RE: iDefense Security Advisory

2002-12-13 Thread David Endler
/advisory and are properly PGP signed when sent over email. Thanks, - -dave David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook Drive Suite 100 Chantilly, VA 20151 voice: 703-344-2632 fax: 703-961-1071 [EMAIL PROTECTED] www.idefense.com > -Original Mess

iDEFENSE Security Advisory 11.19.02b: Eudora Script Execution Vulnerability

2002-11-25 Thread David Endler
hreats. For more information, visit http://www.idefense.com. - -dave David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook Drive Suite 100 Chantilly, VA 20151 voice: 703-344-2632 fax: 703-961-1071 [EMAIL PROTECTED] www.idefense.com -BEGIN PGP SIGNATURE- Version: PGP 7.1

iDEFENSE Security Advisory 11.19.02a: Denial of Service Vulnerability in Linksys Cable/DSL Routers

2002-11-24 Thread David Endler
on cyber-related threats. For more information, visit http://www.idefense.com. - -dave David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook Drive Suite 100 Chantilly, VA 20151 voice: 703-344-2632 fax: 703-961-1071 [EMAIL PROTECTED] www.idefense.com -BEGIN PGP SIGNAT

iDEFENSE Security Advisory 11.19.02c: Netscape Predictable Directory Structure Allows Theft of Preferences File

2002-11-23 Thread David Endler
dministrators with timely access to actionable intelligence and decision support on cyber-related threats. For more information, visit http://www.idefense.com. - -dave David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook Drive Suite 100 Chantilly, VA 20151 voice: 703

Update: iDEFENSE Security Advisory 11.19.02b: Eudora Script Execution Vulnerability

2002-11-21 Thread David Endler
to our attention. - -dave David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook Drive Suite 100 Chantilly, VA 20151 voice: 703-344-2632 fax: 703-961-1071 [EMAIL PROTECTED] www.idefense.com -BEGIN PGP SIGNATURE- Version: PGPfreeware 6.5.8 for non-commercial use

iDEFENSE Security Advisory 11.11.02: Buffer Overflow in KDE resLISa

2002-11-11 Thread David Endler
etwork administrators with timely access to actionable intelligence and decision support on cyber-related threats. For more information, visit http://www.idefense.com. - -dave David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook Drive Suite 100 Chantilly, VA 20151

iDEFENSE Security Advisory 11.08.02b: Non-Explicit Path Vulnerability in QNX Neutrino RTOS

2002-11-08 Thread David Endler
ovide decision-makers, frontline security professionals and network administrators with timely access to actionable intelligence and decision support on cyber-related threats. For more information, visit http://www.idefense.com. - -dave David Endler, CISSP Director, Technical Intelligence iDEFENSE, I

iDEFENSE Security Advisory 11.08.02a: File Disclosure Vulnerability in Simple Web Server

2002-11-08 Thread David Endler
ide decision-makers, frontline security professionals and network administrators with timely access to actionable intelligence and decision support on cyber-related threats. For more information, visit http://www.idefense.com. - -dave David Endler, CISSP Director, Technical Intelligence iDEFE

Linksys security contact

2002-11-07 Thread David Endler
Cable/DSL Router, has been udpated to reflect an official vendor response from Linksys. Also, the analysis section has been refined to address some inaccuracies from people reporting on this in the press. http://www.idefense.com/advisory/10.31.02a.txt Thanks, - -dave David Endler, CISSP

iDEFENSE Security Advisory 11.06.02: Non-Explicit Path Vulnerability in LuxMan

2002-11-06 Thread David Endler
on support on cyber-related threats. For more information, visit http://www.idefense.com. - -dave David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook Drive Suite 100 Chantilly, VA 20151 voice: 703-344-2632 fax: 703-961-1071 [EMAIL PROTECTED] www.idefense.com -BEGIN P

iDEFENSE Security Advisory 11.04.02a: Pablo FTP Server DoS Vulnerability

2002-11-04 Thread David Endler
on support on cyber-related threats. For more information, visit http://www.idefense.com. - -dave David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook Drive Suite 100 Chantilly, VA 20151 voice: 703-344-2632 fax: 703-961-1071 [EMAIL PROTECTED] www.idefense.com -BEGIN

iDEFENSE Security Advisory 11.04.02b: Denial of Service Vulnerability in Xeneo Web Server

2002-11-04 Thread David Endler
ous code. Our security intelligence services provide decision-makers, frontline security professionals and network administrators with timely access to actionable intelligence and decision support on cyber-related threats. For more information, visit http://www.idefense.com. - -dave David En

iDEFENSE Security Advisory 11.01.02: Buffer Overflow Vulnerability in Abuse

2002-11-01 Thread David Endler
telligence and decision support on cyber-related threats. For more information, visit http://www.idefense.com. - -dave David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook Drive Suite 100 Chantilly, VA 20151 voice: 703-344-2632 fax: 703-961-1071 [EMAIL PROTECTED] www.idefense.c

iDEFENSE Security Advisory 10.31.02c: PHP-Nuke SQL Injection Vulnerability

2002-11-01 Thread David Endler
ot; About iDEFENSE: iDEFENSE is a global security intelligence company that proactively monitors sources throughout the world — from technical vulnerabilities and hacker profiling to the global spread of viruses and other malicious code. Our security intelligence services provide decision-make

iDEFENSE Security Advisory 10.31.02a: Denial of Service Vulnerability in Linksys BEFSR41 EtherFast Cable/DSL Router

2002-11-01 Thread David Endler
gence and decision support on cyber-related threats. For more information, visit http://www.idefense.com. - -dave David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook Drive Suite 100 Chantilly, VA 20151 voice: 703-344-2632 fax: 703-961-1071 [EMAIL PROTECTED] www

iDEFENSE Security Advisory 10.31.02b: Prometheus Application Framework Code Injection

2002-11-01 Thread David Endler
ices provide decision-makers, frontline security professionals and network administrators with timely access to actionable intelligence and decision support on cyber-related threats. For more information, visit http://www.idefense.com. - -dave David Endler, CISSP Director, Technical Intelligen

iDEFENSE Security Advisory 10.24.02: Directory Traversal in SolarWinds TFTP Server

2002-10-24 Thread David Endler
ing to the global spread of viruses and other malicious code. Our security intelligence services provide decision-makers, frontline security professionals and network administrators with timely access to actionable intelligence and decision support on cyber-related threats. For more information, vi

iDEFENSE Security Advisory 10.16.02: Denial of Service in Sabre Desktop Reservation Client for Windows

2002-10-16 Thread David Endler
intelligence and decision support on cyber-related threats. For more information, visit http://www.idefense.com. - -dave David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook Drive Suite 100 Chantilly, VA 20151 voice: 703-344-2632 fax: 703-961-1071 [EMAIL PR

iDEFENSE Security Advisory 10.15.02: DoS and Directory Traversal Vulnerabilities in WebServer 4 Everyone

2002-10-15 Thread David Endler
on cyber-related threats. For more information, visit http://www.idefense.com. - -dave David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook Drive Suite 100 Chantilly, VA 20151 voice: 703-344-2632 fax: 703-961-1071 [EMAIL PROTECTED] www.idefense.com -BEGIN P

iDEFENSE Security Advisory 10.03.2002: Apache 1.3.x shared memory scoreboard vulnerabilities

2002-10-03 Thread David Endler
on-makers, frontline security professionals and network administrators with timely access to actionable intelligence and decision support on cyber-related threats. For more information, visit http://www.idefense.com. - -dave David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook

iDEFENSE Security Advisory 10.02.2002: Net-SNMP DoS Vulnerability

2002-10-02 Thread David Endler
y access to actionable intelligence and decision support on cyber-related threats. For more information, visit http://www.idefense.com. - -dave David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook Drive Suite 100 Chantilly, VA 20151 voice: 703-344-2632 fax: 703-9

iDEFENSE Security Advisory 10.01.02: Sendmail smrsh bypass vulnerabilities

2002-10-01 Thread David Endler
T Method One was exclusively disclosed to iDEFENSE by zen-parse ([EMAIL PROTECTED]) Method Two was discovered during the verification process by Pedram Amini ([EMAIL PROTECTED]) Get paid for security research http://www.idefense.com/contributor.html Subscribe to iDEFENSE Advisories: send email to

iDEFENSE Security Advisory 09.30.2002: Buffer Overflow in WN Server

2002-09-30 Thread David Endler
AIL PROTECTED]). Get paid for security research http://www.idefense.com/contributor.html - -dave David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook Drive Suite 100 Chantilly, VA 20151 voice: 703-344-2632 fax: 703-961-1071 [EMAIL PROTECTED] www.idefense.com -BE

RE: iDEFENSE Security Advisory 09.26.2002: Exploitable Buffer Overflow in gv

2002-09-26 Thread David Endler
ts I imagine would be trivial to create. - -dave David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook Drive Suite 100 Chantilly, VA 20151 voice: 703-344-2632 fax: 703-961-1071 [EMAIL PROTECTED] www.idefense.com -BEGIN PGP SIGNATURE- Version: PGP 7.1.2 Comment: htt

Errata: iDEFENSE Security Advisory 09.26.2002: Exploitable Buffer Overflow in gv

2002-09-26 Thread David Endler
/cvename.cgi?name=CAN-2002-0838 - -dave David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook Drive Suite 100 Chantilly, VA 20151 voice: 703-344-2632 fax: 703-961-1071 [EMAIL PROTECTED] www.idefense.com -BEGIN PGP SIGNATURE- Version: PGP 7.1.2 Comment: http

iDEFENSE Security Advisory 09.26.2002: Exploitable Buffer Overflow in gv

2002-09-26 Thread David Endler
DIT This issue was exclusively disclosed to iDEFENSE by zen-parse ([EMAIL PROTECTED]). Get paid for vulnerability research http://www.idefense.com/contributor.html David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook Drive Suite 100 Chantilly, VA 20151 voice: 70

Now Online: OWASP Guide to Building Secure Web Applications v1.1

2002-09-23 Thread David Endler
We are pleased to announce an updated version of the Open Web Application Security Project Guide to Building Secure Web Applications in both PDF (983K) and HTML at: http://www.owasp.org/guide/ The Guide covers various web application security topics from architecture to preventing attack sp

iDEFENSE Security Advisory 09.23.2002: Directory Traversal in Dino's Webserver

2002-09-23 Thread David Endler
Clients 9/14/2002 - Vendor Response 9/23/2002 - Public Disclosure CREDIT This issue was exclusively disclosed to iDEFENSE by Tamer Sahin ([EMAIL PROTECTED]). Get paid for security research: http://www.idefense.com/contributor.html David Endler, CISSP Director, Technical Intelligence iDEF

iDEFENSE Security Advisory 09.18.2002: Security Vulnerabilities in OSF1/Tru64 3.

2002-09-18 Thread David Endler
onse received from [EMAIL PROTECTED] September 18, 2002 - Public Disclosure http://www.idefense.com/contributor.html David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook Drive Suite 100 Chantilly, VA 20151 voice: 703-344-2632 fax: 703-961-1071 [EMAIL PROTECTED] www.i

iDEFENSE Security Advisory 09.16.2002: FreeBSD Ports libkvm Security Vulnerabilities

2002-09-17 Thread David Endler
ENSE clients September 16, 2002 - Coordinated public disclosure by FreeBSD and iDEFENSE CREDIT This issue was exclusively disclosed to iDEFENSE by [EMAIL PROTECTED] http://www.idefense.com/contributor.html David Endler, CISSP Director, Technical Intelligence iDEFENSE,

iDEFENSE Security Advisory: Linuxconf locally exploitable buffer overflow

2002-08-28 Thread David Endler
Briggs ([EMAIL PROTECTED]) http://www.idefense.com/contributor.html - - -dave David Endler, CISSP Director, Technical Intelligence iDEFENSE, Inc. 14151 Newbrook Drive Suite 100 Chantilly, VA 20151 voice: 703-344-2632 fax: 703-961-1071 [EMAIL PROTECTED] www.idefense.com -BEGIN PGP SIGNATURE---

US TurboLinux Security Severely Out of Date

2002-05-30 Thread David Endler
/7 and ftp://ftp.turbolinux.com/mirrors/ftp.turbolinux.co.jp/stable Additionally while it may be inconvenient to many non-Japanese customers, users can also get notification of new security issues in Japanese for the time being from http://the.turbolinux.co.jp/bugzilla/. David Endler, CISS

Evolution of Cross-Site Scripting Attacks

2002-05-21 Thread David Endler
sed a great FAQ today available at: http://www.cgisecurity.com/articles/xss-faq.shtml Some of the concepts in the iDEFENSE Labs paper may be better understood after reading this FAQ. -dave David Endler, CISSP Director, iDEFENSE Labs 14151 Newbrook Drive Suite 100 Chantilly, VA 20151 voice: 70