Re: Re: Re: Re: Apache Server HTML Injection and UTF-7 XSS Vulnerability

2008-05-17 Thread yos20053
Dear Bill From Apache I think that you didn't understand this vulnerability properly. I ask to to check again and run this exploit with Firefox. After running this exploit, change manually the ecnoding in Firefox to UTF-7.. You will see that the alert will jump up. There is no problem to trick

StanWeb.CMS (default.asp id) Remote SQL Injection Exploit

2008-05-17 Thread sys-project
# --==+=== Spanish Hackers Team (www.spanish-hackers.com) =+==-- # --==+ StanWeb.CMS (default.asp id) Remote SQL Injection Exploit +==-- # --==++==-- #

[SECURITY] [DSA 1578-1] New php4 packages fix several vulnerabilities

2008-05-17 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1578-1 [EMAIL PROTECTED] http://www.debian.org/security/ Thijs Kinkhorst May 17, 2008

CFP for HITBSecConf2008 - Malaysia now open

2008-05-17 Thread Praburaajan
Hello from Malaysia! The Call for Papers (CFP) for the 6th Hack In The Box Security Conference in Malaysia (27th - 30th October 2008) is now open. We've got some really cool stuff lined up this year including an open-hack competition for charity, a third track in the conference (hitb-labs), 4 ke

PHP-Nuke Module KuraniKerim [sid] SQL Injection

2008-05-17 Thread lovebug
Author : LovebugItaly Rbt-4 Crew www.rbt-4.net PHP-Nuke Module KuraniKerim [sid] SQL Injection Bug : modules.php?name=KuraniKerim&op=TurkceNuke_Com_Islami_Moduller_Destek_Sitesi&sid = [S Q L] Exploit :-1%2F%2A%2A%2Funion%2F%2A%2A%2Fselect%2F%2

IOS rootkits

2008-05-17 Thread Gadi Evron
At the upcoming EusecWest Sebastian Muniz will apparently unveil an IOS rootkit. skip below for the news item itself. We've had discussions on this before, here and elsewhere. I've been heavily attacked on the subject of considering router security as an issue when compared to routing security