Re: [Full-disclosure] Sprint / Verizon MiFi CSRF+CSS Gives up GPS info to attacker

2010-01-18 Thread A. Ramos
Hello all, Just another one: you can access to the configuration backup without authentication at: /config.xml.sav On Fri, Jan 15, 2010 at 17:12, Adam Baldwin wrote: > The MiFi by Novatel Wireless (re-branded and sold by multiple vendors > such as Sprint and Verizon) is a mobile wifi hotspot. Th

Cerberus Helpdesk multiple vulnerabilities.

2005-12-27 Thread A. Ramos
e_id AND th.thread_address_id = ad.address_id AND t.ticket_id = " . $ticket . " GROUP BY th.thread_id LIMIT 0,1"; Solution: --- Not available, maybe changing every "$cerberus_db->query($sql)" to "$cerberus_db->escape($sql)". History: --- 15-20/Nov/2005 --- Bugs discovered 11/Dec/2005 --- The Author has been notified . 19/Dec/2005 --- Full disclosure -- A. Ramos mailto: <[EMAIL PROTECTED]> http://www.unsec.net

Re: iis exploit (fixed)

2001-05-16 Thread A . Ramos
Hi. another port in perl in: http://www.knelo.com/~aramos/perl/iisrules.tgz $ gzip -dc iisrules.tgz | tar -xvf - iisrules.exe iisrules.pl -- A. Ramos mailto:[EMAIL PROTECTED] "Existen dos productos importantes que salieron de Berkeley: LSD y UNIX. No creemos que esto sea una coincid