iDEFENSE Security Advisory 10.16.02: Denial of Service in Sabre Desktop Reservation Client for Windows

2002-10-16 Thread David Endler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 iDEFENSE Security Advisory 10.16.02: http://www.idefense.com/advisory/10.16.02.txt Denial of Service in Sabre Desktop Reservation Client for Windows October 16, 2002 I. BACKGROUND Sabre Inc.’s Desktop Reservation Software for Windows is a legacy

NSSI-2002-zonealarm3: ZoneAlarm Pro Denial of Service Vulnerability

2002-10-16 Thread Abraham Lincoln
NSSI Technologies Inc Research Labs Security Advisory http://www.nssolution.com (Philippines / .ph) Maximum e-security http://nssilabs.nssolution.com ZoneAlarm Pro 3.1 and 3.0 Denial of Service Vulnerability Author: Abraham Lincoln Hao / SunNinja e-Mail: [EMAIL PROTECTED] / [EMAIL

Re: CoolForum v 0.5 beta shows content of PHP files

2002-10-16 Thread David Woods
If the webserver is not chrooted or otherwise protected from escaping a directory all files on the system will be potentially readable by an attacker (providing the user the webserver runs as has read permissions) i.e. http://Forum_URLavatar.php?img=3D../../../../../etc/passwd David Woods

Linux Security Protection System

2002-10-16 Thread Bosko Radivojevic
LinSec team is proud to announce the first stable release of LinSec. LinSec, as the name says, is Linux Security Protection System. The main aim of LinSec is to introduce Mandatory Access Control (MAC) mechanism into Linux (as opposed to existing Discretionary Access Control mechanism). LinSec

Cisco Security Advisory: Cisco CatOS Embedded HTTP Server Buffer Overflow

2002-10-16 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco CatOS Embedded HTTP Server Buffer Overflow Revision 1.0 FINAL == For Public Release 2002 October 16 17:00 (UTC) - -- Please

X Windows zlib/MIT-SHM/huge font DoS vulnerabilities

2002-10-16 Thread SGI Security Coordinator
-BEGIN PGP SIGNED MESSAGE- __ SGI Security Advisory Title: X Windows zlib/MIT-SHM/huge font DoS vulnerabilities Number: 20021001-01-P Date: October 15,

Designing Shellcode Demystified

2002-10-16 Thread Murat Balaban
Hi, Here is a paper about shellcode design fundamentals. Available both in English and Turkish: http://www.enderunix.org/docs/en/sc-en.txt [English] http://www.enderunix.org/docs/sc-tr.txt [Turkish] -- Murat Balaban http://www.enderunix.org/

RE: Who Need Friends ? IE MSN expose contact list other info

2002-10-16 Thread Thor Larholm
This is not a vulnerability or even privacy exposure in MSN, but just a demonstration of zone spoofing by using the %2F encoding bug. All the exposed MSN contact list and information is intentionally, and safely, exposed in the My Computer zone. Regards Thor Larholm, Security Researcher PivX

phptonuke allows Remote File Retrieving

2002-10-16 Thread Zero-X ScriptKiddy
The file phptonuke.php from myphpnuke allows Remote File Retrieving. Exploit Example: http://website.com/phptonuke.php?filnavn=/etc/passwd Zero X, member of www.Lobnan.de -- Get your free email from www.linuxmail.org Powered by Outblaze

[SECURITY] [DSA 176-1] New gv packages fix buffer overflow

2002-10-16 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 176-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze October 16th, 2002

[CLA-2002:533] Conectiva Linux Security Announcement - XFree86

2002-10-16 Thread secure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - -- PACKAGE : XFree86 SUMMARY : Several vulnerabilities

[CLA-2002:531] Conectiva Linux Security Announcement - fetchmail

2002-10-16 Thread secure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - -- PACKAGE : fetchmail SUMMARY : Multidrop mode

Apache 1.3.26

2002-10-16 Thread David Wagner
I recently did a very brief (and non-exhaustive) security audit of Apache 1.3.26, and noticed some small potential bugs in some of the helper programs that come with the distribution. Apache maintainers have been notified, and the most serious of these bugs have been fixed in 1.3.27. I'm

MSN Moster Strike Back ?!

2002-10-16 Thread drorshalev
In-Reply-To: [EMAIL PROTECTED] IS MSN Moster Strike Back ?! Less then 10 hours After i Post This message on BugTraq Hotmail Cancelled My Hotmail Account (my Primary email account). So Now I am a Man Without Email Account. you can check out the Error MSG on my Security Workshop :

Re: Undocumented account vulnerability in Avaya P550R/P580/P880/P882switches

2002-10-16 Thread Mike Scher
In response to tbe below, we examined this issue on a Cajun P550 (not 550R) with software version 4.3.5. We found: 1) The accounts (manuf and diag) are clearly present in the config and easily seen with 'show running-conf' or 'show startup-conf' 2) They are system accounts and cannot be deleted

[GIS 2002021001] SkyStream EMR5000 DVB router DoS.

2002-10-16 Thread Global InterSec Research
Global InterSec LLC http://www.globalintersec.com GIS Advisory ID:2002021001 Changed:10/16/2002 Author: [EMAIL PROTECTED] Reference: http://www.globalintersec.com/adv/skystream-2002021001.txt Summary: SkyStream's Edge Media Router-5000 (EMR5000) a DVB to

Openwall GNU/*/Linux (Owl) 1.0 release

2002-10-16 Thread Solar Designer
Hi, For those who don't know yet, Openwall GNU/*/Linux (or Owl) is a security-enhanced operating system with Linux and GNU software as its core, intended as a server platform. And, of course, it's free. More detailed information is available on the web site: