[HITB-Announce] HITBSecConf2010 - Dubai - Presentation Materials

2010-04-23 Thread Hafez Kamal
Presentation materials from the 4th annual Hack In The Box Security Conference in Dubai are now available for download! http://conference.hitb.org/hitbsecconf2010dxb/materials/ KEYNOTE 1 - John Viega - A/V Vendors Aren't As Dumb As They Look D1 - Daniel Mende - Attacking Cisco WLAN Solutions D1

Re: Vulnerabilities in NovaBoard

2010-04-23 Thread terry white
... ciao: : on 4-21-2010 MustLive writ: and about which, i find me confused. : you can saw the letter which was posted last week by one developer of : one such vulnerable web application --- from my reading of that exchange, i thought the author a 'system administrator', rather

[HITB-Announce] HITBSecConf2009 - Malaysia Videos Released!

2010-04-23 Thread Hafez Kamal
The second quarterly HITB eZine (issue 002) has been released! Grab your copies from here: https://www.hackinthebox.org/modules.php?op=modloadname=Newsfile=articlesid=35995 === 3 months ago, our newly 'reborn' ezine was a completely new experience to our small team and we didn't expect it to

In-portal 5.0.3 Remote Arbitrary File Upload Exploit

2010-04-23 Thread eidelweiss
In-portal is prone to a remote arbitrary file-upload vulnerability This issue may allow remote attackers to upload arbitrary files, including malicious scripts, and possibly to execute a script on the affected server. In-portal Web 2.0 CMS v5.0.3 is affected by this issue. Other or lowers

ZDI-10-078: Novell ZENworks Configuration Management UploadServlet Remote Code Execution Vulnerability

2010-04-23 Thread ZDI Disclosures
ZDI-10-078: Novell ZENworks Configuration Management UploadServlet Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-078 April 23, 2010 -- Affected Vendors: Novell -- Affected Products: Novell Zenworks -- TippingPoint(TM) IPS Customer Protection: