Big Flaw in Firefox 2: Password Manager Bug Exposes Passwords

2006-11-22 Thread fash1on
"Today, Mozilla made public bug #360493, which exposes Firefox's Password Manager on many public sites. The flaw derives from Firefox's willingness to supply the username and password stored on one page on a domain to another page on a domain. For example, username/password input tags on a Myspa

XSS in scriptat support InverseFlow Help Desk v2.31

2006-11-22 Thread gamr-14
XSS in scriptat support InverseFlow Help Desk v2.31 :: Discovered : SwEET-DeViL & viP HaCkEr & HaCkEr sUn Name scriptat: InverseFlow Help Desk v2.31 tame : AL-garnei K-S-A :: #

Perl proxy checker using samair.ru

2006-11-22 Thread Iko Riyadi
hi here it is, perl proxy checker using samair.ru , you can supply proxy list in there, max 15 lines manually, see hints in the code : code: -- #!/usr/bin/perl # # proxck-001.pl - perl proxy list checker #

CONFidence 2007 CFP

2006-11-22 Thread andrzej . targosz
Attention! Calling all practitioners in the field of IT security! The 3rd edition of the best Polish IT security conference, CONFIDENCE 2007, is taking place on May 12/13, 2007. Once again, the royal city of Cracow (Krakow), with a little help from the ProIdea Foundation, will host the world's be

Re: *BSD banner INT overflow vulnerability

2006-11-22 Thread Bob Beck
> that vuln is about as useless as the dhcpd vuln I found. I guess it's good > for practice, but why would you brag about finding that Since it was a vulnerability that bugtraq could post immediately since they didn't have to alert their corporate sugardaddies about it first ;)

Lack of environment sanitization in the FreeBSD, OpenBSD, NetBSD dynamic loaders.

2006-11-22 Thread In Cognito
Vulnerability: Lack of environment sanitization in the FreeBSD, OpenBSD, NetBSD dynamic loaders. Impact: Serious. May lead to privilege escalation. A class of security vulnerabilities has resurfaced in the dynamic loaders of FreeBSD, OpenBSD, and NetBSD in the sanitization of environment variab

Re: Re: *BSD banner INT overflow vulnerability

2006-11-22 Thread evilrabbi
that vuln is about as useless as the dhcpd vuln I found. I guess it's good for practice, but why would you brag about finding that

Lack of environment sanitization in the FreeBSD, OpenBSD, NetBSD dynamic loaders.

2006-11-22 Thread In Cognito
Impact: Serious. May lead to privilege escalation. A class of security vulnerabilities has resurfaced in the dynamic loaders of FreeBSD, OpenBSD, and NetBSD in the sanitization of environment variables for suid and sgid binaries. Due to either badly implemented sanitization or a lack of it, a s

[ MDKSA-2006:208-1 ] - Updated openldap packages fixes Bind vulnerability

2006-11-22 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2006:208-1 http://www.mandriva.com/security/ ___

Windows Media ASX PlayList File Denial Of Service Vulnerability

2006-11-22 Thread sehato
Windows Media ASX PlayList File Denial Of Service Vulnerability Tested: Windows Media 10.00.00.4036 Windows XP SP2 file "example.asx":

Re: [ECHO_ADV_53$2006] QnECMS <= 2.5.6 (adminfolderpath) Remote File Inclusion Vulnerability

2006-11-22 Thread jim
This vulnerability was patched from v2.6.3. Jim

"Which is more secure? Oracle vs. Microsoft" (is it a fair comparison?)

2006-11-22 Thread Matthew Conover
Given that NGS Software participated in Microsoft's Security Development Lifecycle [1] and your paper is already being referenced by Microsoft employees [2], the following question should be addressed to ensure the comparison is fair: Did NGS Software find any bugs in a version of SQL Server mentio

Re: "Which is more secure? Oracle vs. Microsoft" (is it a fair comparison?)

2006-11-22 Thread David Litchfield
Hi Matt, Given that NGS Software participated in Microsoft's Security Development Lifecycle [1] and your paper is already being referenced by Microsoft employees [2], the following question should be addressed to ensure the comparison is fair: Did NGS Software find any bugs in a version of SQL S

Re: Clarifying integer overflows vs. signedness errors

2006-11-22 Thread Thiago Zaninotti
Hi Steve, There seems to have a common association between signedess errors and integer overflow: http://www.phrack.org/archives/60/p60-0x0a.txt IMHO, they are not the same. The issue seems pretty much like Apache Chunked-Encoding Signedess error (when dealing with chunked http header values) an

Re: *BSD banner INT overflow vulnerability

2006-11-22 Thread Steve Shockley
Gruzicki Wlodek wrote: ( By default banner hasn't got set suid bit ) Why in the world would someone add a suid bit to banner? Maybe it's a bug, but you had to work hard to turn it into a vulnerability.

Secunia Research: PassGo SSO Plus Insecure Default Directory Permissions

2006-11-22 Thread Secunia Research
== Secunia Research 22/11/2006 - PassGo SSO Plus Insecure Default Directory Permissions - == Table of Contents Affected Software...

*BSD banner INT overflow vulnerability

2006-11-22 Thread Gruzicki Wlodek
.=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-. | __ | | .-" "-. | | / banner \ | | _ | | _ | |( \ |, .-. .-. ,|

RE: LS-20061113 - CA BrightStor ARCserve Backup Remote Buffer Overflow Vulnerability

2006-11-22 Thread Williams, James K
> -Original Message- > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] > Sent: Tuesday, November 21, 2006 5:07 AM > To: bugtraq@securityfocus.com > Subject: LS-20061113 - CA BrightStor ARCserve Backup Remote > Buffer Overflow Vulnerability > > LS-20061113 > > LSsec has discovered a v