Re: [Full-disclosure] Zotob Worm Remover

2005-08-21 Thread Valdis . Kletnieks
On Mon, 22 Aug 2005 01:15:17 BST, n3td3v said: > Diabl0 won't be happy that you're trying to supress his worm. Could be worse. We could have decided his worm wasn't bothersome enough to be worth suppressing. :) pgplBeLr79Imm.pgp Description: PGP signature __

Re: [Full-disclosure] Zotob Worm Remover

2005-08-21 Thread n3td3v
On 8/21/05, Ill will <[EMAIL PROTECTED]> wrote: > Made a Zotob Worm Remover that removes the processes/files/registry entries > from variants A through G. includes MASM source code. Diabl0 won't be happy that you're trying to supress his worm. ___ Full

[Full-disclosure] BBCode [IMG] [/IMG ] Tag Vulnerability

2005-08-21 Thread h4cky0u
Hi, Saw this one on www.waraxe.us (Discovered by Easyex) and i was thinking if there are some more possibilities using the method described. The POC below is for phpBB. - == make yourself a folder on your host rename the folder to signature.jpg this will trick bbcode that its an image f

Re: [Full-disclosure] FrSIRT False Alarm

2005-08-21 Thread Jérôme ATHIAS
"amazing" http://www.securityfocus.com/archive/1/359969/2004-04-06/2004-04-12/0 btw, another KillBit: http://isc.sans.org/msddskillbit.php Paul a écrit : "Microsoft is concerned that this new report of a vulnerability in Internet Explorer was not disclosed responsibly, potentially putting co

[Full-disclosure] Re: Secunia Research: HAURI Anti-Virus Compressed Archive Directory Traversal

2005-08-21 Thread Andreas Marx
Hi! I'm sorry, but you were not the first one who noticed this kind of problem. :-) I've discovered the same type of problems much earlier and reported it to the vendor several times. However, Hauri *never* responded to our inqueries. When I was calling them, they at least acknowledged that th

Re: [Full-disclosure] Zotob Worm Remover

2005-08-21 Thread ad
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 symantec has been faster for this one http://securityresponse.symantec.com/avcenter/venc/data/w32.zotob.removal.tool.html was posted on the javascript page a few time before ;) KEY: 0x

[Full-disclosure] Re: Erroneous Informations - Multiple directory traversal vulnerabilities in Claroline

2005-08-21 Thread Hugues Peeters
Dear Sir, Your web site states at the address below that our application, Claroline, suffer from several security holes. http://seclists.org/lists/fulldisclosure/2005/Aug/0394.html As I have emailed to the author of this warning four days ago (see my message below), Claroline is NOT concerned b

Re:[Full-disclosure] Re: ATutor 1.5.1 and prior multiple XSS Vulnerabilities

2005-08-21 Thread mayank priya
mr. deep (i mean matrix_k , or h4cky0u), its nice to find these elite vuln. of behalf of someone else(you) and then telling vendor properly. just wondering, how come all the vulns are found by matrix and same vendor status "Vendor was contacted but no response received till date." grow up. fu

Re: [Full-disclosure] Zotob Worm Remover

2005-08-21 Thread pingywon
Looks good man - glad to see someone taking some initiative over MS ;) ~pingywon - Original Message - From: "Ill will" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Sunday, August 21, 2005 1:32 AM Subject: Re: [Full-disclosure] Zotob Worm Remover Made a Zotob Worm Remover that rem

Re: [Full-disclosure] Re: MS not telling enough - ethics

2005-08-21 Thread Ivan .
>: Well done, anyone else who knows of people committing fraud against isc2 >: should report them. Unfortunately I don't think its feasible for isc2 to >: check everybody. >Oh, how coincidental.. What do you suggest? that they check everyone who passes the exam? >Ethics Complaint Procedures [0]