Hiding Backdoors in plain sight

2010-07-05 Thread Mailing lists at Core Security Technologies
The CoreTex Team from Core Security is happy to announce the *1st Open Backdoor Hiding & Finding Contest* to be held at DEFCON 0x12 this year! Hiding a backdoor in open source code that will be subjected to the scrutiny of security auditors by the hundredths may not be an easy task. Positively and

Re: Nginx 0.8.35 Space Character Remote Source Disclosure

2010-06-02 Thread Mailing lists at Core Security Technologies
i...@securitylab.ir wrote: > Vul in stable versions now isn't work. > Original Advisory: > http://blog.pouya.info/userfiles/vul/NginX.rar http://www.coresecurity.com/content/filename-pseudonyms-vulnerabilities Multiple Vulnerabilities with 8.3 filename pseudonyms in Web servers "Nginx Web Server

Re: [Full-disclosure] 3rd party patch for XP for MS09-048?

2009-09-23 Thread Mailing lists at Core Security Technologies
Aras "Russ" Memisyazici wrote: > > How effective is what Tom Grace suggests? Unless I'm misunderstanding, he's > suggesting switching to an iptables based protection along with a registry > tweak... ahh the good ol' batch firewall :) Would this actually work as a > viable work-around? I realize M$