type in

Coolsoft PowerFTP = v2.24 Denial of Service (Linux Source)

2002-10-14 Thread a b
Coded for fun.. I had nothing else to code and had nothing else to do. :P I coded it cause Armand released C source that wuz for Windows. Enjoy, --p0pt4rtz /*uNF!uNF!uNF!uNF!uNF!uNF!uNF!uNF!uNF!uNF!uNF!uNF!uNF!uNF! *uNF! * PowerFTP Denial of